Jump to content

TheScarfedOne

Edu Supporters
  • Posts

    1,543
  • Joined

Blog Entries posted by TheScarfedOne

  1. TheScarfedOne
    Ok... so a departure from my normal belongings - but a bit of idle (well maybe not) fun and games...
     
    Read, and enjoy the underbelly of society!
     
    The DARWIN Awards!
     
    It's with great pleasure that I announce...it's that time again. The Darwin Awards are out! These Annual Honors are given to the persons who did the human gene pool the biggest service by killing themselves in the most extraordinarily stupid way.
     
    You may recall that last year's winner was the fellow who was killed by a Coke machine which toppled over on top of him as he was attempting to tip a free soda out.
     
    This year's winner was a genuine Rocket Scientist...no jive! Read on...and remember that each and every one of these is a true story. The nominees were:
     
    Semifinalist #1
     
    A young Canadian man, searching for a way of getting drunk cheaply because he had no money with which to buy alcohol, mixed gasoline with milk. Not surprisingly, this concoction made him ill, and he vomited into the fireplace in his house. The resulting explosion and fire burned his house down, killing both him and his sister.
     
    Semifinalist #2
     
    Three Brazilian men were flying in a light aircraft at low altitude when another plane approached. It appears that they decided to moon the occupants of the other plane, but lost control of their own aircraft and crashed. They were all found dead in the wreckage with their pants around their ankles.
     
    Semifinalist #3
     
    A 22-year-old Reston , VA man was found dead after he tried to use octopus straps to bungee jump off a 70-foot rail road trestle. Fairfax County police said Eric Barcia, a fast-food worker, taped a bunch of these straps together, wrapped an end around one foot, anchored the other end to the trestle at Lake Accotink Park, jumped and hit the pavement. Warren Carmichael, a police spokesman, said investigators think Barcia was alone because his car was found nearby. "The length of the cord that he had assembled was greater than the distance between the trestle and the concrete," Carmichael said. Police say the apparent cause of death was "Major trauma."
     
    Semifinalist #4
     
    A man in Alabama died from numerous rattlesnake bites. It seems that he and a friend were playing a game of catch, using the rattlesnake as a ball. The friend - no doubt a future Darwin Awards candidate - was hospitalized, but lived.
     
    Semifinalist #5
     
    Employees in a medium-sized warehouse in west Texas noticed the smell of a gas leak. Sensibly, management evacuated the building, extinguishing all potential sources of ignition; lights, power, etc. After the building had been evacuated, two technicians from the ga s company were dispatched. Upon entering the building, they found they had difficulty navigating in the dark. To their frustration, none of the lights worked. Witnesses later described the sight of one of the technicians reaching into his pocket and retrieving an object that resembled a cigarette lighter. Upon operation of the lighter-like object, the gas in the warehouse exploded, sending pieces of it up to three miles away. Nothing was found of the technicians, but the lighter was virtually untouched by the explosion. The technician suspected of causing the blast had never been thought of as ''especially bright'' by his peers.
     
    And now the winner of this year's Darwin Award; as always, awarded posthumously;
     
    THE 2011 WINNER!
     
    Arizona Highway Patrol came upon a pile of smoldering metal embedded in the side of a cliff rising above the road at the apex of a curve. The wreckage resembled the site of an airplane crash, but it was a car. The type of car was unidentifiable at the scene.
     
    Police investigators finally pieced together the mystery. An amateur rocket scientist had somehow gotten hold of a JATO unit (Jet Assisted Take Off...actually a solid-fuel rocket) that is used to give heavy military transport planes an extra 'push' for taking off from short airfields. He had driven his Chevy Impala out into the desert and found a long, straight stretch of road. He attached the JATO unit to the car, jumped in, got up some speed and fired off the JATO!
     
    The facts as best could be determined are that the operator of the 1967 Impala hit the JATO ignition at a distance of approximately 3.0 miles from the crash site. This was established by the scorched and melted asphalt at that location.
     
    The JATO, if operating properly, would have reached maximum thrust within 5 seconds, causing the Chevy to reach speeds well in excess of 350 mph and continuing at full power for an additional 20-25 seconds.
     
    The driver, and soon-to-be pilot, would have experienced G-forces usually reserved for dog fighting F-14 jocks under full afterburners, causing him to become irrelevant for the remainder of the event.
     
    However, the automobile remained on the straight highway for about 2.5 miles (15-20 seconds) before the driver applied and completely melted the brakes, blowing the tires and leaving thick rubber marks on the road surface, then becoming airborne for an additional 1.4 miles and impacting the cliff face at a height of 125 feet, leaving a blackened crater 3 feet deep in the rock. Most of the driver's remains were not recoverable.
     
    Epilogue: It has been calculated that this moron attained a ground speed of approximately 420-mph, though much of his voyage was not actually on the ground.
     
    Really.....we couldn't make this stuff up. People like these are all around us. They have kids and they vote.
  2. TheScarfedOne
    This post is going to seem very odd - as it is Part 4 of a series, where Ive only published Part 1 so far! Bear with me, there is a reason...
     
    A lot of my blogs recently have covered areas I get asked about a lot - and this one came up today!
     
    Take the scenario, you are sending out your OS Builds to Machines, and also you are letting staff choose from your catalog of software to install themselves.
     
    Problem - your OS install also shows in the list, so technically - they could bork the machine youve just set up for them.
     
    Hiding Tasks from the Run Advertised Programs window
     
    There is no way to hide the Operating System Deployments from being advertised to “normal” users, but there is a workaround. You can set the OSD to run only on a specific OS. Then you would select an OS that you don’t use in your organization.
     

     
    With this setting, an OSD will not be advertised to a user while working on the computer. However, you will still be able to re-image the system using PXEboot or USB boot (booting to WinPE)
  3. TheScarfedOne
    Ive had a lot of contact from people asking about installing System Centre Configuration Manager (SCCM) – having all sorts of issues with it. Normally – this install and config to the basics of doing a build and capture, through to the end game of it deploying your network clients for you!
     
    Im not going to cover AD or DHCP – other than saying have 2 accounts setup ready to use, something like SCCMAdmin and SCCMClient. Make sure that you arent running SCCM on the same server as DHCP; and if at all possible, run it on dedicated hardware.
     
    This is going to be a 3 part post – this one (the first) will deal with the getting started bits. The stuff you really need to read and follow to avoid issues later.
     
    First Steps
     
    Rule 1 – make sure you have all your prerequisites done. No, seriously – really do. The amount of times this happens!
     
    1. Do the AD Schema update
    Its not as terrible as it sounds! If you’ve not extended the Active directory schema before – this is a good guide… WindowsNoob SCCM Schema Update.
     
    2. Remote Differential Compression
    It is needed, so in Server Manager, on the Features node, start the Add Features Wizard.On the Select Features page, select Remote Differential Compression. Job done.
     
    3. Windows Deployment Services
    WDS – well, Im assuming you will be wanting to use the killer automated Operating Systems deployment! Add the WDS role – but do not (I repeat really DO NOT) configure it. Don’t even open its console!a
     
    4. IIS[/i
    ]IIS – yes, SCCM “needs” IIS, make sure you give it all this bits of it that it needs. There are a few, and 9 times out of 10 – you will miss one!
     
    The following Web Server role services should be installed.
     
    IIS Role Services
     
    Web Server
    Common HTTP Features (in IIS 7.5 [server 2008 R2] – you will find WebDav here which you also need to add)
    Static Content
    Default Document
    Directory Browsing
    HTTP Errors
    HTTP Redirection
     
    Application Development
    ASP.NET
    .NET Extensibility
    ASP
    ISAPI Extensions
    ISAPI Filters
     
    Health and Diagnostics
    HTTP logging
    Logging tools
    Request Monitor
    Tracing
     
    Security
    Basic Authentication
    Windows Authentication
    URL Authorization
    Request Filtering
    IP and Domain Restrictions
     
    Performance
    Static Content Compression
     
    Management Tools
    IIS Management Console
    IIS Management Scripts and Tools
    Management Service
    IIS 6 Management Compatibilty
    IIS 6 Metabase Compatibility
    IIS 6 WMI Compatibility
    IIS 6 Scripting Tools
    IIS 6 Management Console
     
    Now, after you’ve got that little lot all installed, time to do a bit of configuring!
     
