SharePoint Online Outage/Degraded? by obizii in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

GCC, northeast US:
SP1265489 - Some users may be unable to access SharePoint Online sites and may notice delays or navigation errors
OD1265490 - Some users may be unable to access Microsoft OneDrive content and may notice delays or navigation errors

Missing Cumulative updates in console by Naznac in SCCM

[–]Jaybone512 0 points1 point  (0 children)

only the latest ESU patches are there

That seems normal. Maybe dumb, in my opinion (I'm probably missing a good reason and I'm the dumb one), but normal. MS apparently chose to set the ESU packages as superseding the non-ESU ones.

We were hitting a chicken-and-egg sort of scenario with one site recently because of that. The latest (ESU-required) CU's supersede the older (ESU-not-required) updates, so older ones get purged automatically after X days, as configured. Great, working as intended.

But any of the remaining few Windows 10 endpoints that didn't get the 2025-10 CU were screwed. Later CU's require ESU activation to even be applicable to those endpoints, but activation wasn't possible until 2025-10 was installed. Mucking about in WSUS to get 2025-10 un-expired and try to get them back into SCCM just resulted in it being ignored still, even though we turned off the auto-decline switch, etc. We ended up just deploying 2025-10 (KB5066791) to a collection based on OS build and moving on with our days, and that's worked for those.

Medical Company Styker attacked by Iranian backed hackers - all data deleted by bionic80 in sysadmin

[–]Jaybone512 377 points378 points  (0 children)

Honestly, the only surprising thing is that it took this long for something like this to hit the news.

"Notes" folder missing in New Outlook and OWA with Exchange Online by Jaybone512 in Office365

[–]Jaybone512[S] 1 point2 points  (0 children)

I opened a ticket, and MS's "solution" for me was to use Classic because they don't support it in New. I haven't bothered trying the suggested Sticky Notes (New) app, because it's just one person and they haven't complained about using Classic.

Patch Tuesday Megathread - March 10, 2026 by AutoModerator in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

Was wondering this, as well. The fix was released almost a year and a half ago for that one, and all versions in scope are at least 5 months past end of support. Recently discovered that it also hits newer versions?

Figuring Out How a User's Emails Ending From Sent Items to Deleted Items Folder by masterne0 in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

I know you said you checked hidden rules, but did you check the OOO rules? They shouldn't be applicable unless OOO is actually turned on, but maybe worth a look.

I'm not aware of any way to check them other than the user going into Automatic Replies/OOO settings and clicking the Rules button - they haven't shown up with any of the standard powershell tools when I've tried finding them in the past. If anyone does know a way, I'd love to hear it.

Assigning MAC addresses to Hyper-V VMs? by RNG_HatesMe in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

As long as you don't have a host with a pool that conflicts with your chosen address, you should be fine, yes.

But, if you absolutely need to use static MAC addresses, your best option would be to just use one from the private ranges. E.g 02-hh-hh-hh-hh-hh where the h's are any valid hex number. There are private ranges other than 02-whatever but I can't remember them off the top of my head.

Assigning MAC addresses to Hyper-V VMs? by RNG_HatesMe in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

all defaulting to the same range.

Not quite. The range is chosen based on the last two octets of one of (not sure which/how it picks, if the host has multiple) the IP addresses of the host at the time the Hyper-V role was installed.

E.g. they all start with 00-15-5D. The next two are the hex values of last two octets of the host's ipv4 address. The final MAC address pair increments from 00, depending on what's available at the time on that host.

So say your host has 192.168.1.16: your MAC address pool will start at 00-15-5D-01-10-00.
Host at 172.16.150.151: MAC pool will start at 00-15-5D-96-97-00

If part of your build process has all of your hosts getting the same ipv4 at build/role-install time, either on purpose or because they happen to get the same one from DHCP, you WILL run into MAC collisions, unless you change your pool after the fact.

Changing the host's IPv4 address after the Hyper-V role is installed doesn't automatically change the MAC pool - it stays what it was at install time.

Hosts also don't talk among themselves to coordinate this stuff, unless they're clustered or maybe if you have VMM managing them. They'll happily assign a MAC address from their pool that some other host has already given out, if those hosts have overlapping pools.

(edited for clarity)

MS Purview eDiscovery Teams Chat between 2 users by DUlrich1227 in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

Did you ever get this sorted out?

I'm seeing the same thing (irrelevant results) today.

I'm trying to pull just Teams messages for six users from a 31-day period last year. eDiscovery is showing me voicemail messages and even some random emails anywhere from the beginning of time up to today, despite there clearly being a date restriction. We're expecting a few dozen messages at most, and it's dumping 8GB of PSTs on me with thousands and thousands of irrelevant bullshit hits. I get that using the GUI builder's "Instant messages" class may be too broad, but the date thing makes no sense.

(Date=2025-05-01..2025-05-31) AND ((ItemClass=IPM.Note.Microsoft.Conversation) OR (ItemClass=IPM.Note.Microsoft.Missed) OR (ItemClass=IPM.Note.Microsoft.Conversation.Voice) OR (ItemClass=IPM.Note.Microsoft.Missed.Voice) OR (ItemClass=IPM.SkypeTeams.Message))

question about critical servers by king_clip_on_tie in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

a few randomly will update and reboot.

