Jump to content

Steve21

Members
  • Posts

    9,168
  • Joined

Everything posted by Steve21

  1. Yep you're right. We've deployed it back out as a SCCM package to 20H2 machines so it'll force it down without having to leave them all unexpired/expired. Same issue if you want to upgrade them to 21H1 it stops it because of that issue Steve
  2. Do it as a powershell detection rather than using the built in registry lookup and use: $RegArray = (Get-Itemproperty "HKLM:\Software\Microsoft\WcmSvc" -name "CMPOL").("CMPOL") [string[]]$TempArray = @() $TempArray = New-Object System.Collections.Arraylist(,$RegArray) if ( $TempArray -contains "YOURSSIDHERE" ) { $true } If it finds the SSID it should return True which will then flag to SCCM it's installed, else False which is flagged as non-installed etc Steve
  3. By default the GPOs shouldn't start any encryption off on their own (as least not that I've ever seen) What devices are they on? I know certain brands like Dell have auto bitlocker enabled, when certain criteria are met, like a MS account being used on them (even if for apps etc) There's a whole new section since 8.1 about automatic bitlocker based on specs/hardware etc - https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-device-encryption-overview-windows-10#bitlocker-device-encryption Steve
  4. 0x800f0823 is normally a service stack error. Do you have the latest SSU applied? Think it's KB5001403 for 2012R2 Steve
  5. You say about your server but it's deffo not a problem on your side, as we have 8 old 2012r2's still running and 7 worked fine, 1 was a complete nightmare In the end, it seemed to be a combination of a few programs for us: a) The folders you mentioned b) The files "within" those folders, yes we had to repopulate them with the original flash files (Flash.ocx etc) c) Finally, we found it error'ing deep in the Windows Update logs because of a missing folder in ProgramData - Seemingly if you don't have the admin tools folder it blows up too. Made that blank folder and it installed the patch fine, then just manually removed it all again after! Yet all the other servers were fine without any of this, so very odd patch logic! Steve
  6. There's a full MS article under the download link I did above (under the related resources) that explains how to do it from the download, obviously shout if you get stuck but best to have a flick through that first Steve
  7. Installing the MSI just puts the GPOs into a folder in Program Files, you need to upload them to your central store still Steve
  8. I think this is the newer one: https://support.hpe.com/hpesc/public/swd/detail?swItemId=MTX_99ee14f68fe74c66a894f00a31 as it has 2019 support too Steve
  9. I take it you had both domains setup when you enabled password sync? It won't work retrospectively if you add new subs in. Re-run through the AADC config and disable password hash, then re-run through and enable it again to see if it'll kick the second one into action. It won't lose anything on the main domain as long as it's enabled within a sync. Steve
  10. Is that just the standard password sync diagnostic you ran? If so what happens if you run the in depth version: Invoke-ADSyncDiagnostics -PasswordSync -ADConnectorName "InsertConnectorName" -DistinguishedName "InsertDNName" Steve
  11. The first thing that would spring to mind, have you checked your CSV file doesn't include anything like special chars? As it won't then match it if it's importing it with the special char, but would when you type it manually Notepad++ is a good test, as you can turn on the special chars showing in there to see if there are any Steve
  12. Call me pessimistic, but seeing the football wouldn't have even been 3 weeks ago yet, I have the feeling it's more likely people just not getting tests before holidays/events, or turning off the apps so some who would have got tested aren't now etc, rather than cases going down yet. Seems too early as you say Steve
  13. Apps server too Steve
  14. Seems like Intel may have leaked the release month in their latest drivers: Windows 11-64 – October 2021 Update – version 21H2 Guessing if that's the case it'll be a joint Win10/11 21H2 release Steve
  15. Which A3/A5 are you referring to? If's Office neither of those will include InTune etc If it's Microsoft A3/A5 you don't need to upgrade to get any of what you mentioned, unless they're going into very complex restrictions/auditing etc https://m365maps.com/ is your friend in this kind of situations https://m365maps.com/Microsoft%20365%20Education.png or https://m365maps.com/Office%20365%20Education.png Steve
