Jump to content

Steve21

Members
  • Posts

    9,168
  • Joined

Everything posted by Steve21

  1. I know it's a slight off-track to the question, as I've seen a few threads on here regarding this (Some seem to use things like robocopy/rsync etc, while others are doing the full image/backup file), but I just wondered what's the actual legal/terms status around this? Seeing it's not actually a user who's using the storage is it a bit of a grey area, or has anyone found anything that say it's ok? With 15TB of legacy data to store somewhere would save a lot of cash on storage devices Many thanks, Steve
  2. It might just be if you have it set to only allow from certain IPs on your switch access etc, normally it shouldn't matter as it just requests a response on the VLAN (or equivalent IPHelper/DHCP options) Steve
  3. A few options I guess, Did the old Fog server use a different port? There's 7 and 9 normally, you can do a switch in the one I linked to try a specific one, as it might be it's using the wrong one Switch wise should only block it if it's set to a different IP etc than the old Fog server, and if it's on the same VLAN etc shouldn't be a problem, unless you have a specific MAC based ACL etc? Steve
  4. I mean if you know the MACs etc, you could just pipe them into a BAT with wol.exe https://www.gammadyne.com/cmdline.htm#wol Was what we used previously to SCCM Steve
  5. When you say whole domain does that mean some work and some don’t? If so is it across vlans and did you update iphelpers on router etc? Steve
  6. Good Afternoon All, So bit of a weird one here, recently changed jobs and taken over a school that's seems to have been run by a bunch of cowboys for many years, and it's a complete state, weird permissions bodges put in place all over AD/GPO, loads of 2008 servers with huge security issues, servers in-place upgraded multiple times with no cleanups in place, no proper documentation, 6+ long daisy chained switches etc etc and all! So certainly an interesting project to get stuck into Now one of my first things I need to get sorted is getting a clean state of AD to begin the healing process, but with thousands of random groups/users who haven't been used in ages, and the previously mentioned permission bodges etc, I'm seriously considering it might be safer all over to just rebuild the domain, considering there's no documentation as to what each of these bodges relates to, and by "fixing" one it's likely to cause problems down the line Now with so many servers that needs rebuilds etc, while I'd normally just go down the route of taking it offline over summer and bringing it all over to the new domain I really don't think that's going to be a choice here time wise Thinking of going down the route of side-by-side domains forested/trusted (obviously going to have to use another domain name for this), and then slowly migrating things over as I go, rebuilding a server at a time etc and fixing all the issues Now my concern is that using a cross domain/forest account would mess with the GPOs that are applying to said users depending where they logged on (Either the new/working side that might not play nicely with the bodges on the other side, or the bodged users logging in to a new server again with issues due to GPOs etc). Is there any way while all the users/pcs etc are trusted, that you fully block crossing GPOs, and forcing them to use the "correct" domain settings during their access to those services? (As a side note, the other thought was a fully AD default back to basic reset via Powershell, but obviously that could nuke some important bits if they are needed and hidden away!) Steve
  7. Did you check those GPOs out I said before? I'd still say 99.9% its down to them bodging your program files permissions Steve
  8. It runs automatically as a service, so normally it's on MIS as it just does its stuff It's not manual sync style program like some companies use. Steve
  9. Sounds interesting! Any further details on them? Pricing etc if you can say anything on it, always nice to see what’s available outside the “norm” Steve
  10. Last time I asked for it yep, they’ve disabled the individual license servers but if you have a valid key they give out a pre licensed installer Steve
  11. If you have a valid key you can contact SMART and they'll provide all downloads you need Steve
  12. It'll be in that folder you're running it as (C:\windows\system32 in your case). If you can't access that, run it like gpresult /h N:\gpo.html or whatever drive you do have access on Steve
  13. If you got access can you do a gpresult /h gpo.html and see what it's listing as having applied from that file Normally that sounds like one of a few items, either disabling the store, or applocker rules that aren't setup for apps (or depending how the build is done it could be a bodged profile/appx package, but if that was the case it shouldn't work before you join the domain, unless they're forcing a mand profile) Steve
