Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Thanks Ants
May 21, 2004

#essereFerrari


https://docs.microsoft.com/en-us/windows/deployment/mbr-to-gpt

Adbot
ADBOT LOVES YOU

vanity slug
Jul 20, 2010

GreenNight posted:

Is there a good tool, free or paid, that can convert an MBR partition to GPT? Need to increase a partition to greater than 2TB.

Can't lose data or permission info.

I've had good experience with EaseUS's tools.

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

This.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.


This is a Server 2019 install with a MBR partition connected to it. Curious if this works on 2019.

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

GreenNight posted:

This is a Server 2019 install with a MBR partition connected to it. Curious if this works on 2019.

https://miketerrill.net/2017/01/15/getting-started-with-mbr2gpt/#comment-3607

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.


Ooh nice, thank you.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

MBR2GPT /validate /allowFullOS /Disk:3
MBR2GPT: Attempting to validate disk 3
MBR2GPT: Retrieving layout of disk
MBR2GPT: Validating layout, disk sector size is: 512 bytes
Disk layout validation failed for disk 3

Bummer.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

code:
There is enough space not occupied by partitions to store the primary and secondary GPTs:
   16KB + 2 sectors at the front of the disk 
   16KB + 1 sector at the end of the disk
There are at most 3 primary partitions in the MBR partition table
How many partitions are on the disk? If its 4 or has extended ones you might need to nuke one before the converter can do its thing. Also shrink down the last partition by a megabyte to give it the space it needs if its allocated all the way to the end

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Yeah, it's 4 partitions including the OS partition. They all have 50+ gigs of space free. Nuking one isn't a huge deal. Who cares back Cisco CUCM backups anyways.

Schadenboner
Aug 15, 2011

by Shine
Zero-pass the drive, re-format it GPT, accept the data loss, grieve for it, and learn to love again?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

GreenNight posted:

Yeah, it's 4 partitions including the OS partition. They all have 50+ gigs of space free. Nuking one isn't a huge deal. Who cares back Cisco CUCM backups anyways.

The recovery partition isn't technically needed if you want to yolo it

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

BangersInMyKnickers posted:

The recovery partition isn't technically needed if you want to yolo it

No recovery partition exists.

1. OS
2. Main file storage for entire org
3. DFS backup from branch office
4. Cisco backups from CUCM

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

GreenNight posted:

Yeah, it's 4 partitions including the OS partition. They all have 50+ gigs of space free. Nuking one isn't a huge deal. Who cares back Cisco CUCM backups anyways.

Kill them with prejudice. No one needs that poo poo.

PUBLIC TOILET
Jun 13, 2009

GreenNight posted:

Yeah, it's 4 partitions including the OS partition. They all have 50+ gigs of space free. Nuking one isn't a huge deal. Who cares back Cisco CUCM backups anyways.

:tif:

Potato Salad
Oct 23, 2014

nobody cares


GreenNight posted:

Is there a good tool, free or paid, that can convert an MBR partition to GPT? Need to increase a partition to greater than 2TB.

Can't lose data or permission info.

Seen a few such as -

https://www.partitionwizard.com/partitionmagic/will-converting-mbr-to-gpt-erase-all-the-disk-partitions.html

But it would be good if someone has done this before.

mbr2gpt runs online and ships with win10 1709+

Edit: god drat it, thants beat me

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010
boooiiiii they did it

quote:

Skype for Business Online to Be Retired in 2021

Today we’re announcing that Skype for Business Online will be retired on July 31, 2021. This post provides details on the retirement plan, a brief explanation of why we’re making this announcement now, and a summary of what we’re doing to help customers migrate to Teams.

https://techcommunity.microsoft.com/t5/Microsoft-Teams-Blog/Skype-for-Business-Online-to-Be-Retired-in-2021/ba-p/777833. I'll never have to worry about a weird skype transition with my impending deployment.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Good riddance.

cage-free egghead
Mar 8, 2004
So what's the difference between Server and Online? My org just got an email about this but says if you use server then you won't be affected by the retirement.

The Fool
Oct 16, 2003


On prem Skype is a completely separate product and will have its own schedule for end of support.

