Jump to content

Steve21

Members
  • Posts

    9,168
  • Joined

Everything posted by Steve21

  1. Might be nothing to do with it, but I've had that before on some MSI's it depends on the exit code (You should be able to see them in the deployment type -> return codes if you used the application route). If it's still giving a 3010 exit code or similar it'll still try to reboot from SCCM being "nice" rather than the reboot that the MSI is suppressing Can try to change them on a test to note register the code as a reboot and see if it helps Steve
  2. Have you run the report on why it failed? If you select it the report button should be ungreyed Steve
  3. Any specific non-standard AV/anti-malware etc installed on it? It shouldn't need internet access unless you're checking for updates (but that error is network access not internet from what you said). Normally it's something that's blocking access to said files or permissions for those kind of error codes Steve
  4. Just tried it on mine, and I'm getting what looks like a good connection. Ping wise it'll timeout as guessing firewall as you said rather than unreachable, but can add the connection and get as far as a login box for credentials. This is on Virgin currently (I do have IPSec allowed on my firewall by default for other VPNs) so will have a play later to see if that might be why and take it off (Will drop some details across in PM later) Steve
  5. Is it just her/you or everyone that's got the problem? The fact it's working on mobile data but not any normal connections could also suggest DNS issues (possibly internal) if the phones using ipv6 while you're on ipv4 etc. Happy to have a test on it from my end if you wanted to drop an IP in a PM etc to see what we get on another connection Steve
  6. Yeah I've never worked out why it does it, as you said even if you've deleted the SSL cert from the server it still seems happy with it somehow, but hey Never seems to cause a problem so guessing it self-heals somehow! Steve
  7. Have you tried clearing the cache on your browser for SSL certs? I often get the same issue, and find that going to inprivate etc shows the new one, but the old one caches for a while Or do you mean the HTML5 one as that's a different command to set SSL Steve
  8. Ah yeah guess motorcycles would make more sense, as they wouldn't be able to twist the bars enough to get through, while bicycles could with dismounting as you say Steve
  9. They're anti cycle gates I've always been told. The idea being you can't cycle through them, but if you dismount you can turn the handlebars and the wheel fits through the bottom. Never understood the point as no doubt you just then get back on and cycle again (or in your case around the side lol)... But yeah... council logic Steve
  10. Since v16~ you should be able to do all 5 together (previous versions it's 4 max), but in terms of the 2 locations I guess it depends what you're trying to get out of having it between all of them in terms of redundancy etc Unless you specifically want routing in both areas etc, I'd be more a fan of keeping them as 2 separate ones, as if something fails in the stack with a firmware upgrade etc you could take them all out at once. Steve
  11. If you're happy doing it across all of your devices, the easiest way is changing the SCCM ADR to do "Download from Microsoft Updates" and then it'll still restrict what applies, but it does mean all machines would use the internet to download them (not just laptops etc) Steve
  12. Yep wouldn't bother with 3rd party items now with hardened if you wanted that route, still feel an off-site backup is better choice though But a rough idea for pricing: https://www.bechtle.com/gb/shop/blocky-for-veeam-ideal-protection-against-ransomware-for-your-backup--106488086--p £3,756.00 - One server licence or Veeam instance, cumulative backup capacity up to 100 TB, 36 months maintenance. With Blocky for Veeam, you choose the reliable protection of your Veeam backups against ransomware - fully integrated and without annoying administration effort. The ransomware protection is based on GRAU DATA's proven WORM (Write Once Read Many) technology and is specially tailored for integration into Veeam backup solutions. Blocky for Veeam is the last line of defence. Steve
  13. If I remember correctly you can modify the GPO to use AllSync instead of NTP, that will auto to domain hier but then fallback to the specific NTP you set in the GPO if it fails (e.g. by default uses DC, then set an external NTP in the normal NTP setting) Steve
  14. Yes to both of those, however we asked about the limit previously, and they said it's not a hard cap more a recommendation, so it's not like it blocks it etc. I think it's more a if you say you need 10k and use 1million they might complain But not had any issues so far (obviously in the first year still so guess time will tell) 67,857 - visitors this month (is this months counter to give you an example, bearing in mind it's on unique IPs etc not repeat visitors) Steve
