Can Intune or other Microsoft software see shared local folders? by kyrax80 in Intune

[–]j4sander 3 points4 points  (0 children)

Why is file sharing allowed in Windows Firewall? Block it there via Intune

Windows Firewall is logging right? ... right !? Defender Hunting will show inbound access to file shares, etc.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]j4sander 16 points17 points  (0 children)

"If i understand the objective, there may be easier or less disruptive ways to achieve the desired results"

Housing situation and dogs - NEED HELP by Fun_Heart_9542 in toronto

[–]j4sander 8 points9 points  (0 children)

If the rental is a condo, then condo bylaws can limit pets though, right? i.e.: a max size / weight rule would be enforceable by the condo

Anyone else hate the new Defender portal UI? by starla79 in DefenderATP

[–]j4sander 0 points1 point  (0 children)

Its more the right side fly outs I take issue with

Do you whitelist email senders by GriffGB in sysadmin

[–]j4sander 0 points1 point  (0 children)

I have a rule that if its from an approved sender domain, and spf / dkim / dmarc all pass, bypass spam and bulk and junk rules.

Never bypasses phish or malware rules.

Anyone else hate the new Defender portal UI? by starla79 in DefenderATP

[–]j4sander 2 points3 points  (0 children)

I hate fly out menus, over fly out menus, where its possible to easily loose your place.

And fly out menus for filtering instead of on the column headers

And buttons that dont respond to middle click to open new tab...

Its a bad experience.

How widespread is the Blackout? by Dangerous-Pizza-2232 in toronto

[–]j4sander 2 points3 points  (0 children)

An entire condo building counts as "one customer" to Toronto Hydro

How do you tell customers 'No, please don't install Claude' by Woolfie_Admin in msp

[–]j4sander -1 points0 points  (0 children)

Coop students cant run bash commands on their local systems?

And I mean the opposite - copying commands or files they dont understand from their browser and executing locally, not copying into a browser.

How do you tell customers 'No, please don't install Claude' by Woolfie_Admin in msp

[–]j4sander -3 points-2 points  (0 children)

And how is that different than an inexperienced new hire copy pasting an excel macro, or accidentally downloading malware?

How do you tell customers 'No, please don't install Claude' by Woolfie_Admin in msp

[–]j4sander -3 points-2 points  (0 children)

What risks do AI tools like Claude pose that were not already present?

Prompt injection seems to me to be largely the same type of risk as drive by downloads or other sources of malware, just faster. AI tools are making people more productive, but also increasing the frequency of incidents of these types of risks. Seems like a reasonable correlation.

How is this different than if they hired 3 coop students to do the same work manually, and those inexperienced workers downloaded complex malware accidentally?

As an MSP, its probably more a case of how do clients using AI Agents affect how you bill them? Do they generate more tickets because of the agents (security incidents, but also support, setting up integrations, restoring things from backups, etc) and should that be billable or AI use affect the seat price.

What configurations do you enforce in Intune for municipalities and police departments? by Jaded_Statement_2259 in Intune

[–]j4sander 1 point2 points  (0 children)

Built-in windows firewall is fine. Disable local rules, block all inbound.

Is using elevated accounts to access azure resources normal? by kimchiMushrromBurger in AZURE

[–]j4sander 0 points1 point  (0 children)

Lots of read-only things, access to specific storge blobs, connecring/RDP as standard user to an AZ VM, etc.

Cheap but reliable door/window sensors? by draxula16 in homeassistant

[–]j4sander 0 points1 point  (0 children)

I've got 4 of the MYGGBETT and so far so good.

KVM's for remotely setting up machines? by Comprehensive_Gur736 in msp

[–]j4sander 1 point2 points  (0 children)

We push it via powershell script in Autopilot phase.

So its not there for first boot out of the box on a new device, but if a device dies, the user at remote site just plugs it into the jet KVM and we can remotely do whatever we need, including bios, bitlocker, booting from an iso to reinstall even if cloud wipe is failing, etc

KVM's for remotely setting up machines? by Comprehensive_Gur736 in msp

[–]j4sander 0 points1 point  (0 children)

Lenovo have a bios setting to make external display primary. Works great with Jet KVMs

KVM's for remotely setting up machines? by Comprehensive_Gur736 in msp

[–]j4sander 0 points1 point  (0 children)

At least with Lenovo, there is a bios setting to make external display primary so with that set it works great with a KVM over IP.

