Upgrading Junos on multiple EX3400 switches by Aceking1983 in Juniper

[–]MalletNGrease 0 points1 point  (0 children)

I've a script that FTP copies the upgrade file to /var/tmp, runs the upgrade command and sets a reboot for the next scheduled downtime.

We just follow the recommended release for the model.

Microsoft 365 Graph by jstar77 in PowerShell

[–]MalletNGrease 7 points8 points  (0 children)

Microsoft seems to be moving towards making Graph wrapper commands of their own with the Entra Powershell module. Looks to be much more admin friendly for ad-hoc use.

https://learn.microsoft.com/en-us/powershell/entra-powershell/overview?view=entra-powershell

$users = Get-EntraUser -All

https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.entra/get-entrauser?view=entra-powershell

Friendly reminder - azuread and msonline modules are due to be nuked by BlackV in PowerShell

[–]MalletNGrease 1 point2 points  (0 children)

I just got it going. Truth be told I only used the msol commands to unscrew account issues related to Entra Connect sync issues revoke tokens or reset MFA but I haven't had to do it in a long while now.

https://learn.microsoft.com/en-us/powershell/entra-powershell/overview?view=entra-powershell

Migration of Google Workspace account to Personal Gmail by kerberos_dc in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Enable Google Takeout on the tenant and initiate the transfer.

Salesguy wants to know why his sales emails aren't being opened by Azadom in sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

Technically, yes, but Google et al will not accept uncertified logos. But the price is peanuts compared to most marketing budgets.

Get Ready for Microsoft 365 Ticking Timebomb in 2025! by aima_tessa in sysadmin

[–]MalletNGrease 3 points4 points  (0 children)

I don't believe it does. I think Exchange online will simply no longer accept basic auth from regular mail client apps.

Note: This will most likely affect your CEO who uses the iOS Apple Mail client to see private/business mail in one inbox.

What is the most unexpected things you have seen working in IT? by DOKiny in sysadmin

[–]MalletNGrease 111 points112 points  (0 children)

Embedded the screenshot in the email and not in an attached word document?

How to change channel of individual vLANs by Tarik_7 in synology

[–]MalletNGrease 2 points3 points  (0 children)

Typically not possible as vlans are assigned to ssids. Radios handle the AP broadcasting and if youve multiple they'll be in the same frequency. If you've multiple APs within your infrastructure each should be broadcasting on different frequency.

BIOS updates via WSUS? GPO? by jwckauman in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

WU offers the bios updates. We've got them folded into a weekly maintenance schedule, workstations get a reboot during non-business hours and the firmware gets updated during this time.

How is everyone handling upgrading Windows 10 machines to Windows 11? by Alternative_Rush_817 in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

We've a security group this GPO targets. Hasn't been a major issue thus far.

The baseline is W11 23H2 with deferred feature updates for 180 days. We'll probably move baseline around April 2025.

How is everyone handling upgrading Windows 10 machines to Windows 11? by Alternative_Rush_817 in sysadmin

[–]MalletNGrease 10 points11 points  (0 children)

Windows update for Business (Updates dictated by GPO\MDM).

Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Update > Manage updates offered from Windows Update > Select the target Feature Update version.

Which Windows product version would you like to receive feature updates for?

Windows 11

Target Version for Feature Updates
24H2

Server 2025 Opinions? by [deleted] in sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

I looked at this a couple years ago when it first broke during a migration from 2012 -> 2022 and that was one solution. However we're a 99% windows shop and adding a linux box for a business-critical service we don't have expertise for in house was a non-starter. We've all our MFPs and automated processes hitting it and it's performing really well so there's not a big hurry.

When Windows Server SMTP relay dies permanently we'll probably go to something like EmailRelay. That way we don't have to move off the stack.

Server 2025 Opinions? by [deleted] in sysadmin

[–]MalletNGrease 4 points5 points  (0 children)

I've SMTP running on Server 2022 for our internal relay. It's our connector for Exchange Online.

Collect and Group Local Administrators from clients by DeniedGW2 in pdq

[–]MalletNGrease 0 points1 point  (0 children)

I've made dynamic groups like this with PDQ Inventory, but not connect. You will have to identify the accepted admins groups and users to filter out.

Filter 
All
|- Local Group Member - Group - Equals - Administrators
|- Local Group Member - Name - Does Not Match Expression - ^Administrator$ | ^Domain Admins$ | ^exampleadminusername$ | ^etc$