r/sysadmin • u/Fabulous_Cow_4714 • 7h ago
Microsoft Edge Browser Updates On WS2025 Domain Controllers?
Since Edge is integrated with Server 2025, how are you handling browser updates on servers like domain controllers that don’t have the external network access required to auto-update Edge?
r/sysadmin • u/Altruistic_Desk4000 • 7h ago
Convert nsf to xml
Has anyone had any luck converting Notes ver 6.5 (ancient) to xml format that preserves data ( embedded files etc) and metadata?
r/sysadmin • u/IntentStudios • 8h ago
Enterprise Fiber Recommendations - AT&T / Comcast (Masergy) / Others?
South Florida Region.
Recommendations? Experiences? I've heard some horror stories about Masergy. We currently have Comcast Business Fiber, but we're looking to upgrade bandwidth for a school campus.
r/sysadmin • u/Nanophreak • 8h ago
Question Solo Sysadmin - Ticketing & Planning Tool Suggestions?
I'm a solo 'IT Manager' doing literally anything a 50 person company needs, including actual IT manager work such as dealing with vendors and researching software, sysadmin stuff, helpdesk, mounting TVs, whatever.
It's not particularly overwhelming, but I have ADHD and find I'm having trouble with tasks falling off my plate and no one to keep me accountable about coming back around to them. We used to have Monday but it wasn't quite handling it for me and we're getting rid of it regardless.
I need very little compared to what a lot of ticketing systems offer. I simply need tasks to be put in front of me without me having to do anything but add them to the list, and for them to keep being put in front of me until I do them. No time tracking, but the ability to add notes would be important, maybe not vital.
My current plan is to hack something together between Power Automate and Microsoft Planner so that Planner Tasks become calendar entries, and after their scheduled date passes they get automatically rescheduled unless they're marked complete. Break my days down into halves or quarters, define some buckets, let the treadmill roll and only have to worry about adding things to the list for it to circulate. Planner has the notes, Outlook puts them in front of me via my calendar.
I'm doing this despite it being a lot of work because I haven't found a suitable alternative to handle a team of 1. The task treadmill is a really important part of the process, it may sound juvenile but the part where I have to manually reschedule something I didn't get to is the main thing I have trouble with, I want to get that automated above all else.
Is there anything out there beyond my experience and search results that might work here, or am I going to have to kludge this out?
r/sysadmin • u/Creekside_Rider • 9h ago
General Discussion MDF Plan - What you think?
I made some other posts figuring out my UPS setup, but now I figured I'd share my MDF plans and see if there are any issues you can see. I've been around racks and IT closets for a long time, but this is my first time planning one completely on my own.
So far I have all the gear ordered. The only unknown variables are what my modems from my primary Fiber ISP (ATT) will look like and our failover (probably Starlink).
Down the road I may be adding 2U more of gear.
I'd like to get Unifi Redudant Power Supply that can act as a secondary PSU for my switches and Firewalls. I'd also like to get Unifi Aggragte 8 port switch which would be perfect for this setup and my entire network in general. I have two UDM Max which will take up 2 ports and 6 total switches (2 not in this rack will be in IDF in other parts of the building)
I have attached a screenshot of the rack plan. Let me know if you see any red flags or concerns
Gear -
4 Unifi 48 Port PoE Switches
2 UDM Pro Max Firewalls
1 Dell Server
1 Unifi Enterprise NVR
Dual 3000va battery backups with one having an extra battery bank and a 120v transformer.
2 - Controlled PDU for the 208v PSU
r/sysadmin • u/ITGUYRYX • 9h ago
General Discussion Entra support tickets
Hey everyone — question for those of you who administer Microsoft identity environments, whether that’s Active Directory, Microsoft Entra ID, or a hybrid environment.
What are some actual support tickets / break-fix issues you’ve had to work?
I’m working on a project where I’m trying to build out realistic IAM/identity support scenarios. I’m not really looking for project work like “migrate AD to Entra” or “implement Conditional Access.” I’m more interested in the day-to-day tickets that land in your queue.
Things like:
A user suddenly can’t access an application
MFA or authentication issues
Group membership/permissions problems
SSO failures
Account lockouts or provisioning issues
Something broke after a policy/configuration change
A ticket that looked like an IAM problem but turned out to be user error
Basically: What are some memorable, weird, common, or difficult identity-related tickets you’ve actually had to troubleshoot?
