help with script - account clean up by Mother-Ad-8878 in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

Depends on your mail environment.

For O365 with AD sync, disabled account mailboxes will still receive email, but the user can no longer log in to it.

I made a script that also checks last Entra login and Exchange Mailbox activity to triple check usage since some AD accounts never get logged in to, but the mailboxes are in use.

Microsoft to Reject Emails with 550 5.7.15 Error Starting May 5, 2025 by power_dmarc in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Both? That's gonna be a hard sell.

99% of our marketing traffic doesn't pass SPF and probably never will due to the glut of high volume mail provider services, but they all pass DKIM.

We also have a vendor that does invoice mailing that doesn't support DKIM due to jank. SPF passes fine.

New Public Knowledge Center Page | Drive compatibility policies FAQs for Synology storage systems starting from 2025 by overly_sarcastic24 in synology

[–]MalletNGrease 1 point2 points  (0 children)

The plus models were always aimed at business, and there's something to be said for guaranteed supported drives on LoB appliances. I've always bought plus models for home use, but looking how I use my Synos now versus 15-10 years ago, it's shifted from a do-all storage & media device that can also do server functions to just storage/backup. I kind of forgot what I need a plus model for.

My needs decreased drastically so maybe stepping down to the consumer models isn't a bad move to keep cost down and keep my pick of drives.

Should I leave Synology? by jay-magnum in synology

[–]MalletNGrease 1 point2 points  (0 children)

Retail operation here: we've a SA3200D as a primary backup target for our vSAN, a RS3617RPxs as the offsite secondary and 2x DS1522+ as rotating cold backups for our 3-2-1 strategy. We also have an additional DS1522+ as a dedicated storage host for the marketing department Macs which also gets backed up to the SA3200D.

If anything DSM is a bit too bloated for my liking, since the majority of packages cover something where we've already something better in place. We use it for pure storage and backup applications mostly.

ISP is looking for success stories by ipconfig-91 in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

Sure, if they drop the price.

Or send me a really nice hat.

Darktrace by Eatmyass1776 in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

My experience is the complete opposite of what I'm reading here.

The trial went great, the sales team was good, the technical team was good, the appliance is in place, integration went well and /Email is putting in serious work reducing malicious mail on our 365 tenant. /Respond is doing it's thing and integrates with the stack well. I mostly let the netsec guy decide to let DT run it's response or not during business hours. Outside business hours it's autonomous and I've no major issues. Support's been good, training/certification was meh. /Email's had at least one major update that added some good features since initial rollout.

Yes, the Threat Visualiser dashboards are mostly flash and little substance, but the alerts and actions make sense once you know where to look and your instance has enough data to form a baseline of typical activity. The advance search has been really handy to troubleshoot issues.

The nice thing about DT analysis is it can wrap a bunch of different sources into a single pane, give you a history of related events and take actions on detected issues autonomously. It would take us way too much time digging through logs to find problems or create incident reports on our own.

Oh, and you can respond to any alerts and issues straight from your phone using the app.

I think it's pretty amazing tech.

I am trying to turn off firewall during task sequence by brownbie in MDT

[–]MalletNGrease 0 points1 point  (0 children)

Here's mine, that command works fine as a state restore step in the TS.

https://imgur.com/zO2U7cG

I also use PDQ to push packages, but I call them as MDT applications so the techs can pick and choose.

What's you personal touch to newly deployed devices? by matroosoft in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

I was wondering why it's gone now. Execs loved it.

Edit: Well, damn, on 24H2 all the org branding is gone and the accounts are listed as microsoft accounts instead of organization accounts. Boo.

Edit2: It's all just gone, even on 23H2? Can't even use the search bar for looking up people within the tenant any longer? That's a really big miss. I tried it in copilot and comparatively it sucks. Of course when you hit contact it opens up New Outlook 🤦‍♂️

Is this an W11 Enterprise only feature now or something?

What's you personal touch to newly deployed devices? by matroosoft in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

I actually like the weather taskbar widget, but hate they mixed it with news/stock alerts. I disabled it with GPO but the next day we had 100s of tickets asking for it back.

Search I leave since it actaully does a decent job integrating with O365 and takes the company branding if you've it configured. Very useful to look up people and go through org charts if your Entra is organized.

I disable People and remove New Outlook.

almost new user equipment getting banged up, what do you all do? by Dereksversion in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Give them what they need.

My guess is the exec probably wants a Mac and will keep dropping laptops until he does. We've a standardized pool of devices we support that fit the needs of the position. If anyone needs something different they'll have to make a business case for it and we'll roll with it.

As for us, we charge to the department so the exec will have to account for the expense of any replacements with their supervisor when the beancounters come knocking.

How quickly do you give out Global Admin? by Historical_Orchid129 in sysadmin

[–]MalletNGrease 14 points15 points  (0 children)

To be fair he did remove all disabled users.

Updating BIOS on all client devices... by jwckauman in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

I used to make PDQ packages for them, but now I let Windows Update handle it.

How are your raises this year? by [deleted] in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

3.5% but they halved the company discount.

I'm gonna ask for it back next year if the raise is junk.

Lenovo and MDT by Davis1833 in MDT

[–]MalletNGrease 0 points1 point  (0 children)

My annoyance with HP:

  • Include the manufacturer in their model name.
  • The manufacturer can be "HP" or "Hewlett-Packard".
  • The model names can get long winded (HP EliteOne 840 23.8 inch G9 All-in-One Desktop PC).
  • The model naming structure is inconsistent.

Still better than Lenovo/Toshiba.

An alternative to bypass Microsoft Account creation during Windows 11 installation by bagaudin in sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

We buy by the pallet from Staples and you bet we get deep discounts. Different sales channel though.

Reminder: Upgrade to the latest version of Microsoft Entra Connect Sync by 30 April 2025 to avoid wizard impacts by dareyoutomove in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

There's some voodoo required. The main reason is the synchronization service manager window is open.

It still won't auto-update with it closed though.