Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. On our Server 2022 we notice that the Windows Update has disappeared from the Services.msc console - and wuauserv doesn't seem to be running in the task list. However, looking at the event logs we can see the Windows Update service starting, detecting updates (or lack of) and then shutting down This is a bit worrying as this has only happened on the DCs and I don't have any policies in place to disable access to Windows Update (there is a GPO setting for this but I don't think it would remove it from the services list) Anyone seen anything like this? To me it looks like the Windows Update is running, but not under the wuauserv process but under the svhost.exe process?
  2. Cheers for the advice, in the end the easiest way was to completely wipe the internal drive and then copy the files back on. Something must have happened at the volume/partition level because I still couldn’t rename the volume after disabling SIP All sorted now though - happy Mac mini!
  3. Cheers, filevault isn't enabled on it but I'll try disabling SIP and do it that way. Just need to get access to reboot it now as its always being used!
  4. Bit of an oddly specific case here but I'm interested to see if there is a quick way around it. User had a Mac Mini 2014 with the 1.4 processor - upgraded to a 1tb SSD running Monterrey. All working fine etc and the user upgraded to a higher spec 2014 Mac Mini with i5 and more memory etc and the apple SSD (i.e not Sata) so put the old 1tb drive in as a secondary drive as it contained all the data Works fine - new Mac Mini sees the secondary drive and all the data. So the user decided to 'tidy up' the secondary drive - remove all the Applications, Library folders etc as they aren't used anymore, after all the OS is now on the onboard SSD! Problem is on a lot of the folders like these no matter what permissions or elevation they try it always says they don't have permissions, or in terminal says its a Read-only file system - despite the user having read/write on the whole drive. I've had a look and can't see a way around this, presumably these folders are locked somehow as they were system folders, but is there a way around this without formatting the drive and starting copying the files back over again?
  5. Thanks I think that’s what they were expecting but I couldn’t find a definitive answer. It’s a shame apple don’t have a 500gb and 1tb option as well!
  6. I've been asked a question that I can't find an answer to - a family have a apple storage plan of 200gb and all 4 members of the family in the Family sharing group and currently shared that storage Out of the 4 members there is one who uses the about half of the 200gb plan, so they want to move him to a separate 200gb plan of his own but still remain in the family sharing group (mainly so they use 'find my phone' for each other!) Is that possible, or are the family sharing and storage tied together? I know they could pay for the next storage tier, but thats £6.99 for 2tb which is a massive jump and overkill for them, and the 200gb would be enough for the 3 others and the other person if it was their own and its £2 a month cheaper to do it this way and the two 200gb plans would last them for years
  7. We have an offline Root CA and online subordinate CA used for internal PKI - the subordinates certificate (i.e the one issued from the Root CA) expires in about 10 months but I want to renew early. If I renew it now (creating a new certificate for the subordinate CA) and deploy it using GPO (and manually for other systems that have it) am I right in thinking that any certificate issued against the old (but still valid) subordinate CA will still be valid? In other words, if I miss something and it doesn't get the new subordinate CA cert will the old certs continue to be valid (until their expiry date of course!) That's my plan, renew, deploy and then I have a window to find anywhere that has the subordinate CA cert installed that might have been done manually
  8. I've come across a 2019 virtual server which is running out of space on the boot C: volume and it looks like someone has tried to add space but gave up because there is an EFI System Partition in the way so it can't be extended: I can't just delete this - does anyone know of a way to move it, or delete/recreate it without knackering the server?
  9. Unfortunately I still get this error even with FQDN - the only way I've found around it was to RDP to another server, and then hop to the other one!
  10. Just noticed an issue when I try to RDP from a fully patched Win11 Pro desktop to a fully patched Server 2019 1809 server, and we get the old CredSSP error - now I haven't seen that since the early days of Win 10/Server 2016 With both systems fully patched I'm not sure how to resolve this, apart from switching the 'encryption oracle remediation' setting to vulnerable which seems like a dangerous and massively backwards step - has anyone seen this error recently?
