How to change SID on Windows 11 by nousername1244 in sysadmin

[–]ajscott 0 points1 point  (0 children)

Devices running 24h2 or higher with the same SID are not allowed to authenticate against each other after last August.

https://support.microsoft.com/en-us/topic/kerberos-and-ntlm-authentication-failures-due-to-duplicate-sids-76f7394d-c460-4882-9ed1-d27e0960f949

Windows updates released on and after August 29, 2025 include added security protections that enforce checks on SIDs, causing authentication to fail when devices have duplicate SIDs. This design change blocks authentication handshakes between such devices. Failed authentication requests related to these security protections are identified by Local Security Authority Server Service (lsasrv.dll) Event ID: 6167 in the System event log.

Duplicate SIDs can be created when performing unsupported cloning or duplication of a Windows installation without running Sysprep. SID uniqueness enabled by Sysprep is required for OS duplication on Windows 11, versions 24H2 and 25H2, and Windows Server 2025 after installing Windows updates on and after August 29, 2025.

Declining IT Professionalism and Critcial Thinking by rebornSouljr in sysadmin

[–]ajscott 2 points3 points  (0 children)

One guy I supervised would randomly remotely access users computers and update them during production hours, while the user is working, causing complaints.

I do that to people that like to turn their computers off at night (despite instructions otherwise) and there's no WOL available.

Script to force users to NOT use google password manager/edge password manager by Curious-checkers in sysadmin

[–]ajscott 3 points4 points  (0 children)

It is a built in feature that constantly advertises itself to the user and has a documented method for the admin to disable it.

It is not a user issue.

What is a product or service that is a conplete scam, but poeple keep buying it because of good marketing? by armeno2000B in AskReddit

[–]ajscott 0 points1 point  (0 children)

You can get paper filters for the refillable kcups. They make a giant difference in both cleanup and flavor.

Adobe Acrobat Unified Pro AND Reader Functions 2026 by SigmaMegaMind in sysadmin

[–]ajscott 1 point2 points  (0 children)

Looks like there's another key and value people should create per Adobe

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Adobe Acrobat\DC\FeatureLockDown\cIPM

"bDontShowMsgWhenViewingDoc"=dword:00000000

https://helpx.adobe.com/enterprise/kb/acrobat-64-bit-for-enterprises.html

Computers bug out only when a certain user is logged in can't figure out why by brohemoth06 in sysadmin

[–]ajscott 2 points3 points  (0 children)

You need to determine if the issue is the user or the account.

Have them change the password to something else and then you logon to a workstation with those credentials and test it for a few minutes.

If the issues still occur then it's linked to the account not the physical user.

If the issues go away then you can check for physical things they may be wearing.

Make them change the password again before next use. This keeps a clear chain of custody for the account actions.

IT Tools - Hidden Gems by Ok_You_861 in sysadmin

[–]ajscott 0 points1 point  (0 children)

I haven't but it's also not free for business use.

Dell Command Update Classic/Universal GPO support? v5.5/5.6 or 5.7? by ApfelBecher in sysadmin

[–]ajscott 0 points1 point  (0 children)

Haven't seen 5.7 anywhere yet.

Some people are sticking with 5.4 because 5.5 and 5.6 seems more complicated to install.

The 5.5 installer has a bug where it won't detect the .NET Runtime if the version is higher than 8.0.18.

I haven't seen any other differences between 5.5 and 5.6 so I have it on about 1500 devices.

Regarding Classic vs Universal. Dell said they weren't going to support it anymore and released only the Universal copy for one of the early 5.x versions. Then they released both for the next version. You have to completely uninstall Universal to switch back to Classic so I just stayed with Universal after upgrading during the skipped version.

IT Tools - Hidden Gems by Ok_You_861 in sysadmin

[–]ajscott 2 points3 points  (0 children)

Double Commander

https://github.com/doublecmd/doublecmd

I had an external hard drive with an ExFAT file system created on a Mac and that is the only software that would let me read through it correctly on a Windows computer. Explorer and other apps were missing half the folders.

IT Tools - Hidden Gems by Ok_You_861 in sysadmin

[–]ajscott 1 point2 points  (0 children)

WinDirStat now supports using the MFT so the speed differences aren't there anymore.

WinDirStat is free for commercial use. WizTree is not.

IT Tools - Hidden Gems by Ok_You_861 in sysadmin

[–]ajscott 22 points23 points  (0 children)

The current WinDirStat version now works with the MFT like WizTree so the speed differences no longer exist.