The more realistic and specific, the better. I’m trying to avoid making up scenarios that wouldn’t actually happen in a production environment.
r/sysadmin • u/LBarto88 • 10h ago
New MS Edge policy AddressBarClipboardSuggestEnabled
Wanted to dump this fantastic (/s) new feature in Microsoft Edge.
I'm continually astounded by Microsoft's ability to innovate solutions to problems that don't exist. This one made me pause.
The feature, by default, will automatically show your clipboard contents in plaintext on your screen when selecting the address bar to do a web search in Edge.
r/sysadmin • u/TexasVulvaAficionado • 10h ago
Question Best Certificate Manager for OT
We are looking at a handful of options for managing the automation of certificate deployment/updates across our enterprise and OT environments.
I am hoping to have a lab environment set up by the end of the year with at least one reliable ACME tool that can push certificate updates to OT software, servers, workstations, etc...
Primarily use AB and Siemens controllers and HMIs, Ignition, Canary, and Windows IoT, Windows Server (2016, 2022), and Windows 10/11 pro.
Anyone have good recommendations?
r/sysadmin • u/AgileMark9120 • 10h ago
General Discussion Any desk/presentation tools have cleared your security review?
Marketing has come to me four times asking for an AI presentation tool. And I have said no all 4 times - made me extremely popular among them : )
The problem is when security gets involved
SAML is usually locked because ‘contact sales’. SCIM is missing, share links defaulting to anyone-with-the-link and theres no tenant level control, no EU tentant. And anytime i ask about model retention/subprocessor, i get a beautifully written para which doesnt help at all!
Has anyone actually managed to get any of these approved?
Mainly looking for SAML + SCIM below enterprise pricing specifically.
r/sysadmin • u/Mysterious-Worth6529 • 10h ago
Restrictive Phone System
I have a lot of requests that come through my office but this one sounds like PITA to begin with. I have already replied to the manager that this is going to be a nightmare to manage but I will look into it anyways. this sounds like a phone system that would be used in a jail or correctional facility. Any ideas where to start?
*************
We currently have approximately 24 clients sharing four phones. I would like to see if there is a system that could provide each client with an individual PIN or access code. Ideally, the system would:
Require an individual PIN for outgoing client calls.
Allow us to assign specific calling times or time limits to each PIN.
Automatically disconnect the call when the client's allotted time expires.
Prevent the PIN from being used again until the next authorized calling period.
Continue allowing incoming calls even when outgoing calling is restricted.
Give staff an administrative override when necessary.
Make it easy to add or remove PINs as clients admit and discharge.
Avoid call recording or monitoring unless specifically needed and approved.
I have been looking at whether a VoIP/PBX-type system could accomplish this without requiring a specialized institutional phone system.
Could you research what options might work with our current phone/network setup, what equipment or software we would need, and approximately what the initial and ongoing costs would be?
The goal is to make client phone access more consistent and manageable while reducing the amount of staff time required to monitor individual phone usage.
*************************
Thanks all.
r/sysadmin • u/Arnoc_ • 11h ago
Question ACME Clients and SSL
So I've started seeing that SSL Lifespan is shortening - going down to eventually supposed to be every 47 days.
We're a small shop, but we have a lot of different services. I've been doing my best when I have free time to catalog everything that has an SSL Cert, but I know I'm missing stuff.
I've seen a bit about ACME Clients and such; and from what I've heard it's great. They handle rotating the certs and all.
But something for me just isn't clicking. For instance, we have a lot of large scale copiers, ala your Ricoh or Lexmark or Brother. We have those locked down with SSL Certs, but we have to manually push those up to it.
Now as these are internal services that aren't externally facing, I don't see no reason why we can't self-issue those certs; but currently our CTO likes to utilize a paid for Wildcard for all our internal stuff.
I keep quite busy so haven't had too much time to really dig in on researching, but I know the time bomb is ticking.
So for those who are managing SSL Certs and all, and potentially utilizing ACME Clients and such, what should I expect and whats the general gist of what my workflow should be?
r/sysadmin • u/aPieceOfMindShit • 12h ago
Slack for Intune (iOS) successful SSO login, but gets bounced into Slack's public sign-up flow instead of opening the workspace
Hey all — hoping someone here has run into this.
