Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Swink
Apr 18, 2006
Left Side <--- Many Whelps
I'm preparing the images for our upgrade from XP > Win7. I'm using MDT2010 to prepare the images. How does inserting windows updates work? If I get the latest security update and insert it, will that be installed when I deploy the image, or will it install the update after the deployment, like it does with applications?

Edit - And is it worth doing? I'm starting to think I'll just let WSUS update the image once its deployed.

Swink fucked around with this message at 01:11 on Oct 10, 2010

Adbot
ADBOT LOVES YOU

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I have (another) MDT/WDS question. Hopefully its obvious but I've been so overloaded with this I cant find it.

I've got an image that I can deploy successfully using MDT. The client pulls down the files from the deploymentshare$, my task sequence and unattend.xml gets picked up and all is well.

Can I import the reference image into WDS as an "install image"? What are the advantages? If any? And how does the task sequence apply to that image once its loaded as an 'Install image' ?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Can someone explain App-V to me in simple, practical, "This is how you would actively use this technology" terms. I'm really struggling with the marketing speel.

Also, am I reading this right, the RDS CALS I already have can be used for App-V? http://www.microsoft.com/windowsserver2008/en/us/licensing-rds.aspx

Oh, and why would I use it instead of RemoteApp, which I have had a play with and mostly understand?

Swink fucked around with this message at 13:07 on Jun 1, 2011

Swink
Apr 18, 2006
Left Side <--- Many Whelps
How do I document my domains GPOs?

The documentation I need to create is intended for my only-semi-technical managers, and possibly the not-yet-competent tech they hire to replace me when I leave.

If they see a setting thats greyed out in Outlook, they need to be able to easily find out three things:

1) A GPO was used to configure that setting
2) The reason it was set
3) What GPO it is in\Security group considerations for that GPO.

I want to create an extremely thorough doco, but I am profoundly poo poo at documentation. How have you done yours? Just dumping the settings .htm is not good enough in this case.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
To the roaming profiles guy: Microsoft calls roaming + folder redirection "user state virtualisation". It sits atop the other desktop technologies like med-v and RDS.

E- test the ever-loving poo poo out of it first.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Could you use a script to install it on shutdown?

Swink
Apr 18, 2006
Left Side <--- Many Whelps

Wicaeed posted:

For those of you in the know for WDS & Windows 7, is it possible to have a sysprepped Win 7 image prompt the user for a CD key the first time it is deployed/run (for use with an OEM key) as opposed to specifying a KMS/MAK key at image build time?

My MDT setup prompts for key and pc name for exactly this reason.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Can anyone help me perfect my MDT deployment?

The issues I'm having are at the beginning, WinPE prompts me for a timezone, I want to get rid of that.

Then right at the end, it prompts for a PC name and product key. If possible I want to be able to enter the PC Name at the very start, and completely skip over the product key. Is that possible to do? My customsettings looks like this:

code:
[Settings]
Priority=Default
Properties=MyCustomProperty
 
[Default]
SkipBDDWelcome=YES
SkipWizard=YES
OSInstall=YES
SkipDomainMembership=YES
 
SkipTaskSequence=YES
TaskSequenceID=DEPLOY

SkipLocaleSelection=YES
KeyboardLocale=en-AU
UserLocale=en-AU
UILanguage=en-AU
SkipTimezone=YES

SkipApplications=NO

SkipDeploymentType=YES
DeploymentType=NEWCOMPUTER
JoinDomain=HA
DomainAdmin=ADMINISTRATOR
DomainAdminDomain=HA
DomainAdminPassword=
SkipAppsOnUpgrade=YES
 
SkipBitLocker=YES

SkipCapture=YES
  
SkipComputerBackup=YES
SkipFinalSummary=NO
 
SkipProductKey=YES
SkipSummary=YES
SkipTimeZone=YES
TimeZoneName=AUS Eastern Standard Time
 
SkipUserData=YES
SkipProductKey=YES
OverrideProductKey=YES

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Any recommendations for full disk encryption for about 50 Win7 laptops? Other than Bitlocker I mean.

Swink
Apr 18, 2006
Left Side <--- Many Whelps

InfiniteDonkey posted:



I've also been making images with physical computers. Now i've been thinking of switching to use VMWare workstation to make the base image as a virtual machine. Does anybody have any experience on creating images from virtual machines?

