-
Posts
1,402 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ADMaster
-
I saw a similar thread to this when researching my own applocker issue, but mixed results. Do you have the latest updates installed? I have May's installed build 10.0.15063.332. I've not had any reason to update my applocker policy yet, so I created a new test gpo. I was able to add rules to it just fine, no crashes, I tried exe publisher rule and packaged app. I have most modern apps removed via script during osd.
-
Just subscribing to keep an eye on this. I had an applocker issue where removing the apps with ntlite before imageing broke applocker. I remove modern apps with a script during OSD near the end of the process. Can you explain more about cannot create applocker policies, don't they get pulled from GPO? I don't think I've tried to edit my applocker GPO since updating. Is the issue only on 1703 or what version?
-
You need to know the current password, and if they already know that it can be changed with the usual methods. PassCore does not allow a reset only a change. We use it so users on chromebooks and offsite can change their passwords since GAFE is synced with AD.
- 11 replies
-
- change password
- reset password
-
(and 2 more)
Tagged with:
-
To run scripts and MSIs I use an elevated command prompt, this should solve the immediate issue. However is there any reason your not using applocker? It is much more flexible on allowing access based on usergroup, more details for signed apps etc. It also has separate lists for exes, scripts, installers and packaged apps.
-
+1 PassCore here too.
- 11 replies
-
- 1
-
-
- change password
- reset password
-
(and 2 more)
Tagged with:
-
I reran the upgrade TS and it did not fix the issue. In hindsight I should have rolled back the upgrade, but now a rollback will just revert to the first run of the upgrade. Any other ideas before I reimage to a fresh install?
-
Have either of you modified your wim with ntlite? I've done nothing but watch a VM reimage its self half a dozen times today. I extracted a fresh copy from the iso and everything worked. I modified a copy with ntlite and applocker failed. I've attached my xml if you spot something I'm removing that I shouldn't. Thankfuly only my PC and a couple admin staff got this version of the deployment so I'll test just redoing the upgrade TS with the corrected wim. ntlite.txt
-
Email addresses are not case sensitive. All of our students here are lastname firstname last four of ID number Joe Blogs with ID 123987 would be blogsj3987 This provides no duplicates and sorted by last name when looking in AD. I put all the students in OUs by year group so its easier to manage.
-
So today I thought I'd do a fresh image on a VM and run procmon to figure out what file is missing. However the fresh install has issues with applocker now. The only thing I can conclude at this point is updating to the image I modified with ntlite broke something. If anyone knows what I may have removed that broke applocker I'll give it another go. But I think I'll just go back to my scripts.
-
I upgraded my own machine today and discovered applocker not working. I have checked on a few VMs too, a fresh install of 1703 and applocker works, an upgrade it does not. Back on SRP I knew of a reg key I could delete that would reset it and get everything fresh from the GPO. I don’t know of anything like this for Applocker. A gpresult does not show any errors and it has the correct version from ad / sysvol. I moved my PC into another OU and forced a policy refresh and rebooted, moved it back rinse and repeat. I am getting this in the event log ID 8000 I found a post were this same ID gave the message access denied, but system does have access to the TxR folder in my case. The appidsvc is running. What file is it looking for? Can anyone else replicate this in their environment. A couple other issues with the upgrade is sccm services remote control and task sequence are disabled. I have fixed those by configuring them to automatic start in GPO. TIA
-
LAN Settings automatically detect settings
ADMaster replied to Shadow_Walker's topic in Windows Server 2012
Since you tried on a few different machines its not likely an extension but worth a check anyway. I've seen dodgy extensions try to control proxy settings before. chrome://extensions/ Edit: also have you tried incognito mode, that bypasses most extensions? -
I'm not sure how your netgear works, I'd guess it is doing some sort of NATing, so does the server think the traffic is coming from the netgear IP? Enable firewall logging of successful connections on a server and see if it points you in the right direction.
-
I just looked at my own policies and it doesn't appear this is in the default policy by default. I'd still look at the inheritance, gpresults, and/or rsop as troubleshooting steps.
-
I'm testing an image now that has been modified by ntlite. I disabled the consumer experience key, removed smbv1 and all the apps I had my script removing. However I found a couple apps that were not in my script, I don't know if they will cause issue so I'm interested to know what others have done too. I removed Microsoft.Advertising.Xaml Microsoft.StorePurchaseApp Microsoft.Wallet I'm not sure what these do so time will tell.
-
I would do the following. Setup your guest ssid to use a different vlan. Configure the vlan interface on the router with ip helper and an ACL The ip helper allows the vlan to pass dhcp across vlans to your dhcp server. The ACL should do the following; allow dhcp between guest vlan and dhcp server allow dns between guest and dns allow for any internally hosted services such as website deny to all internal address allow to any on common ports, web, imap, google/apple stores whatever you want to allow allow established deny all others fwbuilder is a good tool to create an ACL. Here is a trimmed down version of mine. I allow more access to staff devices then student or unknown devices but that all would not fit in a screenshot.
