Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi all,

 

Sorry for another RM CC4 removal thread, but I have a few questions which I'm struggling to answer...

 

I ideally want to be able to roll out a new vanilla network to a single IT classroom while keeping the rest of the school running CC4, just so we can do some further testing with the students before we reimage every PC in school.

Is there any reason this won't work if I use WMI filtering so new vanilla user policies only apply to vanilla PCs, and I create a policy to disable CC4 roaming profiles on the vanilla PCs?

(CC4 currently uses roaming profiles but we want to move to local profiles)

 

 

Can CC4 DCs and Vanilla DCs coexist?

During the transition period, can CC4 DCs and Vanilla DCs run alongside each other?

RM say they can make it work (https://help.rm.com/TechnicalArticle.asp?cref=TEC1713624) but their tech support has told me "we believe it may lead to unexpected issues with CC4 environment"

 

 

I've read through the other RM CC4 removal threads, but if anyone can offer any further advice it would be much appreciated.

 

Thanks,

Posted
You could create a new OU structure for your vanilla network (which is what we did for our move from CC3), and in GPMC set that OU to block inheritance of GPO's from other locations and then just create the GPO's you want and assign to them that OU structure.
Posted
You could create a new OU structure for your vanilla network (which is what we did for our move from CC3), and in GPMC set that OU to block inheritance of GPO's from other locations and then just create the GPO's you want and assign to them that OU structure.

 

That’s exactly what I was going to do for the computers, but it’s the users/user policies that are more challenging as I might have users moving between RM and Non-RM PCs

Posted

Thats not a problem, since the user policy is applied based on the OU the workstations are in if it is still the same as the CC3 days.

 

If you block inheritance for your new OU, you can set it so all stations within that folder use local policy and not roaming by setting the local loopback for the station.

We did that for years while running vanilla and CC3 stations

  • Thanks 1
Posted

If nothing else, you can change the permissions on the RM GPOs so that they don't apply to particular PCs or a group. There are ways around it.

 

The important thing to remember, as much as RM like to obfuscate it, a CC4 domain is still just a bog standard AD domain with some extra software installed. Sure, there are some custom schema extensions that they put in there but there's still nothing inherently special about them. You don't need to add extra DCs to your network until you're ready to remove the RM CC4 site servers. There is absolutely no reason why you can't add some PCs which don't have the RM middleware layer on them to that domain and manage them in the non-RM way.

  • Thanks 3

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...