Jump to content

talksr

Members
  • Posts

    1,565
  • Joined

  • Last visited

Everything posted by talksr

  1. Server Stats: Xeon E-2224 @ 3.40GB 32gb RAM WSUS Share Disk: 10.3TB / 10.2TB free. TaskManager shows average CPU utilisation at 47% Memory use 7.6/31.9GB
  2. Hi, Thanks to the Microsoft Printer cockup detailed in this thread, we really need to remove the updates in question. Our existing WSUS server has no space, so we have had to stop it. I have done this by visiting services.msc and stopping WsusService. I have then stopped the WsusPool in IIS>Application Pools. I have also stopped WSUS Administraton in IIS>Sites. The old server above is a 2016. The new one we have set up is a 2019. I have set it up as I usually would and I am constantly getting the following error: The Copy Error to Clipboard is as follows: I have followed all of the guides online to try and make this work. 1.Changing IIS>Application Pool>WsusPool>Advance Settings>Private Memory Limit KB to 0 2. (1) On your WSUS Server, launch the IIS Manager. (2) Click 'Application Pools' is in the Connections list. (3) Right-click 'WsusPool' and select 'Advanced Settings…' (4) Increase the WsusPool 'Private Memory limit' x4 times, or set to 0 (unlimited). (5) Change 'Queue Length' from the default 1,000 to 25,000. (6) Save the configuration. 3. Restart IIS using the IISReset command-line utility From the Start menu, click Run. In the Open box, type cmd, and click OK. At the command prompt, type iisreset /noforce Nothing works, I get the same error every time. Why yet again does a Microsoft product not work? We have been put in an impossible situation. Old server has no room, have set up a new one, cannot use WSUS as it simply doesn't work. Microsoft have released these printer updates with no sensible workaround. We are now unable to remove the update as Microsoft's WSUS doesn't work. I am having to charge this school for my time and I am totally unable to get them any further forward. Absolutely livid about this situation. Does this company have any idea of the chaos it is causing?
  3. Thanks again for your really helpful posts. Ok, I got the WSUS view back so everything is showing. I located the update again within WSUS, Approved and then Approved for Removal just as you said. I then went back to the update in question and selected Deadline. I set the deadline to 14th Sep meaning that as soon as my server polls the WSUS server to check for updates, it should try and remove this update. I went to Windows Updates on the server, it it picked up the exact update in question, was saying it was installing it, but left it to run and now have this. So we are getting somewhere (thanks massively to your help), but still, this server is not playing ball. Could it be to do with the fact I have re-created Software Distribution folder? I am going to look in to the print server on the 2019 server as I am thinking this will work as a workaround, but just feel so close with this 2016 server, I may not need to go down that route if I can get this update removed (for now).
  4. Thanks for your post. By Remove, I mean... I can either Approve or Decline it. There are no other options that will be of use. Yes, tried other views, but just get the same view whatever I try. I can't remember how the computers for this site were added, but I would expect mine are also set via GP and client-side targeting. I did manage to get it back to the proper view after more messing around by selecting Window>Update Services as opposed to All Updates. At least now I have proper control of it again! Thanks, will have a look through that thread. Yes, we have WSUS on 2016 and 2019 but they are both independent and nothing runs as an up or downstream server. No devices have ever been pointed to the 2019 WSUS server as it has never worked. I just stopped the service on it using Start-Service wsusservice on PS. Every single time we tried using it, we got the same errors about it not being able to connect to end node, looked it up, seemed to be IIS issue, went through all of the IIS settings and tweaks, no difference. The school was paying by the day, so we gave up as it was costing so much in time. Another broken Microsoft product, used to be great, now is just useless. Shame as the 2019 server is new, has bundles of space, but cannot justify spending any more time on Microsoft's broken products. The 2019 server, however would be prime for using as a Windows Print Server and then hopefully this would resolve this issue? Does it matter if the Windows 10 clients have KB5005573 installed? My understanding is that if the server has it installed, that is why users can't print and are asked to install drivers or authenticate?
  5. Hello, Thanks for your post. Yes I do, but WSUS has not worked for some time and I did go through all of the steps to clean it up. The issue is that the space on the server it is on is totally full. Like you suggested I didn't have many categories as they take up so much space. The problem with WSUS is I only get this view: I have no way of being able to see Critical/Security etc Updates. Computers, Synchronisations, Reports or Options. I did manage to search for KB5005573 and it found it 3 times. Twice for Windows 10 and once for Server 2016. I removed the entry, but still, server 2016 will not remove the KB5005573 update. On the new 2019 server, WSUS also doesn't work. It constantly crashes and says something about the node. I have done all of the tricks regarding IIS tweaks etc but it never works.
