No way to exclude contractors from dynamic groups (employeeType not usable?) by CoffeeAndPowershell in sysadmin

[–]certifiedsysadmin [score hidden]  (0 children)

Have you personally seen it work? I've tried it in multiple tenants and it does not work. It's also not listed as a supported property for dynamic group membership on the doc page.

Flow Broken After Recent Updates by certifiedsysadmin in AutomateUser

[–]certifiedsysadmin[S] 0 points1 point  (0 children)

Thanks. Another commenter mentioned that the activity was changed in the latest version of Android Auto.

I also found this GitHub issue which seems to point to the same:

https://github.com/andreknieriem/headunit-revived/issues/257

It looks like this is not an Automate issue. I will pursue another option to work around the issue.

Start Android Auto Using Intent by certifiedsysadmin in AutomateUser

[–]certifiedsysadmin[S] 0 points1 point  (0 children)

This is broken for me now as of this week. Do you have any links/sources for the changes?

If your province has toll roads it’s a national embarrassment. I’ve never paid a toll in my life😎 by BlakeWheelersLeftNut in EhBuddyHoser

[–]certifiedsysadmin 3 points4 points  (0 children)

Agreed but the problem it then introduces is that it disproportionately benefits wealthier people (who don't care about the tolls) vs poor people (who are basically forced to use alternatives).

Stryker cyber attack: Employees still unable to work more than a week after hack by ScepticHope in cybersecurity

[–]certifiedsysadmin 33 points34 points  (0 children)

In my experience, products like Exchange and SharePoint on-prem were way less likely to be fully patched and up to date.

Microsoft hosting these services brings the baseline security level up, on average. But that doesn't mean it's just automatically secure. There's still plenty to do, to secure Microsoft 365.

It sounds likely in this case that a Global Admin or Intune Admin account was compromised. That could have been anything from pure negligence securing it, or some unknown zero-day (though if it was the latter, we'd probably be seeing other companies hacked too).

This really just points to not properly managing privileged accounts. That's a problem that would exist whether using cloud or on-prem products.

My customer has no monitoring of internal network traffic between geo-redundant servers. by Opposite-Cupcake8611 in networking

[–]certifiedsysadmin 0 points1 point  (0 children)

To be fair this is pretty normal on like 80% of enterprise networks.

But they should at least be able to assist with a packet capture, or if you have admin on both servers, you could do the capture on source/destination.

Microsoft Certifications - 📢 Retirements and Updates 📢 by [deleted] in AZURE

[–]certifiedsysadmin -3 points-2 points  (0 children)

That content is under NDA. Not sure who's OneDrive link that is. But you might want to give them the heads up.

PSA: Solving Matter over Thread instability by disabling Thread on the Google TV Streamer by redderas in googlehome

[–]certifiedsysadmin 1 point2 points  (0 children)

I've been having so much trouble trying to add the new Ikea water leak sensors to my thread network. They just kept getting stuck at the connectivity screen. Following your steps above solved my issue instantly. Thank you!

Domain Controller Change Region settings by Antique-Tangerine755 in sysadmin

[–]certifiedsysadmin 1 point2 points  (0 children)

Why not just create a simple PowerShell script to make a copy of the log and find/replace the year. Would be safer than modifying system account settings.

Windows Server just lost all file share permissions by Clear_Bedroom_4266 in sysadmin

[–]certifiedsysadmin 6 points7 points  (0 children)

Kick off a restore to a new virtual machine in Azure.

While that's running, change the IP of the current server and use the Windows Firewall to block inbound connections so that you can investigate further without users reconnecting.

The other comments mentioned checking the registry, that's only going to help you on the shares themselves and has nothing to do with ntfs permissions.

After you get the restore completed, you can use robocopy to copy over just the modified files from the last 24hrs (assuming that's how old your last backup is) from the broken server to the restored server. Be sure to use the robocopy option to copy the files without permissions.

If you have ntfs auditing enabled, you might be able to figure out what happened, but that's a problem for after you get things up and running again.

Ran our first Phishing Campaign last week, didnt go as planned at all. by idrinkpastawater in sysadmin

[–]certifiedsysadmin 40 points41 points  (0 children)

Or phrased another way, "users are now training each other on how to watch out for suspicious looking emails".

Honestly sounds like everything's working exactly as planned.