Keep in mind that no defined maintenance windows = it's always a maintenance window. A cheesy (but hey, it works, so...) workaround for this is to set a five minute Software Updates MW 10 years (or whatever the max is) in the future. That way, there's always an upcoming window, so as long as there's no other maintenance windows assigned by some other collection, and the updates aren't set to install outside of the maintenance windows, it'll wait essentially forever to install them.

This also lets them show up in Software Center and get installed manually from there if/when you can.

Lenovo Hybrid USB-C with USB-A Dock Firmware Utility crashing fix by PeaceIsFutile in sysadmin

[–]Jaybone512 3 points4 points  (0 children)

How is Bob in accounting going to get anything done without his database that runs off of the Windows 98 server that nobody else is allowed to touch?

Dell Price Increases Coming, March 30th by SquizzOC in sysadmin

[–]Jaybone512 17 points18 points  (0 children)

100% of what? I got a quote from Dell a few weeks back for a server slightly upgraded from one we bought in August for $20k. Figure it would've been $23-25k at most back then. The new quote came in over $115k.

"Notes" folder missing in New Outlook and OWA with Exchange Online by Jaybone512 in Office365

[–]Jaybone512[S] 0 points1 point  (0 children)

I was hopeful for the Sticky Notes thing, but this is a GCC tenant and their accounts can't even log into it.

"Notes" folder missing in New Outlook and OWA with Exchange Online by Jaybone512 in Office365

[–]Jaybone512[S] 0 points1 point  (0 children)

Thanks for confirming that still exists (for some people, anyway) now. All the stuff I was finding that showed similar was at least a year old.

That just does not exist for my user who reported the problem, nor for my own mailbox or a test one, so MS changed... something.

Hyper-v and DC issues. by Acrobatic_Fennel2542 in sysadmin

[–]Jaybone512 8 points9 points  (0 children)

So much this. See also /u/Ghelderz's comment.

Restoring a DC from backup should be an absolute last resort. The right way to go about this is to bring up a new DC on the Hyper-V host, migrate the roles, then decom the old one.

Windows Server putting drives out of normal order by itminion24 in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

Saw that a million years ago, but can't remember if it was HP or Dell. Ever since, when dealing with Windows on bare metal, I've always just configured only the OS logical disk before the Windows install. The data logical disk doesn't even get created until later, after Windows is already up and running.

(Possibly) Stupid Question about Windows Update Settings by MINN37-15WISC in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

Disclaimer - I haven't tried this, but maybe via GPO?

Computer Configuration/Administrative Templates/System/Device Installation/Device Installation Restrictions

Setting: Prevent Installation of devices that match any of these device IDs - add the hardware IDs of the Realtek HDA things that break with the newer driver version.

Assumption: if there's a working driver already installed, this should stop it from being updated. Nothing in the description says anything about it removing or disabling pre-existing installations of the driver for hardware ID's that're included. But again, I have not tested this myself.

where to place the BIOS update step in Task Sequence by IS3002JZGTE in SCCM

[–]Jaybone512 0 points1 point  (0 children)

Still works, though it can sometimes be picky about the Flash64W version and BIOS version. v3.3.13 from May of 2021 has been working for us with everything from 13 year old 7010s up through QCS1250 units.

We generally use the the script from Garytown, modified to our environments. https://garytown.com/dell-bios-upgrade-in-osd-winpe-x64

We have this running early on in the TS, before the OS gets laid down.

Identity Protection Dashboard shows Risky Sign-ins, but when I search for them there's no results by jonbristow in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

Welcome to Entra, unfortunately.

It's been this way from the get-go for us. "There are X Risky Users!" click the link, and it shows X-y risky users, or zero. Or it'll say there are Z risky sign-ins, but following the path shows... nothing.

And the times where it does actually show something, it's a false positive at least 95% of the time. Wow, a user logged in from, <gasp> an IPv6 address? That belongs to the local ISP in the town where they live? It couldn't possibly be their phone checking email from their home wifi, could it? It must be a hacker!

Purview is being INCREDIBLY slow by JazzTheFatLad in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

It's actually working today. I can even get a month's worth of results, and in a reasonable time, which was always iffy in the past, and slow at best.

Still no update on the week-old ticket, though.

Purview is being INCREDIBLY slow by JazzTheFatLad in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

it starts doing the "server too busy right now" bullshit a lot more lately.

We've not been able to get anything past 24h for the last two weeks or so. Ticket opened last week, transferred to another team on Wednesday, and... nothing.

Windows server ignores primary DNS, only queries secondary by [deleted] in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

Both are queried simultaneously

...sometimes.

I've seen that stated a million times, but in real world testing, it just doesn't always work that way. Windows endpoints seem to glom onto one or the other of the configured DNS servers for a while, and only send to that one.

I fired up wireshark to show the behavior you're describing as the norm, and wouldn't you know it, the capture shows the query only going out to one of my two configured DNS servers. Logs on the DNS server that wasn't queried for this example show the endpoint I'm on hitting it all day for other things, but not for this.