    URL Authorization Feature:
    When the Authorization feature opens, make sure that an Allow rule is defined that includes the administrator account
     
    Authentication Feature:
    Right click on Windows Authentication and choose Enable
     
    WebDav Feature:
    This one should come with a health warning! In IIS7.5 [server 2008 R2]– this is a role service not an additional install. For IIS7 [server 2008] – download and install from Microsoft download centre.
     
    Then configure as follows…
     
    1.Startup IIS Manager and in the Connections pane, expand the Sites node in the tree, then click the Default Web Site, then double-click the WebDAV Authoring Rules icon.
    2. Click enable webdav in the Actions pane on the right side. Once you've clicked it it will then say 'Disable webdav' so be sure not to click there again, now we need to click the Add Authoring Rule task in the Actions pane.
     

     
    3. Start IIS Manager, select the server and select Stop from the actions.
    4. Start Explorer and navigate to C:\Windows\System32\inetsrv\config\schema.
    5. Right-click WebDAV_schema.xml and select Properties.
    6. Select the Security tab and click the Advanced button.
    7. Select the Owner tab and click Edit. Change the owner to administrators so the permissions can be changed.
    8. Select the Permissions tab and grant your user or administrators Full Control via the Change Permissions button. Click OK, and then open the WebDAV_schema.xml file in Notepad. Find the area below and make sure the values are set as shown:
     

     
    9. Click Save.
    10. Start the IIS service in IIS Manager
     
    These settings you can make in IIS Manager, but Ive found that they don’t actually set in the xml file 9 times out of 10 – so doing it this way prevents it being a worry. IIS reads this file when it starts so it appears correctly.
     
    Now you should be ready to do the install, which will be covered in Post 2 in a few days time.
  4. TheScarfedOne
    Ok – so, most of you know I love System Centre products – and after getting SCCM (System Centre Configuration Manger) setup nicely (I will blog on this, as lots of people seem to have a problem getting this up and running in less than a day) – it was time to play with its partner in crime SCOM (System Centre Operations Manager).
     
    Introduction
    What exactly is Operations Manager? Well, it revolves around an agent on the computer to be monitored. The agent watches that computer, grabbing and collating all the information about its inner workings - including the Windows Event Log. It can be set to look for specific events or alerts generated by the applications executing on the monitored computer. Upon alert occurrence and detection, the agent forwards the alert to a central SCOM server. This SCOM server application maintains a database that includes a history of alerts. The SCOM server applies filtering rules to alerts as they arrive; a rule can trigger some notification to a human, such as an e-mail, generate a network support ticket (it can feed to System Centre Service Manager – I will write about that at some point!), or basically any other action you want it to.
     
    When you deploy software with SCCM, you may have seen the dialog about “Generating MOM alert”. Not surprisingly being part of the same suite of products – you can read and query the software installs that you request completion of. In fact most actions that you can complete in SCCM have the option of generating information for SCOM.
     
    SCOM uses management packs (MP) to keep tabs on machines. MPs to refer to a set of filtering rules specific to some monitored application. Obviously Microsoft make management packages available for their products (Exchange, Sharepoint and the usual suspects) - and also SCOM also provides for authoring custom management packs. A lot of other vendors have now started doing MPs too.
     
    Now that’s our overview done, lets get to the nitty gritty of installing this beast.
     
    Installation....you think!
    I would recommend that SCOM sits on its own dedicated server – it an get quite busy depending on the size of your network! So, it was time to quickly build another VM on my Hyper V Platform.
     
    As the whole network is only 6 months old, it is all Server 2008 R2 – and the SQL Platform is at 2008 R2 as well.
     
    Problem number one – although SQL Server 2008 R2 has been out and about now for over a year, can cannot do a straight install. Irritatingly, the installer logic will fail to see either a local, remote or clustered SQL 2008 R2 system. Grrrr!
     
    Cue some jumping through hoops. I will assume you’ve got your SQL all set up already; and just a quick hint - if you need SCOM 2007 R2 reporting, don't forget install SSRS. You will want it, and anyway – most other database backend products want Reporting Services anyway.
     
    Database setup
    On your SQL Server, find and run DBCreatWizard.exe tool from the SCOM R2 install media – it hides in SupportTools > AMD64. This will launch the Database configuration wizard. Hit next, and then under Database Information , you can select database type , now we need create Operations Manager Database firstly, fill in SQL Port and Database Name and size (leave as default to be honest). Your instance and the data file locations should be picked automatically according to your SQL setup.
     

     
    After that you can choose the Management Group name , and permissions to run and administer SCOM. I would set your MG name to your domain or something descriptive rather than the default. Another heads up – set your administrators to Domain Admins, (or another group preferably) which has your technicians in it.
     

     
    You will then get the usual summary screen to hit next to, and hopefully all being well you will get the “Database created successfully” popup.
     
    Now, you need to run the tool again to create the Operations Manager DW database. Everything is as before, except on the Database Information screen, change the Database type in the top drop down.
     

     
    The usual amount of next-ing, and finally - you can see the databases in SQL Studio.
     

     
    Actual application setup
    You are now good to go with installing the actual SCOM 2007 R2 management system. Of course – all we have done so far is make a blank set of databases. So – obviously, we need to choose Custom setup (we’ve done part of it right!), and make sure you don’t choose the Database item.
     

     
    That will install all the managementy kind of stuff for you – and it will take it a little while. Another pointer – that Management Group name you chose in the Database setup; make sure you use the same name (but you knew that right!?)!
     
    Next step…install SCOM 2007 R2 Reporting, and I’m afraid there’s some more hoops.
     
    On the SQL Server Reporting Services server, rename the local group SQLServerReportServerUser$<hostname>$MSSRS10_50.<SQLInstanceName> to SQLServerReportServerUser$<hostname>$MSSRS10.<SQLInstanceName>
     
    And, as per the main management install, when you install System Center Operations Manager 2007 R2 Reporting, you need to choose Custom. Do not install the Data Warehouse component!
     
    Once the install has completed, rename the local group SQLServerReportServerUser$<hostname>$MSSRS10.<SQLInstanceName> back to original name SQLServerReportServerUser$<hostname>$MSSRS10_50.<SQLInstanceName>
     
    Looking for the official Microsoft article – well that’s here (http://support.microsoft.com/kb/2425714)
  5. TheScarfedOne
    The last article covered some of the rationale and an overview - this is a bit more of the "how to". Remember, there are two elements to MySite – the first showing your feed, all activity from your linked people (a la friends). The second, your profile.
     
    Now – the problem comes with the logic behind setting this up. In Education – we tend to like everything being accessible through one entry point. This will usually be though a firewall or gateway device.
     
    MySites - the standard config issue
    However, by default when you create the MySite, according to the main documentation - the location is under a different web application (URL) to your main Sharepoint site. I think an example is required…
     
    Your organisational portal site is on http://portal
    Your MySite must be on another URL domain or port so let say... http://Portal:12345
     
    What this will mean, by default, is that your users MySites are at http://OrgsIntranet:12345/personal/<username>
     
    As you can probably imagine, this is not ideal - In fact for most that will only ever have one main portal this is really not ideal.
     
    The reason we host MySites on another web application is so that no matter what site you are on, when you hit the "mysite" link at the top of the page, it will take you to the right place and that place is not dependant on any individual portal.
     
    In an ideal world you would have an address like http://my or http://mysites as a DNS name for your MySite … so that the address makes sense and you could run it on port 80 like everything else. It makes the URL look nicer I guess. Anyway – this doesn’t apply to our use of Sharepoint - so for with only one main portal we want it to look something like:
     
    Main portal: http://portal
    MySites : http://portal/personal/<user name>
     
    So how do you go about configuring this, when all the main documentation centres around the separate website model. And then worse than that – how do we get Alternate Access Mapping (the way that Sharepoint translates your internal http://portal used internally to https://gateway.org.uk outside) to behave. Well – that one will be the next article, but setting up MySites is now…
     
    Setup MySites
    Some assumptions for this article. You have an intranet web application named: 'http://mywebapp' it has it's own Content Database named "MyWebApp_Content".
     
