Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Swink
Apr 18, 2006
Left Side <--- Many Whelps
^ When I was looking at that issue, I came across a blogger who suggested that the login script creates a scheduled task to run immediately after creation that maps the drive as the current user level.

I cant seem to find the blog that I read that from. Dont know if it's suitable in your situation. We are going with the EnabledLinkedConnections method.


Question: The startup script description say that all scripts will run before the login screen is presented to the user. Is this the case at all? It is definitely not the case in my org.

Swink fucked around with this message at 13:55 on Jul 20, 2010

Adbot
ADBOT LOVES YOU

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Is there any downside to having heaps and heaps of policies?

In our current environment a lot of settings are all thrown in together and its sometimes hard to track down which policy has a particular setting.
In our new environment I want to separate out a bunch of settings into their own policy, for ease of administration.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Can I just get some clarification on what loopback processing does?


I want to deploy a startup script to a particular group of users, no matter what PC they log into.

If i create the GPO, assign it to a group of users, and enable loopback, will the PC that those users log into get the policy and apply it?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I'm about to push out Adobe Reader 9.4 to a bunch of new PCs. Whats the deal with getting them up to the latest version (9.4.4) and keeping them there? Is there an MSI installer at the latest version, or do I need to use these .msp files somehow?

Swink
Apr 18, 2006
Left Side <--- Many Whelps

Cpt.Wacky posted:

I haven't done my Win 7 rollout yet, but on XP I disable showing the last user name that logged in so that users learn their user names. I also disable the desktop clean-up wizard. How about forcing a password-protected screen saver after X minutes?

Can anyone help me out with this setting? I want our screens to lock after 30 mins, but nothing I set seems to work.

Swink
Apr 18, 2006
Left Side <--- Many Whelps

thebmw posted:


- Password protect the screen saver (Enabled)


Turns out this was the one I was missing. (works in 7, btw). Thanks

Swink
Apr 18, 2006
Left Side <--- Many Whelps

FISHMANPET posted:

What the gently caress Microsoft, no way to enable "File and Print Sharing" through GPO. Not sure that would ever be needed. Oh wait, because I want the admin shares!

Does anybody know of a way to do this? I've found this a few places but I'm not sure it does what I want it to, and it seems a little suspect.

This hosed me for a while too.

Computer > Policies > Admin Templates > Windows Firewall > Domain Profile

All of what you need should be in here.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Which runs first, a User GPO login script, or a script in the startup directory?

Swink
Apr 18, 2006
Left Side <--- Many Whelps
That requirement can be disabled in group policy.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I have an issue with some printers coming back from the dead.

I had a GPO that deployed some laserjet printers through Computer > Policies > Windows Settings > Deployed Printers

I have since deleted that GPO as well as the printers, but some workstations have the following error all through the event log:

quote:

The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key S-1-5-21-315623756-43523542-1544898942-6495\Printers\Connections\,,Server,PrinterName.
This can occur if the key name or values are malformed or missing.

There multiple entries for each of the printers that used to exist, occuring every minute or so.

I'm not sure if this by itself is causing problems, but it is making it difficult to diagnose a problem we're having with our current printers.

I've been through all our GPOs to see if one of them is still somehow referencing these non-existent printers and theres nothing. These are all freshly imaged machines and the printers were removed 3+ months ago.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Thanks mate that is some good info. I do suspect that the image i'm deploying may be to blame.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Are you sure you can install office programs using just the msi?

Edit - to clarify, I don't believe you can do this via GPO software policies, you have to do it via a startup script.

Swink fucked around with this message at 05:30 on Jan 18, 2012

Swink
Apr 18, 2006
Left Side <--- Many Whelps
I asked the same question and was told that there is no real issue with having 100 gpos. Apart from the issue of managing them all.

I have about 40 for 150 users.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Group Policy Management Improvements in Windows Server "8" Beta

Remote policy refresh!

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Default printer is one of the things that turned out easier to just write a script for. It's more flexible especially if your print situation is as bizarre as mine.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Ever wanted an online resource where you could search policies by name, see their description and the registry key it changes?


