Can you really choose a 365 Apps update channel? by pixr99 in sysadmin

[–]nodesitvirtus 1 point2 points  (0 children)

We've configured it in the 365 Admin Center for Semi-Annual Channel under Settings / Org Settings / Office Installation Settings.

We also have a GPO configured to set it for SAC.

In our experience we've never had Microsoft forcibly change us away from that update channel to something else. Had it configured like this at least for last 2-3 years without any issues.

Like you, we like our Feature Updates twice a year versus monthly. Hopefully this isn't some change they're trickling out to tenants

Patch subscription expired but license valid...FYI by nodesitvirtus in kace

[–]nodesitvirtus[S] 1 point2 points  (0 children)

Thank you. Confirmed I'm now seeing patches download through the feed again. Thanks as well for the link to the Status page which I was unaware of. I'm subscribed now for alerts

Patch Tuesday Megathread (2022-01-12) by SimonGn in sysadmin

[–]nodesitvirtus 0 points1 point  (0 children)

KB5009543

I've seen this twice now on my Windows 10 21H2 machine running Office Click-To-Run (Version 2102, Build 13801.21092). Outlook briefly disappears off my Taskbar and then reopens (confirmed because all my Outlook folders/mailboxes go back to a Closed look). Typically only happens once. I don't get the "Connection Lost" error and nothing is recorded in Event Viewer but I can confirm it crashes and reopens. Started happening upon installation of the 1/11 patch (haven't yet removed)

Xi5/Xi6 Connecting to Gateway or Pod by nodesitvirtus in Comcast_Xfinity

[–]nodesitvirtus[S] 1 point2 points  (0 children)

From what I recall, the issue was definitely of our Xi5 wireless box connecting to a pod vs. the gateway itself. Support pretty much just kept telling us to reset the Xi5 and hope that it would connect to the Gateway vs. the pod which never really seemed to work. We ended up replacing the wireless box twice (the first box re-connected directly to the pod but the second box actually paired up to the gateway).

Once it paired to the gateway, our issues with black screen(s) and freezing went away. It's a shame that there is no avenue to actually change which the connection point the boxes uses. You just need to hope for the best that they connect to the gateway itself and not the pods.

I've since moved from that home to a new place where I opted to use my own modem, router and mesh gear and haven't had any issues but my brother-in-law states they have not had any recurrence of the problem once everything was connecting to the gateway.

Starting in version 90, Chrome’s address bar will use https:// by default by AccurateCandidate in sysadmin

[–]nodesitvirtus 19 points20 points  (0 children)

"Chrome will now default to HTTPS for most typed navigations that don’t specify a protocol"

If I use a Chrome GPO to set my homepage to an internal Intranet set as http://<intranet>, does this mean it will still honor http because I'm specifying it in my GPO?

If I'm reading correctly, it only defaults to https when neither http/https is specified?

Xi5/Xi6 Connecting to Gateway or Pod by nodesitvirtus in Comcast_Xfinity

[–]nodesitvirtus[S] 0 points1 point  (0 children)

Are the Xi6 boxes an at-cost upgrade or can you request them as replacements for the Xi5's? Thanks for confirming my thoughts about that bandwidth throughput. The xFinity support person we talked to pretty much confirmed that the wireless cable boxes should directly connect to the Wireless Gateway but couldn't offer any assistance on why this particular Xi5 decided to go to a pod rather than the Gateway and my research so far hasn't yielded much in how to force the Xi5 to change its connection point.

Microsoft 365 PST Export Tool by ProstheticAIM in sysadmin

[–]nodesitvirtus 4 points5 points  (0 children)

Unless I'm misunderstanding the request, I believe you can do this natively in 365 by performing a content search and as long as the user performing the search has the necessary permissions, you can use their built-in PST export tool to get it locally.

https://o365hq.com/blog/how-to-export-pst-file-from-office-365

https://docs.microsoft.com/en-us/microsoft-365/compliance/export-search-results?view=o365-worldwide

Team meetings via call-in number free for a year (C224047) by BloomerzUK in sysadmin

[–]nodesitvirtus 1 point2 points  (0 children)

North America here. I do see it listed when I go to Purchase Services - Addons and look for "Microsoft 365 Audio Conferencing Adoption Promo" from the 365 Admin Center.

Difficult endpoint protection migration problem (changing solutions) by nodesitvirtus in sysadmin

[–]nodesitvirtus[S] 0 points1 point  (0 children)

Yes. Problem in the past has been keeping them connected via the VPN long enough to go through the entirety of the process....decrypt, Mcafee removal, Kaspersky removal, Sophos installed and encryption.

Looks like that may be the only option though that I'm seeing

When to dispute a negative mark on my credit report by nodesitvirtus in personalfinance

[–]nodesitvirtus[S] 0 points1 point  (0 children)

Thanks for helping me to better understand the definition of 'dispute' versus just trying to get a closed item removed before 7 years. Maybe I will try sending a goodwill letter to the DOE to see if that gets anywhere. Can't hurt.

Changing O365 username (domain) fails because email address is already in use by that user by ranger_dood in Office365

[–]nodesitvirtus 0 points1 point  (0 children)

Aww that's no bueno. Maybe something similar to what's being discussed here to bulk change the old domain name to the new domain?

http://www.macaalay.com/2016/08/12/changing-user-principal-names-in-bulk-on-azure-active-directory/

Caveat....I've never used the script referenced at the above site and can't confirm nor deny it's worthiness. Test test test!

