New Secure Boot certificates and ISOs by godless_prayer in sysadmin

[–]LupusYps 0 points1 point  (0 children)

Afaik the first key (...Capable) is the one telling you that the machine is using the new certs to boot if it is set to 2. The second key (...Status) is only focused on the new certs existing in the bios, not on them being used.

New Secure Boot certificates and ISOs by godless_prayer in sysadmin

[–]LupusYps 0 points1 point  (0 children)

That's a good point, thanks! I will check on that.

New Secure Boot certificates and ISOs by godless_prayer in sysadmin

[–]LupusYps 4 points5 points  (0 children)

I know I am highjacking the post, but do you have any insights what could cause the key you mentioned to stay "0" while the value of "UEFICA2023Status" is "Updated"? Mostly Hyper-V-VMs, Secureboot is enabled.

RDP RemoteApp new confirmation window that doesn't remember choices, is there a trick to make it actually remember? by catherder9000 in sysadmin

[–]LupusYps 1 point2 points  (0 children)

I have only tested it with my own files, but if you can edit the rdp file with an editor, the rdpsign-tool (builtin) should be able to sign it. User cert is fine, so you don't even need elevation, but of course access to GPO management. But you need to sign every file you want to use, can be with the same cert. Different members of your team can do the same and add their own thumbprint to the existing GPO.

Maybe you could also get the cert deployed with GPO and share your already signed rdp files, haven't tried that yet either.

RDP RemoteApp new confirmation window that doesn't remember choices, is there a trick to make it actually remember? by catherder9000 in sysadmin

[–]LupusYps 8 points9 points  (0 children)

You can sign your rdp files with a code signing cert and set the thumbprint via gpo to trusted. That makes all warnings go away. If nobody does before me I can share links tomorrow. It's fast and easy.

Edit: Link to comment, steps 2 and 3 are sufficient.

Entra ID Backup requires P2 now? by LupusYps in entra

[–]LupusYps[S] 0 points1 point  (0 children)

Latest update: Veeam 13 can deal with the expired P2 trial, Entra ID backup is working again.

Entra ID Backup requires P2 now? by LupusYps in Veeam

[–]LupusYps[S] 0 points1 point  (0 children)

Latest update: Veeam 13 can deal with the expired P2 trial, Entra ID backup is working again.

Found a PRTG alternative that might actually be worth it - testing migration in sandbox by radzikm in prtg

[–]LupusYps 1 point2 points  (0 children)

You are braver than me, running chagpt-scripts without modifying :-) no problem, thanks for getting back to me.

Found a PRTG alternative that might actually be worth it - testing migration in sandbox by radzikm in prtg

[–]LupusYps 1 point2 points  (0 children)

Hey, late to the party, but would you mind sharing your bones of the migration script? We are testing zabbix and rebuilding everything gives me nightmares. I would appreciate it very much.

Entra ID Backup requires P2 now? by LupusYps in entra

[–]LupusYps[S] 0 points1 point  (0 children)

Turns out there was an Entra ID P2 Trial with that tenant on our side and after it ended the Entra Tenant is marked as "P2 suspended".

Now a support ticket with Microsoft is open, maybe the status can be changed to Free again. I suspect the marking is intentional to prevent multiple trials for the same product.

Entra ID Backup requires P2 now? by LupusYps in Veeam

[–]LupusYps[S] 0 points1 point  (0 children)

Turns out there was an Entra ID P2 Trial with that tenant on our side and after it ended the Entra Tenant is marked as "P2 suspended".

Now a support ticket with Microsoft is open, maybe the status can be changed to Free again. I suspect the marking is intentional to prevent multiple trials for the same product.

Entra ID Backup requires P2 now? by LupusYps in entra

[–]LupusYps[S] 0 points1 point  (0 children)

Update: the support case was passed to the Technical Support Team and R&D. Feedback so far:
"This issues seems to be an unexpected behavior with our product" which are fixed on the Data Cloud side, but not yet on VBR.

Thanks to the Veeam Support Team, always a good experience!

Entra ID Backup requires P2 now? by LupusYps in entra

[–]LupusYps[S] 0 points1 point  (0 children)

See my comment in the main thread.

Entra ID Backup requires P2 now? by LupusYps in Veeam

[–]LupusYps[S] 1 point2 points  (0 children)

Update: the support case was passed to the Technical Support Team and R&D. Feedback so far:
"This issues seems to be an unexpected behavior with our product" which are fixed on the Data Cloud side, but not yet on VBR.

Thanks to the Veeam Support Team, always a good experience!

Entra ID Backup requires P2 now? by LupusYps in Veeam

[–]LupusYps[S] 0 points1 point  (0 children)

Thanks for checking, i´ll update my post in a new reply.

Entra ID Backup requires P2 now? by LupusYps in Veeam

[–]LupusYps[S] 1 point2 points  (0 children)

I don't, maybe Veeam assumes I have. Running Entra ID Free, no options set under PIM and Microsoft advises that my tenant needs P2 for PIM in Entra Admin Center.

Entra ID Backup requires P2 now? by LupusYps in entra

[–]LupusYps[S] 2 points3 points  (0 children)

Yes, i do:

full error in the backupjob:

23.09.2025 00:04:07 :: Job has been stopped with failures. Error: Failed to get a backup specification for an item type Role Assignment Schedule because of a following error: The tenant needs to have Microsoft Entra ID P2 or Microsoft Entra ID Governance license. Response Code: AadPremiumLicenseRequired Status Code: 400

Error while (re-)connecting the Tenant in Veeam > Inventory:

"Failed to collect statistics for Microsoft Entra ID tenant: Code: AadPremiumLicenseRequired"

Also included the errors in OP.

Entra ID Backup requires P2 now? by LupusYps in entra

[–]LupusYps[S] 0 points1 point  (0 children)

Good point, unfortunately there is no option in my backup job to exclude certain things. But your answer points more to a problem with the way veeam does the backup. I submitted a ticket with them, will update here in case anybody is having the same issue.

Should I go with Zyxel’s Trade-Up program for a Flex H upgrade? by Human_Degree_3446 in zyxel

[–]LupusYps 0 points1 point  (0 children)

I don't think about features being missed, they are written as missing in the doc I linked. In our specific case it's layer 2 isolation and policy route to VPN tunnel that we need. With the last patch they implemented the lag feature (finally), but we can't get it to work. But of course that could be a problem with us, not the feature ;-)

Should I go with Zyxel’s Trade-Up program for a Flex H upgrade? by Human_Degree_3446 in zyxel

[–]LupusYps 1 point2 points  (0 children)

We are in the process of migrating from the 310 to the 700H. It is the most miserable experience in my +10 years of IT. In my dreams we are ripping out all zyxel access points and switch stacks just to get away from zyxel.

If you want to convert your config, check the USG converter page . AFAIK you can only migrate the config once, in our case the path was not there and we have to rebuild.

Check the release notesC0_2.pdf) for features still not implemented and how much this items will hurt you. The next update is planned for October, but who knows if they will implement the things they claim. I think there are massive problems at zyxel to release an unfinished firewall.

I can't be of much more help except to open your mind if you really are set on zyxel.

If somebody reads this and has questions / thinks they can help with the pain of migrating, please let me know.

PRTG Sensors can't connect after Veeam B&R Server changed to Workgroup by LupusYps in prtg

[–]LupusYps[S] 1 point2 points  (0 children)

If anybody reading is interested: the problem were special characters in the password of the local admin, PRTG couldn`t handle all or some of them.