-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
As an update to this thread, I've managed to be able to install the VPN for remote users, who can't use Software Center. Use PSExec to run the Powershell script that SCCM installs as the SYSTEM account Copy a known working/configured rasphone.pbk to the user's %appdata% location (While the user is logged onto their remote device as their cached domain account) Log the user into our RDS server, access their user certificate and export it. Upload it to their OneDrive and download it onto their remote machine. Then import the certificate into their domain account on the remote device. Steps 1) and 2) I have scripted but 3) has to be done manually. If I export a certificate from RDS as user Domain\User1 and install that on a local/non-domain account on their laptop, would that still be valid? Or does the certificate need to match the account using it? Also the VPN IKEv2 is configured to specify our domain CA server, so I assume that the remote device also requires a machine certificate to be installed from our CA in the Trusted Root CAs. I hope that means that user's can't use the VPN on non-domain machines.
-
I use Spiceworks and have done for many years. It's completely free and I had been running the on-site version, which requires a server to run it on. I used it purely for the Help Desk and don't use the more advanced features, like the inventory or purchasing. Spiceworks offer a free cloud-hosted version (less features than the on-site version) and it made sense for me, meaning I can have one less VM running. It does AD integration/authentication via a tool you install on a local server and manages fine as a help desk.
-
I watched this on Friday night and agree completely.
-
Whilst it's not necessarily related, I've been having issues with my Always-On VPN and I cross-posted it on Reddit, where someone suggested copying %AppData%\Roaming\Microsoft\Network\Connections\Pbk\rasphone.pbk from a working user to the affected user. I don't know if it would fix your issue though.
-
I have a post on Reddit too and one of the suggestions was to copy %AppData%\Roaming\Microsoft\Network\Connections\Pbk\rasphone.pbk from a working machine to the affected machine. This worked in the sense that the VPN connection appeared again, however it wouldn't connect because it complained about not having the certificate. I'm not particularly comfortable exposing the DC to the Internet. We have remote access to staff laptops, even if they're at home and not connected to the domain (Cisco Meraki's free Systems Manager software). So I can perform some testing. My idea at the moment: 1) User at home logs on as the local account on the laptop (not a domain account) 2) User connects to our RDS (when connected to RDS, as they're logging onto a domain machine, with their AD account - the certificate is installed by GPO) 3) Export the personal certificate and save it to the user's OneDrive (or elsewhere) 4) User disconnects from RDS, logs off the laptop and logs back on as their domain account 5) User downloads the certificate and imports/installs it 6) Copy rasphone.pbk to the user's appdata 7) See if it works I'm not sure what specific steps I need to take to export/import the certificate correctly. Edit: I have checked the certificate validity and the certificate issued is valid for 1 year.
-
It is using certificate authentication and the CA is on one of our DCs, so all clients have access to it, even when connected via the VPN. When I checked an affeceted user's installed certificates, the VPN certificate was missing completely. If it had expired, I would have expected to see it there but show as expired. I wasn't expecting for it to be missing completely. Is there a way that I can generate that user's certificate, transfer it to their machine and install it for them?
-
Get a FREE pair of socks with our webinar this morning!
CHiLL replied to VeryPC's topic in Our Advertisers
Surely nobody is going to turn down the option of more socks?! -
I hated that song, though it seemed everyone I spoke to loved it. Though I didn't hate it for the actual song, but for the fact it didn't fit in the film...that style of music I mean. It really took me out of the film because it didn't match it's 'period'. Yes I know it's an animated film and a fantasy, but it's set in an old-timey world, but with magic. Having heavy guitars and drums just really threw me. I had a similar experience when binging Peaky Blinders and they had cutscenes with modern music.
-
I've got a couple of users that had been remoting in via our Microsoft Always-On VPN, which is deployed out as an Application (Powershell script) via SCCM. However they've stopped working and the only way I've managed to fix this in the past, is to have the laptop in the office, logged on as the user and reinstall the application from Software Center. However I cannot use Software Center on a laptop that is not connected to the domain, because it errors during launch, saying it can't be loaded (same error message as if the SMSAgentHost service hasn't started yet). The command that the SCCM application uses is: Powershell.exe -ExecutionPolicy Bypass -File "VPN_Profile.ps1" -xmlfilepath "VPN_Profile.xml" -ProfileName "Always-On VPN" I have connected to the user's computer remotely and I can't use Software Center to reinstall it, so have looked to replicate that the PowerShell script does using the files copied from ccmcache and a PowerShell window. I can locate the files in ccmcache and copy them out to another location. If I use PowerShell in the user's context and cd to that location and run the following command: .\VPN_Profile.ps1 -xmlfilepath .\VPN_Profile.xml -ProfileName "Always-On VPN" I get the following message: Unable to remove existing outdated instance(s) of Always-On VPN profile: Access is denied. If I run the same command as an elevated PowerShell instance, I get the following result: User SID is S-1-5-21-. AlwaysOn : ByPassForLocal : DnsSuffix : EdpModeId : InstanceID : Always-On%20VPN LockDown : ParentID : ./Vendor/MSFT/VPNv2 ProfileXML : RememberCredentials : TrustedNetworkDetection : PSComputerName : Created Always-On VPN profile. Script Complete However no VPN appears in the list of network connections (as it would normally do when installed via SCCM) and nothing appears in the VPN settings applet. I don't understand why SCCM and PowerShell are having different results, executing the same command. How can I reinstall the VPN for a user in a remote location?
