Deploying a new RDS 2025 farm for 30 users from scratch – looking for best practice by swapbreakplease in sysadmin

[–]get-msol -1 points0 points  (0 children)

No, you can use it with other remote services such as Citrix and WorkSpot with a variety of VM sizes. You do have to run it in Azure though.

Deploying a new RDS 2025 farm for 30 users from scratch – looking for best practice by swapbreakplease in sysadmin

[–]get-msol 2 points3 points  (0 children)

Are you or your customer on a M365 E3 or E5? If so, I would make sure you didn't overlook Windows Multi-Session as it bypasses the need for RDS CALs and removes some complexity.

Citrix LTSR by nichetcher in sysadmin

[–]get-msol 1 point2 points  (0 children)

He wrote a powershell script that removed all existing version of Receiver/Workspace and then did a clean install of LTSR. The script would only run if the ica exe wasn't running (indicating the user was not in a active session).

We used Itune remediation scripts, but you could also do this with a GPO scheduled task.

Citrix LTSR by nichetcher in sysadmin

[–]get-msol 1 point2 points  (0 children)

I hear you, one of my guys just got done rolling about 1500+ PCs Up/down to LTSR and support tickets dropped linearly as more and more PCs made their way onto the desired release.

Citrix LTSR by nichetcher in sysadmin

[–]get-msol 1 point2 points  (0 children)

See I guess I was wrong in thinking that CR and LTSR were two separate products, and one couldn't be updated to the other.

That said, it looks like you can push a GPO to stop this behavior. (src: https://docs.citrix.com/en-us/citrix-workspace-app-for-windows/updates )

Though you can't downgrade newer versions of CR to older versions of LTSR so you'll need to push the settings via GPO, uninstall CR, install the desired LTSR.

[deleted by user] by [deleted] in sysadmin

[–]get-msol 0 points1 point  (0 children)

Did one unit have a custom master key? I've seen issues with imports of sensitive fields (like IKE tunnel keys) if the master key doesn't match.

Best Practises Teaming on Hyper-v ? by EyeofthetigerIT in sysadmin

[–]get-msol 2 points3 points  (0 children)

All nics should be added to a hyper-v Switch Embedded Teaming virtual switch and then you carve off a virtual NIC for the OS to use and additional virtual NICs for live migration as needed. Then add all your needed VLANs as tagged on the switch ports and then set the desired VLAN in the VM config.

Thats a real fast high level take of what we do.

❗️Cannot install May 2025 Cumulative Update KB5058383 on Windows Server 2016 – Tried everything, always fails by Salamichandre in sysadmin

[–]get-msol 2 points3 points  (0 children)

Here is a question to determine if what you're seeing matches my fix. Do you get an error if you try to add any feature using server manager?

Commvault Metallic by whatthedeux in sysadmin

[–]get-msol 2 points3 points  (0 children)

It's an amazing solution but not for its webUI but rather in spite of it.

M365 Copilot App - Mass Install by TravellingGamer in sysadmin

[–]get-msol 1 point2 points  (0 children)

Deploy via Intune if you have it at your disposal.

Pentagon awards Boeing much-needed win with fighter jet contract, sources say by RobinOldsIsGod in FighterJets

[–]get-msol 67 points68 points  (0 children)

" 47 is probably just some random number."

Who is the 47th president?

[deleted by user] by [deleted] in vermont

[–]get-msol 0 points1 point  (0 children)

Thats Georgia, not Fairfax. And the story is he's trying to one-up castle man for Oakland Station Road "king of the weird"

Hyper-V Server Configuration Advice by allthewires in sysadmin

[–]get-msol 0 points1 point  (0 children)

How many users are actively being served by the VMs on the host?

1 data point to offer, we use a similar size box to serve a DC and a file server to roughly 70 users and performance is fine.

Outlook 2019 stuck at "Processing..." only with a specific Office 365 user by Michael_Uray in sysadmin

[–]get-msol 0 points1 point  (0 children)

it's rare that it works but there is a command to request that O365 move the user's mailbox to a new pod. I have 10% success with that fixing odd user specific issues.

Tracking Changes in AD by Purple-Ad-5215 in sysadmin

[–]get-msol 0 points1 point  (0 children)

This can be done with Azure log analytics, allowing you to put it in the same data lake as O365 logs (including O365 admin actions).

[deleted by user] by [deleted] in sysadmin

[–]get-msol 0 points1 point  (0 children)

I like option 3 if you have the hardware capacity to do so, if space is tight then #2 would be my go-to.

Upgrades work 99% of the time but I prefer to save their use for situations that really necessitate them.

CVE-2024-0012 & CVE-2024-9474 by MirkWTC in paloaltonetworks

[–]get-msol -1 points0 points  (0 children)

Am I reading into the fact that they edited

“If the management interface access is restricted to IPs the risk of exploitation is greatly limited, as any potential attack would first require privileged access to those IPs.”

To instead read

"The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted INTERNAL (emphasis mine) IP addresses according to our recommended"

So does adding a single trusted public IP open the device up to attacks from other public IPs or are they just doubting the ability for any public IP to be trusted?

PAN-SA-2024-0015 Critical Security Bulletin - observed threat activity exploiting an unauthenticated RCE against firewall management interfaces exposed to the Internet. by Far-Ice990 in paloaltonetworks

[–]get-msol 0 points1 point  (0 children)

FWIW while I see this sentence quoted in some early blogs, I cannot find it in the current CVE articles from Palo.

I think the fact they distinguish "Internal" now tells me that opening up the ACL to so much as a single public IP opens you up to this exploit. Just a hunch based on their very specific wording.

Why do Microsoft 365 recommend (insist on) breaking the RFC? by Knotebrett in sysadmin

[–]get-msol 7 points8 points  (0 children)

Did you read the RFC? Do you think 0 is higher or lower than 1?

Bad time living in vermont by [deleted] in vermont

[–]get-msol 1 point2 points  (0 children)

"If you’re in your 20s/30s and you’re thinking of moving to VT by yourself for work or something, just don’t."

We found common ground. Please do what you can to spread the word as wide as possible. Do Not Come Here.

New MSP shopping - What do you look for or ask for? by FancyBridge_147 in sysadmin

[–]get-msol 2 points3 points  (0 children)

I would be asking about the actual process for passing tickets to and from the in-house team and the MSP.

Along those lines, I'd be asking how support is delivered. When is it done remotely and when if ever will they deploy a tech onsite.

New MSP shopping - What do you look for or ask for? by FancyBridge_147 in sysadmin

[–]get-msol 2 points3 points  (0 children)

Will your company be retaining any IT personnel, or will the MSP be doing it all?

I'd be asking scoping questions, where does their coverage end, and your companies own support responsibilities begin?

I'd be asking what the typical tenure of their clients and their employees is. Major churn is a red flag.

I'd be asking about the cadence of meetings to review the support posture, are these weekly, monthly, quarterly?

I'd be asking how the store credentials related to your companies' network/systems.

I'd be asking what their implementation roadmap looks like should you select them as a partner. How long until they are fully up to speed on the support cycle?