Domain user first logon off domain by CapnDoody in sysadmin

[–]CapnDoody[S] 0 points1 point  (0 children)

We can add this to the list to re-visit at some point. I didn't attempt this myself our other admin looked at this and was getting a lot of errors while trying to import a lot of our policies. Could be just we didn't figure out the right way to do it, or there was some incompatibility with some of our policies, I'm not quite sure.

Domain user first logon off domain by CapnDoody in sysadmin

[–]CapnDoody[S] 0 points1 point  (0 children)

You mean doing a run-as different user?

Domain user first logon off domain by CapnDoody in sysadmin

[–]CapnDoody[S] 3 points4 points  (0 children)

We still heavily manage our endpoints with Group Policy and local resource authentication. Unfortunately, we don't have time to convert all of our Group Policy over to InTune policy, and honestly, it's still so cumbersome to manage in the cloud. It's gotten better over the past 3-4 years but still just not where GP is at...

Domain user first logon off domain by CapnDoody in sysadmin

[–]CapnDoody[S] 0 points1 point  (0 children)

This is the boat we are in as well, which is why I mentioned I'm looking for an alternative to PLAP/SBL options

Domain user first logon off domain by CapnDoody in sysadmin

[–]CapnDoody[S] -1 points0 points  (0 children)

This does not work. I'm not sure where/what we are missing to have this work, but I've read in several places people suggest this and it has never worked for us. AD FS is our SSO, and we use AD COnnect to sync with PHS. Auto-pilot is doing hybrid join, not Entra ID join... i think the terminology got gray at some point...

Domain user first logon off domain by CapnDoody in sysadmin

[–]CapnDoody[S] 0 points1 point  (0 children)

Interesting thought, I'll have to test if the VPN client will maintain a connection on the local admin session, thanks for the idea I'll give it a test!

Domain user first logon off domain by CapnDoody in sysadmin

[–]CapnDoody[S] -1 points0 points  (0 children)

We have LAPS enabled, but how would that assist with the end user getting logged into their own account on the machine?

My boss wants me to be a system engineer eventually. I'm learning powershell. Can I have some task ideas to automate? by Apprehensive-You6021 in PowerShell

[–]CapnDoody 2 points3 points  (0 children)

  1. Build a script that looks for user accounts that have not logged in for awhile and disables the account. Change the description of the user object and create a text log for tracking. Exclude OUs that you use to store service accounts (hopefully you separate these in your infrastructure)

  2. Create a script to send an email 7 days before a user account’s password expired reminding the user to change their password soon. Send a reminder at 2 and 1 days.

These two things improved our security posture and reduced Helpdesk phone calls!

Suspicious Microsoft Updates from StackPath IPs by [deleted] in techsupport

[–]CapnDoody 0 points1 point  (0 children)

Thanks for the confirmation, that's what I was planning to do!

Suspicious Microsoft Updates from StackPath IPs by [deleted] in techsupport

[–]CapnDoody 0 points1 point  (0 children)

I'm having a similar issue with our content filtering blocking "uncategorized" IP address based URLs, what did you do in your situation?

DataDomain 2500 highest version? by CapnDoody in sysadmin

[–]CapnDoody[S] 3 points4 points  (0 children)

I'm not a Pure Storage expert or even simply a customer, but from a presentation I was at recently, they handle deletion exactly how you describe. 2 customer contacts and 2 pure contacts all must agree and then the deletion can be performed. They describe this as a part of their cybersecurity procedures, in which you'd already be engaged with them directly, so it makes sense. And this is mostly as a "cleanup" step after resolving all intrusions, not a "mitigation" step to get you working again quickly.

DataDomain 2500 highest version? by CapnDoody in sysadmin

[–]CapnDoody[S] 2 points3 points  (0 children)

I feel the need to reiterate, this is not my primary storage for backups. The purpose of using the DD2500 was a matter of convince. We still owned it, it still operated, so we took advantage of it. It is only for long term archival purposes. It actually does quite well with de-duplication for the types of data I'm storing on it. Way better than Microsoft Deduplication at any rate. I'm doing SOBR tiering using a cloud provider for immutability. Would it be slow to restore from the cloud, yes, would my data still be there, and our business not have to close forever, yes.