-
Coronavirus: General discussion (see opening post for rules)
CHiLL replied to Dos_Box's topic in General Chat
I'm not surprised. I still remember back in dial-up and when broadband was introduced, BT's support was along the lines of 'if you have internet connection issues, go to . Unless they think parents will have an internet connected phone, but would that rule them out of this survey? Or would it not class as 'connectivity for devices at home', given hotspot and data limits? -
Makes sense, sometimes people don't want to deal with a company that's several hundred miles away (for example, I have a support contract with a company in Coventry, which is fairly local). What sort of managed services would you want included? Some companies offer support agreements and some offer complete solutions. Companies like Stone, VeryPC, Proband all offer some form of solution options, though I can't comment on pricing.
-
What area of the UK?
-
Is that the live 'PE with Joe' videos, or his other ones too? I know in his live ones he's got a broken hand/wrist, so can't it properly. I found him to be too hyper/spontaneous in his live videos, which is understandable since they're aimed at kids, but I don't have kids and doing it on my own. I also noticed that as the days went on, his live viewing figures were just falling off a cliff as each day passed. I think that coupled with the fact he's also recording other fitness videos for his other series on the same day and tiring himself out...he's much less enthusiastic about the whole thing and sometimes he comes across as miserable or it's a chore/he's committed himself to do and doesn't enjoy it. I've found his 7 days of sweat a much better challenge, though I may consider switching to something else.
-
We generally do on desktop, server and network infrastructure. They were all purchased in 2015 and had a 3-year NBD warranty and have had their warranties extended via third party suppliers, on a two year deal. We renewed them again for another two years earlier this year. We initially planned the servers on a 8 year life cycle and the network on 15 years. The desktops were on a 5 year life cycle, though due to financial issues, that's been extended to at least 7.
-
No, she has no admin rights on the RDS host or her normal office PC. We've never had need for that and I'm strongly against granting local admin privileges for non sysadmins. I've only done it once in this school, because the site team need it on their desktop for the heating monitoring software and CCTV software. I've had no other issues in terms of requiring local admin, though on the odd occasion I've had to grand full control for a specific user to the C:\Program Files\SIMS folder.
-
I've been using in work and at home for a good couple of months now. It's been pretty good, though I do miss some of the features of Chrome, such as history/tabs/extension synchronisation. Once those (or at least just history sync) and the features @mullet_man suggested are implemented, I can see myself looking to start test deployments of this, replacing Chrome. (I'll probably keep Chrome on as a backup, but change the default browser and remove the shortcuts.
-
Our bursar did the rollover last week. Initially she was remoted in via RDS, however had issues printing (see the thread I created for this) as some stuff has to be printed and filed away for legal reasons. I couldn't sort the printing out remotely, so she managed to gain access to the site and print the stuff off. As far as I'm aware, she was successful in rolling over the year.
-
I did try and change the default printer in FMS, however it just wouldn't take it and revert back to the school office printer. I didn't try removing or preventing the other printers, mainly because they'd get automatically added back in during a session by GP (there's a setting where GPOs will re-apply during a session). I didn't actually think about removing the printers manually and trying that, though again, they'd get added during a session again. I could have gone and found that setting and disabled it temporarily, but again I didn't think of that. Since she was able to get on-site she managed to get everything sorted. If this happens again, I'll definitely try those steps. Hopefully it won't be needed now, as the end of year stuff is done and she can move onto processing payroll.
-
No, her school office was set as the default in FMS. FMS could see the PDF and home printer, however would send ALL jobs to the school office printer, regardless of which printer was selected. Even when I set the default printer in Windows, so other applications picked up the home printer...FMS wouldn't detect that at all and ONLY have the school office printer as the default. She managed to contact someone with keys to the building and got on site, so she managed to do the work she needed there.
-
Yeah, I loaded the Options module by mistake earlier and it's the first time I've accessed it...I had a flash back to 1998! We need the redirected printer though, because she needs to print the stuff to the printer in her home.
-
I've just had a call from our bursar, who is attempting to print off year end reports and roll over to the new year. Apparently this has to be done before she can do payroll for this month, so she's quite stressed. We do not have any access to the building at the moment because the head's decision was to completely shut the school, though the she is trying to contact the site team or one of the deputy heads to open the school for a couple of hours to print. To the issue; FMS is a bugger with printers, I know this. It doesn't print properly unless the printer you want to print to is the system default. She is working from home and accessing FMS via our RDS connection. So group policy is adding the normal printers she would have if she were sat at her desk, but obviously she can't access that printer physically. She has a small inkjet Epson printer that is connected to her laptop via USB and it works fine when printing from Word, even if when the job has been sent from Word on RDS (as it has redirected the printer/passed it through). However the system's default printer is still the her office one. I have managed to change that via Notepad (because the Control Panel/Settings applet are blocked on RDS for security) and changed it to her Epson inkjet. When I open up Office applications such as Word, Excel, etc...they all see this Epson as the system default printer and print to it. However FMS will still show her office printer as the default, even after closing the application and reopening it. I have absolutely no idea why. If I specify in FMS to use a different printer, it will print to the office printer regardless. Has anyone encountered this before or know how to solve it? If she can't access the building, I can see there being a lot of issues and questions asked.
-
I've started on the final season of Ray Donovan. I've always loved the show, though I have to be in the right mood to watch it. However I do thing it's come to the end of it's run and it's best to stop it now.
-
I've moved from doing the PE with Joe Wicks to his 7 days of sweat thing. Did the first one today and it was a step up, I'll say that much!
-
Finished Star Trek: Picard last night and really enjoyed it. I have Good Omens on my list next.
-
I've been on a couple of cycles this week, utilising Birmingham's new A38 cycle path. I have been critical of the expense and disruption caused by the council building this and the lack of cyclists in general in Birmingham. However it is a nice cycle path to use and has it's own traffic lights for crossing junctions, etc. As well as the cycling, I'm still doing the daily PE with Joe Wicks exercises. It's tough going!