Thanks Ants
May 21, 2004

#essereFerrari


I'm planning to look into this some more tomorrow but does anyone have any ideas why Windows 10 Enterprise (in-place upgrade from a license in Azure AD) on a machine managed by Intune and enrolled with AutoPilot would not have the option to automatically set the time and time zone anywhere in the date and time settings page? As far as I know no location services have been disabled.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Thanks Ants posted:

I'm planning to look into this some more tomorrow but does anyone have any ideas why Windows 10 Enterprise (in-place upgrade from a license in Azure AD) on a machine managed by Intune and enrolled with AutoPilot would not have the option to automatically set the time and time zone anywhere in the date and time settings page? As far as I know no location services have been disabled.

I ran in to this with a fresh 1903 install just last week. Ended up going in to the legacy clock control panel applet, manually setting the timezone there, then all the stuff in the new UI stopped being locked out and it worked from there forward.

Thanks Ants
May 21, 2004

#essereFerrari


This isn't even locked out - the options just aren't there. Is that the same thing you saw?

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I didn't look too closely at it. What I remember was seeing that the clock was in pacific time, so I went in to the modern settings and tried to set the clock there but I couldn't. Said it was doing automatic timezone detection which was enabled and it wouldn't let me turn it off there. Then I hit the link on the right that took me to the classic clock settings and was able to override it there

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

Thanks Ants posted:

I'm planning to look into this some more tomorrow but does anyone have any ideas why Windows 10 Enterprise (in-place upgrade from a license in Azure AD) on a machine managed by Intune and enrolled with AutoPilot would not have the option to automatically set the time and time zone anywhere in the date and time settings page? As far as I know no location services have been disabled.

We had some weird issues with it because of a GPO EntSec demanded we implement. We're still pushing back, because the users are blaming us for it.

On mine, going into the Modern Date & time settings says, "*Some settings are hidden or managed by your organization.", but if I click on the "Additional date, time & regional settings" link on the right sidebar, it brings up the Classic control panel and all the options are available over there. (Haha, I should show that to EntSec as a justification for not doing this, since obviously the GPO isn't effectively blocking anything.)

So...not sure why they're missing? Is there a registry setting that hides sections of control panels, maybe?

Col. Mustard
Nov 26, 2000

Initech Administrator

Thanks for this.

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
Are there any restrictions to applying security groups to computer objects? Trying to prevent write-access to a network share on a specific computer that has to stay logged in by someone who has Modify access to that share.

$Folder has Read and Execute / Modify security groups
Created additional security group called $FolderNoWrite
Set NTFS permissions on share to explicit deny Write to $FolderNoWrite
Made $Computer member of $FolderNoWrite
Gpupdate, logged out and in

User was still able to make a text file on the share. Recreated in test network, still did not work when applied deny group to computer object, but did work when applied to the user object.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

How were you testing? What you are doing will block the system account from writing to the share, but its kinda hard to pop a command shell as system these days. What you are doing will not block users logged in to that computer, just the computer context itself.

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

The computer object isn't the security principal writing the file, so it won't be stopped. You'd have to block the user from being able to write there. I'm not aware of any sort of conditional access that pairs the origin workstation plus user account

AlternateAccount
Apr 25, 2005
FYGM
It sounds like the user who is represented by the user account that is logged in is not the person who will actually be using the computer. Your difficulties are illustrative of Why This Is Bad.

Wizard of the Deep
Sep 25, 2005

Another productive workday
I don't think loopback processing will work in this situation, but it's the closest solution I can immediately think of. I think LBP only recursively applies user settings to computer objects.

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
Useful to know, thanks!

Came up with a better solution. Created a separate user account that only has read-only access to the required share (info from the share is displayed on a TV) and restricted its login to only that computer.

Thanks Ants
May 21, 2004

#essereFerrari


Make an account with gently caress all access if you need it to stay logged in, the actual user can open up an RDP session if they need access to “their” stuff.

SaTaMaS
Apr 18, 2003
I'm having some trouble with a per-app VPN configuration through Intune and Anyconnect on iOS. The app used to do OAuth authentication using its own UI, which worked great with per-app VPN, but recently it began using a Safari web view - which apparently is considered a separate app since it can't get through the VPN. Is there some way to get the per-app VPN to allow Safari interactions as well?

Digital_Jesus
Feb 10, 2011

klosterdev posted:

Useful to know, thanks!

Came up with a better solution. Created a separate user account that only has read-only access to the required share (info from the share is displayed on a TV) and restricted its login to only that computer.

