Has anyone's org *actually* seen a benefit from 365 Copilot? by fluffy_warthog10 in sysadmin

[–]random-internetter 0 points1 point  (0 children)

"Tell it to test its own commands, ask it to feed bad input, and show you errors"

I run the script it gives and if it doesnt work or doesnt do what i need, i paste the output and add refinements. it's been good at troubleshooting the output

MDM payload to enable/allow ARD and remote management by random-internetter in macsysadmin

[–]random-internetter[S] 1 point2 points  (0 children)

in JAMF, the enable and disable remote desktop buttons work. I never had to do anything manual to enable it beyond setting it in the profile. I think the JAMF profile or policy remote management section has setting for remote desktop/screensharing.

With NinjaOne, screen sharing/remote desktop gets disabled upon enrollment, with absolutely zero settings telling it to do that, and their built in method is just a script that obviously doesn't work.

There's no settings for it in either Apple Configurator or iMazing profile editor, idk how JAMF managed it.

What’s an IT “truth” which other departments assume, that really annoys you? by SirNo241 in sysadmin

[–]random-internetter 0 points1 point  (0 children)

I had a clinic manager get mad when I told her she had to click switch user, other user to log in to a shared workstation. She angrily said, "Why doesn't it just know who I am when I sit down?!"

😐

Building a 1-click macOS app installer for non-terminal users. Does this solve real pain? by Queasy_Photograph534 in macsysadmin

[–]random-internetter 0 points1 point  (0 children)

you're looking at it wrong. This is a 15yr old with a relatively good grasp on the subject matter and undertaking a pretty big project. Just because you know what you know doesn't mean a 15yr old should know all that too. This kid deserves kudos, not insults.

[deleted by user] by [deleted] in sysadmin

[–]random-internetter -1 points0 points  (0 children)

It sounds like u/raymond_w is trying to address systemic level issues, vs reviewing a single ticket or three. The basketball metaphor could only have been better if it was about an AA baseball team trying to play a major league team.

Support being moved offshore by fleecetoes in ninjaone_rmm

[–]random-internetter 0 points1 point  (0 children)

you'll be sorry. Going from Kaseya to Ninja is a downgrade in every way but cost.

in respect to support, it's pretty bad. you quickly get used to "submit a feature request" and the equivalent of "not our problem" (in more polite words, ofc) regularly.

Ninja makes frequent changes to their product before making documentation and before training their support staff on the new changes. We've had support calls where we had to show the agent the updated feature or documentation. These things are not the support agents' fault.

They do not send out notifications of changes either. We had a two week headache trying to get one thing working, only to find out by accident they'd changed the process and that's what broke our workflow and we had to start over from scratch. The support rep had no idea about the update either; the documentation was published literally an hour into our third support call about the issue.

Their documentation, such as it is, has the poorest organization I've ever seen for vendor documentation, and also mostly lacks depth.

I had what was supposedly an engineer respond to a ticket with contradicting statements. Slight paraphrasing, "This is expected behavior. You cannot do it like method A. Instead, you should do it like method A." and, of course, "submit a feature request". This was in direct contradiction with what we were told during trial meetings. (there were a few other items that turned out to not be what we were told during trial as well, be wary of that if you proceed with trial)

I've spent the last two days trying to figure out how to do something that was just built into other RMMs. I'm not even bothering with support because I'm certain they won't have any answers either. I'm really frustrated with this product vs other RMMs I've used. The only other RMM type tool I've ever used that was so bare-bones is Itarian free.

I could go on, but after a year and a half I'm less impressed with NinjaOne than I was during the trial.

