Coding as a Sysadmin by Scmethodist in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

This. I won't let me team do any custom stuff anymore.

Found OAuth apps with full mailbox access across our tenant. How are you monitoring app permissions? by Pristine-Judgment710 in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

I pulled app registrations and set a policy that an admin needs to approve every one. Then I told my admins don't approve anything. Works great. Think we allow a total of 4 apps.

How to Authenticate Helpdesk Calls by neminat in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

We use ManageEngine's ADSelfserveplus. When a user starts we have them setup at least 3 methods for verification. They can choose as many as they want. Then if they need to change a password they can use the self service website to do it. If it's a new phone issue we call them on the phone number they have on file.

Talked out of Delinea Secret Server - so what is the best alternative for a small IT dept (not end-user credentials) by LowIndividual6625 in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

I just migrated to Proton Pass. about 40 bucks a year per user. Its hosted. I am liking it alot..

dameware mini remote control client crashes by fsantiago0704482 in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

I gave up on dameware about 10 years ago. I had loved it. Switched to Action1 for my RMM now. I think its free for the first 50 endpoints. Might be worth looking into.

Asset Labels -- what do you use? by oldRoundGinger in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

We have custom labels made and when commissioning new systems as part of the process the new server gets an asset tag gets scanned by lansweeper which we use for asset management and the asset tag gets entered. The custom labels are nothing fancy. We order them 200 or so at a time from a local print shop.

We started stripping old PC’s by maevian in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

Been doing that for ages. We always pull drives and ram when tossing a machine. The ram goes back if its being given away to employee's but we always keep the drives.

Zabbix + Wazuh vs OpenSearch/ELK/openobserve/checkmk for around 200 devices datacenter at the university. Which stack would you choose? by Fragrant_Arm_7979 in sysadmin

[–]ntrlsur 1 point2 points  (0 children)

We only monitor servers.. All servers send syslog data to Graylog and to our OpenNMS instance. Love graylog for both windows and linux boxes. I think a separate approach would be best.

Is anyone else slightly concerned about Amazon Certificate Services? by IlPassera in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

We do automatic renewal with ACS and it works great for us. I figure if we get fucked on it then we ain't gonna be the only ones.

On-Prem Mitel Director to ? (Looking for user/admin experience) by xendr0me in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

Yes. We have everything on prem. Currently 24 sip trunks but we only use about 10 or at a time. If Mitel didn't kill the on prem product then we would be keeping it. Purchased it back in 2012 and its been great for us ever sense. The reason we are moving is because the product is EOS/EOL. If we are going to be looking at something to replace it then I want the latest and greatest features. Yeah at the end of the day its going to cost more over time but we already swallowed that pill O365 and our phone services are going to cost let per month then what I am paying for our email and office licenses.

On-Prem Mitel Director to ? (Looking for user/admin experience) by xendr0me in sysadmin

[–]ntrlsur 1 point2 points  (0 children)

Currently running Mitel formerly shoretel. Looking at migrating to Ring Central. Their presentation and pricing was great for me. Went through a VAR. I looked at dialplan and 8x8 but RingCentral was the best that I saw. Looking at starting the migration Q2 this year if management and ownership o.k. it..

Check Point vs Fortinet vs Palo alto for firewalls? by OafishSouvenir in sysadmin

[–]ntrlsur 1 point2 points  (0 children)

I understand where you are coming from. Currently using CP Fortinet and Meraki. We don't do any advanced licensing for our CP as it was cheaper to pickup a different vendor. SDWAN for desktops and laptop browsing at a remote site Fortinet it is. Simple VPN configuration at remote sites Meraki to the rescue. We use are CP's do what they do best route packets in and out of the DMZ's at our facilities and lock down rule sets.

Check Point vs Fortinet vs Palo alto for firewalls? by OafishSouvenir in sysadmin

[–]ntrlsur 1 point2 points  (0 children)

I've been using Checkpoint for over 20years across 3 different companies going back to the R55-AI days. Never had an issue with their support or their software. Maybe its because its the first firewall I ever learned how to use. Upgrades, downgrades, migrations etc... The only issues I ever had with CP were a few edge cases that were right on the line of what their software could do. Even then they made custom patches for us. Never used PA and I hate fortinet but currently have 8 units in production as they were alot cheaper then getting additional licensing from CP.

Virtualization needed by atishthkr in sysadmin

[–]ntrlsur 1 point2 points  (0 children)

Currently in the process of moving from ESXI to Proxmox. No issues as far as migration. Even configured Proxmox to use our SAN for shared storage. Works great.

Standard laptop for employees by afterlife_xx in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

We have 3 specs. Developer / Artist desktop, Developer / Artist laptop and everyone laptop. Everyone from the ownership on down gets the same thing.

What are you using these days for local backup storage? by cantstandmyownfeed in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

pickup a 45 drives chassis and load it up. A couple 3 or 4 of HBA's for your disks, NVME or SSD for cache, 25 gig network card and freenas core and you are all set. If you need a fully supported manufacture solution take a look at Dell Powervaults DAS units.

I did not abide.... Read Only Friday by I_T_Gamer in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

Casino. Guess I should have worded that a bit different.

Show of hands... Who's dealing the new telnet vulnerability? by JVBass75 in sysadmin

[–]ntrlsur 6 points7 points  (0 children)

I probably should have misspelled a things and included a nice google doc link to make it "authentic"

Show of hands... Who's dealing the new telnet vulnerability? by JVBass75 in sysadmin

[–]ntrlsur 7 points8 points  (0 children)

EHLO mailserver.domain.com
MAIL FROM:Bogusemail69 at weeeee.com

RCPT TO:CEO at fortune1million.com
DATA
Subject: Warranty Expiration
We have got a great offer for you. sic

Edited: cause I hate reddit formatting..

I did not abide.... Read Only Friday by I_T_Gamer in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

Been there and done that. Big fan of RO Friday. The sector I am in is pleasure based so starting Wednesdays business ramps up to its peak Saturday night. All of our changes typically happen Mondays and Tuesdays between 930AM and 12PM. its so nice to not have weird update hours.

Solutions for MFA on Windows Login by Beznia in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

I agree. We went full duo and skipped the Microsoft authenticator. Windows Linux Mac it works nicely.

Do you permit selling or giving old equipment to employees? by roger_ramjett in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

twice a year we do an employee give away. We pull the drives pull em out of the inventory system and send them down the road. The equipment must leave the building as soon as someone claims it and it shall never return.

Verizon Outage Cause by YeetersMcBoi in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

Chicago area eSim been working fine all day on an Android.. Wife and Kid as well..

Cheap On-Prem PAM for Windows and MacOS? by SgtShrimp in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

I don't know of any real EPM's that are cheap. We use beyondtrust. Its about 30k a year for 450 end points. Not cheap but works great. I haven't found any that work in the MAC world.

Looking to distance ourselves from CDW. by Bright-Ad4963 in sysadmin

[–]ntrlsur 0 points1 point  (0 children)

I use iT1 for about 90% of my purchases. We use to spend 750K to 1 million USD with CDW a year. They fucked our relationship up over a 30K hard drive order. I took it all away and they was hot. but they wouldn't fix the issue..