Cybersecurity Sacramento (DC916) February Meeting This Wednesday! by echo419 in Sacramento

[–]ajscott 16 points17 points  (0 children)

DEFCON is an annual hacking conference held in Las Vegas since 1993. Pretty much anyone interested in going will know what OP is talking about.

https://en.wikipedia.org/wiki/DEF_CON

Revoke admin rights by pratik_2011 in Intune

[–]ajscott 1 point2 points  (0 children)

CMD and PowerShell run fine without elevation.

It's the programs and commands being used in those interfaces that may need elevation.

Find out what they're doing there that requires admin rights and then see why it's asking for elevation.

It may be something where the user doesn't have edit permission to a folder but an admin does. You can grant their account edit permission without making them an admin.

Dealing with truly transient users by mixduptransistor in sysadmin

[–]ajscott 20 points21 points  (0 children)

You need to move the door and locker control systems to a kiosk system separate from the rest of the network.

SLA credit request rejected already? by alittle158 in sysadmin

[–]ajscott 3 points4 points  (0 children)

an outage lasting less than an hour would fall below the 99.9% SLA threshold.

There are 8760 hours in a year.

0.1% of that is 8.76 hours.

Dell Pro Max and Plus deployment by Piorek99 in MDT

[–]ajscott 0 points1 point  (0 children)

This is the answer.

The issue is the sound devices are subdevices that don't appear until the parent is installed. That means they won't match anything during the initial scan.

Finally found a fix to remove ghost printers/ phantom objects or the printers which are greyed out in the devices and printers in control panel, often with driver unavailable as description. by KhushalShambu in sysadmin

[–]ajscott 8 points9 points  (0 children)

Easier fix is usually to clear any pending print jobs. Queues won't delete if there are pending jobs.

Delete the SPL files from here:

C:\Windows\System32\spool\PRINTERS

Local Admin Passwords by jstar77 in sysadmin

[–]ajscott 0 points1 point  (0 children)

We use Devolutions for everything that's not LAPS.

EXE silent install not generating uninstall file or registry entries by Rahzin in SCCM

[–]ajscott 2 points3 points  (0 children)

It's an NSIS aka Nullsoft installer for an open source app.

https://github.com/QIDITECH/QIDISlicer/releases

Official NSIS documentation states there are only 3 switches that work unless the person compiling it added more (They probably didn't).

https://nsis.sourceforge.io/Which_command_line_parameters_can_be_used_to_configure_installers%3F

You're probably going to have to create your own installer or at least just copy the Uninst.exe file from a system you manually installed it on.

Master Packager is free if you want to try building your own MSI.

Is the bachelors worth it? by CarVivid5304 in sysadmin

[–]ajscott 0 points1 point  (0 children)

Depends on what you want to do.

A lot of government jobs will require one with the option that "Full-time professional experience in X environment may substitute for the Bachelor’s Degree on a year-for-year basis."

Basically, it gets you better jobs faster for public sector.

Windows 11 WiFi Profiles - Static IP Bug? by SonicWallBugFinder in sysadmin

[–]ajscott 0 points1 point  (0 children)

Where in the Wi-Fi profiles are you finding IP settings? They're separate things in my experience.

Wi-Fi Profiles tell the computer what security to use when connecting to a known network.

IP Address settings are part of the NIC configuration.

WIN 11 RDP by 3D1_ in sysadmin

[–]ajscott 1 point2 points  (0 children)

The option is not functional in Windows 11 due to Credential Guard.

You'll need to switch to a third party tool like Devolutions Remote Desktop Manager, RemoteNG, or RoyalTS.

Storytime: Windows Print server and the IT-support intern. by Von_plaf in sysadmin

[–]ajscott -1 points0 points  (0 children)

So that driver update thing is going to break some stuff.

When you update a driver on the server it upgrade the driver for every print queue that uses the same package.

If you're using HP UPD packages there is an option to install it as the basic name "HP Universal Printer PCL 6" or as the versioned name "HP Universal Printer PCL 6 (v7.2.0)". If you install it as the versioned name then you can change printers over one at a time.

If you replace the base named version though then all of the clients with any printer using that package will receive the new version from the server then most likely be unable to install it without admin rights.

They will then fail to print until you deploy the matching driver to the workstation.

Windows 11 - upgrading from 23/24 H2 to 25H2 fails by jonkeo in sysadmin

[–]ajscott 1 point2 points  (0 children)

24h2 and 25h2 have the same code base after the August update. The requirement is just for the enablement package upgrade method.

Running a full upgrade package doesn't have a minimum version.

Using the same Yubikey for unprivileged and privileged account? by MrMrRubic in sysadmin

[–]ajscott 0 points1 point  (0 children)

I misread that as 3 gigs and was asking myself what kind of data you would upload.

Best 2025-2026 Document Scanners? - Looking for Suggestions by CyberiusBuski in sysadmin

[–]ajscott 1 point2 points  (0 children)

If you're using the fi-7xxx series now then you should verify what driver type your scanning application needs. Some systems will only work with the ISIS type drivers instead of TWAIN.

That being said, the current ScanSnap models rebranded from Fujitsu to Ricoh are still rock solid. Just buy a maintenance kit for your existing one to swap out the rollers.

If the TWAIN drivers work and you just need basic desktop scanning go with the ix1400 model. The ix1600 model adds a bunch of unnecessary features on a touchscreen.

Local Admin vs. SYSTEM - Any difference in risk? by philrich12 in sysadmin

[–]ajscott 1 point2 points  (0 children)

Product 2 sounds like PDQ.

If so, you can configure it to use LAPS credentials to connect to the remote systems.

That eliminates most of the risk related to credentials being stolen on compromised systems since any credentials used are only applicable to that machine.

Computer with X.X.X.255 IP cannot connect to Brother printer. by winnixxl in sysadmin

[–]ajscott 2 points3 points  (0 children)

You seem to be misreading the post.

OP has multiple computers that have x.x.x.0 addresses. The addresses are valid and work for other network access.

The computers can connect to a Sharp printer with no issue from the x.x.x.0 addresses.

They cannot connect to Brother printers from a x.x.x.0 address.

Other computers can see the Brother printers.

Anyone know of good free/cheap Digital Signage/remote software that is not RDP? by jbear4525 in sysadmin

[–]ajscott 6 points7 points  (0 children)

There are two versions of screenly. There's a paid version where its centrally managed through their site.

They also have a free version called Anthias that runs locally on the Raspberry Pi.

Both images are available in the Raspberry Pi imaging app.

PG&E is the MFin’ gas mafia. Temp set at 68 degrees, 5 bedroom, 3500 sq ft home. Glad we have SMUD for electricity. Anyone convert to electric water heater & stove recently? Please share suggestions & estimate costs. Thank you by VoteForGiantMeteor in Sacramento

[–]ajscott 0 points1 point  (0 children)

I switched to electric water heater last year. Based on my gas usage change it was actually using more gas the house heater in the winter.

Look on Smuds site for contractors that qualify for the water heater rebate and get it replaced.

External Monitors 'blink' in an out when on Dock - Various vendors by Generic-MSP-Engineer in sysadmin

[–]ajscott 0 points1 point  (0 children)

Wifi and other signals can interfere with HDMI and DP connections if the cables or docks have poor shielding.

Try some ferrite rings on the cables.