Jump to content

sch

Members
  • Posts

    24
  • Joined

  • Last visited

Everything posted by sch

  1. It seems like Microsoft still hasn't made any real improvements to the customizations for the start menu and taskbar through GPO. In our case, we are currently configuring our first customer with 2012 terminal servers. And like most sysadmins, we do not want the regular user on the terminal server to be able to even see the icons for powershell, server manager or administrative tools on their start menu or taskbar. Not that they are able to run those programs, but knowing from experience, "dumb" users will eventually click on anything they see is available on their menus. And when those programs generates the "access denied" error message, our phones are glowing in the matter of minutes. So! With the help of some heavy googlin' and lots of error and trial, i finally got what i wanted to work. So here is a guide which will provide you with the right GPO settings to clear the start menu of server manager, task manager and powershell. It will also clear the taskbar for server manager and powershell, but leave the file explorer and still let the users pin the programs they want to the taskbar. 1. User Configuration\Policies\Administrative Templates\Start Menu and Taskbar 2. Computer Configuration\Preferences\Windows Settings\Files 3. User Configuration\Preferences\Windows Settings\Files 4. User Configuration\Preferences\Windows Settings\Registry - HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband (set to delete and apply once and do not reapply) - Create the following new registry items: [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband] "FavoritesResolve"=hex:98,02,00,00,4c,00,00,00,01,14,02,00,00,00,00,00,c0,00,00,00,00,00,00,46,83,00,80,00,20,00,00,00,4e,95,54,7a,4b,bf,cd,01,4e,95,54,7a,4b,bf,cd,01,36,42,94,a5,a4,6a,cd,01,97,01,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,3e,01,14,00,1f,80,c8,27,34,1f,10,5c,10,42,aa,03,2e,e4,52,87,d6,68,52,00,31,00,00,00,00,00,6a,41,52,6f,11,00,54,61,73,6b,42,61,72,00,3c,00,08,00,04,00,ef,be,6a,41,52,6f,6a,41,52,6f,2a,00,00,00,46,3d,01,00,00,00,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,54,00,61,00,73,00,6b,00,42,00,61,00,72,00,00,00,16,00,d6,00,32,00,97,01,00,00,f9,40,17,a4,20,00,46,49,4c,45,45,58,7e,31,2e,4c,4e,4b,00,00,78,00,08,00,04,00,ef,be,6a,41,52,6f,6a,41,52,6f,2a,00,00,00,4a,3d,01,00,00,00,04,00,00,00,00,00,00,00,00,00,4e,00,00,00,00,00,46,00,69,00,6c,00,65,00,20,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,40,00,73,00,68,00,65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,32,00,32,00,30,00,36,00,37,00,00,00,1c,00,42,02,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,2e,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,00,00,1c,00,00,00,a8,00,00,00,1c,00,00,00,01,00,00,00,1c,00,00,00,2d,00,00,00,00,00,00,00,a7,00,00,00,11,00,00,00,03,00,00,00,02,a6,df,3a,10,00,00,00,00,43,3a,5c,55,73,65,72,73,5c,61,64,6d,69,6e,69,73,74,72,61,74,6f,72,2e,53,4d,42,5c,41,70,70,44,61,74,61,5c,52,6f,61,6d,69,6e,67,5c,4d,69,63,72,6f,73,6f,66,74,5c,49,6e,74,65,72,6e,65,74,20,45,78,70,6c,6f,72,65,72,5c,51,75,69,63,6b,20,4c,61,75,6e,63,68,5c,55,73,65,72,20,50,69,6e,6e,65,64,5c,54,61,73,6b,42,61,72,5c,46,69,6c,65,20,45,78,70,6c,6f,72,65,72,2e,6c,6e,6b,00,00,60,00,00,00,03,00,00,a0,58,00,00,00,00,00,00,00,69,6e,76,65,6e,74,75,6d,30,32,00,00,00,00,00,00,a6,58,be,d3,b6,46,ed,42,8f,a3,d3,93,8e,1d,5d,8c,95,9e,41,73,c0,2a,e2,11,93,f3,00,50,56,90,4c,60,a6,58,be,d3,b6,46,ed,42,8f,a3,d3,93,8e,1d,5d,8c,95,9e,41,73,c0,2a,e2,11,93,f3,00,50,56,90,4c,60,00,00,00,00 "Favorites"=hex:00,3e,01,00,00,14,00,1f,80,c8,27,34,1f,10,5c,10,42,aa,03,2e,e4,52,87,d6,68,52,00,31,00,00,00,00,00,6a,41,52,6f,11,00,54,61,73,6b,42,61,72,00,3c,00,08,00,04,00,ef,be,6a,41,52,6f,6a,41,52,6f,2a,00,00,00,46,3d,01,00,00,00,04,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,54,00,61,00,73,00,6b,00,42,00,61,00,72,00,00,00,16,00,d6,00,32,00,97,01,00,00,f9,40,17,a4,20,00,46,49,4c,45,45,58,7e,31,2e,4c,4e,4b,00,00,78,00,08,00,04,00,ef,be,6a,41,52,6f,6a,41,52,6f,2a,00,00,00,4a,3d,01,00,00,00,04,00,00,00,00,00,00,00,00,00,4e,00,00,00,00,00,46,00,69,00,6c,00,65,00,20,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,2e,00,6c,00,6e,00,6b,00,00,00,40,00,73,00,68,00,65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,32,00,32,00,30,00,36,00,37,00,00,00,1c,00,42,00,00,00,1d,00,ef,be,02,00,4d,00,69,00,63,00,72,00,6f,00,73,00,6f,00,66,00,74,00,2e,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,2e,00,45,00,78,00,70,00,6c,00,6f,00,72,00,65,00,72,00,00,00,1c,00,00,00,ff "FavoritesChanges"=dword:0000000a "FavoritesVersion"=dword:00000002 "FavoritesRemovedChanges"=dword:00000002 Set all these registry items to ble "apply once and do not reapply" 5. One important thing to remember Depending on what language you have configured for the users you also have to take that into consideration when creating the policies for deleting the shortcuts. In my case, i also had to add the Norwegian names for Task Manager and Administrative Tools for example. Hope this was helpfull!
  2. Does anyone know of any software (third-party or not/paid/free) that provides extended logging possibilities for DFS? To be more specific i want logging for what user modifies which file on what server and at what time it happens.
  3. Yes, but as far as i understand and see, you can't create and automated restore-job in the GUI. You have to do that by script? I did come across a script of something similar after i posted this thread, so i will try it out.
  4. Hi! I am a total novice with powershell, but have been given the task by my manager to create a script wich selects the newest replica of a database in dpm, and copies the .ldf and .mdf files to an network share. I have managed to scramble the commands wich always selects the newest replica. But i can't figure out what the command to select the files within that replica, and then copy them to the network share. Furthermore, they have to overwrite existing files everytime they get copied. You can easily do this via the GUI, but the client who needs this setup wants it to be automated, as it has to be done once every 24 hours. Does anyone have a script like this lying around, or could whip something up in a jiffy?
  5. Forgot to mention that, they have fiber between the two sites. We actually have experienced the same problem in our own system. And we don't have multiple sites.
  6. We have a customer who runs their terminal servers and domain controllers on server 2008 r2. The DC's also act as fileservers. They are using DFS, wich are replicated between two sites. Now we have come across a user who has problems when copying files to a DFS share. If he uploads a file to the share, he can't open it until 5-10 minutes after the upload. If he tries to open it before, he gets an error saying the files i already in use and is write-protected. He copies the files he wants to edit to his personal folder first, then edits them, changes the filename, and then uploads the file back to the DFS share. And still he gets the same error when trying to open them after the upload. We have run into the same problem at our own enviroment, without being able to find an answer. Does anyone know about this issue?
  7. I have tried that too. But it looks like i got the export through poweshell working now. The issue was a combination of permissions on the mailbox and the folder i was exporting to. Amazing, yet embarrassing how something simple as that can be overlooked. I still bugs me that i can't get the export through the console working though, i am a big fan of simple graphical interfaces
  8. Nope! The user i am using is Administrator anyway Seriously? I didn't see anything about that when i was researching, think i have to do another round of googlin'! That does seem like a huge hassle, and way too much of a hassle for me to bother trying. Yet, i can't say that i am surprised either, it's Microsoft afterall. I have to doublecheck, but Administrator already should have full access to all mailboxes already. Thanks anyway! And yes, i agree! Powershell is there to be used
  9. I tried exporting it to the local C: drive, but i get the same 'access denied' error. I am trying with the administrator user of the domain (wich was used when installing exchange too), so the permissions should be sufficient. It is SP1, yes. But Outlook and the exchange management console is installed on a server we use as a management-server in the domain, not the exchange server itself.
