-
Posts
254 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by link470
-
Printer GPP - Printer replaced, same share name, GPP setting?
link470 replied to link470's topic in Windows Server 2012
Thanks. This is what I was after. I know perfectly well what options do what but wanted to hear it from someone who's actually had this exact setup where the share name is the same but the printer is different. -
Hi everyone, I use Group Policy Preferences (user configuration) to deploy a copier at a small office. The copier is the only printer on the network. The GPP option has always been set to "Create", and I've left it there so anyone who logs in on a machine they haven't logged into before simply gets the new printer. Done. Easy. Now, they've just received a new copier. The copier share name is the same, since the new copier is simply replacing the old copier. I replaced the driver on the server for that printer, set the options in the driver, and then changed the GPP option from "Create" to "Replace". This works. Everyone received the new copier the next time they logged in, as the GPP deleted the old printer connection and re-made it with the new one. My question is how long do I keep the "Replace" in there before switching it back to "Create"? In my mind, I'm thinking I'd have to leave it there before every user who's potentially logged into any machine before has logged into that machine again and had their printer connections swapped. Right now, the users won't be able to create their own preferences for that printer, because the copier connection will be deleted and re-added every time they log in. I was hesitant to set the GPP to "Update", since A, I didn't know if the drivers would change properly from the old ones, and B, I didn't know if that would overwrite custom settings set by the user in their driver every time. So what do you guys do? Should I leave the GPP set to Replace indefinitely? Should I set the "Run Once" box? Should I leave it at Replace for a couple more weeks then set it back to Create? If I leave it at Replace and Run Once, will new users who have never logged into a particular computer before receive the connection as if it was set to Create? What do you think? Thanks in advance!
-
Thanks, I saw those earlier today and was going to use that as a last resort if I couldn't get the actual GPO options to work. Ah...no, I actually don't. Is it really just as easy as creating a PolicyDefinitions folder in the sysvol policies folder [where the ID'd folders are for existing GPO's] and then copy all files from C:\Windows\PolicyDefinitions to there, and add the new ones [minus unneeded language files] from the downloaded zip to there and overwrite existing inetres files? Or do I only copy the new files from the zip and leave the remaining C:\Windows\PolicyDefinition files where they are and not copy those?
-
Hi everyone, I'm running into an issue with the new ActiveX blocking that Microsoft implemented. This particular network has a Windows Server 2012 [non R2] domain controller, and Windows 7 clients running IE 11. The problem is that even though the clients and server are fully up to date, I can't see the new ADMX templates for "Turn off blocking of outdated ActiveX controls for Internet Explorer on specific domains" and other new entries added due to the new ActiveX blocking. I would assume this is because Windows Server 2012 uses IE 10, not 11 [which I still think is insane that it needs to upgrade to R2 just to get a new free browser...but anyway]. Our Windows 7 clients use Java 6 Update 45, as the developer of the application they use only supports Java 6. I'm trying to enable the "Turn off blocking of outdated ActiveX controls for Internet Explorer on specific domains" GPO and push it down to allow those clients to access this site. But I can't see those settings in the GPO. I've tried downloading the ADMX files [KB2841134] and adding the template to the GPO I want to add the setting to by opening the GPO and right clicking Admiistrative Templates and choosing Add/Remove templates. This doesn't do squat. If I do that and then check Administrative Templates>Windows Components>Internet Explorer>Security Features>Add-on Management, I see no new settings. Has anyone had to bypass blocking for older versions of Java on Server 2012 [non R2] and actually had it work? Any advice would be greatly appreciated.
-
I opted for just building the image again, only took me a few hours.
- 9 replies
-
- activation
- mak
-
(and 2 more)
Tagged with:
-
Even with the SkipRearm=1 set? I thought it would need to be reactivated too, which was why I ended up pulling the ethernet cable after copying the image to the second computer I tested. But when it boot up for the second time after completing setup during the first boot, it appeared activated when I logged in as a local admin. The machine never contacted the internet from the time imagex copied the image to the time I was looking at the Computer Properties window showing Windows is Activated.
