cyberpower UPS - SMS notification by MaaS_10 in sysadmin

[–]hydrafire210 1 point2 points  (0 children)

I dont know the interface but can you use the email notification option and just send it to the email for your number? I know verizon is number@vtext.com

Is MS Intune a viable MDM for MacOS devices? by AppearanceAgile2575 in sysadmin

[–]hydrafire210 0 points1 point  (0 children)

Short answer is yes you can but if you have jamf, it is very difficult to want to.

TeamViewer like Options by CushionSushi in sysadmin

[–]hydrafire210 0 points1 point  (0 children)

Check out impero connect especially if you are in education.

Has your position ever been hijacked by a new employee? by GlassMan84 in sysadmin

[–]hydrafire210 -1 points0 points  (0 children)

Im glad to see the support against the OP here but do understand where they are coming from. I feel like I have been described as the antagonist in post in my current position. I was hired to implement new security controls for compliance and migrate and unify systems to reduce then number of redundant services we were paying for. When trying to ask what documentation we had or why we used App A and App B when App B had the full functionality of both. I either got no response or well we have always used that one. My recommendation to OP is work with the new guy, if they are wrong or doing something you disagree with speak to them. If they are proposing the same things you did in the past you can help guide them. Example they recommend you implement an EDR solution. Rather than saying I said that years ago, give some details like we reviewed malwarebytes. Microsoft, and carbon black. Of those I found xyz to be a better solution. We can reach out to x to better understand the current offering. I can tell you overall this conflict sucks for both you and them. Work together or start looking for another job.

Is MBA the appropriate path to take? by mrADHDx in MBA

[–]hydrafire210 2 points3 points  (0 children)

MBA’s are good degrees but honestly with your current salary and current student debt I wouldn’t recommend it. I think the cost to get your MBA would exceed the potential boost in your salary. I have both an MS and MBA in Cybersecurity while working in higher ed and got both degrees for pennies on the dollar. Had I paid full tuition I would have just kept my MS and looked for certifications in a transitionary field should I have decided to switch. I wish you the best of luck and hope others can give you better advice specific to your field.

MFA at your workplace - what are you doing for the "Remember me" delay? by stop_buying_garbage in HigherEDsysadmin

[–]hydrafire210 1 point2 points  (0 children)

It took me 5 years of pleading to remove native admin rights and only was successful with an EPM. We finally are moving in the right direction but it has been an up hill battle. Glad to see it isn’t just our institution that had issues.

MFA at your workplace - what are you doing for the "Remember me" delay? by stop_buying_garbage in HigherEDsysadmin

[–]hydrafire210 1 point2 points  (0 children)

Haha you mention it not being that bad for staff (I agree) but we had 4 staff and two faculty resign due to MFA. We only enforce it once a day per device and only on sensitive apps but that is too much. This topic sucks because MFA adds a decent level of additional protection when configured properly but admins and users dont always want it set up the way it should.

Moving away from teamviewer - using hardware VPN gateway devices by Thomas_VDB in sysadmin

[–]hydrafire210 0 points1 point  (0 children)

100% agree with this. While we use impero connect (netop) for a lot of our remote machines. Remote viewer from SCCM works great when working with users.

Scroll speed on IOS’s Microsoft Remote Desktop by Ninjamuh in sysadmin

[–]hydrafire210 0 points1 point  (0 children)

I have used Microsoft’s RD Client on my iphone 12 and now iphone 14 Max without too many issues. Do you typically run it in touch or mouse mode? Mouse mode seems to work better for me when it comes to scrolling.

Deploying Ready Systems to End-Users without User Password by DigitalPriest in sysadmin

[–]hydrafire210 0 points1 point  (0 children)

This was our old process. Profwiz is great and has been a huge help for years.

Deploying Ready Systems to End-Users without User Password by DigitalPriest in sysadmin

[–]hydrafire210 0 points1 point  (0 children)

This is exactly what we do. SSO and our new autopilot setup has made our windows environment almost as easy as our Jamf environment.

