Stephen! Question for you - Is there a way to use SSO to sign people into their Work or School accounts in WIn11 automatically? We're trying to build a Win11 gold image to replace Win10. We are using FSLogix to backup profiles and have RoamIdentity turned on. The issue we're facing is its not roaming the work or school account and telling users to verify their account whenever they login to a new VDI session. I just turned RoamIdentity off and am trying to set up Azure AD SSO, but its not signing into work or school accounts automatically and when I log into a new VDI, it throws an error saying the TPM has malfunctioned. - I'm a new SysAdmin, so may have set something up incorrectly. Any help would be greatly appreciated.
@StephenWagner2 күн бұрын
Hello, Yes, Azure SSO is specifically designed to provide a single sign on experience. If you are using SSO with hybrid domain joining and PRT, you need to turn off "Roam Identity". If you're using Seamless SSO with Azure, you can probably leave "Roam Identity" turned on. When you say that you're receiving prompts to log on, is this for Office Activation, Office sign-in, or is to to complete an MFA policy that your Azure tenant has enabled? In regards to your TPM errors, did you properly create your base without a TPM using ADK and WinPE (supported method)? Usually these errors are seen when that process isn't followed. Cheers
@mahdyfouad5 күн бұрын
your mouth is very close to mic sound very sssssss thththth that very bad for headphones users
@claybreland919616 күн бұрын
I see you made notes in Notepad about the network where you specify the names, IPs, and services for each component. Is this an industry standard way of taking notes of a domain or is it a pattern you've come up with? It looks very clean and organized which is why I'm wondering
@StephenWagner16 күн бұрын
Appreciate your comment! :) I don't think there's an industry standard way of taking notes, but it's always good to document both your active deployments, as well as your environments. It's always handy to have notes and documentation because it assists with troubleshooting, emergencies, Backup and DR, etc.
@claybreland919614 күн бұрын
@@StephenWagner Thanks for the reply! That makes sense. I'm using the same style of notetaking in my lab. I honestly didn't know that notepad doesn't save automatically though, learned the hard way haha. Might use notion for the auto-save feature
@alirezapourranjbar765219 күн бұрын
i have been looking for a video like this all over. Thanks. this made my day.
@udirtАй бұрын
This is for the type of datacenter where i got those two x3650M5 on a trolley 😅
@satyakirti5610Ай бұрын
Can we deploy the updates to Byos laptops as well,those are having the Windows 10/11 home editions through WSUS?
@StephenWagnerАй бұрын
To be honest I'm not too sure if the home editions support using WSUS servers. You'd have to test.
@chrisdietz8519Ай бұрын
Well done.
@hamzapurisАй бұрын
Great tutorial, easy to follow and understand! Keep up the good work.
@syafiq3543Ай бұрын
so if my wsus server notworking to push update, i can use this method to update? is this something like manual update?
@MikeBeeTV2 ай бұрын
This is another way Synology Fs you. I have a DS1815+ that's died, for a second time. I had an SSD cache on it. I wanted to get my data off of the drives in that NAS but, of course, I couldn't just put the drives into a Linux server and read the RAID array, even though it's claimed that works. I bought a cheap DS423 (non plus mind you) and now my volume is critical because I can't turn off the SSD cache that no longer exists. WTF Synology?! At every point Synology is a fail.
@chijiiloabachie38362 ай бұрын
the best
@avinash00723552 ай бұрын
Thank you so much! Excellent video.
@tonyhall6992 ай бұрын
Great video. Just for reference, the WSUS changed to "Configuration successfully completed" around 13:00.
@jamesdanielelliott2 ай бұрын
You never issued a certificate using the new template, it was issued with the original template.
@kevinkirk31562 ай бұрын
I hate ssl's.
@Minerva___2 ай бұрын
I’ve seen it mentioned that CAWE was designed with Server 2003-2006 in mind and that is now insecure to use it, with people recommending other methods but I just can’t find more detailed information. For internal only SSL certificates, would the CAWE role still be safe to use for Server 2016 and newer?
@sarifudinbaharsah33673 ай бұрын
I'm trying to restore data on C2 to a new NAS, but why is it so slow, please what should I do?
@StephenWagner3 ай бұрын
Hello, this could be due to a number of reasons, such as slow internet, slow disks, etc...
@steveabba84634 ай бұрын
I did not know about this, thanks for the video!!!
@StephenWagner4 ай бұрын
Glad it helped!
