Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
thebigcow
Jan 3, 2001

Bully!
I tried Spark but it felt really slow on our really slow computers. Pidgin was available in Ninite and I've had no complaints.

Adbot
ADBOT LOVES YOU

thebigcow
Jan 3, 2001

Bully!
slowly replace them with things that have some kind of ipmi

thebigcow
Jan 3, 2001

Bully!
Maybe this will help: http://www.nsa.gov/ia/_files/app/Deploying_and_Securing_Google_Chrome_in_a_Windows_Enterprise.pdf

thebigcow
Jan 3, 2001

Bully!

GreenNight posted:

Yes, I purchased it last week even though we have SCCM. Way easier to get info out of. Try the free ver, it has everything but scheduled updates.

Paid version also gets you product keys for installed software, remote uninstalls, and some other things that I forgot about.

thebigcow
Jan 3, 2001

Bully!
You could probably store it all in a csv and pull it in that way if you want to fancy it up.

thebigcow
Jan 3, 2001

Bully!

Gyshall posted:

Do this:

http://support.microsoft.com/kb/929841

I think IE is moving to some convoluted as gently caress Internet Explorer Administrator Toolkit or something like that, but for the most part the above will work for you.

I use all the RSAT policies, Office Policies, etc and put them into the Central Store, which makes it pretty easy to set policy settings on various software. Even Google and Firefox make group policies you can put there.

The IEAK has existed for several versions of IE and basically lets you make your own custom IE installs with whatever default options and bookmarks you want. You can also make a reconfigurator that will make an existing install like your custom version but I don't think it was ever intended as a management tool.

thebigcow
Jan 3, 2001

Bully!

nexxai posted:

This is the very definition of a situation where you're trying to use technology to solve a personnel problem. At a certain point, you can't make things any easier for people. Obviously they care enough to use snip-tool to send you a screenshot, so teach them to use "CTRL-C" when the error message appears which will (if the software was written correctly) copy the title and text of the prompt.

I've bolded the problem with your plan.

thebigcow
Jan 3, 2001

Bully!

lol internet. posted:

We have a couple machines which were licensed for Windows 8.1. There's no Windows 7 OEM license sticker or anything on it but does it actually have downgrade rights?

Downgrade rights come with volume licensing with software assurance. Enjoy your modern operating system experience.

thebigcow
Jan 3, 2001

Bully!
Is there any best practice for where to install legacy programs that insist on putting everything in program files and letting every user write there? One vendor's solution was to put their stuff in C:\vendorname, another vendors was to put it under public documents\vendorname. Would a legacy app folder similar to /opt on linux be the right thing?

I'm finally getting rid of some XP machines for 7 and I'd like to start out right.

thebigcow
Jan 3, 2001

Bully!

MrMoo posted:

There's a c:/ProgramData/ already for that, just hidden by default for Microsoft awesome reasons.

I saw that and assumed it was for something else.

thebigcow
Jan 3, 2001

Bully!
Roughly how lovely is Server 2008? I never hear anything about it.

thebigcow
Jan 3, 2001

Bully!

Fruit Smoothies posted:

I'm a bit out of my depth with planning this. I need a truly redundant setup, and I have an almost unlimited budget. I basically need constant uptime of a domain and ~2TB of files housed in SMB shares.
In all my previous challenges, I've used 2+ DCs, and used DFS for the file sharing. In this case, however, I have an ancient application that uses flatfile (CSV) "database" and basic file locking to handle its operation, and an accounting package that uses FoxPro databases. Both of these rule out DFS as it's not sensitive enough to low level file operations.
My basic understanding of what I need is:

File Storage (SANs)
File Server Cluster
Fall over Hyper V pointing to VHDX on cluster.

Forgive my ignorance, and PLEASE help me understand the basic segments of this operation! Many thanks.

FYI the FoxPro thing and probably the CSV thing will choke and mysteriously corrupt themselves on SMB 2.

thebigcow
Jan 3, 2001

Bully!
I'm sure know what you're doing and you've thought about this already but just in case, have you looked into moving to something that wasn't designed to run on a single win9x machine?

thebigcow
Jan 3, 2001

Bully!
NIC drivers that aren't part of Windows for some reason. It doesn't have to be anything fancy.

thebigcow
Jan 3, 2001

Bully!
NIC drivers are helpful for letting your new machine communicate with whatever is installing everything else. I don't know how much of a problem this still is but Broadcom and XP :(

thebigcow
Jan 3, 2001

Bully!

