Friday, May 3, 2024

Am I too old to view the software installed on a remote computater?

Yall, I couldn't remember how to stealthy, geeky, and command liney check to see what was on a remote computer.  I thought I had a post about it but I could not find it.  So, here's an easy way to get your geek on.

Get-CimInstance -Class Win32_Product -Computer YoReplaceWithRemoteComputerName | where vendor -eq 'YoReplaceWithVendorName' | select Name,Version

Monday, April 15, 2024

If Peter Parker were to manage the Googles - GAM

 

GAM is an open source command line tool for making changes to objects in the Google Admin console. It is thoroughly documented at the Github Wiki. The options available for use with GAM are displayed in specific sections on the right-hand side of the GAM Wiki.

I always quote Peter Parker's Uncle Ben when discussing a tool like this.  
"With great power comes great responsibility" 
GAM is a powerful tool, and it could be easy to break a lot of stuff rapidly.  Google support may not be super forgiving if you tell them you deleted all your user accounts while using GAM.

If you need help, this page should be your next click.

Directory Commands

In my case, I needed a way to suspend a little over 1700 accounts that had been improperly processed for a few years.  Below is the command I used to suspend all the user accounts in the Inactive Students organizational unit.  Please note suspend 0 will make accounts active and suspended 1 will suspend the account.

gam ou "/Inactive Students" update user suspended 1

I should say, I'm not really sure what GAM stands for.  I assume it is Google Admin Manage(r) or something like that.  I couldn't find it listed anywhere.  

Thursday, March 7, 2024

M365: I guess it's time to hybrid join

 Well, they finally pushed us to hybrid join all our clients to Microsoft Endpoint (otherwise known as intune).  It is actually really cool and made me excited about Microsoft again.  

You can do cool stuff like

  • Finally, ditch WSUS servers in favor of Windows Update Rings (WUR)😍
  • Deploy software packages and configuration profiles while the client is offsite

    Instructions to hybrid

Friday, June 9, 2023

Windows Updates Got The 0x80248007 Blues

Does your winders updates have the 0x80248007 blues?

1. Hold down the Winders Key and Press R. Type services.msc and enter.  If you are running as a standard user (you not be running with admin privileges), I like to run a command prompt by right click run as administrator.  Then you can type services.msc into the command prompt to run services.msc with elevated privileges. 

2. In the Services window, find the Windows Update and right-click it to select Stop.

3. Using the File Explorer or command prompt, navigate to the partition or drive where Windows is installed. Find the following path.  Usually this will be the C:\SoftwareDistrobution\DataStore

4. Delete everything in the DataStore folder.

5. Now go to C:\SoftwareDistrobution\Download and delete everything. 

6. You can now go back to services.msc and start the Windows Update service.

7. Find Windows Update or Automatic Updates, right-click it and select Start from the context menu.

Now you should be able to check for updates again to be sure everything is working.

Tuesday, May 2, 2023

Powershazzille Exchange Folder Size


From the Lazy Admin.  Cool dude Connect to Exchange Online with PowerShell - The Best Method (lazyadmin.nl)

1.  Launch an elevated PowerShell window

2.  Set-ExecutionPolicy -ExecutionPolicy RemoteSigned -Scope CurrentUser
        a. Say Y

3.  Install-Module -Name PowerShellGet -Force
        a. Say Y

4.  Install-Module -Name ExchangeOnlineManagement -Force

5.  Update-Module -Name ExchangeOnlineManagement

6.  Connect-ExchangeOnline -UserPrincipalName john@contoso.com

Now that you are connected you can run the next command to get the folder size information.  Replace username with the user you want to look up.

7.  Get-MailboxFolderStatistics username | Select Name,FolderSize,ItemsInFolder

When you finish, don't forget to disconnect

8.  Disconnect-ExchangeOnline



Friday, March 10, 2023

Installing .mis and .exe packages with Intune


1.       Go to this link and download the converter.  If you want more instructions, click here.

2.       After downloading the IntuneWinAppUtil.exe, you may want to move it over to an easy to find folder on your computer.