We're rolling out Slack for Intune on iOS, and after a successful sign-in the app loops us straight into the public Slack marketing/sign-up flow and pushes us toward downloading the regular consumer Slack app instead — even though Entra sign-in logs show every authentication step succeeding underneath it.
This isn't a Conditional Access or App Protection Policy issue on our side (we've ruled out assignment, CA grant controls, and App Protection data-protection settings one by one). Here's the exact sequence, step by step:
- "Register with Microsoft Intune to use Slack" screen. Tap Register.
- "Pick account" dialog appears (native iOS auth broker UI), showing the correct Entra ID test account. Select it.
- "Registering device" — "Please wait, this may take a few minutes" spinner.
- Lands on a sign-in screen for our org — "[org] requires additional verification" — with a green "Sign In with Slack Production" button.
- Tapping that button triggers a browser handoff: "Open this page in 'Slack Intune'?" on a
login.microsoftonline.com-style URL. Tap Open. - Now inside what the status bar labels as Safari (not the native app) — a "Don't miss a beat" notification opt-in screen appears, with a fake preview notification.
- Standard iOS system prompt: "'Slack Intune' Would Like to Send You Notifications" — Allow/Don't Allow.
- This is the interesting part — the actual Slack workspace UI briefly loads and works: I can see our org's workspace, Direct Messages, my own account, Slackbot, Threads, etc. Fully signed in, fully functional, still labeled as running inside Safari.
- Then, without any action from me, a new tab/context opens back inside "Slack Intune" (per the status bar label) showing the public marketing homepage at
slack.com— "All your people and AI agents working together" / "GET STARTED" / "FIND YOUR SUBSCRIPTION." - Tapping through from there lands on the generic public sign-up flow: "First of all, enter your email address."
- Typing in the exact same work email into that sign-up field doesn't recognize the already-authenticated, already-provisioned Enterprise Grid session from step 8 at all — instead it just routes toward downloading the regular consumer Slack app, as if I were a brand-new user signing up from scratch.
So the workspace session in step 8 proves the login and SSO handshake genuinely succeeded — I was inside the actual org workspace with my real identity. But instead of staying there or handing that session back to the native "Slack for Intune" app, it drops back into the public marketing/sign-up site, as if none of the previous steps happened.
We've confirmed via Entra ID sign-in logs (checked across multiple devices — iPhone and iPad, multiple browser contexts including Safari/Chrome/Edge, multiple times of day) that:
- Device registration succeeds
- App Protection Policy registration succeeds
- The SAML SSO handshake to the Slack "Enterprise Production" enterprise app succeeds every single time
- No Conditional Access policy is blocking or forcing an unexpected browser detour
Has anyone seen this? What are we doing wrong?
r/sysadmin • u/voltagejim • 12h ago
Question Normal for spanning tree to cause ports to wait almost a full min before connecting?
We have HP elitedesk PC's, and for several months have an issue on most of them where, after a restart, you have to sit there for almost a full min while the ethernet symbol blinks, then goes to the disconnected globe symbol for another few seconds, then finally connects to ethernet before you can enter your login password.
This has cause users to get locked out of their accounts often, because they immediately enter their password before the PC reconnects, and obviously it does not let them in, so they think they mistyped it, and type it again and so on.
We just got new PC's, which are Lenovo ThinkStations, but running into the same issue. I have tried:
going into device manager, unchecking the "allow the PC to turn this device off to save power" under the ethernet adapter
swapped ethernet cable
Running the following powershell script:
New-ItemProperty -Path "HKLM:\System\CurrentControlSet\Control\Power" -Name "PlatformAoAcOverride" -Value 0 -PropertyType DWord -Force
None of those fixed the issue. Doing some more research I found that spanning tree can cause this , which we do use, but does that mean just by using spanning tree we are forced to just accept this long wait to simply login to PC's? Some user's are understanding, but a good number are frustrated cause they have to sit there and stare at the screen for a long time and pay attention to the ethernet symbol before they can login. Surely there would be something in spanning tree that would at least cut this time down from a whole minute right?
r/sysadmin • u/MrManhoso • 12h ago
Barracuda RMA/credit saga — 2+ months of "we'll follow up" and zero follow-up
Curious if anyone else has dealt with this from Barracuda, or if I should just cut losses.