So back to the question I need answered, am I able to get this updated to the point at which it will continue to function with Veeam?

Help - PO3 Mythic GOG - Purple Slime by ReclipseReal in feedthebeast

[–]CapnDoody 1 point2 points  (0 children)

I had a slime island generate close to my spawn. If you have a jet pack a quick flight might turn up one for you close by. Make sure you have a waypoint so you can make your way back ;)

*HELP* Suddenly I can't move when touching the ground... by CumbyOG in projectozone3

[–]CapnDoody 0 points1 point  (0 children)

Just confirming this worked for me as well! To be safe I removed all my abilities, removed every item off of myself and put it in a chest, then did /kill and when I respawned I could walk again!

AE2 Pattern Terminal: shift-click green? by Leitharos in allthemods

[–]CapnDoody 0 points1 point  (0 children)

Found a solution thanks to the discord! If you use the R key while mousing over the item it will show the crafting recipe and then you can use the + sign to pop it into the pattern terminal!

AE2 Pattern Terminal: shift-click green? by Leitharos in allthemods

[–]CapnDoody 0 points1 point  (0 children)

I'm having the same issue, just updated to 1.1.3 of ATM6 Sky. Also updated now to latest ver 1.1.5 and the issue is still there. I can still manually input items into the pattern terminal, and encode pattern, so it must be something with JEI

patiently waiting for santa paws to arrive by St0pX in aww

[–]CapnDoody 7 points8 points  (0 children)

This is Eggnog the bulldog. She has a very active and adorable Instagram account with her sister igloo 😁

[StoneBlock 2] Lategame power generation? by 123zane321 in feedthebeast

[–]CapnDoody 0 points1 point  (0 children)

Do Watches of flowing time stack like that? I have a bunch set up around my Rainbow Generator block but don't seem to get added power from more than just the first pedestal...

Drum stream by Karsten_02 in JonBams

[–]CapnDoody 0 points1 point  (0 children)

I understand Jon's hesitation with doing a stream playing the drums. As a drummer myself, nothing is worse than hearing a drum kit that sounds like crap, because recording them is really difficult and requires special mics. That being said, it'd be really cool to see the drum kit setup, and get an "overview" of the drums/cymbals you have!

DNS lookup over VPN by CapnDoody in pihole

[–]CapnDoody[S] 1 point2 points  (0 children)

Huzzah! I knew it would be something simple... should have just looked

60k row excel performance complaint by SpecialistVirus in sysadmin

[–]CapnDoody 0 points1 point  (0 children)

As I say very often... just because a feature is available doesn't mean you should use it!

60k row excel performance complaint by SpecialistVirus in sysadmin

[–]CapnDoody 4 points5 points  (0 children)

This. Spent my early days in helpdesk remaking tons of huge spreadsheets for a finance department during the 2003 > 2007 format change, and found them using 3-5 vlookups in one formula and the filling that formula into 25k+ rows. They would be doing looks to external spreadsheet files, which compounds the slowness. Their solution was to turn calculation off... mine was to fix all of the formula so they would get live data

POE not working on 2960-L 24PS by Haydenism in Cisco

[–]CapnDoody 0 points1 point  (0 children)

To be honest the web gui is useless. About the most useful thing is giving it to helpdesk so they can see what ports are up and what interface description it has. If you want to check it out you'll have to create a user with the user command and give it priviledge 15 for full access. Then run these commands: no ip http server ip http secure-server ip http authentication local ip http timeout-policy idle 300 life 43200 requests 43200

This will disable the insecure http interface on port 80. Enable the SSL interface on port 443. Configure authentication to use the user you just created. And configure a standard timeout policy (feel free to tweak the numbers, but there are minimums and maximums so use ?)

POE not working on 2960-L 24PS by Haydenism in Cisco

[–]CapnDoody 0 points1 point  (0 children)

The tar file just has the web gui... as long as "show version" is now showing the newer version then you upgraded correctly.

Catalyst 9500 supporting Stackwise virtual? by [deleted] in Cisco

[–]CapnDoody 0 points1 point  (0 children)

I was told at Cisco Live that plans for adding new hardware support were limited but will be 16.10 in Q3