Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. Sheridan

    SMB on 10.7.5

    We tried to setup the iMacs onto 10.9.5 with the same AD/OD connection that uses the network home share, and they run so slow as to be unusable. Plus the Workgroup Manager settings that used to work reliably seem to be very intermittent. The server is 10.9.5 so I thought this combo would work but not in our case! We had major issues with speed when connecting right the way back to 10.8, which is why we held on to 10.7.5 for so long. If it wasn't for Logic these damn things would have Windows 7 on by now!
  2. Sheridan

    SMB on 10.7.5

    It looks like it, thats our Macs in the bin then! We never got Profile Manager to work, and the golden triangle doesn't seem to work any more past 10.7 I managed to get a test 10.9 and a test 10.12 working, but the access to the Windows shares is so painfully slow its not usable. Guess Apple are pushing you to an all apple network.
  3. Sheridan

    SMB on 10.7.5

    We're still using some older iMacs running 10.7.5, but since the recent ransomware problem which involved making sure SMB1 was disabled on Windows servers, the clients can no longer connect! I'm guessing that 10.7.5 uses SMB1 or similar to connect to the users Home Share (as defined in the Directory utility) - is there a way to work around this without updating OSX or re-enabling SMB1 on the Windows servers? I know these are overdue for an update but thats for a holiday period!
  4. Ad activation is an option for when we run w10 clients, which brings so many nightmares that activation will be the least of them! [emoji3]
  5. I'll give that another go, I've noticed that some have update but others not which is of as they are all the same model and age of iPad. Meraki will only update if the iPad is on and unlocked and I'm wondering if they are staying locked too often for the update to get pushed down
  6. Well,the deny for everyone but the local account works well. I know it's not the most elegant solution but it works so well, staff login as normal on the network, but at home or offsite login with an offline account that has a lighter set of policies so they can change wifi/printers etc. They can store files on the locally encrypted drive and copy them to the network when back onsite, job done and dead easy to use.
  7. Moved it to a new server, and changed the DNS entry - now working again! Can't even uninstall the service on the old one so I've left it.
  8. I've just added the Office 2016 KMS to our 2012 Server running KMS, which was sucessful - until the end when I close the dialogue box Now the KMS service (software protection?) can't be stopped/started and KMS is completely unresponsive. I'm not able to reboot this server for a while as its in use and I suspect my KMS is now knackered. There's so little in the way of diagnostics for kms, has anyone found a way to 'reset' it?
  9. I did set the policy to Bypass for this and switched it off again, so thats maybe where its got those entries from. It looks like wsus is just another part of the broken mess that is W10. It makes me laugh to think how much Vista was slagged off when 10 is the worst OS I've ever had to deploy, by a massive margin. Looks like I'll just have to set these up to download updates as if they were home machines, which is pretty much microsofts way of thinking these days anyway.
  10. This is odd, looking at the log in Windows\SoftwareDistribution on one of the W10 PCs that isn't showing in WSUS and the end shows: {01309C18-EA37-4F0E-AEB5-54004F5FD2B5} 2017-05-10 14:06:39:952+0100 1 181 [AGENT_INSTALLING_STARTED] 101 {C51E9B44-D599-4007-BAA5-0D5011C1E6DF} 1 0 Update;taskhostw Success Content Install Installation Started: Windows has started installing the following update: Microsoft .Net Native Framework Package 1.6 {48E0F841-ADC2-4DFA-9B0D-6FF83D29F02D} 2017-05-10 14:06:40:374+0100 1 183 [AGENT_INSTALLING_SUCCEEDED] 101 {C51E9B44-D599-4007-BAA5-0D5011C1E6DF} 1 0 Update;taskhostw Success Content Install Installation Successful: Windows successfully installed the following update: Microsoft .Net Native Framework Package 1.6 {2578A138-D3C6-4E73-B7F1-3BF8B891FA84} 2017-05-10 14:06:40:415+0100 1 181 [AGENT_INSTALLING_STARTED] 101 {742DB728-811B-4F07-BCF2-0AD2B5CD9312} 1 0 Update;taskhostw Success Content Install Installation Started: Windows has started installing the following update: Microsoft .Net Native Runtime Package 1.6 {2F0D574D-4EAE-4CAD-8E57-848B0781C4EF} 2017-05-10 14:06:40:785+0100 1 183 [AGENT_INSTALLING_SUCCEEDED] 101 {742DB728-811B-4F07-BCF2-0AD2B5CD9312} 1 0 Update;taskhostw Success Content Install Installation Successful: Windows successfully installed the following update: Microsoft .Net Native Runtime Package 1.6 {9F794BF7-08F1-4D05-86E1-235DA977D1C9} 2017-05-10 14:06:40:815+0100 1 181 [AGENT_INSTALLING_STARTED] 101 {CF0E1B33-B56C-44DF-BC4F-046683959381} 1 0 Update;taskhostw Success Content Install Installation Started: Windows has started installing the following update: Windows Camera {1FCD6E3C-3720-4F5F-9E33-3F8733802919} 2017-05-10 14:06:41:494+0100 1 183 [AGENT_INSTALLING_SUCCEEDED] 101 {CF0E1B33-B56C-44DF-BC4F-046683959381} 1 0 Update;taskhostw Success Content Install Installation Successful: Windows successfully installed the following update: Windows Camera So its getting updates from somewhere!
