Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. Fixed it. Turns out it was a problem with Chrome.adml in the en-GB folder. It seems like Google previously supplied en-GB adml files, but haven't included it in the latest version to the ADMX templates (unsure how far back this goes). Group Policy will attempt to load adml from your OS's corresponding locale first (en-GB for me) and will fall back to en-US if it doesn't exist. Since my locale is en-GB and Chrome.adml did exist in en-GB, it was being called. But as it's is outdated, it didn't contain the section that admx file was attempting to reference, causing the error. I removed Chrome.adml from en-GB, reloaded Group Policy and now it's working as expected, where it must be using the chrome.adml file in the en-US folder.
  2. I've had this type of issue every now and again with ADMX templates, where it complains about not being able to find a resource. Usually it's a bug in the template or a corruption and reinstalling/updating them works, but these are the latest ADMX templates from Google. I've re-downloaded and installed them again, but still the same issue. I've tried the templates from the admin bundle and the separate ADMX download. I don't have a copy of older ADMX templates and struggling to find them online.
  3. I'm still having issues where I can't I edit or preview the user's Adminstrative Templates section, as it displays this when it's expanded: An error has occurred while collecting data for Administrative Templates. The following errors were encountered: Resource '$(string.ScreenCapture_group)' referenced in attribute displayName could not be found. File \\DC2.SJW.Internal\SysVol\SJW.Internal\Policies\PolicyDefinitions\chrome.admx, line 23, column 79
  4. Thanks for that. My Google-fu must be lacking, as I couldn't find any reference to that in my searches. Though reading through that, that assumes we're having our users sign in to Chrome? They don't and just use basic profiles within the browsers (restricted via GPO). That makes me doubt that changing the setting in our Google Education admin portal is going to have any effect. I'll have a closer read through the documentation though.
  5. We've noticed our users are being shown a confirmation box on Google's home/search page that they cannot remove. It only happens on Chrome, not Edge. The message is: Google has changed some of your settings for this site (google.com) because you aren't confirmed to be over 18. To verify that you're over 18 sign in. SafeSearch on Ad personalisation on Google Search isn't available Choose 'Customise to check if your settings are right for you. Customise Got It The users cannot press either Customise or Got it, the buttons just don't do anything and the box doesn't go away, meaning they can't use Google Search. I presume this is a new feature in Chrome, so I downloaded and installed the latest ADMX templates (94.0.4606.61), to see if there are any new policies to specify these settings. After installing the policies (into domain\SYSVOL\domain\Policies\PolicyDefinitions)...When I launch Group Policy Management on my workstation (Win10 Edu 21H1 x64 with RSAT 2004) and attempt to open User Configuration > Administrative Policies, I get the following error: Resource '$(string.ScreenCapture_group)' referenced in attribute displayName could not be found. File \\domain\sysvol\domain\Policies\PolicyDefinitions\Chrome.admx, line 23, column 79 The confusing thing is that I can expand the same section when I'm connected to both our domain controllers (Server 2019) and it works. However, my colleague also experiences the same issue as me on his workstation (also Win10 Edu 21H1 x64 with RSAT 2004). I've not come across this behaviour before. I was thinking a replication issue between the two DCs, with my machine pulling the ADMX templates from the problem DC. But the fact that the policies load on both servers without issue is throwing a spanner into that theory.
  6. I have a bit of an odd request when it comes to a collection I want to deploy to. We have our VPN profile pushed as an app (a PowerShell script that add the profile with a configuration XML defined). This has worked fine for the couple of years we've had it in place. However, it's pushed to a machine collection (staff laptops) and installed as System, which adds it into the logged on user's profile. Because it's pushed to a machine collection, it only runs once. If another user logs on, it won't re-run. I have changed the deployment type to push it to our user collection (All Staff) and install as the user. At the moment, I've only made it "Available", as I don't want it to push everywhere (which is would if set to "Required"). Ideally, I'd like to push this VPN profile to all staff users, but only when they're logged onto their laptops. I'm not sure how I can go about achieving this. The closest thing I can seem to find is setting the Requirements to the device must be in our Laptops OU. I've only just specified this Requirement, so I need to wait to test it. Is that the best option, or is there a potentially better solution?
  7. I thought that policy didn't work, or it did in XP days but not on more recent versions of Windows.
  8. I have seen that comment for a few years, but I don't know what people are doing instead. Our PCs only have 120GB SSDs, and they're quickly filled by profiles.
