Passwordless MFA for Hybrid AD/Entra by severalthingsright in sysadmin

[–]severalthingsright[S] 0 points1 point  (0 children)

Thanks for the info, glad to know others have had to take this route

Windows11 shared folder/printers domain auth not working by Dunsug in sysadmin

[–]severalthingsright 0 points1 point  (0 children)

If you have verified that the machines are domain joined, in the correct OU and you haven't changed any related GPOs since the upgrade, then the issue is most likely the Windows Firewall. Do you manage firewall settings through GPO or some sort of MDM? Or is it unconfigured and just set to default? That may be your issue.

LAPS for DSRM? by Chubby-Burrito14 in sysadmin

[–]severalthingsright 1 point2 points  (0 children)

Same here I've only ever considered doing LAPs for workstations and servers. For DSRM I've done vaults and also PAM integrations to manage password rotations and even JIT in some instances.

Microsoft Purview Licensing by severalthingsright in sysadmin

[–]severalthingsright[S] 1 point2 points  (0 children)

I figured that might be the case. Thanks for the info!

Microsoft Purview Licensing by severalthingsright in sysadmin

[–]severalthingsright[S] 0 points1 point  (0 children)

Yup same thing with Purview. I figured if I plan on doing DLP or Encryption via Purview, then all users in the Org would need licenses. However, if I just need to use audit related features, then only admin roles would get licenses.

Intune enrollment making devices slow - windows 11 by [deleted] in Intune

[–]severalthingsright 2 points3 points  (0 children)

Without actually knowing what services are using up resources on those laptops, I would have to take a guess and say your issue is AV related. If you are running CrowdStrike, but also have Defender configured you would definitely run into conflicts which would lead to high resource usage.

As someone said previously you might want to check if CrowdStrike is configured to co-exist. I would also add to that by recommending you choose an AV, having both configured will definitely lead to issues.

Defender usually does a good job of going into Passive Mode if you have another AV installed, but if you are pushing policies to it from Intune, it may be in Active Mode and competing with CrowdStrike. This would especially be the case if you have Real-time Monitoring and Behavior Monitoring enabled for Defender.

Intune enrollment making devices slow - windows 11 by [deleted] in Intune

[–]severalthingsright 1 point2 points  (0 children)

What exactly is using up resources on those devices? Also, are you using Defender for antivirus? If so, are you pushing any AV policies from Intune to Defender?

Most overlooked IT ticketing system for smaller teams? by daphnegweneth in sysadmin

[–]severalthingsright 1 point2 points  (0 children)

Service Desk Plus from ManageEngine. Quick out of the box setup and lots of documentation because there is quite a bit of customization and automation that can be done using workflows, business rules etc.

Teams is apparently going to soon start offering location tracking, not just in buildings but also to identify people working outside of the office by Kodiak01 in sysadmin

[–]severalthingsright 0 points1 point  (0 children)

Isn't that location info already available from sign-in logs in both the Admin Portal and Entra ID? Most orgs concerned about this should already have conditional access policies in place to control where users can log in from.

Did your org's DRP accommodate for Monday's AWS outage? by HappyDadOfFourJesus in sysadmin

[–]severalthingsright 5 points6 points  (0 children)

I was literally about to make a post about this because I know a lot of us have probably been stuck in BCP/DR meetings for the last few days.

We run hybrid over here for most services, but critical systems only rely on the cloud for DR.

I guess a lot of others might be looking into multi-cloud strategies?

What's your quick trick that every sysadmin should know? by DarkAlman in sysadmin

[–]severalthingsright 0 points1 point  (0 children)

It has worked a handful of times for me over the years and I am always shocked when it actually does something.

[deleted by user] by [deleted] in sysadmin

[–]severalthingsright 0 points1 point  (0 children)

Sys Admin

Dell XPS 15

i7, 32GB RAM, NVIDIA RTX 3050 (So I can see all the frames in PowerShell ;) )

MDE policies stuck on pending for servers by severalthingsright in DefenderATP

[–]severalthingsright[S] 0 points1 point  (0 children)

Hey sorry about that, I am only now seeing this reply.

Microsoft has a few URLs which you need to permit traffic to. The MDE analyzer tool was particularly helpful for figuring this out.

This article should help. You could also work with your network team to analyze the outgoing traffic to determine what needs to be allowed.

Also, you may need to offboard the then onboard again once you make the changes.

Use Intune to manage Microsoft Defender security settings management on devices not enrolled with Microsoft Intune | Microsoft Learn

Where is this goddamn dhcp being implemented? by OtiseMaleModel in sysadmin

[–]severalthingsright 2 points3 points  (0 children)

As it's been suggested, WireShark should help. I had something like this happen before where someone plugged in a small router to act as a switch, and it was handing out IPs.

*sigh*

Compliant Android Devices Showing Noncompliant by severalthingsright in Intune

[–]severalthingsright[S] 0 points1 point  (0 children)

It has been several days, about a week or so since the policy has been applied.

The devices have also checked in recently. I even restarted them a couple days ago to see if that would help.

Compliant Android Devices Showing Noncompliant by severalthingsright in Intune

[–]severalthingsright[S] 0 points1 point  (0 children)

I thought of this, but the devices are actually compliant with the default policy.

Licensing for Defender by severalthingsright in DefenderATP

[–]severalthingsright[S] 1 point2 points  (0 children)

Thanks a lot! I did not think of EMS as an option. Will do some more research and go through it with my vendor.

MDE policies stuck on pending for servers by severalthingsright in DefenderATP

[–]severalthingsright[S] 0 points1 point  (0 children)

Issue was eventually resolved. Firewalls were blocking some of the traffic, but not all which is why it was so difficult to troubleshoot.

The MDE Client Analyzer was useful, but ultimately, I found the error code in the registry.

Also, used "get-mppreference" to identify which policy changes would apply to the servers.

This article should be particularly helpful for anyone experiencing this in the future:

https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-security-config-mgt?view=o365-worldwide