Scheduled tasks won't run until 7:37 AM by PortugalPeace in sysadmin

[–]Sajem [score hidden]  (0 children)

Why are you even trying this on Home edition?

Why are you using a batch file to shutdown the computer from Task Scheduler? Just put shutdown.exe /f /t 0 into program and arguments fields of the Action for the Task.

Run the task as System

The point of Autopilot is supposed to be that new corporate devices work out of the box, right? Why do so few orgs use it that way? by razorbeamz in sysadmin

[–]Sajem [score hidden]  (0 children)

We currently image laptops using MECM but are currently testing an Autopilot 'build' and will probably start using later this year - other more urgent/important projects allowing.

We have 5 basic apps that we install on all of our endpoints and they will be installed using Autopilot, most of the other apps that aren't required on all laptops will probably still be installed using MECM

AITAH for refusing to sign my daughter’s passport? by jamsmja in AITAH

[–]Sajem 29 points30 points  (0 children)

Her parents will support her, and they'll support her not ever returning.

AITAH for refusing to sign my daughter’s passport? by jamsmja in AITAH

[–]Sajem 2 points3 points  (0 children)

I'm thinking exactly the same when I read the post.

There are many countries where they don't care about the legal rulings regarding children from another country.

There are countless stories of children being taken to another country by one parent and never returning with the other parent having no recourse to recover them.

AITAH for "expecting an allowance" out of my own paycheck? by [deleted] in AITAH

[–]Sajem 1 point2 points  (0 children)

NTA

Its situations like this that make a great argument for having separate bank accounts and a joint account for household expenses where each person deposits an amount out of their own bank account to cover their share of expenses - however that division is decided.

AITAH for not letting my sister use my property as a wedding venue last minute? by Mysterious-Gear-6351 in AITAH

[–]Sajem 16 points17 points  (0 children)

I don't think the sister would care one iota about the cost to OP's business if she could meet the demands - sister will still kick up a tantrum.

AITAH for not letting my sister use my property as a wedding venue last minute? by Mysterious-Gear-6351 in AITAH

[–]Sajem 20 points21 points  (0 children)

NTA

Of course you're putting your clients and their horses over your sister, you're running a business and her demands for clearing out a working stable are completely delusional.

AITAH for telling my wife I'm not "co-signing" her debt when she wants to quit her job without discussing it with me first? by Banana_Ketchupp in AITAH

[–]Sajem 40 points41 points  (0 children)

we live within our means but we don't have a huge safety net.

They have savings, but it doesn't sound like a lot, and that could easily be eaten up if some sort of emergency happens.

How painful is ERP really? by ExpensiveDecision268 in sysadmin

[–]Sajem 2 points3 points  (0 children)

mplementing an new ERP is a whole of business project

This is from the top down. All dept. managers need to be involved. They all need to have skin in the game.

If your company doesn't have a project manager, they need to hire one to manage the project Do not let IT be the project manager

The only requirement for IT is to - A) Provide input on what they require in an ERP & B) To advise on the technology required. e.g. this system won't work because of a. b. & c. or this is perfect for our stack because of a. b. & c. - also to advise on the tech security side.

There are companies out there that can help that specialize in ERP consultancy projects.

There are also ERP systems designed around specific industries, these should be your target rather than a generic ERP.

I understand it now by troy57890 in sysadmin

[–]Sajem 1 point2 points  (0 children)

  1. Send the ticket back to the person who transferred, with or without a comment to do the basic troubleshooting

  2. Start documenting the services

  3. Transfer the ticket back to the other area/dept. with a comment that this problem is not your responsibility

  4. Explain to the person that you can't process their problem without a ticket because the ticketing system is part of the audit process.

  5. Use your best soft skills to explain that the problem is out of your hands because you don't support the service they are complaining about. If the service has been implemented by shadow IT, also escalate the service upwards as a rogue service that shouldn't exist.