@Albert-North4 ай бұрын
Thanks for video. Used it to setup the CA on our domain - but did not see comments about not setting up on a DC in the domain (as those who argued that it should be on a non-domain server that is eventually disconnected from the network): 1) how big of a hassle would it be to move the CA now that it is integrated with (and on) a DC? I see that it has now issued domain certs to all four DC's in our domain. 2) do we need to manually keep track of the certs issued to the DCs or do they auto-renew in 2 years (since they were auto-created); likewise, do I need to keep track of the expiry for the CA - 5 years out - to have the certificate for the CA itself renewed? 3) what happens if the CA server goes down? I guess the certificate must be "self-contained" enough that even if the CA is down, it can continue to function (up until its expiry date). Thanks. Albert (from Kincardine, ON - on the shores of Lake Huron)
@supronoono4 ай бұрын
Nice info
@zijadzikedzehovic62064 ай бұрын
Need to repeat lectures, did not work in Win Ser for long. This advice should advancemy skills. Thy.
@xandrios4 ай бұрын
Thanks for the video, very interesting. I'm very surprised by the Synology performance. 2200MB/s reads on 6 disks means over 350MB/sec per drive. Also the number of IOPS is enormous if you consider that regular HDD drives typically only reach ~200 IOPS each. Did you happen to run the same tests with the NVMe cache enabled on the Synology? Would be interesting to see the IOPS count in that config.
@StephenWagner4 ай бұрын
I'm travelling so can't verify, but these tests were with NVME cache. The NVME cache provided a beautiful boost in both throughput and IOPS.
@rasmus4594 ай бұрын
hey Stephen have you made two videos about Active Directory Domain ? the. I just tried, I have more problems with getting online on both server and client PC
@DanteBasso4 ай бұрын
I have a question, not totally related with your video, but: it's necessary to use AD to use RDS? It's possible to use only the RDS without the Active Directory...
@StephenWagner4 ай бұрын
Hello, I think I've heard of some org's using RDS without AD, however I'm not personally versed in how that would work, or what the configuration would look. I think it also has an effect on what licensing you can use as well.
@rasmus4594 ай бұрын
hi i just installed windows server 2022 64-bit and lvate domain do i need a dhcp server on it so i can get domain on a windows 10 11 computers
@StephenWagner4 ай бұрын
Hello, you can install the DHCP role on your Windows Server to provide DHCP to your network. Using it on your DC, will allow dynamic DNS updates as well!
@rasmus4594 ай бұрын
hi, thank you for your answer, when I try to connect to the domain and write domain, it comes to login, but when I write user and code, it writes An Active Directory Domain Controller for the Domain Could Not be Contacted.@@StephenWagner
@rasmus4594 ай бұрын
An Active Directory Domain Controller for the Domain Could Not be Contacted.I have tried that, but when I try to write it An Active Directory Domain Controller for the Domain Could Not be Contacted.@@StephenWagner
@rasmus4594 ай бұрын
@@StephenWagner when I install active directory and create a domain and I try to be on a dkmane on a windowos prr computer it says can not connect to domain
@StephenWagner4 ай бұрын
@@rasmus459 the computer has to use the AD domain controller for DNS to be visible.
@aolish5 ай бұрын
I had recently bought the "HPE ProLiant MicroServer Gen10 Plus v2" and would like to run Windows Server 2022 Essentials, however MS no longer provides the iso for this and I was wondering if anyone knows how to obtain this? What makes this worse is the Microserver that I have does NOT come with an optical drive. Any help is appreciated.
@StephenWagner5 ай бұрын
Hello, I believe the "Essential Experience" is now a Windows Server Feature and Role that you install after you install the operating system.
@faisaljan38845 ай бұрын
Greatttt
@weneedheros5 ай бұрын
Really good content. Clear and concise explanations.
@mentezari5 ай бұрын
Thank you so much for your tip. One of my 2016 servers would not update through GUI but did through sconfig. Have a great day.
@StephenWagner4 ай бұрын
Glad to hear!
@blessingkagurabadza89215 ай бұрын
Is it possible on server 2022 to configure NAT and DHCP without promoting to DC?
@StephenWagner5 ай бұрын
Hello, you can configure most server roles without promoting to a DC.
@user-bh4us8xe8t5 ай бұрын
Hi there;first I gotta say u rock:) and thank you for ur thorough and informative video. I have a Q though!: right now I'm at deployment configuration for Active directory domain services section and I don't know what address is best or even ok to put in as Root domain name.??!!(bc I don't own any domain) / for more clarification, I am an IT student and I'm just tryin to learn this subject via practicing it on VirtualBox. Could u pls help me with this matter? Tnx.
