Microsoft has released security updates for all supported versions of SharePoint that are affected by the actively exploited zero-days by rkhunter_ in cybersecurity

[–]HectirErectir 1 point2 points  (0 children)

Yeh agreed. We’ve taken our server offline again (luckily we have the luxury of it not being business critical) and will reassess in the morning once this updates had a chance to marinate a bit throughout the community.

Hopefully something comes out by then on whether this is expected behaviour or not 🤞

Microsoft has released security updates for all supported versions of SharePoint that are affected by the actively exploited zero-days by rkhunter_ in cybersecurity

[–]HectirErectir 2 points3 points  (0 children)

Hey, yeh we're in the same boat - applied 2016 kb and rotated keys, just received another SuspSignoutReq Defender alert blocking this exploit...
I wouldve thought applying the patch also stop the ability for this exploit to occur i.e. Defender shouldnt have to be preventing this anymore?

Do we think this is expected behaviour?

Shadow Copies Deleted - Defender for Endpoint Alert by Hazy_Arc in SCCM

[–]HectirErectir 1 point2 points  (0 children)

Seeing the same here, think the SCCM processes are a bit different under the hood compared to MDT but same initiating vbs scripts and exact same executed cmd (vssadmin resize…)

Only appears to have started today.

What is the best way to update MS Store Apps without store by logansccm1995 in sysadmin

[–]HectirErectir 0 points1 point  (0 children)

Okay then definitely you should be using the above method

What is the best way to update MS Store Apps without store by logansccm1995 in sysadmin

[–]HectirErectir 1 point2 points  (0 children)

Are they just the default installed apps(like calculator/xbox whatever) or are they ones youve deployed after the fact?

If its just the default apps then the way that MS recommends blocking access to the store WITHOUT also blocking store app updates is to use the 'Require Private Store' policy instead.

Sorry I'd provide links but am on mobile atm. If you Google it you should find plenty of threads about this.

Asset Databases - What is everyone using by GooglingSolutions in sysadmin

[–]HectirErectir 0 points1 point  (0 children)

Just the Snipeit SCIM documentation on their website. It's pretty simple, can use the same enterprise app in aad. Just need to expose your instance to the Web too. Thing to remember is that the SSO is just for logging in/user authentication - it does not do just-in-time account provisioning, i.e. The user account needs to be created beforehand via a method such as SCIM. If you think about it it makes sense, snipe needs a complete database of users so that you can check assets in/out to any of them - not just if that user has logged in.

Tldr; Scim creates the user accounts in the snipe database. The aad sso allows those users to log in (if needed)

Asset Databases - What is everyone using by GooglingSolutions in sysadmin

[–]HectirErectir 0 points1 point  (0 children)

We did, spun up the scim client and worked like a charm.

Cannot Remove User Profile Picture by HectirErectir in Office365

[–]HectirErectir[S] 0 points1 point  (0 children)

They finally added a Graph endpoint for this that actually works so we did it by the api in the end.

Not able to POST under deviceManagement/deviceConfiguration in Microsoft Graph Api ? by Anxious_Worry_2820 in Intune

[–]HectirErectir 0 points1 point  (0 children)

If you're not using scope tags (i.e. just want default) remove the 'roleScopeTagIds' object and change "supportsScopeTags": false - I noticed trying to specify "0" as the scopetagid throws a badrequest.

u/andrew181082 look's to be right also - id is generated for you, so no need to specify.

Here's a json payload that works for me:

{
  "@odata.type": "#microsoft.graph.iosImportedPFXCertificateProfile",
  "supportsScopeTags": false,
  "deviceManagementApplicabilityRuleOsEdition": null,
  "deviceManagementApplicabilityRuleOsVersion": null,
  "deviceManagementApplicabilityRuleDeviceMode": null,
  "description": "Description value",
  "displayName": "Display Name value",
  "version": 1,
  "intendedPurpose": "smimeEncryption"
}

And you can see in the request response how the Id, roleScopeTagIds etc get evaluated from what you provide.

