Jump to content

smarties11

Members
  • Posts

    645
  • Joined

  • Last visited

Everything posted by smarties11

  1. That's very interesting, thanks for confirming. I suspect that the article linked is talking about the actual guest account (which is disabled by default) rather than accounts that are members of the guest group. Out of interest, how are you getting on with your student accounts being member of guests? I'd be interested to hear your feedback as it certainly appears to work OK in my limited testing, but we've not rolled Win10 out yet. Not sure about your my docs issue. We redirect directly into the user area i.e. \\server\usershare$\%USERNAME% rather than \\server\usershare$\%USERNAME%\Documents, so the folder is created automatically when the user account is created anyway. The new 'microsoft way' is to redirect into %USERNAME%\Documents but as we've had ours setup the way it is since XP, I've not bothered to change it. The only issue we get is the user folders all showing up as 'Documents' when browsing the user share, but that's an easy fix and easier than restructuring the user areas. Perhaps we'll change it the next time we build the user file server.
  2. That's interesting - will try that on Monday - thanks! No issues with accessing remote shares - however our servers are 2008R2 and I've not disabled SMBv1 so perhaps it is falling back to that during handshake. Reading the article though I wonder if this applies to the actual guest account, that is disabled by default - rather than accounts that are part of the guest group? Win10 guest group description implies they have identical rights to normal users (but the disabled guest account itself has further restrictions applied). Will have to investigate in a bit more detail, as if accounts belonging to the guest group cannot support encryption then this is a non starter. Being able to force a temporary profile without belonging to the guests group is s cleaner solution, I feel!
  3. Yeah, same here, don't like the idea of profiles accumulating. There is a GPO setting to clear profiles older than x days but from what I've read it's not reliable. Delprof2 is a bit too Heath Robinson for me, better to fix the issue at source. Mandatory profiles would be the ideal I guess but i can't find a definitive answer about long term support of those in Win10? And I think they suffer with the same issue as roaming profiles in terms of start layout XML not reliably applying?
  4. Login times currently sub 30 seconds, but still have a few group policies to configure and applocker to set up so may increase a little. Staff with local profiles are the same for first login but much quicker on subsequent logins. I'm wondering if there is another way to force temporary profiles without being a member of guests - that would solve the one drive issue which we may use in the future.
  5. I'm also in the process of testing local profiles for staff with Win10 and everything is positive so far. I think lots of schools have moved in this direction already. For your user settings, check out U-EV (User Environment Virtualisation) which is built in to Win10 clients. It packages user settings up and saves them in a network share, so that their personal settings roam with them. It comes with templates already for Windows, Office etc but you can create templates for any application and capture the settings. I've not actually tested it here yet, but will be doing so next week. My understanding is that this should negate the need to redirect appdata too. If you don't want to combine the redirected with local start menu, enable the group policy option 'Remove common program groups from Start Menu' at 'User Configuration/Policies/Administrative Templates/Start Menu and Taskbar'. This will hide all start menu items in the all users profile, effectively showing only your redirected menus plus any installed UWP apps. That's what I have done here and it works well. For machines that have ad-hoc software installed that isn't installed site wide, you just need to ensure you have a shortcut in the public desktop folder so your users can access. For our pupils I'm currently testing having them as guest users (by adding pupil user group to 'guest users' group on the local machine - can be done by GPO) - as this just gives them a temporary profile which is deleted on logoff. Haven't come across any issues yet, except for OneDrive which fails to open saying it can't be used with guest accounts. We don't use it here though (yet, anyway). The other option is mandatory profiles but my understanding is that these don't work well with start layout xmls, in the same way that roaming ones don't. Failing that pupils will have to have local profiles too, but then that becomes another thing to manage with something like delprof2. Just going through all of this here now in my Win10 testing so hope this helps.
  6. Hi All, I've seen mention either on here or elsewhere at some point in the past about a piece of software that enables you to manage all of your remote connections in one app, and save all your assets and connection information. i.e. RDP, VMWare, SSH, Telnet etc all in one app. I can't remember the name of it - can anyone shed any light? Thanks
  7. Hi, On your printer mapping GPO, do you have an entry at the top to delete all network printers, set as '1' in the order? The default for Windows is to reconnect to any printers that have previously been added into the user profile. e.g.
  8. Hi All, Currently testing the use of local profiles as part of our upcoming Windows 10 deployment. Seems to be working well so far. Have started looking at U-EV for staff instead of redirecting appdata. However, for pupils my concern is hundreds of local profiles stored on machines. I appreciate I can use the 'deleting profiles older than...' GPO however I understand that this isn't reliable, and using delprof2 is an additional step. I started searching online around 'forcing temporary profiles' for students and came across an article stating that members of the local computer group 'guests' will always be given a temporary profile. I've added our student group to the guest group on a local machine and tested, and indeed the profile is removed at logoff. I can set this to apply to all machines using a GPO. Our students are already used to their profiles not persisting, so there is no issue there - but - can anyone foresee any issues with this approach? The description of the guest group in Win10 says that basically a member of this group has the same permissions to the local machine as a standard user, but I wasn't sure if making student users a member of this group added further restrictions? Would appreciate any thoughts before I do a full scale test! Thanks!
  9. I realise you may have this fixed now but I also had the same issue as you on 1709. To get it working, do the following Ensure that you are redirecting AppData too Create a new decimal DWORD registry key called SpecialRoamingOverrideAllowed at HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer and set it to 1 Your redirected menu should now appear at every logon without an issues - at least it does for us. Now just trying to get the start layout xml working - apparently not officially supported with roaming profiles but we shall see.
  10. Hi, Quick query with regard to ADMX files. If I copy Win10 1709 ADMX files to our SYSVOL PolicyDefinitions folder, can these be managed from... Server 2016 1607 GPMC Win10 1607 (with RSAT installed )GPMC Or do I need a Win10 1709 client with RSAT installed? Thanks!
  11. Haha! That doesn't inspire me with confidence. To be fair, our Backup Exec licensing is only £1k a year and my experiences with it are generally quite good. Veeam is definitely faster and does a lot of nice things that BE doesn't, but BE does the job for now.
  12. Fab, thanks Norphy, appreciate your help. I will be going to at least another two suppliers for comparison quotes but just wanted to ensure our incumbent quote was correct first for a benchmark otherwise it gets messy. I had that problem when the server 2016 licensing model came out, our incumbent (a different company to now) quoted and then I was getting mixed messages about the requirements from other suppliers! Will be interesting to take a proper look at DPM (I know the opinions vary on this product) as we are currently using Backup Exec for our virtuals and physicals and the renewal for that is this summer. I had been looking at Veaam but it's twice as expensive based on one suppliers quote!
  13. Hi Norphy, Thanks for all your help, I really appreciate it. Unfortunately our incumbent EES supplier have given us a new account manager who isn't really up to speed like our old one was. They had told me that I needed a ConfigMgr license rather than a System Center one, so I had assumed you could buy the individual components or the whole bundle. From what you are saying it seems our best bet then is to buy System Center data centre licenses for our VM Hosts, standard licenses for our three physical servers and then we'll be covered for the whole System Center suite including Ops Manager and DPM? I didn't realise the server licenses were so cheap!
  14. Thanks! Do you know how much a System Center licence is in comparison to just a ConfigMgr one? And also at what point it makes economical sense to buy Datacentre licenses for either System Centre / ConfigMgr as opposed to indvidual server licenses? Our two virtual hosts run 6 VMs each so wasn't sure whether to ask for 2 datacentre licenses or individual licenses for the 12 VMs
  15. Thanks for the clarity. I'll see how expensive the licenses are but in that case it might make more sense to handle server updates independently of ConfigMgr. We only have around a dozen servers.
  16. Hi, We are looking to move to SCCM as our deployment solution for Windows 10. We have used fat images and Ghost over the years but are taking a new OS rollout as an opportunity to move to a zero-touch, thin deployment system. As I understand it, the client CALs are included with the EES desktop pack and therefore we don't need to licence client endpoints. We won't be using SCCM for server deployment, but we may use it for WSUS. Do I therefore need to license all physical/virtual servers with a server endpoint license? Or can I get away with licensing just the SCCM server? Lastly, does the server endpoint license cover just ConfigMgr or the whole System Center suite? I've spoken to our the company who provide our EES agreement however we've got a new account manager and they aren't quite as clued up on MS licensing as our old one was, so I just want to make sure I know what is required before ordering. Thanks!
  17. Try PC Specialist - the VeryPC Ultrabook chassis is the same as the PC Specialist Lafite model
  18. Thank you both! I shall get SLT to put an agreement in place.
  19. Hi All, We have someone who is an ex-employee that is doing some consultancy and advisory work around SEN. Essentially this person is our old SENCO who has retired and is now training up an employee for the SENCO role. This is being done on a consultancy basis, i.e. the person is working as a private individual and submitting an invoice. Initially I was told that there would be no need for a computer, network account or SIMS account but now this arrangement has started, I've been asked for all three. This person is viewing and processing data about SEN students. I was wondering how this arrangement works in terms of the data protection act? Do we need some sort of an agreement in place with the invidividual, as presumably now they are classed as a third party and shouldn't be accessing data protected by the DPA. It's a temporary arrangement (until Christmas I am told) so it's just the DP side of things to consider and not GDPR. Thanks!
  20. I would say so. That's what I've done anyway.
  21. Have the PCs you are using definitely updated their policies? The default policy refresh interval I think is 60 minutes. You could try an agent wake-up call and ticking the 'force completely policy and task update' check box.
  22. For McAfee schools..... In addition to the rules mentioned by @jthompson above - there is an EXTRA.DAT available which will protect against this new threat until McAfee incorporate protection into their daily DAT file. I would recommend that all McAfee schools check this EXTRA.DAT in to ePO and keep an eye on this page (https://kc.mcafee.com/corporate/index?page=content&id=KB89540) for any updates to the EXTRA.DAT. With the WannaCry ransomware, McAfee were a good 3-4 days before protection was available in the daily DAT, so importing the EXTRA.DAT and monitoring for updates to it is critical!
  23. Thanks k-strider. Sorry, I should have come back to update, but I was able to automate the unticking of the "automatically detect settings" check box using a registry GPP, following the info in this MSDN article - https://blogs.msdn.microsoft.com/askie/2014/12/17/how-to-use-gpp-registry-to-uncheck-automatically-detect-settings/ This worked and I've tested on a few workstations and all is now well as long as the user logged on to the computer is the mailbox owner. However, I still can't get Outlook 2016 to connect to an Exchange 2010 mailbox for a different user when the logged on user has full access rights to the mailbox. Permissions are correct as it works in Outlook 2010. I'm just giving up - there's only one user on site this scenario applies to so I've just moved the mailbox to the account the user is logged on as and that works.
  24. Hi, thanks for your reply. Unfortunately that didn't work. However, I have got a bit further this morning. As in my original post, I had already noticed that having a proxy set made a difference to how long it took to come back with an error. With the proxy set, it takes a while, with it unset it is immediate. Playing further with the proxy settings, I've discovered that disabling "detect settings automatically" makes it work. Which is very bizarre?! However, now I know that I've googled Outlook 2016 and 'automatically detect settings' and others have had the same problem. Just need to test this now on a few more machines to make sure it is a reliable fix! So that's great - however what I can't get to work is connecting to a mailbox for another user. So for example, what I am currently trying to achieve is connecting our technician's admin account to her staff account mailbox. Permissions are all set correctly as I have tested in Outlook 2010. It still gives the same error about not being able to find the EAS server....
  25. Update: if I try logged in as the domain administrator account (which is mail enabled) it works perfectly first time. But with any other user it does not...
×
×
  • Create New...