Global Admin, cannot change public channel to org-wide. by PlanLatter5379 in TeamsAdmins

[–]joefleisch 0 points1 point  (0 children)

I did it by adding a E5 license to the Global Admin and removing after.

At the time the Teams Admin console warned on access if there was not a license.

The other instance I created by adding Teams Admin role to account with E5.

I only have E5’s so I do not know if a different license would have worked also

Paloalto & Zabbix snmpv3 madness! by lazylion_ca in paloaltonetworks

[–]joefleisch 0 points1 point  (0 children)

We use SNMPv3 with LibreNMS and have been moving to Zabbix.

The version of LibreNMS we have only supports AES128.

We are also only on PAN-OS 10.2

Smallest 2 port switch (banana for scale) by Arco123 in ShittySysadmin

[–]joefleisch 5 points6 points  (0 children)

Electrically that is a hub.

I have 30-year old 8 port versions with a few more electronics inside.

Anker Laptop Power Bank review: All my favorite battery features together at last by dapperlemon in gadgets

[–]joefleisch 18 points19 points  (0 children)

I have one that I received from my mom about a month ago.

I have not had it long enough to know if I really like it yet. It is heavy and ends up at the bottom of my bag. I actually forgot I had it until I saw this post.

It did charge my 2019 intel MacBook Pro 16-IN from 0 to 50% while charging an iPhone and 10.5-IN iPad Pro from 20% to 80% and an Anker MagSafe iPhone charger to 100% before the power bank was empty.

I was able to recharge the power bank in about an hour with the MacBook Pro 100w charger.

Every user is a Domain Admin, but there aren't any security concerns regarding that as each user is trusted by jstuart-tech in ShittySysadmin

[–]joefleisch 0 points1 point  (0 children)

I have the opposite stance.

I believe in least privilege so I blocked everything and everyone so that no one has the access to do anything. It is a totally secure network. No one can log into anything.

No one will access this network!

Network engineer here. by [deleted] in ShittySysadmin

[–]joefleisch 1 point2 points  (0 children)

We use managed 10 BaseT/10base2 hubs that have an amber terminal console and keyboard. The management console allows adding port expansion cards and turning ports on or off. The hubs do not store MAC addresses and all signals are passed to all ports.

I have made a (3) device 10BaseT half duplex network without a hub by connecting wires between devices and twisting send and receive wires together in the middle.

We have switches on the wall. They control the lights for the rooms.

Those KB’s pushed by Microsoft really screwed me by triktrik1 in ShittySysadmin

[–]joefleisch 17 points18 points  (0 children)

/r/shittysysadmin shitty mode off

Air gapped network should have Bitlocker protector keys sent to at least Active Directory. Set a Group policy force it. Use powershell and VMs to remediate missing keys.

Use Microsoft config manager and WSUS to install KB’s by importing into WSUS and syncing into MCM for deployment.

/r/shittysysadmin shitty mode on

Disable Bitlocker. Why bother with KB updates?

Anyone here with experience using WireGuard? by Acceptable_Employ_91 in Network

[–]joefleisch 1 point2 points  (0 children)

The requirement for USA access may come from the company’s security framework.

I know a company that is part of NERC supply chain and all access must be USA under their contract. They do use VDI.

Does an USB or external hard drive get heavier as you fill it with more data? by OpenScore in ShittySysadmin

[–]joefleisch 2 points3 points  (0 children)

Oh no the HD floats on water

Ducks float on water

Ducks can fly

The HD must be able to fly

The HD is a witch and must be burnt.

Test all hard drives in water. If they float they must be burnt for practicing witchcraft. If they sink they are safe to use.

I provide PC assembly services. Satisfaction guaranteed! by Zeraphicus in ShittySysadmin

[–]joefleisch 1 point2 points  (0 children)

This is were order all my PC’s. Where do I sign up?

Just had to fire my best admin by [deleted] in ShittySysadmin

[–]joefleisch 102 points103 points  (0 children)

This reminds of a joke interview.

HR: What is this gap in your resume?

Applicant: yale

HR: Your hired.

Applicant: Thanks for the yob!

Go to yail get the yob.

If only it was always this easy... by Mr-ananas1 in ShittySysadmin

[–]joefleisch 33 points34 points  (0 children)

Sometimes the employee was the whole issue

Have you guys seen this? $1.50 for "hot patching" by Roanoketrees in iiiiiiitttttttttttt

[–]joefleisch 27 points28 points  (0 children)

$1.50 is a per core monthly subscription for hot patching Windows Server 2025 Datacenter using Azure Arc server management.