  15. The only ones we encrypt are ones that have tags like [secure] [Encrypt] for use with external LEA/companies for data protection etc. My understanding was internal emails never really need to be encrypted as they're not leaving the MS world of servers so the "internal" encrypt as such doesn't need to come into play? I thought it would only be when going to external email providers etc. Unless I'm misunderstanding something with that Steve
  16. You know if you spent more time actually reading the stuff you post and trying to help others rather than trying to be smart you'd realise that is the archive link for blogs that hasn't been updated in years, not active posts... Steve
  17. It'll be a bit of a nightmare with everything encrypted. As you'll end up forcing everyone external to sign up to MS to open emails. (Think parents/external companies etc) The only time we've seen a loop like that is when someone has forwarded an encrypted mail to someone who isn't "allowed it" so it keeps trying to get signed in by the original account. For example, a finance mailbox with delegated permissions, PersonA isn't allowed to open the mail as they're not "finance" so it'll loop back asking for finance again Steve
  18. You mean by a seller with 0% feedback in the last 12 months? That's also got every feedback saying they're cancelling orders and asking for bank transfer as a scam... Translated versions of last 5 reviews - I really think you need to start doing some research on items here, and not just buying things that look cheap and sound good about... If it's that just cheaper than normal there's probably a reason Steve
  19. I don’t know if it’s still broke in the latest wsus servers (haven’t used it in a long time with sccm) but that used to be when you had to increase the iis pool memory on the server Steve
  20. We went with the Onyx package in the end and very happy with it so far (Was going to go with the cheaper one, but the school wanted the higher resources etc as apparently they've had issues in the past with cheaper hosts so would prefer higher spec for when it gets the hits on open evenings etc) Steve
  21. You'll have to show us what you've got in there exactly, As if you typed the same in both it'll still point to the wrong one even etc Steve
  22. Think you're mixing up two formulas posted above. The one you have in your screenshot is the one related to the 7.8 style as it's looking on the left of the "." which doesn't exist on what you screenshotted as you've got it on the months/years one, that's a different formula Steve
  23. Once the replication has run once you should just be able to rename the replica with a prefix (pretty sure this was what Veeam did automatically) As it’ll use the guid once it’s setup once so the name shouldn’t matter Steve
  24. Without better context all of these questions are pretty impossible to answer. It's the same type of "how long a piece of string" kind of question Why would any 10/11th gen be good for you compared to what you have now? What are you running? Games/Software? What is your current machine struggling with? Are you running out of RAM? etc etc etc Steve
  25. I've been looking at this recently as we're getting lots of laptops not being brought back in to update etc, but still find it hard addressing some issues with this system on a few test machines I have, and wondered how you're currently working around these (Only doing basic tests so might have overlooked something obvious!): 1) Managing feature updates so they won't affect lessons etc (For example, even with a scheduled update times/reboots set if they're turning it off/not restarting it at the right time, it'll start doing a long slow update in the mornings (An example on an old old laptop being like 1709 to 2004 on a non-SSD when turned on at 8:00am and wouldn't be ready for lesson times) 2) Bypassing mini-FeatureUpdates (for example, if we want 1909 to go to 20H2 not 2004), with the set day deferrals if it overlaps it'll still do the 2004 update before the 20H2 which seems silly and annoying to end users doing multiple updates that aren't needed) 3) Blocking single updates from deploying (For example, with the recent printing one, with SCCM/WSUS we just decline that update, with WUfB is there any way apart from pausing all updates?) 4) Complying with things like Cyber Essentials (patching in 14 days), while having the same issues above about not being able to block updates etc 5) More as a query, did you do this for desktops etc too? or just laptops? Just in terms of "cache" devices for Delivery Opt. if they're all laptops there doesnt' seem any point in these Sure I'll find some more as my testing goes, but just curious if you had any of these and any thoughts/solutions? Steve
×
×
  • Create New...