    You want to setup and configure My Sites to be used via the URL 'http://mywebapp/mysites' and you want all your My Sites content to be stored in it's own new Content database named "MySites_Content"
     
    The following steps outline how to configure your existing web app 'http://mywebapp' to host ‘My Sites’ to be stored in a separate database (a screenshotted walkthrough is here: http://www.bybugday.com/Lists/Posts/Post.aspx?ID=22)
     
    1.Go to “Application Management” and select “Content Databases” under “SharePoint Web Application Management”
    2.Select the ‘http://mywebapp’ web application. And select “Add Content Database”
    3.Create a new DB and name it: "MySites_Content"
    4.Once this DB is created select the existing database named: MyWebApp_Content.
    5.In the “Manage Content Database Settings” for 'MyWebApp_Content’ select Database status to “Offline”
     
    This will ensure that no new site collections are created in the default content database 'MyWebApp_Content'. Taking this content database offline only prevents new site collections from being created. Users are still able to create sub sites and items and use the existing sites1.First you have to make sure you have 2 managed paths set up in the http://OrgsIntranet web application. To do this jump into central admin, "Application Management" tab, "Define Managed Paths". Make sure you are working on the right web application once you are in that screen.
     
    4.Go to Application Management and select “Define Managed Paths” under “SharePoint Web Application Management”
    5.Select the 'http://mywebapp' web application and create a new path named ‘mysite’ and select “Explicit inclusion”
    6.Create a another managed path named ‘personal’ and make it a “Wildcard inclusion”
    7.Go to “Application Management” and select “Create Site Collection”
    8.Ensure that the path selected is 'http://mywebapp/mysite' <Important - chose the same name> , and select the “My Site Host” template from the templates list on the “Enterprise” tab.
    9. Now, configure the My Site Setup from Central Administration > Application Managment > Manage Service Applications > User Profile Service. Click the Setup My Site link under “My Site Settings”. You need to configure all the settings in this page like the preferred search center, “My Site Host Location” and “Personal Site Location”. Set "Personal site provider" to "http://mywebapp/mysite/" and "Location" to "personal", click OK.
     
    Done! Now when your users click on the "mysite" link their MySite will be created in the right place.
  6. TheScarfedOne
    When I first started writing on Edugeek, many will remember me as one of the Sharepoint gang. My more recent writings may have convinced some of you that I was less interested in it now…but that couldn’t be further from the truth. Sharepoint 2010 is a brilliant product – and one which could be put to great use in Schools and Colleges.
     
    The Rationale
    As IT Professionals, we are constantly battling against the students (and the staff in some cases) with Social Networking. We are also in a battle to bring some kind of information organisation. When I joined my new Academy – the traditional old-school “shared mapped drives” were the mele you would expect. The problem with these areas is that they are difficult to make dynamic. They are also open to all kinds of abuse – and bar some serious messing with ACLs and NTFS permissions…it is basically unmanageable. Just try searching for a “lost” document in there too…I dare you!
     
    A Home page
    A picture says a thousand words...! Well - heres a screenie of my "still in development" environment. A central landing page with new items depending who has logged on. Here - you can also signpost other services.
     

     
    Improve Staff Access
    So, what can we do about this? For a start, at its most simplistic level – a single Sharepoint site with Document Libraries per Learning Area or Department. That’s a start, with the Document Libraries set with permissions “Contribute” only set for members of those areas.
     
    No more general dumping grounds, and also management of the area is under the Learning Area or Department. If you configure Search (by default, you will get this out of the box – I will go into more advanced settings at a later date) – you can search for anything. The terms you search for can be in the title or within the actual body of the document – and it will still be returned (so long as you have permissions!).
     
    Lets take that one stage further – a Site per Learning Area. Now, it is not just a Document Library they can use. The users now have a News Board, Discussion Forum, Calendar and Task list too. So – we have extra functionality for them – take for example department meetings – linked with their agenda and minutes. This is becoming cohesive.
     
    Still want more features….why not! Those documents that you have added, well lets say they are Microsoft Office documents. Most of them will be. Add the Office Web Apps feature to your site (details here) and you can now view and edit these documents in the browser (IE, Firefox, Opera, Safari) – and even better, multiple users can edit at the same time and it will live update! Genius…think collaboration now.
     
    Student use?
    We have so far just been talking staff, but extend this now to Students. We have the separate “Staff Areas”, so lets add sites for the Students by Learning Area too (or have the Learning area, but with a private area for Staff off that – the architecture layout is up to you!). All the same functionality exists, and you can group the permissions around your exisiting AD groups. No reorganising required – why reinvent the wheel?
    Now – the title said Social Sharepoint…and Ive not touched on that yet. But, I wanted to start with a little intro to what would get you to this point in the first place.
     
    Enter MySite - The Social Network
    MySite has been a feature of Sharepoint since 2003. Back then, it was a bit of a pig to manage to say the least. With 2010 – not only has it got easier to manage and implement, but it has gathered some extra killer features. MySite is basically what it says – a personal site for each user. It actually really consists of two – a profile and a storage area. You have a news feed – a la Facebook – and a document library. All files on Sharepoint are essentially stored in Document Libraries. Here are two images of the entry point to MySite – the first showing your feed, all activity from your linked people (a la friends). The second, your profile.
     

    [ATTACH=CONFIG]12582[/ATTACH]
     
    The next post will cover how to set this up...
  7. TheScarfedOne
    Introduction
    This article is a continuation, and update on the changes made since the original article published earlier in the year.
     
    A bit of background to start with… in Summer 2011, I started a big modernisation project at the Academy I took over at. When I started, we were still on Windows XP across the desktops. To take us to Windows 7 presented a problem – the specs of some machines prevented it. I had a significant number of Celeron 1.6’s and 1.9’s. Although I tested Windows 7 on these successfully, the performance once loaded with software was poor. Rethink time.
     
    The Client End
    Following some early work with Microsoft – we got access to Windows Thin PC (Windows 7 Lite). This was perfect for our Celerons – and gave them a new lease of life. Being based on Windows 7, it didn’t take much to have these deployed via System Centre Config Manager.
     
    I also needed a new solution for the Admin machines – which I had just stolen to refresh an IT suite. Here – we used a Wyse terminal solution based on Linux.
     
    The Server End
    The solution… a Remote Desktop environment. This was built from the same Server platform as I used for the rest of my new network. There will be another post on the new network architecture in full. It was summarised in an article here, and more to be published over on the Microsoft Schools Blog (link to follow). This would be the “actual machine” that the users of the Windows Thin PC and Wyse terminals would see.
     
    How is it laid out then? We start with our main HyperV Host server (known as HV3). This contains 4 Windows Server 2008 R2 installs. The virtual machines were stored on my SAN, meaing I could user Clustering. The next step was configuring them to be Remote Desktop Session Hosts, done by adding the Remote Desktop Role from the wizard, and choosing the role service Session Host.
     
    http://technet.microsoft.com/en-us/library/dd736539(WS.10).aspx
    http://technet.microsoft.com/en-us/library/ff710434(WS.10).aspx
     
    Then, I added that HyperV server to the HyperV cluster – which was made up of the other two main HyperV servers for the system (see separate article). This would mean that in case I lost one of the HyperV Cluster Servers, the individual virtual machines could move between the Cluster Servers. The virtual machines were setup to use the HV3 as their preferred server, that way they would move back there if it went offline and came back – and to prevent them moving to the other HVs to often.
     
     
    On its own, this doesn’t give me the Remote Desktop environment. What I wanted is a Pool, so that I can use one name – and the system will work out which of the Session Host servers can handle the load. To do this, I need a Connection Broker. Again, there is a great guide to setting this up here – so I wont repeat it. Essentially – as per the Session Hosts – you choose the service role Connection Broker. Then you add the Session Host servers to the “farm”. You also need a Web Access server – which is incredibly handy, when you think about the VLE needs of a School. Nothing speaks true “anywhere, anytime” like being able to login to Remote Desktop and get exactly the same experience and programs at home as you do at School.
    More great links for this here....
     
    http://technet.microsoft.com/en-us/library/ff710462(WS.10).aspx
    http://technet.microsoft.com/en-us/library/ff686148(WS.10).aspx
    http://aaronwalrath.wordpress.com/2010/05/28/configuring-windows-2008-r2-remote-desktop-farm-with-connection-broker/
    http://www.techotopia.com/index.php/Deploying_a_Windows_Server_2008_R2_Remote_Desktop_Server_Farm_using_RD_Connection_Broker
     
    Connecting the two
    So…that was the core of the Remote Desktop system setup. Next – how to get the clients to connect to it. Well, the Session Hosts were called Site-RDSH, and the farm Site-RDS. Using a locally installed certificate authority, I created a signed Remote Desktop connection for Site-RDS. This had all the options for the sessions themselves in – such as the desktop background, animation, printer and client drive redirection etc.
     
