Jump to content

Recommended Posts

Posted (edited)

I'm trying to get my head around this:

 

Over summer we rolled out a new Windows build via Deployment Services. I built it myself. Fairly standard build of getting the latest Edu Win 10 version, installing fresh, updating it, and dropping a minimal set of essential programs onto it (Office, 7zip, A PDF reader..).

 

I didn't mess with the settings at all, preferring to do that through GPOs.

 

Since then we've started using Zoom, and every time we install Zoom we're getting errors that TLS isn't enabled. It's obviously a dead easy fix (Go to IE, Advanced Settings, tick TLS 1.2, done).

 

But all the reading I'm doing suggests that TLS 1.2 should be enabled by default on all OS's since Windows 8.

 

My first thought was a rogue GPO, but there's nothing showing in the gpresults output that would affect this.

 

Any ideas why this might be disabled (seemingly on a per user basis - the option is not locked, but it's becoming a headache having to change it each time a new user logs in) and the outdated SSL options are still ticked?

Edited by Cazale
Posted

This article suggests TLS 1.2 is enabled (as I'd expect).

 

I'd suggest installing a new non-domain attached install to observe settings, then manually join the domain. By default it'll be in 'Computers', but then you can move it to another OU and observe whether it is GPOs which are (for whatever reason) disabling TLS 1.2.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...