Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ADMaster

Members
  • Posts

    1,402
  • Joined

  • Last visited

Everything posted by ADMaster

  1. Thanks all, I've not had a lot of time to work on this the past week, but rebooting into winPE has worked. I still have a few settings to iron out, but the overall process provides a functional machine.
  2. Yes I decided with windows 10 to not modify the install.wim and do everything I would have done to the wim with steps in the TS. The only thing I've done is slipstreamed in the latest updates from the console. However I had these issues before and after the updates were applied, so that's not the cause.
  3. Your idea of a new profile got me going in the right direction. I still don't have an automated fix, but I can fix it by hand. Some of my tweaks modify the default profile during OSD with a reg load / unload. These scripts work just fine for a fresh install, but for some reason the default profile is not getting unloaded with the upgrade task. I have added two steps to my task sequence, a restart followed by a reg unload. This did not fix the issue. If I log on as admin open regedit and unload the hive a new user is able to log on. Any idea what is different between the new install and upgrade TS's that will not allow the hive to unload? Any ideas on forcing the TS to unload it. Thanks,
  4. Hello, I've been testing some upgrades to 1607 and I've run into a few issues. A fresh image of 1607 is tested and working, its the upgrades that have issues. When upgrading from 1511 to 1607 via the SCCM servicing I loose all branding / customization, default apps come back etc. I imported the 1607 files into the upgrade packages and created an upgrade task sequence. Then added my tweaks to the post upgrade section. Any new admin user, does not have a start menu Any new standard user cannot log on. it gets to preparing windows then goes to signing off This leads me to believe I've somehow corrupted the default profile in my post upgrade tweaks. I've also tried this upgrade from W8.1 to 1607 with the same results. Can anyone point me in the right direction, every change takes 1.5 - 2 hours to test, so any help is appreciated? Thank you,
  5. Any update on this? I've had the same issue with both 1511 and 1607, no one drive installed. I've ended up removing classic shell, but when searching for my start menu woes, I see so many posts about it working well in W10. Classic Shell is working great on all the machines still on W8. Thanks,
  6. I run it as part of an SCCM deployment task however, I don't see any reason you could not run it as a startup script. The theme is set per user so anyone who already has a profile will not get the settings as this script modifies the default profile. If you want to brand machines already deployed consider a GPO. The main reason I don't use a GPO is I want users to be able to change it after the fact.
  7. A minor edit to the script to create the windows defender path, and I can't edit the original post. Added the new item path between $defenderpath and set item property. $defenderpath = "HKLM:\DEFAULT\SOFTWARE\Microsoft\Windows Defender" New-Item -Path HKLM:\DEFAULT\SOFTWARE\Microsoft -Name "Windows Defender" –Force Set-ItemProperty -Path $defenderpath -name UIFirstRun -value 0 There are also a few paths and file names that will need changed to suit your environment. Here is the whole thing again. #===Start Script=== Start-Transcript -Path "$OSDISK\branding.log" $Wallpaper = "yourwallpaper.jpg" $OSDISK=$env:OSDISK REG LOAD HKLM\DEFAULT $OSDISK\Users\Default\NTUSER.DAT # copy the OEM bitmap If (-not(Test-Path $OSDISK\windows\system32\oobe\info\backgrounds)){New-item $OSDISK\windows\system32\oobe\info\backgrounds -type directory} copy-item $PSScriptRoot\user.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user-192.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user-48.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user-40.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user-32.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\guest.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user.bmp "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\guest.bmp "$OSDISK\ProgramData\Microsoft\User Account Pictures" Move-Item "$OSDISK\Windows\Web\Screen\img100.jpg" "$OSDISK\Windows\Web\Screen\img100-1.jpg" copy-item $PSScriptRoot\$Wallpaper "$OSDISK\windows\system32\oobe\info\backgrounds\backgroundDefault.jpg" copy-item $PSScriptRoot\$Wallpaper "$OSDISK\Windows\Web\Screen\img100.jpg" copy-item $PSScriptRoot\$Wallpaper "$OSDISK\Windows\Web\Wallpaper\Windows\$wallpaper" # make required registry changes $strPath2 = "HKLM:\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Background" $strPath5 = "HKLM:\DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes" Set-ItemProperty -Path $strPath2 -Name OEMBackground -value 1 Copy-Item $PSScriptRoot\yourtheme.theme "$OSDISK\Windows\Resources\Themes" Set-ItemProperty -Path $strPath5 -Name InstallTheme -Value %SystemRoot%\resources\Themes\yourtheme.theme #create defender ui reg key $defenderpath = "HKLM:\DEFAULT\SOFTWARE\Microsoft\Windows Defender" New-Item -Path HKLM:\DEFAULT\SOFTWARE\Microsoft -Name "Windows Defender" –Force Set-ItemProperty -Path $defenderpath -name UIFirstRun -value 0 [gc]::Collect() # necessary call to be able to unload registry hive REG UNLOAD HKLM\DEFAULT Stop-Transcript
