Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?



Bump. All these are excellent and it astounds me this sort of thing isn't more popular.

Adbot
ADBOT LOVES YOU

Sickening
Jul 16, 2007

Black summer was the best summer.

Tab8715 posted:

Bump. All these are excellent and it astounds me this sort of thing isn't more popular.

I agree. Its laughable how much is there for free.

RFC2324
Jun 7, 2012

http 418

why would you not just use virtualbox to set up your from scratch AD domain? its free, and more free.

keseph
Oct 21, 2010

beep bawk boop bawk

RFC2324 posted:

why would you not just use virtualbox to set up your from scratch AD domain? its free, and more free.

The memory and storage space on a typical desktop go by extremely fast running this stuff. As slow as those cheap VMs are, they don't also crush your daily machine in the process.

RFC2324
Jun 7, 2012

http 418

keseph posted:

The memory and storage space on a typical desktop go by extremely fast running this stuff. As slow as those cheap VMs are, they don't also crush your daily machine in the process.

Are you leaving them up all the time or something? Last time I did this, I just powered the VMs on when I wanted to play with them, then shut them down otherwise. Not like you are running services off them to outside the virtual network or anything.


\/\/\/\/\/ More aimed at the AWS suggestion. I haven't looked at the MS labs.

Sickening
Jul 16, 2007

Black summer was the best summer.

RFC2324 posted:

why would you not just use virtualbox to set up your from scratch AD domain? its free, and more free.

Who is saying you can't do both? :iiam:

If you don't understand the value of a instructional lab then don't know what to tell you.

DigitalMocking
Jun 8, 2010

Wine is constant proof that God loves us and loves to see us happy.
Benjamin Franklin

BaseballPCHiker posted:

A recruiter kept calling me and pestering me to apply for this job that they have had trouble keeping filled. Its as a lead Exchange admin. For a law firm. In the law firms downtown HQ. Despite every bone in my body telling me not to I applied. It's been a goal to crack $100K a year and this starts at that with good benefits. Something tells me though that there is a reason they've had trouble keeping the spot filled.

Because the only people on the planet worse to work for are doctors, but god drat do lawyers try hard to be that bad.

Don't do it.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

DigitalMocking posted:

Because the only people on the planet worse to work for are doctors, but god drat do lawyers try hard to be that bad.

Don't do it.

I think it really depends on their field. Working at an MSP, I've dealt with a wide variety. Divorce lawyers are pretty good, their most concerning issue with Exchange is attachment size, inbox sharing with admin assistants, and conference room bookings. Real estate lawyers is purely attachment size issues. Business lawyers loving suck, they will give you an encrypted thumb drive with an OST and yell at you when you can't access the emails because it's somehow your fault the guy on the other end hosed up. Then they'll demand you attach a .pst from whothefuckknowswhere in their outlook so they can click on and open every attachment, and downtime caused by viruses is unacceptably your fault as well.

"Can you export all email from this 40 gig PST from this guy, who has 3 separate email addresses, that non-exclusively contain the words "Company", "Client", "Of", and "Wetfart"? And I need this in 30 minutes for a discovery meeting across town, for which I am leaving now. Email me the results or something."

I guess basically if Lead Exchange Admin is in charge of discovery procedures, do not take that job, because that's exactly why they can't retain people.

super mario batali
Aug 1, 2013

Dice-a the Mushroom
Grimey Drawer

Thanks

Boogalo
Jul 8, 2012

Meep Meep




UPS whining about batteries. Let's take a look...




:gonk:

4 years old so they were due but there miiiight be an issue in the charging circuit of that unit.

CLAM DOWN
Feb 13, 2007





this is fine

Thanks Ants
May 21, 2004

#essereFerrari


Time to scrap it

Zaepho
Oct 31, 2013

Boogalo posted:

UPS whining about batteries. Let's take a look...




:gonk:

4 years old so they were due but there miiiight be an issue in the charging circuit of that unit.

The charging circuit was just making room for more volts, watts, and amps!

PBS
Sep 21, 2015
Anyone ever see AD computer accounts just disappear into thin air?