    You may remember from the first article (here) that the Windows Thin PC clients connected to the RDS system via a pre-determined single username. This username auto logged on to the Windows terminal, then triggered the RDS session prompting for the actual username to use the machine. This was OK to a point, except I found some problems mainly around printers. We use PaperCut – and all print jobs would show as my “communal” user rather than the actual user. Hmmm.
     
    Next problem - logon stats were distorted, and it meant that there was always a connection to the system from these machines. Final problem, from the netbooks I had also setup for this system – they would always be triggering the remote desktop before the network was truly ready.
    Rethink time.
     
    What I did was change one of the settings available in Group Policy and on the Session Host servers to take the actual machine logon, and auto logon this username to the Remote Desktop. So – the Windows Thin PC machines would now present a standard Windows logon (and it looks exactly the same as the Windows 7 one) – which the user would enter their details. The same shell replacement as described in the first article is still used – so the RDP file is still triggered. The difference now – it is automatically logged in as the user. Technically, the user logs in twice (once to the physical machine, and once automatically to the RDS) – which you must account for if using any logon restrictors.
     
    The next stages were the printers, which back to front I covered in this article (here)
     
    Any questions or comments, please let me know. Site visits are also possible – I am based in the South West. You can follow me @TheScarfedOne on Twitter too.
  8. TheScarfedOne
    Introduction
    Right... as part of a corporate branding exercise - I have been working on sorting out the email signature front.
     
    Before everyone says it - yes, I know you can do a "sort of solution" on the Exchange server. Im not going to cover that one in this post - as its more designed for Disclaimers. If you want to know more on that - Google "Exchange Transport Rule Disclaimer".
     
    Why not Exchange Transport Rules
    Back to this post - and why I didnt use Exchange server. Well - the one big bug/by design behavior with the Transport Rule option is that it cant work out where the body of a reply or forward is - and therefore can only tag its content to either the start or end of the entire message.
     
    The Solution
    Enter my solution. What I wanted to do was add a customised signature via Outlook and Web Access to all messages. Yes - I know that in theory these could be editted by the users - but I will come back to that one.
     
    Lets start with Outlook. First off, lets get friendly with some scripting. This is Powershell - and you need Windows 7 (built in) or XP SP3 (with Powershell 2.0 addin free download from Microsoft Download Centre).
     
    Create your Outlook Template
    Now - we need to create a kind of template to use. This should be done in Word - and call it CompanyName.docx (replace Company Name with your School name). Create the look and feel you want your signature to have - and yes you can include images! Make sure you use the following keywords: DisplayName, Title, Email, TelephoneNumber, Fax etc..
     
    THis is a bit of a noob thing - but you must ensure these fields are filled out for all users in Active Directory Users and Computers. This is designed to save you time - information in one location.
     
    Put your file on your server under the following path \\domain\NETLOGON\sig_files\CompanyName\CompanyName.docx
     
    Now - here is the script. I cant take any credit for this - other than the find - and confirming that it works like a dream. You will need to edit sections at the top - the variables for your site. It is uploaded here as a txt - save it as a .ps1 file.
    SetOutlookSignature.txt
     
    Source Credit: http://www.immense.net/deploying-unified-email-signature-template-outlook/
     
    Group Policy Fun
    Next, you need to get busy with Group Policy. Two things we need to do - one assign our script. Thats under User Configuration > Policies > Windows Settings > Scripts > Logon. Another caveat here - which I should have mentioned earlier. You NEED to be Server 2008 R2 really for this. On the Scripts dialog, you have a second tab "Powershell". Click Browse - and copy your script to this location (which will be a folder within Sysvol.....GUID....Scripts/Login. This is really important. Powershell is so damn powerful that Microsoft have built in a load of protection. By default, unsigned scripts cannot run, and ours certainly isnt! But, by putting it here - it will run safely.
     
    So... Thats done. Next - to lock down Outlook to prevent users fiddling with Outlook settings. Sadly, the Office 14 ADMX files (free download from the Microsoft Download Centre) do not give you check boxes to disable features. We have to know the IDs of the controls we want to disable.
     
    These are... 5608, 14014, 11323, 21553, 5611, 14823, 12305, 16182, 13991, 12245, 12680, 12863, 12681, 12864, 2087 and you put them here Microsoft Outlook 2010 > Disable Items in User Interface > Custom
     
    Outlook Web Access
    Onto OWA. Yes you can get to the Signatures here as well - under Options. Thankfully - you can prevent access to it via Web Access policies in the Exchange Management Console. But - again, with a little bit of Powershell on the server, we can ensure that a signature we want is set there too - for when your users send email from there.
     

    $mailboxes = Get-Mailbox $mailboxes| foreach {$file= "C:\signatures\" + ($_.alias) + ".html"; Set-MailboxMessageConfiguration -identity $_.alias -SignatureHtml "$(Get-Content -Path $file -ReadCount 0)"}
     
    Source Credit: http://blog.exchangegeek.com/2010/08/manage-owa-signatures-using-powershell.html
     
    Now - one problem with this - you need to have pre-created an HTML signature for each user, and as per the script as is - located it in C:\signatures; issue! So, how to fix that...
     
    Well, that will be the subject of my next post - and as a teaser as to the fix, think about what the first Outlook bit is doing! If i can sort out a small prize for BETT, this will be awarded if a member can come up with what the answer is (which is already part written as my next article). Bear in mind - Ive already implemented this....
     
    Questions and comments welcome :-)
  9. TheScarfedOne
    Introduction
    So, regular readers of my blog will know that we run quite an extensive Remote Desktop Environment at my new School. This poses for some interesting issues when dealing with printing - so a rethink on the traditional methods was needed.
     
    Traditional Printer Scripting
    Lets start at the beginning - with the "old-school" method of printer mappings. Usually, this was achieved with a good old-fashioned batch script, ala Drive Mappings. Not content with batch anymore - I moved this on to VBS for speed. Ive attached my main script to this post for a nosey; but below is an except...
     

    Add printer connections dependant upon location Select Case (Left(computerName, 6)) Case "******" WshNetwork.AddWindowsPrinterConnection "\\PRINTSERVERNAME\PRINTERSHARE" WshNetwork.SetDefaultPrinter "\\PRINTSERVERNAME\PRINTERSHARE"
     
    This does as it says really. It compares the first 6 characters of the machine name (retrieved and stored in a variable earlier in the script) to a specified statement. When it matches, it runs that section. See the full script for more (the logoff one in there too) - it is well commented!
     
    WorkstationPrintersLogoff.vbs
    WorkstationPrinters.vbs
     
    This works fine for normal workstations - where it runs as a logon script. There is also a partner logoff script which clears the connections to stop them following the user around. The last thing we need is Student 1 printing in IT2 when they are in IT1 - just because they have been in IT2 last lesson.
     
    So, what about Remote Desktop Services
    But - this wont work with RDS - as the machine is resolved as the server, and there could be multiple locations with different printers. In our case, there definately are. Our Thin Client (RDS) environment is made up of two types of machine. We have repurposed hardware running Windows Thin PC (Windows 7 extra light!), and Wyse T50 terminals running their "HomeBrew" linux.
     
    The Thin PC ones use a similar script setup to the conventional PCs. The only difference is that the printers are added on startup - since the shell for the Thin PCs has been altered to load VBS and RDP session. More on that will follow in another post - but it is touched on slightly in my SCCM posts from Summer: http://www.edugeek.net/blogs/thescarfedone/871-some-things-field-sccm-saving-my-bacon-massive-system-deployment.html
     
    The RDP session is set to carry thought client printers (there is a custom RDP connection file used on all of the Thin PCs) - so they get the printer for their room and no others. The ability to add and remove printer has also been removed across the site. Well, there is no point putting the effort into setting the printers is people can monkey with them!
     
    Non-Windows Remote Desktop Connections
    Next then, the Wyse terminals. More problematic, as they wouldnt understand any of the scripts or GPOs. Instead, some clever GPO and OU layout - and use of the GPO Mode "Replace" to set user properties for the RDP session were used. You can see my structure here...

     
    The "TS" after the GPO name is the magic. These two GPOs have extra settings to push printer connections for the RDP sessions. Problem number two - how to work out what machines get what printers, or you just have all of them and users select theirs. Messy - very messy. Instead - group your users around printers - which they need, defaults etc. We created AD groups and put staff into these groups depending which they needed. Then, used Group Policy Preferences (not Deployed Printers) to set them. Preferences allows you to do item level targetting so only people in the AD group specified get the printer. Here is an except...

