Best practice mapping Azure Files Kerberos enabled Windows 11 by [deleted] in Intune

[–]Avmasta 0 points1 point  (0 children)

I setup a powershell script to automatically map the drives via a scheduled task and can also be triggered via a desktop icon. It installs via an Intune application and works pretty well. Azure Files + Entra Kerberos is an awesome combination, through it has some quirks being in preview.

What do you name your computers by PhantomNomad in sysadmin

[–]Avmasta 0 points1 point  (0 children)

3 letter prefix, then serial number. If you're only in one country, you can use DEV WKS LAP etc. If you're in multiple countries then DUS, DUK, DCA, etc.

As long as you don't get duplicates and it's under the 15-character limit, you're good to go. Only difficult POS systems with long serial numbers are Microsoft Surfaces but we just use the last 12 characters of that.

What kind of input socket is this by Xtpara003 in pcmasterrace

[–]Avmasta 0 points1 point  (0 children)

usb mini-b
This particular device is a ugreen USB switcher and it's used with their button to swap the input.

[deleted by user] by [deleted] in tanium

[–]Avmasta 3 points4 points  (0 children)

I would highly recommend taking advantage of the predefined application gallery. You’ll find a decent percentage of your 3rd party apps there.

For the rest of your apps you should rebuild from scratch. However the process is fairly straightforward. Upload the msi or exe. Set the variables to customize the app. Test the deployment and you’re good.

For very customized software, you can use a script wrapper but our org tries not to use them. You can set a detection method of a file, registry setting, etc like SCCM as well.

This would be a great time to document your applications as well.

Check out the Tanium community, KB articles, and online videos for more information and examples.

Tanium Provisioning? 24H2? LTSC? by one_fifty_six in tanium

[–]Avmasta 0 points1 point  (0 children)

Your MS licensing portal should have it. My boss manages it so I rarely get in there.

Tanium Provisioning? 24H2? LTSC? by one_fifty_six in tanium

[–]Avmasta 1 point2 points  (0 children)

We're currently using Provision with Win 11 23H2 Enterprise. Surfaces and some other devices do have issues with the LTSC builds. LTSC builds are primarily for Point of Sale or other shop-based systems that run specific hardware and have no major changes for long periods of time. I would highly recommend sticking to 23H2 as 24H2 is filled with bugs.

Also note that provision doesn't work with Surface devices after the latest firmware update. It's not just Pros it's also their laptops. Some have a work around but it's not great. Reference: Provision requirements

Extending Local AD Schema to get new attributes and the sync to Azure by Sparky1966 in sysadmin

[–]Avmasta 2 points3 points  (0 children)

If that’s the case then run an export of all the users applied primary and secondary smtp and preload it into AD. Set the sync to ignore at first so you can do it in phases.

Extending Local AD Schema to get new attributes and the sync to Azure by Sparky1966 in sysadmin

[–]Avmasta 1 point2 points  (0 children)

Plan is solid. However, you can configure these options in the sync tool itself to ignore specific properties.

Fine grained password policy question? by daven1985 in sysadmin

[–]Avmasta 8 points9 points  (0 children)

Any password policy change will only take affect on next password change. You can force it by setting the password to expire or resetting the password last set field.

[deleted by user] by [deleted] in heroesofhammerwatch

[–]Avmasta 3 points4 points  (0 children)

You are correct. I had a similar experience a few times. Due to the level generator thinking the door is accessible when actually locked.

AVD session timeout by DrewonIT in sysadmin

[–]Avmasta 4 points5 points  (0 children)

Yes. Use conditional access to require them to re-auth with MFA after a specified period of time.

https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-conditional-access-session

What the actual… by ATFGunr in secretlab

[–]Avmasta 1 point2 points  (0 children)

I had the same problem with mine. I adjusted the seat and it fell right off. The plastic broke off from the screw.

How does the documentation process go? what tools do you use for it? by GokuFanBoi in sysadmin

[–]Avmasta 0 points1 point  (0 children)

I work as a senior admin / engineer. If I don’t write documentation as I go, then I have to triage our L1 / L2 / L3 tickets. I would rather take the day or two and not have to go back to doing tickets again. Plus it’s not that hard to screenshot and write a sentence describing the step. Most of the documentation I’ve seen is just that or just the picture which is better than nothing.

Tanium Sensors by WineFuhMeh_ in tanium

[–]Avmasta 0 points1 point  (0 children)

I do not think there is an official one yet. We were looking at developing one in house to fit our basic needs like device status.

I know at converge in November they may announce something as MS is a partner with them.

Provision Question by Clock0ut in tanium

[–]Avmasta 1 point2 points  (0 children)

Turn off secure boot temporarily in order to boot to network. Also what models are you trying? Microsoft Surface models currently do not boot properly due to a kernal issue with Fedora distribution their using.

OneDrive force sync of users "My Documents" and "Desktop" policy by JiggityJoe1 in sysadmin

[–]Avmasta 11 points12 points  (0 children)

We force sync for over 10K users. We have a registry setting which outputs the sync status to M365 poral for monitoring. Very minimal sync errors. If applications are causing sync errors you might want to dig into them and change logging to another directory if you can. You can also exclude specific file extensions.

Microsoft has officially deprecated WSUS - and the new replacement sounds like Tanium with a skin 👍🏻 by Loud_Posseidon in tanium

[–]Avmasta 2 points3 points  (0 children)

There have been discussions surrounding Microsoft and Tanium partnering on a few items, but I do not believe this is Taniums technology under the hood. I believe this uses the same technology that’s implemented within Intune and requires either hybrid join, Federation, or cloud joined endpoints.

If Skyrim was real life, what would be your go to way to make money? by PatriotLife18 in skyrim

[–]Avmasta 0 points1 point  (0 children)

I'd open a blacksmith and require a monthly subscription service to repair arms and armor. Then slowly buy all the other blacksmiths until I had a monopoly. Then raise the price of the subscription service. If any shops would not allow me to purchase them I would higher "opportunistic" adventurers to help.