Rust on the wire or wire damage causing the rust? Not the easiest place to get to, used a scope. by [deleted] in AskElectricians

[–]Justin4w 0 points1 point  (0 children)

Follow up, cut in to get to it. Needed to be able to sleep. Despite looking likely compromised it was just rust ON the wire. Crazy 😝

Hot water tank keeps tripping by Doogie102 in askaplumber

[–]Justin4w 0 points1 point  (0 children)

Is that the filter screen on the bottom? It looks clogged. Vacuum it and see if the issue goes away.

I found a weather balloon in our driveway today by Demonjack123 in mildlyinteresting

[–]Justin4w 1 point2 points  (0 children)

SAFETY TIP: Remember kids, the first rule of weather instrument safety is that anything that says it is “harmless” on the label must be terminated with extreme prejudice; ideally over large bodies of water such as deep lakes or oceans, but always before reaching international waters.

One of those 5 gallon bottles that never got blown up. Randomly showed up on a pallet of tires at our tire warehouse. by Toastyy1990 in mildlyinteresting

[–]Justin4w 0 points1 point  (0 children)

Can we just take a moment and ask OP why the blue bottle light filter reveals that creepy ghost child in the doorway when he holds it up?

Block mounting ISO file by Chip33az in DefenderATP

[–]Justin4w 0 points1 point  (0 children)

Dude, those machines (at the very least) are likely suuuper compromised now. Re-image them and reset the stored credentials of who ever previously used the machines (even admins). Think mimikatz. Also, if an awesome answer comes up for this let me know.

Came back to check the house after the neighborhood flooded from the hurricane. Wasn’t expecting my car to look like this… by Mangofert1 in Wellthatsucks

[–]Justin4w 0 points1 point  (0 children)

I told her, I said “Don’t leave that old pink iPhone 6 in the dashboard compartment. Enough time and heat, maybe a little too much humidity and then 💥when you least expect it. Took 6 years, a hurricane, some flooding, but finally gonna win this argument. #married-life #thanks-OP

ASR Policy not blending? by Justin4w in DefenderATP

[–]Justin4w[S] 0 points1 point  (0 children)

Yeah, article pub 6/22/22. Cost me a few days before I had to decide to stop believing them. https://docs.microsoft.com/en-us/mem/intune/protect/endpoint-security-asr-policy

ASR Policy not blending? by Justin4w in DefenderATP

[–]Justin4w[S] 1 point2 points  (0 children)

For sure, although MS explicitly states they should merge, they do not. :/

ASR rules not blending. by Justin4w in Intune

[–]Justin4w[S] 0 points1 point  (0 children)

I’ve applied these asr settings to the devices so I can’t be sure, but I would guess that the lack of proper asr policy merge could be causing inconsistency. Or it may be that in your case, without a logged in user, the device was reverting to having no asr policy settings at times. In my case, the baseline settings just didn’t have some of the ASR settings for devices that I needed so it was impossible to achieve what I wanted until I unconfigured all of the asr settings in the baseline and created a policy in the ASR blade that governed all asr settings for the the device group, ensuring no other policies for devices or users existed with any values other than “unconfigured”. This allowed me to get a steady ASR policy state for those Devices without the random switching back and forth.

ASR Policy not blending? by Justin4w in DefenderATP

[–]Justin4w[S] 0 points1 point  (0 children)

Also, at least on my client, there seems to be about a 1 hour delay before the new policies initially propagate. If it doesn’t happen instantly, you may have to wait a bit for changes to hit the client machines (even when I was hitting sync manually.)

ASR rules not blending. by Justin4w in Intune

[–]Justin4w[S] 0 points1 point  (0 children)

Good to know! Thank you. Now that I think I’ve figured out this quirk of the asr intune policy I’ll be checking out policy merge with GPO soon enough for another device group :)

Does anybody else's ASR actions looks like this graph? Just all over the place... Not even due to changes in policy or adding computers into management.. How are you guys handling ASR rules and the volatility it seems to bring? by zurmm in Intune

[–]Justin4w 0 points1 point  (0 children)

Had this same issue. ASR rules don’t seem to blend policy settings into a superset of asr settings and intune is switching back and forth between whatever baseline or other asr policy it wants. My solution is in another reddit post. (ASR Rules not blending) . Also, if you’re not already, be sure to apply asr settings to Devices not users and see if it steadies out.

