Jump to content

computer_expert

Members
  • Posts

    1,188
  • Joined

  • Last visited

Everything posted by computer_expert

  1. I've just re-read all posts and spotted the bit about the dism cleanup not cleaning up. This was one of the issues that my 2019 box had and only the in-place upgrade sorted it (this was an 'upgrade' from 2019 to 2019). I wanted to do a fresh install but was overruled... In some cases, just pointing it at the public windows update servers and letting it scan/install has worked in the past, however, it sounds like your install is way past that stage. At this point, take a backup first and do an IPU to server 2012 R2 (using the latest media on the volume licensing portal) as you will probably spend lots of time going nowhere fast trying to troubleshoot, then get that patched and upgrade to 2016 if you have the licences. Just be aware that 2016 has it's own set of issues with windows update and the 'fix' is to upgrade to server 2019, but by the sounds of it that's not an option with hardware support.
  2. Have you attempted to install the latest SSU? https://support.microsoft.com/en-us/topic/kb5016264-servicing-stack-update-for-windows-8-1-rt-8-1-and-server-2012-r2-july-12-2022-3d08ad01-6d15-4507-b413-b8d4d4dc9614 Some updates need the SSU before they will install successfully.
  3. I did an IPU on a server 2019 box that wasn't installing updates from the WSUS role it was hosting and it fixed the issues with it installing updates. I did lose the WSUS DB but was easier to reconfigure that than fight a 30GB+ SUSDB back into shape. This was just putting 2019 back on over the top of the broken install and it's been fine for the last year or so now Have you seen this? https://social.technet.microsoft.com/wiki/contents/articles/37901.windows-server-2012-r2-troubleshooting-windows-updates-failed-to-install-with-error-code-800f0831-in.aspx Look at CBS.log as this should give you the KB id of the update that's causing issues (possibly a missing prerequisite?)
  4. The caching bits in macOS only deal with icloud and other apple content such as macOS/iPadOS/IOS updates. Google drive uses certificate pinning which will make it even harder, if not impossible, to cache content at the network level. Caching only really helps if the source file is the same and several clients need it (e.g. apple releasing a new macOS version and 20 macs downloading it from the cache server). Cache servers have limited use in today's world of HTTPS and certificate pinning (and faster internet connections, if you can get them). More so with dynamically generated content such as google drive.
  5. I must remove the 365 app from my phone (now using google workspace ) but earlier in the week, I kept getting lots of service issues with intune/autopilot popping up which sounds about the same time you were seeing delays. Honestly, I really like intune/MEM with windows. Some things took me a while to adjust to (Win32 application packaging/custom settings profiles etc) but it does eventually do what you configure. I'm used to things taking a while from SCCM (or Systems Management Server as it used to be called...slow moving software) but when autopilot works it's absolutely fantastic. I did find it tricky/fussy when first setting it up but most of the stuff I did then, like custom OMA-URI/CSPs, are now in the settings catalog feature from the intune UI. Edit: found one of the issues that may have impacted you - https://support.nhs.net/2022/05/microsoft-365-alert-service-degradation-microsoft-intune-users-may-be-intermittently-unable-to-use-autopilot-to-set-up-their-devices/
  6. Not sure about Hyper-V, but autopilot does work with VMware VMs (on VMware Workstation at least). I've got 5 or 6 VMs running a mix of W10/11, with a mix of TPM for testing bitlocker and others without. The only things I've found not supported with VMs are the white glove part of Autopilot and self-deploying mode.
  7. These are the main reasons I stick to the big manufacturers. I'm dreading the summer when I have to touch 200 older machines one by one to change them all from BIOS to EFI. The Dells & HPs EFI conversion is all done with the manufacturer tools as part of the SCCM TS. There is better spare parts availability with the big manufacturers in my experience (ignoring the current supply chain issues). A recent discussion with one of the system integrator types said to buy 5 or so extra motherboards with the machines to keep them all the same if one failed.
