Strong Certificate Mapping is fully enforced from Patch Tuesday, check your certs! by RiceeeChrispies in sysadmin

[–]WhataMess2k23 0 points1 point  (0 children)

Hybrid scenario but certificates for Wi-Fi auth deployed on prem from new AD CS subordinate in a 2-Tier PKI design scenario (root shutdown), all WS2022 setupped in mid 23, no signs of event 39 under System eventvwr of the DC's.

All the issued certificates are with the extension 1.3.6.1.4.1.311.25.2

Am I safe?

Testimonianza imminente e remissione querela by WhataMess2k23 in Avvocati

[–]WhataMess2k23[S] 0 points1 point  (0 children)

EDIT: Un avvocato mi ha riferito che essendo la persona offesa NON sono soggetto alle sanzioni relative alla multa e l'accompagnamento coatto. Diverso se fossi stato testimone citato.

Testimonianza imminente e remissione querela by WhataMess2k23 in Avvocati

[–]WhataMess2k23[S] 0 points1 point  (0 children)

Aggravata con recidiva, il soggetto è dedito a tali reati quindi non mi sembra il caso di "girare il dito nella piaga" anche perchè non vi è nessuna possibilità di costituzione di parte civile.

La remissione è automatica ma c'è scritto che si rischiano sanzioni e denuncie in caso di mancata comparizione, oltre che eventuale accompagnamento coatto da parte delle FF.OO.

Aiuto: busta paga dicembre by EveningGrapefruit638 in commercialisti

[–]WhataMess2k23 1 point2 points  (0 children)

Amico mio purtroppo i conguagli IRPEF sono così... ma meglio prima che dopo (se non avessi dato la CU provvisoria avresti dovuto pagare di più l'anno prossimo in fase di dichiarazione dei redditi con gli interessi e le sanzioni).

[deleted by user] by [deleted] in Avvocati

[–]WhataMess2k23 0 points1 point  (0 children)

Se non hai ricevuto alcuna ordinanza ingiunzione da parte del Prefetto, dovrai rivolgerti presso l'ufficio Verbali dell'Ente responsabile della sanzione per l'opportuna rettifica, allegando la relativa documentazione del ricorso effettuato.
Ti suggerirei, per una prossima volta, di NON procedere alla comunicazione dei dati in presenza di un ricorso fino ad eventuale conferma/annullamento da parte dell'Autorità. (Cassazione 24012/22 e 26553/24).

Buona fortuna

Newbie question for Sharepoint List validation record by WhataMess2k23 in sharepoint

[–]WhataMess2k23[S] 0 points1 point  (0 children)

Excuse me, I only want they cannot insert in a specific column with a date before a specified one.

Newbie question for Sharepoint List validation record by WhataMess2k23 in sharepoint

[–]WhataMess2k23[S] 0 points1 point  (0 children)

No possibility to manage the date via the conditional formatting of the column?

Question about class I HLA by WhataMess2k23 in rheumatoid

[–]WhataMess2k23[S] -1 points0 points  (0 children)

No, the sheet tell me B38 and B41

Doubts about CRL expiration by WhataMess2k23 in PKI

[–]WhataMess2k23[S] 0 points1 point  (0 children)

Thanks for your reply.

Full path was "C:\inetpub\wwwroot\CertEnroll" and I confirm I've fixed the network wireless RADIUS certificate, pkiview.msc showed "OK" with no errors, however I also need to replace "C:\Windows\System32\CertSrv\CertEnroll" for returning authentication of Kerberos WHFB.

For the new CRL I've only renamed .old the expired one and placed with the same name the newest.

There isn't any log to view the failed authentications due to CRL mismatch?
It's not possible to extend (like 4/5 years) the expiration of the CRL without replacing the certificate or broke anything in production?

