-
Posts
1,598 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Duke5A
-
Run DCDIAG from an elevated command prompt. Even though you're an administrator you still need to start a prompt where UAC asks for elevation first. This started with server 2012 I think.
- 1 reply
-
- 1
-
-
This is really odd. I don't know how the underlying tech works with DHCP failover in MS server, but before it was a thing I always split the scope across two independent DHCP servers if I needed redundancy. Maybe give this a try providing that you would still have enough available addresses for the devices if the subnet was suddenly cut in half.
-
Cisco ASA 5505 Packet drops possibly ARP related ?
Duke5A replied to Davit2005's topic in Wired Networks
Can't speak for ASA, but in their switches the MAC table timeout is five minutes and the ARP table timeout if four hours. I ran into some issues with asymmetric routing and changing the ARP timeout to being sooner than the MAC solved it - in my case I set it to four minutes. -
The first run of Chromebooks we bought only have dual core Celerons and 2GB of RAM in them. About five or six years old now. Still running great.
-
Same here, only I use the cards with the ports for the external temperature probes and hang the probe up under the air conditioning unit. Alerts are sent out via the card in the APC and also my SNMP monitoring setup. If the temp raises up to 82 degrees I start getting text messages. What is nice about the APC setup is I also have it setup to gracefully start shutting things down once it passes 85 degrees. APC has software that integrates with not only Windows, but with ESXi too.
-
What wireless chipsets are in the clients? The driver that ships with Windows 10 for Dell 1397/1510 wireless cards is bugged and will do exactly what you're describing - erratic pings, dropped connectivity, etc. Does it with 802.1x and even PSK security. I ran into this just last week after imaging a bunch of older laptops that use these cards. Anything with a Broadcom 4322 chip or maybe even in the same family will need the driver replaced. https://www.ispcolohost.com/2018/03/06/getting-a-dell-1510-wireless-aka-broadcom-4322-working-in-windows-10/ If you're imaging Windows will still prefer the built-in Microsoft provided driver even if you add the working one from the link above. To get around this I removed the bad Microsoft driver from the driver store in my image.
-
I'm a bit late to this thread, but we're an LTSB shop too. I manage about 1500 machines by myself and I don't have time to keep current on all of Microsoft's forced updates. Honestly, the only reason to use any flavor of Windows 10 that has the Store built in is if you're using Office 365 and you want the integration. Outside of that the entire purpose of Windows 10 is to serve as a platform to sell you crap.
-
Check this out: https://social.technet.microsoft.com/wiki/contents/articles/5927.how-to-disable-ipv6-through-group-policy.aspx Microsoft has GPO templates available for configuring IPv6. As stated though, don't outright disable it. One of the configurable options is to make the OS prefer IPv4 over IPv6 - use this one. As to it fixing your original issue, I have no idea.
-
Sounds like you have DNS setup right. Are you using Google Apps for Education (or G-Suite, whatever they're calling it now)? If you are, the way it's supposed to work is all users have access to restricted mode; which is a specially curtailed white-list of kid friendly stuff. There is a lot of things that are friendly though that aren't in this list. Where Google Apps comes in is you can then give other accounts unrestricted access and the ability to add videos to that white-list for your domain. This access is given to your staff by making their accounts members is the 'classroom teachers' group (side note, this group also grants access to use Google Classroom). When a teacher browses videos not in your domain's white-list they'll be prompted right under the video as it plays to add it. Turn on 'Special approvers' in the conent settings for Youtube. Add teachers to the 'Classroom Teachers' group Let teachers know of there new found power and take one more thing off of your plate Of course, if you don't have a Google Apps domain, then disregard this post in its entirety.
-
If printers are failing to install on login, then check the Application Log in Event Viewer. Any failed printer connection will be dumped in there and if you see it then odds are your chosen deployment method is working. If you don't see an error in the log then I would fault the deployment script/GPO/GPP or whatever is used.