Now there is one! http://gps.cloudapp.net

Edit: This poo poo has been around since 2010 and I had no idea. What the gently caress.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
On the subject of Outlook & GPOs, is it possible to disable user access to Out of Office replies? Its against our policy to use them but people do anyway. My boss wants to take away the ability completely.

Swink
Apr 18, 2006
Left Side <--- Many Whelps

Caged posted:

Has anyone had any luck getting RDP 8.0 to work when connecting to Server 2008 R2? I've got a desktop at home on Windows 7 talking to a Windows 8 client over RDP 8.0 successfully, I've been following the guide here:

http://support.microsoft.com/kb/2592687

But I don't have "Enable Remote Desktop Protocol 8.0" as an option in Group Policy Management. Am I missing an ADMX template file or something?

Without having read about this at all, those settings may only be exposed when looking at GPMC.msc in Server2012.



Yep 2010. Link posted refers to setting OOF on behalf of users, I want it completely disabled. I want the feature removed. When users try and set an OOF message, I want a big hammer to stretch out and break thier fingers.




After a fair bit of Googling, it's starting to look like this isnt possible.

Swink fucked around with this message at 05:57 on Nov 28, 2012

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Double!

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Never mind.

Swink fucked around with this message at 07:26 on Mar 19, 2013

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Is there a way I can update a software deployment policy and not have it re-install the application? I want to change the location of the installer MSI for a certain program.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Looking at the policies I'm editing, I cant avoid the action of giving a certain group a 'new policy' - even though its functionally the same as a previous one. I'll just have to let the installation run again. It should only reinstall the msi, which shouldnt case any issues except for the delay in startup.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
On this topic, how do you disable Offline Files on an 2008R2 RDS server?

The 'disable offline files GPO' is only valid for 2003 servers and there doesnt seem to be a replacement.


Edit - we use folder redirection but not roaming profiles.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
You need to use a script. I put mine in the startup folder.It removes all the default icons, then adds what I want. (Office etc). Then deletes itself.


Here's mine:

code:
Option Explicit

Const CSIDL_COMMON_PROGRAMS = &H17
Const CSIDL_PROGRAMS = &H2
Const CSIDL_STARTMENU = &HB

Dim objShell, objFSO
Dim objCurrentUserStartFolder
Dim strCurrentUserStartFolderPath
Dim objAllUsersProgramsFolder
Dim strAllUsersProgramsPath
Dim objFolder
Dim objFolderItem
Dim colVerbs
Dim objVerb

Set objShell = CreateObject("Shell.Application")
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objCurrentUserStartFolder = objShell.NameSpace (CSIDL_STARTMENU)
strCurrentUserStartFolderPath = objCurrentUserStartFolder.Self.Path
Set objAllUsersProgramsFolder = objShell.NameSpace(CSIDL_COMMON_PROGRAMS)
strAllUsersProgramsPath = objAllUsersProgramsFolder.Self.Path

' - Remove pinned items -

'PowerShell
If objFSO.FileExists(strCurrentUserStartFolderPath & "\Programs\Accessories\Windows PowerShell\Windows Powershell.lnk") Then
    Set objFolder = objShell.Namespace(strCurrentUserStartFolderPath & "\Programs\Accessories\Windows Powershell\")
    Set objFolderItem = objFolder.ParseName("Windows Powershell.lnk")
    Set colVerbs = objFolderItem.Verbs
    For Each objVerb in colVerbs
        If Replace(objVerb.name, "&", "") = "Unpin from Taskbar" Then objVerb.DoIt
    Next
End If

'Internet Explorer
If objFSO.FileExists(strCurrentUserStartFolderPath & "\Programs\Internet Explorer.lnk") Then
    Set objFolder = objShell.Namespace(strCurrentUserStartFolderPath & "\Programs")
    Set objFolderItem = objFolder.ParseName("Internet Explorer.lnk")
    Set colVerbs = objFolderItem.Verbs
    For Each objVerb in colVerbs
        If Replace(objVerb.name, "&", "") = "Unpin from Taskbar" Then objVerb.DoIt
    Next
End If

