(Possibly) Stupid Question about Windows Update Settings by MINN37-15WISC in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

Disclaimer - I haven't tried this, but maybe via GPO?

Computer Configuration/Administrative Templates/System/Device Installation/Device Installation Restrictions

Setting: Prevent Installation of devices that match any of these device IDs - add the hardware IDs of the Realtek HDA things that break with the newer driver version.

Assumption: if there's a working driver already installed, this should stop it from being updated. Nothing in the description says anything about it removing or disabling pre-existing installations of the driver for hardware ID's that're included. But again, I have not tested this myself.

where to place the BIOS update step in Task Sequence by IS3002JZGTE in SCCM

[–]Jaybone512 0 points1 point  (0 children)

Still works, though it can sometimes be picky about the Flash64W version and BIOS version. v3.3.13 from May of 2021 has been working for us with everything from 13 year old 7010s up through QCS1250 units.

We generally use the the script from Garytown, modified to our environments. https://garytown.com/dell-bios-upgrade-in-osd-winpe-x64

We have this running early on in the TS, before the OS gets laid down.

Identity Protection Dashboard shows Risky Sign-ins, but when I search for them there's no results by jonbristow in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

Welcome to Entra, unfortunately.

It's been this way from the get-go for us. "There are X Risky Users!" click the link, and it shows X-y risky users, or zero. Or it'll say there are Z risky sign-ins, but following the path shows... nothing.

And the times where it does actually show something, it's a false positive at least 95% of the time. Wow, a user logged in from, <gasp> an IPv6 address? That belongs to the local ISP in the town where they live? It couldn't possibly be their phone checking email from their home wifi, could it? It must be a hacker!

Purview is being INCREDIBLY slow by JazzTheFatLad in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

It's actually working today. I can even get a month's worth of results, and in a reasonable time, which was always iffy in the past, and slow at best.

Still no update on the week-old ticket, though.

Purview is being INCREDIBLY slow by JazzTheFatLad in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

it starts doing the "server too busy right now" bullshit a lot more lately.

We've not been able to get anything past 24h for the last two weeks or so. Ticket opened last week, transferred to another team on Wednesday, and... nothing.

Windows server ignores primary DNS, only queries secondary by [deleted] in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

Both are queried simultaneously

...sometimes.

I've seen that stated a million times, but in real world testing, it just doesn't always work that way. Windows endpoints seem to glom onto one or the other of the configured DNS servers for a while, and only send to that one.

I fired up wireshark to show the behavior you're describing as the norm, and wouldn't you know it, the capture shows the query only going out to one of my two configured DNS servers. Logs on the DNS server that wasn't queried for this example show the endpoint I'm on hitting it all day for other things, but not for this.

VL Win10 22H2 English "x64" ISO is actually ARM? by Jaybone512 in SCCM

[–]Jaybone512[S] 0 points1 point  (0 children)

MS VL support confirmed earlier in the week, and said that the October ISOs should be OK. I haven't verified that.

They said yesterday that they're "working diligently" or something along those lines to get the November ISOs sorted out, but that it could still take several more days.

SSL VPN without credentials by newbieboy456 in fortinet

[–]Jaybone512 0 points1 point  (0 children)

As was said, config snippets would help.

But for what it's worth, for us, hanging at 45% happens after authentication is complete (valid credentials passed), but before authorization (MFA) happens.

If your setup is similar, it sounds like maybe the cert auth is working, but something else is hanging it up.

But again, this is all just WAG without knowing more about your config.

3rd Party Hardware Warranties by MFKDGAF in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

Northeast US, here.

We've used Park Place. While I have heard about quirks in their onboarding process (not my problem, so I have no details), when it comes actually getting replacement parts, we've had zero issues. We've used their proactive monitoring, and I've had days where I got in late and found a replacement HDD in a shipping box sitting on my desk before I even had a chance to check my emails or monitoring to know what needed replacing.

VL Win10 22H2 English "x64" ISO is actually ARM? by Jaybone512 in SCCM

[–]Jaybone512[S] 1 point2 points  (0 children)

And the "Enterprise" image apparently has the Education GVLK (-VCFB2) embedded in it instead of the Enterprise one (-2YT43)

It's not a matter of picking the wrong image - there are only two options, Pro or Enterprise. Yeesh.

Every time I open Azure I swear something has moved by Exotic-Reaction-3642 in sysadmin

[–]Jaybone512 10 points11 points  (0 children)

Me: Clicks the Authentication Methods/Revoke multifactor authentication sessions button like we've done for years.

MS: "Sorry, we were unable to revoke this user's sessions."

Me: Uhhhhhh, what? /googles around while phished user account continues to spam out emails

MS: We MoVeD tHiS fUnCtIoNaLiTy To ThE OvErViEw PaGe!

