Jump to content

Recommended Posts

Posted
The messaging I am seeing is that they've basically given up on the set of technologies that were once back in 1998 branded as "IntelliMirror". Enterprise can stick happily with Windows 7 and Group Policy until such time as cloud management and services can offer capabilities that meet business requirements.

 

Don't forget that many of us are trying to make the new stuff do things the old way, whereas in reality we need to step back, learn about the cloud management and storage and figure out how to make that work for our organisations. If we try to re-implement the old way using the new tools we are fighting against the tech and we will find it will never work. Nobody is trying to make Andriod or IOS or Chromebooks work like a Unix networked workstation, and they work (within their context) very well. We need to stop trying to make Windows 10 behave like Windows 2000/XP, and figure out the new right way of doing things that will work for the next 10-15 years.

 

https://books.google.co.uk/books?id=vTsEAAAAMBAJ&pg=PA14&lpg=PA14&dq=Intellimirror+1998&source=bl&ots=XUS2od4UVt&sig=wP-gNosFWp512AyKcjfqFTSes9U&hl=en&sa=X&ved=0ahUKEwj1soOard3RAhVkC8AKHSkWB1AQ6AEILTAD#v=onepage&q=Intellimirror%201998&f=false

 

https://news.microsoft.com/1998/08/18/microsoft-delivers-windows-nt-5-0-beta-2-to-more-than-250000-testers/#sm.001ga051w17ones4u1s145vtwgg5m

 

https://technet.microsoft.com/en-us/library/hh848267(v=ws.11).aspx

 

https://technet.microsoft.com/en-gb/itpro/windows/manage/index

From what im seeing, win10 is designed as a 1:1 OS meaning everyone needs a device, something we just cant afford.

  • Thanks 1
Posted
The messaging I am seeing is that they've basically given up on the set of technologies that were once back in 1998 branded as "IntelliMirror". Enterprise can stick happily with Windows 7 and Group Policy until such time as cloud management and services can offer capabilities that meet business requirements.

 

Don't forget that many of us are trying to make the new stuff do things the old way, whereas in reality we need to step back, learn about the cloud management and storage and figure out how to make that work for our organisations. If we try to re-implement the old way using the new tools we are fighting against the tech and we will find it will never work. Nobody is trying to make Andriod or IOS or Chromebooks work like a Unix networked workstation, and they work (within their context) very well. We need to stop trying to make Windows 10 behave like Windows 2000/XP, and figure out the new right way of doing things that will work for the next 10-15 years.

 

Surely W7 is likely to be EOL before then? I agree that the way to make W10 work is the "MS way" (once they work out what that is) but most schools (heck, most businesses) can't (at least in the short to medium term) afford to change their infrastructure to do that.

Posted

Everything is heading towards 1:1 - the mass panic to buy ipads for schools showed that they don't work very well unless they're 1:1 (G Suite Apps aren't multi user on these sort of things)

 

I agree we need to adopt new ways and we are doing that, but the old ways are still in use in massive amounts of examples.

 

I may be old school, but when it comes to any prolonged amount of typing/browsing I still always revert to laptop/desktop.

 

Again its an example where MS could have offered W10 Home/Tablet Edition and W10 Business Edition, they are distinct areas of use and W10 could have worked well if adjusted to suit the environment.

Posted
IIRC I have set these services to automatic - they were manual...

 

REM Netman (Network Connections)
sc config Netman start= auto

REM Network List Service
sc config netprofm start= auto

 

Ive had some real fun and games with the netprofm service over the last 24 hours and today ive been at BETT. Basically, a school boy error on my part, i used Group Polciy to set the service to automatic and started but i changed the log on credentials to Logon with the system account and majorly knacked things up so for the last 24 hours ive been trying to find out what the problem was and trying to find the best way to fix it. By disabling the service it causes the windows fireware to enter the guest/public profile therefore things dont work correctly. I wont be making this mistake again.

