-
Posts
1,402 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ADMaster
-
I think I read in another thread if you disable the option for them to sign in to the browser, it will also disable the welcome screen.
-
Well I have two more ideas Enable Ephemeral mode via GPO, I've never used it but it says it will delete all profile data after the browser is closed. Script the deletion of the chrome profile folder from appdata. I'd try Ephemeral mode first.
-
The keyboard shortcut to reset to 100 is ctrl+0 maybe stick it on a sign. In my experience chrome zooming is per website and per user. Do the users not log in as themselves?
-
Looks like you have it worked out and I'm late to the party but... Can you extract data from sims with direct SQL queries? I use powershell to extract the data directly from my MIS via SQL, do some logic on it and put it into the format AR want. However, I do not use Scharacteristics as it is not a required field. This may be a goal you can work toward to semi automate the process for you. Now if only you could automate the import without it costing an arm and a leg. I had no idea anyone used AR over there, welcome to the fun and terrible imports.
-
[1709, fcu] Question on deployment of ADMX Templates
ADMaster replied to speckytecky's topic in Windows 10
yes I use a similar script to Arthur that will get rid of the apps for you. The msi installs to C:\Program Files (x86)\Microsoft Group Policy\Windows 10 Fall Creators Update (1709)\ Then just copy the admx and adml files to your central store \\domain\sysvol\domain\policies\policydefinitions If you don't have a central store... https://support.microsoft.com/en-us/help/3087759/how-to-create-and-manage-the-central-store-for-group-policy-administra You do not need to copy all the adml file folders, just the English ones, unless you need others. -
Here is my one drive removal script. I also have the gpo set. I do not have anything about one drive in explore or in the start menu. It's been a while, but I think the runone uninstall may remove it from start. $OSDISK=$env:OSDISK REG LOAD HKLM\DEFAULT $OSDISK\Users\Default\NTUSER.DAT REG DELETE HKLM\default\software\Microsoft\Windows\CurrentVersion\Run /v OneDriveSetup /f REG DELETE "HKEY_CLASSES_ROOT\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /f REG DELETE "HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /f REG ADD "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce" /v removeonedrive /t REG_SZ /d "%SystemRoot%\SysWOW64\OneDriveSetup.exe /uninstall" /f REG UNLOAD HKLM\DEFAULT Hope this helps
-
GAFE Creating Alias for a different domain not mail enabled in GAFE
ADMaster replied to mowgli82's topic in Cloud Services
If I'm reading this correctly your second domain is a domain alias of the first? Go into the admin console > domains > add domain or domain alias. Does it read something like this seconddomain.sch.uk Domain alias for primarydomain.education If this is the case just create an alias for the user and it will be an alias on both domains. -
I think I have the roles bit configured now so it is restricted to staff only. That's a huge step in the right direction.
-
Hi all, I have a ZD 3000 updated to the V10 firmware. I'm exploring using guest passes but can't seam to get them configured correctly. I finally have the email sponsor bit working, but any user in the domain can be a sponsor. I'd like to restrict this to just staff. If I go with the admin generated guest pass... can I restrict this to just a few users perhaps in an AD group? Can I restrict the number of devices they are allowed. I don't want someone generating an unlimited devices pass valid for a year or something silly like that. When I try pressing device registration instead of guess pass, no passwords will work. Am I overlooking a pre authentication ACL somewhere to deny all traffic until they get a valid guest pass? Any chance of dynamic Vlans working to provide different levels of access? Should I make my guest ssid radius auth and create guest accounts in AD? The back story / reasons for these changes is we currently have 2 main ssids schoolname is an ssid with radius auth and dynamic vlans to provide various levels of accessed based on staff / year group. guest is open with splash tos page restricted to that of the youngest students as they can't be identified. We have adult presenters come in who should have staff level access to the internet, but I can't raise the level of guest access with out putting in some sort of checks or all students would be on it. Other ideas / advice welcome too. Thank you,
-
Start it via a powershell script and put in a sleep time before the program starts.
-
I'm not familiar with this particular software, but this from the website you linked. We have two print contracts, one for mfp and the other for all the laser jets. They each wanted to me install their own software, I've configured each to only look at the devices we have on contract with them.
-
Google introduces Chrome Enterprise subscription for businesses
ADMaster replied to Arthur's topic in Cloud Services
61 didn't last too long, almost 2 months on 60 and only 3 weeks on 61. -
oh the suspense
-
robocopy - How to get relevant data from log file
ADMaster replied to Shadow_Walker's topic in Windows Server 2012
When you do a robocopy there are a few columns of data, copied, skipped, failed. So for every copy job your going to find the word failed. try starting robocopy from powershell and allowing it to pass the exit code back, then write that to a log file. Here is a reference on exit codes https://blogs.technet.microsoft.com/deploymentguys/2008/06/16/robocopy-exit-codes/ barring that, I think the most common errors are time out and accessed denied so try searching on those terms. I'm sure there is a powershell equivalent, but also try running them through grep on a linux box. cat log.txt | grep denied ah looks like select-string https://communary.net/2014/11/10/grep-the-powershell-way/ -
For that setup, I'd skip the whole domain setup and do it all by hand. What version are the clients, home / pro? To really block things on a domain you would need at least pro but preferably enterprise / education so you can use applocker. I think what you are doing is overkill. If you want to use a domain there is a group policy to control weather ctl+alt+del is required. However if you are not on a domain, that isn't an issue. 1. make them a standard user account, not admin, that will go a long way to reduce any damage virus or otherwise. 2. if you are using Microsoft accounts there is the whole family safety thing that allows you to control apps / websites. https://support.microsoft.com/en-us/help/12413/microsoft-account-what-is-family Plus this will allow them to log onto each pc without a domain setup. 3. to keep apps updated at home I like patch my pc, there is also ninite. https://patchmypc.net/ 4. for the media files just setup emby, it gives a nice netflix style interface, and can be setup with accounts to restrict by content rating etc. https://emby.media/ I use both patchmypc and emby at home myself, the whole domain is overkill for so few devices.