  11. I did have a look at hardened UNC paths, but they were set up by someone else 4/5 years ago and seem to be configured as per MS recommendations, similar to what you've posted as well Its the odd combination I don't get - an admin on Server A can edit the netlogon folder via the path on Server B - but not Server A or the domain path, so permissions seem correct and we use the \\*\Netlogon and \\*\sysvol paths so its not limited to specific servers
  12. Something odd has started to happen with our netlogon\sysvol shares. As an administrator I can browse to the shares on any specific DC and edit files/copy files etc using the path \\server\netlogon. However when I try this using the domain path (i.e \\domain\netlogon) I cannot do this as I get access denied, despite being logged in as the same administrator. Replication across the DCs is OK - and I can edit the files on each server individually but not via the domain unc path - which is what we use in some scripts. Is there anywhere permissions on the domain unc could be different to the individual servers? Edit: even more weird is that if I am logged on to server01 I can use the paths \\server02\netlogon, \\server03\netlogon etc to edit the files in the share, but not the server I am actually logged into, like \\server01\netlogon! This can't be by design? There must be some permissions issue somewhere here
  13. I've seen this once or twice, but usually with a couple more options showing. If a reboot didn't fix it I uninstalled and reinstalled the client which worked fine afterwards
  14. Its the shorter sit code style one, I can see plenty of them but not the one that's triggering the error.
  15. That's the odd thing, the deployment ID doesn't show in Deployments, or when you use the powershell. The server has been online for days as well so isn't brand new
  16. Just installed SCCM onto a Server 2019 client and it should install several software packages, has worked for dozens of others. However in the status view I see the message "Deployment "xxx" from site "xxx" was rejected because the client's platform is not supported." Now, I cannot see a deployment with that ID anywhere in the console, no matter where I look. And the new server was created from the same template as all the others so identical in its settings and config. I can easily redeploy the server but what concerns me is the fact I can't find the deployment referenced in the error, is there a way to find this?
  17. Thanks, that's what I've been working on, but haven't managed to find it clarified anywhere by MS!
  18. I'm implementing fine grained password policies and cannot find a definitive answer for one of my questions, which is 'when does the FGPP take effect'. For example, if I have a domain policy that dictates a 10 char password and implement a FGPP for a group of users that enforces 12 characters/complex, does that mean the users have to change on their next login, or does this only take effect when they change their passwords themselves? With a large number of users being involved I want to leave the old domain policy in place, add a new FGPP to a group (that has 1000's users) and then in chunks set those users to 'change password on next login' to implement this. Would that work, or would all members of that group be forced to change their password as soon as the policy was assigned to their group?
  19. Just in case anyone else has this sort of issue, it was to do with the channel my 5ghz Wi-Fi was on. It was set to channel 36 and I moved it channel by channel up to 44, and at this point all devices were fine and got the same speed! According to my router nothing else around me was on channel 36 so not interference, but maybe the m1 range of apple gear doesn’t like that frequency, been on channel 44 for a while now and consistent speeds across all apple and non apple devices.
  20. D'oh! You're 100% right - I've just realised that you have to remove them. Its been a long week.......
  21. I've tried all of these variations, with single and double quotes, and NOT rather than <> but in the Modelling wizard the Filter always shows as true - whether I enter the server name correctly or not. In fact I can't get it to show anything other than true!
  22. I'm trying to create a WMI filter so I can apply a GPO to a whole OU, but simply block a handful of computers from applying it. The WMI filter is Select * From Win32_ComputerSystem Where Name <> "COMPUTER" and it always shows as True on the GPO modelling wizard. Its shows true if I change the filter to read ="COMPUTER" or <>"COMPUTER" so it suggests something else is wrong with my query, but I can't see what? Anyone else written a wmi query that will work like this?
  23. It’s both safari and chrome and chrome on the windows machines It seems to be an m1 Mac specific issue as I’ve managed to borrow on a MacBook Air m1, and iPad Pro m1 and also a non m1 Mac mini 2014 to test and the results are the same, the m1 devices are slower than the older 2014 device! I’ve also tried with Bluetooth off and that doesn’t seem to have any impact. Maybe something in the m1 WiFi chipset is the culprit
  24. Ok this is a bit weird and I'm not sure what's going on. In my test room I have three devices connected to the same wifi router. A Windows 11 laptop, a Windows 11 mini-pc and a Mac mini M1 - all connecting at about the same wireless speed of approx 800mbps. No problems there and stable wifi connection all the time However - baring in mind these sit next to each other on the same desk, so the same distance away from the router, the internet speed achieved (measured by both fast.com and speedtest.net) is quite different. The three devices get consistent readings from both sites in these areas: (55mbps is the max speed on the connection) Laptop - 48-55mbps Mini-pc - 45-55 Mbps Mac mini - 24-29Mbps And its noticeable on the Mac - it definitely takes longer loading pages etc - its fully up to date as well (as are both Windows devices) and it can't be a distance issue as they are on the same desk (issue is the same even if just one of the three is running) So, do these sites always read lower on macOS, or is there something on the Mac I can change to get this in line with the others? They all show as connected on the router as AC/Wifi5 so all using the same channel
×
×
  • Create New...