Jump to content

Duke5A

Members
  • Posts

    1,598
  • Joined

  • Last visited

Everything posted by Duke5A

  1. Are you certain the install WIM has the storage drivers? Import the storage drivers from that WinPE pack into the WDS console and give it another go. If not it might be something to do with the disk configuration in the answer file.
  2. I'm using WDS in my basement because it's that easy. As long as you have a 1Gb switched network and a Windows Server install somewhere. Right-Click add drivers to the console and various install WIMs. If you're absolutely set on using USB sticks then use Rufus to transfer an ISO to it and make it bootable. Inject your drivers via command line DISM into the install WIM. I seem to remember someone sharing a GUI frontend for DISM here that made things pretty easy.
  3. We run a Google domain with directory sync against our AD and also use onsite Exchange. When it was first setup we didn't really care about GMail, so we just left that turned off. After a couple of years the school wanted to provide the students with mail. GSuite supports using multiple domains and the users we sync over are using a different domain from the internal. I don't know what renaming the underlying AD domain would do though. There has to be a path to utilizing multiple AD domains with Google and Azure. Standing up your new domain with a trust relationship to the old and slowly migrating over would be the safest thing to do if it is an option.
  4. What kind of hardware are you attempting to load Windows 7 onto? You'll probably need to disable UEFI and enable the legacy boot options if that can even be done depending on the age of the system. Some of the brand new stuff I see doesn't even have those options anymore. The USB issue you describe sounds like Windows 7 doesn't have the USB3 drivers. For a couple hardware generations systems had both USB3 and USB2 ports. If yours has both then try the USB2 ports. If it doesn't then you're looking at having to inject the USB3 driver into the install WIM. That is if you can even get a driver that can be used with 7.
  5. I hate to be the bearer of bad news, but it's already gone. If the drive is in fact an SSD then TRIM already zeroed the space the profile used to sit on. I can't speak as to why their profile got nuked. Maybe something Event Viewer could tell you.
  6. I'm a bit late to this party, but are you using a proxy in the browser settings? If so, the proxy needs to be pointing to the DNS where you have the setup done. HTTP browsing uses the proxy server DNS.
  7. Not that I've encountered at least. All the issues I saw related to the security patches never took down the spooler. Print Spooler crashes will be captured be in Event Viewer. Maybe that can help narrow down what is causing it.
  8. Haven't needed to get naked yet during those rituals, but haven't ruled it out if the need arises. I'm using GPP in one policy to hand out printers at the user level. Then a second policy with Point and Print setup with the mitigations recommended by MS and the registry key to allow non-admin users to install print drivers at the computer level.
  9. I goofed. The print server is 2016, sorry for the confusion. The first post the server was at September and by the second post I had updated it to October. I tested a number of clients at both the September and October patch levels against the server first with September on it, and last with October - didn't notice any issues. So, tested clients at higher levels than the sever, the server at higher level than the client and finally both at the same patch level. Everything past the September update seems to be behaving itself. It takes about three or four days for the entirety of the laptop fleet to come up to the latest patch level.
  10. Yeah, all quiet on the western front here.
  11. All seems well. I can confirm clients (Win10 1809 LTSC) with the September update can still print to the server (Server 2016) with the October update.
  12. After the registry key is in place to allow non-admins to install print drivers the issues I've seen were caused by the clients and server being at dissimilar patch levels. I installed the October Cumulative update on a couple of Windows 10 LTSC clients and left the print server, Windows Server 2019, at September. Clients could still print just fine to the Papercut queue. I don't know if this means anything though. Beforehand the server was at a higher level whereas the clients were at a lower. I'll find out tomorrow morning after patches are installed on the servers and report back then.