  8. Thanks for the GP that worked. I've never had it set before and it worked just fine in 1511. Here is my branding script. Put your wallpaper in with the default wallpapers, create your theme and export it into a .theme file. Put the script, wallpaper, theme file, and user account pictures all in the same folder. I've also added the reg key to not show the first run UI for defender 1607. #===Start Script===Start-Transcript -Path "$OSDISK\branding.log" #New-PSDrive -PSProvider Registry -Name HKU -Root HKEY_USERS $Wallpaper = "yourwallpaper.jpg" $OSDISK=$env:OSDISK REG LOAD HKLM\DEFAULT $OSDISK\Users\Default\NTUSER.DAT # copy the OEM bitmap If (-not(Test-Path $OSDISK\windows\system32\oobe\info\backgrounds)){New-item $OSDISK\windows\system32\oobe\info\backgrounds -type directory} copy-item $PSScriptRoot\user.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user-192.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user-48.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user-40.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user-32.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\guest.png "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\user.bmp "$OSDISK\ProgramData\Microsoft\User Account Pictures" copy-item $PSScriptRoot\guest.bmp "$OSDISK\ProgramData\Microsoft\User Account Pictures" Move-Item "$OSDISK\Windows\Web\Screen\img100.jpg" "$OSDISK\Windows\Web\Screen\img100-1.jpg" copy-item $PSScriptRoot\$Wallpaper "$OSDISK\windows\system32\oobe\info\backgrounds\backgroundDefault.jpg" copy-item $PSScriptRoot\$Wallpaper "$OSDISK\Windows\Web\Screen\img100.jpg" copy-item $PSScriptRoot\$Wallpaper "$OSDISK\Windows\Web\Wallpaper\Windows\$wallpaper" # make required registry changes $strPath2 = "HKLM:\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Background" $strPath5 = "HKLM:\DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes" $defenderpath = "HKLM:\DEFAULT\SOFTWARE\Microsoft\Windows Defender" Set-ItemProperty -Path $defenderpath -name UIFirstRun -value 0 Set-ItemProperty -Path $strPath2 -Name OEMBackground -value 1 Copy-Item $PSScriptRoot\yourtheme.theme "$OSDISK\Windows\Resources\Themes" Set-ItemProperty -Path $strPath5 -Name InstallTheme -Value %SystemRoot%\resources\Themes\yourtheme.theme [gc]::Collect() # necessary call to be able to unload registry hive REG UNLOAD HKLM\DEFAULT Stop-Transcript
  9. Hi All, I have several branding scripts that i used for 1511, one of them replaced the images in the user accounts picture folder so all users have the school shield as their profile picture. I did a fresh install of 1607 on a VM to see what changed, and the profile picture does not appear on the lock screen. I've looked in the folder and all images were replaced correctly, the profile pictures show up after login, just not before login. When a user presses ctrl alt del they get the grey blank face. My Google-Fu is failing, is there any way to get the shield back on the sign in / lock screen. Thank you,
  10. The other consideration is VLANs. The switch you connect the AP to must know about the vlans of the SSIDs it serves. For the APs to discover the ZD just put in a DNS entry for zonedirector with its IP
  11. Try disabling the firewall on the server, if that works then turn it back on and add the correct exceptions. Same with the clients is java permitted through the firewall?
  12. Look for apple configurator on that Mac. That is what is most likely supervising them. Its been awhile so I'm not sure if you can change that setting without erasing the device. Also, IIRC when I had that ticked it would still connect to a windows machine.
  13. Hello, I'd look at vlan configuration. The ruckus has two modes, to route the traffic at the ap's switch, or route the traffic back through the zone director. If you are routing traffic at the AP each switch needs the vlan configuration to match. You said the only difference was vlan IP addresses. I'm not sure how HP works but on my cisco I have one IP per vlan at the core. There is no IP assigned to the vlan at the edge. The two settings I'd look at next are; Are the vlans allowed across the trunk back to the core? Do you have the equivalent of IP helper configured on those vlans? Hope this helps
