@kevmjohnston@infosec.exchange

@kevmjohnston

IT Systems Admin/Engineer with a Microsoft focus: ConfigMgr, PowerShell, MDT, OSD, App packaging. Formerly in Oil & Gas, currently in Healthcare.

Iowa, USA Katılım Eylül 2014
2.2K Takip Edilen695 Takipçiler
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@miketerrill It's been a perfectly fine strategy...until now. Only one site and client update per year to what is a very stable release by the time the HFRU comes out. Made more sense when there were 3x updates per year instead of 2 though, sure
English
0
0
1
116
Mike Terrill [MVP]
Mike Terrill [MVP]@miketerrill·
Today marks the end of support for Microsoft Configuration Manager current branch 2303. If you are still running this version (or an older one), it is time to upgrade! #ConfigMgr #SCCM
Mike Terrill [MVP] tweet media
English
2
4
21
2.8K
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@znackattack @UmairMSFT There are individual hotfixes for CMG and client software update related issues. Beyond that, I don’t know. But for me it’s more a matter of my org doesn’t update to a version until the HFRU is out.
English
1
0
0
60
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@UmairMSFT @znackattack Any chance that a HFRU for 2403 is releasing this month?😊 Or maybe it will coincide with the announcement of 2409 next month?
English
1
0
0
50
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@cdnk3v @SeguraOSD @gwblok In my experience, the latest OSDBuilder release is able to service 23H2 successfully (even though it says that it only supports up to 22H2). It utilizes the update catalogs from the “OSD” module so I would make sure it’s on the latest version too.
English
2
0
2
87
Kevin Johnston
Kevin Johnston@cdnk3v·
@SeguraOSD @gwblok Just wondering if #OSDBuilder is getting any updates for Win11 23H2. Our company is just starting Win11 testing and we are no cloud, so we leverage OSDBuilder to help out.. just wondering.
English
1
0
0
105
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@IoanPopovici This reminded me of something I encountered a while back. Not sure if it’s relevant to what you’re seeing but figured I’d link it just in case it’s helpful: x.com/kevmjohnston/s…
@[email protected]@kevmjohnston

@AdamGrossTX This seems to be related to having the "select when FUs are received" GPO set which is deprecated after 1809. This is causing CCM_OperatingSystem.OSBranch = 1 which translates to a NULL servicing state scenario. Remove GPO and OSBranch returns to 0 which fixes dashboard state 🤔

English
1
1
2
293
Ioan Popovici @ MEM.Zone
Ioan Popovici @ MEM.Zone@IoanPopovici·
I don't miss working with the #ConfgMgr database one bit. I hoped that 4 years later, I don't need to hardcode things in my reports anymore, but it seems that even #Microsoft can't tell which branches are still serviced...
Ioan Popovici @ MEM.Zone tweet media
English
2
2
8
1.6K
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@ccmexec @sassan_f This is great, thanks! One thing I noticed is that there are references to Install-NewTeams.ps1, but the actual file is named Install-MSTeams.ps1, so if you copy/paste like I did, make sure you're calling the right one or you'll end up with weird stuff in AppEnforce.log 😁
English
1
0
2
152
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@chukdotcom Somebody on a different IT team who probably should have their workstation admin privileges taken away 😏
English
0
0
0
58
chukdotcom
chukdotcom@chukdotcom·
@kevmjohnston What kind of savage uses apostrophes.
Windsor Locks, CT 🇺🇸 English
1
0
0
49
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
I guess the #ConfigMgr client doesn't like it when the network adapter name has an apostrophe in it?...cause I just fixed a client that wasn't able to determine boundary group membership (and couldn't download content) by renaming the adapter and removing the apostrophe 🤯
English
3
0
22
1.8K
Hotzenwalder ⓥ Ⓦ
Hotzenwalder ⓥ Ⓦ@Hotzenwalder·
@miketerrill @bytenerd @sudhagart @AdamGrossTX It seems the update resets the registrykey value that disables the searchbar. The key is HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Search, the name is SearchboxTaskbarMode and the value should be REG_DWORD = 0x0000000 (0). Our remediation will set this back from 2 to 0
English
3
3
6
1.9K
Mike Terrill [MVP]
Mike Terrill [MVP]@miketerrill·
"Search box has been added to your task bar. Want to keep this change?" Um...no! And why is this and other items appearing on enterprise managed systems??? These "features" need to be off by default on enterprise and education systems. @bytenerd @sudhagart
English
7
8
71
11.9K
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
There must also be someone whose bonus is directly tied to how many people have the Windows taskbar search box enabled...
MattWreede@MattWreede

@MEM_MVP Someone's bonus is directly tied to how many people buy stuff through Edge shopping, so "no" :P

English
1
0
1
304
Bryan Dam
Bryan Dam@bdam555·
#ConfigMgr update peeps: Anyone seeing August's updates for Win11 22h2 reports as not applicable/needed? I've not personally but I've heard from 3 separate orgs reporting the same thing.
English
6
4
16
4.9K
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@abetterpc Well that’s not good… I installed it about a week ago immediately after updating to 2303. I haven’t noticed the issues mentioned in the doc, or any other issues yet though. Hopefully the fix to the “fix” will be server-side components only and not another client update 😩
English
1
0
2
580
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@PotentEngineer @mike_marable So I think what can happen is that a user signing into apps with the Azure account will trigger the machine to switch over from KMS to subscription based activation. But if that user doesn't regularly use that machine, it can fail to renew Ent and fail back to Pro only
English
0
0
0
76
@kevmjohnston@infosec.exchange
@[email protected]@kevmjohnston·
@PotentEngineer @mike_marable We have domain A and B. Users log on to Windows with A which is not tied to Azure. Azure entitlements are assigned to account in B. User uses B account to sign in to M365 Apps, Teams, OneDrive, etc.
English
1
0
0
45
Mike Marable
Mike Marable@mike_marable·
Long shot here. Around early October our on-prem AD, CM managed devices started to revert from the Enterprise SKU down to Professional. If we inject the Enterprise GVLK they will activate against our KMS properly, but they revert back again and activate Retail Pro. Any ideas?
English
12
5
30
0