  13. This is what is working in most situations. Only catch is the client and server need to be at the same patch level. In my case everything has the September 2021 cumulative update. In some situations though the driver doesn't want to update. If the printer still isn't showing up then browse the shares on the print server manually and try adding the printer by hand. If it errors out still then there is one more thing to try. Stop print spooler service Remove affected print driver keys from registry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Environments\Windows x64\Drivers Start service Remove print driver from driver store file repository You'll need to take ownership and give yourself write access to delete the folder C:\Windows\System32\DriverStore\FileRepository Attempt adding printer by hand again On the few problem teacher workstations I have that refuse to add printers after the GPO fix the above works every time. Cheers.
  14. Yeah, I don't know why you can't pipe 'Get-WindowsDriver' to 'Export-WindowsDriver'. The get cmdlet gives you the path to the driver in the driverstore folder, so at least we can work with that. $Destination = ".\StuffGoHere" $Drivers = Get-WindowsDriver -Online | Where-Object {$_.ClassName -eq "Printer"} Foreach ($Driver in $Drivers) { $Source = (Get-Item $Driver.OriginalFileName).Directory.FullName Copy-Item -Path $Source -Destination $Destination -Recurse }
  15. Probably something concerning data collection of minors (under 18). I'm going to have to test the impact of a force install with these plug-ins on a test account. I don't think there is going to be a way around this.
  16. Are these Chromebooks assigned to specific students? If they're communal there is a setting in the admin panel that removes profiles when Chromebook is shutdown. We used this for years and just recently had to turn it off when students were being assigned Chromebooks to take home when in-person school was shutdown.
  17. So we got the notice that Google was clamping down on access to certain services based on age. Wasn't a big deal for staff as they gave us a way to specify an entire organization unit was over 18 and accept the terms of those users behalf. For the students though this is an issue. We've got about 4500 students and one of our departments wants to roll out a suite of plug-ins for Chrome that would only be used by about 500 of those students. What I would do before is just add said apps to the whitelist and for the students that use them they would just just go through Web Store. With no access to said store now I'm looking at having to force install these plug-ins for the entire student body. I'm real apprehensive to do this because we're not a 1:1 school. Chromebooks are communal still and reside in carts. Every time a student signs into a Chromebook now it's going to be installing these plug-ins they most likely won't be using. I'm worried moving forward the login process is going to start to getting bogged down with plug-ins that I have to force install to make available. Anyone else running into this issue?
  18. I ended up going this route. As long as the clients and server are at the same patch level (September cumulative) all seems fine.
  19. Same boat here. LTSC has been a Godsend. My teacher laptops just hum along merrily without any intervention from me whatsoever. It's been three years since I imaged most of them. Just check the WSUS server periodically and make sure they're still processing their security updates and move onto other fires. We're also a Google school, so we can get away with it. Also a one man show.
  20. I'm going to lose my shit on people. I just had a staff member feel the need to come into my office, place her hand on my desk and lean against it to tell me a stupid joke. I told her to leave and she comes back with a bleach wipe, wipes the spot on my desk, then proceeds to pick up a banana on my desk with her free hand to wipe under it. At which I just yelled at her to GTFO. People are complete idiots.
  21. An elder care facility got hit in Washington and that is where a lot of the deaths come from. I believe the average age of fatalities in Italy is somewhere up in the late 70's.
  22. The governor just ordered schools to be closed for three weeks. No idea what this means for me as SLT is still hashing out who needs to report and who doesn't. I also just bit the head off of someone who came into my office to ask a stupid question and felt the need to touch everything while doing it. sigh....
  23. The cert we use on our NPS instance is specified in two different places: Network Policy Server > Policies > Connection Request Policies > (Policy Name) > Settings Tab > Authentication Methods > EAP Type: PEAP <-- Edit Network Policy Server > Policies > Network Policies > (Policy Name) Settings > Constraints Tab > Authentication Methods > EAP Type: PEAP <-- Edit
  24. Download the enterprise version of Reader DC and then get the Customization Wizard to setup a silent MSI based install. https://get.adobe.com/reader/enterprise/ ftp://ftp.adobe.com/pub/adobe/acrobat/win/AcrobatDC/misc/
  25. I run into this with CS5. Running it as a user with local administrator rights isn't enough. The silent installer won't trigger a UAC prompt if you run it simply by double-clicking it. Either get around it by running it in an elevated command prompt (these will prompt for UAC), or as already mentioned, right-click -> run as admin. As long as the UAC prompt is brought up you're good.
×
×
  • Create New...