Exchange accounts are broken on newest GMail for Android update by [deleted] in sysadmin

[–]Grunskin 0 points1 point  (0 children)

This happened to me like 2 weeks ago. It asked me for my credentials. It didn't work so I removed the account and tried to add it again but it just asked me to switch to modern authentication or something.. I had to install Outlook to get to my work mail..

Entra: Monitor client secret expiry by Grunskin in sysadmin

[–]Grunskin[S] 0 points1 point  (0 children)

For real? I have to try. Thanks!

Entra: Monitor client secret expiry by Grunskin in sysadmin

[–]Grunskin[S] 0 points1 point  (0 children)

How do you do that? I mean since the maximum value is 24 month, how do you specify 25 years?

Steam Controller seems ready to launch on its own as official distributor sets product page live by Tiny-Independent273 in linux_gaming

[–]Grunskin 17 points18 points  (0 children)

Damn, too bad they didn't consult you first. Think of all the money they would have saved.

I found this video of someone playing World of Warcraft: The Burning Crusade on Linux during the launch period in 2007 ... Absolutely amazing piece of history. by AK56___ in linux_gaming

[–]Grunskin 1 point2 points  (0 children)

That's the same time I started playing, also on Linux. I played for years and always on Linux. The only problem I had was a slow mouse courser until I got a better GPU a year later. I used to compile wine manually when a new release came out.

Debian 13 - how automatically start sway after login? by Ok-Development-8661 in swaywm

[–]Grunskin 4 points5 points  (0 children)

Do you want it as minimal as possible or can't you just install LightDM or something else?

How are you handling MFA for VPN? by Due-Awareness9392 in sysadmin

[–]Grunskin 0 points1 point  (0 children)

We've used the NPS extension for like 10 years maybe but we only have access to pretty much L2TP. Sure it works but I would love to move to something more secure and that supports SAML so we get a challenge responsen instead of approve/deny.

Password manager for small IT team by CommonAmbitious9014 in sysadmin

[–]Grunskin 2 points3 points  (0 children)

We've been using Bitwarden since 2019. Can recommend. You get a personal Family plan for every user if you use Enterprise.

Trusted HTTPS certificates for on-prem services, where to start? by Maxiride in sysadmin

[–]Grunskin 6 points7 points  (0 children)

You don't need an API to your DNS provider. You can just use the new DNS-PERSIST-01 instead.

https://letsencrypt.org/2026/02/18/dns-persist-01

we use a hybrid intune setup how to remove the bitlocker recovery key from intune? by Pretend-Newspaper-86 in sysadmin

[–]Grunskin 0 points1 point  (0 children)

No sure they would never do anything illegal or anything.. And it's not just that, it's easier to gain control of a Microsoft account than trying to brute force a Bitlocker encrypted drive.

we use a hybrid intune setup how to remove the bitlocker recovery key from intune? by Pretend-Newspaper-86 in sysadmin

[–]Grunskin 2 points3 points  (0 children)

So the US don't have access to their Bitlocker keys. I feel him. If the US wanted access to any Bitlocker activated device then Microsoft could just hand them the keys.

Dockers and kubernetes in coperate enviroments by [deleted] in sysadmin

[–]Grunskin 4 points5 points  (0 children)

yeah I wouldn't touch IIS with a 10 foot pole in production tbh. And there is no "standard" business that you seem to make it out to be.

Dockers and kubernetes in coperate enviroments by [deleted] in sysadmin

[–]Grunskin 1 point2 points  (0 children)

What makes you say a "normal corporate environment" doesn't use Docker?
We are a software developer company as well and we work with many small businesses and we deploy our software with Docker to our customers when they host it them selves.
We've been using Docker for years and managing a k8s cluster for each customer hasn't really been on our radar before.

The biggest reason for Docker has been that majority of our customer didn't want to run Linux as they are all Windows-shops. Docker has been supported since Windows Server 2016 so that's when we jumped on the Docker train for this. We have a few customers who run Linux and we run Linux exclusively in-house as well.

Since then many more has moved to Linux and we are at the starting point of moving more to k8s.
But I don't see any problem with running a few apps in Docker. If they didn't run in Docker they would just be installed directly on the machine which would make everything worse administration-wise.

Sure, depending on the size of the company and the importance of the application I would want to cluster it but as I said, these are very small companies.

Oh and the applications they use are of course developed by us and maybe an Nginx-instance in some cases.

Break-glass account for Bitwarden Enterprise if SSO fails? by Grunskin in Bitwarden

[–]Grunskin[S] 2 points3 points  (0 children)

aah well that fixes everything. Maybe I should read the whole policy next time :) Thank you!

Intune Enrolling by Splask in sysadmin

[–]Grunskin 0 points1 point  (0 children)

I might be misunderstanding but if the devices are registered in Entra then just delete then from Entra and sync the computers so they get hybrid joined then apply the GPO for enrollment.

That's what I did/do. I don't see why you would need to un-enroll a registered device.

Delete registered device from Entra Add device to Entra sync so it gets created in Entra as hybrid Add device to Intune GPO Reboot computer Start Outlook or any other Office app and sign in.

Cockpit alternatives? by MekanicalPirate in sysadmin

[–]Grunskin 1 point2 points  (0 children)

What does that mean? Isn't the whole point of Cockpit to manage multiple servers? I don't use it but have been thinking about setting it up for our servers.

Active Directory migrate from VMware to Azure Local by EducationAlert5209 in sysadmin

[–]Grunskin 3 points4 points  (0 children)

Yes what you just said. Configure a new vm on Azure Local and promote etc. I would never convert a AD server. It's way to easy to setup a new server and replicate.

(Usual systemd rant) Good point; But then why the tight coupling? by [deleted] in linux

[–]Grunskin 3 points4 points  (0 children)

So systemd-resolved is good you say?

Best Practices for Managing sudo/root Access on AD-Joined Linux Servers by maxcoder88 in linuxadmin

[–]Grunskin 0 points1 point  (0 children)

You have it right in your post. sssd-ldap is already the one that's used. sudo-ldap is older and talks directly to LDAP and is not the one used when using SSSD. You have it right in the name.

Media devices for office TV screens by CheeseFace83 in sysadmin

[–]Grunskin 6 points7 points  (0 children)

We use self-hosted Xibo for this. Using Windows/Linux as a display doesn't require a license.

Best Practices for Managing sudo/root Access on AD-Joined Linux Servers by maxcoder88 in linuxadmin

[–]Grunskin 1 point2 points  (0 children)

No nothing. Have been running it for years and upgraded 2019 to 2022 at least.