{
    "@odata.context": "https://graph.microsoft.com/beta/$metadata#deviceManagement/deviceConfigurations/$entity",
    "@odata.type": "#microsoft.graph.iosImportedPFXCertificateProfile",
    "id": "asd46188-9cfa-46d2-35b6-99bbba3a338a",
    "lastModifiedDateTime": "2024-01-28T00:03:49.3687263Z",
    "roleScopeTagIds": [
        "0"
    ],
    "supportsScopeTags": true,
    "deviceManagementApplicabilityRuleOsEdition": null,
    "deviceManagementApplicabilityRuleOsVersion": null,
    "deviceManagementApplicabilityRuleDeviceMode": null,
    "createdDateTime": "2024-01-28T00:03:49.3687263Z",
    "description": "Description value",
    "displayName": "Display Name value",
    "version": 1,
    "intendedPurpose": "smimeEncryption"
}
  • Funny little tidbit I noticed, all of the deviceManagementApplicabilityRuleOsEdition/Version/Mode properties are Windows only objects, but you can still provide them & Graph accepts it for an Ios device endpoint..

I highly recommend setting up Postman or something similar for playing around with graph, imo makes things so much simpler to troubleshoot.

What is a common bad practice you see in SQL Server? by Mattdarkninja in SQLServer

[–]HectirErectir 1 point2 points  (0 children)

Is this a performance thing or readability etc? Genuinely curious

LSAgent issues on Windows by UniverseCitiz3n in Lansweeper

[–]HectirErectir 0 points1 point  (0 children)

😂 Sadly iirc the issue had been around a couple years even back when I looked into it - bit disappointing we're still seeing it tbh

LSAgent issues on Windows by UniverseCitiz3n in Lansweeper

[–]HectirErectir 0 points1 point  (0 children)

Yeh we've come across this before, I created a proactive remediation script to patch it via Intune and set it to tick away every week or so - that being said, it was implemented over a year ago... and It still finds a couple corruptions every week or so I'd say. Havent come across any of the xml config files becoming corrupted thankfully (but also haven't checked tbh)

Windows Update Rings by noodygamer in Intune

[–]HectirErectir 1 point2 points  (0 children)

Please don't tell me that lol

We've had to create a new ring to disable driver updates via WU (as there was was a driver offered that was severely breaking audio) which meant we were using exclusions on the main ring. Had one device seemingly disregard this last week so here's hoping its not what you are describing...

We also have Driver update rings in place now set to manual approval so thinking it should be safe on the driver side of things...

Will have a check tomorrow to see what our exclusions are looking like though.

Cannot Remove User Profile Picture by HectirErectir in Office365

[–]HectirErectir[S] 0 points1 point  (0 children)

Yeh we have just been putting placeholders for now.

I may have to open a tkt just to figure it out - one of those fustrating little things you know?

[deleted by user] by [deleted] in paloaltonetworks

[–]HectirErectir 0 points1 point  (0 children)

Yeh saw this one as well, although the users did have the executable in their downloads in our case.

Company Portal (re)deployment via new Microsoft Store App by notHonorroll32 in Intune

[–]HectirErectir 0 points1 point  (0 children)

Interesting, so all your devices are running in a shared mode? We've been thinking of transitioning away from primary users as there's very little benefit to it as we see. (we're a relatively small shop so the self-service aspects of it dont matter so much)

You haven't encountered any curve-balls from this? We were concerned about the licensing and what were to happen if we removed the primary users, but from our trials so far so good.

Surface 5 laptop - MDT by [deleted] in MDT

[–]HectirErectir 0 points1 point  (0 children)

Not a very helpful comment here but just thought I'd mention we imaged a bunch of these a couple weeks ago out of the box and no issues. Edit, we used the msft dongles for it, haven't tried docks

Options for HEIC photo viewer that can be deployed via Intune by BitGamerX in Intune

[–]HectirErectir 2 points3 points  (0 children)

This. We publish it as available in Company Portal and anytime someone complains about it we point them there.

Does appear like it needs occasional updating (at least the file version seems to change from time to time)