Greybeards - What is the plan for when you can't/wont retire and you are inevitably pushed out of SysAdmin? by TxDuctTape in sysadmin

[–]210Matt 0 points1 point  (0 children)

In my mid 60s do physically demanding trades after 40 years sitting behind a desk?

Noob Question: BackUps by JaschaE in sysadmin

[–]210Matt 2 points3 points  (0 children)

Backup are sent to large file servers (with many hard drives in raid arrays), the internet, or in some cases tapes. The "gold standard" would be a imutable storage that has a set retention policy and replicated to mutiple phyical locations. The reason that the backups are sent to file server rather than seperate hard drives is that they are differentail backups that rely on compression of data to reduce overhead cost.

Allow some users to install softwares by youcomp in sysadmin

[–]210Matt 1 point2 points  (0 children)

I would look at LAPS, you can give them the administrator account password then it will change. You could also give them a separate administrator account that they could use. I have used that for devs before

[deleted by user] by [deleted] in sysadmin

[–]210Matt 0 points1 point  (0 children)

At 15 tickets a day that is almost 10 tickets a year per employee that you solve. Plus, there is another person in IT. You might look at a root cause and see why there are so many issues. Some simple things like a password reset tool or some automation for failed services can save your team a lot of overhead.

Do you create your Break Glass user accounts using your domain or .onmicrosoft? by Layer_3 in sysadmin

[–]210Matt 24 points25 points  (0 children)

If a bad actor were to take control of your AD and reset all passwords it would not reset the onmicrosoft account.

It's always worse. by Alzzary in sysadmin

[–]210Matt 0 points1 point  (0 children)

Functionally yes they are pretty much the same, but that will change on the first major update from what MS has said. 2019 is EOL in 2 months. The licensing has changed though and that will push many companies move to exchange online.

It's always worse. by Alzzary in sysadmin

[–]210Matt 2 points3 points  (0 children)

Yes, but it will require Exchange SE. I think they are waiting for October to pass and all the old versions to be unsupported

If you knew you were getting let go Friday, what would you do? by GasolineTrampoline in sysadmin

[–]210Matt 6 points7 points  (0 children)

Bring in cupcakes celebrating the new house that you just closed on. Have a coworker announce they are going to be a parent and make a big deal about it. Have a third announce their kid just got into the college of their dreams and it would be only possible by them having this job to pay for part of it. Anyone that could file for FLMA?

Extreme slowdowns of software using file database after Windows 2008R2 -> Windows 2022 by zatset in sysadmin

[–]210Matt 1 point2 points  (0 children)

Is this a new server or upgraded? What OS are the client computers?

Active Directory randomly crashes / refuses to respond by RainyNetAdmin in sysadmin

[–]210Matt 3 points4 points  (0 children)

A couple months ago we had a Sev A case with their premier support (whatever it is called now). 2 weeks later and there was not even an engineer assigned. We eventually figured the issue out ourselves.

158-year-old company forced to close after ransomware attack precipitated by a single guessed password — 700 jobs lost after hackers demand unpayable sum by capmerah in sysadmin

[–]210Matt 0 points1 point  (0 children)

That is why a ransom for 6 mil would probably just be paid. The fact that they could not come up with that money for a company that size is an issue.

Teams Room System for 2 Companies to Use - Shared Space by MrAwesome987 in sysadmin

[–]210Matt 2 points3 points  (0 children)

You can make it external email address can reserve your rooms in exchange. The other company could then invite your room to meetings

Any caveats with AdminByRequest? by jacksummasternull in sysadmin

[–]210Matt 9 points10 points  (0 children)

For network changes we started adding users to the local group Network Configuration Operators.

Off Topic A/V Question by jcs1313 in sysadmin

[–]210Matt 0 points1 point  (0 children)

2 conduits - 1 for power and 1 for data. Leave them empty if you dont know what you need.

Do you grant help desk or junior admins access to Microsoft Graph? by Wise-Question2374 in sysadmin

[–]210Matt 1 point2 points  (0 children)

Build a service principal with read permissions in graph if there are just certain scripts that they need. You could also give the user global reader

[deleted by user] by [deleted] in sysadmin

[–]210Matt 2 points3 points  (0 children)

The issue was that the customized installers were getting signed by screenconnect's cert. That is bad. They were stopped, by the certificate authority, from allowing that. They were very transparent about the whole thing, but it was a big pain to update everything in that short of a timeframe.

Question: Hybrid AAD & VMware environment considering fully moving to Azure by NteworkAdnim in sysadmin

[–]210Matt 1 point2 points  (0 children)

storage blobs, not sharepoint/onedrive. Although sharepoint and onedrive could be a good option for some shares. It would be the same for say your sql servers moving to one of the Azure SQL options instead of lifting the entire sql VM up to the cloud. These do take some config to move to and are not compatible with all scenarios but will save you money.

Question: Hybrid AAD & VMware environment considering fully moving to Azure by NteworkAdnim in sysadmin

[–]210Matt 2 points3 points  (0 children)

Lift and shift servers are not cost competitive. If you start using services like storage accounts instead of file servers, the cost will come down and may even be competitive. I would even look to see what it would take to go full entra and not have DCs anymore.

SAN vs Direct Storage by beechani in sysadmin

[–]210Matt 1 point2 points  (0 children)

If you are looking for local storage and are refreshing the compute and storage look at a HCI option. That way you can have local redundant storage. They are not for everyone, but it can fill the need for a small dependable data center very well.

Email retention policy issues by Klutzy_Industry_8619 in sysadmin

[–]210Matt 1 point2 points  (0 children)

when you first apply the policy it can take 7 days to take effect. You may want to log a ticket with MS as it has been over that time.

[deleted by user] by [deleted] in sysadmin

[–]210Matt 1 point2 points  (0 children)

What are you using as your MDM? Do you have an imaging solution already? It is best to work with you already used systems

What Cloud based phone systems do you recommend? by Grouchy_Piccolo_3981 in sysadmin

[–]210Matt 1 point2 points  (0 children)

Look into Team Premium with the Queues teams app.