  6. Thanks for your helpful posts. I have been off for a few days, not been well not helped by the abuse I have received over these printers which has absolutely nothing to do with any chances I have made. I have returned back and now another site is having the same issue. Windows 2016 server, update KB5005573 was installed on it on 17th of September so obviously the client computers have only just done their updates. If I am understanding this right, the problem is KB5005573 (for a 2016 server) so if I can uninstall that, it will work on the client machines? Thankfully, it has uninstalled so I will try and do a reboot later. Back to my last post... You were right about wuauserv, it was that, as soon as I shut it down, I was able to rename software distribution folder, however, I have still been unable to remove the update. The setup is as follows: 1 2016 FRDC 2 secondary domain connected "client" servers. One running 2016 and other running 2019. The 2019 does not yet have the equivalent KB5005568 update so I am thinking of using this as a print server. But it is only a matter of time before it tries to install it and not sure I can prevent it from doing so. The printers of which there are three are deployed via Group Policy. Everything is very basic. Just photocopiers with an IP address. It is a very basic GPO. It sits at the root of the domain and is called Printers All Locations. The three printers are listed in there and will apply for all computers and locations in the domain so everyone gets the same ones. The printer connection paths are listed as \\servername\PrinterName. I tried to add the RestrictDriverInstallationToAdministrators reg to this GPO but it has made no difference at all. I have spent hours trying to remove KB5005573 on this server and it just will not remove. My only other thought would be to use the 2019 server (we use for Backups, Paxton Access and a few other things) as a print server, re-do the GPO and put in new paths for the printers? What do you think? We have WSUS on the second 2016 server but it is constantly crashing and not working, again spent hours trying to solve it and it just doesn't work so updates to client computers will be hit and miss at the moment.
  7. Just a quick update to say, for some reason, it now has allowed me to rename the SoftwareDistribution folder. I have renamed it SoftwareDistribution.old and re-executed the PowerShell script, but again, I am getting the same error. Tried again and again, rebooting server each time. Have never had the need to roll back any drivers before this ridiculous situation. Any ideas? I have had multiple phone calls and emails from furious staff today who have been unable to print for over a week now. Nothing I can do to help them as everything I am trying is just not working.
  8. Thanks for your post. Thought I would try renaming SoftwareDistribution but I am getting: "The action can't be completed because the folder or a file in it is open in another program" Any ideas what else might be using it?
  9. Thank you for the helpful post and script. I have run it and got the following: The log file is showing the following... Not sure why it would not be able to find the file specified. KB5005573 is still showing as installed on Installed Updates. What a mess.
  10. I have tried repeatedly removing update, it is not coming off. Any ideas? I am getting hounded by people every day because they cannot print.
  11. Thanks everyone for your posts. This is just a total mess. I have applied the reg, Windows 10 computers still not liking it. It looks like some computers have not yet got the July 21 update due to WSUS issues. Had been hoping to move away from WSUS but school had not got the money to give me more time to look into this. I just do not have the time to keep wasting on this and the school cannot afford more of my time. Does anyone know what the specific update is on the server which is enabling this new security feature? I am thinking of just removing it for now as the impact this is having is unprecedented.
  12. Thank you, very helpful. My only issue is that from following the post you linked me to, it says: Create a GPP regedit: Code: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint Value: RestrictDriverInstallationToAdministrators Dword: 0 I am finding that when I go to make a new registry on the GPO with the printer settings, by going to Computer Config>Preferences>Windows Settings>Registry, I am only able to browse the key path to: SOFTWARE\Policies\Microsoft\Windows NT\Printers There is no \PointAndPrint after the Printers folder. Any ideas on why that would be?