     
    Here is the actual GPO editor - so you can see we have lots of printers and lots of targetted printers. We also use this to set the defaults for different groups. You can see we also use a "Delete All" to stop them collecting printers.

     
    Job done... :-)
    Happy GPO Admin
     
    As always, questions, comments always welcome. Post here or PM me if you want to know more.
  10. TheScarfedOne
    I use roamin profiles - and I know that people have their own views on using them, so no flaming please! I use it for all users, and combine it with folder redirection to for speed and efficiency.
     
    Here is an outline of my setup then... and some links to getting it set up the same way if you are so inclined.
     
    All userdata is stored on SAN paths, mapped through DFS. But, but could have this on single servers equally, and it would work just fine. The root path is \\DNSNAME\Network\, with paths off this for home folders, profiles and redirection. A great Microsoft Article from the Directory Services team gives you the lowdown on how to get this set up, so rather than just repeat all of it - here is the link...http://blogs.technet.com/b/askds/archive/2008/06/30/automatic-creation-of-user-folders-for-home-roaming-profile-and-redirected-folders.aspx
     
    Right... so youve got that all set up just nicely then, but someones profile gets corrupted? You go and delete the folder (yes the whole folder - do not just delete the contents or you will get a "Temporary Profile" message). Sorted... wrong, becuase this is a member of staff - who has a laptop. Laptops are set to cache logons, unlike workstations - so that they can logon offline at home. So you go and delete the folder there too. Youve done all this correctly, but you still get the "Temporary Profile" warning. What has gone wrong?
     
    Vista and 7 store the profile paths in the Registry, and going in and deleting the folder remotely doesnt clean this up. If you logged on Locally, and used the Advanced User Control Panel to delete the profile and it would be fine.
     
    To manually tidy up, follow the below...
     
    1.Fire up regedit (yes you can do this remotely too - Connect Network Registry)
    2.Locate the following registry subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
    3. The ProfileList entries are all SIDs. This is a placeholder for the security identifier (SID) of the user account that is experiencing the problem. The subkey should contain a ProfileImagePath registry entry that points to the original profile folder of the user account that is experiencing the problem. Delete the subkey for the affected user.
    4.Exit Registry Editor.
    5.Log off the system.
    6.Log on to the system again.
    7.After you log on to the system, the profile folder is re-created
  11. TheScarfedOne
    Hello again! This one wanders off into slightly differenet territory for my normal blogging - but its one Ive had lots of questions about recently. Its also been a fairly busy one on the forums too, so here is a reasonably definative guide on how to get it working properly...
     
    1. Create a server side copy of your structure
    Sounds simple, but how many times this isnt done properly never ceases to amaze me. Now, some poeple I know wont like what Im about to recommend, but trust me - there is a very good reason.
     
    in your NETLOGON folder (\\DomainNameHere\NETLOGON) create a folder called Environment. This will be our nice handy root folder. Why netlogon? Well, first off - it has permissions on it so Domain users and Domain compuers can read it but not mess with it; second, it gets load balanced and sync'd between however many DCs you have. No single point of failure. Now, I know you can craete your own DFS (Distriburted File System) to do the same thing, but there really is no need for most systems. The files you will have in this folder are shortcuts - and are tiny anyway.
     
    Right, in ENVIRONMENT, create Staff and Student subfolders, and then StartMenu and Desktop subfolders within those. You will also need a Programs folder in StartMenu (StartMenu rather than Start Menu - better not to have spaces).
     
    Copythe various shortcuts you want, and create your Desktop and Start Menu as you want them to be (I have only said about Staff and Students, but you could do this for as many other user groups as you want - you will just need extra subfolders).
     
    2. Create your GPO Settings
    This one is where people sometimes have issues. Usually, you will have a GPO for Staff and another for Students. I will assume here you do. If not - create them for this purpose.
     
    The settings, in the main are identical. The only difference comes at the folder reference part. For speed - I have included a screenie below of the settings I have used in my previous Schools, as well as at those I have been across to to set this up. You may not want to be as restrictive - the choice is yours.
     

     

     
    Then, you need to actually point at your desktop and start menu folders. This is done at User Configuration > Policies > Windows Settings >Folder Redirection > then right clicking the object to redirect and selecting Properties. Choose Basic—Redirect everyone's folder to the same location, and then select Redirect to the following location. Enter your path. Now, you have two options here. I personally redirect to a local copy of the structure I have on the Server. This is maintained by a Startup Script. This I will cover in a 2nd part to this article, including the script used. Alternatively, you can point to the Server path. Note, for Start Menu, do not go down to the Programs level - your path would be \\DomainNameHere\Netlogon\Environment\StartMenu
     
    Then, you must go to the Settings tab. In the Settings tab in the Properties box for a folder, you should change these settings:
     
    Grant the user exclusive rights. This setting is enabled by default and is not the recommended setting for here. Usually, yes, but we dont want to lock others out of it (particularly on the Server sharing scenario)
     
    Move the contents of [FolderName] to the new location. This setting moves all the data the user has in the local folder to the shared folder on the network. We definately dont want this either
     
    Also apply redirection policy to Windows 2000, Windows 2000 Server, Windows XP, and Windows Server 2003 operating systems. This enables folder redirection to work withWindows 7 and Windows Vista, and earlier Windows operating systems. This option applies only to redirectable folders in earlier Windows operating systems, which are the Application Data, Desktop, My Documents, My Pictures, and Start Menu folders. You will want this setting.
     
     
    3. What often goes wrong
     
    Right, the setting that causes this not to work! The one to watch is
    User Configuration > Policies > Admin Templates > Start Menu & Taskbar > Remove User's folders from the Start Menu - this needs to be DISABLED for Windows 7. On XP, it should be Enabled. So... yes - in co-existance you will need two policies, and to use security group filtering to ensure Staff applies to Staff, and Students to Students. Alternatively, careful use of the "Apply to OS" setting can also do this. I will cover this scenario in more detail in Part 2.
     
    Hope this helps - and the screenshot will be added on Monday!
  12. TheScarfedOne
    Ok, so - some of you have tried to put this in place and have not had much luck with it. I use this one a lot, as it saves additional software - and it is just nice to have everything all in one place.
     
    How to do it properly then...
     
    1 Create a NEW GPO... yes I said new. Don't go adding this to exisitng ones as when you want to change the time for different machines - you will be stuffed (well you could use item level targetting -but thats a bit out of the reach of this post)... and the second reason is more important though. For some reason - when you use GPO Scheduled Tasks - it breaks GPMCs way of showing the settings in that nice little HTML pane. At least if it is just these in there, you dont really need it.
     
    2. Computer Config > Preferences > Control Panel Settings > Scheduled Tasks
     

     
    3. Right Click, New Task - and complete a la
     

     
    4. Repeat as required - we have our machine set to wake on BIOS - so that is why there is a Weekday and Weekend Shutdown - the Weekend shutting down at 9.30am.
     
    Enjoy :-)
  13. TheScarfedOne
    So, as you will have gathered from my recent blog posts... there is some serious systems change happening at my place!
     
    Quite simply put - without SCCM and Windows Thin PC, there is no way I could have got it done.
     
    THat being said... there were a few times I was pulling may hair out with it! So, this post is a heads up on what might go wrong... and in no particular order...
     
    1. Error 8004005 - Cannot retrieve policy for this computer and a reboot before even getting to task sequence choices in OSD. THis pain is often caused by an incorrect Network Access Account, or in my case - the account had got locked out. Grrr! For info - 8004005 generally means access denied so go on the permissions and account checking (or in packages, DP checking)...
     