  11. Yes to all, and I've even rebuilt the WSUS to move it from its original port (8530) to the default Port 80 and the W10 can see the iuident.cab file on the server!
  12. Thats exactly the same version their WSUS is showing, all the W10 that aren't appearing are 1607. Oddly, we have another primary running 1511 and WSUS 3.0 on Server 2008 R2 and thats working fine!
  13. I'm getting some complaints that our filtering (smoothwall) is blocking legitimate searchs for drug related information (laws, classifications, penalities etc) - I've checked and the searches are genuinely work related but tend to fall into the smoothwall 'Drugs' category which is blocked as it falls into the Legal and Liability section. Now, I can unblock certain search terms (i.e 'drug laws') but obviously this isn't ideal as I'd have to predict every search term combination Just wondered how anyone else categorised things like this (its Sixth form students who need this so not a whole school issue)
  14. Thats the problem, a lot of our primaries can't afford to upgrade their servers just to cope with a few new W10 machines - not in the same year anyway. Downgrade to W7 looks like a viable option. The MS way seems to be update everything all together now.
  15. Oh god I don't even want to think about 1703! Every update fixes 10 things and breaks 25 new things!
  16. When you mention lastest updates on 1607, we have tried installing the April 2017 update rollup, but thats had no effect. I've rebuild WSUS on the server completely and only the W7 PCs are reappearing! W10 is a real pleasure to deploy isn't it.
  17. Checking the registry shows that they are picking up the policy and pointing towards the correct server. I'm going to rebuild wsus on the server to start from scratch and see what reports in.
  18. Yup, 2008 is ancient but a primary school doesn't have the budget or demand to upgrade to 2012 or higher!
  19. Its synching OK and the W7 PCs are checking in - just the W10 ones don't appear at all! I've got Windows 10 selected in the Product as well.
  20. In one of our primaries we've added a load of W10 PCs, which are on a Server 2008 R2 domain. Now I know WSUS 3.0 supports W10 (despite the Vista tags!) but oddly none of the W10 machines are even appearing in the WSUS console. Checking the registry of each PC shows the correct settings and browsing the url http://server/selfupdate/iuident.cab results in a sucessfull download so I'm a bit puzzled as to where this is going wrong. In the past the problems I've had with WSUS and W10 are that they appear in the console but never update their status, this is the first time they haven't appeared at all! Is this another update=broken aspect to W10 I've not yet seen?
  21. It's a mixture of things, and some legacy things. People got so used to the dual logins it was difficult to break out of. Plus there are issues with domain accounts used offline, such as redirected desktops, and allowing certain things to home users but not to domain users when online such as adding printers or connecting to home wifi, so the offline login worked very well!
  22. Never found out why this started happening, but denying access to the GroupPolicy folder for all users except the local account sorted this out!
  23. For years we've had laptops that are joined to the domain but also have a completely seperate local account login (i.e for home or external use) To keep this secure we ran gpedit.msc on the machine, and then denied Read permissions to the \Windows\System32\Group Policy folder for Administrators, so that only non admins would be able to read and apply this. Obviously when on the domain the users got standard GPO's, and the local copies were effectively a duplicate for local users and it worked very well. However somethign must have changed - now the fact that the local Group Policy folder is there makes it do something very odd to domain logins. For example, standard domain user here can't get the Run dialogue, this was also in the local GPO. However now when a domain users logs into one of these laptops they get the Run dialogue! So a double negative becomes a positive if you see what I mean! The local user option has worked so well I'd like to keep it, but something is wrong now, and it does the same in Windows 10 as well. Anyone got any experience doing it like this?
  24. Anyone using the Sumdog app for IOS with smoothwall? It just doesn't seem to work As soon as you start it you get the 'Sumdog is loading' message and then fairly soon after that the message 'If this is taking longer than normal please check you internet connection' and it will stay like that until you kill it off. Checking our smoothie shows whitelisted access to sumdog.com so I'm not sure what its trying to connect to?
  25. I'm missing the Update button in Meraki for these apps, which I thought meant they were up to date!
×
×
  • Create New...