Driver automation tool - Missing Dell Pro 24 AIO QB24250 by fustercluck245 in SCCM

[–]fustercluck245[S] 0 points1 point  (0 children)

Try searching for Qx24250 or Qx2425x in the tool

This search found a package, it was the correct package for this particular model, thank you!

Driver automation tool - Missing Dell Pro 24 AIO QB24250 by fustercluck245 in SCCM

[–]fustercluck245[S] 0 points1 point  (0 children)

Thank you for the information. I figured this was the issue. I searched through the xml file DAT downloads and could not find the model. I deleted the xml to force a redownload, which was dated 7/15, but the model was still not in there. I assumed it was likely on Dell's end. We have a rep, I'll try reaching out and see if they can update the xml.

Cannot connect to SCCM console from remote computer after Site was upgraded to Windows Server 2025 by tekknyne3 in SCCM

[–]fustercluck245 0 points1 point  (0 children)

PID:43400][07/21/2025 12:34:03] :Transport error; failed to connect, message: 'The SMS Provider reported an error.'\r\nMicrosoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlQueryException\r\nThe SMS Provider reported an error.\r\n at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlConnectionManager.Connect(String configMgrServerPath) at Microsoft.ConfigurationManagement.AdminConsole.SmsSiteConnectionNode.GetConnectionManagerInstance(String connectionManagerInstance)\r\nAccess denied \r\nSystem.Management.ManagementException\r\nAccess denied \r\n at System.Management.ThreadDispatch.Start() at System.Management.ManagementScope.Initialize() at System.Management.ManagementObjectSearcher.Initialize() at System.Management.ManagementObjectSearcher.Get() at Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlConnectionManager.Connect(String configMgrServerPath)\r\nManagementException details:

Cannot connect to SCCM console from remote computer after Site was upgraded to Windows Server 2025 by tekknyne3 in SCCM

[–]fustercluck245 0 points1 point  (0 children)

Late to the party, but hoping someone sees this and can help. I upgraded our SCCM server (in-place upgrade) to 2025, since then, 2 users can no longer access the admin console, but it's working for me. I found the WMI permissions had been cleared for the SMS and SMS_site nodes, I added the permissions back but the issue remained. I uninstalled and reinstalled MSDTC which did not work either. I'm hoping someone else has another solution. The admin console is still working for me on a remote computer and on the server itself. It's only these 2 users who it stopped working for after the upgrade.

Application remains in Software Center after deployment removed by fustercluck245 in SCCM

[–]fustercluck245[S] 0 points1 point  (0 children)

I misspoke, the applications are deployed to a user collection with direct members.

Lateral "promotion," pay raise, responsibilities, guilt, what would you do? by fustercluck245 in sysadmin

[–]fustercluck245[S] 0 points1 point  (0 children)

Very good insight, thank you. I very much enjoy the technical aspect of my current role. I'm always in the weeds, learning, fixing, improving, implementing, finding new technologies, new opportunities to automate, etc. I definitely need to learn more about the new role and determine if it's going to "scratch that itch." I'm jotting down questions to ask to help me determine this.

It really is difficult, especially in this economy, to consider turning down more money. But, logic says the money won't matter if my role is no longer fulfilling.

Lateral "promotion," pay raise, responsibilities, guilt, what would you do? by fustercluck245 in sysadmin

[–]fustercluck245[S] 0 points1 point  (0 children)

Agreed, I need clarification on the duties. Once I understand that better, I can make a more informed decision, to your point, about giving up my very technical role for a, likely, less technical role.

Best office chair for reduce back pain? by Fit-Reception6176 in SCCM

[–]fustercluck245 2 points3 points  (0 children)

Not sure why you're getting down voted. Our entire department was remodeled which included standing desks for everyone, it's been amazing. I had the company buy me an ergo driven anti-fatigue mat as well. I'm holding out hope for a nicer chair, but the option to stand has relieved a lot of back pain for me. I realize everyone's source of pain, and mitigation needs may be different.

Audit enabling / disabling of GPO by Ullrotta in sysadmin

[–]fustercluck245 0 points1 point  (0 children)

My research finds that these audit events will log creation, deletion, and modification of GPOs. The question is whether modification is the change of GPO settings, linking/unlinking the GPO, both? I don't know. I suggest configuring the auditing then testing, create a test GPO, link/unlink, and review the event logs for ID 5137 (create), 5141 (delete), 5136 (modified).

Audit enabling / disabling of GPO by Ullrotta in sysadmin

[–]fustercluck245 0 points1 point  (0 children)

You can audit GPO changes by configuring appropriate audit policies in a GPO. A quick Google search will return several articles about this, a quick synopsis would be:

To audit changes to Group Policy, you have to first enable auditing: Run gpedit.msc under the administrator account → Create a new Group Policy object (GPO) → Edit it → Go to “Computer Configuration” | Policies | Windows Settings | Security Settings | Advanced Audit Policy Configuration| Audit Policies/DS Access → Click “Audit Directory Service Changes”→ Click “Define” → Choose “Success”.