    2. SCCM Client not installing Error 1635 in Windows Event log. This one comes up when, like me you are trying to integrate the R3 (or any other Client updates) hotfix into your OSD task sequence. This was a head scratcher, but was fixed by changing the properties of the step in the task sequence. The correct property is PATCH="C:\_SMSTaskSequence\OSD\<PACKAGEID in SCCM>\i386\hotfix\KB977384\ sccm2007ac-sp2-kb977384-x86-enu.msp"
     
    3. FEP via OSD - by default, this one will bomb your TS. And just when you think youve fixed it, unless you update to Update Rollup 1 - then your Windows Thin PCs will bomb as well! So... the fix...! Firstly - update to UR1. There is a pre-requisite, and then the UR itself is made up of three separate updates. Link here: http://blogs.technet.com/b/clientsecurity/archive/2011/06/28/forefront-endpoint-protection-2010-update-rollup-1.aspx
     
    Next, create a new program in the deployment package. The program is "FEPInstall.exe /s /q" (without the quotes). I know thats not what it says on this article (http://social.technet.microsoft.com/wiki/contents/articles/how-to-deploy-the-fep-2010-client-via-osd-and-test-deployment.aspx) but it doesnt work if you do that - not on UR1 anyway! Also - very important... the Program name is InstallFEPviaOSD... or no default policy.
     
    Thats it for now... well tomorrow... when i will add a few more gotchas - but I dont have all the details to hand. Hope this helps...
  14. TheScarfedOne
    Couldnt quite work out what to call this blog post - as it ties so many different areas in together.
     
    As Ive written about before - Ive been busy doing a mass upgrade and virtualisation project at my new place. First step was getting the HyperV hosts all set up. That was a breeze, as was the SAN - all bar a bit of waiting whilst it all initialised.
     
    Once that was done, it was time to get the roles onto each of the nice new HyperV Clients. An SQL cluster, a pair of SCCM servers, and Forefront Endpoint on one of the SCCM boxes too.
     
    SCCM went on fine, as did SQL - nothing to see here. FEP however... more of an issue.
     
    For those also playing with clustering, or just FEP in general - here are the setup gotchas!
     
    1. SQL Reporting Services
     
    Make sure that one of the SQL Nodes has SQL Reporting Services set up, and initialise its database. Point your FEP install at it - not the Cluster. The DB still points at the Cluster though.
     
    2. SQL Server Prerequisite Error
     
    This looks like:
     
    "Setup cannot verify the service principal name (SPN) for this account. Ensure that there is a single valid SPN entry for this account in the Active Directory Domain Services.
    Account: Yourdomain\accountname"
     
    And to fix it...
     
    Launch an elevated CMD Prompt and use the following...
     
    setspn -a mssqlsvc/NODE1FQDN Domain\ServiceAccountname
    setspn -a mssqlsvc/NODE2FQDN Domain\ServiceAccountname
    setspn -a mssqlsvc/NODE1 Domain\ServiceAccountname
    setspn -a mssqlsvc/NODE2 Domain\ServiceAccountname
    setspn -a mssqlsvc/CLUSTERFQDN Domain\ServiceAccountname
    setspn -a mssqlsvc/CLUSTER Domain\ServiceAccountname
     
    3. Pending Restart
     
    This one is a real pain. You restart, as it sayis, but the more stranger thing happens after you restart your computer and start the Setup again. The same is displayed. Why? Well, maybe because on the FEP 2010 requirement is to have a working Configuration Manager 2007 infrastructure and almost always ConfigMgr will have open files and read/write operations on the computer you’re trying to install FEP 2010.
     
    So, to workaround this problem you have to modify your registry (do it on your own as I did). Open PendingFileRenameOperations key from HKLM\SYSTEM\CurrentControlSet\Control\Session Manager and delete or copy its content to a notepad. Save the key and start Setup now, it should work, at least it for me.
     
    Hope this helps
     
    Stuart
  15. TheScarfedOne
    OK - so some of you now know I moved on from my last School - where I was very vocal with Sharepoint and later SCCM.
     
    Well, now at my new Academy - we are going to get down and dirt with virtualization as well. You may have seen my last post about SCCM and AppV; and also Windows Thin PC - which is part of the story, and also our testing and QA process.
     
    Whats going in then? Well, to sort out the underpowering on the Server side - incoming 2 x Dell R710s with 300gb Raid and 128GB RAM; and an MD3200i with 8 x 2TB SAS yet to decide on the arrangement on there - but there will be separate VHD storage, SQL Stream and User Data storage.
     
    This will be used to virtualize the Server Platform. Exchange will go onto it (splitting DB from CAS - currently single server) and being upgraded to 2010 SP1 at the same time from 2007. SCCM will go over too. Currely single server from our testing and QA - but its a simple migrate; it will also become a two server platform. SQL will be clustered - hosting SCCM, Forefront, SIMS, Eclipse and TMG databases. It will also later hold Sharepoint databases too - but that one will be setup towards the end of the summer - again a two server structure. DFS for User Data access will move off the two physical DCs, leaving them to do just DC work. There will also be a RDS Farm for the Thin Client system - which I will come back too. Also moving onto the virtual platform will be the Runtime software share and your old style Staff/Student shares. These will go DFS too, with replication.
     
    Thin Client then... two different ways being used. The Windows THin PC section - reusing some older equipment namely some Celeron 2.6 RM Ones, and IBM SFF ThinkStation Celeron 2.9s. Runs nicely. Then, for our Admin section - Wyse T50s, some dual screened. The T50s come with the VESA mount kits and will be attached to the back of the TFTs.
     
    On the dual screening - heres how:

     
    I didnt know that!
     
    Anyway, wish me luck! Oh, and the whole platform for the site is moving to Windows 7 too. System Centre will be doing that upgrade for me though, easy peasy! And app installs are a dream, as most of my apps are actually AppV apps. Helps as my RDS servers then wont actually have the apps installed on them either!
     
    Questions and comments always welcome
  16. TheScarfedOne

    Software
    So... Windows Thin PC (Windows Embedded Standard 7 - for its full name really) is now out, whats the story?
     
    Its the replacement for Windows Fundamentals for Legacy PCS... ie its a cut down version of the current Windows OS, designed for older PCs to make them last a bit longer. You can use it to make a "Think Thin Client"... ie Autologon, start an RDP session and thats it.
     
    And thats exactly what Ive done with it.
     
    So, hows it all set up, and what do I think of it? Well - it installs in the same way the full Windows 7 OS does. For us here, that means SCCM. Created a capture image from the original media in the same way you do for the full OS (see earlier blog posts for guidance)... created a task sequence to deploy it - it is exactly the same as my main Windows 7 one - minus the core software. Why you might say? Remember, this machine is going to be a dumb terminal.
     
    Then, Ive ammended some of the scripts used for deploying my Laptops with Bitlocker. What does that have to do with WTPC? I needed the machine to be configured to autologon for a start! We dont want people having to logon twice! So, all the machines are set to autologon with a restricted network account (in our case called RDPService) - and then the shell has been changed from explorer.exe to mstsc.exe. This makes it run in kiosk mode effectively, there is no taskbar, desktop or anything that can be fiddled with!
     
    Just to make doubly sure, Ive used an app called Shelly to launch mstsc as an unkillable process. If it closes, it is just respawned.
     
    This system is going to be used in Admin, General purpose ICT rooms (ie those without high GFX needs)... even tho the Remote FX available by using this with RDS in Server 2008 R2 make it pretty good! Prodesktop even works well as does CS5.
     
    Ive uploaded the script here, which you need to add as a package in SCCM (or to an accessible folder eg NETLOGON) and then point to it as a Run Command Line in the Task Sequence. Put a reboot after it, and the machine with then autologin and do all the rest of the jazz. Shelly and your RDP file must be in a folder called RDP at the root of C:\. This can be achieved by GPO Preferences under File.
     
    Any queries... fire off a comment below...
     
    Updates to this original post... we now use Shelly (as described here http://www.insidetheregistry.com/content/viewarticle.aspx?articleid=1722) to handle the RDP shell replacement.
  17. TheScarfedOne
    Laptop House Education Show: 17th June 2011
     
    After a break of two years, it was time for these guys to have another Trade Show. Like last time, they didn’t disappoint! So, first for a bit of an intro…
     
    Laptop House are an independent IT equipment reseller founded in March 2002; and based just outside Stoke on Trent. They are able to supply major brands including Dell, HP, Toshiba, Acer, Sony, Apple, Fujitsu & IBM, Promethean, Bretford, Smart and many more.
     
    Also on offer are additional services, such as Installation, leasing facilities and insurance cover for "ALL" your IT products including any special projects. A combination of "First Class" service (with next day delivery as standard) have earned a reputation for excellence, receiving regular referrals from satisfied customers and now have a client base throughout the UK, extending to almost every county and still ever growing.
     
    Right… onto the show itself. With Laptop House being a partner with HP and Acer – there was a good presence from them. Of particular interest was HPs Thin Client range. Through their links, Ive set up (or will hopefully be setting up) evals of the kit for my own virtualization project. And that’s the great thing – its being seen as a project, and getting the full backing and support of the HP specialists.
     