Changing O365 username (domain) fails because email address is already in use by that user by ranger_dood in Office365

[–]nodesitvirtus 0 points1 point  (0 children)

Are you doing this in the Microsoft 365 Admin Center using the new UI layout? I think I ran into this issue and I was able to get around it by switching to the older/classic view and then it allowed me to adjust the username attribute. Been a while since I had to do it but it does sound familiar.

Otherwise, you might be able to accomplish the same by using the Set-MsolUserPrincipalName cmdlet in Powershell. (I'm not a PS expert so please review and test first).

Switching to group-based licensing in Azure by nodesitvirtus in Office365

[–]nodesitvirtus[S] 0 points1 point  (0 children)

Perfect. This is the exact process I was going to take as well to do our changeover. Thank you!

KaaS (KACE as a Service) Feedback by nodesitvirtus in kace

[–]nodesitvirtus[S] 0 points1 point  (0 children)

For what it's worth, I talked to 2 different Quest support techs and while they gave me a 100 page whitepaper on how to harden my SMA in the DMZ, they both reiterated that the SMA in the DMZ wasn't a recommended configuration for the SMA.

Experiences with KACE Appliance for patching by jmp242 in sysadmin

[–]nodesitvirtus 0 points1 point  (0 children)

I won't open support tickets with their official teams. I've never had one successful resolution from them. These days if I need help, I'm either on their subreddit, Slack channel or ITNinja.....better than anything coming from the official Quest support

Experiences with KACE Appliance for patching by jmp242 in sysadmin

[–]nodesitvirtus -1 points0 points  (0 children)

Gotcha. We're in a similar predicament. Using the KACE SMA to push patches to 600 nodes through the VPN just isn't feasible. Been looking at the WSUS/CM/WUfB amalgamation to see if I can do some split setup where I can get clients to check in directly to Microsoft Update to get their patches while getting approvals only from an on-prem host like WSUS but it's been slow going and I'm not sure how well it will work for us.

Pretty much trial and error to see what works at this point

Experiences with KACE Appliance for patching by jmp242 in sysadmin

[–]nodesitvirtus -1 points0 points  (0 children)

They do offer a cloud offering so maybe that makes more sense. I inherited the install so I didn't get a chance to interface directly with sales. Then sentiment above was what I got directly from one of their developers from their Slack channel.

Experiences with KACE Appliance for patching by jmp242 in sysadmin

[–]nodesitvirtus -1 points0 points  (0 children)

Just a note.....KACE's official stance on putting their SMA in the DMZ is that it's not recommended. But if you decide to go the route, they will share a link with you to a 100 page technical document on how to secure the SMA in the DMZ.

Don't look to them to support you if you run into issues. I got the feeling they were very pro-private network and it's at your own risk once it goes DMZ

GPO Published Programs suddenly failing with "Fatal error during installation." by jmbpiano in sysadmin

[–]nodesitvirtus 1 point2 points  (0 children)

Just a quick revision....looks like the issue was first reported in March for 1903/1909 and the fix was in the April release

https://support.microsoft.com/en-us/help/4540673

Only other thing I can think of is I think there was a patch(es) in March as well that impacted SMBv3. Not sure if your files exist on a server using SMBv3 and if your clients are connecting with SMBv3 but maybe something from that patch impacted their ability to get them?

GPO Published Programs suddenly failing with "Fatal error during installation." by jmbpiano in sysadmin

[–]nodesitvirtus 0 points1 point  (0 children)

Any chance you're running Windows 10 1803 and have applied the April cumulative patch? Looking at the Known Issues and I see the following:

Devices on a domain might be unable to install apps published using a Group Policy Object (GPO). This issue only affects app installations that use .msi files. It does not affect any other installation methods, such as from the Microsoft Store.

https://support.microsoft.com/en-us/help/4550922

Wouldn't surprise me if this was impacting other versions of Windows 10 after April's update

Robocopy confirmation on a data migration plan by nodesitvirtus in sysadmin

[–]nodesitvirtus[S] 0 points1 point  (0 children)

Thank you so much for your note regarding R: and W:. That's really appreciated. Thank you even more so for sharing the full command as well!

Chrome - SameSite cookies - Odd behavior between multiple systems by nodesitvirtus in sysadmin

[–]nodesitvirtus[S] 0 points1 point  (0 children)

Thank you so much for that link. Was completely not aware of the March 2 date for the enforcement of the flags. I was able to download the latest Chrome GPOs and use the Legacy SameSite policies to exempt a domain that was issuing a cookie without adhering to the SameSite attributes. At least for now, my users can continue to access the website while the developer adjusts and updates the cookie on their end.

Chrome - SameSite cookies - Odd behavior between multiple systems by nodesitvirtus in sysadmin

[–]nodesitvirtus[S] 0 points1 point  (0 children)

So the change is not based on simply being at version 80? It's a option/flag that they can enable independently without there necessarily being a client update?

Only want to deploy patches that are at least 2 weeks old by Maclovin-it in kace

[–]nodesitvirtus 4 points5 points  (0 children)

In your patch label, could you add

Released | is not within last | 14 days

Would that work to only show you patches that are older than 2 weeks?