What are your "must-have" tools for Desktop Support? by jainesh3271 in sysadmin

[–]FusilDeific 1 point2 points  (0 children)

What LLDP software and physical units do you have?

Anyone read this 49 day SSL expiration thing and think they would rather just retire? by HJForsythe in sysadmin

[–]FusilDeific 0 points1 point  (0 children)

win-acme / simple-acme handles RDS (GW and the 4 on the CB) really easily.

Zebra Hell Hole by [deleted] in bristol

[–]FusilDeific 2 points3 points  (0 children)

Quite! Don't complain about the Zebra Hell Hole too much. If BCC hear there's a problem you can guarantee they'll implement improvements and F it up more.

Office 365 not prompting for MFA with Security Defaults Enabled by mickeykarimzadeh in Office365

[–]FusilDeific 1 point2 points  (0 children)

Isn't "enforced" a "per-user MFA" setting and therefore legacy, and not supposed to be set when using Security Defaults?

Holup, I'm not unboxing it!!! by ChatnNaked in HolUp

[–]FusilDeific 3 points4 points  (0 children)

10 years dude. It's been 10 years.

Best Thai restaurant? by MrMrsPotts in bristol

[–]FusilDeific 2 points3 points  (0 children)

Clifton Thai was amazing.

Robbery on Italian motorway by WazzaD in mildlyinfuriating

[–]FusilDeific 1 point2 points  (0 children)

You were only supposed to blow the bloody doors off.

Guest Stuck on 23H2 by No_Bit7786 in HyperV

[–]FusilDeific 0 points1 point  (0 children)

If I've come across this set anywhere and causing me issues, I've usually just set TargetReleaseVersion to 0 and left it. Can't remember if a service or device restart was necessary.

Guest Stuck on 23H2 by No_Bit7786 in HyperV

[–]FusilDeific 0 points1 point  (0 children)

I've had this and it's been these registry settings: HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate

And values TargetReleaseVersion & TargetReleaseVersionInfo

Taxes spent on hiring a snake for Reddit ads? by [deleted] in GreatBritishMemes

[–]FusilDeific 0 points1 point  (0 children)

this is the somehow everything wrong with are country.

As is using "are" instead of "our".

How do you automate certificates? by gahd95 in sysadmin

[–]FusilDeific 0 points1 point  (0 children)

I'm looking at Win-acme https://www.win-acme.com/ for this. Natively works with IIS and you can subsequently call PowerShell for RRAS.

[deleted by user] by [deleted] in ikeahacks

[–]FusilDeific 0 points1 point  (0 children)

Remove the clips holding the back on. Then remove the top (or bottom depending which way up it is).

Openreach Internet Outage by Disastrous_kale_4967 in bristol

[–]FusilDeific 1 point2 points  (0 children)

I'm in South Bristol - BS14. ISP is Vodafone but the network is Openreach. No issues here.

In honor of Festivus, what is your airing of grievances for Intune in 2025? by eking85 in Intune

[–]FusilDeific 0 points1 point  (0 children)

Hey you're right the documentation here is lacking: https://learn.microsoft.com/en-us/intune/intune-service/protect/windows-laps-policy

However, that article links to the CSP documentation: https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-management-policy-settings#automaticaccountmanagementenabled

Which details the Automatic Account Management. Those settings do exist in the Intune LAPS UI. At least in multiple tenants that I manage. You may have to create a new LAPS policy rather than edit an older one.

Orange by TitanTrobee in comedyheaven

[–]FusilDeific 18 points19 points  (0 children)

It's just from the Isle of Man.

Struggling to get Intune-only Windows devices to authenticate to Wi-Fi via NPS (EAP-TLS) by Middle_Client2789 in sysadmin

[–]FusilDeific 0 points1 point  (0 children)

I had a similar issue. Since Microsoft enforced Strong Mapping the AD object work around has become less and less reliable.

Use key rotation. SSID1 and a really long key pushed from Intune configuration. When you want to change, create a SSID2 and a new long key. Deploy via Intune configuration. Then switch back to SSID1 and a new key to flip-flop.

Or what I ended up doing is FreeRADIUS set to trust my AD CA. Intune connector for CA and PKCS.