-
Posts
111 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Ergo
-
The other part for testing would be to run the script manually for a user where it did not work. This may be slightly more difficult as the users no doubt are prevented from accessing the Run dialog or loading the Command Prompt, but if you are happy to allow either of these for a short period of time to allow you to test all you would need to do would be to open either (although the command prompt is better as you will see error messages, etc) and run: cscript \\server\share\scriptname.vbs PLease substitue the correct path and filenames! If you get an error, please post it back. If it works please let me know. Thanks Dave
-
The setting I was refering to can be found in: Computer Configuration -> Policies -> Administrative Templates -> System -> Logon and is called Always wait for the network at computer startup and logon (screenshot below). Hopefully that helps. Dave
-
Apologies - I was also posting in that other thread. I will find it and post there Dave
-
@caffrey this may be me going down the wrong route, but is your network domain name .local if so you will have problems with apple mac computers in general - I am not a mac expert but my understanding is that MacOS uses .local to mean "the local computer". For this reason we have started using .internal or .school for domain names. Apologies if I have misunderstood your post. Dave
-
@Kineas sounds like you may have the GPO set for "Do not log users on with a temporary profile" and due to some problem with either creating or accessing a user profile for Win7 clients the user is not being logged on. This policy is a Computer Configuration policy, so may be different for the laptops/desktops depending on your GPOs/OUs. Regards Dave ps. apologies if I have the GPO setting slightly wrong - am writing this from memory!
-
Sorry for the delay. Sounds like when some users try to log on windows is trying to copy files into the start menu. Possibly because on the folder redirection you have the setting "Move the contents of Start Menu to the new location" enabled. (see pictures below). Neither of the two default tick boxes should be selected if you are redirecting to a common start menu. Regards Dave
-
You've got to love Microsoft's useful error logs! I will ask a couple of my tech colleagues if they have some suggestions! Dave
-
2h55 and counting... Live Broadcast | Red Bull Stratos
-
I would recommend this only be enabled if you are allowing offline files. If you are not allowing offline files then ensure you disable offline files for users, and set the "prevent redirected folders being automatically set as offline" GPOs. Yes, we always enable this - partly to get rid of the error, but does also speed up searching from Win7 clients. I have not seen problems based on the number of files, but then we also recommend separate file servers for Student, Staff and Shared files (separate VMs in most installs) to allow better load balancing across physical servers. I would also recommend enabling Remote Differential Compression on both Win7 clients and Win2008 Servers which can improve speed of uploading/downloading files. Regards Dave
-
@Darylrese there must be something else at play here. Are you getting any errors in the machine's event log regarding folder redirection, or group policy processing? Regards Dave
-
I am sure that you already have it on your list, but as you have not mentioned it - for all of the Schools and Academies we talk to server virtualisation with shared storage is assumed to sit underneath whatever vanilla (or other) network is being used - mostly because of how it can allow ongoing use even with server hardware failure, but also because of the ability to clone the "real" network into an isolated test environment for testing, practicing and validating application upgrades. SCCM has not been a standard for many of our customers, but with the changes to licensing which have just come in it does become simpler to consider. If you are planning on the install possibly being Summer 2013 then I would probably assume that at least some of your servers will be 2012 (eg. Domain controllers) but some application servers may 'still' need to be on 2008/2008R2. MS have already announced Exchange 2010 support on Server 2012 (in SP3). Regards, Dave
-
To resolve that you need to set the GPO for hiding the common programs start menu: Remove common program groups from Start Menu Regards Dave
-
Glad you got it sorted Dave
-
There are many reasons why your backups may be slow, and while they are running causing performance problems but I would in the first instance get a good undersatanding of how your VMware storage and backups are configured. There are many articles available online about how best to set up Backup Exec 2012 to back up VMware (including applications/databases within VMs) such as: BE2012 - Design/strategy - VMware based with GRT OR regular backups with periodic VMware backups | Symantec Connect Community As you have recently procured the solution I would recommend working with the supplier in the first instance to resolve - as this appears to be a backup issue I would hope they prioritise the issue for you. To ensure that we are not recommending you look at the wrong thing I would suggest testing performance/pings, etc when the backup is not running - I would expect the results to be significantly different if the backups are the cause. Regards, David
-
Microsoft Select agreement not signed by the Department of Education
Ergo replied to Lipjam's topic in Licensing Questions
Although it may be the case that you cannot access licensing through the previous BECTA select agreement (although I am not aware of this particular avenue for schools to purchase licensing, this does not mean that schools are not entitled to discounted pricing for any licenses from Microsoft. There are several avenues which you can pursue including setting up your own select agreement (possible but may require a minium quantity of licenses), utilising an alternate "shared" agreement such as from NAACE (depends on the reseller), or EES subscription agreements. In many cases now the EES agreements work out as very cost effective but without knowing your particular requirements I would not want to recommend any particular option as being the best for you, but if you would like to have a conversation about the various options I would be happy to PM, email or call you to talk them through. Regards, David -
Thanks for the additional detail. I would say that from the sounds of it the backup is the likely cause of your problems. I would suggest your only way to really be sure would be to stop the backup (possibly not ideal as it may have to be re-started from the begining if you do). I assume it is trying to complete a full backup of the exchange databases across the network as your initial backup? If you don't mind me asking what backup software/method are you using? Regards, David
-
Looks from your email like something funny is happening with your networking - it looks like there is a 10Mbps limit on network throughput which the server is constantly hitting against. I cannot see from the config screenshot which VMware NIC you have specified, but I would assume E1000. Need to ensure your VMware tools are installed and up to date within the VM, and may be worth looking at the physical network throughput against the host in case there is a wider problem. I have been advised by one of my colleages to look at whether you have traffic shaping set on the VM which could be limiting the server's access to network bandwidth. Also the network traffic does look like it is a "new" pattern may be worth looking to see if you can identify the source of that traffic (is it a client machine, other server, etc). Regards, David
-
How to secure my MSI mapped folder as a drive letter...