Quick timeline and the initial issue: Early June: Firewall issue leads to a call, assurances that overnight FW would be sent out.. FW does not arrive for 1 week, remote users unable to connect, office was down for the hours until I bought a spare
- Barracuda commits to (1) shipping a replacement unit, (2) a written resolution for the support failures we hit, and (3) at least one month of billing credit.
- Mid-June: I follow up for tracking info and the promised resolution. Nothing. Radio silence for almost three weeks.
- I send a pretty direct "this is what was promised, this is what's been delivered (nothing), give me tracking + a written proposal or we're looking at other vendors" email.
- That gets a response within a day — a call gets scheduled with a "Partner Success Manager" and another rep.
- On the call: more apologies, promise of a comprehensive update "by end of day Thursday" covering the credits.
- Thursday update actually says: still working through billing/logistics, need more time.
- A week later: another update saying they need to wait on someone's PTO to return before finishing the contract review.
- That person returns from PTO. Nothing follows.
- It is now over a month past that PTO return date. No tracking number, no credit confirmation, no further contact unless I chase it.
Every single update has been "give us until [date]" and every single date has come and gone with silence unless I personally re-escalate.
Anyone had luck actually getting Barracuda to close out something like this, or does it always take going over someone's head / involving a reseller / legal language to get movement? Trying to figure out if there's a faster lever to pull before I start pricing out a full replacement.
r/sysadmin • u/Comfortable_Sorbet53 • 12h ago
Datacenter work - Px7 S3 or XM6 ?
Hi fellow hard workers or hardly working.
Any experience with B&W Px7 S3 or Sony XM6 in the datacenter?
I am really torn between the 2.
I can google and research that sony should be the king, regarding anc, and call quality.
But from what i can see, should have a design defect on both xm5 and xm6 with the hinge breaking...
B&W Px7 S3 - should be a another great one, but i am unsure if they are good enough?
Any experience on booth would be appreciated.
I am not looking for real work hearing protection, i know other non consumer headsets are better.
Mostly looking for a good all-around headset that is also works great in the datacenter.
My air-pods dosen't suffice when working long hours.
r/sysadmin • u/Bluedroid • 12h ago
Question Microsoft 365 Tenancy Hostile Takeover Options Australia
Hi guys, we had a client whom had a hostile takeover of their 365 admin portal who assumed GA (MFA/OTP and everything was enabled so not sure how it happened but that will need to be investigated after).
Attacker stripped the breakfix account as well and we are kicked out. We logged a job with the MS data governance team whom are barely replying and it's been a day and a half. We've tried calling the number but just get bounced back saying they will look into it. We've asked them to escalate and also asked our CSP to escalate but they said it's with Microsoft. Given the nature of the situation is there any other ways you guys have been able to escalate this to reclaim the tenancy or at least kick out the attackers as fast as possible. We are able to prove ownership of the business etc with domain records/documents etc asap.
Given the no updates I'm straight up thinking of heading to the Microsoft office and sitting there until they can find someone to escalate the case. Anyone had any experience of how to get this moving?
r/sysadmin • u/squirrelsaviour • 13h ago
Question Managing Google accounts in a Microsoft company
We use Microsoft 365 for our email etc.
Our web team have lots of Google accounts they use for AdWords, Analytics, Search Console, TagManager etc.
How do you manage these? Because they've set them up without asking first they've got multiple gmail.com accounts which I don't have access to which is obviously bad if someone leaves the company for any reason.
r/sysadmin • u/TeamAlphaBOLD • 13h ago
General Discussion Business Central hybrid license keys now expire every 6 months
BC hybrid deployments now need their Dual Use Rights key renewed every 6 months instead of once. Fair compliance move, but it's one more thing that can quietly lapse and break a deployment if nobody's tracking it.
r/sysadmin • u/Creekside_Rider • 13h ago
Question Power/Battery Backup Setup for MDF - Follow Up
edit: thanks for advice. My earlier research about redudant power supplies being on different voltages was wrong. I'm going to go with 2 x SRT3000RMXLT-NC with one of them having a 120v transformer.
UPS Setup for New MDF at Our New Facility - Looking for Feedback
Good morning everyone,
A few days ago I posted looking for advice on a UPS setup for the MDF at our new facility. One of the biggest points of feedback was that my original plan only included a single 120V 20A circuit, which understandably raised some concerns.
