Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
vanity slug
Jul 20, 2010

That's what we do. We got rid of all our 2000 and 2003 servers this week because :siren: AUDIT :siren:

Adbot
ADBOT LOVES YOU

vanity slug
Jul 20, 2010

You can put the disk in maintenance mode and run chkdsk.

vanity slug
Jul 20, 2010

We just forced a reboot within 1 hour of installation.

vanity slug
Jul 20, 2010

We used to have Lenovo laptops but didn't like the amount of customization. So we're back to being almost 100% HP (servers, SAN, laptops, desktops) again. We throw lots of money at them and they support us pretty well. And sometimes the engineers bring pastries and cake :)

vanity slug
Jul 20, 2010

I guess you could do some failover stuff in Orchestrator. But why would you want to do that when Exchange or SCVMM are perfectly capable of handling that?

vanity slug
Jul 20, 2010

Most of my runbooks feature a heavy amount of PowerShell anyway.

vanity slug
Jul 20, 2010

TWBalls posted:

Ok, so while the forums were down I had asked this on the goon Linked-in group page. I figured I'd ask here now that the forums are back up as I'm hoping to get more suggestions.

We're needing to change the local admin passwords on our systems. We were hoping to be able to do this via Group Policy. While there is a Group Policy Preference that will do this, it's not really secure. Well, apparently that isn't even an option now because there's been an update that disables the password boxes, so it's now impossible to change the password that way.

At this time, I'm seeing 2 ways of doing this. I've seen some scripts that can be used that will do this. But again, I'd like to make sure that this is encrypted to keep it from prying eyes.

The other option is PsPassword from Sysinternals. My concern with that is, our OU is quite the mess. I've been slowly trying to clean it up, but the other techs don't seem to be helping (they're making things worse, if anything). So, it may be a bit of a pain to get a list of computer names that are actually in use. The other possible issue would be if Windows Firewall prevents the program from connecting.

Anyway, I'm hoping that someone may have had to do this before and maybe they know of an easy way to accomplish this. For now, I'm going to try testing the PsPassword on a test OU.

We used PsPassword when it turned out someone had all the local admin passwords in a .txt file on our management server. It worked pretty well. And now you have a good excuse to sort out your OUs :)

vanity slug
Jul 20, 2010

Straight outta SAP for us for promotions, office changes, stuff like that. New hires are still just automated e-mails, but that should be hooked into FIM soon enough.

vanity slug
Jul 20, 2010

Gyshall posted:

Can I ask how you guys sync SAP with Active Directory?

Arcane loving wizardry, as far as I know. I know we just pull certain data out of SAP into a MSSQL database every night, and we use that as a cache for AD and the other applications. But not sure on the specifics.

vanity slug
Jul 20, 2010

skipdogg posted:

Feeling your pain.. I'm the main AD guy where I work and I get asked once or twice a month to do bulk updates to folks user accounts or group membership..

Sure, no problem, send me the data..

I get data that takes me 5 or 6 hours to massage into a useable format to run a script that takes 3 minutes.

Ok, here's what you're gonna say next time: "Sure, no problem, send me the data in this format."

GreenNight posted:

I was asked to add everyones pictures to AD so it gets used in Outlook and Lync. They gave me 400+ pictures and each one a huge fuckoff 40 meg tif on a terabyte drive.

IrfanView takes care of this nicely, usually.

vanity slug
Jul 20, 2010

What kind of authentication are you using? NTLM or Kerberos?

vanity slug
Jul 20, 2010

hihifellow posted:

We have users who "float" between departments or need access to more than one so we share out the root as a DFS share then use ABE and NTFS to control which subfolders the users see and have access to.

That's pretty much what we do, too.

vanity slug
Jul 20, 2010

If you have a GPO that overrides the local users / groups, then you're also going to lose them. :)

vanity slug
Jul 20, 2010

Yaos posted:

You mean with restricted groups or something else?

Yes

vanity slug
Jul 20, 2010

AlternateAccount posted:

Anyone know of a way to trigger a powershell script to run against a user account when they are added to a specific OU? I'd like to streamline our deprovisioning process by running a script that does a few tasks whenever users are moved to a terminated group.

You could use a Scheduled Task to run the Powershell script every x minutes, and compare the list of current objects in that OU to the list of objects in the OU in the last run.

vanity slug
Jul 20, 2010

Uh, just remove 'List folder contents' permission? You can still Read files.

vanity slug
Jul 20, 2010

You're adding two single points of failure to your network.

vanity slug
Jul 20, 2010

We're using RemoteDesktopManager, which is pretty decent, and the server edition ties in nicely with AD.

vanity slug
Jul 20, 2010

orange sky posted:

Do not forget to use bdehdcfg.exe to prepare the disk during the deployment process.

Did you just smash your fist on the keyboard and add .exe?

vanity slug
Jul 20, 2010

Swink posted:

How can I work ABE into my org when I want to hide folders that are not relevant to the user, but still give them the option to acess them if necessary?

If they need access to a folder, you add them to the security group that has access to the folder.

vanity slug
Jul 20, 2010

http://arstechnica.com/security/2015/02/15-year-old-bug-allows-malicious-code-execution-in-all-versions-of-windows/

Time to patch your poo poo.

vanity slug
Jul 20, 2010

Zero VGS posted:

Is there a way to just dump the employee ID badge photos into Office 365 so they show up in Lync and Outlook? I must be bad at Google today.

Edit: With the stipulation, the photos aren't shown outside of the org.

Yeah, import them into AD. This is what we use: http://www.dovestones.com/active-directory-photo-import/

vanity slug
Jul 20, 2010

You have a people problem, not a technical problem.

