Jump to content

edutech4schools

Members
  • Posts

    2,744
  • Joined

  • Last visited

Everything posted by edutech4schools

  1. Found while Googling that apparently the new way uses Group Policy Preferences, but I don't have any time to check. Restricted groups is the old way but will work on all servers & GPP is newer but will only work on 2008 or newer. Seeing as we have a 2012r2 server Ill do some more research when I get some time, unless someone wants to help me.
  2. hello, I am in the process of locking things down a bit and want to remove all the teachers from the local admin account which is deployed via GPO using restricted groups. Q1 - What group should I apply to the staff? They are using Windows 10 if that makes any difference. Q2 - When the gpo was created we were using server 2008r2, we are currently on 2012r2, is it the same process, or has it changed? Thanks
  3. OMG I am such a donkey. I looked at the host backup issue at around 11:15 am and thought it had been running since 11pm the night before, in fact I had scheduled the backup to start at 11am, what a plonker.
  4. Not sure if I have an issue or not. On our 2012 R2 host I have Windows backing up 2 VM's to an iSCSI target which was setup yesterday. The backup was scheduled to start at 11pm last night but is still listed as backing up in Windows Backup which is possibly OK although the 2 VMs are small and possibly should have completed by now, its been 12 hours. The issue that concerns me is that if I look in hyper-console at the vm's they both also say backing up. I thought but could be wrong that the vm's had 'Backing up' listed while a VSS snapshot was created, which definitely should not take 12 hours, or do they have backing up for the entire duration of the backup?
  5. I always get that if I install all the updates in one go on a fresh server install. I think it's KB 2919355 which causes the issue if it's installed before some other update, so I leave this until last, along with the larger updates.
  6. Hello, New to the World of iSCSI and I would like to use our older server for backups for a primary school, using windows backup to backup the host vm files. I have followed some online instructions about setting up the iSCSI target on the 2012r2 server but I noticed within the 'Add Roles' section along with the option to install the iSCSI Target role is another role named 'iSCSI Target Storage (VDS/VSS) Provider'. None of the instructions about creating an iSCSI target for backups mentions the 'iSCSI Target Storage (VDS/VSS) Provider' role but having looked what this does I wonder if I do need this also. Although I have also found the following information Which then makes me think I should not install this role. So If I want to backup from our new 2012r2 server to our older 2012r2 server using Windows backup, do I need to install the 'iSCSI Target Storage (VDS/VSS) Provider' role along with the 'iSCSI Target role'??? Thanks for you help & time.
  7. Thanks. The 2008 method is the old way of doing it. Think this is the new way - https://4sysops.com/archives/fine-grained-password-policy-in-windows-server-2012/
  8. Never played any of the single player modes in BF. Always got to engaged in the multiplayer.
  9. Just helping out at a primary school and I noticed all the staff are using very silly passwords. The head has given me the OK to make sure all the staff are forced to change their passwords to something more secure, but has asked me to make sure the passwords are not altered for any pupils. I think the normal way of changing a password is to change the 'Computer'....... gpo but I assume this is not an option as on occasion a staff member might need to log onto a curriculum laptop and that would then apply the password policy to the pupils that use it. I seem to remember getting the password policies to apply years ago using password complexity or something but this seems to have all changed with Windows 2012r2. Does anyone have any ideas how I can get the staff to meet my password settings but not the pupils. Thanks
  10. Our aging Dell server has a PERC bettery warning so I contacted Dell who have quoted £76 for a new one. Don't know why but I imagined it would be like a bios battery or similar but for that price it must be much more heavy duty. I know you pay a bit for brand etc but does that price sound correct? Thanks
  11. OK all fixed. I needed my user account to have the administrator group added. Can someone explain why domain admin group was not good enough to copy the files in to the policies folder please. Just to clarify the events. Went to new server (2012r2) to update our WSUS group policy, Policy settings on the right looked fine but when I went to navigated through Computer Configuration, Policies, Administrative Templates, that was as far as I could navigate both Windows Components, Windows Update. were missing. Found out that you could fix this by replacing the files in sysvol / domain / policies folder but could not paste the new files, started to panic. Remembered our old 2008r2 server in a cupboard at the other end of the school that I had not dcpromo yet so went to check. Logged in but it took ages for me to get in and then DNS would not open AD would not open and I realized the network was not connected. Found out LAN cable had been damaged by a member of staff at some point. As this was about to be decommissioned I took the decision to turn it off and remove all trace of it from our new 2012r2 server. It just seemed the safest option. Anyway I added administrator to my domain account on the new server and was then able to copy the policies to the folder and was then able to browse and edit the policies in GP editor.
