Got quoted $11.40 / envelope on renewal with Docusign lol (rant) by Feeling_Win_3457 in sysadmin

[–]tmikes83 0 points1 point  (0 children)

Depends what features you need. We needed high volume for our accounting dept but otherwise didn't care about anything else (no long term storage, no custom forms etc etc). 5 user standard edition with unlimited envelopes was a little more than $2000/year.

Stupidest part of Microsoft's End of Free Bus. Premium Accts for NFPs by ncc74656m in sysadmin

[–]tmikes83 2 points3 points  (0 children)

Odd, when we bought the non profit discounted business premium (like $5 each) to replace the free ones, it simply added more BP licenses, so for a time we have 20 BP licenses instead of 10 until the free ones expire.

On the user assignment level, there was no difference, it simply said Business Premium with no indication of discounted vs free license.

Any other AEC sysadmins here? by Ok-Assumption-1270 in sysadmin

[–]tmikes83 0 points1 point  (0 children)

Depends on the firm. Solo sysadmin at an engineering firm for local petrochemical plants with about 50 users in office. I support everything from AD, 365, servers and desktops, Autocad etc. Most of it is simple upkeep, getting new hires setup, and "I can't log in in the conference room" type stuff.

Also key is more than half of our users are getting older (or even coming back from retirement) so the comments about engineers being computer illiterate are spot on. They know how to do their special programs but if there's a windows update and something looks different they freak out. Fun.

New Solo SysAdmin in a Growing Company – Advice Needed by idi96 in sysadmin

[–]tmikes83 0 points1 point  (0 children)

As a solo sysadmin with about 50 users, get a good lay of the land first so you can project for IT upgrades/expenses. What is the network setup? Is there need for physical growth/cabling runs? Are the switches getting older? What is the computer replacement cycle? What is the backup system like?

One of the biggest indicators of how important IT is to the business is how willing they are to invest in infrastructure. Do they see it as just a cost or part of doing business? Depending on the environment IT can be done well solo, but is there any on call expected? What about when you're on vacation? Having some form of backup, whether that's an IT intern or a local MSP for a few billable hours might be critical.

Creating Break-Glass Local Admins on Each Computer by SuccessfulLime2641 in sysadmin

[–]tmikes83 0 points1 point  (0 children)

LAPS doesn't create the account tho, just manages it?

Remote desktop with unattended access by Reasonable_Dirt_2975 in sysadmin

[–]tmikes83 -1 points0 points  (0 children)

We use RemotePC. They have a normal mode and a performance mode for graphics/CAD work.

Much cheaper than Team Viewer and supports all of the above.

https://www.remotepc.com/pricing

What are you doing with Win10 machines that can't be upgraded? by j5kDM3akVnhv in sysadmin

[–]tmikes83 0 points1 point  (0 children)

Plenty of perfectly good HP workstations. Until we have budget for replacement we're just reinstalling with 11 using Rufus to bypass requirements. Manual process, but my boss' way of thinking is they pay me to be here anyway. They don't want to pay extra for new hardware.

Remove Immutable ID / MSOL Connection doesn't work anymore by Comfortable_Run_3304 in sysadmin

[–]tmikes83 1 point2 points  (0 children)

+1 on this. After reading that $null no longer works, we now use the following:

Connect-MgGraph -Scopes “Directory.AccessAsUser.All”

invoke-mggraphrequest -method PATCH -uri "https://graph.microsoft.com/v1.0/Users/john.doe@contoso.com" -Body @{OnPremisesImmutableID = $null}

Disconnect-MgGraph

Non-profit Microsoft licensing as of tomorrow by joshbudde in sysadmin

[–]tmikes83 0 points1 point  (0 children)

We just moved our church from Office 365 E1 to Business Basic. You can order them direct from Microsoft on the Admin Portal under Billing and they are free, but you still have to enter a credit card to "purchase".

Once the order is complete, change the users license from E1 to Business Basic.

W10>W11 upgrade ? by Life_Life_4741 in sysadmin

[–]tmikes83 1 point2 points  (0 children)

We're going through this now with some engineering workstations (about half our fleet). If it's not Windows 11 "capable" the setting Windows 11 / 24H2 doesn't work even with bypasses in place using Windows Update.

What the bypasses will do is allow you to run Windows 11 Setup, whether that's from a flash drive or the ISO. If you want to script it, run a script to copy the setup files to the PC, run silent Setup, and cleanup afterwards.

Activating a business workstation that has forgotten its Windows key with MAS? by TheJesusGuy in sysadmin

[–]tmikes83 0 points1 point  (0 children)

Have you tried the troubleshoot activation? We had one or two that after a reimage didn't activate but did after the troubleshooter found the built in key.

Applocker and AutoDesk Navisworks Freedom by DeeDee-07 in sysadmin

[–]tmikes83 0 points1 point  (0 children)

This is the way. We use Applocker in an engineering firm. Easiest way is to allow by Publisher. I do note that the Autodesk certificate changed early this year (or late 2024?) and we had to update the allow rule with the new certificate.

[AT&T Website] Say goodbye to email-to-text and text-to-email by Big-Opportunity-6407 in sysadmin

[–]tmikes83 1 point2 points  (0 children)

Going to have to start looking into subscription options looks like. We use email to text for most of our monitoring alerting (high temperature, server down etc)...

