Jump to content

Recommended Posts

Posted

Hullo,

 

As we evaluate our image (again), I'm interested to know what people image. We have several GPO based MSI installations that I could use but I wonder sometimes whether I am better imaging them.

 

When I build my base image I put on the following:

 

Adobe Flash Player

Adobe Air

Adobe Authorware player

ShockWave Player

Reader 9 + Updates

 

There is other stuff that could be sent out via GPO.

 

Adobe CS3 is put on the image due to it being a git to install via GPO.

 

But what about things like Office - we have 2003. It is ready to be deployed via GPO and when we were RIS based this is how it went on. However am I better putting it on the image? Will I be able to update it with Office 2007 over Easter without any issues?

 

So just let me know what you guys put in your images. Everyone? Some things or nothing if it has an MSI.

 

Cheers

 

Gareth

Posted

I dont install anything on our image

 

All software gets deployed with Group Policy

 

Best to do that, has if the program gets updated, you can remotely uninstall the old version and install the new one

 

Only thing I do with our image, is install the the update including netframework, directx, IE8, WMP11, all the updates that are out

 

Well thats for our domain image

 

 

I also make an workgroup image thats for staff laptops, I include on that everything

 

all updates, Flash, Shockwave, Java, Office 2007 With All Updates, VLC (XP Only) Foxit Reader, maybe a few others, cant think of any more at the moment

  • Thanks 1
Posted
So just let me know what you guys put in your images.

 

My baseline for XP is all the latest MS updates to anything that was already in the OS, plus a few bits I think should have been in the OS. New IE, WMP, latest-greatest post-SP3 hotfixes, GPP CSEs, csccmd and so on. I also add the dotNets. I'm reasonably confident I will never need to remove any of this stuff and if there are new versions and updates to any of it the MS install logic will just sort it out.

 

Everything else that I may want to remove at some point in future is put on later (via deployment stuff that can handle EXE installers - if I can preserve the original vendors installation logic by using those I'd much rather do that than turn them into MSIs).

  • Thanks 1
Posted

My student machine images are just Windows XPSP2 off the disk. No other software, no windows updates or nothing.

 

Software is deployed though Msi's...all of it, including stuff like VLC, VNC, Flash/Shockwave Player, Acrobat etc

 

All updates done through WSUS

 

:)

 

Works a treat, but was a long slog to get setup

  • Thanks 1
Posted

Personally I get as much as I can on new images. Primarily the OS with the latest Service Pack and Security Updates, latest drivers and as many applications possible.

 

I then just worry about future Security Updates which are handled by WSUS and other updates such as Adobe Reader 9.3.0 I deploy using an MSI. It also keeps traffic down to a minimum.

 

When installing Office 2007 the default behaviour is to uninstall the older (if any) Office software, however I have seen on these very forums admins upgrading from Office 2003 + Office 2007 Compatibility Pack to Office 2007 and experiencing problems. I would recommend you create an admin installation point, as this allows you to tweak specific settings and include updates.

 

I would also say with the 'popularity' of wireless, deploying applications just doesn't work very well and brings everything to a crawl.

  • Thanks 2
Posted

Images contain:

 

Windows, Patches to the build date

Some local policy settings

Office 2007

Open Office

CS4 (Inc Acrobat)

Flash

Shockwave

Java

Quicktime

Kaspersky (not management agent as it generates a unique ID and deploys fine with AD)

VLC

Audacity

 

 

Other apps are made available with App-V, virtually nothing is AD now as it's just not reliable enough when using 802.1x, although this may no longer be the case with Vista/7).

 

I was quite conservative with our Vista roll out as I'd been burnt badly the previous year using the GPOs for Java, Quicktime, Flash, Adobe Reader and shockwave. The would usually install but not always work correctly (some users had PDFs associated, others didn't even though they were the same mandatory profile.

 

 

CS4 is certainly one to build into the image as it has a number of tweaks and changes to stop various updaters and things from running.

  • Thanks 1
Posted

Thanks guys for all the posts. I think I'll stick with the original list and when I sit down and teach myself Advanced Installer - which I have purchased - I will move to transform .exe files into msi format.

 

I think then the plan will be to create one image every year.

 

Cheers everyone,

 

Gareth

Posted

Our XP image contains nothing except being patched up to date the FOG client. Apps are installed by GPO which isn't great, hence I am about to evaluate SCCM which should prove more flexible (or all sorts of reasons)

 

What about things with no MSI?

I make my own msi with WinInstall LE and Orca.

 

Personally I like to separate the images and software, I just like to have more control, by GPO, of what's out there.

 

Realistically though you have to pay somewhere and its either larger images that take longer to deploy or smaller quicker images followed by network traffic and time to install apps.

  • Thanks 1
Posted

Just to add - I've been happy enough using the (free, easy) "Windows Installer Wrapper Wizard" to bundle CMDs, EXEs and a mix of them into MSIs. [Would link to it but the site doesn't work].

 

Not sure what they use but some vendor MSIs are like that, for instance the corporate Flash MSI is wrapper around an EXE installer.

  • Thanks 1
Posted
Also, lots of exes extract an msi to a temp location that you can pick up and use. If I remember JRE and Quicktime do this (among others I can't remember now).
  • Thanks 1
Posted
Also, lots of exes extract an msi to a temp location that you can pick up and use. If I remember JRE and Quicktime do this (among others I can't remember now).

 

yup both of them are exe wrappers for msi

 

i tend to use msi where possible (usually only if it deploys vanilla or like office 03 / smart 10 has a management tool or like java is simple enough to use orca on. Next preference is scripted install usually a quick batch file that goes does file x exist if not run installer. followed by ghost packages again where possible script installed (lea router tends to kill the net as it perceives ghost as a broadcast storm if i fire out from the console whatever options ive tried and they wont changer the config) then manual install (usually create a quick user with a logon script that runs the setup (rm maths springs to mind pos software). My base images ghost or wds (i use both but atm mainly ghost as im used to it supose i ought to get used to wds more esp with win 7 but the one school i have atm with win 7 laptops the server keels over if i apply sp2 so thats a no go) are windows updates and usually msn exploder and outlook express removed as on a domain they are useless(what does msn explorer do anyway?). I only install software in a base image as a last resort

  • Thanks 1
Posted

Thanks for the link.

 

The good news is we purchased Advanced Installer today so I was able to repackage quite easily with the Pro version.

 

I've now got the apps I need done. Excellent application.

 

Gareth

Posted

We put everything in the image - i dont see the point in deploying stuff via group policy as this majorly increases the time it takes for one of our technicians to reimage a machine - first they would have to reimage, second join to ad, place in correct ou, and then wait for the machine to pickup the policy and install the software.

 

If everything is already on the image just a case of reimaging joining to ad and away you go...

Posted
We put everything in the image - i dont see the point in deploying stuff via group policy as this majorly increases the time it takes for one of our technicians to reimage a machine

I used to think like that but I must admit I am now a convert to GPO software deployment. Rather than having 10's of different images with different software combinations for different models in different department I know have 1 base image of each model.

It's now much easier for me to redeploy a model to a different department, control which departments get which software and manage software upgrades beyond the lifespan of the images.

Posted
We put everything in the image - i dont see the point in deploying stuff via group policy as this majorly increases the time it takes for one of our technicians to reimage a machine - first they would have to reimage, second join to ad, place in correct ou, and then wait for the machine to pickup the policy and install the software.

 

Depends on what imaging process you are using, SCCM/WDS/WDT and FOG can easily be set to join the domain during imaging and prestaging can put the machine in the correct OU, set policies and install software, then there is no need to do all this manually.

Posted
We put everything in the image - i dont see the point in deploying stuff via group policy as this majorly increases the time it takes for one of our technicians to reimage a machine - first they would have to reimage, second join to ad, place in correct ou, and then wait for the machine to pickup the policy and install the software.

 

If everything is already on the image just a case of reimaging joining to ad and away you go...

And keeping the software up to date? Deploying over GPO allows easy uninstall of old versions and installation of new versions should a patch come out, like say Adobe Reader 9.3.

 

I have the GPO at the top level of my OU and then specify which software gets installed to which computer by hostname. Then following a re-image or machine replacement, the user gets the software they need.

Using Group Policy to deploy software to select computers - 404 Tech Support

  • Thanks 1
Posted

Well what we have decided is to get the main OS installed and patched.

 

The software which cannot be installed via GPO will be going on. Creative Suite CS3 is going on because... it just is - it takes ages to install of a network drive later.

 

Sibelius 5 and it's associated programs are going on due to there being a problem with the msi. They know about it, but I cannot be bothered to chase it up.

 

Everything else is msi'ed up.

 

Now I am trying the image. Having problems with my sysprep file at the moment and with the image not restarting into the domain. It joins but doesn't put up the logon screen unless I manually restart it.

 

Weird - time to read the WDS thread.

 

Gareth

Posted

In honesty I think you should stick with what you're already doing more or less.

 

If something is a real nuisance to install across a network via GPO (or has no silent switch for the exe) stick it on the image and hope the app doesn't have frequent updates.

 

If something is updated often and works via GPO then do it that way.

 

I'd also say decide on what to include App by App. It might seem a bit strange but try to look at it from the point of view of what the software needs or can / can't do rather than from the "I'm a techie it's easiest to do this" point of view. Start by listing your apps and whether they do or don't install via GPO, can they be installed silently, what are they like to update, where are they needed. Then use this list to work out what goes on the image and what gets deployed.

  • Thanks 1
Posted
And keeping the software up to date? Deploying over GPO allows easy uninstall of old versions and installation of new versions should a patch come out, like say Adobe Reader 9.3.

 

I have the GPO at the top level of my OU and then specify which software gets installed to which computer by hostname. Then following a re-image or machine replacement, the user gets the software they need.

Using Group Policy to deploy software to select computers - 404 Tech Support

 

The problem is when the software doesn't just deploy from group policy. The things I really want to keep up to date just don't deploy properly from their distributable msi files. Quicktime, Flash and Acrobat are often unpredictable even on identical machines. If I could trust them to just work then I would!

 

I do have other applications that work perfectly from MSI, and upgrade/remote etc fine.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...