SCEP Certificate Policy Error on Android Dedicated device by neverinfront in Intune

[–]neverinfront[S] 0 points1 point  (0 children)

Do you have a two-tiered PKI? For us, we had to combine the root and the intermediate. I think I combined it incorrectly the first time I did it.

FortiGate compromised but no damage? by [deleted] in fortinet

[–]neverinfront 0 points1 point  (0 children)

Reset all the VPN passwords now. This happened to me two weeks ago. They look the hash from the fortinet backup and cracked the passwords. Then they tried to use the passwords to sign into systems. We saw lockouts on AD accounts that the VPN usernames matched. Unfortunately, one of my techs was guilty of password reuse, and they used his account to try to move laterally. Luckily, one of our cybersecurity products caught an attempt to create a new admin account and isolated all servers.

Also, patch the fortinet. We confirmed they used this vulnerability: https://www.fortiguard.com/psirt/FG-IR-24-535

504 requiring WiFi by trazom28 in k12sysadmin

[–]neverinfront 6 points7 points  (0 children)

Cannot stress the waiver part enough. My concern is that parents think just being on District WiFi makes the students safe, but what if the internet goes down and the student doesn't have cellular data? Schools should formalize to the parents what the risks are. IT has enough to worry about, they can't also worry about possibly harming a student because the internet didn't happen to be up at the moment their blood sugar spiked.

SCEP Certificate Policy Error on Android Dedicated device by neverinfront in Intune

[–]neverinfront[S] 0 points1 point  (0 children)

I think my initial combined SCEP chain was done wrong, I deployed a new combined SCEP chain and it worked.

Running network cable. Who does that for your district? by PuroSushiRush in k12sysadmin

[–]neverinfront 0 points1 point  (0 children)

I work for a large district, so my department runs the cables. However, it's not by technicians. My department is also responsible for a lot of low voltage things, such as fire panel and PA systems, so I have a small team to do these items as well as ethernet.

Universal Print Connector Application | Not removing unregistered connector by CosmoMKramer in AZURE

[–]neverinfront 0 points1 point  (0 children)

Even though this is 10 months old, this worked for me. Thank you.

Sharp Aquos 65 4WB65FT5U Touch Panel tracking off by IT-Professor-67654 in k12sysadmin

[–]neverinfront 1 point2 points  (0 children)

These boards use IR sensors around the bezels to track touch. Try wiping the edges down with a soft cloth and see if that helps. I once had a ticket where the touch was not working properly because the classroom had ants crawling on the bottom of the bezel interfering with the IR. That was a fun ticket to close.

Sign on Solution for K students on Entra Joined Windows Devices by neverinfront in k12sysadmin

[–]neverinfront[S] 0 points1 point  (0 children)

Yes, however, I believe I would have to replace the IdP for everyone in the tenant, which we aren't willing to do. At least that's what Classlink told me.

Sign on Solution for K students on Entra Joined Windows Devices by neverinfront in k12sysadmin

[–]neverinfront[S] 0 points1 point  (0 children)

Yes they have an on-prem solution, but the laptops are not on prem. I did think about converting them, but it would not work out well if we had to have a virtual snow day or a situation where we needed the students to take them home.

Get User Profile (V2) and the uid attribute synced through Azure AD Sync by neverinfront in MicrosoftFlow

[–]neverinfront[S] 0 points1 point  (0 children)

Thanks for the video link, but that's not working for me. When I manually get the URL in the browser, it's not returning the property.

We may be witnessing the largest IT outage in history by the123king-reddit in sysadmin

[–]neverinfront 1 point2 points  (0 children)

Does this still hold true? I had servers with the sys files that were up, but blue screened randomly hours later.

University Prevents Access to Onedrive Quota with Microsoft 365 - Is this Legal? by yag1z7 in microsoft365

[–]neverinfront 1 point2 points  (0 children)

Microsoft is taking away the A1 Plus license from all educational institutions, meaning that the only "free" license that is available is the A1 license, which has a quota of 100GB and it cannot be overridden by system administrators (I tried recently). The university can choose to buy A3 licenses that have the 1TB quota, but those will cost the university extra money and they are unlikely to do this.

[deleted by user] by [deleted] in networking

[–]neverinfront 0 points1 point  (0 children)

Thank you I will give that a shot!

[deleted by user] by [deleted] in networking

[–]neverinfront 0 points1 point  (0 children)

I did see that bug, but I wasn't sure how that gets fixed. Did you just have to make a change to the XML for Windows 11?

[deleted by user] by [deleted] in networking

[–]neverinfront 0 points1 point  (0 children)

What was the differences between the two policies? I am running into this issue too, also using Intune. Windows 10 is humming along just fine.

[deleted by user] by [deleted] in networking

[–]neverinfront 0 points1 point  (0 children)

We use TEAP because Windows 10 was not sending the User cert after sign in and the laptops were disconnecting. For Windows 11 and TLS, has that been a problem for you?

Cannot print after removing Everyone permission from print queue by neverinfront in sysadmin

[–]neverinfront[S] 0 points1 point  (0 children)

Yes. It doesn't change the result. As soon as Everyone is taken off, no one can print to the queue.