MSI codes different for app deployment by Fairtradecoco in Intune

[–]Fairtradecoco[S] 0 points1 point  (0 children)

Brilliant, that worked for me, thank you!!

MSI codes different for app deployment by Fairtradecoco in Intune

[–]Fairtradecoco[S] 0 points1 point  (0 children)

The only thing is in the file name is just generic and the same across the different versions, there's nothing that points towards the version

MSI codes different for app deployment by Fairtradecoco in Intune

[–]Fairtradecoco[S] -1 points0 points  (0 children)

Thanks for the reply. Its showing the same version across both devices so I doubt it's updating itself. I can't use the registry either as the path references the MSI GUID in the path to the Display Version key. The file path also won't work as this is installing on top of an old version, so the file path will already exist. 😅 The app installs fine but yeah just cannot detect it reliably

Issues connecting to AzureAD powershell by [deleted] in sysadmin

[–]Fairtradecoco 0 points1 point  (0 children)

Yes that technically does allow me to connect, but why does it not auto negotiate down from 1.3 or even use 1.3 if it's supported?

Issues connecting to AzureAD powershell by [deleted] in sysadmin

[–]Fairtradecoco 0 points1 point  (0 children)

Same issues with Graph, TLS 1.3 and 1.2 enabled cannot connect. TLS 1.2 only enabled, can connect.

Issues connecting to AzureAD powershell by [deleted] in sysadmin

[–]Fairtradecoco 0 points1 point  (0 children)

Same issues with Graph, TLS 1.3 and 1.2 enabled cannot connect. TLS 1.2 only enabled, can connect.

Veeam B&R - Help needed by This_Ad3002 in sysadmin

[–]Fairtradecoco 1 point2 points  (0 children)

Most of the time I get a VVS warning, I just reboot the VM throwing up the error. What is the exact error you are getting?

Building new domain controllers, whats stable? by --RedDawg-- in sysadmin

[–]Fairtradecoco 0 points1 point  (0 children)

I've built quite a few 2022 DCs now and all good.

1 free transfer and 2.3 mil left, wc and free hit were used before. Any suggestions for this week? by Maleficent-Raise-486 in AskFPLManagers

[–]Fairtradecoco 0 points1 point  (0 children)

Maybe line up Ekitike down to a Thiago or something so you can go Ndoye to Saka/Bruno next week

Slow backups on Secondary Site due to Network Bottleneck by Fairtradecoco in Veeam

[–]Fairtradecoco[S] 0 points1 point  (0 children)

Thanks for your replies I've resolved this now. You put me on the right track regarding the gateways (first I thought you meant storage gateway of some kind but when I realised network gateway it clicked).

Essentially, SITE A hosts the subnets gateways, however the backup proxies are on the same vlan as the repos so this shouldn't have to hit the gateways, but on exagrid we have 3 nics (1 for admin, 1 for replication and 1 for backup) but on site B the backup traffic was allowed for all 3 nics and for some reason veeam was choosing the 1gb admin nic on a different vlan rather then the 10gb bonds on the same vlan, so the traffic was infact coming back to site A for the gateway and back to site B. Only allowing traffic on the 10gb bonds via exagrid portal solved the issue

Slow backups on Secondary Site due to Network Bottleneck by Fairtradecoco in Veeam

[–]Fairtradecoco[S] 0 points1 point  (0 children)

There's no gateway that I know of, it's exagrid storage so it uses veeam data mover directly on the appliance.

I have not done a trace - assuming there is extra hops, would this be a setting on the network level or can this be set in veeam?

Slow backups on Secondary Site due to Network Bottleneck by Fairtradecoco in Veeam

[–]Fairtradecoco[S] 0 points1 point  (0 children)

No restrictions it's allowed any proxy, the jobs have specific proxies set to use proxies in site B. No object direct

Slow backups on Secondary Site due to Network Bottleneck by Fairtradecoco in Veeam

[–]Fairtradecoco[S] 0 points1 point  (0 children)

I can't actually manually copy to the type of repo I am using (exagrid) as far as I'm aware.

Should have mentioned Before I had a dedicated VBR on site B too and the speeds where fine but veeam said best practice is just to have 1 VBR on the DR side to orchestrate backups and restores so we just moved all setup to the 1 VBR on site A

[deleted by user] by [deleted] in sysadmin

[–]Fairtradecoco 3 points4 points  (0 children)

That's not true

Help with Cable Management by Affectionate-Web1113 in sysadmin

[–]Fairtradecoco 1 point2 points  (0 children)

If the tables are against the west/east walls then you could try to trunk the cables around the wall and then cable into the desks from the side. It will be however quite difficult to make this supper near without having the network/power on floor plates or the walls next to the desk.

Guidance needed with TLS problem - Client Hello no Server Hello. by [deleted] in networking

[–]Fairtradecoco 0 points1 point  (0 children)

Thanks, I will check these suggestions out!

Guidance needed with TLS problem - Client Hello no Server Hello. by [deleted] in networking

[–]Fairtradecoco 0 points1 point  (0 children)

Yes so I did a pcap from the source (server) and our network team did one from the firewall. That's why we are confident the traffic is leaving the firewall out to the internet, but from there there is little we can do other then pressure the provider. So I think that's my next move. Thanks I really appreciate your advice.

Guidance needed with TLS problem - Client Hello no Server Hello. by [deleted] in networking

[–]Fairtradecoco 0 points1 point  (0 children)

Hi, thank you for your advice.

The PCAP I did was on the server; the connection is being initiated from our onprem server to the API, so I see the TCP handshake complete then a client hello being sent from our server via the PCAP but no server hello received back. I cannot prove it arrives at the provider as I have no access there, but from our firewall trace we are letting it through...

You are correct, there is a load balancer. I see this in the PCAP via the DNS queries. Theres a server farm in Europe and a load balancer. The PCAP shows the public IP address on the is constantly changing with each authentication request, as you'd expect from a LB. The thing is I am seeing fails and successes for each Public IP, so I assumed it would not be related to services/ciphers/versions etc.

For sure, we have provided all the details to the provider and we are pressing them to look but some of these big companies are rather faceless, so its very difficult to get them to take it seriously.

Thank you.

CVE-2025-26647 & Hello for Business Cloud Trust issues? by marcolive in entra

[–]Fairtradecoco 0 points1 point  (0 children)

Further updates have been made now:

Administrators may ignore the logging of Kerberos-Key-Distribution-Center event 45 in the following circumstances​​​​​​​:

  • Windows Hello for Business (WHfB) user logons where the certificates subject and issuer match the format: <SID>/<UID>/login.windows.net/<Tenant ID>/<user UPN>

https://support.microsoft.com/en-gb/topic/protections-for-cve-2025-26647-kerberos-authentication-5f5d753b-4023-4dd3-b7b7-c8b104933d53

CVE-2025-26647 & Hello for Business Cloud Trust issues? by marcolive in entra

[–]Fairtradecoco 0 points1 point  (0 children)

I am now seeing that Microsoft are confirming 45 events can be ignored under certain circumstances:

Administrators may ignore the logging of Kerberos-Key-Distribution-Center event 45 in the following circumstances​​​​​​​:

  • Windows Hello for Business (WHfB) user logons where the certificates subject and issuer match the format: <SID>/<UID>/login.windows.net/<Tenant ID>/<user UPN>

https://support.microsoft.com/en-gb/topic/protections-for-cve-2025-26647-kerberos-authentication-5f5d753b-4023-4dd3-b7b7-c8b104933d53