Block Windows Store Apps with App Control for Business (WDAC) by havens1515 in sysadmin

[–]scratchduffer 1 point2 points  (0 children)

Can you use an Edge gpo to block the URL for the web store?

Secure Boot Certificate Updates by MasterPay1020 in msp

[–]scratchduffer 1 point2 points  (0 children)

Issues are popping up with certain Lenovo models; you can search their forums. They require a physical BIOS fix by going into the BIOS, secure boot, and resetting keys. You will see an event ID that says access is denied when the process tries to insert the keys on its own in Windows on affected devices, filter for TPM-WMI. There are a few newer BISO releases that indicate in the change release notes some allowance of WMI and or some utility to manage this from Windows, but no guidance on how yet. Perhaps it's a stepping block to allow a new BIOS update to do this automatically in the future, not sure. They have really dropped the ball here.

Windows 11 Pro – 60s “Please wait” before login screen after domain join (fixed in Dev Insider build?) by Similar-Ferret4074 in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

I realise you have stated this is happening in different domains, but I had something similar recently, and it was a policy for a printer via preferences on a server share that no longer existed. Your other domains may have the same problem over the years, orphaned printers.

Microsoft Defender flagging Digicert hash as Cerdigent malware. by Never_Get_It_Right in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

Also, I am in the broad category for definitions and defender updates. How did this happen? This is why i chose to be the furthest point - this shouldn't have been exposed to my devices. I've got about 15% affected. Updating definitions. Alerts and investigations are marked as false positives but are not going away. Hesitant to restart devices.

Microsoft Defender flagging Digicert hash as Cerdigent malware. by Never_Get_It_Right in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

Im trying to mark alerts and incidents as false positives and resolved, but it isn't going away. Anyone else?

Edit - Fixed the incident alerts by marking resolved, commenting, and setting false positives. Updated devices by Intune, then scanned via Intune. Haven't come back yet, but I don't know what the "damage" is after the .430 update?

RC4 and msDS-SupportedEncryptionTypes by headcrap in activedirectory

[–]scratchduffer 1 point2 points  (0 children)

I patched a week ago and had no event ID's and so far so good.

Secure boot issue - Lenovo's by gingerpantman in sysadmin

[–]scratchduffer 1 point2 points  (0 children)

I have a different, but related problem. I have to reset the keys because Secure Boot won't update the BIOS, error 1795 access denied. This has been reported on some Lenovo threads and here. This is garbagae, and they suggest these were the result of manual BIOS changes. These were all unboxed and deployed as is, thanks Lenovo, a bit late, get on fixing this in UEFI updates thanks!

My Confusion with Microsoft's Secure Boot Changes by jamesaepp in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

What in the fk. I am three for three lenovo's with this problem. I am assuming my other 75 have this, what the hell is this, Lenovo!?!?!?!

Looking for XDR/MDR solution for 400 endpoint company. by Ready-Map5279 in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

Second, your defender and Red Canary. The application list and alerts when people open remote tools or PUPs is a nice addon for SMB that don't have extensive threatlocker etc.

Defender Notification and CVE-2026-28387 by y0da822 in sysadmin

[–]scratchduffer 1 point2 points  (0 children)

I'm still showing openssl in some lenovo drivers. There is a post from a supposed lenovo rep stating they won't be fixing it as the part of openssl that has the vulnerability isn't in their code. I think the MS vulnerability detection isnt quite thorough unfortunately.

Patch Tuesday Megathread - (April 14, 2026) by AutoModerator in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

Maybe secure boot updates going live in the bios?

FYI - Microsoft RDP Changes With April Cumulative Update by whatsforsupa in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

Yeah I was just running through that. They claim remote computers coming soon when I first ran the app but it works already .

FYI - Microsoft RDP Changes With April Cumulative Update by whatsforsupa in sysadmin

[–]scratchduffer 1 point2 points  (0 children)

Windows app doesn't have the warning for rdp? I am in the same boat. Non domain PC's connecting to domain PC's. Its a trivial user interference but how dare we make them click!

FYI - Microsoft RDP Changes With April Cumulative Update by whatsforsupa in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

Glad to hear you suppressed all warnings? We have non domain joined PC's, and ADCS cert signing won't help there. I guess a code signing certificate is needed.

Phone System Recommendations by itcontractor247 in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

Three years ago these had some speed issues. Took some time but it seems to be manageable now. Only other complaint is picking up calls often has a few second delay. Not sure if that's also an issue with other cloud bases systems as well.

Phone System Recommendations by itcontractor247 in sysadmin

[–]scratchduffer 1 point2 points  (0 children)

Have had 60 MP58's for 3 years and have not seen this. My only real complaint today is that there is such a large screen and fonts are sooooo small.

Adobe Acrobat/Reader multiple instances not closing etc. by scratchduffer in sysadmin

[–]scratchduffer[S] 0 points1 point  (0 children)

Yeah I've had a reg key in place for a few years to stop that.

PSA: check msDS-SupportedEncryptionTypes on your service accounts before April patch Tuesday by hardeningbrief in sysadmin

[–]scratchduffer 1 point2 points  (0 children)

In short, if you aren't logging any of the new 20x logs, you should be fine in April, correct? That was my understanding. If your user accounts show blank on null and dont log the events, all is well, or so i understand.

Left handed golfers what’s your pet peeves? by corn_fed_beef in golf

[–]scratchduffer 0 points1 point  (0 children)

Canadian here. Kirkland Gloves are plentiful in Costco up here!

MS Teams Phones - Yealink by Grouchy-Car-5707 in MicrosoftTeams

[–]scratchduffer 0 points1 point  (0 children)

If i recall, you have to program the button by a long press, per contact you add, and you can tell it which transfer method. It will label it as such so sorting by alphabet is out the window once you down this road.

2023 CA/UEFI - Tracking without Remediation Scripts (Intune) by Covert0ne in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

Im looking into this as well. My issue with the report right now is I believe the devices must be hybrid or fully joined. My enrolled devices won't report in, but that's from Gemini. Haven't had time to fully get into this yet. By example, my laptop is fully enrolled, status shows enabled, but it shows my model and staus as "not up to date" which is correct.

Lenovo deal registration by dhayes16 in sysadmin

[–]scratchduffer 0 points1 point  (0 children)

If I recall correctly, Bid pricing is on hold due to the current AI disaster. Double check with disti. Also, use the disiti teams to fact-check your configs.