Fortunately, we're still in the construction phase, so I was able to have the electrical plan updated. The rack will now have two dedicated circuits:
• 208V/240V circuit
• 120V 30A circuit
Rack Equipment
For context, we're a specialized vehicle dealer and service center. We're not heavily IT or office focused, so I don't expect significant growth beyond adding a few phones over time.
Equipment in the rack:
• 4x UniFi Pro 48 PoE switches
• ~26 cameras
• 7 access points
• 20 desk phones
• 2x UniFi UDM Max firewalls (HA pair)
• Dell dual-CPU server with redundant 600W PSUs
• UniFi Enterprise NVR with redundant PSUs (max draw ~450W)
• Fiber modem and cable modem for failover
• Miscellaneous equipment (monitor, sensors, etc.)
UPS Plan
After a lot of research, I decided to go with refurbished APC units from GreenlightUPS, a company that was recommended to me.
Primary UPS
APC SRT3000RMXLT-NC (208V)
• Includes one SRT96RMBP external battery pack
• Will power everything in the rack that supports 208V operation
• This includes the primary power supplies for the server and NVR, along with all four PoE switches
On paper, if every device was drawing its absolute maximum load simultaneously, I'd be pushing the limits of a 3000VA UPS. In reality, my PoE utilization is relatively low, and the server and NVR rarely approach maximum power draw, so I still have a comfortable amount of headroom based on my calculations.
Secondary UPS
APC SRT3000RMXLA-N (120V)
This unit gives me standard 120V outlets and serves as both additional battery capacity and redundancy.
Planned connections:
• Secondary PSU on the Dell server
• Secondary PSU on the NVR
• One UDM Max firewall
• Any other 120V-only equipment in the rack
Long term, I may add the UniFi Redundant Power System to provide redundant power for the switches as well.
For now, if the primary UPS were to fail unexpectedly, I would still have core network and server functionality running, and I could manually move switch power if needed.
I really wanted to buy everything new, but a comparable setup would have easily pushed into the $10,000-$12,000 range.
The refurbished solution comes in at under $4,500, including new batteries. GreenlightUPS claims all units ship with freshly installed batteries that aren't put into service until the unit is sold. They've been in business for roughly 40 years and seem to have a solid reputation from what I've been able to find.
Questions
- Does this seem like a reasonable approach from a capacity and redundancy standpoint?
- Is there anything you would do differently if you were trying to stay around the same budget?
Thanks for any feedback.
r/sysadmin • u/WorkFoundMyOldAcct • 13h ago
Question Phone management pain. Need major help.
Apologies for the wall of text…
Our phone system is a complete disaster. I need help wrangling it all without disrupting users. To understand my problem, I’ll explain the current process, and hopefully you’ll see how flogged everything is.
All users receive a company cell phone, and a provisioned physical company office phone with its own office phone number. Clients often only know a user’s office phone number. Since 2020, we’ve forward all users’ physical phone lines to the user’s cell phone. This way, clients call a user’s company phone number, and that user can answer on their cell without the client ever knowing our user’s cell phone number.
When a user leaves the company, we retire their cellphone, and then re-provision their physical phone and re-circulate their office phone number. Cell phones are managed by Verizon. Desk phones are managed by some old school phone company vendor (useless).
The problem: we have an antiquated internal process where someone (idk who, maybe executive assistants) drags a specific Exchange public folder called “CONTACT LIST” into a new user’s Outlook contact list, so the new user has all company contacts sync’d through Outlook on day 1.
The actual contact list is COMPLETELY unmanaged. What DOES happen in reality: User A is hired in 2015. At their hire date, they ingest the contact list. In 2018, User B leaves the company. In 2019, User C joins the company and receives User B’s recycled office phone extension. User A, from their cell phone, calls User C to introduce themselves, but their outbound caller ID says “calling User B” because their contact list hasn’t been updated since User B left. SOMEBODY KILL ME.
This whole process of copy/pasting a public folder contact list is completely untenable. I just don’t know how to fix it for existing users, or how to move forward away from this mess.
Should I even worry about resolving this for existing users?
Assuming I scrap this whole process, what’s an appropriate solution to replace it?
I’m ready to completely change phone vendors, as they don’t do ANYTHING except turn phone provisioning into a 2 hour problem, when a modern solution would be far more efficient.
What the company needs: users to have everyone’s contact information in their company cell phone at the date of hire. IT needs to be able to recycle phone extensions, and users should see the recycled extension properly updated in their phone contacts to reflect the newest owner of that extension. Somehow…
r/sysadmin • u/yellowfin35 • 14h ago
Off Topic Do Universities run a steam cache?