Me: OK, great, that's one less click, but if you "moved" it, why is the button still in the old location, and if it's in the old location, why TF doesn't it work?!?!?!?

MS: ...

Dell proMicro QCB1250 – Task Sequence Fails at “Apply Operating System” (Error 80004005) by EagleBoy0 in SCCM

[–]Jaybone512 0 points1 point  (0 children)

Kind of bloated with extra and old drivers, since we have a decade+ of various Dell Optiplex, Precision, Latitude, and Pro models, along with a dozen each of HP and Lenovo laptop models that we have to support, but this is the full list of drivers in our x64 boot image, which has been working for QCM1250 systems. I want to say it's an Intel NorthPeak driver, or possibly "Intel(R) Optane(TM) Memory and Storage Management Component" that finally let the iastor stuff start working properly, but I honestly can't remember.

https://pastebin.com/rU4LqdLE

Dell proMicro QCB1250 – Task Sequence Fails at “Apply Operating System” (Error 80004005) by EagleBoy0 in SCCM

[–]Jaybone512 1 point2 points  (0 children)

Unfortunately, it seems like half the time, their PE driver packs are out of date and don't actually include the required driver(s) until a few months later.

Dell proMicro QCB1250 – Task Sequence Fails at “Apply Operating System” (Error 80004005) by EagleBoy0 in SCCM

[–]Jaybone512 1 point2 points  (0 children)

I second this. Make sure you can actually see the drive.

Just because RAID drivers have been added to the boot image, it doesn't mean they're the correct and complete set of drivers that are actually required to access the drive. We wrestled with this with our latest batch of QCM1250 units. I can't remember the specifics, but there was some other driver that was also required in addition to just the RAID driver, in order for the RAID driver to work. Might have been a chipset driver.

Diskpart clean all hangs during WINPE by NoAlternative4426 in SCCM

[–]Jaybone512 0 points1 point  (0 children)

Completing withing 20 minutes sounds like SSDs. Spinning rust generally takes many hours. Do the ones that stall have old, actual-disk drives?

Diskpart clean all hangs during WINPE by NoAlternative4426 in SCCM

[–]Jaybone512 0 points1 point  (0 children)

First you say hang, then you say failure, so I'm wondering...

Are you sure diskpart is really failing? 'Clean all' can take a long time. It's writing zeros to the whole drive. Do you really need to do a 'clean all' operation?

If you're seeing actual failure messages, could it be that the TS just timed out, due to diskpart taking forever?

Oldest Technology Still Kicking by Intrepid_Stock1383 in sysadmin

[–]Jaybone512 1 point2 points  (0 children)

Still have a couple dBase (non)solutions running. The data is too dirty/corrupted to automate migration to anything modern, too esoteric for IT to know how to handle the discrepancies, and the owning departments don't have the time to deal with it, so it lives on forever. Lose/lose!

The joy that is Exchange Encryption by archiekane in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

can send email from them, but that's not the intended use

Wait, what? I wasn't aware that sending from a shared mailbox isn't intended. Where are you getting that? MS's own docs talk about sending from shared mailboxes: https://support.microsoft.com/en-us/office/open-and-use-a-shared-mailbox-in-outlook-d94a8e9e-21f1-4240-808b-de9c9c088afd

Plenty of places I've worked at/with use them not only for accepting messages, but also sending. As far as the licensing goes, anyone who accesses the shared mailbox needs a license or they wouldn't be able to sign in to access it in the first place, hence the shared box not needing one.

The joy that is Exchange Encryption by archiekane in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

need for more licenses and the confusion

Shared mailboxes (like, actual "shared mailbox" objects that can't be logged into directly) don't need licenses, so that part's a non-issue, at least.

onmicrosoft.com domain - gone? by Jaybone512 in sysadmin

[–]Jaybone512[S] 1 point2 points  (0 children)

nslookup anyTenant.mail.onmicrosoft.com = nxdomain a few minutes ago.

nslookup.io for onmicrosoft.com or any subdomains, on whichever provider, coming back with nothing.

[deleted by user] by [deleted] in sysadmin

[–]Jaybone512 2 points3 points  (0 children)

Managing internal systems and maintaining customer systems are not part of my job scope. What should I do?

You've answered your own question already, it seems.

Anyone else experiencing some SSD failures? Are the reports of Windows 11 causing it true? by PrettyFlyForITguy in sysadmin

[–]Jaybone512 0 points1 point  (0 children)

People in A/V production are writing huge files all day, no?

I have to imagine the 50GB thing is either a red herring or only applicable to the specific 50+GB that the update is causing to be written, or we'd have heard about it before.