igodwin 55b6fd73b8 Add od-cfg-persist runbook + od-cfg-acl script
Persist Open Dental's 'Do not show this window on startup' by making
FreeDentalConfig.xml writable:
- Option A: one-time elevated save
- Option B (preferred): grant Users Modify via well-known SID S-1-5-32-545
- od-cfg-acl.ps1 auto-resolves 64/32-bit install path, iex-safe conventions
- Security note on reversible MySQL password in the config; limited user / Middle Tier
- Cites OD manual freedentalconfig.html / choosedatabase.html

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 00:20:29 -07:00

rb — runbooks

Generic, reusable IT procedures and scripts for MSP field work. Fetched onto client workstations during on-site work with short, hand-typeable commands.

Warning

This repository is PUBLIC-READ. It must never contain client-identifying information — no client names, hostnames, IPs, usernames, credentials, or screenshots. Procedures with placeholders only. See CONTRIBUTING.md for the sanitization rule.

Provided as-is, no warranty. Running any script is at your own risk. Contains no client-identifying data by policy.

Using a runbook

Fetch and read on the target workstation:

irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/<file> | more

Run an executable runbook script directly (scripts live under scripts/):

irm https://gitea.ivangodwin.com/ops/rb/raw/branch/main/scripts/<file>.ps1 | iex

Scripts prompt for anything client-specific via Read-Host — nothing to edit before running. See scripts/_template.ps1 for the convention.

Layout & naming

  • Runbooks (.md) live flat at the repo root with short, hand-typeable filenames and light category prefixes.
  • Scripts (.ps1) live under scripts/. _template.ps1 sorts first and is the convention reference, not a runnable runbook.
  • Meta (README.md, CONTRIBUTING.md) stays at the root.

Runbook prefixes:

Prefix Domain
win- Windows workstation / server
m365- Microsoft 365 / Entra
od- Open Dental
net- Networking

Placeholder conventions

Fill these from the private tier (private repo or Bitwarden secure note) at run time — never commit filled-in values.

Placeholder Meaning
<CLIENT> Client / site identifier
<SERVER> Server hostname
<SHARE> Share name
<SHARE_USER> Local account used for share access
<USER> End-user account
<PASSWORD> From password manager — never written to a file

Contents

File Purpose
od-smb-cred.md Open Dental SMB share — stored-credential fix
od-cfg-persist.md Open Dental — persist "Do not show this window on startup" (writable FreeDentalConfig.xml)
scripts/cg-disable.ps1 Disable Credential Guard, then reboot (prompts to confirm)
scripts/od-cfg-acl.ps1 Grant Users Modify on FreeDentalConfig.xml (Option B of od-cfg-persist)

Tiers

  • This repo (public): generic procedures, placeholders only.
  • Private tier: filled-in, client-specific versions — private repo or Bitwarden secure notes. Never here.

This repo also serves as the raw source for Intune remediation scripts and as documented-procedures evidence for E&O / cyber insurance.

S
Description
No description provided
Readme 105 KiB
Languages
PowerShell 100%