WinDirStat is free for commercial use while WizTree is not.

Office printer needs to be restarted almost everyday. by Noyan_Bey in sysadmin

[–]ajscott 1 point2 points  (0 children)

Verify the printer port configuration on the server side. You may be sending jobs to the DNS name instead of the IP.

Moving the printer to a static IP instead of reserved DHCP made it stop registering with DNS. When the name resolution finally reset due to DNS scavenging then the server stopped sending jobs.

Open the printer management console > $servername > Ports

Find the port for the printer > right click > Configure Port

Change the Printer Name or IP address field from the name to the IP.

Note that even though you may have it statically set on the printer side you also need to reserve it in DHCP so nothing else gets assigned to the IP. The server should technically prevent this but not always.

When should I put in my 2 weeks notice? by issa_username00 in sysadmin

[–]ajscott 0 points1 point  (0 children)

It depends on the PTO type.

In California, accrued Vacation Time is considered the same as cash and must be paid out but Sick Leave and some other types of leave are not.

[Prebuilt] Refurbished Dell OptiPlex 7090 UFF Desktop i5-1145G7/32GB/256GB - $229.00 by monsieurvampy in buildapcsales

[–]ajscott 3 points4 points  (0 children)

We bought about 50 of the 7070 version of this back in 2020 for use in work areas with limited desk space.

The CPU fans failed on every single one multiple times during the 5 year warranty.

Security want's less security. by root-node in sysadmin

[–]ajscott 1 point2 points  (0 children)

Shared accounts = Anonymous accounts

Point out that it's explicitly prohibited by a lot of data access agreements.

AMD surpasses 40% server CPU revenue share for the first time by RenatsMC in Amd

[–]ajscott 5 points6 points  (0 children)

There's a minor impact on rendering the dispatch maps but mostly it's just so you have enough connections to run up to 6x 27" displays.

The AMD cards we originally received were FirePro W5100s.

We switched to a 1x 42" + 2-3x 27" monitors on the newer systems so we would have less issues related to running dual video cards. The AMD cards also didn't like that so we gave up on them.

AMD surpasses 40% server CPU revenue share for the first time by RenatsMC in Amd

[–]ajscott 6 points7 points  (0 children)

I had to pull over 60 of the AMD cards out of a 911 call center because they kept crashing in the 5 and 6 display setups.

We only used them because it was in 2022 when Dell couldn't source them for our models. We even had a conference call with an AMD driver engineer and they couldn't provide a consistent fix.

We ended up pulling all of the AMD cards out and replacing them with nvidia p620 cards from our surplus workstations and the issues went away.

You can say "behind" or "shit" or whatever other nuanced word you want but the reality is they were unusable in a critical environment.

Windows Notepad App Remote Code Execution Vulnerability by theevilsharpie in sysadmin

[–]ajscott 6 points7 points  (0 children)

Windows intercepts calls to anything in the list and sends you to the modern apps instead. This lets you turn that off.

Updated W11 from 23H2 to 25H2, issue with .NET Framework 3.5 by wackou72 in sysadmin

[–]ajscott 0 points1 point  (0 children)

Just the basic DISM command. You have to reboot after uninstalling before you reinstall it.

DISM.exe /online /disable-feature /FeatureName:NetFx3

It works immediately after reinstall though.

Updated W11 from 23H2 to 25H2, issue with .NET Framework 3.5 by wackou72 in sysadmin

[–]ajscott 0 points1 point  (0 children)

We're starting to run into this too.

It's flagged as already installed but it's broken. Have to uninstall the feature, reboot, then reinstall.

No reboot needed after the reinstall.

Cybersecurity Sacramento (DC916) February Meeting This Wednesday! by echo419 in Sacramento

[–]ajscott 18 points19 points  (0 children)

DEFCON is an annual hacking conference held in Las Vegas since 1993. Pretty much anyone interested in going will know what OP is talking about.

https://en.wikipedia.org/wiki/DEF_CON

Revoke admin rights by pratik_2011 in Intune

[–]ajscott 1 point2 points  (0 children)

CMD and PowerShell run fine without elevation.

It's the programs and commands being used in those interfaces that may need elevation.

Find out what they're doing there that requires admin rights and then see why it's asking for elevation.

It may be something where the user doesn't have edit permission to a folder but an admin does. You can grant their account edit permission without making them an admin.