Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Michael

Edu Supporters
  • Posts

    12,849
  • Joined

Everything posted by Michael

  1. But we're in the age of multi-core or more processors and 8GB+ memory as standard on a basic server. The GUI can't be that demanding on resources! I just think the argument is somewhat flawed - it's still Windows in the background and can't be compared to the likes of Linux. Web providers still favour Linux due to its open source code and low overhead, but removing the Desktop Experience can't speed the server up that drastically surely? Please prove me wrong someone!
  2. I've never quite understood why not installing the GUI reduces the surface of attack? How many GUI (Desktop Experience) flaws have there been in recent times? I'd always recommend installing the Desktop Experience as well as RSAT, then focus on using RSAT as much as possible for day to day tasks.
  3. You buy into a volume license agreement for Office, as you would Windows. The PDF converter is built into Office itself - File > Save as, change it down to PDF from DOCX.
  4. Office 2013 or Office 2016 is the way to go, with no requirement for third party software.
  5. Thinking about it, the problem has been created with newer Microsoft OSes to tighten up security, so the limiting factor is still the client rather than the server OS in this case. You must (logically) have a newer server somewhere in your domain 2008 R2 or later, with Windows 10 GPOs installed, which then allows you to control the behaviour of Point and Print Restrictions. In saying that, I would suggest ditching 2003 altogether and moving your servers to 2008 R2 or later. Then the reg fix would apply.
  6. Have a look here, it may be linked.
  7. Thanks for this, but I'd rather wait until Canon release it through the proper channels. I can confirm however it has worked 100% with the Canon drivers, so will try it out with RISO's next as their drivers are even worse.
  8. Essentially what's happening is if the driver isn't packaged (like the Canon drivers), it will ignore the 2 x Do not show warning or elevation prompt. Using the registry tweak above will make Windows Server 'think' the driver is packaged and install it without prompting the end user.
  9. Last I checked they still hadn't (yesterday). This issue only came about as the network in question and printer drivers were installed prior to July 2016. I was required to update the drivers yesterday and there was the problem. End users see the 'Trust driver install' notification, but despite clicking Install, it continues to re-prompt them.
  10. Hello all, Note this involves modifying the Registry, so please take care! As many of you are aware, installing KB3170455 and equivalent can cause havoc with Point and Print Restrictions, but I've stumbled across a few websites and came up with the following - If you navigate to Admin Tools > Print Management. Highlight your print server, then 'Drivers' Scroll across to the 'Packaged' column. If the driver reads 'true' it means it can be deployed with Point and Print Restrictions without prompting the user. If it reads 'false' it means the driver won't work well with Point and Print Restrictions, however the following tweak makes Windows Server treat the driver as packaged. Close Print Management, then open regedit and navigate to (in turn): HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Environments\Windows x64\Drivers\Version-3\Printer Name HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Printer Name Look for 'PrinterDriverAttributes' and set it to a value of 5. Now restart the Spooler and return to Print Management. The 'Packaged' column should now read 'true' for all printers you modified. I've so far tried this with a Canon Photocopier, as none of their drivers are packaged and neither are RISO's or Oki (next on the list). Ricoh's and Kyocera's are packaged and HP are 50/50 depending on the model. I hope this helps someone else
  11. Yes you have to uninstall the whole Cumulative Update, even though 95% could be OK, and was limited to a specific component. Evidently Microsoft have published the September Update twice for build 1507, once for 1511 and three times for 1607. Definitely not ideal when we're talking about update files which are hundreds of Megabytes or more in size!
  12. I'm on the fence with this one - Yes single Cumulative Updates are useful, but then each month it's getting progressively larger and takes more resources to deploy. If I have a machine that's already updated to September, I'd still prefer to have 12 separate updates per year, rather than download the same information 11 times prior - downloading/installing in order. It could mean the difference between installing a 50MB update and a 500MB update.