  10. Yes, i can. But it shouldn't be necessary
  11. We recently upgraded from exchange 2007 to 2010 for one of our customers. But i have trouble finding out why exporting mailboxes to .pst doesn't work. We have a designated computer for this kind of operation, with outlook 2010 installed, and the exchange management console installed. In addition i have done every pre-configuration you should have to do to make it work (as far as i can tell). Running the New-MailboxExportRequest to a shared folder simply gives me the error of 'access denied'. Exchange Trusted Subsystem group also has read/write permissions on that share. In 2010, you also should get the "export mailbox" as an option when right-clicking the mailbox on a user in the management console. This option is not there either. Here are the pre-configurations i have done: Ensured that the Mailbox Import Export role is added in a group wich the user i am using is a member of. Also tried to designate this role directly to the user with the powershell command, without luck. Added Exchange Trusted Subsystem with read/write on the share to wich i want to export the mailboxes. Installed Outlook 2010 with the office tools and the exchange management console on a designated computer. The exchange organization still has a 2007 mailbox server in it though, can this have anything to do with it? If not, can anyone see what i am missing here?
  12. Before i called it today, i managed to test it on xp clients. It seemed to work, but you get prompted for a user with admin rights. I read somewhere on the MS forums that if you disable Point to Print Restrictions it will go without the prompting in xp, i will test this tomorrow. If i can manage to remove that prompt, it will go smoothly. Oh, and yeah, item-level targeting is supernice. We already use this to define the power settings on laptops in our domain. I'm sure we will use this more and more in the future
  13. Hello, thanks for the replies! It seems we've resolved this issue now, and i am ashamed to say it was due to my own nubeness . It was a security issue that caused the problem. Using the settings already applied, and then choosing in the printer connection witch you apply in the GPO, you choose to it to run with Run in logged-on user's security context (user policy option) enabled.
  14. This is a very big network, and lot's of locations with lots of users and computers. And i have spent the last 6 months cleaning AD and it's policies up after starting in this job. A big part of the cleanup was to remove all scripts, and find other solutions to it. Like for example removing scripts for mapping network drives, and using policies instead. We found that this was much more stable than scripts. Going back to scripts is not an option in this case, i don't see why there is GPO settings for pushing printers when we can't use it. It should be a cakewalk, yet it's not.
  15. We recently lifted the domain functional level to 2008 R2. We are starting to see more windows 7 clients in our domain, but we still have lots of clients with windows xp. Although we had this problem before we lifted our functional level (then running in mixed mode with 2003), it has become even worse now. The problem is network printers via GPO. I'll try to keep it short Basically, it won't work on either win7 or winxp computers when pushing the printers out on user configuration. However, it DOES work on win7 computers if i push the printers out via Print Services installed on the printserver on computer level, and then using the "add network printers" function in the GPO to set the printers as standard, for example. This does not work on winxp computers. But, using the only GPO to add the printers, and only on user level, like i want to, won't work at all. And this is a massive headache to me. The printservers are spread out on various locations, all connected with fiber connection and running either server 2003 32bit or 2008 32bit. Here is the setup i am currently using in my GPO's: Computer configuration -> Administrative templates - Printers -> Point and Print Restrictions Enabled Users can only point and print to these servers: Disabled Users can only point and print to machines in their forest Disabled Security Prompts: When installing drivers for a new connection: Do not show warning or elevation prompt When updating drivers for an existing connection: Do not show warning or elevation prompt Computer configuration -> Administrative templates - System -> Driver installation Allow non-administrators to install drivers for these device setup classes Enabled Allow Users to install device drivers for these classes: {4d36e979-e325-11ce-bfc1-08002be10318} {4658ee7e-f050-11d1-b6bd-00c04fa372a7} User configuration -> Administrative templates -> Control Panel -> Printers Prevent addition of printers Disabled User configuration -> Administrative templates -> System -> Driver installation Code signing for device drivers Enabled When Windows detects a driver file without a digital signature: Ignore I have confirmed that it's not any UAC or something like that that prevents the users to add the printers, because they can do that without any hickups when doing it manually. Has anyone encountered this problem before, and got it to work? I'll provide you with as much information i can, so please ask. Thanks for the help in advance!
  16. Aye, i did check this, and the groups were missing. But i have added them.
  17. Thanks for the reply! After i posted my thread, i managed to google myself to the answer you gave here. Seems like it's only the DC template that doesn't work in 2003. A regular computer certificate from the CA installs just fine on 2003 and xp. If i choose manage on my templates folder i get a list of already ready templates to use. Is it not possible to create a new template from scratch? There is another DC template already there, wich is possible to edit. But i can't get it to show on the list of templates i'm able to issue, why is that?
