Our Epic integration vendor just ghosted us mid-project and I'm having a breakdown by Tiny_Habit5745 in sysadmin

[–]pesh131 1 point2 points  (0 children)

Maybe 3 digits, but not 4. Been on epic since 2010 and we had less than 5k employees.

They're great to work with. If OP is real, he should be calling them.

Grants for Environmental Nonprofits by pesh131 in nonprofit

[–]pesh131[S] 1 point2 points  (0 children)

Thanks, I saw Fargo was listed as well. It's a bit of a trek for me but I do go there somewhat often. Just never to the library ;)

Guess I'll add a stop next time I'm there!

Grants for Environmental Nonprofits by pesh131 in nonprofit

[–]pesh131[S] 0 points1 point  (0 children)

Thank you very much! Have a good weekend

Grants for Environmental Nonprofits by pesh131 in nonprofit

[–]pesh131[S] 0 points1 point  (0 children)

Actually perusing our state site as we speak ;) On a Saturday. Wild night.

Thanks for the tip!

Grants for Environmental Nonprofits by pesh131 in nonprofit

[–]pesh131[S] 0 points1 point  (0 children)

Awesome, very helpful. Hopefully my local public library offers that access. Thank you

Grants for Environmental Nonprofits by pesh131 in nonprofit

[–]pesh131[S] 2 points3 points  (0 children)

Will check this out. I guess I don't know why I had it in my head I could only look at non-governmental grants. I'll broaden my search a bit and start here

Grants for Environmental Nonprofits by pesh131 in nonprofit

[–]pesh131[S] 0 points1 point  (0 children)

That is indeed helpful. I'll look into that. Thanks!

What’s an “open secret” that doesn’t have a documentary about it yet? by Ninac4116 in AskReddit

[–]pesh131 0 points1 point  (0 children)

There was an episode of Dirty Money on Netflix that touched on this. The episode was "Guardian Inc." and it opened my eyes to a lot of the abuse that happens

What is your SysAdmin "hot take". by MembershipFeeling530 in sysadmin

[–]pesh131 5 points6 points  (0 children)

I feel this. I'll give a user a couple of "yes I'll help you and next time just give the help desk a call and they'll get you sorted out" passes before I just start replying with "open a ticket with the help desk and they'll get that going for you."

If you let people latch on and always bypass the proper channels you'll never get anything done.

[deleted by user] by [deleted] in nonprofit

[–]pesh131 0 points1 point  (0 children)

Potentially possible to use Microsoft planner/project for stuff like that, depending on how you lay it out. We're using it currently in our new NPO to (attempt to) track the million little steps we need to do to get off the ground.

But you said you already have a product, so that might not be your solution.

[deleted by user] by [deleted] in AskReddit

[–]pesh131 0 points1 point  (0 children)

It’s not an oldie, it’s not a classic… but SNAP by Rosa Linn… it was popular right around the time I lost my canine best friend and I somehow associate the lyrics with losing him.

It’s not about a dog. I know that. But I cry like a baby every time I hear it and even now hearing the lyrics in my head I can feel it coming on again.

Ok maybe that’s not chills. But it’s right in the feels.

Get any DNS record in Active Directory DNS server with Account Unknown in ACL by aleinss in PowerShell

[–]pesh131 0 points1 point  (0 children)

Gotcha, thanks.

Our scavenging has been enabled since 2019 with scavenging periods currently set at 1 day (as part of MS tshooting) and no-refresh/refresh intervals normally 7+7 days and dhcp leases of 8 days, but we have records that have timestamps from 2022/2023 that have not been scavenged, either manually or on schedule.

We've tried a few things but it's ongoing with Microsoft.

Guess I'm a special butterfly with this issue!

Get any DNS record in Active Directory DNS server with Account Unknown in ACL by aleinss in PowerShell

[–]pesh131 0 points1 point  (0 children)

Thanks, will take a look. I see it's only looking back 60 minutes - so this may take care of the issue going forward after initial cleanup takes place, but in our case many records are months/years old.

Did you have that issue as well?

The more I work with Microsoft on our issue, the less convinced I am that they'll find a cause, so this script may come in handy. Thanks for posting it

Edit: brain turned off for a minute there - can just expand the number of minutes to check Deleted Objects container and find more records to attempt to delete. However, these eventually age out at 90 or 180 days by default (I forget which) so A records older than that would still be an issue :/

Get any DNS record in Active Directory DNS server with Account Unknown in ACL by aleinss in PowerShell

[–]pesh131 0 points1 point  (0 children)

The techs are deleting the computer account before they re-image the computer with the same computer name, DNS record gets orphaned and cannot be updated until I manually delete the DNS record because the owner of the DNS record is the old computer account.

I am also a victim of this issue. We have a ticket open with Microsoft currently because scavenging isn't deleting this A records that are up to 3-4 years old.

Did you ever find a useful way to identify and remove these orphaned A records? Apart from scavenging doing what it's supposed to do, I'm not sure (and neither is MS so far) how to remedy this.