  14. He's on about the old Veeam Free version I guess, the "new" free community one does yes Steve
  15. I mean it depends on your setup really You can install Veeam in a few places depending how you want it, personally we have it on a separate server in the backup location, so it's self contained if the main HOSTs die. But you can have it on a VM as well on the host if you want, personally I wouldn't install it neat on the host unless you really wanted to. It'll auto install the agent on the servers when they're added into the system Steve
  16. Mini you’re trying to make this a lot more complex than it needs to be, If the school is choosing to drop their OVS/KMS you need to make sure you’re picking something that replaces it, the options are as I mentioned above with the caveats You can argue round and round that one plan has an item another doesn’t but I’ll refer you back to my first line on that last post (wants vs availability) and leave it there as this will go on forever otherwise Steve
  17. I don't think it's a mess personally (no more than normal MS licenses), just think people are getting mixed up with what they want vs what's actually available to buy currently If you're going down the MS A3 route (again not Office A3 as in OP) you have to use EES as it's never been available on OVS, so you can get your device based licenses free If you're going down OVS, you don't have the option for MS A3 unless you're doing a hybrid, so you still have the KMS etc available for normal office and personal "plus" licenses on the normal 40:1 ratio If you're going down the CSP route, you're normally going cloud without servers (At the start they didn't even have the option to offer Server licenses on-prem, so had to double up licensing again, unless that's changed recently?), so you'll need to use either the lab rights mentioned previously again on the 40:1 ratio, or user based Basically it's pick a route, and that's what's available unless you're double licensing until it's changed anytime soon As a side note, Remember shared device activation has never officially been in the UK, it's always been using US "tricks" Steve
  18. I'm pretty sure you can also request free device based licensing for Win10/A3 (edu only) as I read about it before when flicking through some reddit threads Might be worth a shot asking your supplier Steve
  19. I mean if you've already done that (and set it up securely), why not just enable caching and act as their server? They'll download it from your site effectively, and you don't need DO internally that way (Ok bandwidth etc, but you'll be controlling updates still and assuming this is for lock downs etc, it's not going to be hundreds of clients and updates daily etc, and would work just like if they're on a VPN connection) Remembering that the majority will update internally, and only the odd offsite/maternity will really use that download speed, and during holidays etc will it matter if you're using more speed? (Personally always found DO to be a bit spiteful in terms of losing local storage, added network bandwidth etc, for not much gains) Steve
  20. Mu has its own config file that points to its default home path Normally that’s in the C drive so when it’s deployed a config file is pushed with it too, so guessing you have one still pointing to the old path Steve
  21. It should give you the option to export as a PST etc when doing it under content search etc (Rather than reports) And don't forget you'll need to go through and remove any other personal info from the emails before sending it the joy! Steve
  22. As long as you aren't deleting the machines from AD it'll keep the records in AD for the newly imaged machine. I did find a powershell script somewhere in the past that allowed a full export that I did once in a while in case we deleted something, but it'll still sit in recycle bin within AD etc as normal Steve
  23. Not really (at least during last few years), as soon as they encrypt it’ll copy it up to AD as an attribute on the computers it’s done on, and with the bitlocker management tools you can pull any back as required, remember it’s only needed if they forget their original key But obviously test test test Steve
  24. Ah fair enough, makes sense, guess we didn’t get it as didn’t use Pro on 7 Out of curiosity any reason you won’t let them do it themselves? With the ability to force how they do it, and auto backup keys to AD etc seems no reason not to let them, one less job for you Steve
  25. Are they signed into two accounts at all in Office etc? I've had similar before with a personal + work account being signed in, and the work one kept trying to upgrade to a higher edition than the personal which kicked it out everytime it did it Steve
×
×
  • Create New...