'Windows Explorer
If objFSO.FileExists(strCurrentUserStartFolderPath & "\Programs\Accessories\Windows Explorer.lnk") Then
    Set objFolder = objShell.Namespace(strCurrentUserStartFolderPath & "\Programs\Accessories")
    Set objFolderItem = objFolder.ParseName("Windows Explorer.lnk")
    Set colVerbs = objFolderItem.Verbs
    For Each objVerb in colVerbs
        If Replace(objVerb.name, "&", "") = "Unpin from Taskbar" Then objVerb.DoIt
    Next
End If

'Windows Media Player
If objFSO.FileExists(strAllUsersProgramsPath & "\Windows Media Player.lnk") Then
    Set objFolder = objShell.Namespace(strAllUsersProgramsPath)
    Set objFolderItem = objFolder.ParseName("Windows Media Player.lnk")
    Set colVerbs = objFolderItem.Verbs
    For Each objVerb in colVerbs
        If Replace(objVerb.name, "&", "") = "Unpin from Taskbar" Then objVerb.DoIt
    Next
End If

' - Pin to Taskbar -

'Microsoft Outlook 2010
If objFSO.FileExists(strAllUsersProgramsPath & "\Microsoft Office\Microsoft Outlook 2010.lnk") Then
	Set objFolder = objShell.Namespace(strAllUsersProgramsPath & "\Microsoft Office")
	Set objFolderItem = objFolder.ParseName("Microsoft Outlook 2010.lnk")
	Set colVerbs = objFolderItem.Verbs
	For Each objVerb in colVerbs
		If Replace(objVerb.name, "&", "") = "Pin to Taskbar" Then objVerb.DoIt
	Next
End If

'Internet Explorer
If objFSO.FileExists(strCurrentUserStartFolderPath & "\Programs\Internet Explorer.lnk") Then
    Set objFolder = objShell.Namespace(strCurrentUserStartFolderPath & "\Programs")
    Set objFolderItem = objFolder.ParseName("Internet Explorer.lnk")
    Set colVerbs = objFolderItem.Verbs
    For Each objVerb in colVerbs
        If Replace(objVerb.name, "&", "") = "Pin to Taskbar" Then objVerb.DoIt
    Next
End If

'Windows Explorer(My computer link)
If objFSO.FileExists(strAllUsersProgramsPath & "\Accessories\My Computer.lnk") Then
	Set objFolder = objShell.Namespace(strAllUsersProgramsPath & "\Accessories")
	Set objFolderItem = objFolder.ParseName("My Computer.lnk")
	Set colVerbs = objFolderItem.Verbs
	For Each objVerb in colVerbs
		If Replace(objVerb.name, "&", "") = "Pin to Taskbar" Then objVerb.DoIt
	Next
End If


'Microsoft Word 2010
If objFSO.FileExists(strAllUsersProgramsPath & "\Microsoft Office\Microsoft Word 2010.lnk") Then
	Set objFolder = objShell.Namespace(strAllUsersProgramsPath & "\Microsoft Office")
	Set objFolderItem = objFolder.ParseName("Microsoft Word 2010.lnk")
	Set colVerbs = objFolderItem.Verbs
	For Each objVerb in colVerbs
		If Replace(objVerb.name, "&", "") = "Pin to Taskbar" Then objVerb.DoIt
	Next
End If



'Delete the script
DeleteSelf

Sub DeleteSelf()
        Dim objFSO
        'Create a File System Object
        Set objFSO = CreateObject("Scripting.FileSystemObject")
        'Delete the currently executing script
        objFSO.DeleteFile WScript.ScriptFullName
        Set objFSO = Nothing
End Sub

Edit - and I found the blog I lifted it off - http://blogs.technet.com/b/deploymentguys/archive/2009/04/08/pin-items-to-the-start-menu-or-windows-7-taskbar-via-script.aspx

There's plenty more examples if you google "taskbar pin script" or similar.

Swink fucked around with this message at 02:20 on Jan 28, 2014

Adbot
ADBOT LOVES YOU

Swink
Apr 18, 2006
Left Side <--- Many Whelps

kiwid posted:

Do you deploy this via GPO and then just set the flag to apply once and don't reapply?

edit: ahh gently caress it, what a mess. I'll just create documentation.

It's in our windows image at C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pin.vbs

It gets copied to each new user profile that is created on a machine.

  • Locked thread