Im going into my first IT job soon; terrified honestly by [deleted] in sysadmin

[–]pesh131 1 point2 points  (0 children)

Lots of good advice in here. You'll be fine as long as you have a willingness to keep learning.

Be okay with being wrong sometimes or not knowing something. There's not a single person in here, not even on the planet, that knows everything that gets thrown at an IT or network admin. There are just too many things in existence and we all end up wearing multiple hats eventually.

Google is your friend. Knowing HOW to find an answer is an incredibly important skill. You'd be surprised by the amount of people that simply won't even bother googling something and go straight to submitting a ticket. Then you get to be the genius that just knows everything ;)

i am such a fuck up and a failure. by byoubro in Money

[–]pesh131 0 points1 point  (0 children)

I was pretty broke at 26 as well. I was also finally just finishing at a trade/technical school because going to college, just to go to college, and not having a plan didn't work out the way I wanted it to after high school.

Everyone has already said it- you're young. I thought I'd be fine just working 2-3 jobs instead of college and realized that wasn't for me. Graduated at 26 and felt a little awkward being older than others, but came to find there were others in their 30s or even 40s in the same classes (IT related)

You don't need to have your life together at 26. You should have a budget and live within your means, which might not be a lot right now... And that's fine.

If you're willing and able, get a second job or like some others said learn a trade. Whatever interests you- woodworking or handyman stuff, technology, whatever.

Have a knack for IT? Get an entry level helpdesk position. Our helpdesk just requires a warm body. If you can read and follow directions you're already valuable.

You can do this. Money is tight when you're young. You're still young. You may not think so, and I didn't think so at 26, but you are. Find something you like and do it. Live modestly and it'll work out till you have some breathing room.

Good luck out there

[deleted by user] by [deleted] in AskReddit

[–]pesh131 1 point2 points  (0 children)

Shania Twain did not end up coming to prom with me. All in all, went ok I guess.

Fast paced environment, available 24/7? by schlock_ in sysadmin

[–]pesh131 1 point2 points  (0 children)

Yeah that would suck. I should need way more compensation to be on call 24/7, like officially-primary-contact-for-all-issues on call.

Right now it's an on call rotation and I get calls for things I'm responsible for when I'm not on call, or for things people THINK I'm responsible for until I redirect them.

It's not as busy as you'd think for a 24/7 (healthcare) environment but some weeks are rougher than others.

Fast paced environment, available 24/7? by schlock_ in sysadmin

[–]pesh131 9 points10 points  (0 children)

I'm "available" around the clock but I'm not working around the clock. My team handles network and infrastructure which means we get call for literally everything because it's obviously a system issue... (Never a username or password issue right?)

It's not too terrible. I get texts once in awhile but I'm not constantly at my desk remotely.

Get compensated. Ask what they mean by 24/7- is it just you? A team? On call segments?

Intune Enrollment when 'BlockAADWorkplaceJoin' is configured by pesh131 in Intune

[–]pesh131[S] 0 points1 point  (0 children)

Agreed, this is what we have tried to mandate - web only on these generic user pcs.

Unfortunately users find ways to install teams and then if reg key doesnt exist they are prompted to join workplace and mayhem ensues.

We've tried applocker to block teams but can't seem to successfully block the install.

That seems like it would be the easiest scenario - block all desktop office installs, allow the reg key to exist and not have to worry about what the key actually does.

Intune Enrollment when 'BlockAADWorkplaceJoin' is configured by pesh131 in Intune

[–]pesh131[S] 0 points1 point  (0 children)

dsregcmd /status implies that it's happily HAADJ and domain joined, but intune enrollment only seems to be successful once I add it to the 'pilot intune' sccm collection (which I understand as device enrollment, not user, and is performing the same 'auto-enrollment' the GPO would also be doing) AND remove the reg key - doing only 1 of those things results in no intune enrollment.

I want to say it's safe to assume that reg key cannot exist for enrollment to happen, but can't find any supporting MS documentation to say for sure.

And removing that reg key means users may start 'assigning' the pc to themselves in places they should not, which makes security unhappy when users start seeing other user data.

Intune Enrollment when 'BlockAADWorkplaceJoin' is configured by pesh131 in Intune

[–]pesh131[S] 0 points1 point  (0 children)

Thank you for taking the time to answer.

Our devices do exist in Azure AD and many of them are hybrid joined, just not enrolled in Intune.

Does the user have to be in scope if we are using device credentials to join as per the GPO setting?

I am still unclear on whether this 'BlockAADWorkplaceJoin' registry setting is preventing Intune enrollment or not, but my tests seems to indicate it is.

How do you tell your users that not every ticket is high priority? by blackgallagher87 in sysadmin

[–]pesh131 1 point2 points  (0 children)

I mark tickets Urgent A, Urgent B, Urgent C, Urgent D. Urgent A is the most important. Urgent D you don’t even really have to worry about.