  9. I didn't want to have to bump this thread, but here we are! I'm finding that the /ntuserini is deleting all profiles, which is the exact opposite issue I was having! "Delprof2.exe /u /i /q /d:60" - Deletes no profiles, even those older than 60 days "Delprof2.exe /u /i /q /d:60 /ntuserini" - Deletes all profiles, even those younger than 60 days Anyone encountered this behaviour before?
  10. Thanks, I already had Point and Print and the Approved Servers specified, applying that registry key resolved the issue for us. Am I right in thinking that with the server specified via Point and Print, our clients are only vulnerable if the print server itself is compromised, since that's the only server they're told to download drivers from?
  11. I've read through this thread and I don't think I'm any the wiser on how to resolve this. From what I've gathered, the only sure way we know to get around this is to disable Point and Print and set "RestrictDriverInstallationToAdministrators" to 0 - which ? Or purchase an alternative printer deployment method, such as Papercut via an additional license?
  12. Thanks for that, I'll take a look.
  13. Is this issue limited to just 21H1 or does it also affect 1909? I'm having issues doing in-place upgrades from 1909 to 21H1, where the TS fails instantaniously. Looking at my servicing stack updates in SCCM, I can see that all of the monthly servicing stack updates are mared as "Is Deployed = Yes", though the actual numbers reported are odd, such as "Required" being 0, 1, 2,4, etc, and "Installed" also being low, such as 0, 3, etc (depending on the monthly update). Actually, looking at the deployment summary - the Windows 10 Monthly ADR is reporting "Compliant = 4", "Non-compliant = 1" and "Unknown = 379". I don't know why it's showing all our clients as unknown, given that this ADR was updated in July, so should have pushed to our clients by now. On a client, there are no updates showing in the Software Center.
  14. Forgot that I had annual leave the week after I started this thread! The drive the drive itself has >60GB free and the CCM cache has been set to 30GB (and cleared via the control panel applet). So space really shouldn't be the issue at this point.
  15. No, it's directly imported from VLSC. Looking at execmgr.log, I'm seeing: OnOptionalExecutionRequests attempted for package SJW00359 optional program * [QueueRequest: false RunOnCompletion : true QuietMode: true SDKCallerId: (null)] Validating package SJW00359 program * in the chain. The content request ID is {00000000-0000-0000-0000-000000000000} This device is enrolled to an unexpected vendor, it will be set in co-existence mode. This device is enrolled to an unexpected vendor, it will be set in co-existence mode. Device is in coexistence mode. Deployment/Installation of task sequences and classic software distribution packages is disabled. Policy is invalid for program * in the chain. Failed to validate the chain of dependent programs for package SJW00359 optional program * OnOptionalExecutionRequests failed for program * : 0x87d01005
  16. I'm using MECM 2103 and encountering an issue when attempting to deploy Win10 Edu 21H1 x64 as an in-place upgrade to clients (currently running Win10 Edu 1909 x64). I've performed the same steps I previously have for an in-place upgrade and advertised the TS as "Available" while I'm testing. My clients see the TS in the Operating Systems tab of System Center, but it fails instantly with The SCClient log shows: The installation failed with error code -2016407547 (Microsoft.SoftwareCenter.Client.Pages.UtilityClass at ShowInstallationFailedDialog) Exception caught in ExecuteMethod, line 407, file X:\bt\1070266\repo\src\DataAbstractionLib\WmiDataProvider\WmiConnectionManager.cs - Type System.Runtime.InteropServices.COMException: (Microsoft.SoftwareCenter.Client.Data.WmiConnectionManager at ExecuteMethod) StackTrace: at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo) at System.Management.ManagementObject.InvokeMethod(String methodName, ManagementBaseObject inParameters, InvokeMethodOptions options) at Microsoft.SoftwareCenter.Client.Data.WmiConnectionManager.ExecuteMethod(String methodClass, String methodName, Dictionary`2 methodParameters, String callerMethodName) Found exception of type System.Runtime.InteropServices.COMException; wrapping in type Microsoft.SoftwareCenter.Client.Data.WmiException (Microsoft.SoftwareCenter.Client.Data.WmiException at .ctor) Returning COM exception -2016407547. (Microsoft.SoftwareCenter.Client.Data.WmiException at get_ErrorCode) Generating event ProgramInstallationFailed for application SJW00359-* (Microsoft.SoftwareCenter.Client.Data.WmiDataConnector at SendEvent) AppDetails received Event Unknown, state 18, causing a state display value of Failed. The Action Button says _Retry and its enabled state is True (Microsoft.SoftwareCenter.Client.ViewModels.ApplicationDetailsViewModel+d__138 at MoveNext) The error code -2016407547 relates to "The policy for this program does not exist or is invalid.". I can't find any more specific information and not sure which other logs to check. I'm not seeing any issues reported on the server or it's logs. The only one thing I found with my Google-foo skills was that the cache might be too small. This in-place update requires about 25GB of space, so I increased the client cache from the 20GB previously set to 30GB, just to be safe and ensured there's enough free space on the SSD. No luck. The OS image and upgrade package are distributed correctly. Manually installing the OS via a TS (wiping the machine) works correctly, just not an in-place upgrade. Has anyone experienced this issue before?
