Jump to content

link470

Members
  • Posts

    254
  • Joined

  • Last visited

Reputation

55 Excellent

About link470

Personal Information

  • Location
    Canada
  1. Thanks. This is what I was after. I know perfectly well what options do what but wanted to hear it from someone who's actually had this exact setup where the share name is the same but the printer is different.
  2. Hi everyone, I use Group Policy Preferences (user configuration) to deploy a copier at a small office. The copier is the only printer on the network. The GPP option has always been set to "Create", and I've left it there so anyone who logs in on a machine they haven't logged into before simply gets the new printer. Done. Easy. Now, they've just received a new copier. The copier share name is the same, since the new copier is simply replacing the old copier. I replaced the driver on the server for that printer, set the options in the driver, and then changed the GPP option from "Create" to "Replace". This works. Everyone received the new copier the next time they logged in, as the GPP deleted the old printer connection and re-made it with the new one. My question is how long do I keep the "Replace" in there before switching it back to "Create"? In my mind, I'm thinking I'd have to leave it there before every user who's potentially logged into any machine before has logged into that machine again and had their printer connections swapped. Right now, the users won't be able to create their own preferences for that printer, because the copier connection will be deleted and re-added every time they log in. I was hesitant to set the GPP to "Update", since A, I didn't know if the drivers would change properly from the old ones, and B, I didn't know if that would overwrite custom settings set by the user in their driver every time. So what do you guys do? Should I leave the GPP set to Replace indefinitely? Should I set the "Run Once" box? Should I leave it at Replace for a couple more weeks then set it back to Create? If I leave it at Replace and Run Once, will new users who have never logged into a particular computer before receive the connection as if it was set to Create? What do you think? Thanks in advance!
  3. Thanks, I saw those earlier today and was going to use that as a last resort if I couldn't get the actual GPO options to work. Ah...no, I actually don't. Is it really just as easy as creating a PolicyDefinitions folder in the sysvol policies folder [where the ID'd folders are for existing GPO's] and then copy all files from C:\Windows\PolicyDefinitions to there, and add the new ones [minus unneeded language files] from the downloaded zip to there and overwrite existing inetres files? Or do I only copy the new files from the zip and leave the remaining C:\Windows\PolicyDefinition files where they are and not copy those?
  4. Hi everyone, I'm running into an issue with the new ActiveX blocking that Microsoft implemented. This particular network has a Windows Server 2012 [non R2] domain controller, and Windows 7 clients running IE 11. The problem is that even though the clients and server are fully up to date, I can't see the new ADMX templates for "Turn off blocking of outdated ActiveX controls for Internet Explorer on specific domains" and other new entries added due to the new ActiveX blocking. I would assume this is because Windows Server 2012 uses IE 10, not 11 [which I still think is insane that it needs to upgrade to R2 just to get a new free browser...but anyway]. Our Windows 7 clients use Java 6 Update 45, as the developer of the application they use only supports Java 6. I'm trying to enable the "Turn off blocking of outdated ActiveX controls for Internet Explorer on specific domains" GPO and push it down to allow those clients to access this site. But I can't see those settings in the GPO. I've tried downloading the ADMX files [KB2841134] and adding the template to the GPO I want to add the setting to by opening the GPO and right clicking Admiistrative Templates and choosing Add/Remove templates. This doesn't do squat. If I do that and then check Administrative Templates>Windows Components>Internet Explorer>Security Features>Add-on Management, I see no new settings. Has anyone had to bypass blocking for older versions of Java on Server 2012 [non R2] and actually had it work? Any advice would be greatly appreciated.
  5. I opted for just building the image again, only took me a few hours.
  6. Even with the SkipRearm=1 set? I thought it would need to be reactivated too, which was why I ended up pulling the ethernet cable after copying the image to the second computer I tested. But when it boot up for the second time after completing setup during the first boot, it appeared activated when I logged in as a local admin. The machine never contacted the internet from the time imagex copied the image to the time I was looking at the Computer Properties window showing Windows is Activated.
  7. It's for less than 10 computers. I'm just hoping to get these images pushed out and activated. Just need to know whether or not this image would be safe to use or not.
  8. Right, but I have SkipRearm set to 1, is that still ok to deploy this image? I was curious because I deployed the image to a second computer as a test, and after imagex ran, I unplugged the ethernet cable and restarted the computer. The machine still said "Windows is Activated" once setup completed and I was logged in, but couldn't possibly have contacted Microsoft to activate on a MAK key while the ethernet cable was unplugged. I then installed MSE though, and it didn't complain about windows being non genuine. So I don't know.
  9. Hi everyone, I've just finished creating an image for a small set of office computers [Windows 7 Pro 64-bit]. The image is very clean, and my sysprep script has skiprearm to 1, and also has 2 scripts that run after the image is deployed. One script sets the product key, and the other script activates it. Anyway, this works great. I captured the image, restarted the reference computer [which would be one of the office computers], and made sure sysprep ran correctly, which it did. However, since sysprep ran correctly, the product key was applied and the machine was activated. Normally, this is great. But I then wanted to add Adobe Reader [cause I forgot to add it to the image like an idiot], and change one other thing with the wallpaper image. Great, did that. Cleaned up again, and ran sysprep using the same unattend.xml. Captured image. When I restarted this time, again, everything went according to plan. But I didn't see the two cscript windows appear the first time I logged in as administrator. I checked Computer Properties though, and it said Windows is Activated. I also checked the event viewer though, and I see one of these: "Installation of the Proof of Purchase failed. 0xC004F050". Only once, at the beginning. The machine seems to be running fine, I'm on it right now typing this. However, it hasn't been on for more than 45 minutes or so, and I've seen some weird things while Googling the above event that say the computer could randomly blue screen after 3 hours and that sort of thing. I just wanted to check with you guys, do you think I'm ok to push this image out to the other few office computers? Or is it safer to scrap it and start again with windows not activated? Or should I just reapply the product key and activate again? Everything seems to work beautifully, just want to be safe. Any thoughts greatly appreciated, thanks in advance!