@StephenWagner5 ай бұрын
Hey there! Glad the video is helping. Normally in a production environment, you would most likely want this to match you internet domain name (unless you had specific reasons to do otherwise). In your case, just pertend you have a company or your own domain and use that. I just wouldn't use one that actually exists.
@swmitchell765 ай бұрын
I'm a Network Engineer, and I often get sysadmin work thrown at me... this was a GEAT tip. BTW, your videos' are great quality. short punchy, the sound is great.. Keep it up. I cant beleive you only have 3k subscribers
@StephenWagner5 ай бұрын
I really appreciate the comment and support! I'm happy the video(s) helped!
@estebangomez18235 ай бұрын
man, this video was really well elaborated, i thank you for this my friend!
@StephenWagner5 ай бұрын
Glad it helped! My pleasure!
@ITSystemsAdmin6 ай бұрын
✔
@StephenWagner6 ай бұрын
Got it setup later that day, she's working great!
@GrishTech6 ай бұрын
Nice views!
@StephenWagner6 ай бұрын
Thank you! :)
@technicallyme6 ай бұрын
is there a reson to go to mmc vs going to certmgr.msc ?
@georginagraham58096 ай бұрын
i tried it on server 2019 and restarted the server after installation when completed but didnt see the updates under "Update History'?
@mohamedzohayrialotmani15727 ай бұрын
i have a question i am currently configuring dhcp for active directory and my question is why dhcp configured on windos server2022 and not on the router
@StephenWagner7 ай бұрын
Using the DHCP Server on Windows Server allows your much more flexibility and capabilities when using DHCP. Not only are there more options available, but you can also integrate it with Active Directory for Dynamic DNS updates.
@100amazing67 ай бұрын
When using the sconfig command via cmd, does it prompt me to restart the server once the download/install of updates are completed?
@StephenWagner7 ай бұрын
Windows Update (when using the GUI or CLI), will prompt for restart when the updates require it. If the updates do not require a restart, it will not request and prompt for one.
@medusagaming18187 ай бұрын
I have tried. It is not working.
@StephenWagner7 ай бұрын
Can you be more specific? Does it provide an error, or any type of indication?
@jobinjgrk7 ай бұрын
Can you provide cleanup procedure for WSUS Server 2022. I have assign 300 GB for WSUS download Destination drive, but it is full with in 2 days.
@StephenWagner7 ай бұрын
If you need more space, I would recommend moving the WSUS data to another drive/volume. There's a process and workflow to do this.
@jobinjgrk7 ай бұрын
@@StephenWagner, Thanks for your valuable reply kindly share the process or workflow details if you have them. thanks ones again.
@hussamharbi93777 ай бұрын
Thank you for the effort , it was very informative
@StephenWagner7 ай бұрын
Glad it helped!
@FTABoyNavid8 ай бұрын
thanks for the great explanation with example of the usage of certificates.
@donaldpero28 ай бұрын
Hey man. I know these videos take time. Thank you for the post. I had a couple random questions since I am migrating my WSUS to a new VM and its been forever since I installed the service. Thank you for laying out the whole process. I appreciate it.
@Eugensson8 ай бұрын
You cannot run sconfig from a remote PS session.
@ebselectronics8 ай бұрын
What is the hp box on the right of the 2 360's?
@StephenWagner8 ай бұрын
That would be an old HP ML350 G5 server! :)
@moseschung32208 ай бұрын
Hi Stephen, do you know if this port binding setup is a way to "bundle" those iSCSI adapters together to create a larger pipe for transmitting to that SAN or does port binding have no application to trying to create a larger, redundant pipe from VMware to a SAN with multiple interfaces. Regardless, thanks for this video.
@StephenWagner8 ай бұрын
Hey there! MPIO is what's used when to "bundle" multiple adapters for redundancy as well as higher performance. When trying to use MPIO, you need iSCSI Port binding if the adapters are on the same subnet.
@mrmuffin50468 ай бұрын
does this work in windows 11? i keep getting sconfig is not recognized as an internal or external command
@StephenWagner8 ай бұрын
Hello, "sconfig" is only for Windows Server unfortunately.
@mrmuffin50468 ай бұрын
how would you go about studying vmware? other than installing it on the computer how else can i do? whats there to practice?@@StephenWagner
@OscarFaustoPelosi9 ай бұрын
Very well explained and easy to understand. Thank you, much apreciated
@StephenWagner9 ай бұрын
Glad it was helpful!
@serenditymuse9 ай бұрын
I have a true static IP address from my ISP NOT something in a DHCP range. To me that is true static IP not fixed address in DHCP address. How to I set this?
@StephenWagner9 ай бұрын
You'll need to get the information from your ISP for the Static IP, and then set it in your network configuration.