We've had two do this in the past month, can't find an associated 4743 event in splunk for either of them. There are others when just searching that event though, so it is setup to log those events.

Sickening
Jul 16, 2007

Black summer was the best summer.

PBS posted:

Anyone ever see AD computer accounts just disappear into thin air?

We've had two do this in the past month, can't find an associated 4743 event in splunk for either of them. There are others when just searching that event though, so it is setup to log those events.

Is your investigation going down to the SID? If not, most likely they were never deleted at all, simply renamed.

PBS
Sep 21, 2015

Sickening posted:

Is your investigation going down to the SID? If not, most likely they were never deleted at all, simply renamed.

I didn't see any 4742 events targeted at the accounts either, but no I wasn't using the SIDs.

I'll go back and check the SIDs anyway though, maybe something'll come up.

Sickening
Jul 16, 2007

Black summer was the best summer.

PBS posted:

I didn't see any 4742 events targeted at the accounts either, but no I wasn't using the SIDs.

I'll go back and check the SIDs anyway though, maybe something'll come up.

Have you tested you logging to see if its actually working? I would probably do that as well.

PBS
Sep 21, 2015
Yeah it's working, there were 4741 events for when the computer was redomained and other 4743 events during the same day we believe the last one went missing.


I'll try searching the SID to see if there are any objects left with that ID or if there are any events of it being modified. I'll post back with what I find.

PBS fucked around with this message at 04:25 on Mar 10, 2016

Alchenar
Apr 9, 2008

Turtlicious posted:

My boss seemed somewhat receptive to a pay raise, and putting money out for a server. He had another board meeting next month, so I have until then to write a proposal. To present.

This is awesome.

I'm internally freaking the gently caress out though, what in god's name do I do? I don't even have a Comptia A+ Cert. I START on my bachelor's in December and now i have to talk to multi-millionaires about a loving 600 person office? I don't know how to talk to normal people like that. I didn't even know what RAID was until I flubbed a Tier 1 interview! These people are olllld too, like in their upper 50's they're going to take one look at me and say "Hah, look at this loving child playing adult."

In other news, I got a key to the TelCo room, and will spend the most of my day now labeling wires, so that I can come in (with OT,) and unfuck this spaghetti cabling. Boss has received my list after verifying the logs with Dropcam, which I feel kind of scummy about making / handing over, but whatever, I don't jack it at work. (I decided to make 2 lists, one for "Talk about when I have a real management job," and "Work Jacking.")

1. Describe the current situation in layman's terminology (99% likely nobody in the room knows what the status quo is).
2. Describe the various risks and what they mean in business terms rather than IT terms.
3. List a number of options. This can be as simple as 'do nothing and accept the risks' to 'SPEND ALL THE MONEY ON PUTTING A BACKUP INTO SPACE' but even if your recommendation is that there is only one reasonable option it's important to show that you've considered the alternatives and are at least offering them rather than trying to railroad the board onto your plan.
4. On your preferred option, talk money, talk timetable, talk risk, talk outcomes.

Once you have a presentation ask your boss to listen to you do a trial run of it and he'll be able to tell you how to tweak it for your specific audience.

Thanks Ants
May 21, 2004

#essereFerrari


PBS posted:

Yeah it's working, there were 4741 events for when the computer was redomained and other 4743 events during the same day we believe the last one went missing.


I'll try searching the SID to see if there are any objects left with that ID or if there are any events of it being modified. I'll post back with what I find.

Nobody's been taking snapshots of domain controllers have they?

Collateral Damage
Jun 13, 2009

APC? I think we have the same model (or a similar one, I recognize that battery tray)

One of ours failed in a similar fashion, except the batteries swelled up so much you couldn't get the tray out. We ended up scrapping the whole unit and buying a new one.

PBS
Sep 21, 2015

Thanks Ants posted:

Nobody's been taking snapshots of domain controllers have they?

I wouldn't know, there's a separate team that manages the DCs. I rather doubt it though, it's been the same team for a few years now and there haven't been any other fuckups to my knowledge so far.

Walked
Apr 14, 2003

PBS posted:

I wouldn't know, there's a separate team that manages the DCs. I rather doubt it though, it's been the same team for a few years now and there haven't been any other fuckups to my knowledge so far.