I maintain my reference images in esx. Being able to use snapshots makes it invaluable. Using workstation would be no different. You'll never go back to using a physical machine.

Swink
Apr 18, 2006
Left Side <--- Many Whelps

Bitch Stewie posted:

Are any of you folks running any kind of print audit/management software like Papercut?

What bits do you use and do your users hate you for making them confirm they want to print something that's going to cost $12?

FWIW - We're a pretty small org. Papercut is a really solid product and their support when I've needed it has been good. We dont use it to charge users, we've got it hooked up to release stations so people have to swipe their cards to get their printing. Its the only printing-related thing I have any confidence in whatsoever.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
This is probably the best place to ask this question.

I've got a script which auto-creates an Outlook email signature for each user by pulling information from AD (Title, Phonenumber etc)

We now have some special case users who get a different signature to everyone else. Within that special signature, an additional site address needs to be added in. There are four possible site addresses.


1. What is the best way to ensure the user gets the correct signature script? My thought was to put those special users in a security group that only gets the 'special' signature script.

2. How do I tell the script which secondary site address to use? My thought was to put a 'flag' into an unused attribute in the users AD account. eg the 'employeeNumber' attribute is never used here. Putting a 1 in this field could indicate to the script that it should insert the address of Site A. Number 2 = Site B etc.

Basically I need confirmation that it is not a terrible idea to use AD like this.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Is anyone using DirectAccess? Now that it's a lot easier to deploy with Server2012 I've been wondering if it could be a replacement for our oldass VPN.

What would it be like for a remote user connecting over 3G?


Edit - that remote uninstall thing is cool. I could have used it last week!

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Is it only supposed to service intranets, fileshares and emails, or is it designed to support our main database applications as well?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I'm using MDT to deploy images. How can I get the LTI wizard thing to prompt me to manually enter a PC name? I dont get asked and I end up with a PC called 'Network-DAFD466'

Google turns up a bunch of info relating to SCCM which I am not using.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I have nothing. Just a customsettings.ini that sets a bunch of stuff. I purposely left out anything to do with the computername assuming that I would be prompted, instead I get assigned a random name.

I tried putting in

SkipComputerName=No
OSDComputerName=

However that doesnt work, I still get the random name.

Ahh - Turns out I had SkipWizard=YES in there. Removing that line sorted me out.

Swink fucked around with this message at 23:36 on Nov 13, 2012

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I use PDQ once a day in my 150 user shop. It's just useful.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
We have an RDSGateway for staff to access stuff on the road.

How should I conveniently package the required certificate file for staff who work from home on non-domain-joined PCs? Is there anything more elegant than a .bat that runs certutil?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Anyone tried out Work Folders in 2012R2 preview?

By the looks it allows us to share out a users' shared folder to their personal laptop\ipad or whatever, then remotely wipe it (the data) when the staffmember loses his ipad or we just want to fire his rear end.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
^ What would be the reason I dont have DCHP setting 252 available in DCHP manager? My list ends at 121


I've had a 2012 DirectAccess server in testing for while and I want to move it to production soon. Does anyone else have their end users using it? Have you run into anything discouraging/Noteworthy?

Swink
Apr 18, 2006
Left Side <--- Many Whelps

Sweet. How do your users find it? I can only assume they love it.

By "Change IP configuration" Do you just mean changing the IPv4 address of the DA server? I'll know to avoid that.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Does anyone use Amazon to store VMs for a DR\Business Continuity scenario? A consulting company is quoting as for replication to Amazon in the event our main site goes down, we can fire up the replicated VMs and the other sites can continue working.

Can anyone give any insight about their setup? Is it cost-effective? (we are a company of just 150)

Swink
Apr 18, 2006
Left Side <--- Many Whelps
We're only small, but we dont auto-approve updates. We delay approving new updates by at least a couple of days just in case one of them is bad. There have been at least one bad Exchange update released this year that we have avoided with this method.

Swink
Apr 18, 2006
Left Side <--- Many Whelps

kiwid posted:

I want to setup RPC over HTTP (Outlook Anywhere) on our Exchange 2003 server. Can someone tell me what SSL cert I need to buy? What is the difference between a UC cert and an IIS cert, as seen here: http://www.entrust.net/microsoft/

If you're screwing around you can get a free cert from http://www.comodo.com/ that will last 60 days. That'll get you up and running and give you enough time to figure out what you're doing.

