Sheridan Posted September 10, 2015 Posted September 10, 2015 Maybe its me but there are some parts of 10 I just can't get working. Perhaps a thread of this kind might be a way of pooling other peoples success and failures in similar areas? What I can't get working (to date!) is: 1) Apps are difficult to remove and results vary (i.e removing all provisioned apps doesn't always work for all users) 2) Edge is useless in its current state, but finding IE is variable (non admin users can't see it when searching, and adding a tile for it doesn't work) 3) Deploying a custom start layout only half works (some tiles missing (IE, File explorer simply don't appear for anyone other than the initial creator) 4) Office 2013 installation package created with the \admin option fails to install (Works fine on W7 and 8) 5) Windows Update fails behind a proxy (even though update sites are allowed unauthenticated, it still tries to bypass the proxy) 6) Group policy settings lacking for disabling of new features (such as the new Settings app) 7) AppLocker not working properly - blocking whitelisted paths 8) Slow login speeds 9) Cannot seem to remove the 'Other User' on domain login screen, which just looks a bit naff I have plenty more, but I'm struggling with this lot to get a few configured and reasonably protected trial PCs out there!
Oaktech Posted September 10, 2015 Posted September 10, 2015 1) yes 2) yes 3) Working OK here 4) yes 5) Working OK here 6) Yes - this is worrying me a lot. 7) Yes 8) It's no worse than 8/.1 here 9) Forcing Ctrl+Alt+Del seems to get round that here.
CyberNerd Posted September 10, 2015 Posted September 10, 2015 I think I'll like windows10, it sounds like a beta linux distro.
cpjitservices Posted September 10, 2015 Posted September 10, 2015 If I right click anywhere my machine seems to hang for a few minutes... its rather annoying.
GuyJD Posted September 10, 2015 Posted September 10, 2015 I've got an issue with digital camera's at the moment, when you plug one in via USB the built in photo download tool fails with an error and the user has to navigate to the camera in "This PC" to manually copy the photos
Michael Posted September 10, 2015 Posted September 10, 2015 1) Try hiding Apps rather than removing them using a controlled Desktop/Start Menu and Folder Redirection 2) I agree, use IE11 and/or Chrome 3) I agree, it doesn't stop users re-sizing it either as far as I can tell 4) Office 2016 is due out the end of September 5) Are you using WSUS? This should get around the proxy issue 6) Disabling access to Control Panel will disable access to Settings on Start. If you're referring to the WinX menu (right clicking Start), if you navigate to the Default profile in: C:\Users\Default\AppData\Local\Microsoft\Windows\WinX Then delete Group1, Group2 and Group3 folders. Now when a new user logs on (for the first time), nothing appears when right clicking Start. To restore functionality for an administrator account, simply copy Group1, Group2 and Group3 back specifically just for that administrator profile. 7) AppLocker - not sure 8) Logging in the first time I agree, but after that generally OK 9) I thought it was weird too, but I disable Ctrl+Alt+Del for younger pupils who struggle with it too. You can customise the logon picture to make it more appealing I guess.
Sheridan Posted September 10, 2015 Author Posted September 10, 2015 I do use WSUS, but I like to occasionally force a full update (i.e pre image preparation) I can't disable access to the Control Panel entirely, as I let our staff and students access the Printers applet - and this can't be individually allowed with the new 'two control panel' settings! I've left IE on and installed Chrome, but weirdly if I use a custom Start layout with IE defined in it, it simply doesn't appear. If a non admin user searches for Internet Explorer all they get are web links! and I can add: 10) Users desktop background very varaible when it appears. Sometimes it takes 3-4 logins to change from a black background to the locally stored image
Michael Posted September 10, 2015 Posted September 10, 2015 I know what you mean about using Microsoft Update before running Sysprep. It should work fine once you've configured proxy settings in Internet Options, but I know Windows 8 and 8.1 had more issues with proxies previously. That's an interesting point regarding Control Panel and Printers. In the olden days (and I think it still works), you can specify Control Panel *.cpl files via Group Policy which hides specific icons, but then that still leaves Settings on Start. I'll have a play and see what I can find out. If you control the background image using a GPO, it should be consistent.
Sheridan Posted September 10, 2015 Author Posted September 10, 2015 The background image (deployed by GPO) only works when the user has clicked Task View. Otherwise it remains black. Proxy settings are ok and visible - but update seems to be hitting both the proxy and also the firewall (which is blocked for this kind of direct access).
denzal2k4 Posted September 10, 2015 Posted September 10, 2015 Edge deletes downloads Cortana can crash on startup and break the start menu, still unsure how to fix that When you go to Devices in All Settings then click the link for Devices and printers for old style control panel it gives a dll error but opens anyway Pinned Apps sometimes disappear for users.
Sheridan Posted September 11, 2015 Author Posted September 11, 2015 Applocker seems to be an odd one. if you use Software Restriction Policies and duplicate them in Applocker - Applocker will fail even on paths whitelisted in both. If you remove SRP then Applocker seems to work, albeit with the occasional glitch.
Sheridan Posted September 11, 2015 Author Posted September 11, 2015 11) - Once you've uninstalled all the provisioned apps mess, you can't selectively reinstall one app (such as calculator/camera etc)
Michael Posted September 11, 2015 Posted September 11, 2015 I've found a solution to Devices and Printers as follows: Right click Start > Control Panel, then right click Devices and Printers. Select Pin to Start. Return to Group Policy and enable - Prohibit access to Control Panel and Settings. Now logoff or restart. Once logged in, click Start and select Devices and Printers you pinned earlier. It works as expected, yet Settings and Control Panel are disabled. In summary, anything in Control Panel that you can right click and pin to Start will still work 1
Sheridan Posted September 11, 2015 Author Posted September 11, 2015 Thank, I'll give that a try. Might even work in 8.1 as well!