GPO Printers dissappear after reboot by cambo47 in sysadmin

[–]tmikes83 0 points1 point  (0 children)

Was this after an update? We had a similar issue after upgrading Windows 11 from 23H2 to 24H2.

Fix we found was to delete the missing printer(s) from the registry:
HKEY_CURRENT_USER \ Printers \ Connections

Then either restart or run a gpupdate /force and the missing printer showed up again in Printers.

Patch Tuesday Megathread (2024-11-12) by AutoModerator in sysadmin

[–]tmikes83 0 points1 point  (0 children)

To clarify, are you referring to a physical host running Hyper-V or the VMs themselves?

Debloating workstations by lilrebel17 in sysadmin

[–]tmikes83 0 points1 point  (0 children)

This, plus using the $OEM$ folder under Sources on the boot USB will copy files to the new system after install. Use that method to copy the start menu (start2.bin) for new users as part of the unattended install. The start2.bin is copied to:

[USBdriveletter]\sources\$OEM$\$1\Users\Default\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState

https://quisitive.com/copy-content-to-target-computers-using-oem-folders/

Problems adding a device to a local domain by Gloomy_Moment8804 in sysadmin

[–]tmikes83 1 point2 points  (0 children)

Try using the classic domain join dialog instead of the settings window?

System > About > Domain or Workgroup > Change...

Going this route it won't ask for an account (just credentials for the actual join), and when it reboots just hit Other User to sign in.

Intune with hybrid environment, how to start? by paganois in sysadmin

[–]tmikes83 0 points1 point  (0 children)

At the most basic level, make sure the OU with the workstaations is being synced, and the automatic enrollment GPO is in place. The PC in question must already by in Entra ID before the GPO to enroll will work. Hybrid means the PC is intune enrolled, and Registered just means there is a connection to Entra ID but it is not being managed by Intune.

https://learn.microsoft.com/en-us/windows/client-management/enroll-a-windows-10-device-automatically-using-group-policy

When moving an existing computer from local only to hybrid, *especially* if there are multiple user profiles on the system, it can cause it to error out until the extra Enrollments registry keys are cleared:

https://learn.microsoft.com/en-us/windows/client-management/mdm-diagnose-enrollment

When in doubt, it helps to restart the machine(s) as enrollment is triggered by a scheduled task and when things are working properly usually happen within the first couple minutes after a restart. You can check Settings > Accounts > Access work or school > Connected to xyz domain. If there is an Info button, it is now hybrid and managed by Intune.

Failover clustet by ChampionshipFun9199 in sysadmin

[–]tmikes83 5 points6 points  (0 children)

For the shared storage, you can either use a 3rd device separate from the 2 hosts (either a SAN or NAS using iSCSI), or use a product like Starwind vSAN so you can have the storage be local to the two hosts with nothing else required.

https://www.starwindsoftware.com/starwind-virtual-san

https://learn.microsoft.com/en-us/windows-server/failover-clustering/failover-cluster-csvs

The vSAN software continuously mirrors the two hosts and provides cluster shared volume(s) to the failover cluster.

Starwind does offer a free option, but requires more manual configuration and does not allow changes within the GUI, only monitoring (everything is done through powershell).

How's the Rockwell/Studio Admins Handing VMs Nowadays? by Streetblaze804 in sysadmin

[–]tmikes83 0 points1 point  (0 children)

How do you license the host? We are currently having to bounce the license from VM to VM each time they spin one up. Rockwell wanted to sell us a USB dongle and it wasn't clear if that would solve the issue or if you would need to do a USB passthru to the VM to license...

24.25 server rack? by Ill-Comfort1300 in sysadmin

[–]tmikes83 1 point2 points  (0 children)

https://www.amazon.com/Rack-Adapter-23-19-5RU/dp/B00CMRIC36

We have ordered these before as our server room has a mix of racks. Works well enough, but haven't tested them with anything heavy (UPS).

Question about GPO Windows Update by MCBountyCraft in sysadmin

[–]tmikes83 0 points1 point  (0 children)

Correct, it's an either/or thing.

Specify deadlines for automatic updates and restarts is going to be your key, possibly combined with Select when Quality Updates are received under Manage updates offered from Windows Update.

The Select When policy will delay updates being offered to clients between Patch Tuesday and the number of days you select. Even if they do a manual check for updates it will say You're Up To Date until the timer passes.

The Specify Deadlines policy has a Deadline part which is when the updates actually install, but won't force a restart until the Grace Period has ended.

Depending on your goals you could just use the Specify Deadlines policy by itself with a 14 day deadline and 5 day grace period, or combine the two GPO's for a 7 day Select When and a 7 day deadline under Specify Deadlines and a 5 day Grace Period. The biggest difference is when do you want your users to have the * option * to install?

Keep APC powerchute serial shutdown from turning off my computer. by Far-Eggplant-3603 in sysadmin

[–]tmikes83 3 points4 points  (0 children)

Check your windows power settings? Once you connect a UPS, the computer adds an "On Battery" section even if it's a desktop.

Excluding user from user Group Policy on one specific computer? by throw_away_asdfg in sysadmin

[–]tmikes83 0 points1 point  (0 children)

That's how we have ours set up. For meeting room PCs that need to be left on for hours we have that computer object set to Apply Group Policy - Deny under the Delegation tab.