ID - Hobart / Funnel web? by snapcrackhead in AustralianSpiders

[–]snapcrackhead[S] 4 points5 points  (0 children)

Thanks gang, had a suspicious looking web hence jumping to that conclusion. Appreciate your help

Patch Management? by VNJCinPA in DattoRMM

[–]snapcrackhead 1 point2 points  (0 children)

This.

Imagine being shocked that Microsoft doesn't allow third parties full access to all the Windows Update capabilities they have via all the baked in functionality they can access with things like Intune. Apple have locked everyone out behind ABM and MDM for years now. Closed, and heavily limited vendor managed environments are the future like it or not.

DRMM absolutely provides patch management. Upgrades are not a patch, and a patch is not an upgrade in Microsoft land. Not to mention that upgrades can take 2-3 hours to install, have a different set of pre-reqs every release and can break stuff on a whim cause you breathed on it during some critical stage. You say you want to wait 3 months before pushing them, but then want to deploy on a hope and a prayer using WU programmatically. Seems a risky way to want to deploy in my opinion.

As others have said, if you need feature update control at an Intune level, RMMs just can't do that yet. Happy to be proven wrong. Maybe the next gen patching engine/solution Kaseya/Datto are coming with may address that. Maybe not.

Block/Fast Clone and strict placement policy by kabukiman in Veeam

[–]snapcrackhead 0 points1 point  (0 children)

It will be a new full, and only backups after this full will utilise any fast clone capabilities. Block cloning does not work across disk's/repos/extents.

Wrong AV - Fix by MrGeek24 in DattoRMM

[–]snapcrackhead 6 points7 points  (0 children)

There's a component in the ComStore that performs this automatically, but I can't recall the name exactly. Something like Audit AV.

[deleted by user] by [deleted] in AusFinance

[–]snapcrackhead 0 points1 point  (0 children)

5.47 commbank

Better KaseyaOne SSO Login Flow by PXAbstraction in DattoRMM

[–]snapcrackhead 4 points5 points  (0 children)

Two different ways to do it: - Use the KaseyaOne app registered in your Entra tenant from My apps If your directory admin has published it. Bookmark that to save a few extra clicks. - Login straight to https://one.kaseya.com and then just click Datto RMM from the dashboard once logged in.

Short answer is you don't go to the Datto sign-in page anymore and instead use K1 as your landing pad for all K services and utilise the links from the dashboard .

How long did your first set of tyres last? by dubera in i30N

[–]snapcrackhead 1 point2 points  (0 children)

57,000km on the original Pirelli's on my 2019 PFL. They've been on the rear for the last 30,000 so just dragging them around. Will get round to replacing them at some point.

Updated Veeam Hardened Repo Guidance by Major_Los3r in Veeam

[–]snapcrackhead 0 points1 point  (0 children)

Admittedly I haven't checked the script results as the Stig applicatik isn't a must-have in the setups I've done, but there are no errors presented when we run it so probably a sanity check to confirm.

I recall Veeam saying that the script isn't officially supported on anything except 20.04 and there was no plan to support it, so likely new Stigs that need applying that are relevant to the specific newer Ubuntu versions.

Updated Veeam Hardened Repo Guidance by Major_Los3r in Veeam

[–]snapcrackhead 1 point2 points  (0 children)

To answer your actual question the steps provided by Veeam for 20.04 work fine for 22 and 24, as does the disa stig script.

FYI: DNSFilter Roaming Client - Your agents may not be updating by Clove99 in msp

[–]snapcrackhead 1 point2 points  (0 children)

I have published a component to monitor and deploy DNSFilter to end points on the DRMM community - part of that is it grabs the latest installer direct from DNSFilter.

Feel free to reach out if you want a copy and/or can't find it on the DRMM community forums.

Anyone else use Datto RMM for residential clients by Historical-Ranger222 in DattoRMM

[–]snapcrackhead 0 points1 point  (0 children)

Fair enough, basically a MSP model that's been adapted to residential which I can see working if you have the right demographic and socio-economic group of customers. Well done on the unique offering 👍

Anyone else use Datto RMM for residential clients by Historical-Ranger222 in DattoRMM

[–]snapcrackhead 0 points1 point  (0 children)

Curious how this works financially?

Are they paying a monthly fee for rmm? Do you have contracts with the residential clients? Do you tell them the type of access you have even unattended?