  14. I personally like text aloud by nextup.com, it will not keep the formatting of PDFs though. Nextup does have a trial. We also have a site license for read and write for google by texthelp. My biggest issue with read and write is voices. My personal favorite right now is Ivona Amy.
  15. IBoss LEA provided. Great support easy to use.
  16. Do you see any log on failures at all? I thought the default was to audit only success, but technet indicates no auditing as default. Edit the default domain controller policy and go to; computer configuration > Windows security > Security settings > Local policies> audit policy Change the audit account log on events to success and failure. here is the tech net entry https://technet.microsoft.com/en-us/library/cc976367.aspx
  17. @Geoff You can also make signalum with a block of redstone and a restone dust in place of the bucket of redstone. It will give you 4 signalum dust that need smelted in a furnace or like before going into the smeltery. The smeltery would not take the dust directly. That is how I made my signalum bow. I got AE running and some basic auto crafting of crystals and processors. I then made a digital miner it is being powered by two wind turbines. I would like to know if there is a good alternative to tesseracts and transceivers. I don't have the resources for either yet.
  18. They will not change IP's if you set a reservation. I have all of my MFPs on DHCP reservations. I find it easier to change the mac address in DHCP and reboot the MFP, then navigating the MFP screens to set the IP. This is useful for moving devices around or getting new ones. The same applies to the laser jet printers.
  19. I think the way you have it is correct. and i disagree with the WAN scenario. The OP is speaking of setting the adapter DNS. This will effect the servers communication back to the the other sites, and any dns lookups the DC must do The clients at the site will all communicate with the local DNS server and where it resolve client requests from is set in DNS forwarders. The DNS forwards are typically up stream ISP / LEA dns servers.
  20. I was just going to PM you my crash log, but that's moot with you having the issue now too.
  21. @localzuk It looks like we need to disable the WiiEMC mod for EE3's knowledge system to work properly. https://github.com/pahimar/Equivalent-Exchange-3/issues/989 I tried disabling it locally as it is a client mod, but my connection was rejected. Thanks,
  22. Hello all, I trying to move SCCM to a new server. The server it is on now is starting to have hardware issues. I cannot take a full system backup without it rebooting. However I did get a backup of all the data files and the SCCM SQL backup tasks ran correctly. The old server is running SQL 2012, Server 2012 R2 and SCCM 2012 SP1. I removed the old server from the domain and unplugged it from the network. I installed everything on a new 2012 r2 server with the same name and IP address and followed the site recovery wizard. I was getting issues with several of the site roles. Reporting servers is in a constant error state, WSUS I think I have got to work off and on. However the biggest issue is none of my OSD tasks work. The smsts.log on the client fails to verify the certificate. I went to the old server and exported all the certs and imported them onto the new server deleting the ones the new server setup. (This was probably a mistake.) After a reboot SQL would not start, rejecting the cert. I used SQL configuration utility to select the new / old cert, would not start, I set it to not use a cert. SQL starts but stops after a few minutes, and I find the configuration is back to using a cert. I shut down the new server and turned the old one back on. Joined it to the domain. Now everything appears to be back to how it was before. I have a machine starting the OSD process although it is not complete yet. Also this server is extremely slow with the hardware issues. What step did I miss, or what can I do different to transition this to a new server. This is a single server with all roles including DB, no PKI just self-signed certs. @FN-GM @Gatt I see both of you have recovered sites advice please.
  23. If replication is working it should not matter. However you can choose what DC to connect to in GPMC if you think there is an issue there.
  24. Hello, Have you copied the admx and adml files into the policy definitions folder on sysvol? That is all you need to get the admx version to work. I have the home page set in multiple places, so I'm not sure which one it is using. There is start up page, home page, and open these tabs on startup. Are you setting these policies on the computer or user section. In theory a machine policy has the highest priority. https://support.google.com/a/answer/187202?hl=en To help trouble shoot gpresult /h and chrome://policy are your friends. Cheers
×
×
  • Create New...