  12. So just leave it. The policies I downloaded to replace the missing ones were for server 2012r2, would the fact the domains functional level be why I could not paste into the policies folder?
  13. Just had the other very old 2008r2 server go down on me. I have no way to restore it so have removed it from the main DC following MS DC removal process. Just checked and the domain functional level was 2008r2. Now I don't have any 2008r2 DC's should I rais the function levels?
  14. Hi, Just so you know I look after a few small primary schools and need this explained simply please. Just went to edit our WSUS gpo on our 2012r2 domain server and the path within group policy is missing so I checked the sysvol\domain\policies folder and most of the items are missing. I then downloaded the policies from this link - https://www.microsoft.com/en-gb/down....aspx?id=43413 Odd thing is that the download does not contain the GB folder, would that make a difference? Anyway I tried to copy paste into the sysvol\domain\policies and get this error, Destination folder access denied you need permission to perform this action I was logged in with my normal user that has domain admin rights. I then created a new user and added that user to the domain admin group, logged out and back in with this new user but get the same error. What on earth is going on, am I pasting to the wrong folder or something.
  15. Always like playing a bit of Battlefield (PC) and will be pre purchasing but wondered if its worth paying the extra for the Deluxe version, I'm not sure it is. https://www.battlefield.com/buy/battlefield-1
  16. My hunch was correct - all working
  17. Would it have anything to do with me doing a non authoritative restore but my test server is obviously not connected to any other servers and so cant replicate the info needed. Going to try again but doing a authoritative restore and see what happens.
  18. Just doing a test DC system state restore but get error right at the end. My process install 2012r2 OS + updates (as a VM for testing) reboot server in safe mode - system state restore mode restore system state as non authoritative reboot and login using local admin and DS restore password enter correct IP info in adapter settings reboot server so its not in safe mode login as my domain admin account get error - user has been signed in with a temp profile open DNS - all looks fine open AD users - get error - Naming information cannot be located because: The specified domain either does not exist or could not be contacted. Anything wrong with my steps? Any ideas how I can fix this issue?
  19. Seem to have found an issue with Avast. We changed our proxy server to a new address, prior to doing this I updated the Avast template with the new proxy settings and checked a number of clients to make sure the Avast software had updated itself with the new proxy info. A short while after switching to the new proxy address I start getting X number of devices are in danger. I go and check and it does have the new correct proxy info and the clients are also getting the virus updates etc so whats going on. After looking around on Google I found out that Avast uses a file in C:\Program Files\AVAST Software\Avast\conf to call home and this file also has a proxy address. Yep you have guessed it, this local proxy address was never updated and still has our old proxy address. I can't deploy a corrected local file as I think it also has a unique number string for that client. I tested uninstalling Avast from the client and then re-installing and that does fix my issue but I would need to visit lots of clients to do this manually. Anyone got a way to uninstall and re-install Avast on mass? or any other ideas?
  20. Think you can upload to single location (as you) and then share with users individually but when sharing go into advanced and select 'is owner', This then makes each user you share with the owner, you can then remove yourself from the rights and leave each user as the owner of their own areas. Got very bad cold, so hope that makes sense.
  21. Thanks. Our LA controlled all the virus exclusions until recently, so I am having to start from scratch. Any idea what should be excluded for a data server running SQL with Sims & FMS.
  22. So do any of you use Avast on your servers?
  23. Sorry for the delay, our internet has been down for ages all in the middle of a server install. GPO Computer Configuration (Enabled)/Administrative Templates/System/Logon/Always wait for the network at computer startup and logon = enabled Computer Configuration (Enabled)/Administrative Templates/System/Scripts/Run logon scripts synchronously = enabled Computer Configuration (Enabled)/Administrative Templates/System/Scripts/Run startup scripts asynchronously = enabled
  24. How odd all ours are running on USB3 and cables are about 5 meters. Lucky I guess.
  25. It could be those clients are not getting all the gp info before the time out for the desktop to open due to network traffic etc. There are couple of group policies that are standard to have, you probably already have them, that might help, one was wait for network at logon but I can't remember the other as I am not at a server. I'll post back the GP's and locations.
×
×
  • Create New...