I think the event ID to look for is 2095. A lot of time virtualization teams aren't aware of the possible implications of restoring a DC snapshot.

Just verify you don't have any USN rollback events to be sure

BaseballPCHiker
Jan 16, 2006

Got more info on the lead exchange admin job. Apparently I've made it into their final 4 of candidates! I'll be going in for an interview next week. I did ask what exactly their lead exchange admin does all day and they mentioned that they are in the middle of a 2010 to 2013 migration, from the sounds of it it's been ongoing for over a year now. So WAY more red flags just got waved in front of my face. Still going in to see just how big of a poo poo show it is. I do like the money they are offering.

Boogalo
Jul 8, 2012

Meep Meep




Collateral Damage posted:

APC? I think we have the same model (or a similar one, I recognize that battery tray)

One of ours failed in a similar fashion, except the batteries swelled up so much you couldn't get the tray out. We ended up scrapping the whole unit and buying a new one.

Yeah its an old 1400va rack unit. De-rack, unscrew the top cover and a little coaxing with a prybar on the top front beam will give enough clearance for the tray to slide out.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

BaseballPCHiker posted:

Got more info on the lead exchange admin job. Apparently I've made it into their final 4 of candidates! I'll be going in for an interview next week. I did ask what exactly their lead exchange admin does all day and they mentioned that they are in the middle of a 2010 to 2013 migration, from the sounds of it it's been ongoing for over a year now. So WAY more red flags just got waved in front of my face. Still going in to see just how big of a poo poo show it is. I do like the money they are offering.

Make sure to ask how many public folders they use. They are hell in 2013 and some lawyers base their entire practice on them.

high six
Feb 6, 2010

Judge Schnoopy posted:

Every time a client email is blocked by the spam filter they fire an exchange admin to make an example of them.

If a lawyer demands changing settings so she's allowed to send a 50 mb attachment and it bounces back from the receiver's system, that's 2 fired exchange admins.

The lead exchange admin is in charge of training every new admin, and maintaining the 70 year retention policy. If a single email in the history of the firm is missing, or takes more than an hour to restore because a lawyer shift-deleted a .msg saved in a server share, the lead exchange admin gets the boot.

It's scary how accurate that second bit is. The last law office I interacted with was furious at me because they wanted to be able to send 100mb+ attachments to people. There was nothing I could do until MS bumped up the max attachment limit in Office 365, but then they got furious because the emails kept getting bounced back by remote servers because they were too big. They refused something like Dropbox too, of course.

Internet Explorer
Jun 1, 2005





Look at something like ShareFile that will automatically take the file, upload it, and add a link with no user interaction after a certain size.

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal

high six posted:

It's scary how accurate that second bit is. The last law office I interacted with was furious at me because they wanted to be able to send 100mb+ attachments to people. There was nothing I could do until MS bumped up the max attachment limit in Office 365, but then they got furious because the emails kept getting bounced back by remote servers because they were too big. They refused something like Dropbox too, of course.

The client I had that was making these requests so often we set up a one drive for business site and wrote comprehensive instructions to use it. The instructions still proved too difficult, so I was roped in to being their FTP admin. Queue 3 tickets every day at 4:30 demanding FTP directories be set up with separate credentials by end of day.

No matter how much we reminded them of our 4 hour SLA, they would leave a stream of voicemails all night if they weren't ready. My boss would give them a stern warning and then complete their requests. Every time.

Japanese Dating Sim
Nov 12, 2003

hehe
Lipstick Apathy
This is babby's AD/GPO material, but am I correct in understanding that if user accounts are stored in one OU (which I have no admin over), and I have admin over a separate OU, I won't be able to use GPOs to affect User Settings? Even if I create a security group in my OU, populate it with users, and target the GPO to it?

I'm planning on, if not actively seeking MCSA 2012 soon, at least studying the 70-410 material which I think covers this, but I'm just curious for now.

Edit: Thought through this more, and while it's annoying in some cases, it makes sense. Prevents an OU admin of Shitsberg Remote Office with 5 employees from making security groups, populating a bunch of the central office's C-levels in them, and applying stupid GPOs to them.

