Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

RobBaxter

Members
  • Posts

    95
  • Joined

  • Last visited

Everything posted by RobBaxter

  1. hums .... No I just KNOW there was a huge bug of my MCITP on logging. You can set it up with log subscriptions directly to your DC.... this is something that i want to look at doing. So i will get on it asap and let you know how it goes!
  2. I recently bought some PCs, some of our older 15" flats didnt like them for some reason. My solution was to spend £2000 on monitors! I really didn't see it being an issue... talk about caught with my trousers down!
  3. OK with WDS there are now 2 different "unattend" xml files. Once which controls the Windows PE environment its self and one that controls the OS install. For the sake of argument, I'm going to assume that you know how to make a unattend file for the OS of your choice and to apply it to your image. The "Windows PE Environment" however can be also automated. To lets say "not require login" and "set the local information" as you rightly requested! But! The "Boot Image" I am talking about here is the one with "Windows 7", so the assumption is that, while you have XP clients, you must have at least 1 Windows 7 client. So in the WDS admin panel thing "god my brain fails me... msc panel?", under "Servers" select your deployment server and go Properties "in my case DC01", click the client tab and you will see where to apply unattend files to the boot image. YOu will need an unattend for x86 and x64 OSes... since you spoke about XP you will need 32 obviously... since I have no XP Station however, i only have 64bit, but for your help. I will paste in my .xml file now. en-GB Never en-GB en-GB en-GB en-GB true 1 Primary true false NTFS OS C 1 1 0 true 0 1 kingshott.local *** deployment Now, i have a password set in there which allows for "3 click install" of all my systems. As for your XP unattent xml, the one you had for RIS should work in the new system. Anyways! Hope that helps!
  4. It's something in windows update. *Fumes towards MS direction* if its Windows Server 2008 R2 (as i have) I am unsure as to if this happens on other versions. Anywhoo... let me explain. When my servers installed SP1 for R2 back in feb, when they applied the update, which the server was "online" maybe services apeared in a state of wierd 1/2 up 1/2 down mode. RDP was one of them, while authentication seemed to be functioning, the moment it tryed to show me a desktop the application just terminated as if i closed it my self. What I later found out, was while windows is applying updates "which in theory is only when it boots". Once the updates where applied, the RDP sessions worked fine. Now, its very coincidental that a professional such as yourself seems to have the "same" symptoms. Try taking a look at windows update and see if its glitching out on you, as maybe this is a reason for the "wierd time to kick in" as we all know, windows update is scheduled, do they coincide? Food for thought!
  5. First off if your clients are "Windows 7" then weather you use folder redirection or standard profile synchronisation, offline files is supported. By default, credential caching is on, so it should work out the box. Guide above is so useful, thx @strawberry for that, it goes on my list of usefull Technet Also just as a random bit of info, i have played with branch cache, those of you on "Multi Campus" nets may wanna take a look, it works pretty well and i'm sure pleasent on your lease lines
  6. I deploy since a full school year all my printers via GPO. There is no issue what so ever with the system, even the driver deployment works nicely. I do however, only have Windows 7 64 Bit clients... so it "should" work out the box of course.
  7. I would strongly recommend using GPO now for printer assignment under a windows 7 / server 2008 r2 environment. I use this in a live environment with no issues. Like yourself, I have printers in different locations and based on PC and "Teacher / Student" need to offer different printers. Thus GPO is really the only sensible or manageable way to do it.
  8. @apeo: its just a general rule. If you point the AppData folder to the server, you end up with all of the tempory stuff / configs and crap being a) sent over your network b) Read and Written from your storage array. c) Multiply that by every app that uses AppData storage, web browsing etc You have a right pain in the butt! Which is best avoided , SInce you have a HD in the box your using doing nothing really, might as well use it for something hey!
  9. @Ben-BSH: also, just since i have done this to the links above about 3 months ago, seriously, unless you want added grief, use a MAK Key and not a KMS Key if you have any option with that number of PCs, i have 110 stations. I tryed KMS thinking, it will be "Easier", attualy its more hassle. Probably though just inexperience of using them, completely my fault, BUT at the same time you get 500 activations with MS anyway
  10. @apeo: I personaly have profile v2 syncronisation at logon / logoff for the Appdata and Desktop. I don't restrict desktop usage (we are a Prep-School, they don't do what I don't want them to, I keep them out of what they need keeping out of ). Folder redirection for Pictures / Docs / Videos etc with a single K: map share drive for colab. It's been working quite well for over a year now. @Lewisbully: you can attualy do this with Group Policy, In the Server 2008 R2 version, you can attualy on a computer by computer basis clean the C:\Users\ Directory out at boot. This is what I use, and find it extreamly usefull. Also fyi, some stuff that just wont deploy? No MSI? I like to make a GPO with the Registery and Copy Folder to Local feature. Maybe I will write a tut on that as it cures so many evil issues.
  11. You know, I can't for the life of me remember his name. He was a total legend though, they work harder than we do at that place . grrr ... going to wind me up now! I might have to drive by . Cool to know, yes I studied at firebrand, self learning was never my strong point. Intensive 13 day course will all the caffeen you can consume, THAT i can do, go geek skills! Redbull, Nicotean and Caffeen is all i need. The food is passable too, i wouldn't say nice... but hey its an IT Training Camp, what would they do with a Michelin Star
  12. @apeo I used too, last summer holiday i did a complete start over of our school domain. From the ground up, we used it as it was the default and it was an oversight on my part. There are lots of "optimizations" shall we say that need doing with the way the win7 client interacts in my opinion. I have verbose on because I like to see what its doing, enough of waiting to see if my msi has deployed correctly
  13. I had this issue. Windows 7 has some pretty nasty (in our business) sync stuff by default. Trying to sync my teachers 2GB - 3GB profiles, can take a age, even with quite tip top internal transport infer-structure. What I now do, is only sync the App Data and Desktops. The rest I use folder redirection to create direct mounts over to our file servers. This way, logon takes sub 20-30 seconds in all cases. I strongly suggest tho, NEVER adding folder redirection on the App Data. Simply because the real time interaction will either slow/lag out the client station OR worse, overload your servers HD R/W ability. If you use a NAS or other storage array, its not going to take to kindly to being hammered by your clients. Also this cures a few wierd issues i get with profile / sync version issues. But thats a storey for another day!
  14. Hi, i did the new MCITP EA when it first started with the windows 7 module just before christmas (not the one gone, the one before). It was the most full, "lengthy" MS Course i could find. I went to St Neots where I happen to live to a very good company. I don't wish to advertise and break the edugeek rules, even if the company is nothing to do with me After i finished within 3 months, they were advising the SA. (It's all about the final example, weather or not you site the EA or the SA module). It is 100% worth doing if you can, and the difference between the EA and SA is practical 1 module, if you do both, you would get the credits for both. This is a Microsoft Certified Proffesional Level certification, but even if you can't quite make the EA or SA, the Technology Specialist modules in Server 2008 R2 (3 of them) and the Windows 7 one, is so usefull by its self. I listed my technology specialist certs bellow. If you want any help or advise regarding MCITP courses I am more than happy to help you out! I also host some low level CCNA (1 & 2) of the old stuff (its about 5 years old now), I studied at Coventry University doing there (Network Computing BSc), i have followed this up with the MCITP course for "inplace practical" qualifications.
  15. They really are not that hard, as long as you have spent along time around windows domain technology. I find it very easy to, fail, lookup, learn and repeat with IT related tasks, so i'm very practically skilled. However, i'm not so great and learning the theorys. Lucky for me the MCITP EA is all really task related so was perfect for me. ALso... branch cache (evil!)
  16. Hi Fellow Geeks! I have just undergone a nice little change of anti virus. To sophos! Now for those who may have just spent hours of you life beating you head against a brick wall I thought i would save you the trouble. Once you have got the Management console installed to your DC of choice, which is easy, you then try to protect PCs, just to have it throw back in your face that it didn't work. Well the reasons for this I am Afraid are 3 fold. 1. If you are on Windows 7 as I am accross the school, the RemoteRegistry service is off my default which is "Required" 2. By default the ports sophos needs to use are blocked by the nasty WIndows Server 2008 r2 windows firewall. So even if you do get it to install out of blind luck, the CP still fails you. arge! 3. to install you sophos you should NEVER use a domain account with admin rights. You need to setup a "local user" with "local admin rights" for this purpose. Sophos ofc, leaves that to you. So I have attached a backup of a GPO I call SophosMaster, it configures your entire domain to be "Sophos Ready". I do suggest however you change the users password in the local users section of the GPO. That can be found in the Computer Config > Preferences > Control Panel Settings > Local Users and Groups. by default its sophos and sophos, however mine certainly is not and I suggest strongly using a really evil password if possible! Hope you find this usefull! If so I will write more! SophosGPO.zip
  17. Just saying hi. No idea why I have done this so long and NOT been on here, but now I am. I'm sure my profile says it all and i'm a MCITP EA so im sure I will bump into you around the threads on MS gubbins. Also just finished cracking the evil which is Sophos Remote Deployment via there panel, i will write up a document on that soon. Is there a forum for "Anti-Virus" ?
×
×
  • Create New...