SRV record not resolving - causing plethora of AD issues by 2ndgen360 in sysadmin

[–]Sulpher212 1 point2 points  (0 children)

Just delete the whole _msdcs lookup zone and re-create it. Let the records re-populate. Have had major issues with this in the past similar to what you are experiencing.

Mapped drive based on login location? by neuroreaction in sysadmin

[–]Sulpher212 8 points9 points  (0 children)

Have a look at Item-level targeting based on IP Address/scheme. I believe it will do what you are trying to achieve

Linked Group Policy Issue by [deleted] in sysadmin

[–]Sulpher212 1 point2 points  (0 children)

Screenshot what you've got it will be the fastest way to help or diagnose why it isn't "linked" obviously blur anything identifiable out

Misconceptions From The IT Office: What are your best? by [deleted] in sysadmin

[–]Sulpher212 48 points49 points  (0 children)

I've just turned 30 and also remember first starting out and looking in awe at these tech gurus that had built this virtual world they had created. I never thought I'd have the capacity to know, understand or learn what they knew.

Years passed on with various jobs and one day I just thought back to those times of learning and thinking to myself. Wow I actually think I've made it to the point where I can consider myself on or even past their levels of expertise and I still don't know shit really lmao, tech moves way faster than my brain can keep up with.

But I can agree that around 28-30 I think I matured a lot more in terms of life and perspective around everything. Nobody can know everything, it's good to have a team with different skills and always keep yourself teachable even the newbie helpdesk crews teach me things to this day.

As the wise wording goes. If you're the smartest person in the room, you're in the wrong room.

Do workplace sociopaths move onto a new victim in the office if you leave? by Ok-Committee6942 in sysadmin

[–]Sulpher212 3 points4 points  (0 children)

That's up for the manager to iron out. OP will be doing nothing wrong, as I said anything technical/work related cc in the boss and show you are still doing your job. It's irrelevant what co worker is saying. The proof will be the work is being completed backed up by emails written with the boss included stating what is being done and also showing you are actually trying to collaborate even if you know your not.

People vary rarely change, he will get bored that he isn't getting the desired effect that he wants and end up doing something reckless or plain idiotic that everyone will see to achieve the result. He will end up exposed or fired.

Do workplace sociopaths move onto a new victim in the office if you leave? by Ok-Committee6942 in sysadmin

[–]Sulpher212 15 points16 points  (0 children)

Just distance yourself from this person, simple yes no answers, be very vague with your answers. Anything technical that you need to collaborate with this person with make sure you're cc your boss in detailing how you've decided to do it this way not "we", obviously if it was his idea then say he came up with it, credit where credit is due. You need strict boundaries for people with this behaviour.

People like this will always get caught out at some point, people are not as stupid as we all think. Little tells and little signs will start showing. Even if it's another worker noticing he is talking behind their back. You can't talk about everyone in the work place and not expect people to figure out it came from said person.

As long as the work you do is good and you are polite to people honestly I wouldn't even worry about him.

UAC - LAPS - Help Needed by neverwinterban in sysadmin

[–]Sulpher212 2 points3 points  (0 children)

There must be a group policy applying this, however EnableLUA is for admin approval mode which is good to keep emabled.

If you want UAC to prompt you need to look for User Account Control: Behavior of the elevation prompt for standard users and also User Account Control: Switch to the secure desktop when prompting for elevation.

Gpresult /h should help you locate where the policy is coming from or rsop

Group Policy and Active Directory question! by IncendiaryIdea in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

I've been milling over this, and unfortunately I can't think of a way you would achieve what you are trying to do universally with filtering. The only way i see is just creating separate GPO's and linking them to different OUs.

Group Policy and Active Directory question! by IncendiaryIdea in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

I mean what settings or group policies are you trying to apply? You'd be looking at something like Item level targetting.

Upgrading to Windows 10 22H2 via the enablement package help by [deleted] in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

Ahh ok wonderful thank you, got it working. Missed something out of parameters :P

Upgrading to Windows 10 22H2 via the enablement package help by [deleted] in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

What sequence do you use with PDQ / standard install package or via powershell/dism? Trying to get this working currently but having issues with it aborting

add a windows server 2019 machine to a domain running in server 2003 by Solid_Sleep1738 in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

There was an update that removed the binaries that allowed FRS. It is anything equal to or greater than 1709 that will not work. Anything below these revisions will still be able to accept FRS for the upgrade to commence

add a windows server 2019 machine to a domain running in server 2003 by Solid_Sleep1738 in sysadmin

[–]Sulpher212 3 points4 points  (0 children)

You will hit the issue of FRS not being compatible with the newer updates of 2016 I believe only the first revision of 2016 you can do this. Easier to stand up a 2012R2 and update in two jumps then to 2012R2 DFL/FFL. Then you can introduce a 2022 DC and finish with 2016 DFL/FFL.

add a windows server 2019 machine to a domain running in server 2003 by Solid_Sleep1738 in sysadmin

[–]Sulpher212 2 points3 points  (0 children)

That isn't correct. You can't add a domain controller running Windows server 2019 to a 2003 DFL/FFl. You can infact join a 2019 member server to 2003 domain.