  16. Did you set them up as a mesh (from an earlier comment) though, as surely you're going to cause yourself a loop if you've done it like that. Or are they just standalone APs? Steve
  17. While I'd normally agree for the longer time etc, I'd go with 21H1 (20H2 already being a year old nearly and only has about 4 months longer support time both of which will be outdone by 21H2/Win11), as 21H2 is going to be released around October so being so close it seems silly not to get prepared with the new GPOs etc Steve
  18. https://www.bbc.co.uk/news/uk-57877373 Does this mean anyone who's currently isolating can take part in the pilot?!? *facepalm* Steve https://www.bbc.co.uk/news/uk-57879730 Rapid u turn! 157 minutes later... Seems we do all have to isolate still! Steve
  19. Most enterprise backup software (Veeam etc) has the option to truncate the logs once it backsup so it is automated for all intent, but depends what you're using really Steve
  20. I still personally think it's the wrong pic, as this is the surge protected version of the same model: https://www.broadbandbuyer.com/products/17824-lms-data-pdu-12ws-v-sp-32cmdo/#content This is (dynamode being lms) the 8 plug version: https://www.dynamode.co.uk/products/copy-of-10-way-vertically-mounted-rackmount-32a-commando-pdu-uk-sockets https://cdn.shopify.com/s/files/1/0305/6772/7243/products/PDUinCabient20U_426e5216-0b71-43a1-ae74-c040779a27d1.jpg?v=1604916500 But in regards to brackets it's normally the PDU company who make them rather than the rack (unless it's same brand) for example tripp models are like these: https://www.comms-express.com/products/tripp-lite-bracket-accessory//?keyword=&campaign=9204241339&ad=94746373418&ADtype=&Productcode=2536987&gclid=EAIaIQobChMI997j6Knj8QIVz9rVCh20pQtGEAQYASABEgIeIvD_BwE so you'd need the LMS/dynamode versions if they do them Steve - - - Updated - - - Look at the PDU though, that's for the back mounted holes on the picture https://media.excel-networking.com/images/EXCEL/E0299-2_1600px.jpg Steve
  21. Unless you have a specific rack with built-in slots, normally you use an adapter/mount, but again can depend on brand So with APC for example a lot of their racks have holes specific for it: https://cdn.cnetcontent.com/a0/92/a0921aba-4dcd-492d-a549-a181b7bf2c95.jpg For the cheaper ones, they normally just bolt straight into the back holes/squares of the rack, I wonder if that CPC picture is the horizontal one as the vertical normally have the holes at the back like this one: https://cpc.farnell.com/lms-data/pdu-10ws-v/10-way-vertical-13a-switched-pdu/dp/EN85625 at least on the ones I've seen Steve
  22. If you installed SQL on C it'd be worth checking if you have any old backups in the SQL folder from Solus updates etc, as unless you tick it to delete backups when updating it'll keep them forever in that folder, so that could be multiple copies of your database and a quick win It'd be something along the lines of C:\Program Files\Microsoft SQL Server\MSSQL13.SIMS2016\MSSQL\Backup depending on SQL versions etc Steve
  23. Good Morning All, Slightly badly worded title, but if you have multiple L3 switches setup with VLAN routing will they always route traffic that passes through them, or only if it's set to actually be the Default Gateway etc? One of my schools has their ISP router still doing their VLAN routing, which is causing a bottleneck for things like WiFi traffic getting shunted back and forth across buildings to the ISP router so I'm looking to move it onto their own switches, but was wondering if I setup L3 routing on a "core" switch in each main building, would it just be able to route it within said building without changing every clients DG to a specific one etc (effectively with their current ISP one as the DG still set on each device) I know it'd mean managing a few for new VLANs/IP ranges etc, but at least for the short term that'd remove the bottleneck and mean they'd easily route the traffic on their own devices Many thanks, Steve
  24. If you run Get-NetConnectionProfile does it show it's set to public rather than domain? If so have you tried restarting the NLA service? (Network Location Awareness) If it's got upset and thinks it's public network etc would explain why the firewall would be blocking access Steve
  25. The GVLKs are built into the default WIMs on VL images (not sure about others), so generally unless you want a specific version etc can ignore them and they'll just default to checking for a KMS/AD server etc Steve
×
×
  • Create New...