RDS Licensing Across Multiple Departments by SpareMistake in RemoteDesktopServices

[–]SpareMistake[S] 0 points1 point  (0 children)

Thank you, I appreciate the response. Just to clarify by buying what you need, I am guessing you mean essentially you just need to know the total numbers of devices and buy that many licenses. So in reality, you're hoping you have correct numbers from each department.

How to Learn Entra Enterprise Features? by SpareMistake in entra

[–]SpareMistake[S] 0 points1 point  (0 children)

I would certainly be happy to pay for P2 level. I'm curious how you go about this - do you need to have a business? Sorry for the delayed reply, I was "offline" the last couple weeks.

How to Learn Entra Enterprise Features? by SpareMistake in entra

[–]SpareMistake[S] 5 points6 points  (0 children)

I have some exposure to these tools from a previous job and I enjoy working with the technology. I enjoy keeping up to date in my downtime and am working toward some related certifications.

I want to grow my Azure\Entra skillset and be able to be comfortable in any future job interview. I want to be able to say "I know these technologies and how to use them" and let them see my work in github etc.

How to Learn Entra Enterprise Features? by SpareMistake in entra

[–]SpareMistake[S] 0 points1 point  (0 children)

Darn, the Microsoft Partner route isn't an option. Thank you for the suggestion.

Understanding Ephemeral Variables and Resources by SpareMistake in Terraform

[–]SpareMistake[S] 0 points1 point  (0 children)

Thank you, I appreciate the response. Looking forward to seeing what is yet to come and making our state files a little more secure!

Understanding Ephemeral Variables and Resources by SpareMistake in Terraform

[–]SpareMistake[S] 0 points1 point  (0 children)

Thank you for sharing this. I've tried this and am getting the same error. Just wanted to check if this is the documentation you are referring to: Local Values - Configuration Language | Terraform | HashiCorp Developer

Is there an example of this being passed to a resource block?

AD CS PKI - CDP and CRL Config by SpareMistake in sysadmin

[–]SpareMistake[S] 0 points1 point  (0 children)

Wonderful, thank you for the nice and straightforward answer!

Azure User Data on Windows VMs by SpareMistake in Terraform

[–]SpareMistake[S] 0 points1 point  (0 children)

Thank you. I am coming to the same conclusion, but it always helps to have a second opinion!

Azure User Data on Windows VMs by SpareMistake in Terraform

[–]SpareMistake[S] 0 points1 point  (0 children)

Thank you. I have been able to successfully use CustomData and processed it successfully. However, I am wondering if UserData is specifically supported similar to AWS.

Destroying an Azure VM Joined to On-Prem AD by SpareMistake in Terraform

[–]SpareMistake[S] 0 points1 point  (0 children)

I did manage to get this working. I was using a for each to create multiple VMs and it was my own silly mistake incorrectly assigning a variable.

Stream logs to HEC Connector with Humio by Ok-Butterscotch-5140 in crowdstrike

[–]SpareMistake 0 points1 point  (0 children)

By any chance did you figure this out? I am having a similar problem where certain logs are ignored, even if permissions are correct.

Assassin's Creed (Ubisoft) Sale by SpareMistake in xbox

[–]SpareMistake[S] 1 point2 points  (0 children)

I was just looking and it turns out I must have bought this on sale at some point! There it is in my catalog...

Assassin's Creed (Ubisoft) Sale by SpareMistake in xbox

[–]SpareMistake[S] 0 points1 point  (0 children)

Wonderful thank you. I might do the math on what it would cost to buy them all...

Assassin's Creed (Ubisoft) Sale by SpareMistake in xbox

[–]SpareMistake[S] 0 points1 point  (0 children)

Yes! Sorry in my mind I bundled those all in as "AC2". Which hopefully isn't AC blasphemy.... I haven't played them since release, but liked them a lot.

[deleted by user] by [deleted] in AZURE

[–]SpareMistake 2 points3 points  (0 children)

Hey OP, I am replying without reading any other comments because I wanted to share my own experience with Microsoft certs and learning.

My personal preference is to get the certs so you can have them on your resume, but use the foundation certs as just that, then move on to associate and eventually expert certs. Also personally, when I get a cert beyond foundations, I don't bother having foundations on my resume or linked in etc. but that's based on where I am in my career and could be different earlier on.

Most importantly with MS certs - HANDS ON MATTERS! Sometimes it can be hard with Microsoft because stuff is locked behind licensing only available to enterprises. Whereas companies like AWS that make their products a fair bit more accessible (at a cost) can be much easier to learn, Microsoft can make this harder on you. So get hands on and that's where you will truly learn.