  17. I have had Microsoft's Always-On VPN configured for a couple of years now and it works great. However, I've noticed an issue where the VPN profile will just simply remove itself or disappear from the user's profile, and I have no idea why. Our VPN profile is configured via a batch file, which executes a PowerShell script with a VPN profile XML configuration file. This is pushed out via SCCM, via a package with source files and deployed as an application script installer to our "All Staff Laptops" collection. Even though it's deployed to a machine collection, the VPN installs in the user context. When the VPN is removed, the only way to reinstall it is for the user to bring the laptop on-site, log onto the domain and Repair the VPN profile via Software Center. I've also noticed that the rasphone.pbk file is removed from the user's AppData. So it looks like something is specifically removing it. Has anyone else encountered this sort of issue with the VPN? I'm not entirely sure why it's just disappearing. At first, I thought it was was something to do with the certificates expiring. But even when there's a certificate issue, the profile is still installed, it just won't connect.
  18. Ahah! That's the one, I've just used that switch and it's now detecting those profiles as old enough to delete. I haven't had to use that switch up until now and honestly forgot it existed! Thanks!
  19. I've come across an issue where our machines are filling up storage due to profiles. We have DelProf2 configured as a shutdown script (with the /u /i /q /d:60 parameters), however, we've noticed it isn't deleting profiles, even for staff who left a year ago and their AD accounts are disabled. After some digging, I've found that DelProf2 reports: (reason: not old enough to be deleted) Looking at one of the affected profiles on the machine, the profile is still there and the folder has a modification date of 06/03/2020, so well over a year ago. However, looking at NTUSER.DAT, I'm seeing that it has a modification date of 05/07/2021, so yesterday. I assume DelProf2 is looking at the modification date of this file, but I don't understand why NTUSER.DAT is being modified at all on that computer, on a local profile that's for a long disabled user (August 2020 was the disabled date - and it is definitely disabled). Has anyone else come across this? Edit: Could this be caused by our AV (Windows Security by SCCM/SCEP)?
  20. We've encountered a strange issue with our iPads, where we cannot use any browsers other than Safari. We previously deployed Chrome to the iPads, which worked. We then reset the iPads and the apps just didn't deploy. At first, we got a message in Intune saying that Chrome was installed, but it wasn't showing on the home screen. Checking deeper it said it failed to install, but we couldn't re-push it, because it was already "installed". We've now tried to push Edge, Firefox and Opera as testing and they're also not showing. However, both Edge and Firefox show in the Settings app, just not on the Home Screen. We control the contents of the Home Screen via a configuration policy and I have added the icons for all the browsers (tried as docked, on the home screen directly and within a folder). They still don't appear. This issue appears to be limited specifically to browsers, as we've recently pushed the Rakuten Kobo app to iPads and the icon appeared on all devices. Our app deployment settings for the browsers are identical to that of the Kobo app, using the VPP version of the app (not the iOS store app) and configured as device licenses (not user). This is happening on all of our iPads; iPad 4th Generation (iOS 10.3.3 - EOL) iPad Mini 2 (iOS 12.5.2 - EOL) iPad 7th Generation (iOS 14.5.1) I've gone through the configuration policies in Intune and cannot find anything related to restricting browsers. We have a call raised with Microsoft's Intune support, but they're taking a while to respond. Has anyone else encountered anything similar?
  21. Vale Technical installed our fibre and we use them for other cabling runs. They were originally introduced to us as an outsourced company from European Electronique.
  22. We encountered this a few years ago, though we weren't with Exa. Unfortunately, I'm struggling to remember exactly what the cause was. I have a feeling it was something to do with the Smoothwall filtering. We logged a call with Office 365 support, through the Admin Centre and they were using Fiddler to do the trace.
  23. That's scalper pricing. €876,22 is about £745, over £200 than MSRP for that processor. You're feeding the problem buying it from sellers like that.
  24. I received mine on Friday. Thank you.
  25. I think .ac.uk domains are for further education establishments. Schools (including those with further education provision) are usually either on .sch.uk or their own private domains (.co.uk, .com, etc).
×
×
  • Create New...