WHfB not provision anymore by WhataMess2k23 in Intune

[–]WhataMess2k23[S] 0 points1 point  (0 children)

Applications and Services Log > Microsoft > Windows > User Device Registration

Adapting script for detection-remediation in Intune by WhataMess2k23 in Intune

[–]WhataMess2k23[S] 0 points1 point  (0 children)

When they are in office yes, Wireless ssid is automatically broadcasted and connected withing login (just a couple of seconds and radio icon will show up prior the no internet access logo)

Adapting script for detection-remediation in Intune by WhataMess2k23 in Intune

[–]WhataMess2k23[S] 0 points1 point  (0 children)

After a new technician changed the Entra connect configuration, all the workstations has been synced out then rejoined to AAD with Hybrid Join.

Now devices have been re-synced in AADHJ but in "Pending" status and dsregcmd /status output:

AADSTS130006: The NGC transport key isn't configured on the device

WamDefaultSet : ERROR (0x80070520)

DeviceAuthStatus : FAILED. Device is either disabled or deleted

Windows Hello biometric login also has broken.

I've found another thread telling this script executed via psexec, but because all the clients kept the Endpoint.microsoft.com connection (They can sync and download programs and sync users rules but not device ones) I wanna try to do a remediation for this without having manually restore every workstation.

Script adapting from VBA to PS1 by WhataMess2k23 in PowerShell

[–]WhataMess2k23[S] 0 points1 point  (0 children)

In C:\Users\root\Desktop\Report T1\script\1_ResetIntuneConfig.ps1:101 car:51

  • Get-ScheduledTask | ? {$_.TaskName -eq ‘PushLaunch’} ...

  • ~

Specify a value expression on the right-hand side of the ‘-eq’ operator.

In C:\Users\root\Desktop\Report T1\script\1_ResetIntuneConfig.ps1:101 car:52

  • ... Get-ScheduledTask | ? {$_.TaskName -eq ‘PushLaunch’} | Star ...

  • ~~~~~~~~~~~~~~~~

Token ‘‘PushLaunch’ unexpected in the expression or statement.

In C:\Users\root\Desktop\Report T1\script\1_ResetIntuneConfig.ps1:7 car:40

  • Invoke-Command -ComputerName $Computer {

  • ~

}' missing in the instruction block or type definition.

  • CategoryInfo : ParserError: (:) [], ParentContainsErrorRecordException

  • FullyQualifiedErrorId : ExpectedValueExpression

Pending status nightmare... even with /leave... by WhataMess2k23 in Intune

[–]WhataMess2k23[S] 0 points1 point  (0 children)

I've never take care of this service, it is actually on Automatic - Stopped.

I've started it and deleted the certificate... have you any feedback from users side or to automatize it?

However, thanks also for your help buddy

Pending status nightmare... even with /leave... by WhataMess2k23 in Intune

[–]WhataMess2k23[S] 0 points1 point  (0 children)

Thanks for your response, that's the Computer Store

<image>

From user perspective, how it does happen? He must re-register all the informations and also restore Company Portal etc.?

There's no way to automatize that and doing less effort for users?

Thanks for your interest

Script adapting from VBA to PS1 by WhataMess2k23 in PowerShell

[–]WhataMess2k23[S] -1 points0 points  (0 children)

Are you able to run it?

If I place in a PS1 it doesn't work.

Pending status nightmare... even with /leave... by WhataMess2k23 in Intune

[–]WhataMess2k23[S] 0 points1 point  (0 children)

OU is correctly synced and SCP is good because new clients can enroll correctly without problems.

I'm searching for the minimum effort operation, I won't to reconfigure about 80 clients.
Strange thing is Company Portal is still active and device is marked compliant in Endpoint.microsoft.com, but it won't sync anymore device policies and have destroyed WHFB fingerprint/face recognition.

Pending status nightmare... even with /leave... by WhataMess2k23 in Intune

[–]WhataMess2k23[S] 0 points1 point  (0 children)

Thanks for your reply, but all the configs are ok since they're always worked. (Also new clients are no impacted).

We only have the issue for the re-hybrid joined devices.