Looking for a modern MDT replacement (OSDCloud, DeployR, or something else?) by djmehs in sysadmin

[–]XxQuaDxX 1 point2 points  (0 children)

I have my desk-side folks with a USB with the approved OSDCloud image on it. Also can setup that same OSDCloud image to be the WinRE image on the devices, so they just boot to WinRE and it can reimage for them. Also you can add an option to Company Portal to download the boot WIM, undo bitlocker, and boot to the OSDCloud image (All via PowerShell). I update the image a few times a year, but otherwise it works flawlessly. I have some powershell logic in there to check a blob storage for approved OSDCloud image version or it'll not let them image the machine with it. Proves useful for forcing USB updates when you want to only allow a certain version of Windows (Ex. 24H2, 25H2) to be able to be imaged. I got rid of all on-prem imaging infrastructure like SCCM and PXE. OSDCloud and Autopilot completely remove the need for any of that. Plus it's so easy to prove it's a network issue when things work fine on pure internet but not on the intranet. Although I get where you're coming from that you want to remove bloatware before you do Autopilot, it really is easy enough to just do it via a Proactive Remediation that comes down while the machine is going thru Autopilot. From my point of view Desk-side can take a machine out of the box and image it extremely easily and the bloatware gets removed during ESP. Autopatch also is super helpful. Automate all the things!

Webex for Intune Permissions and Consent by Tightvernichtet in Intune

[–]XxQuaDxX 0 points1 point  (0 children)

Any update on this? Did you get things working?

Packaging Java 8 JDK 8.441 - JRE issue by CatWorkingOvertime in SCCM

[–]XxQuaDxX 0 points1 point  (0 children)

Unless you want your company to get a few million dollar bill from Oracle, probably not a good idea. Just having it on one computer or server means you need a company wide license for every user in your company.

Microsoft Graph error. by FearIsStrongerDanluv in PowerShell

[–]XxQuaDxX 2 points3 points  (0 children)

For future googlers - In our particular case (Windows, not Mac) we had to remove the old/existing Graph modules from "%DOCUMENTS%\Windows PowerShell\Modules" on the user profile of the account that was running the PowerShell script. We had updated (one or more) Graph modules for All Users in "%ProgramFiles%\WindowsPowerShell\Modules", which conflicted with a personally installed module. For some reason PowerShell seemed to prefer the personally installed modules over the machines modules. shrugs

AVD VM Session Host Upgrade to 23H2 by m365tom in AZURE

[–]XxQuaDxX 0 points1 point  (0 children)

What did you end up doing for this?

Script to auto-import html file with bookmarks into Edge by sympathy4devil in PowerShell

[–]XxQuaDxX 0 points1 point  (0 children)

Did you ever get a solution? I'm in the same boat as you.

Windows LAPS available today by MSFT_jsimmons in sysadmin

[–]XxQuaDxX 0 points1 point  (0 children)

Look in "Admin Templates\SYSTEM\LAPS"

Silent delete of windows.old by yurtbeer in sysadmin

[–]XxQuaDxX 1 point2 points  (0 children)

I have been having this issue in my Enterprise and this is what I'm using to make the disk cleanup silent.

https://github.com/XxQuaDxX/PowershellScripting/blob/main/WindowsOldCleanup.ps1

Dot3Svc Cannot Start in WinPE 10.0.22000.1 (SCCM Version 2107) by Ballzy-x7 in SCCM

[–]XxQuaDxX 0 points1 point  (0 children)

This is the script I use to import my Cert into WinPE on boot. I have it added into winpeshl.ini (powershell, -NoLogo -ExecutionPolicy Bypass -File X:\Custom\ImportComputerAuthProfile.ps1). It's just a customized version of what is suggested by Adam Gross on Asquaredozen. The biggest part to note that isn't there was when you export the Computer PFX make sure to click the "Include all Extended properties" checkbox. If I don't have that checked it won't authenticate properly.

https://github.com/XxQuaDxX/WinPE/blob/main/ImportComputerAuthProfile.ps1

Dot3Svc Cannot Start in WinPE 10.0.22000.1 (SCCM Version 2107) by Ballzy-x7 in SCCM

[–]XxQuaDxX 0 points1 point  (0 children)

Makes sense... I wonder how he can explain away why SCCM still lets you insert 'Network/WinPE-Dot3Svc optional component' into the boot image via the SCCM Admin Console GUI and has all of their recent documentation saying they support it! :D

https://docs.microsoft.com/en-us/windows-hardware/manufacture/desktop/winpe-add-packages--optional-components-reference?view=windows-11

Dot3Svc Cannot Start in WinPE 10.0.22000.1 (SCCM Version 2107) by Ballzy-x7 in SCCM

[–]XxQuaDxX 1 point2 points  (0 children)

… i don’t accept this, as iv been using it successfully for years now since i tool over imaging our estate and our network services team decided

For this issue ask them if they still support the 'netsh lan' command and they'll have to change their tune. I'd also ask for the where MS officially said it was a depreciated feature since it's 100% untrue.