-
VLANS no clue what to do need a dummies guide
Duke5A replied to johbreaking's topic in Wired Networks
Router Alley - Guides Check this out. This is the guy that taught my CCNA and CCNP courses in college. He made all of his own guides and they're especially easy to read and follow. There is one that covers VLAN and VTP. -
I just ran into this and Google is pretty blunt about it not supporting proxy authentication. After a couple days I broke down and added these Google domains to an ACL I setup that gets to bypass authentication. .google.com .ytimg.com .googleusercontent.com .gstatic.com Just another set of domains we can't track traffic on by username.... wasn't happy, but didn't see any other way around it.
-
Deleting old DC DNS records...they just come straight back!
Duke5A replied to googlemad's topic in Windows Server 2012
It's been a while, but the last time I lopped the head off of a DC I had to go into ADSI Edit and remove leftovers. -
Remote Desktop Gateway is temporarily unavailable
Duke5A replied to fiza's topic in Windows Server 2016
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\CredSSP\Parameters] "AllowEncryptionOracle"=dword:00000002 The CredSSP issue bit me last week. Our childcare department uses an application that rides on Remote App for billing and after the their laptops installed the April security roll-up it stopped working. Putting the above registry key on the client computer allowed them to connect. You can give it a try I guess, but from what I read about the issue as long as both ends had been patched it should work. -
HELP! NO Teachers laptops can login Network mis-identified
Duke5A replied to chazzy2501's topic in Windows 8
Give this a read: https://blogs.technet.microsoft.com/networking/2010/09/08/network-location-awareness-nla-and-how-it-relates-to-windows-firewall-profiles/ It's a lot of fun during power burps if your domain controllers don't come up before everything else does. Other servers and clients sometimes get stuck on the public firewall profile and lock everything down as a result. Give a look under the Local Security Policy editor on the laptop. Under 'Network List Manager Policies' you should be able to alter location settings for previously identified networks. I guess you could try deleting the registry key for the network too and let the system try and identify it again. HKEY_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Group Policy\History\NetworkName- 4 replies
-
- firewall
- network location service
-
(and 2 more)
Tagged with:
-
In the group policy editor if you right-click in the App Locker Executable Rules section one of the options is to create the default rules. Do this and the defaults will allow all executables in program files and the windows directories.
-
If the computer is browsing the web then you really do need to run an ad blocker of some flavor in conjunction with your AV. Personally I use uBlock Origin on any machine that even touches the web. Take it an additional step with Privacy Badger or No Script. Honestly, I find that the vast majority of infections anymore come right through the web browser via malicious sites masquerading as legit ones and exploited ad networks. This goes without saying though, but you should white-list the sites you frequent if you go this route.
-
Windows laptop stuck on reverting changes to updates after failure
Duke5A replied to Stormborn15's topic in Windows 7
Just for reference since the original problem has been sorted: I used to run into an issue with Deep Freeze where sometimes the machine would go back into a frozen state between reboots while processing updates. What would result was just an infinite boot loop. If you boot the machine with WinPE or even an installation disc (press shift-F10 when the installer comes up for a command prompt) you can delete 'c:\windows\winsxs\pending.xml" to cancel the changes. This is extremely dirty, but it did get the systems to boot for me. -
I don't think you can remove a provisioned app once it has been installed into a user's profile - it has to be removed from the user's profile first. With clients out in the wild that have had users already log into them and have had their local profiles created this creates an issue. To further compound this a lot of these Modern Apps will return if the clients ever pull down a Creators Update. My information might be out of date though, I've been on LTSB this entire school year.
-
I've seen printers do some screwball things of late. We're running LTSB 1607 with printers served off of Server 2016 deployed via GPP. Our issues weren't with the deployment method though, but were with driver's failing to copy over properly. These failures are visible in the Application Log inside Event Viewer. GPP does refresh at a set interval though, so will reapply even after the user is logged in.
-
Do you run KMS over DNS? I do and setup scavenging and it removed my DNS record for the KMS server. For some reason the record isn't created as a static one, so be sure to change that before enabling scavenging.
