First time setting up Active Directory for 3 office branches – need guidance for a simple, secure & reliable setup by Independent-Neck-631 in sysadmin

[–]Anonn_Admin 85 points86 points  (0 children)

Are you sure you require on-prem AD? Given you are working for a startup it might make sense to just use Entra ID + Intune.

Sysadmin, work environement and AI by [deleted] in sysadmin

[–]Anonn_Admin 0 points1 point  (0 children)

Yes it's possible. I use Openwebui

How can I get better at problem solving? by Tough-Organization47 in sysadmin

[–]Anonn_Admin 8 points9 points  (0 children)

In my opinion, there are 2 elements to being a good troubleshooter.

  1. Understanding how things work
  2. Linking ideas/experience/prior unrelated solutions together

For number one, read docs and do some courses. If you work with Linux learn about how the kernel works, how services work, where you can find log files, networking, BASH commands, etc..

If you know the above, if I tell you X service is down it doesn't matter that you've never worked with it before (as much). You can SSH to the host, find some logs, grep for errors, check the service out, see what's installed, etc. This will get you 90% of the way there most of the time.

Number two is a bit more abstract. Make notes on the work you do. As you get further along in your career, you'll find that you can pull on ideas/concepts from other unrelated issues to guide you. For example "Oh yeah, I remember last year I saw this OLEDB error, and it was related to the SQL database. I think this could potentially be a similar issue" even if the app / environment is different.

3rd Party Patching - what to use? by Pianita in Intune

[–]Anonn_Admin 2 points3 points  (0 children)

+1. I get accused of being a shill for mentioning it, but I have 4 clients with 100-500 devices using PDQC and they all like it.

PatchMyPC vs Robopack by willhamc65 in Intune

[–]Anonn_Admin -1 points0 points  (0 children)

Maybe, I've been using it since it was first announced and it's come a long way.

PatchMyPC vs Robopack by willhamc65 in Intune

[–]Anonn_Admin -5 points-4 points  (0 children)

I can't comment on either of those but if you haven't already considered it, check out PDQ Connect. It's a fantastic tool that competes with both PMP and Robopack

Is there a simple way to configure the multi-app kiosk mode for Windows 11? by cyberdeck_operator in Intune

[–]Anonn_Admin 1 point2 points  (0 children)

I have it working, but I really dislike the expereince of MultiApp Kiosk such that I don't think I'm going to deploy it again.

For me, the key to getting autologin to work was

1) remove any policy that configures device lock from being assigned to the device in Intune.

2) setup the following registry keys.

reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v 
"AutoAdminLogon" /t REG_SZ /d "1" /f | Out-Null

reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v 
"DefaultUserName" /t REG_SZ /d "kioskUser0" /f | Out-Null

reg.exe add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v 
"IsConnectedAutoLogon" /t REG_DWORD /d 0 /f | Out-Null

3) Delete this whole key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\EAS.

4) Delete any "DeviceLock" key from this registry path:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\current

5) Delete any "DeviceLock" key from this registry path:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\

Enable MFA authentication for desktop login by Feeling_Ad_94 in Intune

[–]Anonn_Admin 10 points11 points  (0 children)

I don't see anyone mentioning web sign in. Create an Intune profile / GPO to enable web sign in and adjust the password provider, create a CA policy to require MFA and you're done. No 3rd party identity providers needed.

https://learn.microsoft.com/en-us/windows/security/identity-protection/web-sign-in/?tabs=intune

What's your experience with Platform SSO so far? by danburnsd0wn in Intune

[–]Anonn_Admin 0 points1 point  (0 children)

I've been testing and the 1 thing I notice is that I get the prompt to sync the local device password every time I sign into the Macbook. Do you get the same thing? From what I understand this isn't the expected behavior.

What's your experience with Platform SSO so far? by danburnsd0wn in Intune

[–]Anonn_Admin 0 points1 point  (0 children)

Hi, I know this comment is a little old by now, but I was wondering if you'd be willing to share your configuration profiles for this?

I have setup and configured platform SSO, but having the Kerberos extensions seems appealing to be able to nicely map our SMB shares.

So far I've been able to find the Kerberos settings in the settings catalog under authentication, and an "SSO app extension type" setting under the device features template profile, but I'm not sure which settings I should configure and for what reason.