Arthur Posted September 11, 2015 Posted September 11, 2015 AppLocker seems to be an odd one. If all of your Windows PCs are capable of using AppLocker why even bother with SRP? Also... https://technet.microsoft.com/library/hh994614 AppLocker is supported on systems running Windows 7 and above. Software Restriction Policies (SRP) is supported on systems running Windows Vista or earlier. You can continue to use SRP for application control on your pre-Windows 7 computers, but use AppLocker for computers running Windows Server 2008 R2, Windows 7 and later. It is recommended that you author AppLocker and SRP rules in separate GPOs and target the GPO with SRP policies to systems running Windows Vista or earlier. When both SRP and AppLocker policies are applied to computers running Windows Server 2008 R2, Windows 7 and later, the SRP policies are ignored. 1
Sheridan Posted September 11, 2015 Author Posted September 11, 2015 If all of your Windows PCs are capable of using AppLocker why even bother with SRP? Also... https://technet.microsoft.com/library/hh994614 Because srp works and so far applocker isn't working reliably. On a windows 10 machine, if I run an msi as an admin on a network share it blocks it, despite all msi packages being whitelisted for admins. When I check the error log it shows the msi path. If I then click the path in the error log the msi works! So applocker is buggy on 10 so far. I haven't migrated from srp as it works perfectly on our w7 machines, although it's always been on the list of things to do if we'd moved to w8.
Arthur Posted September 11, 2015 Posted September 11, 2015 On a windows 10 machine, if I run an msi as an admin on a network share it blocks it, despite all msi packages being whitelisted for admins. That happens on our Windows 7 PCs too. I think it's due to the way msiexec.exe works. The solution for us was to add a "Run as administrator" option the MSIs context menu for when we need to install MSIs manually. Problem solved! Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Msi.Package\shell\runas] @="Install as &administrator" "HasLUAShield"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Msi.Package\shell\runas\command] @="msiexec /i \"%1\"" http://vgy.me/7cMqc4.png You may also need to enable "linked connections" so that the mapped drives remained mapped when the installer elevates. Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] "EnableLinkedConnections"=dword:00000001 I haven't migrated from srp as it works perfectly on our w7 machines, although it's always been on the list of things to do if we'd moved to w8. We got rid of SRP as soon as we ditched XP and moved to 7. Publisher rules in AppLocker make allowing and denying access to applications much easier compared to SRP. 1
Sheridan Posted September 11, 2015 Author Posted September 11, 2015 Cheers for that @Arthur, I'll give that a go. I always intended to move to applocker but with srp working fine I hadn't had the need!
Sheridan Posted September 14, 2015 Author Posted September 14, 2015 Heres a new one! Fresh install of 10 Enterprise - joined to domain and non admin user logs in and the Start button does absolutely nothing! Login as admin, and it works as expected. What sort of testing did this actually go through
Oaktech Posted September 14, 2015 Posted September 14, 2015 Heres a new one! Fresh install of 10 Enterprise - joined to domain and non admin user logs in and the Start button does absolutely nothing! Login as admin, and it works as expected. What sort of testing did this actually go through The kind of testing where everyone is an admin, no GPOs are applied and they just badge up a consumer grade OS with a business grade name. Standard MS then!
sted Posted September 14, 2015 Posted September 14, 2015 The kind of testing where everyone is an admin, no GPOs are applied and they just badge up a consumer grade OS with a business grade name. Standard MS then! I don't think ms see a long term future for the domain model we are all used to hence things like workfolders and I would be surprised to see direct access working on non domained pcs in future (if it dosent now) I suspect their future vision is basically byod with your data in the cloud either office 365 or azure and you just connect from whatever device you are on (hence the unified windows 10 approach) So if they see the future as self owned devices how much effort do they put into features they expect to be marginalised just look at gpp its a way of keeping admins happy and means ms don't have to write policies into the system. if they really thought domain etc was the way forward we would have policies for libraries as they could make things that bit easier if they were managable 1
CyberNerd Posted September 14, 2015 Posted September 14, 2015 I don't think ms see a long term future for the domain model we are all used to hence things like workfolders and I would be surprised to see direct access working on non domained pcs in future (if it dosent now) I suspect their future vision is basically byod with your data in the cloud either office 365 or azure and you just connect from whatever device you are on (hence the unified windows 10 approach) So if they see the future as self owned devices how much effort do they put into features they expect to be marginalised just look at gpp its a way of keeping admins happy and means ms don't have to write policies into the system. if they really thought domain etc was the way forward we would have policies for libraries as they could make things that bit easier if they were managable I must agree with this. I think the domain model is out, google proved it's perfectly possible to manage a fleet of user accounts for BYOD with their tools. MS's best move would be to adopt this model too.
Oaktech Posted September 14, 2015 Posted September 14, 2015 All of that is lovely, but I'm not sure I want it... It's all much too reliant on internet connectivity that outside major metropolitan areas is patchy-as or prohibitively expensive.
sted Posted September 14, 2015 Posted September 14, 2015 All of that is lovely, but I'm not sure I want it... It's all much too reliant on internet connectivity that outside major metropolitan areas is patchy-as or prohibitively expensive. im not saying I agree with it im just saying that looks like the direction they are headed
Sheridan Posted September 14, 2015 Author Posted September 14, 2015 W10 is a buggy mess whatever MS think of domains. A fresh install and simple join to a domain (with minimal policies) has resulted in a broken OS for me. Even little things are failing - for example the camera app appears for an admin, but seems to have completely vanished for other users. Why? I've spent so much time trying to cobble a working image together but I'm bored with it now.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now