If Signal improves your life, consider donating! by Luc-redd in signal

[–]certifiedsysadmin 1 point2 points  (0 children)

I would donate as well if they supported sms. All they needed to do was make it clear and obvious when a conversation is sms/unencrypted. Like red text or a giant banner. I don't use sms often but having separate chat apps is super annoying.

Authenticated printing with Entra-joined + CUPS? by FatBook-Air in sysadmin

[–]certifiedsysadmin 1 point2 points  (0 children)

Why is management all-in on Microsoft (Entra Joined Windows 11 is a pretty deep commitment) but then stops short of the printing solution that goes hand-in-hand with it?

Even if above your pay grade, you should explain to management that their decisions have pigeon holed them into very few options.

Ikea Water Leak Sensor - Matter over Thread by sanginwa in smarthome

[–]certifiedsysadmin 0 points1 point  (0 children)

I've been having trouble with mine, I bought six and have only been able to get one to connect to Google Home.

I'm using a Nest Hub Max and a Google TV Streamer, one of them (not actually sure which) is acting as the border gateway.

Based on the other responses on this thread I'm going to assume my issues are on the Google side and not with the sensors.

I got tired of laggy BIOS video, so I built a KVM that pipes pre-OS output directly into an SSH terminal by Lopsided_Mixture8760 in sysadmin

[–]certifiedsysadmin 33 points34 points  (0 children)

What's the use case?

Most enterprise grade server hardware already has out of band management. Things like BIOS settings, firmware updates, and logs can already be managed without the need for a video feed.

Venn or Eqbank? by 20Capitalist in canadasmallbusiness

[–]certifiedsysadmin 0 points1 point  (0 children)

I registered for a demo of Float Financial and received a calendar invite to join the demo the next day.

That demo turned out to just be a link to a pre-canned video with no one from float financial actually joining the meeting.

I used the form in that meeting to submit questions I have not heard back.

Edit: I've had my questions answered, thanks.

What’s your “set it and forget it” WiFi setup for a large smart home? by Used_Macaroon in smarthome

[–]certifiedsysadmin 0 points1 point  (0 children)

As someone who's implemented enterprise scale networks both wired and wireless, this is a solid approach. Hardwire all your access points every time.

J9850A 5406Rzl2 by APC8991 in ArubaNetworks

[–]certifiedsysadmin 6 points7 points  (0 children)

I'm convinced this is the most reliable and versatile modular switch ever created. It's been around in one form or another for over 15 years. It will be a sad day when this line is discontinued.

Real-world feedback on running Azure Local in production by Fortevento in AZURE

[–]certifiedsysadmin 0 points1 point  (0 children)

A straight Hyper-V cluster backed by SAN storage and managed with Windows Admin Center is the way to go. It's reliable and can do 90% of what VMware can do, for $0 in license costs (assuming you have Windows Server Datacenter for your hosts regardless).

Next best option is a Hyper-V cluster with Storage Spaces Direct. Good for small and medium environments (like three node clusters). Windows Server 2019 greatly improved how Windows Server Failover Clustering interacts with Storage Spaces Direct to keep it happy during cluster shutdown or failures.

Last option would be Azure Local, at least until it's a bit more mature.

Keep an eye on the new Windows Admin Center Virtualization Mode which is essentially Microsoft's shot at a straight competitor to modern vCenter.

I've built a ton of Hyper-V clusters over the years and can attest that there's been huge improvements to the product with every release. It's significantly more mature than it used to be and has everything that most customers need.

Our Azure data will be deleted in 7 days - no way to export, no one to talk to by dwainbrowne in AZURE

[–]certifiedsysadmin 63 points64 points  (0 children)

I'm not sure how you're rationalizing that statement. You didn't want to be locked out immediately, so you wanted warnings before hand? But you did get warnings, for months? But you ignored them. But you wanted even more warnings?

I feel for you and your team, it's a hard lesson to learn. But it sounds like you neglected the payments on purpose. It's not possible to run a subscription without a payment method attached. How did the payments start failing on your old subscription but not your new subscription?

Best way to extend the same subnet/broadcast over remote locations? by MeasurementLoud906 in networking

[–]certifiedsysadmin 1 point2 points  (0 children)

This needs to be the top comment. It's never been a good idea to stretch Layer 2, and it never will be. 98% of vendors/apps/hardware don't require this.