  13. I agree with others - why release an Evaluation ISO and not the actual ISOs? I wonder if they're going to include the latest October patches (due 11th October), but I'd be surprised if this were the case, or if it were something serious?
  14. NETSH WLAN is definitely the way to go. Initially when joining the domain, your workstation needs to be connected to receive the wireless profile. Afterwards, you can do it wirelessly as follows - Keep your old wireless network online, and use the NETSH WLAN command in a Startup script. In a few days, check a few devices manually to check it has received the new wireless profile. Once you're confident it's worked, over night switch off the old wireless network and enable the new wireless network. Clients should then connect to the new network automatically, providing the security details are identical. I've done this numerous times and it works well. Optionally afterwards, use NETSH WLAN to delete the old wireless profile name, but in saying that, it is optional and not required.
  15. DNS can take up to 72 hours to replicate globally across all main DNS servers, so it's definitely something you need to sort ASAP.
  16. Changing registrar will not wipe e-mails, but it must be done carefully to minimise disruption to Mail flow. Late at night/early hours of the morning when mail traffic is low would be recommended, but in saying that, given that you've already changed registrar I suspect e-mails have stopped working until you populate the MX records.
  17. Within the O365 Admin Console, when setting up your domain and its MX records you can use the wizard to 'talk' to GoDaddy for you (using your GoDaddy user/pass) and it enters all the info for you. This guide explains how to 'point' your domain to Wix, but generally speaking DNS is the way to go. WIX provide you DNS addresses and you input those within GoDaddy.
  18. I do exactly this with Classic Shell - hide/restrict 'Settings' but allow certain CPLs into the 'old' Control Panel in combination with standard Microsoft GPOs.
  19. Before you all get excited - yes it works OK and is better written than the Java version, but I have serious issues running Sysprep with Minecraft Edu as described here. If someone can solve this one, as everything I've tried doesn't work. I don't fancy installing it manually on hundreds of devices!
  20. On closer inspection, the Powershell script is using this method and I can see the: /Online /Add-ProvisionedAppxPackage Command, so I'm at a loss as to why Sysprep is unable to Generalise, as the App is provisioned for all users. I've attached the Powershell script as it's too big to post.Install.ps1
  21. Hi all, Currently building/testing a new 1607 image, however I've stumbled across an issue running Sysprep along with MinecraftEdu pre-installed (The Microsoft version, not the Java version). I downloaded and ran the Offline version of MinecraftEdu. I can run Sysprep without the Generalise option, but that of course is no good for me! I then ran the following commands in the context of the account you install MinecraftEdu - (elevated Powershell) - Get-AppxPackage | Select Name, PackageFullName And then: Remove-AppxPackage Microsoft.MinecraftEducationEdition_0.142.0.0_x86__8wekyb3d8bbwe Sysprep now runs fine and I can run with the Generalise option, but of course MinecraftEdu is now uninstalled. So how (if possible), can I include an image with it included?
  22. Just a thought, are you running any flavour of 2012 Sever? It sounds familiar and is well discussed on Edugeek. The core issue appears to be SMB related (top of my head).
  23. Thank you, that worked like a charm! Of all the years I've worked in IT, I've never exercised such drastic measures! It's something I probably last looked at in the Windows 2000 days (showing my age)! Thanks again guys!
  24. No Sysvol isn't replicating correctly. I can transfer the PDC and Infrastructure roles. I can't do the remaining three as the FSMO holder cannot be contacted.
  25. Hi all, Here's the scenario, any help would be much appreciated - 2 x 2008 R2 Servers configured as Domain Controllers, the one DC has all roles. The DC with all the roles was restored, however although it appears to be working, it is/isn't working fully and likewise clients connecting to it. On the Secondary DC, AD looks normal as does Sysvol. On the Primary DC, Sysvol does not look normal, but is retrieving AD and GPOs from the Secondary DC. DHCP and DNS are working OK. Clients are unable to map all drives hosted on the restored DC (as far as I can gather), as the computer account SID has changed. Any ideas how I can resolve this would be much appreciated!
×
×
  • Create New...