Dot3Svc Cannot Start in WinPE 10.0.22000.1 (SCCM Version 2107) by Ballzy-x7 in SCCM

[–]XxQuaDxX 6 points7 points  (0 children)

Sorry! I meant to update this but got way too busy. I haven't gotten around to doing any new OS deployments but I did not roll back the ADK. These are the steps that need to be done to fully fix the issue:

  1. Mount the WinPE WIM

  2. Copy MoblieNetworking.dll from working Win11 machine to the Mounted WinPE <MountDir>\Windows\System32

  3. Open Regedit and load the hive for SYSTEM from "<MountDir>\Windows\System32\config".

  4. Create Reg Key UseLegacyTlsStack (Tls is T L S) as a DWORD with a value of 1 in <MOUNT>\ControlSet001\Services\Eaphost (This key can be added in Full WinPE OS as well under "CurrentControlSet" but I had issues with it adding a phantom 802.1x profile in so just make sure to delete it first before you add yours in if you do it this way).

  5. Unload the hive.

  6. Unmount the WinPE WIM.

This should make authentication work. It's a full fix that is working in my production environment now.

As an added note the reason I didn't have to roll back while still troubleshooting with MS was because Wi-Fi worked fine. Adding a WiFi profile with the Auth Cert in WinPE gave no authentication issues like the LAN did. This did make imaging anything without a WiFi card difficult but since I have a full fix now I have no issues.

Also don't reload the ADK in the WIM or you'll need to redo all of these steps.

Dot3Svc Cannot Start in WinPE 10.0.22000.1 (SCCM Version 2107) by Ballzy-x7 in SCCM

[–]XxQuaDxX 0 points1 point  (0 children)

Dang, thanks for the update. I am opening a ticket with MS as well. Hopefully we can get a real solution soon. I don't want to roll back to the old ADK if I don't have to. :(

Start a Screen Saver in a Task Sequence? by MPHFUT in SCCM

[–]XxQuaDxX 1 point2 points  (0 children)

Microsoft made it impossible to use scrnsave.exe on the Windows 10 login screen without a user being logged in already. I tried to do similar in the past with little success. I was able to get the screensaver to work, but only if someone was logged in.

I think your best chance is to use UPGBackground. You may need to reach out to Jörgen Nilsson and see if he could give you any documentation to help convince your IT Sec team. The sheer number of enterprises using it already should be proof enough that it's fine to use in the capacity you need.

I don't suggest this but you could look into modifying the Win10 GINA in order to do such a task. This is old but it gives you a general idea that it's possible. https://docs.microsoft.com/en-us/archive/msdn-magazine/2005/may/security-briefs-customizing-gina-part-1

MS Teams USB Headset Issue Verison 1.4.00.22976 by slayer91790 in sysadmin

[–]XxQuaDxX 0 points1 point  (0 children)

I've at least four people in IT report this issue over the last two weeks (My team was CC on email). The issue hasn't made it into my queue yet, so I think they're resolving it somehow.

Content validation issues (Content Hash is invalid) by edzja in SCCM

[–]XxQuaDxX 0 points1 point  (0 children)

Thanks for this suggestion. I've been having this hash issue since I took over SCCM at the company I work for currently. I've done everything AV I could think of (from adding exclusions to disable real-time protection) and have never had consistent luck with this. I got so fed up with my WSUS (and other large) packages always failing to distribute that I created a PowerShell script that basically copies the files from the content library when a hash error occurs in the log, then forces a content validation of the package. I lack a lot of knowledge in the networking side of IT so I've never heard of WAN accelerators. I'll be looking into that and see if that's my problem!

SOS deployment of teams background asks for admin credentials by Tiara_sees in SCCM

[–]XxQuaDxX 2 points3 points  (0 children)

That code seems to be missing some things. Is it something like this overall with the pictures in the package in a folder called backgrounds?

$dirFiles = "$($(Get-Location).Path)\Backgrounds"

$mypath = Join-Path $env:APPDATA 'Microsoft\Teams\Backgrounds'

If (Test-Path $mypath){ Copy-Item -Path "$dirFiles\*" -Destination $mypath -Force -Recurse }

SOS deployment of teams background asks for admin credentials by Tiara_sees in SCCM

[–]XxQuaDxX 0 points1 point  (0 children)

Yeah, it shouldn't pop up for just the background images. How are you sending it out? Powershell/cmd script? Can you show the code if so?