- 9 replies
-
- activation
- mak
-
(and 2 more)
Tagged with:
-
It's for less than 10 computers. I'm just hoping to get these images pushed out and activated. Just need to know whether or not this image would be safe to use or not.
- 9 replies
-
- activation
- mak
-
(and 2 more)
Tagged with:
-
Right, but I have SkipRearm set to 1, is that still ok to deploy this image? I was curious because I deployed the image to a second computer as a test, and after imagex ran, I unplugged the ethernet cable and restarted the computer. The machine still said "Windows is Activated" once setup completed and I was logged in, but couldn't possibly have contacted Microsoft to activate on a MAK key while the ethernet cable was unplugged. I then installed MSE though, and it didn't complain about windows being non genuine. So I don't know.
- 9 replies
-
- activation
- mak
-
(and 2 more)
Tagged with:
-
Hi everyone, I've just finished creating an image for a small set of office computers [Windows 7 Pro 64-bit]. The image is very clean, and my sysprep script has skiprearm to 1, and also has 2 scripts that run after the image is deployed. One script sets the product key, and the other script activates it. Anyway, this works great. I captured the image, restarted the reference computer [which would be one of the office computers], and made sure sysprep ran correctly, which it did. However, since sysprep ran correctly, the product key was applied and the machine was activated. Normally, this is great. But I then wanted to add Adobe Reader [cause I forgot to add it to the image like an idiot], and change one other thing with the wallpaper image. Great, did that. Cleaned up again, and ran sysprep using the same unattend.xml. Captured image. When I restarted this time, again, everything went according to plan. But I didn't see the two cscript windows appear the first time I logged in as administrator. I checked Computer Properties though, and it said Windows is Activated. I also checked the event viewer though, and I see one of these: "Installation of the Proof of Purchase failed. 0xC004F050". Only once, at the beginning. The machine seems to be running fine, I'm on it right now typing this. However, it hasn't been on for more than 45 minutes or so, and I've seen some weird things while Googling the above event that say the computer could randomly blue screen after 3 hours and that sort of thing. I just wanted to check with you guys, do you think I'm ok to push this image out to the other few office computers? Or is it safer to scrap it and start again with windows not activated? Or should I just reapply the product key and activate again? Everything seems to work beautifully, just want to be safe. Any thoughts greatly appreciated, thanks in advance!
- 9 replies
-
- activation
- mak
-
(and 2 more)
Tagged with:
-
Hi everyone, I have a computer here running Windows XP that its sole purpose is to run PlasmaCAM, an application that talks to a plasma cutter in the shop via parallel port. If a local administrator initializes the plasma cutter in the PlasmaCAM software, the machine initializes and works fine, and if I log in as a standard network user account, the machine initializes and works fine. BUT, if I restart the computer and log in as a standard user right away and try to initialize the machine, I get an error message that says "could not start port access driver" and I believe "code 2". Nothing shows up in the Event Viewer logs, but I can only imagine that some parallel driver needs to start at boot and is currently set to manual and only started when I initialize the PlasmaCAM machine as an administrator. What's bugging me most is I seem to have fixed this on a past machine and it WAS working, albeit with a PCI parallel card and not an internal parallel port, but I can't figure out what I did, or if the simple fact of running a PCI card instead of internal was enough to fix it. Any advice on how to start this "access driver" on boot up would be much appreciated. Thanks!
- 1 reply
-
- non administrator
- parallel
-
(and 3 more)
Tagged with:
-
Can I create an Active Directory domain with external DNS name?
link470 replied to link470's topic in Windows Server 2012
Yup, I ended up using a subdomain of the external domain name when I did the rebuild a week ago, and that server is currently in production now and working great, with the website hosted externally outside the network.- 16 replies
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
Ya I haven't tried using Explorer++, but I'm convinced it's a feature of UAC and by design. Although I'm still slightly confused at why that would be the case for a simple folder access. I can understand the need for UAC/permission add-ons for editing a core system file, and I can understand maybe launching a system application at an Administrator level, but just opening a directory that Administrators and Domain Administrators all have access to already according to the ACL's just doesn't make sense in my mind.