    Acer meanwhile were showing off their new tablet range; and looking at the options with their ever growing Veriton PCs – including the newer small form factor and the NetTop Boxes. It shows the view from Acer of the event when the UK EDU Manager was there, and brilliant she was too.
     
    Both Acer and HP have started OEM-ing NetSchool recently, as you may have read on the forums. Well, they also had their own stand, with tech and sales support staff present. Very useful discussions on how to quickly and easily get the product (whether it be the full one, the lite that HP supply or the ACM version that Acer use) onto your system. They also had a presentation slot on getting the best from the product.
     
    Samsung were demoing their ultra portable laptop range, as were MSI. Great to see the moves in the market these guys are making – and giving good pricing support to education too.
     
    Sonicwall were demoing their appliances, as well as giving a presentation on using it and the risks of network and internet security. A mover in the market Ive not seen before – but interesting all the same. I can see this territory being more relevant where Academies move away from their RBC for internet provision.
     
    There were others present too – some which I will have forgotten to mention, so apologies to them. As usual, the Laptop House staff themselves were on top form – including the chance to meet the family! All those in EduGeek conferences know how dangerous meeting the family is (legendary still is @littleMiss from BETT2011).
     
    So… all that remains is to thank Angela (MD) and my account manager (Mat) – and the rest of the team for a great day. The contacts from the day are already helping – and its only Monday!
     
    Ooooh, I almost forgot to mention the food! Thanks also must go to the caterers for the Hog Roast; and to Angela and her mum for the supply of cakes and drinks.
     
    Contact details:
    http://www.laptophouse.co.uk
    01782 838883
  18. TheScarfedOne
    Ok, so after I left you all wondering on the AppV score - I thought it was about time to show where we had go to...
     
    Well - progress is good, very good! AppV (as if it needed any more ranting and raving) is a seriously cool piece of kit. Take this one problem... using CS4 on out ICT Suite machines and to bring in CS5 would bring a learning curve for staff and students alike. Well, what if you could run the two side by side. Normally, not a chance, but with AppV you can. CS4 sequences rather nicely (think of sequencing like packaging), CS5 is still full install at the moment. So - both can run on the machines independantly of eachother - everyone is happy.
     
    Digital Blue is also sequenced up too. Why... well it can be a pain of a bit of software, so to separate it from the OS makes life a lit easier. Same applies to DLK MathsWorks. Anyone who has come across that gem will know what I mean.
     
    So you see, you can use it for co-existing software versions, pain in the behind software, and in the case of Office 2010 - software which is just slow to install.
     
    Office 2010 has some gotchas tho - mainly in that its Licence protection is its downfall. Never fear though - MS have done their homework on sorting it (as you would expect)... and here is how to do it...
     
    http://support.microsoft.com/kb/983462
    and the support files are
    http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=10386
     
    Its very well explained... just click along :-)
     
    For those interested... full list of main Apps sequenced so far...
     
    Office 2010
    Adobe CS4
    Audacity
    Digital Blue
    Adobe Reader X
    DLK MathsWorks
    Media Player Classic
    CamStudio
     
    and there are other departmental ones (I will update with those)
  19. TheScarfedOne
    So, yet again I find myself starting my blog with "Ive not written in ages, and here's why..."...!
     
    Well, first off - Ive moved workplaces. A number of you will already know that - but this blog is going to concentrate on essentially the setup of a new network on the side of the old one!
     
    Why did I move on? Well, after 5 years, all that could be achieved had been - and the system which Id written from scratch (ably assisted by my senior) was in a good state ready for someone else to take on and do the next phase. I also wanted to move closer to home, although it was only a 30 min compute each way - that pales into insignificance when I can now walk to work :-)
     
    Onto the nitty gritty of my "new" old system! 5 Servers - mostly 2008 R2, a juicy SAN for data storage and thats about it. The usual suspects of Exchange and the XP / 7 (to a lesser extent) combo. Remote installs by FOG. ISA for filtering and access to Webmail. Frog (underused) for a VLE and thats it on that score.
     
    Workstations - lots of them, over 600! Mix of IBM, RM Ones, Acer Veritons and some custom SCL things. None of it too shabby, but in need of some TLC. Laptops is a bit more of a problem.
     
    So, the plan...
     
    Everyone knows Im an SCCM fanboy - and it was no surprise that it was one of the first things to come in. Handy that Id recently finished doing 7 - so Id already got all the bits I needed :-). New this time though was playing with AppV. With it being built into R2 SP2 - and there being big job on to repackage lots of apps (or put them into a single central "runtime from server" share) - it made sense to look at sequencing.
     
    Guides for doing this by the way...
    http://technet.microsoft.com/en-us/magazine/2008.10.appv.aspx
    http://caloni.wordpress.com/2009/03/07/app-v-integration-with-sccm/
    http://blogs.msdn.com/b/steverac/archive/2008/12/22/deploying-virtual-apps-with-sccm.aspx
     
    Read and follow those to the letter (and Id strongly advise having a VMWARE Player SCCM 7 Build to hand for it) and you will have it basically working in about 20mins :-)
     
    Its seriously powerful, and the bonus is that you deploy the virtual apps in the same way as the physical ones. No faffing required! Just think... rather than a 10-15min Office 2010 install as part of your task sequence... use one of the Accelerators (some useful ones here: http://gallery.technet.microsoft.com/site/search?f%5B0%5D.Type=RootCategory&f%5B0%5D.Value=App-V&f%5B0%5D.Text=App-V&f%5B1%5D.Type=SubCategory&f%5B1%5D.Value=PackageAccelerators&f%5B1%5D.Text=Package%20Accelerators&pageIndex=2) and you can cut that right down by virtualizing it!
     
    So, once SCCM is in, and building machines to a new OU on the domain - what next...
     
    Intranet time! Sharepoint makes sense (I know Frog is here, but word has it that it wont be here for long) - and we are in desparate need of an intranet for collaboration and external access. Even just to do electronic forms...
     
    Next... workstations. Well, the RM Ones are the original version, the Celeron 2.6 ones. Not too bad - will run 7...slowly, but idea for use as thick "thin clients". As soon as I can get my mits on Windows Thin PC (replacement for Win FLP) - its getting put on them by.... you guessed it SCCM! Some grunt of new Virtualization Server Hardware (3 x R710s and 1 x MD3200i) will do the trick on that front. Looking at getting some proper thin clients too for admin, to cut costs and make best use of the hardware we have. Intel Core2Duo for admin is a little over, when Ive got one ICT suite I need to replace (Cel 2.6)...
     
    On the servers front.... some to server hardware (as above) to be used for... Hyper V with some Terminal Servers (for thin client, maybe MultiPoint [for the classroom] which has my interest), Exchange 2010 (upgrade the current 2007 version), Software Servers and leave the two current physical servers which are connected to the SAN (doing User Data and DC work [eeek!]) to do just DC.
     
    Laptops... will come back to those later - but if youve seen my previous posts on Windows 7 and Bitlocker, I think you get the picture.
     
    I think that gives a good overview of whats going on - the main thing being playing with AppV with SCCM :-)
     
    Any questions on SCCM, AppV...PM or email :-)
  20. TheScarfedOne
    Microsoft Recently released a Service Pack for Windows 7 and it has worked fine until it has been made available via WSUS/Windows Updates for Automatic Install. It has been known to cause a few problems where the system has halted upon startup with a Fatal Error as shown below:
     
    Fatal Error C0000034 applying update operation (Update 282 of 103814)
     
    Many people have turned to re-building the system but there is a fix to getting the system back up and running and it is as follows:
     
    1) When your computer starts up, choose the option "Launch Startup Repair"
     
    2) When the Startup repair starts, click cancel.
    3) After you click cancel it will show a box. Click "Don't Send"
    4) Click the link "View advanced options for recovery and support
    5) You may be asked to authenticate as the local administrator
    6) In the new window click Command Prompt at the bottom.
    7) In Command Prompt type this and press enter: %windir%\system32\notepad.exe
    Notepad will open. In notepad go to File-->Open.
    9) Change the type of files notepad views from .txt to All Files
    10) Now in Notepad, go to C:\Windows\winsxs\ (or whichever drive Windows is installed on)
    11) In that folder, find pending.xml and make a copy of it
    12) Now open the original pending.xml (It may take a short time to open as the file is fairly big, also editing you may find the process a bit slow but be patient)
    13) Press CNTRL+F and search for the following exactly: 0000000000000000.cdf-ms
    14) Delete the following text (you will find it may appear a bit different on your file)
     
    <Checkpoint/>
    <DeleteFile path="\SystemRoot\WinSxS\FileMaps\_000000000000000 0.cdf-ms"/>
    <MoveFile source="\SystemRoot\WinSxS\Temp\PendingRenames\e56 db1db48d4cb0199440000b01de419._0000000000000000.cd f-ms" destination="\SystemRoot\WinSxS\FileMaps\_00000000 00000000.cdf-ms"/>
     
    Your PC might not have all 3 sections of code (<Checkpoint>, <DeleteFile>, <MoveFile>). Just make sure you delete section "Checkpoint" and whatever other sections have "000000000000000.cdf-ms". They will be right next to eachother.
     
