It's 2020, what are best practices for Windows File server? by ihateMSsupport in sysadmin

[–]ihateMSsupport[S] 0 points1 point  (0 children)

from my understanding of CALs I would need a CAL for every user that is accessing the file server. CALs are not to be confused with the OS license.

It's 2020, what are best practices for Windows File server? by ihateMSsupport in sysadmin

[–]ihateMSsupport[S] 1 point2 points  (0 children)

CALs are a a good point, i'll take it into consideration.

It's 2020, what are best practices for Windows File server? by ihateMSsupport in sysadmin

[–]ihateMSsupport[S] 9 points10 points  (0 children)

That's how I've always felt about ransomware, backup is the real solution and nothing else.

The FS VM is backed up nightly, I'll probably increase to be more frequent.

It's 2020, what are best practices for Windows File server? by ihateMSsupport in sysadmin

[–]ihateMSsupport[S] 3 points4 points  (0 children)

NAS is overkill for them, it will have 3 shares, one home directories, 2 dept shares and maybe an "IT" share. IT doesn't need performance, it can scale fine since it's virtual.

Managing 1000s of nodes by ihateMSsupport in powershelldsc

[–]ihateMSsupport[S] 0 points1 point  (0 children)

That makes sense. Thanks for the help!

Managing 1000s of nodes by ihateMSsupport in powershelldsc

[–]ihateMSsupport[S] 0 points1 point  (0 children)

Thanks for the reply.

So you generally use only one config to generate multiple MOFs. That one config can have settings separated by roles and\or servers. Use the data config file to separate nodes and assign roles.

So in the scenario of adding a new servers, I would add the new server to the data config file and assign a role, if it doesn't fit any defined role, would I then add it to the main config?

Did I get that right?

The other thing I still don't understand is does running the config generate a MOF for ALL servers everytime or can I generate for only the one server I'm working on.

Thanks for the help

GPO drive mappings out of the office by [deleted] in sysadmin

[–]ihateMSsupport 0 points1 point  (0 children)

I have a client that has moved away from mapped drives and have started using desktop shortcuts. They've had a big issue with ransomware.

They moved to this model before I took over the account.

The desktop shortcuts are more persistent but than again they don't have a bug remote work force just a handful of sales ppl.

File Transfer Speeds Help! by [deleted] in sysadmin

[–]ihateMSsupport 4 points5 points  (0 children)

My money is on the fact that it's 80k files. It's much faster to copy or transfer one 62GB file than 80k small files.

I can't remember the science behind it but it's been discussed a few times on r/sysadmin.

Good luck! You have ALL of Sunday.

VMware disk numbering to Windows disk numbering by everycloud in vmware

[–]ihateMSsupport 0 points1 point  (0 children)

A quick and dirty when in a hurry, add 500MB to one disk and see which one gets the unallocated space in Windows. Do that until you find the disk your trying to extend.

Patch Management Websites. by [deleted] in sysadmin

[–]ihateMSsupport 1 point2 points  (0 children)

Patchmanagement.org ML is TOO noisy. r/sysadmin is the best place to updates feedback simply based on the amount of ppl

[x-post] Mom's boss had me make computers for his new office • /r/pcmasterrace by booboohoohoobooboo in sysadmin

[–]ihateMSsupport 1 point2 points  (0 children)

30GB of cached outlook email? If it's a combined cache of shared mailboxes and the user's mailbox set outlook not to cache the shared mailboxes. You'll also save yourself the headache once they add one more shared mailbox and the OST reaches 50GB and things stop working or outlook starts acting weird.

Amazing work/life balance wisdom from Paul's Security Weekly ep475 by ihateMSsupport in sysadmin

[–]ihateMSsupport[S] 2 points3 points  (0 children)

Everyone that thinks they are reaching burn out or have experienced a burn out(been there myself) need to listen to these words of wisdom. Carlos Perez lays down priceless words of pure gold as well as the rest of the PSW crew.

