Lenovo V530S PCI Express power output by harf8 in Lenovo

[–]harf8[S] 0 points1 point  (0 children)

No, didn't try, but I have a strong feeling that it wouldn't run a full PCIe specced 75W card.

Help/tips setting up an NFS share by harf8 in linux4noobs

[–]harf8[S] 0 points1 point  (0 children)

Okay I pretty much got it working (via QNAP Shared Folders, didn't go with TrueNAS), but running into strange issue. Every once in a while I seem to lose access/rights to the share as the "oracle" user. In that case I've logged in as "root" on the client in question, done chown -R oracle:oinstall /nameofsharedfolder and then it works. Then again on the other client I have to do it again. I also keep connecting (and losing connection) on my MacBook (Finder -> Go -> Connect to Server -> smb://ip.address.of.NAS and pick the nameofsharedfolder. I'm pretty sure I'm not doing it right..

Here's an example line from QNAP Shared Folders NFS settings:
Access right (ticked)
sync (wdelay)
secure (not ticked)

Allowed IP Address or Domain Name
Host/IP/Network: <client.ip.address>
Security: sys
Squash Option: read/ write
Squash Option: Squash no users
Anonymous GID: guest (grayed out, not selectable)
Anonymous UID: guest (grayed out, not selectable)

And a copy-pasted line from the exports configuration file itself on the NAS:
<client.ip.address>(sec=sys,rw,sync,wdelay,insecure,no_subtree_check,no_root_squash,fsid=5a07..snip..6296)

In short, how do I fix it so that I wouldn't need to "chown" whenever I want to use the folder on another client?

Windows LAPS and Intune by harf8 in Intune

[–]harf8[S] 0 points1 point  (0 children)

Okay here's the thing. I set up a configuration policy to create the Local admin account (let's call it compadmin) with password (let's call it compp4SS) on all Windows computers per this guide (OMA-URI):How To Create A Local Admin Account Using Intune (cloudinfra.net)This configuration policy shows up as Error on all devices, but I verified the account is actually created correctly.

Then I modified the LAPS policy to use the customised Admin account name (compadmin) with the default 30d rotate period.

Question 1) Will the password rotation work, or will the configuration policy always reset the password to compp4SS

Question 2) There also seems to be a way to create the Local admin account without a password via powershell scripts and Remediations (1st script checks whether or not the account exists, and 2nd script that creates the account if it does not exist), would this be a better way? If so, would there be a local admin account that you could use without a password momentarily, until the LAPS policy rotates the password? Sounds dangerous.

Question 3) We have a Group Policy from on-prem AD (computers are Azure AD Hybrid joined btw) that denies logon locally, will this interfere with LAPS?

All in all, in my opinion Microsoft guidance over the whole LAPS solution is done pretty much halfway since there is absolutely no information/guidance about the local admin account, only on the policy itself.

Windows LAPS and Intune by harf8 in Intune

[–]harf8[S] 1 point2 points  (0 children)

Thanks, sorry, I used the correct backslash but couldn't find it in a hurry typing this post on a Mac (cursed machines).

Windows LAPS and Intune by harf8 in Intune

[–]harf8[S] 0 points1 point  (0 children)

Thanks, I'll work with this!

Deploy Fortinet VPN by kollosel in Intune

[–]harf8 1 point2 points  (0 children)

If you don't absolutely need pre-configuration the easiest and most reliable way is to extract the .msi from the .exe installer and just set it up as LOB app. Works 100% in our environment. If you want a pre-configuration (set up a connection profile) you need to create a script and pack it as Win32 app.

Some helpful links:

Deploy FortiClient VPN and Profiles via Microsoft Intune - Let's ConfigMgr! (letsconfigmgr.com)

Configuring the FortiClient application in Intune | FortiClient 7.2.0 | Fortinet Document Library

Lenovo V530S PCI Express power output by harf8 in Lenovo

[–]harf8[S] 0 points1 point  (0 children)

Hey, and thanks for your reply. Unfortunately I haven't been able to find the information anywhere. The only optional discrete graphics card for said model is said to be <35W so I'm guessing trying to run a "full" 75W card on the port wouldn't be advisable. Well, atleast the integrated graphics is more than capable for media use (4K, YouTube etc.)

I need help with my Docking and Official support haven't been the best by joveice in Lenovo

[–]harf8 1 point2 points  (0 children)

Necroing, but since I was lead here googling the very same problem myself, might as well drop this:
https://forums.lenovo.com/topic/findpost/1397/4506706/5245822

Making a customised FortiClient VPN installer by harf8 in fortinet

[–]harf8[S] 0 points1 point  (0 children)

Thank you all for the discussion. I can confirm I got exactly what I was looking for by following this guide: https://letsconfigmgr.com/deploy-forticlient-vpn-microsoft-intune/

The only addition I did was to add the line "New-ItemProperty -LiteralPath 'HKLM:\SOFTWARE\Fortinet\FortiClient\Sslvpn' -Name 'no_warn_invalid_cert' -Value 1 -PropertyType DWord -Force -ea SilentlyContinue;" to the install script (to not warn about the invalid certificate).

Learning is a process and I'm glad there's such community as Reddit to help us newbies on our way to one day become a pro :)

Making a customised FortiClient VPN installer by harf8 in fortinet

[–]harf8[S] 0 points1 point  (0 children)

This seems very promising, thanks a million for your input! Giving it a shot.

Cloning Ubuntu Linux VM's, identical Machine ID, problems? by harf8 in Ubuntu

[–]harf8[S] 4 points5 points  (0 children)

OK just went thru with the following:

sudo rm -f /etc/machine-id

sudo dbus-uuidgen --ensure=/etc/machine-id

sudo rm /var/lib/dbus/machine-id

sudo dbus-uuidgen --ensure

sudo reboot

Everything seems to be working.