  8. I used to be an admin of MS365 in a previous life and like AAD/intune, but the head has demanded everything be googlified so my hands are kinda tied...
  9. Was going to look at this for my Windows machines but looks like its out completely now with the AAD requirement (Google environment here ). Thanks for posting the link.
  10. Freshdesk for me. Was overruled and now have to use spiceworks which is like stepping back into the past as it still only integrates with on-prem active directory and still doesn't support 2FA in 2022!
  11. Like that layout but the typo would only slightly annoy me!
  12. Do you have any 3rd party WSUS cleanup scripts running? (not the stuff built in to later SCCM versions for WSUS cleanup) What version of SCCM are you using? Do you have only the products you need ticked in the SCCM SUP properties?
  13. Like @MJTayloronline I'd go for one of the more established companies in the WiFi space. It looks like Sophos haven't yet released a WiFi6 AP which would be a non starter for me if I was looking to upgrade now.
  14. Started off with Meraki - fantastic but cost an arm and a leg to renew Then moved to Ubiquiti Unifi - was a disaster, buggy AP firmware and ended up moving away due to various issues with both switches and APs Now on Aruba IAPs and these have been fantastic so far
  15. The OOB update is under a different KB no. This is the 2019 one. Needs to be manually imported into WSUS, or installed from the catalog.
  16. Just throwing this out there but the host hasn't been patched with the Jan 2022 windows updates has it? Lots of issues with Server 2012/2012R2 and hyper-v VMs not starting KB5009586 2012 KB5009624 2012R2
  17. We had OneDrive sync set up and forced staff/students to use it as well as blocking read/write access to USB media. There were very limited exceptions to this policy mainly for photography where read only access was allowed. Plenty of warning was given to staff that this was going to happen and there were only a few stragglers who refused.
  18. Try it on a test machine first or take an image of the SSD before, then have a look at MBR2GPT to convert the machine to GPT disk formatting and UEFI booting.
  19. I can't help with the booking system, but I would highly recommend switching to another linux distribution as CentOS Linux 8 is no longer supported after 31/12/21: https://wiki.centos.org/About/Product Most people seem to be switching to Rocky Linux or AlmaLinux which are RHEL rebuilds (there's an oracle rebuild too but I wouldn't even go there!).
  20. If you have little networking/IT knowledge I'd go for the meraki option as you should be able to pick the phone and call meraki support when you get stuck. If you prefer posting on community support forums that may or may not have the answer you need (or using the MSP if they offer support) then ubiquiti is for you. I've used both and meraki easily won (which isn't surprising with the price difference). My experience of Ubiquiti switches/APs was OK, not fantastic due to the amount of buggy firmware they emitted during the period I used them.
  21. If @BJG is using a full tunnel VPN (rather than split tunneling) then all traffic will traverse the VPN. Instead of 10 clients hitting the WSUS box and pulling updates from there, you've now got 10 clients hitting the WSUS box for policy, plus the same 10 clients also downloading the updates from MS over the VPN.
  22. What AAD licensing do you have? If you have AAD P1 with O365, have a look at SSPR https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-sspr-writeback
  23. I no longer have access to VLSC but as long as the keys don't say MAK next to them you should be fine. KMS host key is just a term to differentiate from the client keys I posted above.
  24. It's been a few years since I've done it, but I think you now have to email MS to get the KMS host key added to your VLSC account otherwise you only get MAK keys listed. Edit - it used to be the case where you could email but you now have to fill in a form
  25. At this point I would look at ADBA rather than KMS. The host key from VLSC is the one that goes into your KMS or ADBA server. Use these keys to activate clients that connect to your KMS/ADBA servers. There are thresholds before your KMS/ADBA server will activate clients (5 instances for server stuff and 25 for Win7-10. Office has a separate count which I think is something like 25 too).
×
×
  • Create New...