Japanese Dating Sim fucked around with this message at 18:13 on Mar 10, 2016

Wrath of the Bitch King
May 11, 2005

Research confirms that black is a color like silver is a color, and that beyond black is clarity.
Depends on what is in the OU you have control over. If it's full of Computer Objects you can use GP Loopback Processing to push User Settings to Users that logon to those machines.

There's a lot of variables in play, so I can't give you a really detailed answer without knowing more of the structure. Are you restricted to only that OU, nothing at the root? I would assume so.

Japanese Dating Sim
Nov 12, 2003

hehe
Lipstick Apathy

Wrath of the Bitch King posted:

Depends on what is in the OU you have control over. If it's full of Computer Objects you can use GP Loopback Processing to push User Settings to Users that logon to those machines.

There's a lot of variables in play, so I can't give you a really detailed answer without knowing more of the structure. Are you restricted to only that OU, nothing at the root? I would assume so.

Both of the situations you said are true in my case. Our GPO contains all of our computers, but our users are elsewhere.

And yep, I have OU Admin over my specific OU, and nothing else above.

I'll look into the Loopback Processing, thanks.

the spyder
Feb 18, 2011
Anyone have a recommendation for a book on improving communication skills and professional development? I went from a smaller company to a larger team focused company and there's definitely some areas I could use improvement in.

the spyder fucked around with this message at 21:02 on Mar 10, 2016

Fiendish Dr. Wu
Nov 11, 2010

You done fucked up now!

the spyder posted:

Anyone have a recommendation for a book on improving communication skills and professional development? I went from a smaller company to a larger team focused company and there's definitely some areas I could use improvement in.

https://www.goodreads.com/book/show/28862.The_Prince

PBS
Sep 21, 2015

Walked posted:

I think the event ID to look for is 2095. A lot of time virtualization teams aren't aware of the possible implications of restoring a DC snapshot.

Just verify you don't have any USN rollback events to be sure

We have a team that specifically manages the DCs, so I'd hope they'd have something to say about anyone trying something like that.

I'll take a look though.

---------------

On looking up the old SID and searching for events using it.

I found the old SID, looked for win security events related to that SID. 3/3 the account logged out in the afternoon, no more events after the logout. No change events.

Went in and searched for an AD object with that SID and found nothing at all.

PBS fucked around with this message at 01:29 on Mar 11, 2016

Judge Schnoopy
Nov 2, 2005

dont even TRY it, pal
https://info.varonis.com/cards?utm_source=facebook.com&utm_campaign=cait&utm_medium=display

Security and data protection vendor Varonis created a cards against humanity mod for IT. I'm sure most of it is dry, boring, tame, and worthless but the idea seems to have potential. I'll bet this thread could come up with an actual version that fits IT so we can all play with the IT friends none of us here have.

"A sev 1 ticket came in at 1 AM because _______"
"Senior admin got drunk and started rebooting everything he could"
"The Buffalo drive reached 95% capacity"
"It was blackswordca's fault."
"Typical AS/400 poo poo :argh:"

Wizard of the Deep
Sep 25, 2005

Another productive workday
"A nurse couldn't print a coupon for 5% off a coke and THIS IS AFFECTING PATIENT CARE."

Sickening
Jul 16, 2007

Black summer was the best summer.

PBS posted:

We have a team that specifically manages the DCs, so I'd hope they'd have something to say about anyone trying something like that.

I'll take a look though.

---------------

On looking up the old SID and searching for events using it.

I found the old SID, looked for win security events related to that SID. 3/3 the account logged out in the afternoon, no more events after the logout. No change events.

Went in and searched for an AD object with that SID and found nothing at all.

A team that just manages DC's. I can't imagine being so pigeon holed.

George H.W. Cunt
Oct 6, 2010





Microsoft shaming sys admins into upgrading to Windows 10 is funny as hell. Our users were freaking out

Adbot
ADBOT LOVES YOU

RFC2324
Jun 7, 2012

http 418

Sickening posted:

A team that just manages DC's. I can't imagine being so pigeon holed.

Have enough big DCs and it becomes nessissary.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply