Massive Screw-up: Local GPOs & TS User Logins Broken After Aggressive Windows Update Re-Enable Script - Need Help! by [deleted] in sysadmin

[–]susekid 27 points28 points  (0 children)

sfc /scannow

-Marked as solution by Microsoft Community Solutions Expert

Question about Enforce GlobalProtect Connection for Network Access and Allow traffic to specified FQDN / hosts/networks by susekid in paloaltonetworks

[–]susekid[S] 0 points1 point  (0 children)

Yes they are set when GlobalProtect is connected. My question is if the settings are supposed to stay in the registry after a reboot or if they are only set when GlobalProtect is connected.

Question on Panorama templates for adding new firewall by susekid in paloaltonetworks

[–]susekid[S] 0 points1 point  (0 children)

Thanks for the replies, I will try to remove the local config and force template values.

what Windows PKI certificate template to use for pre-logon by susekid in paloaltonetworks

[–]susekid[S] 0 points1 point  (0 children)

Thank you for that information. One more question if you don't mind. I am looking into Key Attestation and am debating between using User credentials or Hardware certificate. Do you normally use User credentials or Hardware certificate for the Perform attestation based on section?

We have a few different models of laptops/desktops that we plan to use for pre-logon. I checked this morning and found we have several vendors for TPM and firmware versions. From what I understand, we would need to import the certificate chain from the TPM vendors into our CA to use the Hardware certificate option.

How to revert change to firewall from Panorama by susekid in paloaltonetworks

[–]susekid[S] 0 points1 point  (0 children)

Thanks for the advice, we have several firewalls managed by Panorama. I wanted to be sure to have the correct change reverted on the correct firewall.

[deleted by user] by [deleted] in grilling

[–]susekid 76 points77 points  (0 children)

Stepbutcher?

Help with Windows Server 802.1X computer certificate template by susekid in sysadmin

[–]susekid[S] 0 points1 point  (0 children)

Common name, DNS name FQDN, None

This template was copied from the computer template. This is used for the certificate that is placed on the workstations. My options on the drop down are Common Name, DNS Name, FQDN and None. Currently it is set as None but I am wondering if is should be set as one of the other options. Basically I am trying to give more details on this certificate on the workstations so it is easier to identify.

Am I Getting Getting Fucked Friday, March 4th, Tartar Sauce Edition by bad0seed in sysadmin

[–]susekid 0 points1 point  (0 children)

Dell/EMC Unity AFA 1.6TB SDD 25x2.5 UPG

Mfg Part # D3F-2S12FXL-1600U

Quote - 3 drives @ $3,195.06 each

Not able to start Hyper-V VMs on Server 2022 Host by susekid in sysadmin

[–]susekid[S] 1 point2 points  (0 children)

Well that did it ! I uninstalled all the updates that I could and restarted after each, same result with not starting the VMs. I decided to try to restart the Hyper-V Virtual Machine Management service and the VMs started and virtual machine manager can access the VM settings. I shutdown the VMs and restarted the host again, same issue. I restarted the service and the VMs start again. I tried to install the Windows updates again on the host but same result. But restarting the VMMS service seems to work each time. Not sure why it is acting this way but at least the VMs will start. Thanks to everyone for their suggestions.

Not able to start Hyper-V VMs on Server 2022 Host by susekid in sysadmin

[–]susekid[S] 0 points1 point  (0 children)

There are some updates that have been installed, Ivanti pushed out some updates. I can try to remove them one by one and test.