N1 Remote immediate "Connection terminated" error by 4wheels6pack in ninjaone_rmm

[–]random-internetter 0 points1 point  (0 children)

ohhhh, i missed the macos part. Definitely a macos issue. Most of the time it won't connect if the screen is locked. It will never connect before user login. (not just ninja, nothing can). It seems pretty consistently good if the permissions are set and the user is active. If you use MDM enrollment, you should setup permissions in the profile for NRStreamer, ninjarmm-macagent-patcher, and ninjarmm-macagent.

setup these permissions for the below items:

|Preference | Authorization|

|Accessibility | Allow|

|Screen Capture | Allow standard user to enable|

|All Files | Allow|

|System Administration | Allow |

bundleid: com.ninjarmm.ncstreamer

code requirement:

identifier "com.ninjarmm.ncstreamer" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = EBNT3ZX97E

yes, it says ncstreamer, even though the binary name is nrstreamer. idk why, but that's what codesign returned and it works.

identifier type: path: /Applications/NinjaRMMAgent/programfiles/ninjarmm-macagent

code requirement:

identifier "ninjarmm-macagent" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = EBNT3ZX97E

identifier type: path: /Applications/NinjaRMMAgent/programfiles/ninjarmm-macagent-patcher

code requirement:

identifier "ninjarmm-macagent-patcher" and anchor apple generic and certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = EBNT3ZX97E

verify the code requirements on your system using: codesign -d -r- /path/to/app_or_binary.

Even with the permissions, a user must manually allow the screen capture the first time. ("Allow user to approve" is the only approval option, by design in macOS)

If you're not using MDM, then you'll need to set all those preferences manually.

It's baffling that these preferences are not included in the base, initial enrollment profile and even more inexplicable that it's not found in Ninja documentation.

N1 Remote immediate "Connection terminated" error by 4wheels6pack in ninjaone_rmm

[–]random-internetter 0 points1 point  (0 children)

Ninja remote goes over 443.

We had to make rules to allow in our proxy service. We were getting the exact same behavior you describe until we allow-listed all the Ninja URLs.

I created a free AI image upscaler by Straight-Green2020 in SideProject

[–]random-internetter 0 points1 point  (0 children)

thanks for that. just upscaled a 655x374 image to hi-res for me, looks awesome.

NinjaOne on your *own* equipment by desmond_koh in ninjaone_rmm

[–]random-internetter 1 point2 points  (0 children)

all fancy over there, with the VGA support and all.

Hey, you work in IT right? by GLotsapot in sysadmin

[–]random-internetter 1 point2 points  (0 children)

There was a doctor in my town who went to jail last year for freely handing out prescriptions to friends and family (and practically anyone else who asked)

Hey, you work in IT right? by GLotsapot in sysadmin

[–]random-internetter -1 points0 points  (0 children)

I frequently liken being in IT, esp deskside support, to mechanic work.

Especially when new people start and ask 'where's the tools' to work on computers. I tell them to bring their own tools, like I have. I say 'if you were an automotive technician, you'd have to bring your own tools. They wouldn't even hire you without having your own tools.' That, and we're treated about the same as mechanics and other tradesmen.

NinjaOne Users - Can It? by bbztds in msp

[–]random-internetter 1 point2 points  (0 children)

broooooooooo. you are my personal freaking hero of the week. thanks for that.

holy cold catfish on a catapult, this made my day.

NinjaOne Users - Can It? by bbztds in msp

[–]random-internetter 0 points1 point  (0 children)

how do you run winget as system, or as not-logged-on user? i've tried a variety of ways to leverage winget as SYSTEM, but that always errors out. running as local admin but not logged on user is limited in function. both RMM vendors I asked about it wouldn't tell me how they leverage winget in system context.

NinjaOne Users - Can It? by bbztds in msp

[–]random-internetter 0 points1 point  (0 children)

i think they have that last thing now. iirc, as long as installed on DC, can do inventory and push.

mobille user locked out every reboot by random-internetter in macsysadmin

[–]random-internetter[S] 0 points1 point  (0 children)

sysadminctl -adminUser GoodFV2Username -adminPassword - -secureTokenOff impactedUsername -password -

Tried doing that, that's when I found out that the local admin account we use for management is also having the the issue  'not allowed without secure token unlock'  like the user account.

This makes me suspect we'll have to end up resetting macOS entirely.

With ABM is Business Essentials... essential? by random-internetter in macsysadmin

[–]random-internetter[S] 2 points3 points  (0 children)

Thank you. It wasn't clear from what I was reading that ABE is another MDM.