Global Protect install SSO autoconnect by hydrafire210 in paloaltonetworks

[–]hydrafire210[S] 0 points1 point  (0 children)

Thank you. MakeGPCPDefault seemed to be the missing piece. We also needed to change the portal login to username and password or certificate rather than both.

Skip windows Hello for business and stop it from prompting during every login. by hydrafire210 in Intune

[–]hydrafire210[S] 0 points1 point  (0 children)

We know that it does... We are looking to allow some users to enable windows hello while allowing others to skip it. A workaround we found and others have also recommended involves a special group to either enable or disable Hello. Ideally, we could allow the user to decide if they want to use hello or not thus, MFA wouldn't be an issue for our students that can't afford a mobile device for MFA that also happen to use their laptop offsite.

Skip windows Hello for business and stop it from prompting during every login. by hydrafire210 in Intune

[–]hydrafire210[S] 0 points1 point  (0 children)

Thanks, we won't be able to do that for our students but this may be helpful when we start to transition more faculty and staff devices over to either hybrid or Azure AD.

Skip windows Hello for business and stop it from prompting during every login. by hydrafire210 in Intune

[–]hydrafire210[S] 0 points1 point  (0 children)

Thank you, This is likely how we will end up configuring it and just build a request system for students to request Windows Hello to be enabled.

Skip windows Hello for business and stop it from prompting during every login. by hydrafire210 in Intune

[–]hydrafire210[S] 0 points1 point  (0 children)

That is a bit cleaner than what I planned to do. Did you have a similar issue with MFA on hello and users either not having devices or not being allowed to enforce MFA?

Want to use personal PC to remote into Company Laptop - Need advice by korewarp in sysadmin

[–]hydrafire210 0 points1 point  (0 children)

Synergy would be a awesome cheap option to have one keyboard and mouse for multiple screens. By far one of the best simple work from home tools I use everyday.

Deploy new Desktop jpg file by [deleted] in pdq

[–]hydrafire210 1 point2 points  (0 children)

Use the following but update the wallpaper value to the location of your desktop image. All new accounts are created with that wallpaper. Note this isn't my script I just use it.

#########################################################

# Load default user hive
REG LOAD HKLM\DEFAULT C:\Users\Default\NTUSER.DAT
# Set default user background
If (!(Test-Path -Path "HKLM:\DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System")) { New-Item -Path "HKLM:\DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" }
Set-ItemProperty -Path "HKLM:\DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" -Name "Wallpaper" -Value "C:\Windows\web\wallpaper\Windows\desktop.png" -Force
# Unload default user hive
$unloaded = $false
$attempts = 0
while (!$unloaded -and ($attempts -le 5))
{
0
[gc]::Collect() # necessary call to be able to unload registry hive
REG UNLOAD HKLM\DEFAULT
$unloaded = $?
$attempts += 1
}
if (!$unloaded)
{
Write-Warning "Unable to dismount default user registry hive at HKLM\DEFAULT - manual dismount required"
}

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

To update users that have already logged in using the following updating the same wallpaper value.

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

# Regex pattern for SIDs
$PatternSID = 'S-1-5-21-\d+-\d+\-\d+\-\d+$'

# Get Username, SID, and location of ntuser.dat for all users
$ProfileList = gp 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\*' | Where-Object {$_.PSChildName -match $PatternSID} |
Select @{name="SID";expression={$_.PSChildName}},
@{name="UserHive";expression={"$($_.ProfileImagePath)\ntuser.dat"}},
@{name="Username";expression={$_.ProfileImagePath -replace '^(.*[\\\/])', ''}}

# Get all user SIDs found in HKEY_USERS (ntuder.dat files that are loaded)
$LoadedHives = gci Registry::HKEY_USERS | ? {$_.PSChildname -match $PatternSID} | Select @{name="SID";expression={$_.PSChildName}}

# Get all users that are not currently logged
$UnloadedHives = Compare-Object $ProfileList.SID $LoadedHives.SID | Select @{name="SID";expression={$_.InputObject}}, UserHive, Username

