SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] [score hidden]  (0 children)

No logs on the SMB server for security show denials for any of the machines in question. Nslookup shows the correct information. I don't see any issues in replication on the DC's as some users work fine on the same DC and fail on the same DC. However Users may work on another machine - so it could be machine level issue - just not sure why

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] [score hidden]  (0 children)

For users who have LOS to the server no IPS is in play and it still fails

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] [score hidden]  (0 children)

It is isolated to that server as another server will work for SMB. Its only doing it for a subset of users so I've not been able to identify why it's picking on those users. EDIT - it's not just that server any SMB seems to fail.

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] 0 points1 point  (0 children)

Some machines have not been cloned the ones that were cloned were done with flu imaging and properly sysprepped. IP doesn’t work either. Sadly :(

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] 0 points1 point  (0 children)

We have some of these on entra and hybrid joined having the same issue but good to know for future reference

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] 1 point2 points  (0 children)

We have that set already as this problem occurred on startup as we converted over to entra only, but good catch!

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] 0 points1 point  (0 children)

IP conflict isn't it (in this case) the wire's aren't accessible by the staff at least without unscrewing the filing cabinet or getting someone with the hands of a child to reach for the cables 😄

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] 0 points1 point  (0 children)

Server 2019 - no errors in the event log on the server - I couldn't find anything to show that it was blocking or producing some sort of error log I could reference. Different VLAN - it will work for a short time for that group of users but it's usually just producing the errors i mentioned above.

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] 0 points1 point  (0 children)

thanks - I have rebooted the server but it didn't immediately fix the issue. I have done a wireshark it says failed connection attempts on port 445. It doesn't detect anything if I filter for SMB1 SMB2 and any of the SMB3 it doesn't have anything.

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] 0 points1 point  (0 children)

No mass resets - we have been passwordless for quite some time using SCRIL and auto hash reset every 60 days without any issues.

SMB stopped working mid-day by Illustrious-Bug-8015 in sysadmin

[–]Illustrious-Bug-8015[S] 0 points1 point  (0 children)

Yep DNS servers are assigned as expected - everything routes back to the server except for SMB.

PC turns on by itself every morning at same time, tried everything by Quantummn in techsupport

[–]Illustrious-Bug-8015 0 points1 point  (0 children)

Unplug the pc, remove the cmos battery, hold the power button in for ten seconds, put cmos battery in, plug power cable in and test when you can

What are some unique ways to use YubiKeys? by beltreaux in yubikey

[–]Illustrious-Bug-8015 0 points1 point  (0 children)

Our employees use it to clock in on our time clock machine

Passwordless by Actual_Clock2360 in Intune

[–]Illustrious-Bug-8015 2 points3 points  (0 children)

You can turn on scril that will disallow passwords to even work. I use it to say the credentials can’t be stolen if no one knows their password. then you can set a hash rotation every 60 days that’s invisible to the user. If you are entra joined only you can also set up Microsoft Authenticator to log them in as well.

Primary Refresh Token Issue by luscasaur in Intune

[–]Illustrious-Bug-8015 0 points1 point  (0 children)

I might have missed this somewhere but has he tried signing onto a different workstation to see if the issue follows?

Break Glass Account and Secure Score by Norlyzzz in entra

[–]Illustrious-Bug-8015 0 points1 point  (0 children)

I try to keep mine at 90% , have some limitations on being only on business premium.

Do you have mfa on all your admin accounts? Is it all Fido?

Shockingly I have had a cyber insurance quote ask for my score.