|
|
TOPIC: Microsoft 365 Apps (*) end of support (a.e. Word, Excel, Outlook ...) on Windows Server 2016, 2019, 2022, or 2025.
END OF SUPPORT DEADLINES until:
Microsoft 365 Apps migration from Windows Server
(**) Windows Server end of support and Microsoft 365 Apps
On microsoft Windows server at the end of installing windows update KB5066793 (at 98%) the update rolls back and shows Error 0x800f0922 in windows update.
Solution is opening regedit.exe and delete this registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{53e3d721-2aa0-4743-b2db-299d872b8e3d}
More details con be found here
If you need to reset Edge settings profile (you will lose only stored password, bookmarks can be easily reimported, plugin/extentions could be re-downloaded) you need to go to this path and rename following folder
C:\Users\%username%\AppData\Local\Microsoft\Edge\User Data\
https://angolodiwindows.com/2022/04/come-resettare-microsoft-edge/
Microsoft recommends disabling the Secure Time Seeding (STS) in Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025 due to reported timekeeping issues. Additionally, organizations should review and ensure proper time synchronization and monitoring on critical servers.
Microsoft released, several months ago this important bulletin.
The key point is that, after February 2025 patch installation Windows domain controller certificate-based authentication will change (due to security reasons) to Full Enforcement mode. However, you can move back to Compatibility mode until September 2025.
There are several CA checks to be done to be sure that no problem will affect your organization.
One compatibility doubt that it might arise it could be related to organization that have no longer supported O.S. (like 2008 or older)
I think that working in compatibility mode might help to check, on internet, after February 2025 if any customer had some issues and find relative fixes/workarounds
In any case here they are essential checks that you should consider before enable “full enforcement mode”:
KB5014754: Certificate-based authentication changes on Windows domain controllers
https://admin.microsoft.com/AdminPortal/home?#/MessageCenter/:/messages/MC894351
If you have necessity to audit folder permissions change these articles would be helpful for you.
ID Event 4670.
https://www.rootusers.com/configure-file-access-auditing-in-windows-server-2016/
https://keys.direct/blogs/blog/how-to-enable-file-auditing-in-windows-server-2016
On VDI environment new Teams version might have below problem evidence:
If you need to activate your windows Client or Server you could use below commands.
slmgr.vbs /upk
slmgr.vbs /cpky
slmgr.vbs /ipk *********** (you must indicate Key)
slmgr.vbs /ato
[other articles]
Slmgr.vbs options for obtaining volume activation information
How to Use Slmgr to Change, Remove, or Extend Your Windows License
Microsoft released bullettin advising customers experiencing excessive memory consumption by LSASS on Windows Server 2012-2022 DCs that have installed the following Windows Update(s):
KB 5035857: March 12, 2024, KB5035857 (OS Build 20348.2340) Windows Server 2022
KB 5035849: March 12, 2024, KB5035849 (OS Build 17763.5576) Windows Server 2019
KB 5035855: March 14, 2024, KB5035855 (OS Build 14393.5786) Windows Server 2016
KB 5035885: March 12, 2024, KB5035885 Monthly Rollup for Windows Server 2012 R2: March 12, 2024
Fortunately, there are workable solutions that you can use to address the high LSASS usage after the 3b Windows update has been installed.
https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#march-2024
Workarounds suggested by Microsoft are related to install below fix
[original article]
IMPORTANT
Microsoft announced that Classic Teams for VDI will reach end of availability on June 30th, 2024.
In case your VDI farm is on Windows Server 2016 this is no longer supported, consider previous announcement you must plan VDI migration asap.
Original article
https://learn.microsoft.com/en-us/microsoftteams/new-teams-vdi-requirements-deploy
Other important blog articles:
Teams #New Virtual Desktop Infrastructure solution #MC717969 **CITRIX**365**AZURE**
Office - Microsoft 365 Apps and operative system supported roadmap
[update 2024.06.24]
about this topic there these new dealines
https://learn.microsoft.com/en-us/microsoftteams/new-teams-vdi-requirements-deploy#requirements
Microsoft announced that The new Virtual Desktop Infrastructure (VDI) solution for Microsoft Teams is a redesigned version of the existing VDI optimization (WebRTC based)
This release applies to Microsoft Windows endpoints connecting to Microsoft Azure Virtual Desktops, Microsoft Windows 365, and Citrix VDI environments only.
Citrix Workspace app for Windows (2203 Long Term Service Release [LTSR], or 2302 Current Release [CR] or higher)
When this will happen:
Targeted Release: We will begin rolling out early April 2024 and expect to complete by late April 2024.
Standard Release: We will begin rolling out in late April 2024 and expect to complete by early May 2024.
I am taking note about fact that Microsoft 365 Apps is supported on the following versions of Windows Server until the dates specified:
This news will strongly affect infrastrucures where VDI are used on previously O.S.
https://learn.microsoft.com/en-us/deployoffice/endofsupport/windows-server-migration
On windows Server environment, it could be useful to debug and save any DNS query submitted to your domain controllers/DNS servers.
There is an easy way to achieve this goal.
In fact you need to enable DNS debugging mode.
After this feature is enabled you can check logs and identify devices that are querying specific DNS entries/websites.
This approach it is useful, at first, about security interdipendence as well...
If you need to allow RDP multiple connection to windows 2016 server you can follow below procedure.
Be aware that alrerady installed internal RDS cal server is a prerequisite
Here they are minimal steps that need to be followed:
I am taking note, on blog, about an interesting article that explain several ways used to limit bandwitch usage during file transfer.
From my side, GPO, related to QoS was decisevely useful.
https://woshub.com/limit-network-file-transfer-speed-windows/
During these latter weeks Sophos released new AV version. (Core Agent 2023.1/Server Core Agent 2023.1 )
PROBLEM
AFFECTED SYSTEMS
AND DEVICES
APPENDIX
In addition to
having the required Windows Security Updates to verify modules signed by Azure
Code Signing, devices must have the "Microsoft Identity Verification Root
Certificate Authority 2020" certificate authority (CA) installed.
Generally impacted O.S. are Windows 10/11 and Windows 2016/2019/2021 server versions.
Legacy O.S. are
not impacted:
Windows 8.1
New Installation
From the 18th of
April 2023, new installations to operating systems that don't support Azure
Code Signing (ACS) will fail.
Metadata Cleanup Using NTDSUTIL in Windows Server 2008 R2
Clean Up Server Metadata