Edit - Assuming you are just securing the one server - eg mail.consoso.com, you probably just need the basic certificate. https://www.startssl.com will give you a suitable one for free. (dicky signup process but whatever).

Swink fucked around with this message at 04:05 on Nov 7, 2013

Swink
Apr 18, 2006
Left Side <--- Many Whelps

drukqs posted:

Boss carted over a Proliant 320, our long-ago retired domain controller and said "install 2k8 R2 and harden it"

went through the Security Configuration Wizard, unticked a few boxes... Now I'm kind of out of ideas.

Boss tells me today that it is in fact going to be internet-facing which I was completely unaware of.

What else can I do here? The machine is going to sit outside of our domain and store/manage video recordings from our new surveillance system. I've done a bit of googling looking for guidance, but I'm finding a lot of very sparse/zero detail "guides" which aren't all that helpful.

There's a MS program I'm recalling that has a shitload of 'best practice' GPOs for specific OSs. You punch in "2008R2" and it spits out a GPO that you can review and import. I cannot for the life of me remember what its called.

Before all that you should ask if it actually needs to be internet facing. That's dumb.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
CAn someone describe a scenario where I would use RemoteApp or RemoteApp via Web Gateway.

Currently we have remote users log into a full Remote Desktop session where they have access to all our applications. For what reason would I need to deliver a single specific application?

(I have a feeling RemoteApp solves a problem that my company doesn't have, but i'm interested in it)

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Post your experience! We're acquiring 50 peeps next year and I don't have consultant money.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
If the 20 pcs are identical it's probably worth doing.

Good to have in 6 months time when you need to flatten and reinstall due to malware or something.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
We're planning to deploy the Chrome msi at our site because we love our users and want them to be happy.

I'm having trouble figuring out the Chrome master_preferences file as expained here - http://www.chromium.org/administrators/configuring-other-preferences

I'm using GPO to push out the installer. Where exactly do I place the preferences file to have it picked up by the installer?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
It looks like the MSI isntaller creates the master_preference file next to the chrome.exe, but I have to overwrite it with my own preference file before the user runs Chrome for the first time.

I'm not sure if this is better or worse than just creating an .mst

It feels worse.


Edit - and doesnt seem to work at all anyway.

Swink fucked around with this message at 03:24 on Feb 7, 2014

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I've got my head around the Chrome deployment.

1. Install Chrome
2. Use Script\GPO to place M_P file next to chrome.exe binary to set default settings for users
3. Use Chrome GPOs to set mandatory policies (like proxy info)

The only issue I have is there is no way to prevent the .msi installer from creating shortcuts in the AllUsers folder. I have to manually remove them with a script. (The M_P file only prevents taskbar and start menu shortcuts being created per-user post-install).

Swink
Apr 18, 2006
Left Side <--- Many Whelps
PDQ inventory good enough for inventory?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I have a handful of users with redirected folders, whats the best way to move thier folders from the current location to a DFS share?

Can I just update the target location in the GPO or do I have to move the files first?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I do it with a spreadsheet. Doesn't need to be fancy, just accurate.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Anyone have book recommendations for intermediate powershell? Been through the month if lunches book already and looking to get a bit deeper.
Stuff that pertains to system administration is what I'm after.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I need a web-based product for our clients to upload documents to. Nothing too complicated, just a page with a form and an upload box with some security behind it (so people cant upload goddamn cryptolocker). Something we could host ourselves on IIS would be convenient but not necessary.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Does anyone use Owncloud in any kind of business context? Thoughts?

It's in my radar as a file sharing service for our staff to send large files to clients. It's features look good but how does it stand up to the rigours of actual usage by a bunch of people?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I'm got a few DCs In Branch offices that I want to replace with RODCs. Is there any issue with demoting them and then re promoting as RODCs, or is it better practice to introduce an entirely new server?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Anyone using DSC in production yet? I feel it's very much a 1.0 and prob won't be in enterprises for a few years.

It is super interesting. Especially for someone who hasn't played with puppet.

Adbot
ADBOT LOVES YOU

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I've got a Surface Pro 3 with Windows 8.1 Pro. What are my options for getting this working with DirectAccess, which requires 8.1 Ent.

There is no Ultimate equivalent in Win8 land, so I suppose I have to reimage the Surface with a VL copy of 8.1 Enterprise?

Is there any universe where I don't have to have Win8 VL?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply