Jump to content

computer_expert

Members
  • Posts

    1,188
  • Joined

  • Last visited

Everything posted by computer_expert

  1. If you use WSUS don't forget that you'll also need to add/synchronize the new Windows 10 1903 product otherwise you will not get updates for anything newer than 1809
  2. Here is what I have set in GPO: Configure automatic updating: [b]4 - Auto download and schedule the install[/b] The following settings are only required and applicable if 4 is selected. Install during automatic maintenance [b]Enabled [/b] Scheduled install day: [b]0 - Every day[/b] Scheduled install time: [b]18:00[/b] If you have selected “4 – Auto download and schedule the install” for your scheduled install day and specified a schedule, you also have the option to limit updating to a weekly, bi-weekly or monthly occurrence, using the options below: Every week [b]Enabled [/b] First week of the month [b]Disabled [/b] Second week of the month [b]Disabled [/b] Third week of the month [b]Disabled [/b] Fourth week of the month [b]Disabled [/b] Install updates for other Microsoft products [b]Enabled [/b] Specify deadline before auto-restart for update installation [b]Enabled[/b] Specify the number of days before a pending restart will automatically be executed outside of active hours: Quality Updates (days): 7 Feature Updates (days): Specify the max active hours range: Max range: set your desired value the following settings are enabled: Update Power Policy for Cart Restarts Allow non-administrators to receive update notifications Hope this helps! edit - and the usual stuff pointing the clients towards my WSUS server too.
  3. I'll get the settings for you on monday but from what I remember I am using option 4 for scheduling. I made sure to log out and leave it on the login screen.
  4. I've only done this on one box (mine!) but I approved the 1903 update in the afternoon and it had installed by the next morning without any manual intervention. The only difference is that I have active hours set in GP.
  5. Sounds rather like the issue with one of the windows updates a few months ago described here: http://www.edugeek.net/forums/windows-server-2016/204987-cumulative-update-s-break-windows-deployment-services.html If not have you tried regenerating boot.wim from scratch in MDT? (Second option when you update the deployment share and dont forget to use the new image in WDS)
  6. Add the following in customsettings.ini (or database if you use that feature): DomainOU="OU=Site 1,OU=Computers,DC=contoso,DC=corp,DC=com" You can also enable advanced features in active directory users/computers then right click the OU, click the attribute editor tab and copy/paste the value of distinguishedName into the above.
  7. Get the same on my 1903 build (upgraded from 1809 via WSUS) although I can't remember if I enabled server manager via RSAT...
  8. I've never had much luck with reverse proxies & remote desktop gateway/services unless you use the Web App Proxy roles built in to windows server.
  9. We switched from crashplan (resold via ceejay) to backup intellegence when crashplan pulled the plug on server backups. The client is much better than the java rubbish that crashplan used. I only use it to take file backups on our 2 file servers and it works well for this purpose but I think i remember seeing that it can do MSSQL backups (as well as other things) too
  10. Once you have uninstalled the old and installed the new ADK you will need to update the boot images in MDT (I'd fully regenerate the images, it's the second option of the two you get when updating it) and load the new boot images into WDS.
  11. The installed ADK should match the newest version of Win10 that you are deploying. Don't forget that you will need both parts of the ADK installed as they split it into 2 with one of the recent releases (1709 or 1803).
  12. xx09 releases have 30 months support whereas xx03 releases only have 18 months. I rip the unwanted stuff out using OSDBuilder then add the OSDBuilder modified ISO on MDT for deployment to computers.
  13. Try unticking 'Move the contents of start menu to new location' box. This setting along with the read only share permissions will prevent the shortcuts from being copied to the new location and may be the cause of your issue.
  14. I'm doing this from memory so some things may be a little vague... Log on as a test user, let the redirection apply, then log on with an admin account and look for events with folder redirection as the source in the application event log (I'd give you event IDs but I can't remember what they are!). Might be worth checking share permissions (not NTFS permissions) too?
  15. run gpresult /h c:\report.html /target:computer from a client and this report should tell you which policy is blocking packaged apps in applocker.
  16. There are a few things to try here: http://www.edugeek.net/forums/windows-server-2016/204987-cumulative-update-s-break-windows-deployment-services.html
  17. Onboard video anyone?
  18. It sounds to me like it may be having trouble trying to locate the xml file - what is your run command in the MDT application? You may have better luck with using powershell ADT: https://psappdeploytoolkit.com/ I've used it successfully with MDT with a few stubborn programs as it gives much better logs than MDT ever does (make sure you use CMtrace to view the log files generated by ADT though!).
  19. and you don't have to wait weeks for it to install windows updates either (...well, not yet. Give it a few years and it will probably end up like 2016)
  20. Don't use the domain admin account for joining computers to the domain. Use an account with delegated permissions to the OU(s) where your clients end up. https://wibier.me/domain-join-account-for-sccm-and-mdt/ Also create a dedicated build account with access to the deployment share (file & share permissions)
  21. The older Sophos UTM (and also pfSense) does work in a double NAT configuration as I used it like this at one point. Set the plusnet router up in router mode (not bridge/passthrough), then set the WAN interface on the sophos box to DHCP (to grab an address from the plusnet router). Use a separate ip range for the sophos LAN interface. For example in gateway mode: plusnet router - 192.168.1.254/24 \/ ethernet cable \/ Sophos WAN - gets an IP from the 192.168.1.0/24 range Sophos LAN - 192.168.50.254 \/ ethernet cable to switch \/ Clients in the Sophos LAN - something from the 192.168.50.0/24 range via DHCP from the sophos box This should get you started. Once you feel confident I'd move sophos onto it's own box and look at either putting the plusnet into modem only mode or ditching it completely. Also be aware that if you take the ESXi host offline (e.g. patching/rebooting) you will lose all internet connectivity. For this reason I'd suggest putting it on it's own dedicated box. edit - for the sophos setup, connect the machine you are using to the sophos LAN port rather than trying to do it over the WAN port
  22. Walled garden can drill down to hostname but not URLs: https://documentation.meraki.com/zGeneral_Administration/Cross-Platform_Content/Walled_Garden
  23. Server 2019 has a full GUI, the YYMM versions (like 1803/1809) are server core only. For some roles (RDS for one, possibly NPS too if they haven't got around to sorting that yet) need a GUI.
  24. And the blog article has disappeared (it was there earlier!)...
  25. Is it server essentials? If it is, does it hold all of the FSMO foles? https://www.dell.com/support/article/uk/en/ukdhs1/sln288459/can-additional-domain-controllers-coexist-with-windows-small-business-server-or-windows-server-essentials- I seem to remember that older windows versions shut down if you overrun the trial period too (check to see if your server has properly activated), but not sure if this still exists in 2012 or later.
×
×
  • Create New...