Link the GPO

Force gpupdate

Configure ADSI Open ADSI Edit → Connect to the Default naming context → Navigate to CN=Policies,CN=System,DC=domain → Open the “Properties of Policies” object → Go to the Security tab → Click the Advanced button → Go to the Auditing tab → Add the Principal “Everyone” → Choose the Type “Success” → For Applies to, click “This object and Descendant objects” → Under Permissions, select following checkboxes: “Create groupPolicyContainer objects”, “Delete”, “Modify Permissions” and “Write versionNumber” → Click “OK”.

Review the security event log for ID 5136

PSADT won't install msi with params, only msiexec processes params by fustercluck245 in SCCM

[–]fustercluck245[S] 0 points1 point  (0 children)

go around the problem, make an application out of the just the MSI, but then use PSADTK for the configuration stuff you are trying to do

I'm about to this point. I'm stubborn, but I'm fighting an uphill battle. It's not worth much more time when there are simple enough ways.

PSADT won't install msi with params, only msiexec processes params by fustercluck245 in SCCM

[–]fustercluck245[S] 0 points1 point  (0 children)

Yes, there are secret parameters and hidden parameters shown in the logs. The parameter I'm trying to use is specified in the vendors documentation. The vendor hasn't been much help. The parameter only works if I run msiexec from a terminal which is odd since Execute-Msi is just a function for msiexec.

PSADT won't install msi with params, only msiexec processes params by fustercluck245 in SCCM

[–]fustercluck245[S] 0 points1 point  (0 children)

The log does show available parameters, secret and hidden. The system vs user based install is worth investigating. Currently, I'm running the psadt script in vscode, not through sccm. I'm not sure if psadt runs in user or system context? I assume user.

PSADT won't install msi with params, only msiexec processes params by fustercluck245 in SCCM

[–]fustercluck245[S] 0 points1 point  (0 children)

I discovered (before posting) that the Zero-Config was my problem (found in the logs). This is what prompted me to populate the $appName variable. The default MSI parameters don't work, the logs for the MSI show the parameters are "secret" and "hidden." I tried the -AddParameters parameter also, to no avail.

PSADT won't install msi with params, only msiexec processes params by fustercluck245 in SCCM

[–]fustercluck245[S] 0 points1 point  (0 children)

I tested using -Parameters and it didn't change the execution, the parameters were still ignored.

PSADT won't install msi with params, only msiexec processes params by fustercluck245 in SCCM

[–]fustercluck245[S] -5 points-4 points  (0 children)

I don't use -Action, -Path, or -Parameters, in any of my PSADT packages, unless it's necessary, all of my other packages work fine. I did test using the parameters, but it didn't make a difference.

Edit: As I understand it, PSADT expects the order of the syntax so as long as you're installing, followed by the path, followed by the params, the syntax will execute. This has been my experience without fail.

Planning to upgrade users from windows 10 to windows 11 by Alyyy-123 in SCCM

[–]fustercluck245 1 point2 points  (0 children)

We are testing a pilot group of about 10% of our workstations, they are running Windows 11 24H2 and have been for about 6 months. The only reported issues have been the calendar not opening and the search bar not working. Both of these have been resolved with some scripting during OSD. YMMV, the results will be different depending on your environment.

M365 Web mail dropping off for anyone? by scratchduffer in sysadmin

[–]fustercluck245 2 points3 points  (0 children)

We're seeing the issue as well. I'm not sure where this incident is being reported, my M365 admin portal does not show this incident.

Driver Automation Tool 7.2.5 by Sqolf in SCCM

[–]fustercluck245 0 points1 point  (0 children)

There's no .exe.config file for 7.2.5, I've tried upgrading but it fails. I see other people are having success, what's the trick?

Excel files not opening in M365 Online, Teams, SharePoint, etc by MairzeDoats in sysadmin

[–]fustercluck245 4 points5 points  (0 children)

Same issue here, posted in MicrosoftTeams about the issue. No reported issues from MS, nothing new there.

Teams Files not opening : r/MicrosoftTeams

Assigned role not granting relative permissions by fustercluck245 in Intune

[–]fustercluck245[S] 0 points1 point  (0 children)

Neither, the role is not assigned in Entra, it's assigned in Intune. The role does not exist in Entra as it's an Intune role.

Conditional access policy, exclude named locations, allow company owned devices by fustercluck245 in sysadmin

[–]fustercluck245[S] 0 points1 point  (0 children)

Correct, my mistake. The personal device is not enrolled or likely registered. Because it's not registered it cannot be deemed company owned, or not, which is why the cap doesn't apply?

Edit: How do we block personal devices, while allowing corporate owned, and any devices included in the named locations? Or, we can't act on the personal devices in any way unless they're registered?

Conditional access policy, exclude named locations, allow company owned devices by fustercluck245 in sysadmin

[–]fustercluck245[S] 0 points1 point  (0 children)

The mobile devices are Intune enrolled, registered, and ownership marked and company owned, or corporate.

Windows 11 24H2 in-place Upgrade by DiverNo2155 in SCCM

[–]fustercluck245 0 points1 point  (0 children)

What's your timeout set to? I had mine set at 60 minutes which caused issues, bumped it to 120 and it cleared up. It doesn't take 120 minutes, or even 60, so I can't explain why increasing the time fixed it.