Ergo replied to kennysarmy's topic in Windows
Yes. All hiding the drive does is tell Explorer not to list it. If you have permissions and type (for example) v:\ into the window you will still be able to access and browse that folder. There is a separate GPO which is used to "prevent access to drive letters" which prevents users from accessing the drive but this would cause you more problems from how I understand you use the drive. Regards, Dave -
@Darylrese In my experience, looking at the RAM usage of exchange servers can be very misleading when looking at performance problems. I would recommend looking at the overall performance details of the server including disk IO, CPU usage, NIC traffic before you start chasing a solution. Memory usage would only generally cause performance problems if it results in significant page file usage (ie disk IO) which would (in my experience) rarely be the case on Exchange 2010 servers. For a virtual server you should be able to see some of the performance metrics from the virtualisation layer (VMware, Hyper-V, XenServer) which can be a more accurate view than the performance counters inside Windows but generally either will point you quickly in the right direction. Also worth noting that your ping speeds and other network speed issued could be completely separate from the servers (eg. a saturated network link between network cabinets/switches). To test for that specifically try pinging from different locations (eg. your PC, server sharing the same switch as exchange, etc). Regards, David
-
How to secure my MSI mapped folder as a drive letter...
Ergo replied to kennysarmy's topic in Windows
Yes it sounds like you have thought that through well With the permissions changes I would recommend testing on 1 folder before you go through the whole drive to make sure we have not suggested anything which will break your setup! Dave -
Not sure if your Virtual infrastructure has the capacity for it, but being virtualised does give you a nice option here. Take a snapshot of this server and one other DC. Clone the snapshots as separate virtual machines and boot them up in an isolated networking environment (so they cannot speak to your "live" domain). This gives you a test network to do what you like. I would certainly recommend creating a new VM and installing Windows Server 2008 R2 fresh on that - if you are able to create this test network then do it within that which will allow you to practice the migration from 2003 to 2008 using the backup method - we have done this on our in-house servers and it did work. Regards, David
-
How to secure my MSI mapped folder as a drive letter...
Ergo replied to kennysarmy's topic in Windows
1) Correct 2) Correct Yes, removing and re-creating GPOs for software deployment would cause the software to re-install (depending on GPO settigs) but as the drive is mapped for users this could not have been used for deploying software as Computer GPOs. I assume this means you deploy software using the User Policies section of GPOs? For the security settings it will be required for Domain Computers to have at least Read+Execute permissions - I don't think it requires full control. @kennysarmy I assume there is some reason you have mapped this drive in the first place - was it simply convenience or so users could access network applications which are also installed onto that share? Regards, Dave -
Just had a read and was surprised to find out that you cannot demote a 2003 server from being a DC if certificate services is installed. How irritating! I would suggest that your best approach here would be to look at migrating your certificate services Technet Guide then you can do what you like with this server. You will be please to know that since 2008 server the link between CS and DC roles does not exist so you will not have this problem again. If you use virtualisation then consider a server just to be the RootCA server - it will need very few resources but keeps things really simple. Dave
-
Ant, May be worth considering some sort of "Internet Cafe" offering in addition to BYOD - on if there are boarders who may need/want access to communicate with family, etc, out of hours, but do not own a PC/laptop. Microsoft discontinued SteadyState but there are instructions on Technet for creating a setup which will revert to defaults on logoff/reboot which would minimise the support requirement. I hope this helps Dave
-
@Sheridan for the domain controller role it should be easy enough to demote the server before the upgrade, but with the CA there are some challenges about creating a new server and re-importing/creating the certificates. We always recommend where possible that you install new OS from fresh rather than in-place upgrades - it may be worth considering whether you can replace your domain CA (which will require all certificates to be re-issued). this may not be as much of a problem as you think depending on how you use certificates. Regards, David