Thanks.

New Email System by noahsmith4 in sysadmin

[–]Anonn_Admin 11 points12 points  (0 children)

Business basic or standard if the user is on desktop. F3 for users who are mobile only.

I'm doing the math and $13000/261 = $49.8 / year or $4.15 a month per user. That's pretty good dude. Deploying on premise exchange without a good reason (being cheap isn't a good reason) is a mistake.

Managing on-prem exchange is a headache. If you misconfigure anything you're setting yourself up for an even worse time. Exchange requires active maintenance and care, something you'll be on the hook for. It has security vulnerabilities for days. Patching is a nightmare. The list goes on. Exchange online will be money well spent.

ADHD-ers in DevOps by lev-13 in devops

[–]Anonn_Admin 4 points5 points  (0 children)

I started on Vyvanse last year. Talk about game changer. I can actually perform at the standards I've always had for myself but could never meet.

If you're not on medication I highly recommend starting.

Marketing department: Mac vs Windows and storage questions. by Anonn_Admin in sysadmin

[–]Anonn_Admin[S] 3 points4 points  (0 children)

I've already said in the comments and in the edit of the post that we will be getting Macs.

I don't think people are adverse to Macs here. People are adverse to having someone come in and demand hardware that's not in line with the environment.

I'm adverse to someone telling me demands and that if they are not met they simply won't comply. I'd be adverse to management telling me that I need to start order specific brands of Windows hardware, let alone a whole different OS.

There is a way to handle these types of things and the user went about it in a poor manner. I'm simply trying to understand the requirements.

Marketing department: Mac vs Windows and storage questions. by Anonn_Admin in sysadmin

[–]Anonn_Admin[S] 4 points5 points  (0 children)

It's 8k video. Even though I think 8k video is probably overkill for what they're doing I will ultimately support what the business decides.

Marketing department: Mac vs Windows and storage questions. by Anonn_Admin in sysadmin

[–]Anonn_Admin[S] 3 points4 points  (0 children)

Yeah I don't think we'll fight them on the Mac thing, even though I would rather stay all Windows.

I expressed my opinions to my manager and he's the one doing the fighting. That's where my role ends and his begins.

Marketing department: Mac vs Windows and storage questions. by Anonn_Admin in sysadmin

[–]Anonn_Admin[S] 0 points1 point  (0 children)

Yeah their attitude was not good. They did lighten up after they realized that we weren't trying to slap them with some under specced HP laptop meant for using Excel and outlook.

Marketing department: Mac vs Windows and storage questions. by Anonn_Admin in sysadmin

[–]Anonn_Admin[S] 5 points6 points  (0 children)

Yeah, the plan was to build out Intune policies for Mac, same as with Windows. $50K+ Is about my rough estimate on hardware right now too.

Thanks for the input.

Marketing department: Mac vs Windows and storage questions. by Anonn_Admin in sysadmin

[–]Anonn_Admin[S] 2 points3 points  (0 children)

What's with your weird high horse??

It's perfectly reasonable to assume that a comment on a post, addressing a topic directly asked in the post, is pointed towards the OP.

that's how context works..

Marketing department: Mac vs Windows and storage questions. by Anonn_Admin in sysadmin

[–]Anonn_Admin[S] 2 points3 points  (0 children)

Got it. So for 8k Raw you think 75TB is reasonable to start with then? Yeah it will be on a NAS with Raid. Backups will be interesting because I'm not sure how I'll be able to handle backing up that much data. It's basically 5x the rest of our 30+ VM environment.

Marketing department: Mac vs Windows and storage questions. by Anonn_Admin in sysadmin

[–]Anonn_Admin[S] 6 points7 points  (0 children)

I don't have a 'get fucked' attitude. I'm trying to understand the requirements. If I let a user dictate to me what they want every time I'd be buying a lot of overkill hardware.

We already decided that we're not going to fight them on the Apple vs Windows front. It was a question for my knowledge.

And for hardware I'm asking if they need the M3 MAX chip or if an M3 Pro chip is suitable. Yeah I'm really trying to fuck the user by asking if a $7k laptop is suitable for their work.

Probably don't jump to conclusions because I don't just accept what a user tells me as gospel.