-
We run LTSB in our environment. Even our web development classes haven't complained about its absence. Chrome is default everywhere and is pretty much the only option. IE is still present in the LTSB image with no icons pointing to it. If someone needs they can just start typing it's name in the Start Menu to find it. If only having a single browser ever becomes an issue I can use GPP to pop up a shortcut for IE on the desktops.
-
Seems like a lot of hoops to jump through to regain control that we had with previous Windows revisions. I don't even want to think about the support calls that forced revision updates would generate in my district. We're still chugging along merrily with 1607 LTSB. Runs fine on the limited quantity of new hardware we're getting too (8th gen core stuff). We never got in with Office 365 or Microsoft accounts, so having no store access wasn't a loss. Haven't had anyone miss Edge yet either.
-
This book was required reading in my 9th grade English class. I enjoyed it so much I actually finished ahead of the class. This is definitely on the list.
-
#Updated 2018/08/30: Fixed a bug where it didn't count the number of newly created users correctly. Fixed another bug with the continue statement not working as intended when finding an invalid grade I wrote this Power Shell script to automate user creation in Active Directory. It's run off of a scheduled task and maintains a log file of everything it does. It handles pretty much everything: Copies the export and names by date, also names log by date for easy sorting and retention for debugging if need be Rudimentary checking of the export file for date and columns Username formatting User creation and OU placement Group membership Home folder creation Home folder persmissions The Export looks like this: PSNumber Lastname Firstname Grade 1000001000 O'Neill Jack 12 1000001001 Carter Samantha 9 1000001002 Jackson Daniel 11 1000001003 Mal Doran Vala 11 1000001004 McKay Rodney 12 1000001005 Hammond George 12 1000001006 Quinn Jonas 10 1000001007 Mitchell Cameron 12 You'll have to change a few things to fit your environment, but this makes for a good starting point. The script is designed with an OU structure that breaks students down into graduation years. -Students -2018 +Student A +Student B -2017 -2016 -2015 +Student C Every student is a member of their respective graduation year group: Students_2018, Students_2017, etc. Account name is the first six letters of the last name, followed by the last four digits of their student number. The script will also remove some special characters from the names that AD could gripe about. I hope this helps... -Mark #Define editable strings $WorkingDir = "script path goes here" $ADDomain = "Domain Name goes here" $Password = "student" $BaseOU = "ou=Grad Year,ou=Students,ou=Your User OU,dc=domain name,dc=com" $BaseHome = "\\yourfileserver\students$\" $HomeDrive = "H:" $UserCount = 0 #Define non-editable strings $LogPath = $WorkingDir + "Log $($LogDate).txt" $LogDate = Get-Date -UFormat "%Y-%m-%d.%H.%M.%S" $PSExportPath = $WorkingDir + "student.export.text" $UserExportPath = $WorkingDir + "User $($LogDate).txt" $TimeStart = Get-Date #Create the log file and write the header - file named with date "Processing started on $($TimeStart)" | Out-File $LogPath -append "--------------------------------------------" | Out-File $LogPath -append "" | Out-File $LogPath -append #Load the Active Directory module Try{Import-Module ActiveDirectory -ErrorAction Stop} Catch{ "[CRITICAL] Active Directory module not loaded! Aborting." | Out-File $LogPath -append "`t $($_.Exception.ItemName)" | Out-File $LogPath -Append "`t $($_.Exception.Message)" | Out-File $LogPath -Append Exit } #Check for existance of user export file $FileExists = Test-Path $PSExportPath If ($FileExists -eq $False){ "[CRITICAL] User export not found! Aborting." | Out-File $LogPath -append Exit } #Check age of user export file and stop script if more than 12 hours old $PSExportFile = Get-Item $PSExportPath $Limit = (Get-Date).AddHours(-12) If ($PSExportFile.LastWriteTime -lt $Limit){ "[CRITICAL] User export is more than 12 hours old! Aborting." | Out-File $LogPath -append Exit } #Copy automated user export file to another name that includes the date #this preserves the file along with the log, both named by date for debugging purposes Copy-Item $PSExportPath $UserExportPath | Out-Null #Import CSV and bust down using a tab delimiter - script stops if this fails Try{$Users = Import-Csv -Delimiter "`t" -Path $UserExportPath -ErrorAction Stop} Catch{ "[CRITICAL] Export not formatted properly! Aborting." | Out-File $LogPath -append "`t $($_.Exception.ItemName)" | Out-File $LogPath -Append "`t $($_.Exception.Message)" | Out-File $LogPath -Append Exit } #Used to determine fiscal year - most US schools operate on a 9 month calendar year #because of our SIS system the graduation year is derived from the current year and the student's grade level #anything after the month of June is considered to be the next calendar year If ($TimeStart.Month -gt 7) {$FiscalYear = $TimeStart.Year + 1} Else {$FiscalYear = $TimeStart.Year} #Function where the magic happens Function AddUsers{ #Step through each line of the export loaded into $Users :nextUser foreach ($User in $Users) { $i++ #Assign each column it's own variable $UserFirstname = $User.First_Name $UserLastname = $User.Last_Name $PSNumber = $User.Student_Number $Grade = $User.Grade_Level #Check for blank entries in any of the columns - if any are found then log it and go back to the top of the loop, skipping this user line If (($UserFirstname -eq "") -Or ($UserLastname -eq "") -Or ($PSNumber -eq "") -Or ($Grade -eq "")){ "[ERROR] Information missing. Check source line $($i)." | Out-File $LogPath -Append Continue nextUser } #Remove special characters that don't play nice in AD from user names $UserFirstname = $UserFirstname.Replace(".","") $UserFirstname = $UserFirstname.Replace(" ","") $UserFirstname = $UserFirstname.Replace("'","") $UserFirstname = $UserFirstname.Replace("-","") $UserLastname = $UserLastname.Replace(".","") $UserLastname = $UserLastname.Replace(" ","") $UserLastname = $UserLastname.Replace("'","") $UserLastname = $UserLastname.Replace("-","") #Generate user's login name - syntax for our environment is first six characters of last name followed by last four digits of student number If ($UserLastname.Length -lt 6){ $SAM = $UserLastname + $PSNumber.Substring($PSNumber.Length -4,4) } ElseIf($UserLastname.Length -ige 6){ $SAM = $UserLastname.Substring(0,6) + $PSNumber.Substring($PSNumber.Length -4,4) } #Generate strings for other pieces of user information $Displayname = $UserFirstname + " " + $UserLastname $UPN = $SAM + "@" + $ADDomain #Make sure that grade is within proper bounds - if not, write to the log and continue back to the top of the loop skipping this user from further processing Switch ($Grade) { 12 {$GradYear = $FiscalYear + 0} 11 {$GradYear = $FiscalYear + 1} 10 {$GradYear = $FiscalYear + 2} 9 {$GradYear = $FiscalYear + 3} 8 {$GradYear = $FiscalYear + 4} 7 {$GradYear = $FiscalYear + 5} 6 {$GradYear = $FiscalYear + 6} 5 {$GradYear = $FiscalYear + 7} 4 {$GradYear = $FiscalYear + 8} 3 {$GradYear = $FiscalYear + 9} 2 {$GradYear = $FiscalYear + 10} 1 {$GradYear = $FiscalYear + 11} 0 {$GradYear = $FiscalYear + 12} Default {"[ERROR] Grade not valid. Check source line $($i)." | Out-File $LogPath -Append Continue nextUser} } #Generate some more stuff and populate variables $HomeFolder = $BaseHome + $GradYear + "\" + $SAM $OU = "ou=" + $GradYear + "," + $BaseOU $GroupName = "Students_" + $GradYear #Try block to check for existance of user - if this fails then log it and continue back to the top of the loop, skipping this user from further processing Try {$UserExists = Get-ADUser -LDAPFilter "(sAMAccountName=$SAM)"} Catch { "[ERROR] Unabled to check for duplicate user $(SAM) Source line $($i)." | Out-File $LogPath -Append "`t $($_.Exception.ItemName)" | Out-File $LogPath -Append "`t $($_.Exception.Message)" | Out-File $LogPath -Append Continue nextUser } #If user doesn't exist, create said user If(!$UserExists){ #Try block to create user - if this fails then log it and continue back to the top of the loop, skipping this user from further processing Try{ New-ADUser -Name $SAM -DisplayName $Displayname -SamAccountName $SAM -UserPrincipalName $UPN -GivenName $UserFirstname -Surname $UserLastname -HomePhone $PSNumber -Description $GradYear -AccountPassword (ConvertTo-SecureString $Password -AsPlainText -Force) -Enabled $true -ChangePasswordAtLogon $true -PasswordNeverExpires $false -Path $OU -HomeDirectory $HomeFolder -HomeDrive $HomeDrive -ErrorAction Stop } Catch{ "[ERROR] User $($SAM) not created. Source line $($i)." | Out-File $LogPath -Append "`t $($_.Exception.ItemName)" | Out-File $LogPath -Append "`t $($_.Exception.Message)" | Out-File $LogPath -Append Continue nextUser } #Count the number of users added for later use in the log $Global:UserCount = $Global:UserCount + 1 "[sUCCESS] User $($SAM) created. Source line $($i)." | Out-File $LogPath -Append #Try block to add newly created user to the appropriate student graduation group - if this fails then log it and continue back to the top of the loop, skipping this user from further processing Try{Add-ADGroupMember -Identity $GroupName -Members $SAM -ErrorAction Stop} Catch{ "[ERROR] User $($SAM) not added to group $($GroupName). Source line $($i)." | Out-File $LogPath -Append "`t $($_.Exception.ItemName)" | Out-File $LogPath -Append "`t $($_.Exception.Message)" | Out-File $LogPath -Append Continue nextUser } "[sUCCESS] User $($SAM) added to group $($GroupName). Source line $($i)." | Out-File $LogPath -Append #Try block for creating user's home folder and setting permissions - if this fails then log it and continue back to the top of the loop, skipping this user from further processing Try{ New-Item -ItemType "Directory" -Path $HomeFolder -ErrorAction Stop $Acl = (Get-Item $HomeFolder).GetAccessControl('Access') $Ar = New-Object System.Security.AccessControl.FileSystemAccessRule($SAM, "Modify",'ContainerInherit,ObjectInherit', 'None', 'Allow') $Acl.SetAccessRule($Ar) Set-Acl -path $HomeFolder -AclObject $Acl } Catch{ "[ERROR] User $($SAM) home folder messed up. Source line $($i)." | Out-File $LogPath -Append "`t $($_.Exception.ItemName)" | Out-File $LogPath -Append "`t $($_.Exception.Message)" | Out-File $LogPath -Append Continue nextUser } "[sUCCESS] User $($SAM) home folder created. Source line $($i)." | Out-File $LogPath -Append } Else{ "[iNFO] User $($SAM) already exists. Source line $($i)." | Out-File $LogPath -Append Continue nextUser } } #Give a half second between creating users to let AD catch its tail Start-Sleep -Milliseconds 500 } Addusers #Write statistics to the end of the log $TimeEnd = Get-Date $ElapsedTime = $TimeEnd - $TimeStart "" | Out-File $LogPath -Append "Processing Finished on: $($TimeEnd)" | Out-File $LogPath -Append "Total processing time: $($ElapsedTime)" | Out-File $LogPath -Append "Users created: $($UserCount)" | Out-File $LogPath -Append #Debug function Function Debug { Write-Host "Username: " $SAM Write-Host "OU: " $OU Write-Host "Grad Year: " $GradYear Write-Host "Home Folder: " $HomeFolder #Write-Host $UPN #Write-Host $GApps Write-Host }