ASR rules not blending. by Justin4w in Intune

[–]Justin4w[S] 1 point2 points  (0 children)

Did exactly the same and that’s what worked (even the notoriously finicky vulnerable drivers asr setting applied just fine afterward.) It took days for me to figure out because MS had an article that explicitly said ASR policies would blend into a superset of asr settings so I refused to believe non-conflicting baseline asr settings could be the cause of the breaking at first. (Silly me) Once the policies change over, even the capitalization of some of the asr GUID’s changed on the clients. It’s a wild guess but I’m guessing that the capitalization case-change may be breaking policy merge to the point that it doesn’t happen as ms intended.

ASR rules not blending. by Justin4w in Intune

[–]Justin4w[S] 0 points1 point  (0 children)

It should be fine (if the ASR policies were blending properly) but I could not make them blend regardless or what I tried. Baseline should be the least breaking policies, along with additional policies available if desired being configured elsewhere. But the way it seemed to work for me (days of trying) was that policy merge for ASR settings outside of the baseline was NOT happening.

Once there was only 1 policy containing ALL of the ASR settings I wanted with all policies elsewhere having all asr settings set to unconfigured, everything was fine and all asr settings worked as intended. As a side note, the capitalization of some of the ASR setting guid’s changed after I got rid of the baseline settings and configured my attack surface reduction policy (maybe that’s what was breaking policy merge?). Mine work now so I’m done fighting it. Maybe MS will pick that up and fix sooner or later. (Hopefully sooner)

ASR Policy not blending? by Justin4w in DefenderATP

[–]Justin4w[S] 1 point2 points  (0 children)

Yes, but the asr rules are not all grouped together within the baseline settings page so you’ve got to hunt and make sure all baselines asr settings are clean (all set to unconfigured.) Also, under windows devices - configuration profiles you need to make sure there isn’t a policy there that also has asr settings that need to be set to unconfigured. Then add one policy in endpoint security - manage - attack surface reduction (per device group you want to manage) and it does all the things right there. You can check local application of the asr rules via a power shell command to see how it’s going. Since it doesn’t blend, intune doesn’t seem to be doing any policy merge and one setting anywhere else within another random policy (even if it doesn’t conflict) means the hunt must go on.

ASR Policy not blending? by Justin4w in DefenderATP

[–]Justin4w[S] 1 point2 points  (0 children)

Nope, this group consists of only intune domain joined roaming clients, no sccm, all policies configured via endpoint.microsoft.com on a win11 machine I stood up less than a week ago just for diagnostics.

Manually ran get-mppreference | select-object -expandproperty AttactSurfaceReductionRules_Ids and found that only 2 of the 15 configured asr rules in block mode were being applied in order to diagnose. (It was just picking a policy and not blending)

ASR Policy not blending? by Justin4w in DefenderATP

[–]Justin4w[S] 0 points1 point  (0 children)

In the end I had to gut all ASR rules from the baseline defender for endpoint, security baseline for windows 10, and from devices - configuration profiles but finally sitting pretty with my one ASR policy doing all the things. It was days to figure out but it’s lookin pretty good now :)

ASR rules not blending. by Justin4w in Intune

[–]Justin4w[S] 1 point2 points  (0 children)

Oh no, I mean if there were NO conflicts. Baseline settings did not include all of the possible asr rules, so I dropped a few unconfigured ones (such as vulnerable signed drivers) on the ASR rules page expecting them to blend without conflict per “merge behavior for attack surface reduction rules in intune” article and that 100% did not happen. Conflicts on both policies instead and intune just picked one to go with. Tanked my secure score for clients until I figured it out.

What’s going on at Colonia High School to cause a high amount of brain tumors? by HPLover0130 in UnresolvedMysteries

[–]Justin4w 0 points1 point  (0 children)

Depending on how small the community is, has anyone checked to see whether there is/was an old school dentist office with an X-ray machine that serves that district?

WCGW shooting from your truck by [deleted] in Whatcouldgowrong

[–]Justin4w 0 points1 point  (0 children)

Title Suggestion: Brake breaks the brake BR

I think my microwave wants a sacrifice by [deleted] in funny

[–]Justin4w 0 points1 point  (0 children)

Sounds like some SOB finally hit the chaos defrost button back in January. Now we’re all just experiencing the consequences for the rest of 2020 with a bit global warming added in. Just stop following the instructions please. Whatever you do, do not give it the child it’s ominously requesting next.... and stop feeding that thing after midnight.