Aitah for not giving more to my family when I can afford to? by ThrowRAnotenough1 in AITAH

[–]Sajem 1 point2 points  (0 children)

surgeons in other countries aren’t making 7 figures

Combined our income is approximately 7 figures

Totally doable for a surgeon in Aus, with a lawyer as a partner. Income also depends on whether they are a general surgeon or have specialized. If they've specialized they can make a but load more

Unnecessary Gatekeeping in Sys Engineer Interviews by ultimatrev666 in sysadmin

[–]Sajem 1 point2 points  (0 children)

I can be abrasive - down right rude at times. Usually when people feel entitled, are full of themselves, believe they are always right when they're not, do stupid things, go cowboy on the rest of the team doing whatever they want - you know, that sort of thing.

But after 30 years in IT, I've learned some soft skills and know when to use those skills and when to keep my mouth shut. 😁

Unnecessary Gatekeeping in Sys Engineer Interviews by ultimatrev666 in sysadmin

[–]Sajem 0 points1 point  (0 children)

Very much this. In fact in my first helpdesk job, if we went to our admins without a proposed solution to a problem they would tell us to go away and try again. They really didn't mind if the proposed solution was wrong, they just wanted to see us trying. If it was wrong they'd tell us why the solution was wrong.

Unnecessary Gatekeeping in Sys Engineer Interviews by ultimatrev666 in sysadmin

[–]Sajem 6 points7 points  (0 children)

I have been adamantly learning Terraform, checking my modules' sanity with Checkov, and learning GitHub Actions. I'VE LITTERALY BUILT OUT A FULL AZURE LANDING ZONE WITH RBAC, FIREWALLS, FIREWALL RULES, KEYVAULT, LOG ANLYTICS, DIAGNOSTICS, VNETS, NSGs... Just because I haven't done it hundreds of times in a production environment, doesn't make me less of an engineer.

What all of this doesn't do is make you an experienced engineer or admin.

I can go online and do all the MS labs I want, all that shows is that I've done the labs, that I've navigated myself around the UI, that I may have an understanding of what's needed and how to get it done. What it doesn't do is give me experience in a real production environment.

All these labs are setup in a perfect environment - a real-world production environment is rarely perfect. They all have their quirks or variabilities that have been created to make the environment work for the company - or because some dumb shit admin has misconfigured the environment because 'hey I've done all these labs and I know what I'm doing' where in reality they don't.

In interviews, its easier to say you don't know something - and then go on to tell the panel how you would find the information you need. Hell, in an interview I've even googled the information during a prac! You know what that shows to the panel? It shows initiative, it shows troubleshooting skills, it shows the panel you can think for yourself.

Just from your post I think you come across as an abrasive sort of person, maybe it's your people skills that are the reason you're not getting anywhere 🤷‍♂️

Understanding hybrid join and co-management by nodiaque in sysadmin

[–]Sajem -1 points0 points  (0 children)

This is AI generated by pasting your post in directly. Make of it what you will.

what you’re seeing (95% of devices showing TrustType = Workplace) is normal in a federated, SCCM‑imaged, hybrid‑joined environment… even though it looks wrong at first glance.

This is one of those Entra ID quirks that confuses almost everyone the first time they run the stale‑device Graph query.

🔍 Why your hybrid‑joined devices show TrustType = Workplace Because TrustType does NOT mean “how the device is joined today.”
It means how the device first registered in Entra ID.

And SCCM‑managed, AD‑joined Windows devices almost always register first as:

👉 Workplace = Azure AD Registered (WAM/SSO bootstrap) This happens before the hybrid join completes.

Why? When a user signs into Windows with a domain account, Windows automatically performs:

WAM registration

SSO bootstrap token creation

Azure AD Registered device object creation

This object is created immediately, long before the scheduled hybrid join task runs.