  13. Hi there, Has anyone else started getting this message when their users are attempting to print? We are running Server 2012, just 3 shared printers which print directly, no holding in queues etc. They are shared by a GPO at the top of our AD, it goes to all machines and users and is configured in both Computer Config>Policies>Windows Settings>Printer Connections and User Config>Policies>Windows Settings>Printer Connections. All client systems when logged in as teachers/pupils are showing the above message. If the user clicks on Install driver, it seems to install and shows progress, but then it pops up again and again every time you click Install Driver. Thus they are totally unable to print anything. I have logged in as administrator and get no messages like this, the jobs just print. We have made no changes to Group Policy or the server in general so I cannot understand why all of a sudden this is happening. Any ideas?
  14. Thanks, it is all running fine other than this one which will not let me proceed until I select US. Also, thanks the other poster, didn't realise just how much you could put in!
  15. It won't work, it won't let me even put in a username, it is all greyed out. Don't even know why it is there if it can't be used. When you select Create from the drop down, everything is greyed out.
  16. Well spotted, but no, I typed manually as server is on another computer so can't copy and paste. It is spelt correctly on server and running like a dream if I do it as administrator on PowerShell by copying and pasting.
  17. Hi there, Can anyone remind me how you change the default Language, Time and Currency Format (locale), Keyboard Layout and Time Zone on MDT from US to UK? It has been a while since I have run into this issue. This is what I am currently seeing:
  18. Will look into LAPS, but in the mean time, I have made a simple PowerShell to add a local non admin account with no password. Works perfectly on PowerShell, I have added it as a command prompt Task Sequence for our 1909 build on MDT. I am now getting the following: It works perfectly on a W10 system when I run Powershell. Really not understanding why this is so difficult to achieve. I added the Task Sequence at the end of Postinstall named it Create Local User Account, Run command line and it runs: powerhsell.exe New-LocalUser "LocalUser" -NoPassword -FullName "Local User Account" -Description "Local User Account" -AccountNeverExpires.
  19. Hi, thanks for your post. I had a fiddle, I removed the DeploymentShare share from the D:\ drive, the share was DeploymentShare$ I then removed the Deployment Share from E which was DeploymentShare2. I then re-shared the E one but made it DeploymentShare$ and now it is working like a dream. Not sure how I ended up with two DeploymentShares, very strange, but I seem to have solved it through trial and error. Thanks for your post
  20. Hello, Does anyone know how I can resolve this issue? I have WDS all set up on my 2012 R2 server and it works nicely. I had also set up Deployment Workbench and added Windows 10 1809 some time ago. I have logged on to update this image. I firstly removed Deploment Workbench and reinstalled the latest version. I have added a new 1909 image, put in out of box drivers, Office application and a new Task sequence. When I F12 a client machine, I am seeing 1809 only in the Windows Deployment Wizard within Microsoft Deployment Toolkit. 1. I deleted 1809 from Operating Systems in Deployment Workbench, but still, 1809 came up. 2. I did "Update Deployment Share". No change, did it again but completely regenerated images. No change. 3. I "Closed Deployment Share" in Workbench, when I re-added, I can see there are actually two. There is one DeploymentShare in the D:\ drive - this has the old 1809 stuff in and this is what seems to be getting picked up. But there is also, another Deployment share in E:\ and that has my new 1909 images with task sequences etc. How do I get the server to pick up the right deployment share and how has this even happened? I am not too bothered about keeping the old 1809 one as this is old now. Just quite confused about how this has happened in the first place. WDS remote install folder is E:\WDS\RemoteInstall which is a similar area to my new 1909 stuff, so can't see why the D:\ stuff is still there and being recognised. Any help would be great.
  21. Thank you, I am trying through Startup script, but it doesn't like it, it has not made a change. Do you have any ideas?
  22. Ok, good point, so I would change administrators in the ps1 code to Users? Then they would be part of the users group and nothing else?
  23. Thank you, very helpful. What is the best way to put this on Group Policy? I have only really used batch files in the past.
  24. Hi there, Is there a way I can add a local admin username and password to a set of devices in an OU on Active Directory? The school has kindly been donated 30 laptops. I am adding them using WDS and Deployment Workbench to the server but thought it would be useful to have local admin accounts pre-setup so that if there is another lockdown, the laptops could be handed to children who could use workstationname\localadminaccount as the username to get on at home. Any help would be great.
×
×
  • Create New...