This is the semi-good way to do it imo.

Best way is to lay down a blanket policy of any machine with a shared user account that stays logged in 24/7 is local access only, no domain connectivity, on a separate wired network behind a firewall preventing it from touching your production systems. Information can be updated by someone in IT transferring data to it from an encrypted USB drive and billing time to the department that wants something set up that way.

Yes I work in medical why do you ask?

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Cross posting,

I need to do some basic auditing of directory accounts that are assigned special permissions for my application. It writes to only objects in specific OUs but I’m shocked there isn’t a community Powershell script that already does this and I do not want to buy a 3rd Party Program.

To be blunt, I'm running this ( https://gallery.technet.microsoft.com/office/AD-Advanced-Permissions-49723f74 ) and I would really just like *.CSV Output to confirm the permissions (like I'd flip this script to merely show the current permissions of the service account) but dsacls doesn't seem to work that way.

What am I missing?

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

What specific permissions are you trying to check?

edit: I've been screwing around with this the last couple hours. I haven't finished the script to do it, but here's some snippets

Basically stop trying to do this with DSCALCS is my recommendation

I'm using the powershell command Get-ACL for this. Substitute appropriately. You can query AD directly using AD: in your path.

code:
Get-Acl -Path "AD:OU=<OU>,DC=<DOMAIN>,DC=com" | Select-Object -ExpandProperty Access | ?{$_.identityReference -eq "DOMAIN\Account"}
This code will build an array you can lookup Object and Rights GUID to names. I stole it from https://community.spiceworks.com/how_to/149278-how-to-get-an-active-directory-ou-permissions-report

code:
$schemaIDGUID = @{} 
#ignore duplicate errors if any# 
$ErrorActionPreference = 'SilentlyContinue' 
Get-ADObject -SearchBase (Get-ADRootDSE).schemaNamingContext -LDAPFilter '(schemaIDGUID=*)' -Properties name, schemaIDGUID | 
ForEach-Object {$schemaIDGUID.add([System.GUID]$_.schemaIDGUID,$_.name)} 
Get-ADObject -SearchBase "CN=Extended-Rights,$((Get-ADRootDSE).configurationNamingContext)" -LDAPFilter '(objectClass=controlAccessRight)' -Properties name, rightsGUID | 
ForEach-Object {$schemaIDGUID.add([System.GUID]$_.rightsGUID,$_.name)} 
$ErrorActionPreference = 'Continue'
I'm still working on putting an easy report together, with the object name, and it's various rights but I gotta get some work for my job done so I can't mess with it anymore today.

Here's some links that might be useful.

https://blogs.technet.microsoft.com/poshchap/2017/10/06/more-on-get-acl-with-active-directory/
https://rakhesh.com/powershell/using-get-acl-to-filter-ad-objects-without-certain-group-acls/
https://community.spiceworks.com/how_to/149278-how-to-get-an-active-directory-ou-permissions-report

This thing might actually do what you want

https://gist.github.com/indented-automation/7a96a71be7eac9afc750e98fddab488f/revisions


skipdogg fucked around with this message at 18:33 on Aug 6, 2019

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

For some reason that I cannot figure out, standard users a one client of mine (read: non-admins) can initiate disabling/suspending bitlocker from the bitlocker UI. I have never seen this, across every client I've had that uses it, all functions in the bitlocker UI are locked behind UAC.

These are Windows 10 1809, bitlocker was initiated by an admin (ugh), but i also have a GPO out there that would do it if they would just assign it an OU before bitlockering.

Anyway, has anyone seen this? I can't seem to find anything related to this.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

That really shouldn't be possible and I don't think there is a canned GPO to permit this kind of behavior. I would dump the details of their security context during logon and give it a sanity check that they aren't inheriting some group giving them local admin permissions.

Potato Salad
Oct 23, 2014

nobody cares


BangersInMyKnickers posted:

I didn't look too closely at it. What I remember was seeing that the clock was in pacific time, so I went in to the modern settings and tried to set the clock there but I couldn't. Said it was doing automatic timezone detection which was enabled and it wouldn't let me turn it off there. Then I hit the link on the right that took me to the classic clock settings and was able to override it there

dump your w32tm config?

Adbot
ADBOT LOVES YOU

Woof Blitzer
Dec 29, 2012

[-]
Anyone have any good getting started with SCCM type resources?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply