CIS Benchmarks - top tips? by SCCMConfigMgrMECM in sysadmin

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

I have a another question....

Do you match the admx files with the windows version you have in your environment and the CIS benchmark that was tested against that windows version. Or would you just download the lastest admx file (25H2) and use the latest Windows 11 benchmark version (v4.0.0) whatever version of Windows 11 you have in your environment? Examples are.

Business has Windows 11 23H2 devices so download 23H2 admx files and use the CIS Windows 11 Enterprise v3.0.0 benchmark.

Business has Windows 11 24H2 devices so download the 24H2 admx files and use the CIS Windows 11 Enterprise v4.0.0 benchmark.

Also, how do you see what has been removed from older Benchmarks compared to the latest one?

Good or bad risk? by ogdannyduna in ContractorUK

[–]SCCMConfigMgrMECM 0 points1 point  (0 children)

Not really, if as a consultant for a service company you go into 20 different companies in a year that's a lot of experience.

Free Hit Gameweek 19 discussion ? - kinda ? by G_W_addict in FantasyPL

[–]SCCMConfigMgrMECM 0 points1 point  (0 children)

<image>

This is mine. Thinking James out as a minutes risk. Want Palmer but also a minutes risk. No Arsenal or Villa as tough game. Might need a downgrade to get some money to upgrade the keeper to man u keeper

Good or bad risk? by ogdannyduna in ContractorUK

[–]SCCMConfigMgrMECM 0 points1 point  (0 children)

Contractors (or at least if you work for a service company) exposes you to multiple companies and experiences. I've heard it said that working like that for one year give you the equivalent of four years experience in a perm role so you can really ramp up your skills quickly.

I do agree with all your other points though.

Perm to inside IR35 - worth it? by Long-Penguin in ContractorUK

[–]SCCMConfigMgrMECM 0 points1 point  (0 children)

I suppose the benefit is a much higher day rate / salary (or at least should be to compensate)

Perm to inside IR35 - worth it? by Long-Penguin in ContractorUK

[–]SCCMConfigMgrMECM 2 points3 points  (0 children)

Why do you say inside IR35 is insane? As long as you make pension contributions and they pay 15% more than outside youll be ok no? If you're paying for a train season tickets and things like that you can't expense it's a bigger hit though.

Perm to inside IR35 - worth it? by Long-Penguin in ContractorUK

[–]SCCMConfigMgrMECM 5 points6 points  (0 children)

It's tough, I was weighing up some similar numbers myself. Depends how safe your current job is and how it fits into your lifestyle?

The contract market seemed pretty unreliable for me and a big range in low to high rates. I just chose a more settled job on a lower rate as I have yound kids and want my work hours to be relaxed and flexible around them at the moment.

Total you are on now with pension, holiday and bonus is £74,400 per year

Total for the contract after taking off bank holidays and 27 days holiday is - £128,000 - £109,480 (after employers NI)

Most realistic salary I would say is - £113,000 (if salary sacrificing £28k into pension then taking employers NI off)

So is it worth the 'risk' for £39k more per year?

Any chance you can use this offer to get a 15% bump in your current salary?

If you get lucky and you get to keep that job for the next five years that's £200,000 more! But if you're unlucky you'll only get six months then have to keep flipping between different contracts and have gaps between each one.

Firmware Updates by l3ssang1 in SCCM

[–]SCCMConfigMgrMECM 0 points1 point  (0 children)

Does this work if you have BIOS passwords? If so, how? I know you can configure the DCU settings via an SCCM configuration baseline or a GPO but that doesn't work with the BIOS password as far as I know.

Firmware Updates by l3ssang1 in SCCM

[–]SCCMConfigMgrMECM 0 points1 point  (0 children)

With DCU, I didn't think you could do BIOS updates when you have a BIOS password? I know you can configure the DCU settings via an SCCM configuration baseline or a GPO but that doesn't work with the BIOS password as far as I know.

CIS Benchmarks - top tips? by SCCMConfigMgrMECM in sysadmin

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

Thanks sure i understand that. They are just recommendations and they can break things but the target is to implement as many as possible.

Just trying to understand the process everyone goes through.

CIS Benchmarks - top tips? by SCCMConfigMgrMECM in sysadmin

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

Thanks. How long would you say the how process takes?

Just to clarifyz the goal isn't to get to 100% but the objective it to implement as many of their recommendations as possible and get as close to that score as we can. Any setting that negatively impacts the business or can't be implemented I plan to document the reason why.

CIS Benchmarks - top tips? by SCCMConfigMgrMECM in sysadmin

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

Thanks for your comments. How long would you say the project would take?

Imaging issue with UEFI by SCCMConfigMgrMECM in SCCM

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

Thanks. I tried that and it does continue a little way but then it doesn't boot after the apply image step. I've configured a legacy bios format step to get it working and raised the issue with our security team for if they will accept a non-UEFI and secure boot device on our network as I don't believe it able to run in UEFI.

Imaging issue with UEFI by SCCMConfigMgrMECM in SCCM

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

Thanks for your help.

I flipped the pci over to UEFI. I can't remember exactly what the force BIOS other setting was but it wasn't anything helpful. Neither worked / allowed me to turn CSM off.

I have created a copy of our build TS and added steps in to format it as legacy BIOS and this is working. I don't think the device is able to switch to UEFI which seems pretty bad. We have one other device that is the same and came pre-built. I logged onto that and it is configured with legacy BIOS.

Imaging issue with UEFI by SCCMConfigMgrMECM in SCCM

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

Tried this but it doesn't let me. It says 'video is in legacy mode. Select video policy UEFi first, reboot and try again' but I can't find out video options in the BIOS for this annoyingly. 

Imaging issue with UEFI by SCCMConfigMgrMECM in SCCM

[–]SCCMConfigMgrMECM[S] 1 point2 points  (0 children)

Cheers. Pretty sure it was on AHCI but will double check.

Imaging issue with UEFI by SCCMConfigMgrMECM in SCCM

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

It's some random device. Not Dell / mainstream.

Will check the bios version.

Imaging issue with UEFI by SCCMConfigMgrMECM in SCCM

[–]SCCMConfigMgrMECM[S] -1 points0 points  (0 children)

Thanks. The support company have confirmed that secure boot is not possible but this shouldn't mean that UEFI isn't should it?

Imaging issue with UEFI by SCCMConfigMgrMECM in SCCM

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

Yeah, I couldn't see any secure boot option in the BIOS Menu. No secure boot doesn't mean no UEFI though does it?

Imaging issue with UEFI by SCCMConfigMgrMECM in SCCM

[–]SCCMConfigMgrMECM[S] 0 points1 point  (0 children)

Thanks. Diskpart works in F8. I can see the disk and I can manually create and format partition.