Zero VGS posted:

Okay, I'll check out that stupid powershell.

Also, I'm reading that some linux thingies like Samba/Zentyal can be Active Directory domains now. Bad idea, or really bad idea? I only need a domain for basic LDAP/GPO and to link up with Spiceworks. Basically to get my 200 laptops off a workgroup and have some semblance of inventory. Buying Windows Server and all the CALs for 400 laptops is going to run at least 20 grand. Can this all be replaced with a Samba VM, or will I spend the rest of my life figuring out bugs/hacks? Could be good job security!

Depends, do you hate yourself?

thebigcow
Jan 3, 2001

Bully!
Nothing about that sounds like a good idea. Spend some time working on your sales pitch for why you need megabux to pull this off properly. Everything you've suggested in this thread will only end with you attached to a dialysis machine with no health insurance after you get fired.

thebigcow
Jan 3, 2001

Bully!
Its been that way since XP SP2. There is a GPO setting for ICMP to make it easy to turn back on.

thebigcow
Jan 3, 2001

Bully!
There is a gpo setting to limit access to optical drives to the logged in user. AFAIK it isn't enabled by default, but it is what I used to let people burn media on our XP machines.

thebigcow
Jan 3, 2001

Bully!
Does Windows Fax Server look at caller id or does it look at the number the fax machine sends? I've found most people never configure that so the logs on my mfp are useless.

thebigcow
Jan 3, 2001

Bully!
I like PDQ Deploy and they make Java packages if you pay for a license. I don't pay and I don't use Java so I have no idea if their setup will work for you.

thebigcow
Jan 3, 2001

Bully!

Coredump posted:

When practicing with ESXI, Server 2012 and dhcp, how the heck do you keep the esxi box from handing out ip addresses on your real network?

Create a second vswitch not attached to any real interface, create a second nic on the 2012 vm attached to that vswitch, bind the dhcp service to that nic, and then have whatever other virtual machines you use for this only be on that vswitch and access them through the vsphere console.

The best way to do it depends on what you're trying to do and how long this needs to work/good it needs to be. That's what I did when playing around with a router virtual machine.

thebigcow
Jan 3, 2001

Bully!
What does it break? Its pending me finally rebooting....

thebigcow
Jan 3, 2001

Bully!
http://www.zytrax.com/books/ldap/

I bookmarked this an age ago and never got around to reading, maybe it will help you.

thebigcow
Jan 3, 2001

Bully!
Can you yank the drive, install on a different machine, and just deal with the problems after you put it back?

USB DVD drive might work better than a thumb drive.

thebigcow
Jan 3, 2001

Bully!

angry armadillo posted:

Actually you can't even get USB sticks through the door

But we have a number of technological controls to stop that too :(

You have a cavity search robot?

thebigcow
Jan 3, 2001

Bully!

NevergirlsOFFICIAL posted:

OK hi



I want to remove this folder redirection without users losing any of their files. I want the files to stay on their local machines, and I want them to be removed from the server. Actually I don't care if they get removed from the server I just don't want any problems when I turn this server off. What's the best way to do what I want to do? Can I just disable this GPO?

AFAIK you need to change a setting on that thing that lists the path and the rest of what you have set up should move things to the new location. This can blow up on you if everyone has a million files on the server and logs in at the same time, if they don't have enough local disc, etc etc etc. Also I haven't messed with that in an age so don't take my advice.

thebigcow
Jan 3, 2001

Bully!
How much bigger is the bigger pipe at the office? What is your budget for liquor for the first day when nothing is cached?

thebigcow
Jan 3, 2001

Bully!

BaseballPCHiker posted:

How is PDQ at creating your own packages? Since I've been using Chocolatey more and more lately I wouldnt need to use any of their package library but I really want something simple and easy for creating MSI's that isnt Orca.

