timbo343 Posted January 25, 2017 Posted January 25, 2017 The messaging I am seeing is that they've basically given up on the set of technologies that were once back in 1998 branded as "IntelliMirror". Enterprise can stick happily with Windows 7 and Group Policy until such time as cloud management and services can offer capabilities that meet business requirements. Don't forget that many of us are trying to make the new stuff do things the old way, whereas in reality we need to step back, learn about the cloud management and storage and figure out how to make that work for our organisations. If we try to re-implement the old way using the new tools we are fighting against the tech and we will find it will never work. Nobody is trying to make Andriod or IOS or Chromebooks work like a Unix networked workstation, and they work (within their context) very well. We need to stop trying to make Windows 10 behave like Windows 2000/XP, and figure out the new right way of doing things that will work for the next 10-15 years. https://books.google.co.uk/books?id=vTsEAAAAMBAJ&pg=PA14&lpg=PA14&dq=Intellimirror+1998&source=bl&ots=XUS2od4UVt&sig=wP-gNosFWp512AyKcjfqFTSes9U&hl=en&sa=X&ved=0ahUKEwj1soOard3RAhVkC8AKHSkWB1AQ6AEILTAD#v=onepage&q=Intellimirror%201998&f=false https://news.microsoft.com/1998/08/18/microsoft-delivers-windows-nt-5-0-beta-2-to-more-than-250000-testers/#sm.001ga051w17ones4u1s145vtwgg5m https://technet.microsoft.com/en-us/library/hh848267(v=ws.11).aspx https://technet.microsoft.com/en-gb/itpro/windows/manage/index From what im seeing, win10 is designed as a 1:1 OS meaning everyone needs a device, something we just cant afford. 1
LeMarchand Posted January 25, 2017 Posted January 25, 2017 The messaging I am seeing is that they've basically given up on the set of technologies that were once back in 1998 branded as "IntelliMirror". Enterprise can stick happily with Windows 7 and Group Policy until such time as cloud management and services can offer capabilities that meet business requirements. Don't forget that many of us are trying to make the new stuff do things the old way, whereas in reality we need to step back, learn about the cloud management and storage and figure out how to make that work for our organisations. If we try to re-implement the old way using the new tools we are fighting against the tech and we will find it will never work. Nobody is trying to make Andriod or IOS or Chromebooks work like a Unix networked workstation, and they work (within their context) very well. We need to stop trying to make Windows 10 behave like Windows 2000/XP, and figure out the new right way of doing things that will work for the next 10-15 years. Surely W7 is likely to be EOL before then? I agree that the way to make W10 work is the "MS way" (once they work out what that is) but most schools (heck, most businesses) can't (at least in the short to medium term) afford to change their infrastructure to do that.
Sheridan Posted January 25, 2017 Author Posted January 25, 2017 Everything is heading towards 1:1 - the mass panic to buy ipads for schools showed that they don't work very well unless they're 1:1 (G Suite Apps aren't multi user on these sort of things) I agree we need to adopt new ways and we are doing that, but the old ways are still in use in massive amounts of examples. I may be old school, but when it comes to any prolonged amount of typing/browsing I still always revert to laptop/desktop. Again its an example where MS could have offered W10 Home/Tablet Edition and W10 Business Edition, they are distinct areas of use and W10 could have worked well if adjusted to suit the environment.
timbo343 Posted January 26, 2017 Posted January 26, 2017 IIRC I have set these services to automatic - they were manual... REM Netman (Network Connections) sc config Netman start= auto REM Network List Service sc config netprofm start= auto Ive had some real fun and games with the netprofm service over the last 24 hours and today ive been at BETT. Basically, a school boy error on my part, i used Group Polciy to set the service to automatic and started but i changed the log on credentials to Logon with the system account and majorly knacked things up so for the last 24 hours ive been trying to find out what the problem was and trying to find the best way to fix it. By disabling the service it causes the windows fireware to enter the guest/public profile therefore things dont work correctly. I wont be making this mistake again. After trying to find out on the train this morning on a poor 3g connection, wandering round BETT and having breaks to try to get a solution to this, at 4pm we decided to sit down and look for a solution. Working on each machine remotely at BETT we found the problem. Got a script together of sc config "netprofm" obj= "nt authority\localservice" password="" things started to work but we had to check each amd every machine via ping to see if we got a response. Some machines would apply the fix so we had to go in manually to each machine, go to services and remove the "password" from the logon account. We only just managed to get the majority done when we pulled up at our home station at 10.30pm.
