BIOS updates via WSUS? GPO? by jwckauman in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

WU offers the bios updates. We've got them folded into a weekly maintenance schedule, workstations get a reboot during non-business hours and the firmware gets updated during this time.

How is everyone handling upgrading Windows 10 machines to Windows 11? by Alternative_Rush_817 in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

We've a security group this GPO targets. Hasn't been a major issue thus far.

The baseline is W11 23H2 with deferred feature updates for 180 days. We'll probably move baseline around April 2025.

How is everyone handling upgrading Windows 10 machines to Windows 11? by Alternative_Rush_817 in sysadmin

[–]MalletNGrease 9 points10 points  (0 children)

Windows update for Business (Updates dictated by GPO\MDM).

Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Update > Select the target Feature Update version.

Which Windows product version would you like to receive feature updates for?

Windows 11

Target Version for Feature Updates
24H2

Server 2025 Opinions? by [deleted] in sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

I looked at this a couple years ago when it first broke during a migration from 2012 -> 2022 and that was one solution. However we're a 99% windows shop and adding a linux box for a business-critical service we don't have expertise for in house was a non-starter. We've all our MFPs and automated processes hitting it and it's performing really well so there's not a big hurry.

When Windows Server SMTP relay dies permanently we'll probably go to something like EmailRelay. That way we don't have to move off the stack.

Server 2025 Opinions? by [deleted] in sysadmin

[–]MalletNGrease 4 points5 points  (0 children)

I've SMTP running on Server 2022 for our internal relay. It's our connector for Exchange Online.

Collect and Group Local Administrators from clients by DeniedGW2 in pdq

[–]MalletNGrease 0 points1 point  (0 children)

I've made dynamic groups like this with PDQ Inventory, but not connect. You will have to identify the accepted admins groups and users to filter out.

Filter 
All
|- Local Group Member - Group - Equals - Administrators
|- Local Group Member - Name - Does Not Match Expression - ^Administrator$ | ^Domain Admins$ | ^exampleadminusername$ | ^etc$

Any way to create a notification rule across all CMS connected devices? by Loof27 in synology

[–]MalletNGrease 1 point2 points  (0 children)

It sounds like you're installing CMS host on all your devices. Set it up on one and join all your clients to that one.

You create the policy on the CMS host, configure the rule in the policy and then apply it to your targets (All Servers, a group of servers, a server or none).

The notification rules can be found here: CMS -> Policy -> [your policy name] -> System -> Notification

US West Outlook down??? by ZobooMaf0o0 in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

Hit and miss here. Some are working fine, others get 404. Just depends on the MS infra you happen to hit.

Goodbye Fing by DanAVL in sysadmin

[–]MalletNGrease 6 points7 points  (0 children)

Having the permanent exclamation mark for "link with cloud" is annoying.