- 6 replies
-
- administrators
- domain admin
-
(and 3 more)
Tagged with:
-
Glad I'm not the only one! I think you're right, from the reading I've been doing too it appears to be a feature with UAC, albeit one that makes very little sense on anything besides the Windows system directories. So far, this is the best solution I can find, but I also haven't implemented it yet. The good news is it only deals with GPO changes and not editing the registry directly. Check out the marked solution on this page: All-users-required-for-folder-access. The main one that caught my attention was "User Account Control: Run all administrators in Admin Approval Mode: Enabled".
- 6 replies
-
- administrators
- domain admin
-
(and 3 more)
Tagged with:
-
Can I create an Active Directory domain with external DNS name?
link470 replied to link470's topic in Windows Server 2012
Just a quick update, I rebuilt the domain controller today and used a subdomain of the FQDN. I think this should work ok. I'm able to access the externally hosted website now at least from the domain controller so I think I'm set.- 16 replies
-
- 1
-
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
Hi everyone, I'm running into a weird NTFS/group permissions issue that I just can't wrap my head around at all. I'm really hoping someone can help me make sense of this. I have created a Server 2012 Active Directory domain and have created a second domain administrator account by creating a new user and adding that new user to the exact same groups as the default "Administrator" account. Seems simple, right? I've also created a default file share to be shared by all staff, as a test. The file share is in C:\Shares\SharedFolder, for simplicity sake. I've disabled inheritance on the "SharedFolder" and crafted my own permissions [keep in mind in Server 2000 and Server 2003 I have always done this and had absolutely no issues]. For share permissions, DOMAIN\Administrators = full control, and DOMAIN\Staff = full control. Both of these are groups. For Security, I have DOMAIN\Administrators = full control, and DOMAIN\Staff = modify. Again, both of these are groups. Then SYSTEM also has full control in Security. Great. Looks good. The identical setup on the previous Server 2003 network works flawlessly and always has. Now, because one of the 2003 servers is being carried over to the new network and virtualized, I've already used Disk2Vhd and converted it to a virtual machine, removed it from the previous domain, and added it to this domain as a test member server within Hyper-V on the domain controller. So, I then log out of the domain controller after making the group and security changes for the share. I have a login script that adds the share as a drive letter. Now, I log in to the domain controller [via RDP, same way I did the configuration with DOMAIN\Administrator] as the new test admin account, in the identical groups as the default Administrator account, and I notice I can't access the share. I see it in Computer, but I can't open it because I don't have permissions. Now, since the actual share folder resides on THAT machine that I'm RDP'd into, I open C:\Shares, and when I double click on SharedFolder, I got the "You don't currently have permission to access this folder. Click Continue to permanently get access to this folder." message, and then the Continue with UAC shield button. What's worse, is if I open a second RDP session and login as Administrator, and create just a new folder in the root of C, and then switch back to my test admin RDP session, I can't delete the folder without first right clicking on it, editing permissions, adding the test user that I'm logged in with, giving myself full control, applying, and THEN I can delete the folder. Just for fun, I logged in to the test VM I had carried over, running Server 2003, which is now on this network as a member server. I was able to log into that machine locally via Hyper-V manager, using the test domain admin account, and permissions worked perfectly. I could access the share with absolutely no issues and create and delete files/folders inside of it. Can someone please explain to me why this doesn't work in Server 2012, despite the test user having identical group permissions to the default Administrator account for the domain? I thought the idea was to be able to use groups whenever possible, but this share doesn't work unless I specifically define the individual user account of the new domain admin user. Thanks!