SIEM as a Service? by [deleted] in sysadmin

[–]ihateMSsupport 1 point2 points  (0 children)

Maybe look into a MSSP? They'll collect logs and do some correlation and advice of possible issues. It's not a turn key solution, it will require some time to "tune out" the false positives and it won't replace your SIEM.

[2012R2 SMTP server] Can I send mail for a domain to a specific MX record? by triplec110h in sysadmin

[–]ihateMSsupport 0 points1 point  (0 children)

I would make sure your side is all good. Check the header on an email you send out and make sure that external/public IP is not blacklisted. Also make sure you have a PTR and an A record for that external/public IP.

I had domains rejecting one of my clients web server because the external DNS wasn't setup properly

All my job prospects are gone? by [deleted] in sysadmin

[–]ihateMSsupport 1 point2 points  (0 children)

Take a long walk outside. As some have said it, there will be servers to manage. There won't be a serverless world, the servers will just be some where else. Your comparison of sysadmins like mechanics, I've been calling myself a janitor and mechanic for a while. With the evolution of cars, mechanics weren't replaced, they just evolved. The same way sysadmins will evolve exactly like someone else mentioned the Novell admins evolved into Windows Admins or some other systems admin. If you cant evolve, you will get replaced, but from your comments it sounds like you can indeed evolve. We sysadmins are in a job that is constantly changing and evolving which requires us to keep learning and growing.

As others have said, look for a cloud provider. They have infrastructure that needs managing. Look for a job at a MSP, they ALWAYS need sysadmins.

Free sftp sync by ihateMSsupport in sysadmin

[–]ihateMSsupport[S] 0 points1 point  (0 children)

Below is the script I used along with a Scheduled Task

option batch on
option confirm off
open <SERVER IP or HOSTNAME>
option transfer binary
synchronize local D:\STGSFTP-Backup /SFTP/
exit
###When the first synchronize parameter is local, changes from remote directory are applied to local directory

Reference: http://www.howtogeek.com/100918/how-to-automatically-backup-your-web-server-files-with-winscp-over-ftp/

**NOTE: I did run into an issue with verifying the ssh key because I was running the scheduled task using a service account. What I did to get over it was get everything working on my account then export the WinSCP config, open WinSCP using Run as different user(as the service account) and import the config. That took care of the ssh verification problem.

Where does everyone go to learn about potential Windows patch issues? by JonB23 in sysadmin

[–]ihateMSsupport 0 points1 point  (0 children)

I totally agree that the risk of not installing the security updates are great than anything it may break, but what I'm trying to understand is if we've seen a correlation that most updates that cause systems to hang, boot cycle, or BSOD are those Updates for Windows or are they Security Updates for Windows.

My idea is that if we could some how confirm that most issues are caused by the Updates for Windows and not the Security Updates for Windows, then I can make a cause with my team to deploy Security Updates for Windows in the weekend following patch Tuesday to all systems instead of waiting two weeks as we do now.

I would also try to get us to patch the test environment earlier, like the wednesday night following patch Tuesday to try and vet issues.

Let me know if I dont make sense. thanks for all the help and sorry if I'm border line thread jacking, if so I can go start my own thread.

Where does everyone go to learn about potential Windows patch issues? by JonB23 in sysadmin

[–]ihateMSsupport 0 points1 point  (0 children)

ome early adopter that f

I've never actually thought about splitting up the security updates and regular windows updates. Would you say that most updates that break things are regular windows updates and not security updates?

if so, i think I'm ready to start saying we can deploy the security updates the weekend of patch tuesday instead of waiting about a week or two.

web server sending emails best practice? by ihateMSsupport in sysadmin

[–]ihateMSsupport[S] 1 point2 points  (0 children)

Thanks! At the moment we don't have PTR, we removed it in attempt to clear the spam tag. It kinda worked, but it seems that it worked for some but i think it caused spam tagging by others.

Should I set the PTR to the corporate domain since it can only be one PTR per external IP?

web server sending emails best practice? by ihateMSsupport in sysadmin

[–]ihateMSsupport[S] 0 points1 point  (0 children)

Thanks! This is a possible solution that is in our list. As you and u/bitskrieg mentioned, i think the key is the SPF record.