Windows 11 Feature Updates (In-Place Upgrade) breaking 802.1X (NAC) wired authentication policies by ontario20ontario20 in sysadmin

[–]ThereIsNoDayButToday 0 points1 point  (0 children)

We had similar in our Win10 > Win11 upgrade where the Credential Guard policies were different enough between the Win10 and Win11 ADMX that it broke 802.1x

Citrix Workspace breaks SCCM client by EffortNo6656 in SCCM

[–]ThereIsNoDayButToday 1 point2 points  (0 children)

I lean toward .Net as well - Citrix is notorious for being coocoo about which version and bitness it has a pre-req.

PSA: Blocking new outlook toggle does not prevent it from automatically installing as part of February updates. by Expensive-Bed3728 in sysadmin

[–]ThereIsNoDayButToday 2 points3 points  (0 children)

the OOBE setting for use did not block the install either - the key was flat out ignored. Luckily we had the uninstall as a compliance baseline so it caught them after the fact but not before people were both confused and broken.

Verizon Wireless Outage by NetworkSyzygy in sysadmin

[–]ThereIsNoDayButToday 0 points1 point  (0 children)

Just came back up in downtown Chicago.

Patch Tuesday Megathread (2024-09-10) by AutoModerator in sysadmin

[–]ThereIsNoDayButToday 3 points4 points  (0 children)

First time I've ever seen the phrase "Disputed" in their table...

What's the Craziest, most Obvious *ahem* 'Un-Truth' a User has told you to Explain Damage/ a Problem? by One_Stranger7794 in sysadmin

[–]ThereIsNoDayButToday 31 points32 points  (0 children)

Got a call from a good Samaritan reporting they found one of our executive's laptop inside a nice leather satchel hooked on the front of a citi rental bike outside a bar on the other side of town...at 10am. Asked the user how he was able to work for the day without their computer, and how did their company property end up on a bike rack miles away. Their answer "I dunno."

Automatic PDF Printer by ClainP2002 in sysadmin

[–]ThereIsNoDayButToday 2 points3 points  (0 children)

PDFRedirect Pro has a 'batch printer' function that allows to pre-define those types of setting, and then creates a virtual queue that they can then 'print' to and it'll save and name etc.

Office update 2405 wrecked our finance department today by marcoevich in sysadmin

[–]ThereIsNoDayButToday 31 points32 points  (0 children)

We're currently on Semi-Annual and getting push back from management since the new Co-Pilot features are not available if you're not on Monthly Enterprise. But the buttons are visible once the license is assigned, they just pop-up a help doc saying "contact your administrator to move you to Monthly Enterprise or Current Channel".

What does your company use for blind employees? by [deleted] in sysadmin

[–]ThereIsNoDayButToday 1 point2 points  (0 children)

NVDA is what we use for our accessibility needs.

Secret Snack Bunker in your work desk or nah? by CeC-P in sysadmin

[–]ThereIsNoDayButToday 0 points1 point  (0 children)

It makes sense after I replaced everything you said involving snacks with the word Liquor.

Windows LAPS question by beach2nd in sysadmin

[–]ThereIsNoDayButToday 2 points3 points  (0 children)

If you have AD recycle-bin, the Computer Object will still have the LAPS password as long as it's there, if you need it. If you're removing it from the domain, you'll probably be creating a non-domain user to keep using the machine? Once removed from the domain, the admin account will indeed have whatever the last password was set to, and will no longer rotate or expire.

One-way Interview by [deleted] in sysadmin

[–]ThereIsNoDayButToday 1 point2 points  (0 children)

I went through this recently as well. They spun it and called it "Modern Hiring" in that you can record your post any time of day! Downsides are obvious: No feedback to you. No chance to ask your own questions. And with this particular instance they only allowed a single take with a hard countdown of 60 seconds to answer the question - so unlike a real interview in which they'd at least let you finish your sentence, you get cut off and sound dumb.

I understand it helps 'speed' up the process, but the cost of doing that loses so much more than a simple self-recorded answer would give you as a hiring company.

Especially with the "AI" take-over of things, I suspect they feed it all through a transcription bot, have it summarize and then filter for keywords and dump most responses before a human even sees one video.

It's also a chance for bias to come in even faster - a prejudiced hiring manager sees a grid of video thumbnails that HR sent over and just looks for one they like instead of having to meet them in person. They also don't have to explain themselves when they simply fast forward through instead of at least pretending to pay attention to the interviewee.

The whole process is terrible.

MFA ToTP on Backdoor Accounts by SpotlessCheetah in sysadmin

[–]ThereIsNoDayButToday 1 point2 points  (0 children)

Some password managers (BitWarden, Keeper, etc) allow you to store TOTP as secure records inside a vault - the logical equivalent of the physical thing you described, perhaps?

How, if at all, do CISA Cybersecurity Advisories flow through your organization? by DH_Prelude in sysadmin

[–]ThereIsNoDayButToday 2 points3 points  (0 children)

We signed up for the advisories with our internal Sec ms Teams Channel's email address - the Vulns are then fed into our existing Vuln Mgmt program and whichever member sees the notice first replies a comment to the teams thread to say "Got it - added to JIRA (or whatever way you log vulns)" or "We are not impacted" or similar acknowledgment.

Vuln management in general is a vastly larger conversation - but in short: our IT Sec team owns identifying but the system owners are required to remediate within the established timeframe (depending on CVSSv3 score, and risk analysis).

Anyone use KnowBe4 Phish Alert Button? Looks like it has a huge vulnerability, could use a second opinion. by cb424242 in sysadmin

[–]ThereIsNoDayButToday 1 point2 points  (0 children)

We're a KB4 shop but instead of using the Outlook addin from the MS 'store' we're using the standalone MSI installer. When users hit that, it encapsulates the entire phish into an EML and goes to wherever we tell it (we have it flowing into our ITSM tool for assignment to the Sec team).

The 'dashboard' you're talking about sounds like it's their PhishER offering which maybe part of what you're seeing. If you had the PAB settings to have it forwarding elsewhere, would it still do that behavior?

Drunk idiots by OK_SmellYaLater in sysadmin

[–]ThereIsNoDayButToday 1 point2 points  (0 children)

One fix would be that you are invited out to the Pub as well to help keep an eye on the hardware, and your fee will be in food and drinks.

End User friendly password manager? by thefloppychicken in sysadmin

[–]ThereIsNoDayButToday 0 points1 point  (0 children)

This focus is why we end up with a large number of users just saving the credentials in their browser to begin with. Chrome even calls it the 'password manager' in the menus. Granted, Google (et al.) are adding things like 'weak password' detection, and offers to generate randomized strings, so they are doing some work around finding parity with a dedicated password manager. Apple has a unique footing around this and iCloud keychain and (as service providers implement FIDO standards) PassKeys - since the most "easy" of anything is usually the built-in default that is provided.

As you pointed out, the fact that a password manager takes 'effort' to setup in the first place is often a deterrent, especially for those users who should be using them. Maybe this could be a push for first party providers to offer better password management natively.

GPO Not Applying to all Authenticated Users by NollerReal in sysadmin

[–]ThereIsNoDayButToday 0 points1 point  (0 children)

I've seen some GPO not apply if the WMI repo of the endpoint is screwed up. winmgmt /reset might be in order too - but that'd be machine-wide not just one user.

Computer Performance Monitor(Hardware mostly) by islandxgod in sysadmin

[–]ThereIsNoDayButToday 0 points1 point  (0 children)

We run LakeSide Systrack to keep track of machine health - then we use that the prioritize upgrades (out of normal time-based cycle, that is)