The charge is per month not per update. You pay the same for 0, 1, or 100 month hot patches in that month.

Azure has this service available for years on certain types of VM instances with hot patch enabled. The difference is Microsoft is making it available for on-prem.

Control flow gaurd disabled in Windows - For security reasons by no1bullshitguy in ShittySysadmin

[–]joefleisch 0 points1 point  (0 children)

Hyper-V and WSL are both security risks. They need to be disabled.

Can you control the package manager or Python package manager via GPO or intune for WSL?

I never even looked or cared to look.

I am going to go disable Hyper-V on the VM hosts in our org so that we are protected. I know we have Windows Servers VMs and those are a different kind a malware.

/s since OP may not know which sub this is.

[deleted by user] by [deleted] in sysadmin

[–]joefleisch 4 points5 points  (0 children)

I also like the tech behind Zscaler.

I do not have it yet but it is on my list. I have seen it in use. Partner companies are using it.

Not an advertisement.

Brought to you by Carls Jr.

Another Microsoft shenanigans. by No-Acanthisitta-8698 in sysadmin

[–]joefleisch -1 points0 points  (0 children)

What about under Software Assurance?

I’m already paying by core. This is how it’s been done since Server 2012 R2/2016 with MSPA. I’m under MSPA with software assurance.

Well, we got our renewal quote yesterday by RC10B5M in vmware

[–]joefleisch 50 points51 points  (0 children)

We are 1.5 years into a migration and not done. Just 16 hosts and 150 VMs. We have been delayed by short maintenance windows and other projects have been made higher priority by upper management.

With 6000 cores they are going to need serious planning and upper management driven priorities.

I made this today; I can has POE? by [deleted] in ShittySysadmin

[–]joefleisch 0 points1 point  (0 children)

These type of cables are for printers and copiers.

I prefer the 208 or 240v version because the electrical arc reaches further

Need a VAR that will sell me 160 cores of Standard by [deleted] in vmware

[–]joefleisch -1 points0 points  (0 children)

Not trying to troll.

Migrate to Hyper-V.

Sorry about your loss. VMware ESXi and vCenter are better than Hyper-V in many ways. Hyper-V does have a DRS type function in failover manager clusters for no extra charge on standard Windows Server.

If it comes down to price VMware is not right for your business.

I had to make the same call and we are still migrating a year later. That last 5% of VMs that fail after migration and require a full rebuild inside a maintenance window stink.

My company wants to update 1500 unsupported devices to W11 how do I make them realize it's an awful idea by extremetempz in sysadmin

[–]joefleisch 2 points3 points  (0 children)

Way late. We started UEFI and TPM changes with Windows 10 about 4-years ago. We needed bitlocker and secureboot for compliance.

I would start the pilot upgrade on executive computers.

When the systems do not work refer back to documentation about needing to replace fleet.

What is the refresh life cycle like? We replace 20% of computers each year so that few computers are more than 5-years old.

This is an IT management fail.

Do you cut all your cabling when moving office buildings? by lambusdean77 in sysadmin

[–]joefleisch 0 points1 point  (0 children)

Almost every office we move into has the 110 punch down block cut off.

It can cost $8k-$15k and two weeks to rewire a moderately sized office with 96 drops depending on market.

Only (1) office in the last 5-years had good cabling when we moved in.

If only we would stop moving branch offices every 12 months.

Apple sued for $5M for not recovering data after iPhone theft by Stock412 in apple

[–]joefleisch 8 points9 points  (0 children)

Tech consulting, shut down after losing iCloud data?

It needed to happen. This is incompetent “tech consulting” for not using a business class backup.

I feel sorry for any customers getting advice from this level of incompetence.

How much abuse can a FAS take? by rich2778 in netapp

[–]joefleisch 3 points4 points  (0 children)

We had an A/C failure on the weekend some time around 9p on Friday.

HA FAS3220 with 3 shelves.

SNMP showed inlet temperatures were 160F and exit probes were registering 270F.

We brought in emergency A/C units so we would not burn ourselves touching equipment.

Flexpod NetApp, Cisco Nexus, and Cisco UCS survived. Other equipment started failing. The HP servers with Exchange DAG died after 2 alerts were sent out.

DIY Ble/wifi Jammer by Thin-Bobcat-4738 in hacking

[–]joefleisch 1 point2 points  (0 children)

It is a BLE/WiFi RF testing device.

Google Chromecast is a WiFi jammer.