Firefox
Members-
Posts
388 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Firefox
-
You can activate the product with a MAK key then later convert to KMS. One of the options within the KMS server is to remove then reinstall keys ;-)
-
Documents Folder Re-direction - can't get my head around it :(
Firefox replied to kennysarmy's topic in Windows 7
A wonderful windows 7 feature *sarcasm* Seemingly if you prevent the users having rights over the desktop.ini file it prevents the folder being renamed. We ideally don't want to go down this route. We are currently looking into using an environment variables in conjunction with the desktop.ini file - I'll post more on this if/when our test prooves fruitful -
I didn't say you couldn't run other updates without going fully to SP1 @ Arthur, we had the "VM could not initialise" errors too, but we did manage to resolve these before our SP1 update - although this did take a call to microsoft. As with anything, it's going to depend on what your business it happy with risk wise. I have run the SP1 update on 52 DC's so far, and 3 have failed, and corrupted the OS...now for me 3/52 I can work around, if you have 1 and that fails. Also seem to get a problem with some updates, whereby the roles section under server manager simply says "Error"
-
Fresh Server 2008 R2 install for our school. Advice please
Firefox replied to brickwall53's topic in Windows Server 2008 R2
Installing the RSAT tools should be ample for managing your AD environment Configuring DFS? Using a Key Management Server? Update firewall rules? (if they relied on old server name\IP's) Were you using WINS in your old setup? are you confident nothing now relies on this? If you have the budget, I would create a 2nd DC for resiliency (not essential, but good practice). Are you going to be solely responsible for managing the AD? if not I would make sure you protect your objects from acidental deletion Or if you're fully 2008 enable the AD recycle bin :-D -
nope no schema changes with regards to SP1, upgraded our via wsus easy enough, no errors reported. You could argue the case if you need to go to SP1, it seems the update is based around virtualisation more then anything, we needed this to help further make use of Hyper-V, but I can see a lot of people not bothering with the update.
-
For DHCP depending on your ranges you also have the ability to split the scope across multiple DHCP servers (but this maybe OTT for your needs) Make both servers DNS and have this Active Directory intergrated. All these suggestions might seem over the top, because you might be thinking "we've been running ok on 1 server long enough" But as with everything, it works great...until it dies lol had my fingers burnt before, now I build in resiliency whereever I can. For the FSMO roles - as mentioned Schema Master - only really needed for when you wish to make Schema updates Domain naming - if you're not planning on making any new domains hardly used. RID - very critical Infrastructure Master - pretty much negated if all your DC's are GC's PDC - critical role, but easily seized if it was to fail.
-
Personally I would make both old and new windows 2008 R2 DC's Put your schema and domain naming on the same box, the other 3 roles on the 2nd box...make both GC's Setup DFS, and replicate the file shares between the 2 servers. If entirely possibly I would also team network cards on both servers across 2 switches. You can find any machine to carry out your WSUS role, I personally wouldn't have this on my DC.
-
Group Policy Problem - Filtering: Not Applied (empty)
Firefox replied to FN-GM's topic in Windows Server 2008 R2
Also try putting another setting in the GPO...anything fairly low impact...just to see if the policy now doesn't show as empty -
Group Policy Problem - Filtering: Not Applied (empty)
Firefox replied to FN-GM's topic in Windows Server 2008 R2
I take it under the startup option you added the .vbs file under the "scripts" and not under powershell? Because the result you posted above say the order is not configured, but that lives under the powershell tab. -
Try removing 1 layer, so where you have "shortcuts" call that folder "Pupils" and set the targets on that level
-
Group Policy Problem - Filtering: Not Applied (empty)
Firefox replied to FN-GM's topic in Windows Server 2008 R2
Ok under the details tab, disable the user part configuration...without any settings this will just confuse the issue and will give you the "Filter not applied (empty)" error. once this has been done, try a GPupdate /force Then run another gpresult to check your error is still there If your problem still exists, try removing "Autenticated users" and adding in the device you wish to test on. Then repeat the above steps again. -
Group Policy Problem - Filtering: Not Applied (empty)
Firefox replied to FN-GM's topic in Windows Server 2008 R2
Any chance of posting up some screen shots of all the tabs under the policy? This has me intrigued -
As mentioned earlier, we use DFS....and most certainly swear by it, it gives us in ICT a more complex system to have to maintain, but the user experience can always be presented the same if we have a need to change the backend infrastructure. We are currently consolidating over 200 file servers down to a very large SAN and 15 field servers. But all our network drives map via DFS, so from a user point of view nothing will have changed. We're also looking at the option of turning on ABE (Access Bassed Enumeration). This means the user will only actually see the folders they have access to.