I guess you could write a script to create a new computer account and have that check whether the object already exists, and tell people to use that (hell, configure a service account for creating computer accounts then revoke access from others).

vanity slug
Jul 20, 2010

We're currently running Symantec Endpoint Protection and as this thread knows, Symantec is the great Satan and I'd like to get rid of them by the end of the contract this year. I've had good experiences with Forefront at a previous employer, the problem is that we don't have any System Center licenses at work right now. Can we just get FEP client licenses (saving SCCM client licenses for next year)?

Ugh I never had to worry about licensing before :(

vanity slug
Jul 20, 2010

Nebulis01 posted:

It's been non-recommended practice since at least 2008. It has a lot to do with publicly available servers and certificate services. As of last year you can't get a certificate with a non publicly reachable FQDN in the CN or SAN

Can't wait to register the .local TLD!

vanity slug
Jul 20, 2010

skipdogg posted:

Our users love it, the emojis are animated

You can also create a guy fisting a goat now with the emojis. 10/10, at least they don't suck up CPU usage anymore!

And yeah, just about halfway through development did they bother actually renaming it to Skype for Business instead of Lync (we beta-tested (TAP) it).

vanity slug
Jul 20, 2010

Tab8715 posted:

It still irks me you can't copy/paste a picture into Lync.

Uh, yes you can? Depending on the settings (set centrally) you can just copy-paste a picture or copy-paste it and it'll send it as a file.

vanity slug
Jul 20, 2010

Tab8715 posted:

OneDrive or was it SkyDrive? And MySites are the goddamn dumbest things in the world.

Also, OneDrive is a SharePoint Site collection and you can only have a max of 20,000 files no more than 10GB per file. Granted, it's better than it was but it's marketed as a Google Drive or Dropbox alternative which it isn't.


Where do you adjust it to just send as a picture?

Yes, it'll send as a file but it's complicated. Load up clipping tool, crop, go back to lync, paste, leave my chat window and open the file - OR - click on the crop button and it's instantly in the chat window.

No idea, I don't use it anymore (new employer). Maybe they removed the functionality in one of the versions which would suck.

vanity slug
Jul 20, 2010

What are the requirements? Just Server 2012 + Win 8 Enterprise right?

vanity slug
Jul 20, 2010

Nano Server is really exciting. About time, too.

vanity slug
Jul 20, 2010

ZetsurinPower posted:

One of our engineers isn't doing his loving job, so I need to take things into my own hands and get something done but I'm not sure the best way to do it.

We're a Win7 shop, SCCM managed workstations. There is an Office add-in that is causing problems and I want to unregister the DLL for all of the computers to disable it.

I know how to do it on a case by case basis using "regsvr32 /u" but what would be the best way to do this for all laptops? Even better, limited to model-xxx?

Create a group for that model and deploy a script with SCCM that does that?

vanity slug
Jul 20, 2010

KS posted:

We give firstname.lastname@domain as an email address and first initial + last name for an AD username. I think that's silly and leads to user confusion.

Any reason I can't start assigning firstname.lastname for AD accounts for new hires? I can't think of a reason this would be a problem, but I'm realizing I've never actually seen that account naming scheme for AD.

The only reason I can think of is the sAMAccountName character limit (20 characters).

vanity slug
Jul 20, 2010

We just use flastname where f is the first letter in their first name. If someone else already has it, just keep adding letters (and eventually digits at the end)

vanity slug
Jul 20, 2010

KennyG posted:

Passwords! Passwords loving suck. I know there are products out there that can manage service accounts and password rotation for me but I can't find anything but manage engine and I have never had good luck with their stuff.

I want something to manage service accounts and share password access amongst admins. The overwhelming majority of our infrastructure is ad enabled. This is why I chose this thread.

KeePass? It's alright.

vanity slug
Jul 20, 2010

Erwin posted:

Is he explicitly denied on all those folders, or just doesn't have rights? If the latter, can't you just give him modify on the file itself, and put a shortcut to it on his desktop? If he's explicitly denied, then yeah, you'd have to break inheritance.

Explicit Allow overrides inherited Deny, fyi

vanity slug
Jul 20, 2010

https://www.microsoft.com/en-us/download/details.aspx?id=46899

There's a tool for that.

vanity slug
Jul 20, 2010

we're upgrading to windows 2003 in a month! i'm so excited.

vanity slug
Jul 20, 2010

Swink posted:

Can anyone run me through baby's first Server documentation and change-request process? I have a small shop but I want to go through the motions so I know how to handle a big shop.

I just spun up a VM for a new application. Lets say it's Sophos Safeguard + its SQL database. What do I put in the documentation about this server?

When and why would I do a change request, and what would it contain?

Whatever you changed from the default configuration.

Whenever you change the configuration.

vanity slug
Jul 20, 2010

Zero VGS posted:

As of today Microsoft finally has a new sync app to replace their broken as gently caress OneDrive for Business client: https://support.office.com/en-us/ar...&rs=en-US&ad=US

Not for 8.1 but available for 8? That's loving bullshit.

But definitely gonna test this for 10.

Adbot
ADBOT LOVES YOU

vanity slug
Jul 20, 2010

Zero VGS posted:

I guess my mistake was probably not removing the key before making the image so it wouldn't show up on the new PCs before I put in their BIOS keys.

Yep. So create a proper image and go at it again. Ideally you'd re-image the laptops with the bad image as well at some point. Or just stick all your keys in KMS, which'll save you more headaches in the future.

And yeah the 840 is a really solid device. We had some issues with the 4G modules not performing well (cause the fuckers didn't actually put them in properly) but otherwise, really solid.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply