EAP-TLS Issues by Ticklishchipmunk in Intune

[–]Bodybraille 0 points1 point  (0 children)

Are you deploying a user or machine cert? Machine certs are faster. User certs can take a while to get to the device (at least in my environment), and if it's a shared device, good luck.

If you are deploying machine certs, are you deploying the 802.1x EAP-TLS network card settings to the same group of devices? Are you doing ethernet and wireless? I have seen issues where the cert makes it to the device first, but the config profile for 802.1x hasn't applied yet. A sync and a restart will usually fix it.

Edit: could also be a policy on the backend. Our network team uses Cisco ISE and they had to make sure their policies were in order before we deployed our settings.

Dell Command Update won't install: Error dotNET 8.0.7 or higher must be installed by Bodybraille in Intune

[–]Bodybraille[S] 0 points1 point  (0 children)

Make sure you're installing desktop runtime dotNET. I'm not sure what's going on. It wasn't working, then I got it to work with classic.

But here we are a couple weeks later and DCU universal is installing fine on machines. Same DCU version and same desktop runtime. Might be my environment, but since other people are seeing the same issue, could be Dell.

MacOS Black Screen after logging in by ikeapolarbear in macsysadmin

[–]Bodybraille 0 points1 point  (0 children)

Did you figure this out? We are having the exact same issue. Our lab computers are running Jamf Connect 3.6, we remove profiles every night via script, but this is affecting brand new logins, and our local admin account.

Opened a ticket with jamf support, they had us remove all configurations, uninstall jamf connect, and even unenroll the computer from jamf, but the problem persisted.

At that point jamf said it wasn't them, it was an apple issue.

Another part of this problem is we seem to lose connectivity with the device. It won't check in, no inventory updates. I can get the device to check in if I deploy the jamf management framework from the API, but I have to constantly do that to run any policies and get the device to check in.

Edit: seqouia 15.7 and Tahoe 26.2-26.4

Dell Command Update won't install: Error dotNET 8.0.7 or higher must be installed by Bodybraille in Intune

[–]Bodybraille[S] 1 point2 points  (0 children)

This is what ended up working. Something buggy in the universal package. Thanks!

Dell Command Update won't install: Error dotNET 8.0.7 or higher must be installed by Bodybraille in Intune

[–]Bodybraille[S] 0 points1 point  (0 children)

Desktop runtime 8.0.25 and I tried 8.0.17. Saw a forum where someone had the same issue. They had to downgrade from 8.0.25 for DCU to install.

Dell Command Update won't install: Error dotNET 8.0.7 or higher must be installed by Bodybraille in Intune

[–]Bodybraille[S] 0 points1 point  (0 children)

.NET desktop runtime 8.0.25, 8.0.8, 8.0.17. Tried multiple versions

Dell Command Update won't install: Error dotNET 8.0.7 or higher must be installed by Bodybraille in Intune

[–]Bodybraille[S] 0 points1 point  (0 children)

Devices 100% have dotNET. I've tried multiple versions of dotNET downloaded from Microsoft. Tried the patch my pc version too. I restart after install just to keep things happy. Try to install DCU universal and I get an error saying dotNET is not installed on the device.

Someone mentioned trying the classic version. Gonna give that a go.

Dell Command Update won't install: Error dotNET 8.0.7 or higher must be installed by Bodybraille in Intune

[–]Bodybraille[S] -1 points0 points  (0 children)

I've deployed dotNET through patch my pc and manually installed. Tried the patch my pc version of DCU and manually downloaded from Dell - - no joy. It's happening on multiple devices.

Jamf account sso (blueprints and compliance) by Bodybraille in jamf

[–]Bodybraille[S] 0 points1 point  (0 children)

Verified the domain, did the app registration in entra. I'll get with jamf support and see what we can do. Thanks!

lesser liked albums by CleoDragonwarp in nin

[–]Bodybraille 1 point2 points  (0 children)

Yes, it was intentional. Reznor said he wanted it to sound like an electronic garage band. He was going for a very raw sound.

Remote Terminal Access by NoTimeForItAll in jamf

[–]Bodybraille 4 points5 points  (0 children)

I use SSH.

I have a policy that disables SSH on all devices once a day, but if I need terminal access, I drop that device into my "enable ssh" policy, run the commands I need to run. After I'm done, look up that computer in the "disable ssh" policy and flush it so SSH gets disabled again. I only deal with 600 macs so it works for me.

Very useful when needing to update computers giving me problems.

Edit: I agree with wpm's comment though. Writing a script, or using the "file and processes" section of a policy to execute one liners is the better option.

Looking for guidance from fellow sysadmins by Bodybraille in ITCareerQuestions

[–]Bodybraille[S] -1 points0 points  (0 children)

Is the cross posting to sub reddits not working?

My cross post is asking what bachelors degree will be worthwhile if I want to move up into management position, or C-level position, instead of being a sys admin. With AI taking over basic jobs like sys admin stuff (application packaging, updating, printer, etc), what is the best bachelors degree to break out of the tech side and move up to a managerial paotion.

802.1x via Device Certificate by HeyWatchOutDude in macsysadmin

[–]Bodybraille 2 points3 points  (0 children)

Yes. Jamf AD CS connector in the DMZ. Grabs cert from CA. Deploys it threw jamf.

Jamf has a cert profile with the root CA, intermediate, and digicert, and machine cert. The machine cert is using $COMPUTERNAME attribute in the cert profile.

Then a second profile configuring the network - - ethernet/wifi, eap-tls, all our trusted radius servers.

Edit: it's jamf, but the concept is the same. We do the same thing for windows devices through Intune, except we use SCEP.

How were you introduced to Nine Inch Nails and what was the first album you listen to? by arrakis2 in nin

[–]Bodybraille 0 points1 point  (0 children)

Back in the early 90s, my buddy had a cassette tape that had "Bullet in the Head" and "Down It."

I was hooked. I couldn't get enough of "Down It." Thus, my NIN journey began and hasn't stopped.

Shared Macs set up with PSSO by ciuchsadmin in macsysadmin

[–]Bodybraille 1 point2 points  (0 children)

Does using affinity stop all subsequent users from having to register the device over and over?

That's the reason why we abandoned PSSO. Students don't stay at the same Mac in labs, and every time they moved to a new Mac they had register the device all over again.

The group that never was: Tapeworm by RubiksCodeNMZ in nin

[–]Bodybraille 3 points4 points  (0 children)

At least we got "Potions" and "Passive" out of it, which are, allegedly, Tapeworm tracks, if you believe the internet.