- 6 replies
-
- administrators
- domain admin
-
(and 3 more)
Tagged with:
-
Can I create an Active Directory domain with external DNS name?
link470 replied to link470's topic in Windows Server 2012
Ah, too bad. I totally thought this is what everyone was recommending I do, I didn't know I should have made a subdomain instead. Does anyone else have any ideas of how this could be done? I'd prefer to not completely scrap the domain and restart, but I guess I could if I have to.- 16 replies
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
Can I create an Active Directory domain with external DNS name?
link470 replied to link470's topic in Windows Server 2012
Thanks again everyone, trying to figure out something else now that could potentially pose a problem, but I'm sure there's a workaround in DNS. Let's say that I have the website, , hosted outside of this windows domain on a central web server running websites for our whole school district. Right now, since I'm using FQDN for the internal Active Directory domain name, if I go to a test domain member and type in http://department.district.province.country, I of course reach the default IIS 8 page for the domain controller. Pings from inside the domain network for resolve to the domain controller. If I add an A record for www and point it to the district web server IP address, I can ONLY use the www. prefix before the web address to access the site, and even then the page doesn't load any CSS or images because the page redirects to http://department.district.province.country without the www's because we're trying to get people away from using www's in front of subdomains. Is there a change I can make in DNS somehow for this to happen? Or now that I'm using the FQDN for the domain controller, do I HAVE to have the website hosted on the domain controller? There has to be a way to redirect outside the network, even without www's. Thanks!- 16 replies
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
Can I create an Active Directory domain with external DNS name?
link470 replied to link470's topic in Windows Server 2012
Awesome, that's exactly the kind of responses I was hoping for : D Very glad to hear you are all having positive experiences with using the external domain name. Just installed Active Directory on Server 2012 and went with the external domain name myself. I think as long as I add the right host header name and one for www in IIS, and add a www cname to DNS, I should be set. I'm glad I'm not the only one, I've definitely heard of the exact same issues with Mountain Lion completely dropping support for .local and some other strange apple related issues. Seems the .local TLD is on its way out. Thanks again!- 16 replies
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
Hey guys, I'm creating a new domain for a department in the district who has a separate setup than the rest of our district, and I've always used .local domains in the past. However, for this setup I'm thinking of using the actual domain name, . Now, if I use that domain name when I configure this new server running Windows Server 2012 Standard when I'm adding the Active Directory role, can anyone see any downsides? This server also hosts the website for this department via IIS [previously 6 on 2003, now will be 8 on 2012], which is accessed at , the same domain. As I said, in the past, I've used .local on their last network [XP/Server 2003, which I'm currently switching them from and then updating their laptops to Windows 7 and connecting to the new domain once I've configured it]. Does anyone see a problem with using the same domain name as the internal Active Directory Domain? I'd usually think not, but I seem to remember in University at one point our instructor saying "if you make the domain name the same as your external domain name you may have some issues". Any advice would be great! I plan to install the Active Directory roll today. Thanks in advance!
- 16 replies
-
- active directory
- domain
-
(and 3 more)
Tagged with:
-
I just tried resetting the Windows Update client store, as well as checking the machine for malware, and the reset didn't work and the system scans were clean. The system appears to be very clean too, nothing else installed since I originally built it. The only thing I found was the Ask Toolbar, and I removed that as it must have come in with an installer. Otherwise, everything else is as it should be and very clean. I can install other software and run Apple Software Update to update Quicktime perfectly fine. Any other suggestions? :: EDIT :: Partially fixed...I managed to get a large amount of the updates installed after performing the steps labled as "Answer" here. Now I'm down to only 3 updates, and unfortunately, those ones are failing with a nasty error 80070490. I've checked the Microsoft article on this and they say the only 2 things to do are to install the System Update Readiness Tool, or to do a repair install. I've already tried the first option, and that didn't work, and I've seen from a lot of people online that the repair install doesn't work either. Anyone have any good fixes for Windows Update error 80070490? I was SO close! Updates were working great until these last 3. I've also tried installing them from the standalone KB file from Microsoft Downloads too, of course. That also didn't work.
-
Sorry, I totally forgot to mention that I had tried this as well. The results came up clean. I haven't, but I'll try that later on. Not that I know of, but a malware check with several applications [MSE/MalwareBytes/etc.] is on the todo list. I'll let you know how things go. The real thing that kept throwing me off was that ESENT error that repeatedly showed up, and I couldn't help but think that maybe that and Windows Update not installing updates would be related. Right now the system says it has 20 important updates and 4 other updates. I was able to hide the Bing Desktop updates, and that worked, it no longer shows up in the lists. I can also check for updates, and select one, and see it try to download the update, and even look like it's going through the installation. Then at the end it fails with the good ol red X shield and ever so conveniently, a different error code almost every time. Thanks again for your suggestions, I'll try the client store reset tonight.