-
These settings are normally in default domain policy so when you remove the policy it is picked up from there instead. Did you block inheritance for your W10 machines to test GPOs? What does gpresult or RSOP have to say?
-
Most GPOs do not remove the settings once they no longer apply. You can either edit the current GPO to remove staff from the deny logon, or create a new GPO to do it.
-
sccm task sequence without OS and USB drivers W10
ADMaster replied to ADMaster's topic in O/S Deployment
I downloaded an updated driver pack from HP and it worked on the one PC I tested today. I'll have to try it on the other models. I cannot test the rerun task anymore. I found that it was running in the background but failing on various steps. I'm not sure how to recreate the failure that caused the issue in the first place. Also some of my tests were misleading me. I had already logged on and got a new profile while it was in a failed sate. I logged on with a new user and the desktop is as it should be. -
sccm task sequence without OS and USB drivers W10
ADMaster replied to ADMaster's topic in O/S Deployment
I let it auto apply I imported updated Drivers Friday and one of them was the 1c26 driver so I'll try a reimage Monday without disabling that updated one. I also think I found part of the problem with my TS. One of my steps disables PC reset, since that part did run it erred out. I need to figure out how to check for that and continue. -
To prevent needing to do this in the future setup DFS. Overview of DFS Namespaces You don't need to have it replicate or have multiple targets, this will just give a single unchanging unc path for your shares. Then when you need to change the server they are hosted on, just change the target in DFS. The end users will never know the difference.
-
Hi all I have two separate SCCM issues at the moment. I am running the latest 1702 and deploying W10 1703. The first issue, I have an upgrade task sequence that upgrades W8 or an older version of W10 to 1703. After the OS is applied I remove the metro apps and redo the branding. I had one machine fail the upgrade, it applied the OS but did not run any of the customizations. I created a task sequence with a reboot step and the customization steps. When the task runs it reboots but does not run the other steps until I log on. The task fails because these scripts need to run with the same privileges they would if it was an OS deployment. Yes I can simply reimage the machine but I'd like to have a one click fix for when I ask users to upgrade their own machines. How can I get the TS steps to run after a reboot but before logging in? The second issue is USB drivers this was an issue last year with 1511 and/or 1607 too. Deploying a full OS not upgrade to a laptop works fine, but to a desktop/AIO sometimes the mouse and keyboard to not work. I have found if I remote into the machine and update the usb driver to use the one from Microsoft and not Intel it works. I disabled the Intel USB drivers in SCCM but this is still happening on 1703. I'd like to find a solution before I image all the labs this summer. The two machines I tested my image on today were a custom local brand, but if I recall last summer this was an issue on my Lenovo's and HP's. I'll do more testing on Monday. Thank you
-
I'm not familiar with that router, but bottom line is you need an ACL. Go ahead and keep the route the way it is so guests get dhcp from the DC, if you don't want to have smoothwall handle it. I have an ACL on the guest vlan interface that looks something like this from memory so may be forgetting something. allow dhcp to dc allow dhcp from dc allow dns to dc allow dns from dc allow http/https to internal hosted sites deny to 10.x.x.x allow http/https and a few other ports to any allow established deny all This has two effects guest is ACLed from your main network guest cannot access $service that uses random ports. I've added several port exceptions over the years for apple / android updates etc. I use FWBuilder to keep a good visual on the ACL, not sure if your router is supported though. Some wireless controllers support ACLs on the SSID as well. I was just reading about improvements to that in the ruckus release notes today.
-
Saving passwords in browsers
ADMaster replied to DavePa's topic in Internet Related/Filtering/Firewall
I'd be tempted to post something as them to give them a wake up call. However there are GPOs / admin console settings you can use to disable the password manager, that may be your best bet. -
I do not capture a reference image, everything is done via scripts during OSD, I use SCCM but I think you can do similar with MDT. In any case here is my list of customizations. Disable SMBV1 Disable startup repair Disable PC Reset remove default apps set default file associations start layout xml disable consumer experience remove one drive set search branding Branding script does theme, background, user account pictures etc , but also disables chrome and defender first run popups. Then I install the apps, office, chrome, vlc, adobe as part of the osd task. Specialty software that doesn't go to everyone such as photoshop gets pushed out later with PDQ. All of these customizations can be found across the forum, but I think I got the most of them from here All the scripts are provided as a zip download.
-
Not the answer but may help slightly. I use the filter option and set it to only show configured settings if I'm having trouble finding one that I know is configured. RE: AGPM, I set it up about a year ago. it adds change control to the GPOs. Each time you check in / out a GPO you can leave a comment. You can click on history and see a list of changes based on comments, roll back to a previous version or compare versions. I'm the only one here so don't use the rest of it, but you can have levels of access. A tech could edit the GPO then have the NM approve the changes.