  18. We have installed a 2008 r2 server as CA in our domain, and are having problems issuing certificates to our 2003 domain controllers. The root certificate is fine, everyone gets it. But the computer certificate for domain controllers is a whole other story. On our 2008 domain controllers, i can use the wizard when adding certificates in mmc, and request from there. Then the certificate for the DC is issued correctly, and placed correctly. But this option does not work on our 2003 domain controllers, i get the error: The wizard cannot be started because of one or more of the following reasons: - There are no trusted certification authorities (CAs) available. - You do not have the permissions to request certificates from the available CAs. - The available CAs issue certificates for wich you do not have permission. I have checked everything i can think of, and can't find anything wrong. Besides, would i not get the same error on our 2008 DCs if there wasn't any CAs available or there was something wrong with the permissions? If i use Web enrollment, it doesn't work at all, on both 2008 and 2003. I can create a certificate request, and select "domain controller" for the template. But the thing puts the certificate in the personal user store, not in the computer store. And the static information when looking at the details for the certificate is different than the certificate that was issued to a 2008 DC with the wizard. It's like the server issues different certificates through different templates, when all i'm using is the default template. Excuse me for sounding like a total newbie at this, but i am. I just got this task thrown at me, with the order to make it work, because no one else dared to touch our old CA who was failing. Only problem is that my level of skill in this particular field is more or less none Please ask if you are wondering about anything, and i'll try to provide as much information as possible. I am desperate to make this work!
  19. By that i mean i randomly get an error when selecting the zone:"Zone not loaded by DNS server. The DNS server encountered a problem while attempting to load the zone. The transfer of zone data from the master server failed. Correct the problem then either press F5, or in the Action menu, click Refresh." After i reload the zone manually, it stays ok for a while, then goes down again like explained above. The zone is set to replicate to 4 spesified servers within the domain only. Now, obviously it is something between the master server and the secondary servers, but i just can't find out what it is.
  20. My company is currently running a MS server 2003 domain, but we are in the process of getting ready to raise the domain to 2008. Because of this, we went ahead and installed new domain controllers with 2008 and transferred the FSMO-roles to them. All our DNS-zones are AD-intergrated, except one. Now, before the upgrade, the zone replicated fine between the servers. From 1 master, to 3 secondary servers. But after we changed to 2008, and removed the old 2003 servers, i haven't been able to get the replication going again. It's running fine on the master server, but on the secondary ones, it keeps crashing all the time, and then i have to go in manually to reload the zone again. I have set zone transfer to "any server" on the master server, and notify to the selected secondary servers who also holds the zone. The reason for zone transfer to "any" server is simply that it just won't work without. If i minimize it to the servers i want, i can't even get the zone running at all on the secondary servers. The DNS-log and debugging log for the DNS-servers tell me nothing. The whole problem is quite frustrating, because i constantly have to check manually if the zone has crashed on any of the 4 secondary servers, and i never know if i have a failover for that zone or not. Does anyone know what is causing this, or what i might have done wrong?
  21. Hehe, i don't doubt it would make things easier. But that is easier said than done in our case, considering manpower and finanical resources Oh well, if i come across any other solution i'll throw it up here, i doubt that tho! Wasted enough time on this already Thanks for the replies!
  22. My organization is currently running a Windows 2003 domain. We did until recently, use roaming profiles. But decided to turn off this feature as we're now on a level where more or less every user has their own computer. We had some problems with folder redirection and the users profile with Windows 7, but this got better after we turned roaming profiles off. But now i have runned into another headache. Windows 7 users are experiencing, randomly, that their monitor goes black when they log in. The only solution i have found to this problem, is to delete the users local profile. Computer works fine for a while after, then all of a sudden, when they come to work one morning and log in: black monitor after login. If i log in as a local user, or a user who does not have a local profile already, i find nothing in the event viewer or anything that can indicate as to why this is happening. If the user with this problem logs in on a computer with win xp it works fine. Now, it would be nice if someone knows about this, as i imagine this problem will only grow in numbers when more computers are upgraded to Windows 7. Or if anyone has any idea as to what exactly in the profile could be causing this?
  23. Does anyone know if it is possible to run an AD query that lists all users in the domain who are members of more than 1 global security group? If so, do you have a suggestion in how that string might look like, or already have a similar string that you want to share?
×
×
  • Create New...