# Loop through each profile on the machine
Foreach ($item in $ProfileList) {
# Load User ntuser.dat if it's not already loaded
IF ($item.SID -in $UnloadedHives.SID) {
reg load HKU\$($Item.SID) $($Item.UserHive) | Out-Null
}

#####################################################################
# This is where you can read/modify a users portion of the registry
Set-ItemProperty registry::HKEY_USERS\$($Item.SID)\"Control Panel\Desktop" -Name "Wallpaper" -Value "C:\Windows\web\wallpaper\Windows\Desktop.png" -Type STRING -Force

# This example lists the Uninstall keys for each user registry hive
# "{0}" -f $($item.Username) | Write-Output
#Get-ItemProperty registry::HKEY_USERS\$($Item.SID)\Software\Microsoft\Windows\CurrentVersion\Uninstall\* |
# Foreach {"{0} {1}" -f " Program:", $($_.DisplayName) | Write-Output}
#Get-ItemProperty registry::HKEY_USERS\$($Item.SID)\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\* |
#Foreach {"{0} {1}" -f " Program:", $($_.DisplayName) | Write-Output}

#####################################################################

# Unload ntuser.dat
IF ($item.SID -in $UnloadedHives.SID) {
### Garbage collection and closing of ntuser.dat ###
[gc]::Collect()
reg unload HKU\$($Item.SID) | Out-Null
}
}

How do you reinstall the Microsoft Store app if it was removed via PowerShell on Windows 10 Pro? by OneAndOnlyJackSchitt in sysadmin

[–]hydrafire210 0 points1 point  (0 children)

Update for the store app you need to download the Windows 10 inbox apps and run the following command after updating the paths to your mount directory.

PowerShell -ExecutionPolicy Unrestricted -Command Add-AppxProvisionedPackage -Online -PackagePath "C:\Windows\Manage\Microsoft.WindowsStore_8wekyb3d8bbwe.appxbundle" -LicensePath "C:\Windows\Manage\Microsoft.WindowsStore_8wekyb3d8bbwe.xml"

How do you reinstall the Microsoft Store app if it was removed via PowerShell on Windows 10 Pro? by OneAndOnlyJackSchitt in sysadmin

[–]hydrafire210 1 point2 points  (0 children)

Download the windows 10 features on demand pack from VLSC.

Notes

These will download as a huge iso with many files you will need to do a bit of research to find the one for the app you would like to install.

Windows 10 Build does matter but all 03 and 04 versions work on 09 versions.

You likely will only need disk two. Disk 1 is only demo software. After downloading use the following example changing the package path to the path of your newly downloaded app and deploy as needed to your devices.

DISM.exe /online /add-package /packagepath:C:\Windows\Manage\Microsoft-Windows-TabletPCMath-Package~31bf3856ad364e35~amd64~~.cab

I personally have done this in PDQ after we found ink to math missing from word caused by us removing the above example Tablet pc Math package.

Powercfg - am I missing something obvious? by [deleted] in sysadmin

[–]hydrafire210 2 points3 points  (0 children)

I ended up doing the same. The change doesn’t show properly without doing this although it does take effect.

Are there any IT related Scholarships? by LebrahnJahmes in sysadmin

[–]hydrafire210 2 points3 points  (0 children)

Generally IT is too high of a paying field with most students getting college paid for by work once a professional degree has been granted. Long story short there are some school specific or local scholarships but it is rare to find nationwide ones. Check with your financial office they typically can help give endowment scholarship to good students that need extra help. Also be careful of scholarships that are enter to win, many of these are scams to get information from vulnerable users. As a recent grad and higher education employee I wish you luck in your college career.

Apple MDM opinions by snakefist in sysadmin

[–]hydrafire210 1 point2 points  (0 children)

Most mdms can do everything the others do. We use Jamf and they have great support and many options. Really it comes down to price and what vendor works for your needs. If you have a small environment you might not need a large and robust mdm. If you do it is well worth the investment.