alfatec
Members-
Posts
380 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by alfatec
-
No probs. We are running 1709 on 800 workstations and Server 2016 so knew it must have been something to do with the new security implications.
-
And this: Long version: Network Discovery and File and Printer Sharing is turned on. Firewall configured correctly (and I would briefly disable it and try again to see if it worked, nope). Nothing strange about running/stopped services compared to a PC that it works on. Strangely, running "netstat -a" in a command prompt shows localhost is listening on port 445, but when I scan it with nmap (Zenmap on Windows) with "nmap -p 445 ", it says that port is closed - even with the firewall disabled. Hmm. This pointed me to something wrong with the adapter settings. Lo and behold, even though I had "File and Printer Sharing" turned on in Windows, the "File and Printer Sharing for Microsoft Networks" client for the active network adapter was turned off.
-
Try this, apparently SMB2 guest access is disabled in 1709. https://support.microsoft.com/en-us/help/4046019/guest-access-smb2-disabled-by-default-in-windows-10-server-2016
-
You delete it from your default profile. If you are using classic shell then you need to enable 'Remove common program groups from Start Menu' in User config, admin templates, Start menu and taskbar. This will then remove the common folders like admin tools etc.
-
I remove the complete folder which removes the capability to right click on the Start menu.
-
Make sure File sharing and Network discovery are ticked in Network and Sharing center, Advanced sharing settings. I think in 1709 by default they are off even with the firewall disabled.
-
Is the firewall enabled on the workstation. By default we disable the domain firewall connection.
-
How are you creating your default profile. We use a local profile and mandatory on RDP and edge works on both. There are a few new things that you need to do now that were not in the original setups.
-
Not teaching you to suck eggs or anything but I found that I had to do a ipconfig /flushdns on the Solus server when I upgraded our workstations to 1709. I also had to remove the workstation from Solus and re-add.
-
This is the line I use from the 1709 DVD. dism.exe /online /enable-feature /ALL /featurename:NetFX3 /Source:d:\sources\sxs /LimitAccess Have not has any issues.
-
Hi, We are running 1709 and have 260 workstations and laptops with SIMS installed without any problems.
-
There is a group policy setting in Computer Configuration, Admin Templates, Windows Components, Windows updates. 'Do not connect to any Windows Update Internet locations'. Enable this as we noticed that Windows 10 checks internet updates even though it is getting it from WSUS.
-
There is a tool you can use called Delprof 2. We normally script this to run at either half term or end of term to clear local profiles.
-
Remove folder 3 from the WinX folder in the default profile.
-
It certainly looks like the initial login time is quicker. First login is now only about 20 seconds compared to 35-40 with 1703 and that is with a syspreped image rolled out. Even managed to keep using my default profile from the 1703 build and all works the same, start menu etc etc.
-
Is the Feature upgrade to 1709 available in WSUS yet? Not showing in mine.
-
Anybody know when the WSUS update is being released??
-
PDQ has a free version that will deploy 'msi's'. Once you create your OCT file for Office then just create a new package in PDQ and deploy.
-
Configure a package with the Office Customisation tool (OCT) then just use GPO or something like PDQ deploy. The OCT will also remove older versions and install the new one and licence your software.
-
Thumbs up here for PDQ. In the Enterprise version you can now send out Cumulative updates for Windows 10. The best thing is that it has all the software already pre-configured for you. No more Java/Adobe update alerts. When a new Java update comes out just right click, deploy to whole network. Wouldn't be without it.
- 11 replies
-
- deployment
- target tracker
-
(and 2 more)
Tagged with:
-
With Windows 10 you are better off looking at Mandatory or Local. Roaming profiles are causing a lot of issues in Windows 10. Not sure about a solutions provider in the London area, other members will probably give some advice on that. It might also be worth visiting a school who has already deployed to look at the pitfalls etc.
-
OK getting abit further down the line. Can access teams in IE and Edge on 1703 but only when using 'InPrivate Browsing'.
-
I don't think you need a 12 month contracted consultant for that. We rolled out Windows 10 to all 850 devices 18 months ago and it is all about getting your image and profile correct. You would be better off employing a technical solutions provider to do a 2-3 day contract in designing, configuring and building you an image and profile. You could then roll out over a period of time yourself. You would need to start doing an audit of existing workstations and software now though to ensure compatability.
-
Are you putting that in your site to zone assignment list, under internet or intranet or trusted?
-
That's the one.