-
If I read your post correct your asking for 3 things, and I'm guessing this is a home lab based on your other posts. 1. automate user account creation 2. software deployment 3. RM. If those are not correct please clarify. The short answer is no there is no free software I'm aware of that does it all. First the search function is your friend, many of these topics have already been discussed, but sometimes the trick is knowing what to search for. You can automate user account creation with powershell, or there is an account spreadsheet from wisesoft. Software deployment has many options, built into windows you can use group policy to install programs. PDQ deploy is a great free option. do a search you will find a lot of suggestions. RM, I've never used so cannot say anything about it, but fairly certain it isn't free, what are you trying to accomplish with the log in box?
-
boring <<-- DJ-1701
-
I will play either, so if you guys want another go at sky factory, lets do it. I'm not sure if it can be done in teams though. you spawn on a single block of dirt atop an oak. If we do go for sky block you will want to move FullscreenWindowed-1.10.2-1.5.1.jar to a sub folder of mods so it is disabled. This caused my screen to constantly flicker when going full screen. All the mods is a newer pack though based on 1.12 instead of sky factory's 1.10
-
The same as above, in place upgrade via task sequence. I tested the 1703 to 1709 feature update via sccm windows 10 servicing and it brought in the new apps, one drive and a few other settings. I didn't look too closely, one glance was enough to tell me the task sequence is the way to go. I have an upgrade to 1703 TS that applies the upgrade and then removes the extra apps and re applies the various OSD customizations. I've not updated it to 1709 yet but its on my todo list, should be a matter of swapping in the new wim.
-
Time to call in Elmer and Daffy, its WABBIT season. I have automated the vaccine with group policy. 1. create the files on a network share, I just made a sub folder in netlogon called badrabbit. 2. use gpp file copy to put the files in %windir% 3. use group policy file permissions to clear all permissions from the files we have just added. I've taken a screen shot of each step. GPResults for file security GPResults for GPP file copy Configuring file permissions in Windows Settings > Security Settings > File System Configuring GPP file copy in Preferences > Windows Settings > Files The end Result
-
[1709, fcu] Date Released for Fall Creators Update
ADMaster replied to DJ-1701's topic in Windows 10
I found another app that the scripts are not removing, mixed reality portal. From what I've read so far a cab file is downloaded at first log in, I assume after the first user is logged it is cached somewhere. This will explain my discrepancies in log in time testing. I've found some guides on removing it per user after login but not per machine. Anyone know how to remove this? Thanks, EDIT: I must have overlooked this in 1703, it appeared then as mixed reality viewer. -
[1709, fcu] Date Released for Fall Creators Update
ADMaster replied to DJ-1701's topic in Windows 10
I use most of these tweaks already. However the profile size between default user and a newly logged on user is several MB. The default user profile is about 3MB new test staff login is 40MB and domain admin is 70MB. I ran windirstat on it and a webcache dat file takes up the most of that space at 25MB. Would copping this file in during OSD or using the network default profile speed things up. I do see from your previous post I've missed a few built it apps so I'll add those to my script too. -
[1709, fcu] Date Released for Fall Creators Update
ADMaster replied to DJ-1701's topic in Windows 10
I'm not sure what I changed, or maybe it was that it wasn't cold booted on that last test but it is taking longer now. I got well over a minute closer to 1:30 on the VM and almost 2 on old non ssd hardware. I don't have a default profile but it sounds like I should. Instead of going through the hassle of default profile, can I just copy in some files during OSD? I'll do some more tests today. -
I do mine a bit different from everyone else here, maybe I need to rethink it so reasoning welcome. I have a deployment package for each year and create a new one each January. I have 3 fairly current deployment groups +n years back. The only ADR I have is definitions. Each month I filter for 'needed' updates of all my supported products and put them in an update group 2017-10 for this month. I then would take the previous months updates 2017-09 and put them in the 2017-all group. Then I delete the now empty 2017-09 group. Anything in the 2017-all group is scheduled for immediate install and reboot regardless of maintenance window. The current month is scheduled with a two week deadline and a prompt to reboot, but it can be suppressed. This effectively gives them a month to do the updates. This is workstations of course, I never force a reboot on servers ,but they do have maintenance windows.
-
Not to hijack this but I have a dumb noob question about bit locker. In the past if a PC was acting up I'd just swap the drive into another and away the user went. Also if an HDD was failing I'd connect it to a USB cady and retrieve what I could. With SSD's dying suddenly data recovery isn't so much the case anymore. How would I go about swapping a drive into different hardware, the machine name would be the same but it would be a different TPM chip. Is there a process to this or will it just have to be a reimage? Also if I do need to reimage it typically it uses the same hostname so any conflicts there with storing keys in AD.