mrwoberts Posted January 27, 2017 Posted January 27, 2017 Sorry to hear of that trouble; I was hesitant about suggesting those changes. Apologies if I caused you a bit of a headache there. Once those changes have been applied, I'd be interested to know if they resolve the original problem of 'logon server not found'. Have a good day - I'm off to BETT
timbo343 Posted January 27, 2017 Posted January 27, 2017 Sorry to hear of that trouble; I was hesitant about suggesting those changes. Apologies if I caused you a bit of a headache there. Once those changes have been applied, I'd be interested to know if they resolve the original problem of 'logon server not found'. Have a good day - I'm off to BETT Dont worry, hopefully others wont make the mistake now. Have fun at bett, i didnt enjoy as muxh as last year.
timbo343 Posted January 27, 2017 Posted January 27, 2017 Right, going back to the group policy not applying, someone on spiceworks has mentioned the wait for network policy. I only came about this as i was looking into an error. Gentlemen the answer to your questions is to disable group policy optimization. Do this in your GPO. You can change the default setting by using the Group Policy MMC snap-in. This feature is enabled by default, but you can disable it by using the following policy: Administrative Templates\System\Logon\Always wait for the network at computer startup and logon. The reason this issue comes up is that 2008 Active Directory by default is set to use fast login, which means it doesn't wait for the network to process GPO's, therefore user settings can get bypassed. Disable optimization in your GPO's and your issue will be resolved. 1
Sheridan Posted January 30, 2017 Author Posted January 30, 2017 Right, going back to the group policy not applying, someone on spiceworks has mentioned the wait for network policy. I only came about this as i was looking into an error. Hmm I already have this policy enabled so therefore GPO optimisation is already disabled on my w10 pcs
timbo343 Posted January 30, 2017 Posted January 30, 2017 Ah! Have you got the new group policies that were released. Ive installed them but not looked through them.
Sheridan Posted January 30, 2017 Author Posted January 30, 2017 Ah! Have you got the new group policies that were released. Ive installed them but not looked through them. TBH I'm sure that policy setting was there with Windows 7? I seem to remember setting it a long time ago!
timbo343 Posted January 30, 2017 Posted January 30, 2017 Yeah i was but im thinking there might be some new policies that might help.
Sheridan Posted January 30, 2017 Author Posted January 30, 2017 Yeah i was but im thinking there might be some new policies that might help. That's what's seriously lacking with W10, a decent set of policies! There's naff all for Edge and loads of areas that seem to be missed. I guess home users don't need policies so MS won't invest too much time creating them.
timbo343 Posted January 31, 2017 Posted January 31, 2017 Have you got "specify startup policy processing wait time & Specify worlplace connectivity wait time for policy processing enabled under Computer config > System > group policy. I've set these 2 to 60 seconds each.
mrwoberts Posted February 5, 2017 Posted February 5, 2017 Just interested to hear if this problem has now been solved by the various suggestions in this thread?
Sheridan Posted February 17, 2017 Author Posted February 17, 2017 I'm still having issues. Problem seems to be the network isn't ready in time despite all the policy settings set to wait for network.
ITGent Posted May 17, 2017 Posted May 17, 2017 Did you ever found a solution for this? We have the same issue on W10. We also have the impression that the network isn't ready and the gpo does not always work.
psydii Posted May 19, 2017 Posted May 19, 2017 Have you checked that your pc connected switch ports are set to portfast or admin edge?
Chuckster Posted June 22, 2018 Posted June 22, 2018 I'm experiencing these issues on our Windows 10 machines irrespective of make and model. Was this ever resolved?
Farloch Posted June 22, 2018 Posted June 22, 2018 We have had similar issues with group policy and scripts just going through the motions but not actually doing anything. It only seems to happen on our windows 10 machines and all the windows 7 machines work fine. After much weeping and gnashing of teeth I discovered that the machines when powered down were only going into a low power state thanks to the fastboot feature (apparently introduced in windows 8). I'd already set the group policy to wait for network but this alone didn't fix the problem until I disabled hibernation (powercfg -h off) which so far seems to have nailed it.
Chuckster Posted June 22, 2018 Posted June 22, 2018 I have hibernation disabled, ever since from the days of XP. Current W10 machines do not have it enabled.
Wired_Inside_90 Posted May 1, 2019 Posted May 1, 2019 Have you looked at https://blogs.technet.microsoft.com/leesteve/2017/08/09/demystifying-the-unc-hardening-dilemma/. We had a lot of GPO errors has clients couldn't connect to where the policies get stored. I have this script as well - might need to test as I haven't used it in a while @echo offreg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkProvider\HardenedPaths /v \\domain.local\\SYSVOL /t REG_SZ /d RequireMutualAuthentication=0,RequireIntegrity=0,RequirePrivacy=0 /freg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkProvider\HardenedPaths /v \\domain.local\\NETLOGON /t REG_SZ /d RequireMutualAuthentication=0,RequireIntegrity=0,RequirePrivacy=0 /fexit you can check event viewer for a 1058 error i think.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now