PDQ doesn't make installers, it just shoves them where they need to be.

thebigcow
Jan 3, 2001

Bully!
Because those are relatively new and don't provide a nice front end for managing it all. PDQ Deploy also provides some nice integration with PDQ Inventory.

thebigcow
Jan 3, 2001

Bully!
Biggest problem would probably be the 2012r2 box defaulting to newer things in SMB that 2000 doesn't support. Also any Group Policy things you depend on that don't exist in 2000.

I have a Windows 10 Pro machine and a 2000 Small Business Server DC and everything pretty much works :gonk:

thebigcow
Jan 3, 2001

Bully!
Can you script turning the locking on and off locally? Then do whatever you want to prevent the GPO from applying that to that particular machine and have it run the script when he logs in and off.

It's ugly, but if you absolutely have to make it work then I don't see a better way

thebigcow
Jan 3, 2001

Bully!
https://blogs.technet.microsoft.com/windowsitpro/2016/05/17/simplifying-updates-for-windows-7-and-8-1/


One giant rollup for everything between sp1 and April 2016

thebigcow
Jan 3, 2001

Bully!

Thanks Ants posted:

Also the setting in Options > Advanced where you set the maximum thread count to one less than the number of physical cores on your machine.

What he said. Were the previous machines hyper threaded?

thebigcow
Jan 3, 2001

Bully!

Martytoof posted:

Not really "enterprise" but it's AD so I figure you guys would know best.

I'd like to modify my AD schema to add SSH keys, but I'm worried about messing it up. This is my homelab so I guess if I mess it up it's not really a disaster, but I'd rather not reinstall. If this is my only AD controller (no replication), can I just make a VMware snapshot and restore it if I do gently caress up, or is that not going to cut it as far as "restoring" my working AD?

The alternative is that I store my SSH keys in altSecurityIdentities and write a custom script for my Linux boxes to poll AD for keys there, but I guess sss_ssh_authorizedkeys is already built in so I'll take my chances hacking up my schema if I can restore relatively easily.

If its a lab, and you have a single domain controller, you can shut down the domain controller virtual machine and snapshot it. Do not snapshot while it is running. Do not do this if you have more than the one domain controller. Do not plan on rolling back to this in several months or you'll be fixing computer accounts.

thebigcow
Jan 3, 2001

Bully!
Has anyone seen details of how the delivery optimization service is supposed to work? I have four Windows Home machines on satellite internet at a remote site, would be really nice if they shared a download instead of insisting on grabbing it themselves. The only things I turned up while searching were what buttons to click to turn it off.

thebigcow
Jan 3, 2001

Bully!

wyoak posted:

This isn't really an enterprise question because I hope workgroups are pretty rare in 'real' networks but people here might know the answer...

What functionality does a workgroup provide (in windows)? Computers in different workgroups on the same network can access each other's SMB shares fine (as long as credentials are shared). Domain computers can access workgroup systems as well and vice versa (again, if credentials are shared). It doesn't seem to affect network discovery.

edit: Ok, it does actually affect network discovery, is that their only purpose?

Network discovery and nothing else I know of. If you want cross subnet workgroups you need a WINS server.

If you don't need that you might want to look into Homegroups. They handle computers appearing and disappearing pretty quickly, and if everyone is using a Microsoft account to log in are still allow fairly granular permissions. No Microsoft accounts means its read, read/write, or nothing. They work over IPv6 link local addresses so there is no way I know of for them to talk across subnets.

thebigcow
Jan 3, 2001

Bully!
Did you intend to have a /32 network size?

thebigcow
Jan 3, 2001

Bully!
You really need a better workflow instead of a technical solution, but you probably already know that.

Can you whip up something with Get-SmbOpenFile ?

Adbot
ADBOT LOVES YOU

thebigcow
Jan 3, 2001

Bully!

Eschatos posted:

Is it at all possible to deploy wireless network settings (SSID/password/etc.) via group policy? I found how to do so with a non-passworded network, but that's not too useful.

If your network is WPA2-PSK I don't know of anything, other than maybe running some kind of script.

Is Windows Connect Now still in Windows 10? It was a way to save Wi-Fi settings on a USB drive. https://technet.microsoft.com/en-us/library/ff723781.aspx

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply