Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

sukh

Members
  • Posts

    2,161
  • Joined

  • Last visited

Everything posted by sukh

  1. Have you tried to deploy via SCE 2010 using a deadline? Cheers S
  2. Also, Have you tried to deploy Office without AU by setting a deadline via SCE on the package?
  3. And How do I reset Windows Update components? Sorry for the multiple links, I haven't got a lab set-up for SCE 2010. If I do this, I'll have to blow away my exisiting labs and am working on other issues. Let me know how you get along. Thanks Sukh
  4. Also, "Error 0x80092026: The cryptographic operation failed due to a local security option setting." Check for the Key, don't worry about if it's for W2K3
  5. Might want to try You cannot install some updates or programs
  6. Hi Yes that's right. Just need to know more about the error. Event ID on the client and the server if it exisits. Thanks Sukh
  7. Hi @Angrytechnician - Just to clarify, manually deploying Office 2010 on Win 7 SP1 machine work fine? Regards Sukh
  8. Hi Can you post the event ID and of the error and let me know what Forest/Domain Level. Thanks Sukh
  9. Hi See The default permissions for home folders in Windows Server 2003 and in Windows 2000 are different. This should help you. See the other KB's in this article. I assume you are using 2003? Regards Sukh
  10. Hi If you're moving to 2010 from 2003, during co-existence, you should continue to manage 2003 object from systems manager (2003) and 2010 objects from (2010 EMC/EMS). This is best practise. You may be able to manage 2003 objects from 2010 but not the other way round. When manaing OAB/Address lists/RUS etc...I would continue to leave them roles in 2003. 2010 will use the availabilty service too. Also, depends on what MAPI clients you have deployed. Also, mail-enabled groups (Sec/DL/DDL etc..) must not have illegal characters in the name. This will not work and 2010 will give you warnings. 2003 users will see the GAL, as well as 2010. In addition to the GAL, there are complications with OAL. Also, you need to consider F/B for users on both 2003 and 2010. You are fine with migrating users over a period of time. Regards Sukh
  11. Hi Can you clarify the situation. If the printer and drivers are on a print server then why do you think Vista is causing the issue, What is the print server OS and SP level? Where do you have to install the print drivers again? On client machines or the server? Regards Sukh
  12. Hi Glad to hear it worked. Regards Sukh
  13. Make sure when you run that report, it's on the effected machine with a effected user. Use yousendit, PM me email address and I'll reply back.
  14. Can you Download the mpsreports tool from this link: And select General and Internet and Networking and Business Networks option on the effect machine. The tool will automatically collect the information. This procedure will take 5~10 minutes Can you then send it to me, check the size and let me know how big it is? Thanks Sukh
  15. OK. Point 1 was just to test, as it's resolved we can leave this. As for your other issue, can you move the the PC which you used to logon to with the same domain admin account to the Test OU you created with the other test machine. The run the gpupdates and and gpresult on this PC, reboot to make sure, then try logging on with the same domain admin account on that pc and check? Thanks S
  16. Hi I was going to ask you to do this on a PC with an issue. 1. ck Start->Run, type regedit.exe and click OK to open registry 2. Expand to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations NOTE: If you cannot find the Associations key, please manually create it. 3. Right click Associations and select New, point to String Value and click it 4. Type LowRiskFileTypes as the value name 5. After it is created, double click it and type .exe as the Value data 6. Quit registry and restart the workstation to take effect. However, please note that this is not recommended as it opens up your computer to other risks. Right now on issue 2. Do you see any settings in any of the zones which you have set? Also remind me if you have applied your IE8 to this test PC? Thanks Sukh
  17. OK. My understanding was that there are two issues in this post. 1. IE Settings being applied (trusted sites etc...) 2. Shortcuts not working. Are we saying 1 is no longer an issue but 2 is? Thanks S
  18. Hi Thanks for doing the test. Just want to clarify the error still happening. Error as is the sites are still being listed in trusted sites? And we are sure that the in the single GPO applied there is no IE settings? Also, has the new test user got a login script? Thanks Sukh
  19. Can you post the event ID here?
  20. Hi If the Site to zone assignment list policy is enabled, the users cannot see the setting and cannot manage their site to zone assignments via the IE User interface. If we want to push a standardised list of site to zone assignments but want the user to still be able to manage their own site zones, we should use Internet Explorer Maintenance policy instead and import the security settings from a machine that has been configured with the required zone settings. User Configuration ->Windows Settings ->Internet Explorer Maintenance-> Security -> Security Zones and Content Ratings-->Import the current security zones and privacy settings-->Add the sites to trusted zone. For 2003 R2 clients, IE Enhanced Security Configuration feature is enabled by default and a KB was published for this scenario: There is a KB about Site to Zone Assignment List issue: 918915 The Site to Zone Assignment List policy prevents Internet Explorer from using other zone configuration settings when the Internet Explorer Enhanced Security Configuration feature is enabled on a Windows Server 2003 SP1-based computer The Site to Zone Assignment List policy prevents Internet Explorer from using other zone configuration settings when the Internet Explorer Enhanced Security Configuration feature is enabled on a Windows Server 2003 SP1-based computer Regards Sukh
  21. Hi You cannot configure Group policy for Windows 7 on Windows 2003. This is because in Vista and later version OS, group policy file (ADM) are replaced with new version ADMX, which has many improvements like multilanguage support, an optional centralized datastore, and version control capabilities. However, because ADMX file is used their own markup language, Group Policy management console on Windows Server 2003, Windows XP, or Windows 2000 does not support it. Therefore, you cannot use group policy management on Windows 2003 to configure group policy settings that included in admx files for Windows 7. you need to use RAST to manage group policy on Windows 7 computer. To do so: a. Install Remote Server Administration Tools (RSAT) below on Windows 7 Remote Server Administration Tools for Windows 7 Download details: Remote Server Administration Tools for Windows 7 b. Go to Control Panel -> Programs -> Turn Windows Feature on or off. c. Expand Remote Server Administration Tools -> Feature Administration Tools, check Group Policy Management Tools. d. Logon as domain administrator on Windows 7, search Group Policy Management and open it. Now you can management all group policies. Also, you don't need to do anything on Windows 2003 DC, although those settings cannot be read from Group Policy management console, they are existing (in SYSVOL folder). When Windows 7 computer applying group policy, they will read the appropriate information and apply group policy without problem. However, please remember you can only use Windows Vista and later OS to configure group policies dedicated to Windows 7. More information for your reference: Managing Group Policy ADMX Files Step-by-Step Guide Managing Group Policy ADMX Files Step-by-Step Guide Regards Sukh
  22. Hi @Chrisbrown, you are correct. We have set this up on many deployments. Regards Sukh
  23. Hi The reason why I asked which OS you are using was to see if we can deploy poweshell on your server and write a script to monitor the event id and set a trigger, ie. restart the services. Cheers Sukh
  24. Hi When do you plan to migrate? How aften does this crash occur? Are able to reproduce or know the timings? Is there a pattern? Do you want to try and identofy root cause? Thanks Sukh
  25. Hi A simple test. Can you create a new OU and block inheritence of all GPO's. Add a PC, fresh install to that OU. Create a new test account and logon. What are the results?
×
×
  • Create New...