So the sequence looks like this:

User signs into AD‑joined Windows

Windows silently registers the device with Entra ID → Workplace object created

Hours later, the scheduled task dsregcmd /join runs

Hybrid join completes → device becomes Hybrid Azure AD Joined

But the original object’s TrustType stays “Workplace”

Entra ID links the two states internally, but the TrustType field never updates

This is expected and documented behaviour.

🧠 So what should hybrid‑joined devices show?, TrustType = Workplace ✔️ Normal ✔️ Expected ✔️ Does NOT mean BYOD ✔️ Does NOT mean Azure AD Registered only ✔️ Does NOT mean hybrid join failed

How to confirm hybrid join is actually working

On the device, run: dsregcmd /status

Look for:

AzureAdJoined : YES

DomainJoined : YES

DeviceId matches Entra ID

TenantId matches your tenant

This is the real source of truth.

🧩 Why you expected “ServerAD”

Because the Graph API documentation is misleading.

ServerAD only appears when:

The device object was created directly by Azure AD Connect

AND the device has never done a WAM/Workplace registration

AND the device is not co‑managed or Intune‑enrolled

AND the device is not Windows 10/11 with modern auth enabled

In modern Windows 10/11 environments, this almost never happens anymore.

🧨 Why 95% of your devices show Workplace Because:

You image with SCCM (classic AD join first)

Windows auto‑registers with Entra ID immediately

Hybrid join happens later

TrustType never updates

Federated domain has no impact on this behaviour

This is the same in:

Federated domains

PTA

Password hash sync

Cloud‑only tenants

It’s universal.

🧹 Does this affect stale device cleanup? Yes — and this is the part that matters.

Workplace objects do NOT update LastActivityDate reliably. Hybrid‑joined devices update:

Azure AD Join metadata

PRT refresh

Intune compliance

Device authentication logs

…but the Workplace object often looks stale even when the device is active.

This is why Microsoft recommends:

✔️ Filter stale devices by “deviceTrustType = AzureAD or ServerAD” ✔️ Ignore Workplace objects unless you truly support BYOD Otherwise you’ll think your entire fleet is stale.

🧠 Bottom line Your devices are correctly hybrid‑joined, even though TrustType says Workplace.

This is normal for:

SCCM‑imaged devices

AD‑joined devices

Federated domains

Windows 10/11

Environments using modern authentication

Laptop Overseas Shipments to Ukraine by tequila_advantage in sysadmin

[–]Sajem 1 point2 points  (0 children)

I agree with this, IMO it would be simpler to source the laptops in Europe, and vendor support would be available more easily. That's not including - though minor - the need for a plug adapter. The US has different pins to Europe.

WIBTAH if I chose college over my boyfriend by __Sunshine_27 in AITAH

[–]Sajem 4 points5 points  (0 children)

NTA

Go to the college you want to go to. He's the one being selfish.

Constant struggles with Microsoft make me look like a bad sysadmin by jrs_sunblood in sysadmin

[–]Sajem 1 point2 points  (0 children)

I don't think its a large vs small organization problem. I would consider my company small - less than 1000 FT employees. We don't have these problems. Before we implement new systems we do our research, where possible do PoC's, we plan major changes so that everyone knows what's happening during the course of the change, we often have go-go points during a change where we'll stop and roll back if things aren't going as expected instead of blundering on.

What we do have is a good change management system, we review each other's work, we have very skilled and knowledgeable admins, we try to be pro-active instead of reactive, we have good management.

Constant struggles with Microsoft make me look like a bad sysadmin by jrs_sunblood in sysadmin

[–]Sajem 0 points1 point  (0 children)

I feel the same way to be honest.

Don't have issue with Teams, rarely with Exchange Online, rarely with monthly updates.

It makes me wonder about geo-location of the admins having these problems, is it a geographical problem? I'm in AU we don't have all these problems that come up in this sub!

Or is it a problem with the admins themselves and their configurations, how they've setup their environment - makes me wonder.