-
I've got a rather annoying issue that I'm working on with a Windows 7 Professional x64 install I did on a standalone computer last year. The machine was working perfectly fine for months, and in fact, is still working fine. But I recently found out that the machine hasn't been running any updates from Windows Update. I tried the usual Windows Update component fixes and running the Windows Update troubleshooting/fix utility built in to Windows 7 troubleshooting and they don't fix the issue. When I checked event viewer, I discovered a stream of Event ID 447 errors in the Application log: Catalog Database (1320) Catalog Database: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 9, PgnoRoot: 39) of database C:\Windows\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb (6312 => 6134, 10). Looking at the history of the Application log, I discovered that this error has been occurring regularly since around November 2012. I do seem to remember that machine having issues with updating at the time, and I managed to get the updates installed by installing them either 1 or a few at a time, and eventually they all went. But now I can't get a single update to run, not even by searching Microsoft Downloads for the KB number and downloading the update standalone. It fails to install as well. I've ran a full chkdsk /r, I've ran ViVARD hard disk diagnostics from a Ultimate Boot CD, and I've ran MemTest+ overnight on the machine for a full 8 passes of the 8GB of RAM. No errors in anything. Windows continues to perform great and work perfectly fine in everything else. Any ideas of what could be causing this and how to fix it? About the only things I can think of left are a repair install of Windows 7, or a complete reinstall, which I'm trying to avoid as everything else works so well. Thanks in advance!
-
It seems to, although all of the printers here I'm trying to install are HP. We're actually using a Linux print server, and that's what I'm trying to print through. It's hit and miss, some of these laptops I'm configuring [all with the same driver and build] are able to send print jobs perfectly fine. Others give me the exception error above, despite the adding of a new network printer succeeding and the printer showing "ready". Still can't print to it without whatever application that tried to print crashing, or access properties without explorer crashing. I'd say it's because of the Linux server, but that doesn't explain why several are working fine. I'm also supplying the driver straight to the laptop and choosing "Have Disk". It's not obtaining a driver from the server. Also, connecting directly to the TCP/IP port by choosing "local printer" works perfectly fine. I can connect directly to the printer using the same driver with no issues every time.
- 8 replies
-
- driver
- hp printer
-
(and 3 more)
Tagged with:
-
Thanks for your reply. Unfortunately, that didn't work. Under a separate local profile as a standard user, and after adding the network printer, printer properties still gives me the same error. Any other ideas?
- 8 replies
-
- driver
- hp printer
-
(and 3 more)
Tagged with:
-
Hi everyone, We have a number of laptops running Windows XP SP3 that communicate with a print server and I'm adding network printers to them, and then creating a default profile. This works on some laptops just fine. However, I'm having a very annoying issue that causes the following error to come up whenever I right click the printer in Printers and Faxes and select Properties: "Function address [different number every time] caused a protection fault. Exception code 0xc0000005. Some or all property pages may not be displayed.", and this is for Explorer.exe. Trying to print to the printer will also cause whatever application was trying to print to crash. Even just choosing File>Print in some cases without even attempting the print itself, will crash if the network printer is the default printer. One thing that DOES work, is if I create the printer as a local printer and don't run it through the print server. If I create a local IP port, and select the driver, it works perfectly. No crashes. I've tried numerous things to get it to print through the print server: •Different driver versions •Clearing the driver from Server Properties in the Printers and Faxes file menu •Emptying the spool driver cache •Viewing around 10-15 pages deep in Google search results for that error message and have tried almost everything mentioned The most annoying part of all is that out of all of the laptops that I have this set up with [configuration being basically the exact same for each laptop], some work, and some don't. I set all the printers up the same. Certain laptops I can log into as a network user, print to one of the network printers, and have absolutely no problems. Others, crash constantly with that error when viewing print properties, or crash whatever application is trying to print. Any help would be greatly appreciated. Thanks in advance!
- 8 replies
-
- driver
- hp printer
-
(and 3 more)
Tagged with:
