Liam Posted March 23, 2018 Author Posted March 23, 2018 I bet I bloody am! I enforced a crypto setting in fsrm
mdrabble Posted March 24, 2018 Posted March 24, 2018 Interesting about blocking the desktop.ini with FSRM - ive turned it off and hope this will see an improvement.
mavhc Posted March 24, 2018 Posted March 24, 2018 I had a black screen for 5 mins or more, turned out to be impero's fault, sigh, they really need an auto list of injection exceptions But mostly turn on logging 1
free780 Posted March 26, 2018 Posted March 26, 2018 NetsupportImpero really causes more issues than it solves. Corrupting GPOs. Putting PCs to sleep when SCCM is doing something oran admin is RDP/Powershell'd in. It does feel like a rootkit or malware. 1
mavhc Posted March 27, 2018 Posted March 27, 2018 Impero really causes more issues than it solves. Corrupting GPOs. Putting PCs to sleep when SCCM is doing something oran admin is RDP/Powershell'd in. It does feel like a rootkit or malware. Never noticed it corrupting GPOs, and I've not used the sleep actions, so it's never put PCs to sleep.
Mic_Impero Posted March 27, 2018 Posted March 27, 2018 Hi there, We have a built in list of injection exclusions and review it as appropriate for each release. Apologies if something not in that list previously cause you a login delay. @free780 if we can assist with those issues please PM me and we'll be in touch ASAP; Impero will shut down a computer on a schedule and I can understand the issue around a SCCM / background tasks, but I'd like to look at that further with you. Impero certainly shouldn't be 'corrupting' any GPOs as it doesn't do anything with GPOs; the closest I can think of is if you have a GPO set to deploy something (for example) and Impero blocks it due to an application block kicking in, but otherwise it wouldn't be involved with GPO; we'd like to understand that further too. Thanks Mic Head of Support Impero
mavhc Posted March 28, 2018 Posted March 28, 2018 Hi there, We have a built in list of injection exclusions and review it as appropriate for each release. Should this list be auto updating then? It never has for me afaik.
Liam Posted March 29, 2018 Author Posted March 29, 2018 I’m still struggling with folder redirection. I’m thinking it’s permissions. I have checked fsrm
free780 Posted March 29, 2018 Posted March 29, 2018 (edited) Came across this today. https://social.technet.microsoft.com/Forums/windowsserver/en-US/3fdfa58b-fe1b-4546-85d2-d43dac9bcc10/black-screen-on-all-new-connections-sessionhost-has-to-be-rebooted-error-1534?forum=winserverTS Even though its to do with Server 2016. The per user firewall rules get created on Win 10 1709. I did some testing with a non-merged firewall policy and clearing out the firewall entries via a Scheduled Task. Seems to improve 1st login speeds. Edited March 29, 2018 by free780
Liam Posted May 17, 2018 Author Posted May 17, 2018 Ok since i last posted i have been working on this.. I have now build and deployed 1803 with apps removed from the .wim Re done group policy and brought all redirection local login on wifi is now 6 seconds! Hope this can help someone. 1
free780 Posted May 17, 2018 Posted May 17, 2018 I've automated deleting per user firewall rules and first login is 37secs (i3 SSD). Also have a firewall policy with nomerge which seems to speed it up.
free780 Posted May 17, 2018 Posted May 17, 2018 Win10/Server 2016 creates inbound and outbound rules per user per modern app that is provisioned.
smithson83 Posted May 17, 2018 Posted May 17, 2018 I've automated deleting per user firewall rules and first login is 37secs (i3 SSD). Also have a firewall policy with nomerge which seems to speed it up. Colour me intrigued...
free780 Posted May 18, 2018 Posted May 18, 2018 Modern apps create a per user, per app firewall rule. After a while on a shared PC there can be quite a lot. I cant see why modern apps need inbound or outbound rules #MSlogic. Create a new GPO. Turn off local merge on all scopes for the Firewall. On a Win10 PC with no GPO applied capture the default policy and export then import into the GPO. Keep the defaults on Inbound Block unless allowed. Leave Outbound not to block. You may want to allow ping file sharing etc. Go through your applications that may need rules. Impero,ABTutor,Exams Software,Skype for Business etc. Some will try and put in a firewall rule. You can copy these blocked rules and import into your policy. Create scheduled task On user logon Runas :NT AUTHORITY\System powershell.exe Remove-NetFirewallRule Any new software that requires inbound rules will need to be in the policy. Obviously test this before putting into production. Be aware theat if you supress Windows Firewall warig the user that its blocked something you may not find out if something is working or not.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now