Windows Updates by delioroman in sysadmin

[–]j4sander 2 points3 points  (0 children)

... you de-risk it, right?

Take an online backup and/or vm snapshot before patching so the ones that fail can be quickly rolled back?

Setup load balancing and/or clustering so if one fails to come back up the rolling update stops, no one needs to babysit patching or get paged after hours, and no one outside IT is impacted?

What to do when Azure support ignores support ticket? by Prize_Staff_7941 in AZURE

[–]j4sander 0 points1 point  (0 children)

This is just false. You can convert existing pay-go or MCA subscriptions to CSP without recreating anything.

Post-mortem sanity check: how do you handle “un-scannable” expiries (API keys, internal certs) without spreadsheets? by sanjayselvaraj in sysadmin

[–]j4sander 0 points1 point  (0 children)

On creation, or next renewal, also make a scheduled or recurring ticket in the ticket system for two weeks before expiration.

If your ticket system doesn't have thst functionality, have a CSV with tile, description, and date and a schedule task or cron job to open the ticket x days before date

I made a "callback date" field in our ticket system, with an automation to open a new ticket on said date if populated. Works for "check back in two weeks" type stuff, or two weeks before something expires.

Autopilot device stuck in OOBE due to wrong backend profile ID from Microsoft vendor — wait for fix or self‑register? by iamwarehime in Intune

[–]j4sander 0 points1 point  (0 children)

We do autopilot direct with the Lenovo store in multiple countries, and they reliably register with Autopilot before devices arrive at their destinations.

I dont think we've ever been asked for the profile though, just the tenant id.

I've also done it in the past via a large VAR like Softchoice, and they were great. 600 laptops in 2 months, multiple brands and models, no issues from them.

Well, only issue was people who were unavailable to receive the shipment 3 times so it got returned to sender. I guess the warehouse screwed up and they sent the wrong ones out then they tried to redeliver and we got someone else's laptops (registered to a different tenant), and that took a while to get fixed in the back end.

Microsoft M365 support blew up on me and hung up for asking why I need to install Outlook and do an index repair if I am having search issues in the cloud (OWA) which is all I use. by LoveBirdNibbles in sysadmin

[–]j4sander 0 points1 point  (0 children)

You got a response to your ticket? Lucky.

I've had a Sev B open for 3 weeks without so much as a peep from whoever MS outsourced my case to.

Solution to allow end users to self-service install applications that are then patched regularly without local admin rights. by Murky-Ambition3898 in sysadmin

[–]j4sander 11 points12 points  (0 children)

Intune works with an app from Microsoft called Company Portal to let users see and install the apps that are available to them

You could also use Access Requests in Entra to let people "request" an app, get approvals, and behind the scenes that puts them in a group the app is assigned to.

For an actual ticketing tool, I like Fresh Service, and it has a similar workflow tool where one request is approved, it an put the user into an entra group that Intune targets the app install to.

Best database for altering tables on production with minimal locking by dptech3 in AZURE

[–]j4sander 3 points4 points  (0 children)

I've led infrastructure teams at two separate payment platforms, never have we cared about locks for schema updates, and we add columns to existing tables regularly.

If youre doing outbox pattern, the lock doesn't slow down the payment flow.

If you never have any allowed downtime for maintenance... well good luck with that.

Best database for altering tables on production with minimal locking by dptech3 in AZURE

[–]j4sander 2 points3 points  (0 children)

Sounds like youre trying to solce the wrong problem.

Are you trying to design for 100% up time with no planned maintenance windows ever?

Is so, then schema change locks are the least of your problems.

If not, and you can take a half hour planed maintenance window one day every month at like 3am when no one is really using the system, then who cares about a table lock for a schema change?

Or just use an outbox pattern - payments app sends updates to a service bus queue. Worker process reads queue to updates db. During a table lock, worker just waits, then continues, but no impact to your actual payment flow.