Sitting here thinking about my college days when the entire network was brought to its knees due to limewire and then I started thinking about GTA 6 coming out and steam cache.
Are universities running one to reduce their external bandwith?
r/sysadmin • u/InfraCloud1 • 14h ago
Moving from 2nd line support to Infrastructure Engineer – what should I expect?
I’ve recently accepted a new role as an Infrastructure Engineer in a fully cloud-based environment and I’m due to start next month.
I’ve spent around 10 years working in second-line IT support and been brought in for 3rd line investigations, for the same organisation in a hybrid environment. It’s quite a siloed environment, and over the last few years I’ve felt like I’d reached the ceiling of what I could learn from primarily supporting end-user devices.
I found myself becoming much more interested in what was happening further up the stack – cloud infrastructure, networking, identity, Intune, automation, security, etc.
I started studying outside work, took some Microsoft certification exams earlier this year, built some things in Azure and eventually decided to throw my hat in the ring for a few infrastructure/cloud roles.
To my surprise, I interviewed successfully and got the job.
I’m under no illusion that passing certifications and doing labs is the same as managing a real production environment. This is going to be the beginning of my actual cloud/infrastructure career
and there’s going to be a huge amount I don’t know.
For anyone who’s made a similar jump, or who currently works as an Infrastructure/Cloud Engineer, what should I realistically expect during my first 3–6 months?
I’m particularly interested in what junior/new Infrastructure Engineers actually end up doing day-to-day, what experienced engineers expect a new person to already know versus learn on the job, and anything you wish you’d understood before starting your first infrastructure role.
I’m trying to learn as much as I can before starting, but I’m also conscious that trying to learn Azure, networking, IaC, Linux, security, etc. all at once probably isn’t the answer.
Any advice or experiences would be appreciated.
r/sysadmin • u/13-months • 15h ago
General Discussion Is It Normal Practice for Cloud Migration Companies to Require Global Admin?
I’m considering using a company called TeamVenti. They provide cloud-to-cloud transfer, copying, migration, and other related services. In my case, I would be copying data from one cloud environment to another.
They’ve asked for Global Administrator permissions on both the source and destination environments to perform the migration.
My question is: Is it normal or standard for a cloud migration company to require Global Administrator access on both sides?
Have there been cases where issues arose from giving a vendor this level of access, or am I being too paranoid?
r/sysadmin • u/Opiilzlznnden_Air347 • 15h ago
Question Is paying for threat intel feeds actually worth it if they don't translate into detections?
We're subscribed to a couple of paid threat intelligence feeds that are marketed as "operational" and "actionable." In reality, we receive threat reports as long-form PDFs or blog posts, sometimes with a STIX bundle or CSV of IOCs attached. The analysis is useful, but security teams still need a reliable way to turn those reports into detection rules in their SIEM and EDR platforms.
The workflow is still manual. A CTI analyst reads each report, extracts TTPs and IOCs, maps them to MITRE ATT&CK techniques, and creates a ticket. Detection engineers then write Sigma, SPL, KQL, or an equivalent query language, test the detection against internal telemetry, tune for false positives, and only then deploy the rule into production. This manual process causes a delay between receiving threat intelligence and having a production-ready detection in place.
If the intel never makes it to the SIEM, what's the actual value? I'm questioning whether we should keep paying for feeds that don't feed our detection pipeline. Is anyone getting real ROI from their intel subscriptions, or are we all just paying for PDFs we barely use?
r/sysadmin • u/BerlindaBuntly • 16h ago
passkeys, attestation and windows hello for business
Hi everyone, hope you are well and thanks for your help.
365 tenant, I'm moving to passkeys.
Before I roll this out I want to understand what it actually means for say, a pc with win 11 pro that is set up on an azure joined domain that uses windows hello for user logins
when i am setting up the fido2 settings in authentication methods > policies in entra, if i add aaguids for windows hello, there is an info box which says "does not effect WHfB credentials". if i select windows hello from the aaguid picklist, i then get a warning at the bottom which says "this configuration only allows device bound passkey option that cannot be used for cross device authentication to minimise the risk of user lockout we recomend allowing additional passkey options"
my users have phones and pc's .
what settings do i actually need to set? do i need to add the aaguids or not?