    15. Save the file, close notepad, close command prompt, restart your computer.
     
    Once your computer starts up, do a normal startup (it may stall for 5-10 minutes at the "starting windows" screen, but leave it going) and the Service Pack will install some more stuff and restart a few times and then everything should be working! For some people, it reverts everything and cancels the service pack installation. For other people, the service pack installation completes. Either result is fine.
     
    Thanks to EduTech for the original post, but I was also in the middle of writing this having come across it and fixing it last night too!!
  21. TheScarfedOne
    Ok, something we are just about to implement - Password Policies for Staff. However, I hear you cry, you can only have one policy per domain - the "Default Domain Policy GPO". Yes - pre Server 2008 that is true...
     
    With Windows Server 2008 you will now be able to define different password account lockout policies within the same domain. Previously this was not possible and this was also one of the reasons many of our customers implemented multiple domains in their forest. With Fine-Grained Password Policies you can assign different policies to users (individually if you want) or groups.
     
    Its in there, but minus a GUI to configure this and you need to use the ADSIedit to create, manage and set the password policies. This is a bit of a pain, as its not the most friendly of beasts - and a licence to break things if you arent careful. If you want to go play the ADSI way, Kurt Roggen has blogged on it HERE.
     
    Me on the other hand, would rather not. There are some community released nifty tools where you can manage the policies through a GUI, command-line or even by using PowerShell.
     
    Some of the best...
     
    Christoffer Andersson's Fine Grained Password Policy Tool (inc some Powershell snap ins)
    http://blogs.chrisse.se/blogs/chrisse/archive/2009/01/11/fine-grain-password-policy-tool-1-0-2300-0-rtm.aspx
     
    Dmitry Sotnikov's Fine Grained Password Policies POWERGUI
    http://dmitrysotnikov.wordpress.com/2007/06/19/free-ui-console-for-fine-grained-password-policies/
     
    Joe Richards (MVP) PSOMgr
    http://www.joeware.net/freetools/tools/psomgr/index.htm
     
    Enjoy!
  22. TheScarfedOne
    OK - I know SP1 is now out - but in case you havent applied it yet, and arent going too - watch out for these two...
     
    Note - These are supposed to be rolled into SP1, supposed to be!
     
    Issue 1: If your Windows 7 or Windows Server 2008 R2 stops responding at the “Please wait” screen before you are requested to press Ctrl+ALT+DEL.
     
    Lets say you try to start a computer that is running Windows 7 or Windows Server 2008 R2.
     
    However, the operating system stops responding at the “Please wait” screen that appears before you are requested to press Ctrl+ALT+DEL.
     
    Therefore, you cannot log on to your Windows computer.
     
    In such a case download and apply Fix314380 from KB983551.
     
    This issue occurs because an auto-start service remains in the pending mode for too long and cannot start during the Windows startup process. This is caused by a deadlock that occurs because of an interaction between Windows Error Reporting (WER) and AppLocker.
     
    Issue 2: Folder Redirection
     
    If you get a blank desktop or start menu (or both) but you know your folder redirection is working/set up properly... run the following. It clears out the KnownFolders section of the registry which have got broken.
     

    strKeyPath = "CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}" oReg.DeleteKey HKEY_CLASSES_ROOT, strKeyPath strKeyPath = "SOFTWARE\Classes\CLSID\{031E4825-7B94-4dc3-B131-E946B44C8DD5}" oReg.DeleteKey HKEY_LOCAL_MACHINE, strKeyPath strKeyPath = "SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5}" oReg.DeleteKey HKEY_LOCAL_MACHINE, strKeyPath strKeyPath = "SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2112AB0A-C86A-4ffe-A368-0DE96E47012E}" oReg.DeleteKey HKEY_LOCAL_MACHINE, strKeyPath strKeyPath = "SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{491E922F-5643-4af4-A7EB-4E7A138D8174}" oReg.DeleteKey HKEY_LOCAL_MACHINE, strKeyPath strKeyPath = "SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7b0db17d-9cd2-4a93-9733-46cc89022e7c}" oReg.DeleteKey HKEY_LOCAL_MACHINE, strKeyPath strKeyPath = "SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A302545D-DEFF-464b-ABE8-61C8648D939B}" oReg.DeleteKey HKEY_LOCAL_MACHINE, strKeyPath strKeyPath = "SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A990AE9F-A03B-4e80-94BC-9912D7504104}" oReg.DeleteKey HKEY_LOCAL_MACHINE, strKeyPath
     
    Standard rules apply, YMMV.
  23. TheScarfedOne
    That time of year again (well - for us anyway), after doing a load of machine rebuilds - and name changes etc - your AD may look a bit cluttered. Even more so as we moved from using RIS (groan - old tech alert) to SCCM...
     
    So - rather than resurrect some old threads, here is a collection of highly useful powershell scripts to hunt out those old computers and remove them or move them to another OU so you can spot them all together.
     
    Credit to original posters: Boz_l and Rabbieburns
     
    For this, you will need to install and run the Quest Powershell console.
     
    Quest AD Cmdlets are free to download from PowerShell Commands (CMDLETs) for Active Directory by Quest Software
     
    GOTCHA: these commands do not seem to run in the standard shell even with the cmdlets installed. A bit like exchange 2010 seems to need its own shell.
     
     
    Outputs to shell console:

    get-qadcomputer -IncludeAllProperties | Where-Object { $_.lastlogon -lt (get-date).AddDays(-90) }
     
     
    Outputs to csv:

    get-qadcomputer -IncludeAllProperties | Where-Object { $_.lastlogon -lt (get-date).AddDays(-90) } | select-object Name, ParentContainer, Description, pwdLastSet | export-csv c:\outdated.csv
     
     
     
    Moves to alternate OU:

    get-qadcomputer -IncludeAllProperties | Where-Object { $_.lastlogon -lt (get-date).AddDays(-90) } | Move-QADObject -to my.corp/obsolete
     
    Tack this to the end to disable the accounts:
     

    | disable-QADComputer
     
    Check Locate obsolete computer records in AD « Dmitry’s PowerBlog: PowerShell and beyond for more.
     
    And QAD cmdlets reference - PowerGUI Wiki
     
    Enjoy :-)
  24. TheScarfedOne
    OK, I know the "old" XP version of Movie Maker wasnt the best - but as far as quick (ish), easy, and user friendly and FREE movie editting goes - it ticked the boxes. It also follows all the rules for Group Policy etc with no irritations unlike some commercial offerings.
     
    Problem, Microsoft upset the EU Anti Trust bods, so no longer is it in newer versions. Ok, no biggy - lets use the new "Live" version. Er... no - its full of "Live" links and upload and signin rubblish. We have a sitewide ban on use of any of the "Live" services - incident with Messenger.
     
    Problem then, other free options I thought. Pinnacle's free one looked ok, until I installed it and saw it was littered with trial and upgrade bits.
     
    Grrrr, so just on the off chance I thought Id give google a quick whizz. Glad I did, and I hope this post saves you a lot of hassle! First point of call was this one - where we could compile and build our own Win 7 Package.
     
    http://www.sevenforums.com/tutorials/35151-windows-movie-maker-6-0-install-windows-7-a.html
     
    Then, this genius (and I can take no credit other than for finding and posting) went and released it all pre-done. Works a dream - and cos we use SCCM, out onto all my machines silently it does indeed go!!
     
    http://noeld.com/programs.asp?cat=video#wmminst
     
    Enjoy, and save yourself some hassle!!
×
×
  • Create New...