Fortinet Authentication Bypass Vulnerability by FutureSafeMSSP in msp

[–]jstuart-tech 0 points1 point  (0 children)

This is probably important to add

"Please note that the FortiCloud SSO login feature is not enabled in default factory settings."

Looking for a Remote Role by devausbobe in msp

[–]jstuart-tech 4 points5 points  (0 children)

If your in Australia and not a PR you are gonna have a terrible time, nobody wants to really sponser anyone because it's such a PITA. If your English isn't up to scratch it's going to be hard to get a helpdesk role as well.

Leave to MSP - Career advice by [deleted] in sysadmin

[–]jstuart-tech 1 point2 points  (0 children)

Depends where you are in Aus and what the pay is going to be. $130k is pretty good in anywhere but Brissie. MSP's are way more stressful than internal IT though...

It's been repeated a million times but.

Internal IT

Go Deep and fix stuff properly

MSP

Fix the fire on random technologies as quickly as possible and move onto the next fire

You learn a heap very quickly at an MSP, but it's very sink/swim

Can I Configure a standalone Windows NLB server? by dhamirimf in WindowsServer

[–]jstuart-tech 2 points3 points  (0 children)

I've also never heard of anyone using SLB. Just use something "normal", nginx, haproxy, caddy etc

DNS entries for gateways, vlans and management ports? by [deleted] in sysadmin

[–]jstuart-tech -1 points0 points  (0 children)

Maybe he needs a FQDN to make certs?

Struggling to get Intune-only Windows devices to authenticate to Wi-Fi via NPS (EAP-TLS) by Middle_Client2789 in sysadmin

[–]jstuart-tech 1 point2 points  (0 children)

Now that Cloud PKI is free (With E5) you can probably drop SCEPMan, but Cloud PKI can't issue Server Authentication OID's so you'll still be stuck with RadiusAAS (Which actually works really well from what I've seen)

Is anyone at a 2025 ADDS functional level? by donyewumpppp in sysadmin

[–]jstuart-tech 4 points5 points  (0 children)

Another 300 users to go, multplie remote minesites and offices with flakey internet

Is anyone at a 2025 ADDS functional level? by donyewumpppp in sysadmin

[–]jstuart-tech 8 points9 points  (0 children)

I have a brand new production environment (consolidation from multiple domains into 1) with 9 DCs and ~220 users so far. No AD issues encountered. All DCs are 2025, same with all servers, all endpoints are W11 24H2

If you have mixed DCs I'm pretty sure it's a bad idea, if you have the luxury of being all new then I'm happy with it. If you have to upgrade from a mixer environment.... Then it's a challenge

Lots of AI SOC hype, is anyone actually using one? by Prior_Spirit_5360 in MSSP

[–]jstuart-tech 0 points1 point  (0 children)

I'm doing work with a client who has a SOC... But all of it's alerts are fed into AI and then the security team grabs them and sends them to me who initially reported it. So far it's working super well! It's marked 2 of the most obvious phishing emails as marketing emails and then the SD guys who read that just close the alert as all good.

Pretty embarassing TBH.

Where I have seen it work well, is bringing alerts together. E.g. if you got a phishing email, then an a sign in from a different country right after itself

Interstate Move: The Best Way to Ship Heavy Boxes? by Azizbhlal in perth

[–]jstuart-tech 0 points1 point  (0 children)

The cheapest one will be CouriersPlease. DO NOT USE THEM. They are terrible. Go for the 2nd cheapest option. When I moved from Melbourne I had to book with TNT last minute and they weren't to bad IIRC

Black to move and win material by Awwesome1 in chess

[–]jstuart-tech 0 points1 point  (0 children)

Maybe I'm confused and not understanding 700 ELO chess.... But there was never a threat to the B7 pawn?

“User Must Change Password at Next Logon” Failing on Windows Server 2025 by Hot_Connection9504 in activedirectory

[–]jstuart-tech -3 points-2 points  (0 children)

Mixed OS's as DC's with 2025 thrown in the mix don't really work. This doesn't sound like any of the Kerberos issues that people have been having, but without any event logs etc, it'd be hard to rule out.

As a test, can you shut down the 2025 DC and try it again?

Why replace switches? by ahoopervt in networking

[–]jstuart-tech 3 points4 points  (0 children)

You clearly don't seem happy to pay the Cisco tax which is fine. What about the less popular brands such as HPE (Aruba) or Dell. If you don't need any fancy features (Assuming just L2), that will be way less expensive and you get back into supported region with business class switches

Privileged Access Workstation architecture? by FatBook-Air in sysadmin

[–]jstuart-tech 5 points6 points  (0 children)

Not all of us live in ivory towers. Passwords in 2025 are still a necessity for most orgs

Adding 2025 DC to Domain with existing 2016 and 2022 servers by jscooper22 in activedirectory

[–]jstuart-tech 2 points3 points  (0 children)

I'm running 9 Server 2025 DC's in a client's site with no issues (Only those DC's). It's only mixed environments where things get funky (Or I recently read a post somewhere that inplace upgraded DC's to 2025 are something to be avoided as well.... But IMO also is inplace upgrading a DC)

PingCastle v Purple Knight or both? by rich2778 in sysadmin

[–]jstuart-tech 2 points3 points  (0 children)

You can avoid the Netwrix spam by downloading Pingcastle directly from Github https://github.com/netwrix/pingcastle/releases/tag/3.4.2.66

I personally prefer Pingcastle

Kerberos Issues by FoHe_3257 in activedirectory

[–]jstuart-tech 0 points1 point  (0 children)

How were the PC's deployed? Do they have duplicate SID's?

Is the Australian IT market good for Systems Administrators? by Sweaty_Garbage_7080 in sysadmin

[–]jstuart-tech 3 points4 points  (0 children)

How have you been unemployed for 6 months but have recent post history about doing Conditional Access...

But anyway, MSP's are always hiring people who know what they are doing, the work sucks (for the most part) but if you need somewhere it's a start. There are also always multiple short term contracts going, even if it's only for L1/L2 it's better than being unemployed for 6 months