-
Group Policy Problem - Filtering: Not Applied (empty)
Firefox replied to FN-GM's topic in Windows Server 2008 R2
Ok another silly question, but the part of the policy (computer/user configuration) that you have made these settings in, you have made sure that part is enabled? Under the details tab and GPO status? -
Group Policy Problem - Filtering: Not Applied (empty)
Firefox replied to FN-GM's topic in Windows Server 2008 R2
So you've created the GPO, but under the GPMC, look for the group policy, look under the scope tab, and security filtering. Have you added in a group or device/user that you wish the policy to apply to? -
There is nothing wrong with the DS commands, probably why they are still part of the windows 2008 enterprise admin exam. Powershell is a great tool, but not very easy if you have no scripting background or an overview on the product. We use Primal Script with it's link into Powershell for a lot of our work, but simple AD queries DS still works just as easy and in seconds
-
You should be able to also do this with a DSadd command, this should allow to to call on a file with the user names already entered SolutionBase: Using the Dsadd, Dsmod, Dsmove, and Dsrm Windows Server 2003 directory service command-line tools
-
Help! Our PDC cannot see our domain, complete network failure.
Firefox replied to reggiep's topic in Windows Server 2008
DC 1 is now looking totally fine...I would expect those syslog errors will possibly clear in the next 24 hours.....and you can always backup the eventlog and clear those down to clear the other messages. DC 2 does look in a bit worse condition, does this server hold any of the fsmo roles? If not, I would actually suggest a demotion, a metadata cleanup followed by a re-promotion might be the quickest fix to resync everything -
Help! Our PDC cannot see our domain, complete network failure.
Firefox replied to reggiep's topic in Windows Server 2008
Sorry I meant the actual Netlogon service not the share. Is the service running? can you stop and restart it? and what account is it running with? -
Help! Our PDC cannot see our domain, complete network failure.
Firefox replied to reggiep's topic in Windows Server 2008
Sorry if I overlooked this but was just scanning, I'm assuming the netlogon share on the failed PDC is currently running? and without error? Does it let you stop and restart this service? Do you have this running as local service? Most of the errors you see are just a by product of the Failed Advertising, and that is normally directly related to netlogon -
Hello, Hopefully someone can shed some light on the information we are being given back from browstat status There are 18 domains in domain DOMAIN on transport......... How does it calculate the 18 domains? the domain we run the info against is a child domain, with no further child domains. thanks
-
Not answer answer to all...but.. The connection broker i believe is used more in a farm situation with NLB. It also acts as a connection policy server, but depending how you set this up, we used normal GPO's to control this. I would not advise having the gateway and session host on the same server. The gateway will be the initial point of connection, the session host is then the server that loads the app the users try to access. For access control, we allowed a large group of people onto the gateway, then permissioned access to each app and hid the irrelevant icons from display to each user.
-
I guess everyone is equally as stumped as me? lol
-
Ok...it's entirely possible I'm simply going mad...we'll see From a child windows 2003 domain on a windows 2003 DC, I Open the properties of a user, click member of, then add to group....now when I click locations, I can only see my domain and not the entire directory :-s I could swear I've previous been able to view the entire directory from here so that I could add the user to another group in another domain Interestingly enough, we also have a windows 2008 dc in the same domain, and when I carry out the same process as above I can view the entire directory. This wasn't a Windows 2008 new feature was it? Please tell me I'm not going mad