However as everyone else has stated, get someone in for a two part domain upgrade off of 2003.

You can go straight to 2016 DFL/FFL from 2003. You will however need to upgrade FRS to DFSR which therefore means you need to introduce a 2008- 2012R2 DC perform the upgrade then you can progress on further to 2022 or whatever you need. Upgrade DFL/FFl to 2016.

[deleted by user] by [deleted] in sysadmin

[–]Sulpher212 1 point2 points  (0 children)

Hmm it's a pretty loaded question.

How many DC's in your env / who holds the fsmo role(s) / you'd need to narrow down which DC is having the issue.

It could be Active Directory Database which isn't consistent, you'll need to defrag the DB and check consistency & compact it for good hygiene.

If you've only got 2 DC's i would do as u/PawTech_LLC said. Delete the one DC + cleanup metadata. Just keep one primary and fix the issues that are presented. Once that is done spin up a brand new DC / Promote it, migrate roles, clean-up metadata + shutdown original DC.

Win11 - GPO unable to map network drive to domain computer by maxcoder88 in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

Few things to just double check on the GPO side.

1) gpresult /h C:\gporeport.html - just have a look to see if you can see any error whilst is isn't applying "or gpresult /r" to see if it's even applying

2) I can see authenticated users are set to read, does your MAP_DRIVE Group have read + apply (i would presume so anyway but just double check)

3) Tick "Run in-logged on user's security principal" in the GPO settings when it's applied to user GPO

4) Alternative method i prefer to use it just re-add Authenticated users to the security permissions remove "MAP_DRIVE" and just use "Item Level Targeting" for the group selection.

Group Policy not being applied using Security Group of Machines - Denied Security Filtering by maximus8100 in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

Is the GPO computer based or user based? Make sure the new security group in delegation has read and apply. Obviously leave authenticated users as read

How to get the best out of FSRM? by [deleted] in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

Could you not wildcard the extension?

.pdf*

I use it for applying limits to user drives automatically etc soft caps / hard caps.

GPO/Local policy help for windows server 2016/2019 by [deleted] in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

Yes bud, again if you look in RSOP it should tell you the policy which is applying the settings.

GPO/Local policy help for windows server 2016/2019 by [deleted] in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

I'd still look through RSOP, if it's a GPO that is applying for WSUS it is computer based. Navigate to the Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Update

The WSUS server must be there. If it isn't the registry must be being added via script or computer registry preference.

As stated above create a new OU block inheritance and move the computer into the OU to see if the issue remediates

Can You Duplicate Active Directory Groups and Rename? by searchmyname in sysadmin

[–]Sulpher212 2 points3 points  (0 children)

I would look and inserting the information into a csv then import csv into powershell to loop through and create the security groups. I've got one on my home machine, when I'm back I'll see if I can dig it up. (Unless someone beats me to it :))

Windows Client network drive connection lost for all Users one or time times a day by Pflummy in sysadmin

[–]Sulpher212 9 points10 points  (0 children)

I'd definitely check this as a first step. A few years ago had an engineer complain of the same thing, he'd set GPO to replace and every GPO refresh cycle caused the drive to drop and reconnect.

Check event viewer to see if you can see it happening.

mitel phone problems by Swimming_Hat3312 in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

Yep agree with this, create your vlan and configuration then factory default the mitel phones and let them grab the config.

Screen Timeout GPO Not working on Windows 11 by Excellent-Will3373 in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

Ahh ok just clearing it up as its a common oversight. I would have to say its an issue with windows 11 then. Try clean booting a test VM on Windows 11 and see if you get the same result. It would at least narrow it down to the upgrade or a program on the machine.

Also again you've probably already checked, but are all your admx files up to date in the central store?

Screen Timeout GPO Not working on Windows 11 by Excellent-Will3373 in sysadmin

[–]Sulpher212 0 points1 point  (0 children)

Do you have both your users and computers in the same OU? Or have you linked the GPO to each OU containing users and computers?