 

After trying to find out on the train this morning on a poor 3g connection, wandering round BETT and having breaks to try to get a solution to this, at 4pm we decided to sit down and look for a solution. Working on each machine remotely at BETT we found the problem. Got a script together of sc config "netprofm" obj= "nt authority\localservice" password="" things started to work but we had to check each amd every machine via ping to see if we got a response. Some machines would apply the fix so we had to go in manually to each machine, go to services and remove the "password" from the logon account. We only just managed to get the majority done when we pulled up at our home station at 10.30pm.

Posted

:eek:

Sorry to hear of that trouble; I was hesitant about suggesting those changes. Apologies if I caused you a bit of a headache there.

Once those changes have been applied, I'd be interested to know if they resolve the original problem of 'logon server not found'.

Have a good day - I'm off to BETT :doh:

Posted
:eek:

Sorry to hear of that trouble; I was hesitant about suggesting those changes. Apologies if I caused you a bit of a headache there.

Once those changes have been applied, I'd be interested to know if they resolve the original problem of 'logon server not found'.

Have a good day - I'm off to BETT :doh:

Dont worry, hopefully others wont make the mistake now.

 

Have fun at bett, i didnt enjoy as muxh as last year.

Posted

Right, going back to the group policy not applying, someone on spiceworks has mentioned the wait for network policy. I only came about this as i was looking into an error.

 

Gentlemen the answer to your questions is to disable group policy optimization. Do this in your GPO. You can change the default setting by using the Group Policy MMC snap-in. This feature is enabled by default, but you can disable it by using the following policy: Administrative Templates\System\Logon\Always wait for the network at computer startup and logon.

 

The reason this issue comes up is that 2008 Active Directory by default is set to use fast login, which means it doesn't wait for the network to process GPO's, therefore user settings can get bypassed. Disable optimization in your GPO's and your issue will be resolved.

  • Thanks 1
Posted
Right, going back to the group policy not applying, someone on spiceworks has mentioned the wait for network policy. I only came about this as i was looking into an error.

 

Hmm I already have this policy enabled so therefore GPO optimisation is already disabled on my w10 pcs

Posted
Ah! Have you got the new group policies that were released. Ive installed them but not looked through them.

 

TBH I'm sure that policy setting was there with Windows 7? I seem to remember setting it a long time ago!

Posted
Yeah i was but im thinking there might be some new policies that might help.

 

That's what's seriously lacking with W10, a decent set of policies! There's naff all for Edge and loads of areas that seem to be missed. I guess home users don't need policies so MS won't invest too much time creating them.

Posted

Have you got "specify startup policy processing wait time & Specify worlplace connectivity wait time for policy processing enabled under Computer config > System > group policy.

 

I've set these 2 to 60 seconds each.

  • 2 weeks later...
  • 2 months later...
Posted

Did you ever found a solution for this? We have the same issue on W10.

We also have the impression that the network isn't ready and the gpo does not always work.

  • 1 year later...
Posted
We have had similar issues with group policy and scripts just going through the motions but not actually doing anything. It only seems to happen on our windows 10 machines and all the windows 7 machines work fine. After much weeping and gnashing of teeth I discovered that the machines when powered down were only going into a low power state thanks to the fastboot feature (apparently introduced in windows 8). I'd already set the group policy to wait for network but this alone didn't fix the problem until I disabled hibernation (powercfg -h off) which so far seems to have nailed it.
  • 10 months later...
Posted

Have you looked at https://blogs.technet.microsoft.com/leesteve/2017/08/09/demystifying-the-unc-hardening-dilemma/. We had a lot of GPO errors has clients couldn't connect to where the policies get stored.

 

I have this script as well - might need to test as I haven't used it in a while

@echo offreg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkProvider\HardenedPaths /v \\domain.local\\SYSVOL /t REG_SZ /d RequireMutualAuthentication=0,RequireIntegrity=0,RequirePrivacy=0 /freg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkProvider\HardenedPaths /v \\domain.local\\NETLOGON /t REG_SZ /d RequireMutualAuthentication=0,RequireIntegrity=0,RequirePrivacy=0 /fexit

 

you can check event viewer for a 1058 error i think.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...