  10. Hi everyone, I have a computer here running Windows XP that its sole purpose is to run PlasmaCAM, an application that talks to a plasma cutter in the shop via parallel port. If a local administrator initializes the plasma cutter in the PlasmaCAM software, the machine initializes and works fine, and if I log in as a standard network user account, the machine initializes and works fine. BUT, if I restart the computer and log in as a standard user right away and try to initialize the machine, I get an error message that says "could not start port access driver" and I believe "code 2". Nothing shows up in the Event Viewer logs, but I can only imagine that some parallel driver needs to start at boot and is currently set to manual and only started when I initialize the PlasmaCAM machine as an administrator. What's bugging me most is I seem to have fixed this on a past machine and it WAS working, albeit with a PCI parallel card and not an internal parallel port, but I can't figure out what I did, or if the simple fact of running a PCI card instead of internal was enough to fix it. Any advice on how to start this "access driver" on boot up would be much appreciated. Thanks!
  11. Yup, I ended up using a subdomain of the external domain name when I did the rebuild a week ago, and that server is currently in production now and working great, with the website hosted externally outside the network.
  12. Ya I haven't tried using Explorer++, but I'm convinced it's a feature of UAC and by design. Although I'm still slightly confused at why that would be the case for a simple folder access. I can understand the need for UAC/permission add-ons for editing a core system file, and I can understand maybe launching a system application at an Administrator level, but just opening a directory that Administrators and Domain Administrators all have access to already according to the ACL's just doesn't make sense in my mind.
  13. Glad I'm not the only one! I think you're right, from the reading I've been doing too it appears to be a feature with UAC, albeit one that makes very little sense on anything besides the Windows system directories. So far, this is the best solution I can find, but I also haven't implemented it yet. The good news is it only deals with GPO changes and not editing the registry directly. Check out the marked solution on this page: All-users-required-for-folder-access. The main one that caught my attention was "User Account Control: Run all administrators in Admin Approval Mode: Enabled".
  14. Just a quick update, I rebuilt the domain controller today and used a subdomain of the FQDN. I think this should work ok. I'm able to access the externally hosted website now at least from the domain controller so I think I'm set.
  15. Hi everyone, I'm running into a weird NTFS/group permissions issue that I just can't wrap my head around at all. I'm really hoping someone can help me make sense of this. I have created a Server 2012 Active Directory domain and have created a second domain administrator account by creating a new user and adding that new user to the exact same groups as the default "Administrator" account. Seems simple, right? I've also created a default file share to be shared by all staff, as a test. The file share is in C:\Shares\SharedFolder, for simplicity sake. I've disabled inheritance on the "SharedFolder" and crafted my own permissions [keep in mind in Server 2000 and Server 2003 I have always done this and had absolutely no issues]. For share permissions, DOMAIN\Administrators = full control, and DOMAIN\Staff = full control. Both of these are groups. For Security, I have DOMAIN\Administrators = full control, and DOMAIN\Staff = modify. Again, both of these are groups. Then SYSTEM also has full control in Security. Great. Looks good. The identical setup on the previous Server 2003 network works flawlessly and always has. Now, because one of the 2003 servers is being carried over to the new network and virtualized, I've already used Disk2Vhd and converted it to a virtual machine, removed it from the previous domain, and added it to this domain as a test member server within Hyper-V on the domain controller. So, I then log out of the domain controller after making the group and security changes for the share. I have a login script that adds the share as a drive letter. Now, I log in to the domain controller [via RDP, same way I did the configuration with DOMAIN\Administrator] as the new test admin account, in the identical groups as the default Administrator account, and I notice I can't access the share. I see it in Computer, but I can't open it because I don't have permissions. Now, since the actual share folder resides on THAT machine that I'm RDP'd into, I open C:\Shares, and when I double click on SharedFolder, I got the "You don't currently have permission to access this folder. Click Continue to permanently get access to this folder." message, and then the Continue with UAC shield button. What's worse, is if I open a second RDP session and login as Administrator, and create just a new folder in the root of C, and then switch back to my test admin RDP session, I can't delete the folder without first right clicking on it, editing permissions, adding the test user that I'm logged in with, giving myself full control, applying, and THEN I can delete the folder. Just for fun, I logged in to the test VM I had carried over, running Server 2003, which is now on this network as a member server. I was able to log into that machine locally via Hyper-V manager, using the test domain admin account, and permissions worked perfectly. I could access the share with absolutely no issues and create and delete files/folders inside of it. Can someone please explain to me why this doesn't work in Server 2012, despite the test user having identical group permissions to the default Administrator account for the domain? I thought the idea was to be able to use groups whenever possible, but this share doesn't work unless I specifically define the individual user account of the new domain admin user. Thanks!
×
×
  • Create New...