3.       Run IntuneWinAppUtil.exe and follow the prompts.  The file will ask you for the following.

a.       Folder location of your source .msi or .exe

b.       The filename of the .msi or .exe

c.       The destination of the new .intunewin file we are creating

4.       Now you can head on over to endpoint.microsoft.com>Apps>Windows

a.       Click Add

b.       Select the app type Windows app (Win32)

c.       Select the .intunewin file you created earlier

d.       Fill out all the important information.  I like to be sure and add a logo image to make it easier for end users if you are going to allow them to select it in the company portal.

e.       Install command: if you converted a MSI the field should already be populated.  If you converted an exe file, you would use the setup.exe /s command in the

f.        The quest for the uninstaller

                                                               i.      You will need to run this powershell script to find the uninstaller identifying number.

                                                             ii.      get-wmiobject Win32_Product | Format-Table IdentifyingNumber, Name, LocalPackage -AutoSize

                                                           iii.      Now you will need to put the msiexec.exe /x {unique identifying number from step 1} /qb command in the uninstall command in your Intune Win32 Application

Tuesday, January 10, 2023

M365: Whitelisting Stuff Against My Better Judgment

 Well, there are a few options on M365 when looking for where mail flow is hanging up.  I've never been really sure why you have to add it in multiple places.  Probably has something to do with the service it hits first in the mail flow.

  • Sometimes it helps to add a mail flow rule "admin.exchange.micros>Mail flow>Rules"
    •  Add a new rule but just remember to enable it.  
  • Another option is to take a look at the SPAM filter "Security.microsoft.com>Email & collaboration>Policies & rules>Anti-Spam policies>Anti-spam inbound policy (Default)"
  • Policies & rules > Threat Policies >Preset security policies.  Select the policy you want and then walk through the wizard until you get to the Impersonation protection section.  Then you will eventually come across the trusted senders and domains feature.

Monday, June 13, 2022

M365 User blocked from sending emails

 This was a fun one.  Microsoft blocked a user from sending emails a few weeks after the original incident.  When I looked to see where the user would normally show as blocked in the online interface, it was not identified as blocked.  So, the only thing I could think of was to check it in PowersHell.  (Why do I have to use PowersHell for everything...)

1.  Install PowersHell 7 (it is much easier to connect to exchange online)

2.  connect-exchangeonline and login when prompted

3.  get-blockedsenderaddress to see if the account in question was blocked

4.  remove-blockedsenderaddress -senderaddress flast@domain.com

Wednesday, August 25, 2021

Computers with trust issues

 This can be a dark world so sometimes our computers develop trust issues.   This is a powershell command to fix the trust relationship.  I wish it was this easy with humans...

Reset-ComputerMachinePassword -Server DomainController -Credential DomainAdmin
  • Server — the FQDN name of any domain controller;
  • Credential — domain user (with permission to add the computer to the domain) or domain admin account.

Friday, March 5, 2021

*shouting across the network* Hey! Who's logged on to that computer over there?

 Need to figure out who is logged on to that computer on the network in another location?

Try this!  query user /server:ComputerNameHere


Wednesday, October 23, 2019

Where did my WiFi go? - WiFi 6 issues

User:  I cannot see the wireless
Tech:  Well, you really can't see wireless
User:  No, I cannot see any wireless networks to use for internet
Tech:  (inner voice)  Well we did just upgrade our WAPs to the new 802.11ax standard
Tech:  (outer voice)  Let me come investigate
Tech:  You are correct, you can't see WiFi

Upon further investigation, we discovered an issue with Intel WiFi devices.  The fix is really simple.  All you need to do is update the drivers.  At the time of this article, many computer manufacturers have not updated the drivers on their support site to include the fix.  The answer is to go grab a new set of drivers from the http://support.intel.com website.

There's no place like pro. There's no place like pro. There's no place like pro.

Shift F10 Start ms-cxh:localonly   changepk.exe /ProductKey VK7JG-NPHTM-C97JM-9MPGT-3V66T