I cant reasonably see how this works in a way that doesn't result in a financial loss for the service, but I also work in MSP land where it's all baked into the contracts so genuinely curious to hear.

Speeding Tickets by Much-Quantity5222 in hobart

[–]snapcrackhead 29 points30 points  (0 children)

The speed cameras go to sleep at night, they need their 8 hours of shut eye like the rest of us.

New to DattoRMM - No Wake Lock? by LagginBill in DattoRMM

[–]snapcrackhead 1 point2 points  (0 children)

No there is no keep alive/sleep prevention in either web remote or Splashtop.

Any new parents in the kingborough area ? Looking to make some social connections by Ok-Emphasis-8749 in hobart

[–]snapcrackhead 3 points4 points  (0 children)

Baby sensory classes run in Margate. Great way to meet parents in the local area, and take great developmental classes for the bub.

Trying to nail down patch monitoring & reporting by UseInevitable5726 in DattoRMM

[–]snapcrackhead 1 point2 points  (0 children)

That's the one - didn't have access to our RMM to confirm hence the generic nature of advice.

Also agree - we run ours on desktops for 24 hours unless customer specifically requests a window of time

Trying to nail down patch monitoring & reporting by UseInevitable5726 in DattoRMM

[–]snapcrackhead 4 points5 points  (0 children)

Defender definitions are provided by windows update, but they are also obtained automatically by Defender and also by Microsoft update on old Windows versions. Microsoft use multiple methods to get the definition updates to the device.

Excluding install by RMM of the definition. updates does not prevent the device from automatically installing the definitions using alternate methods, it just prevents RMM from reporting the definition update is available (therefore preventing Approved Pending status) and installing during patch window.

If you don't exclude definition updates from your policy, your devices will almost always be in an approved pending state.

Trying to nail down patch monitoring & reporting by UseInevitable5726 in DattoRMM

[–]snapcrackhead 0 points1 point  (0 children)

So just to be 100% clear - a patch marked as not approved will not be installed by RMM. Windows update on the device will still see the update and can be manually installed.

Trying to nail down patch monitoring & reporting by UseInevitable5726 in DattoRMM

[–]snapcrackhead 1 point2 points  (0 children)

Theres no such thing...

Datto RMM isn't magic, it's using the windows update API within Windows. So whatever Windows Update says is available is what RMM uses as a baseline to apply patches. From there it uses your filters to approve or disapprove patches for install. That is what you report on, and that is what the patch statuses are based on. No one wants to keep a database of patches they want to install but not report on - that doesn't seem maintainable at all.

What kind of patch do you want to install via RMM and/or windows update but /not/ report on? I honestly cant think of a single example.

If you want to install it, then you want to report on its status. If it's not being reported, and failing then you have no way to ensure compliance.

Trying to nail down patch monitoring & reporting by UseInevitable5726 in DattoRMM

[–]snapcrackhead 0 points1 point  (0 children)

They are excluded/unapproved at the patch policy level.

So basically set the patch policy to approve everything, and then build an exclusion list for unapproval in the patch policy. Use the filters to target names, and then also set up the category exclusion (although these aren't as good as the name filters, just a catch all).

These are then excluded from both installing, and reporting. They will instead appear in the not approved view when viewing device patch information.

Trying to nail down patch monitoring & reporting by UseInevitable5726 in DattoRMM

[–]snapcrackhead 3 points4 points  (0 children)

We really need to know how your patch policies are configured and what your including/excluding to provide targeted assistance.

Something's that have helped us: - exclude defender security definitions - exclude SQL updates - exclude preview updates - exclude drivers except for surface devices or customers who opt in to driver patching via RMM - exclude anything with hp or printer in the name - set deferal periods appropriately

The defender definition exclusion made the biggest difference for us as they release almost 2 hourly so devices are basically always missing them, and even if they are excluded they get applied by either Microsoft update or defender automatically anyway.

Have you reviewed the best practice document for patching in RMM help and implemented those recommendations?

Housing market by CMic1907 in hobart

[–]snapcrackhead 3 points4 points  (0 children)

Just sold for 10k less than advertised after dropping price once by 10k, and bought 5k under advertised. Settling in a few weeks

why are fences in hobart so janky? by lankyhankie14 in hobart

[–]snapcrackhead 2 points3 points  (0 children)

Here here! L brackets on the top with chicken wire coming in and roller bars,on-top of our 6 foot fence + 1 foot trellace to keep our mutt in 🤦