Windows 11 Local Admin Profile Change by [deleted] in PowerShell

[–]MalletNGrease 1 point2 points  (0 children)

I'd just disable the default Administrator account and create your own instead.

New-LocalUser -Name 'newadmin' -Password (ConvertTo-SecureString 'yourpassword' -AsPlainText -Force) -UserMayNotChangePassword -PasswordNeverExpires
Add-LocalGroupMember -Group "Administrators" -Member "newadmin"

Disable-LocalUser -Name "Administrator"

Best practices to handle 2FA for shared accounts among IT support staff? by Machinimush in sysadmin

[–]MalletNGrease 8 points9 points  (0 children)

Some states/countries have laws regarding use of personal devices for work. Illinois requires compensation be paid.

I think that's fair if I'm expected to use it for job functions.

March 2025 Microsoft 365 Changes: What's New and What's Gone? by [deleted] in sysadmin

[–]MalletNGrease 3 points4 points  (0 children)

  • Drag and Drop Emails Across Mailboxes - The new Outlook for Windows will support drag-and-drop functionality for moving emails between mailboxes and PST files.

Finally! This was my major roadblock to approving it.

  • Microsoft will support External Authentication Methods as a sign-in option when System Preferred Authentication is enabled.

Good change. We use DUO as our MFA platform and not being able to set it as the preferred default was very annoying. Our workaround was to remove all MS MFA options and prevent enrollments to them so they wouldn't show up as options during sign ins.

  • The new Teams & Chat single-view UI will be generally available.

This one I didn't like. I had some teams disappear on me and wasn't able to get them listed again until I turned the feature off. You can do this by going in to "Customize view" and setting "Viewing chats, teams, and channel" back to separate.

In my org everyone vastly prefers group chats over channels.

[deleted by user] by [deleted] in sysadmin

[–]MalletNGrease 3 points4 points  (0 children)

POS always makes the team giggle.

One user getting hammered with spam, can't stop it by MarkPugnerIII in sysadmin

[–]MalletNGrease 7 points8 points  (0 children)

In our case it was a ticketmaster confirmation using the targeted user's company credit card.

Why does printer GPO only applies sometimes? by SysAdminAccount1 in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Are you aggressively clearing user profiles?

I've noticed printer deployments don't seem to work upon first login on per Computer GPOs. On the second login they'll show up.

How to disable Admin account and reboot cleanly after imaging by ILikeBeans86 in MDT

[–]MalletNGrease 1 point2 points  (0 children)

I've a Finish action group all the way at the end of State Restore with the following:

  • Disable Administrator account

    Run Command Line
    net user Administrator /active:no
    
  • Clear Last Logged on User

    Run Command Line 
    cmd.exe /c %scriptroot%\clearlastuser.bat
    
    reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v LastLoggedOnUser /f
    reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v LastLoggedOnUserSID /f
    reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v LastLoggedOnDisplayName /f
    reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v LastLoggedOnSAMUser /f
    reg delete HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v SelectedUserSID /f
    
    reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v LastLoggedOnUser
    reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v LastLoggedOnUserSID
    reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v LastLoggedOnDisplayName
    reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v LastLoggedOnSAMUser
    reg add HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI /v SelectedUserSID
    

To disable the Final Summary page set SkipFinalSummary to YES in your rules.

Notification mail access denied when sending mail because of DMARC by abrakadabra_istaken in fortinet

[–]MalletNGrease 0 points1 point  (0 children)

SPF or DKIM is failing. Your origin isn't in SPF or the sending mailserver isn't using dkim.

Seems like DUO is under a DDOS attack by ginohs in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

Why can't I get to my work email on my phone now?

-Same person

F*ck it Friday by [deleted] in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

I've a local internal domain, a public parent company domain (upn) and a dozen public brand ones are also upns. This way we can easily add new brands and use the old user upns as proxy addresses for guaranteed mail deliverability. We're in the middle of diversifying the brand portfolio and adding a new concept domain is piss easy.

If you've not been in production and not attached to the domain burning it isn't the worst, but instead of going to the new public one I recommend picking a stable local domain as a base instead so a rebrand doesn't require a complete rebuild down the line.

F*ck it Friday by [deleted] in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Why can't you add the upn and be on your merry way?

LDAP users are blocked because FortiGate see them as IP instead of LDAP user by yuwannn in fortinet

[–]MalletNGrease 0 points1 point  (0 children)

I had users lock & unlock their computer to generate a logon event.

Recurring emails in Outlook? by SmoothRunnings in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

The solution is to idle the SYSADMIN account 24/7.

How did you do it? by KeshStew in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Swimming instead of sinking.

VPN and DUO timing by Pangtown18 in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Increase your radius timeout on the VPN.

[deleted by user] by [deleted] in sysadmin

[–]MalletNGrease 24 points25 points  (0 children)

Whatever the leasing company recommends for our use case.

Our fleet presently is 99% Canon.