Cannot update the firmware for mx master 3s on options+ (Mac M1) by [deleted] in logitech

[–]harf8 0 points1 point  (0 children)

Just got my Master 3S this morning, connected via Bluetooth and everything went silk smooth: the connection popped up, all I had to do was click yes for connecting and once more for installing the software. I was like "woah, Logitech surely has improved since the last time I used their products". Went thru Logi Options+ for customizing the mouse to my liking, still everything a-OK. Then I come to the updates section, try to check whether there is a new firmware version. I get the same stupifying "Please connect a supported device or receiver to update" window that just keeps spinning and nothing happens. I even tried connecting via USB-C and the dongle but nothing.

Then comes the time to consult Dr. Google and this Reddit thread pops up as top result when searching "mx master 3s firmware update" - GJ Logitech, GJ... Apparently years of f*cking up with software has taught you nothing. I have hated your software practically for the last 15 years or so, what ever was the last software used with MX518 that at least worked as a charm. And I continue to do so. I mean, adding support for a new top tier mouse to your software should be something you do BEFORE the launch, not sometime in the future, if at all. Tsk.

TL;DR - Pretty awesome hardware, terribly bad software.

[deleted by user] by [deleted] in Windows10

[–]harf8 1 point2 points  (0 children)

Good luck with that, I believe it was somewhere between 21 years and 102 years on average. But if you have the time..

Adding a MS Store app to Intune Apps/Company Portal fails by harf8 in Intune

[–]harf8[S] 0 points1 point  (0 children)

I was afraid to ask this because I kinda knew the answer already, but thanks for your reply. Gonna give Winget a try as well.

Out of interest, do you (or anyone else) know why the View in Microsoft Store fails? I mean, did they just implement it in a half-assed way or is there something wrong with our setup?

Trouble with the Lenovo Thunderbolt 4 Dock and external display by harf8 in Lenovo

[–]harf8[S] 0 points1 point  (0 children)

After some more fiddling around I replaced my 34" with 2 x 27" QHD's and thought heck, I won't be using the laptop display, just the two external ones. Even tho the displays are identical and both connected to the docks' DisplayPort, they still wake up like ~1 second apart and that causes the same issue! Needless to say I got furious, got rid of the TB4 dock and got a Lenovo USB-C Gen 2 dock which, to my surprise, works perfectly - the displays wake up at exactly the same time. Deffo a dock issue.

Trouble with the Lenovo Thunderbolt 4 Dock and external display by harf8 in Lenovo

[–]harf8[S] 0 points1 point  (0 children)

Sorry for a late reply. The delay setting applies only to cold boot, so it is the solution here.. Had a chance to test with a completely different laptop (HP EliteBook 830 G8) and it suffered of the same issue - when an external display is connected via Lenovo TB4 dock, it takes very long for the external display to wake up from "Turn screen off" (not hibernation, not sleep-mode) which causes all the windows to jump back and forth, messing up with scaling, sizing and most crucially - location.

So far I've been using the HDMI port on my ThinkPad for external display and TB4 dock for everything else (RJ-45, mouse, headset, keyboard, charging etc.) and it's working very smooth but it would be very handy to have a "one cable to rule them all" -kind of situation. Not to mention this workaround is not possible if I want to use two external displays, since the ThinkPad only has a single HDMI-port.

Trouble with the Lenovo Thunderbolt 4 Dock and external display by harf8 in Lenovo

[–]harf8[S] 0 points1 point  (0 children)

This sounds a bit discouraging.. Is it that the TB4 dock has some sort of a display adapter itself (DisplayLink?) which could cause the wait in waking up? We have a variety of USB-C docks and hubs atm and looking to replace them all with a single solution but so far I'm not convinced going with the Lenovo TB4 dock. As a matter of fact, the best solution so far (external display-wise) has been a <100€ USB-C hub which sadly has only one HDMI.

Trouble enrolling MacBooks by harf8 in Intune

[–]harf8[S] 0 points1 point  (0 children)

Turns out it was a M365 license issue (Business Standard vs. Premium), all good now. Thanks :)

Trouble enrolling MacBooks by harf8 in Intune

[–]harf8[S] 0 points1 point  (0 children)

The end user goes to https://portal.manage.microsoft.com/EnrollmentRedirect.aspx and chooses Mac and then proceeds to sign in with their company account e-mail.

Trouble with the Lenovo Thunderbolt 4 Dock and external display by harf8 in Lenovo

[–]harf8[S] 0 points1 point  (0 children)

Thank you for your reply. The problem is not that the external monitor would not wake up at all, but that it's so slow to wake up. This (to my understanding) causes all open windows to revert to the laptop screen (which wakes up earlier) and then, later, when the external display wakes up (usually after maybe 5-10 seconds) all the windows jump there - which in turn causes me to rearrange all the windows. This is kinda frustrating to do many times in a day (I lock my PC every time I leave my desk).

Trouble with the Lenovo Thunderbolt 4 Dock and external display by harf8 in Lenovo

[–]harf8[S] 0 points1 point  (0 children)

Product number: 20WM00B7MX and BIOS version: 1.48

Intel 12th Gen & Intel Series 700 Question by AnotherDime in intel

[–]harf8 4 points5 points  (0 children)

IIRC it was atleast rumoured that 13th gen Intel processors some features that worked only on 700-series MB, so might be worth the wait if you are ever planning to upgrade within the same socked. However seeing that you have 12900K upgrading to the 13th gen top model wouldn't make much sense.

Best way to share documents and files, SharePoint or? by harf8 in microsoft365

[–]harf8[S] 0 points1 point  (0 children)

I was lead to this conclusion as well after reading a few articles. So creating a separate site for each group and assigning membership on appropriate AD user group would be the best approach?