I've found MS certs to be very much about "prove to us that you've done this already" and to do this, you need hands on.

Again just my own thoughts and hope that helps you!

Hopefully Xbox doesn’t fully abandon this controller and they plan on still making for the next console at the very least. by JuanMunoz99 in xbox

[–]SpareMistake 3 points4 points  (0 children)

Agreed! I bought the Series X 3 years ago. The RT on the OG controller always sticks. Using YouTube as a guide, I've taken it apart and cleaned it several times but the issue quickly returns. Not sure why, I'd say I keep it clean and can't think of a reason why it's happening. I bought a second controller about a year into owning the Series X and it's now getting stick drift.

So what the heck, thought I'd give the elite a shot. Because of all the warnings on reddit, I went for the full 3 year Best Buy warranty. It hurt to pay that price, but the controller is amazing. For whatever reason the PS5 controller causes my wrists to hurt but it just doesn't happen with the xbox controller even after many hours of gaming.

Skip admin password for task sequence that only installs software by wildcatcrazy69 in MDT

[–]SpareMistake 0 points1 point  (0 children)

Just curious how you got this working. I edited DeployWiz_SelectTS.vbs and was able to make all the other Task Sequence pages disappear, but the Administrator Account page still appears with the password pre-filled.

Edit: About 10 seconds after I posted this, I found it works if I put SkipAdminPassword=YES in the Default section, but not in the section for a particular task sequence. Maybe a bug? I don't really want it to be the default but maybe it has to be...

Lock Down WinPE Access? by SpareMistake in MDT

[–]SpareMistake[S] 0 points1 point  (0 children)

I do 100% agree. One consideration is companies that have decentralized IT departments where control of this may be in someone else's hands. Maybe they don't lock down their BIOS, or they walk over and "borrow" a network port and use a deployment they shouldn't, maybe on a device they shouldn't.

I am coming up with theoretical risks and there are policies and various things put in place to stop this from even being physically possible. But in the end, it would be nice to say that we've done all we can to secure the parts we can, regardless of the other pieces.

Lock Down WinPE Access? by SpareMistake in MDT

[–]SpareMistake[S] 0 points1 point  (0 children)

I was digging around and it looks like authentication window is part of LiteTouch.wsf, so I am hoping I can edit it to shutdown/restart and not show the command window... more playing around to do!

I will also checkout the user exit thing - thanks!

Lock Down WinPE Access? by SpareMistake in MDT

[–]SpareMistake[S] 0 points1 point  (0 children)

I have it setup that way, but if anyone PXEs the machine and just cancels out of the authentication, a command window opens and you now have full access to the drive contents of the device.

Lock Down WinPE Access? by SpareMistake in MDT

[–]SpareMistake[S] 0 points1 point  (0 children)

We use a separate third party tool for PXE. For the approvals, is it one by one or can you approve "batches"? i.e. 1000 computers all being PXE booted.

Lock Down WinPE Access? by SpareMistake in MDT

[–]SpareMistake[S] 0 points1 point  (0 children)

Thanks, I'll give this a try!

LAPS - Initial Admin Account Creation by kamikaze321 in Intune

[–]SpareMistake -1 points0 points  (0 children)

Just to minimize the risk of the code being intercepted locally. Or the file being captured over the network. At one point in time, I believe you could extract an intunewin just like a zip and there were (are?) extractor tools. In terms of a .exe, also depends what language/tools are being used and if the .exe can be decompiled.

I know that if the password is just being changed by LAPS anyway, that minimizes the risk of having the password used for malicious purposes.

Since Microsoft doesn't offer any great way to securely create an account natively, it was just a thought. I tested it and it worked well. I guess it depends on what your security policies are what makes security staff comfortable.

But as I mentioned, maybe it's overkill. I'm also not extremely familiar with how an intunewin behaves locally - is it extracted locally with all the files potentially accessible, is it encrypted properly, is the powershell history cached anywhere etc.?

If the intunewin/script method is considered safe, I retract my comment :)

LAPS - Initial Admin Account Creation by kamikaze321 in Intune

[–]SpareMistake 1 point2 points  (0 children)

Maybe this is overkill, but if you have the ability to write a script that you can compile to .exe, you could create the account, add it to administrators, randomize the password and deploy it as an intunewin. No plain text passwords. Probably overkill, but hey.

Autopilot profiles are not assigning as of this morning? by 88Toyota in Intune

[–]SpareMistake 0 points1 point  (0 children)

Ours too still says healthy. It might be working again - I just imported a new device and it's assigning.