Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Yaos posted:

I have tried to deploy VNC in group policy but have no luck.
I know that LogMeIn != VNC, but with LogMeIn Central, you can create deployable MSI packages. I create groups based on physical (city) locations and make it the first item that gets installed during new system setup as well as upgrades at boot-time so it's always up to date.

Adbot
ADBOT LOVES YOU

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

skipdogg posted:

Just looking to get some opinions.

We're upgrading from AD 2003 to 2008R2 over the next couple of months and our Microsoft PFE is recommending a larger change window, and demoting old 2003DC first, then bringing up the 2008 DC.

I personally feel more comfortable bringing up DC2 in each location, getting everything setup and migrated like any shared printers, RADIUS settings and DHCP scopes, then doing a faster cutover by removing DC1 and then renaming DC2 to DC1 and swapping IP addresses. I know it's not as clean, but I haven't ran into issues with it before. Assuming I wait for full replication between demoting DC1 and renaming DC2 to DC1 there shouldn't be any issues at all.

In case anyone is wondering 2008R2 is a temporary step until 2012R2 early next year. We have some dependencies in our environment we can't get rid of until late this year preventing us from going to 2012 right now.
Don't ever EVER rename DCs to the names of the old ones. Just promote DC2, do your poo poo, demote DC1, leave DC2 as "DC2". Period.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

LmaoTheKid posted:

I think I might just get them all on Skype. For some stupid reason they use IM as a paging system instead of email and REFUSE to adapt. It's a good thing the boss there is cool and they bring in a lot of money because normally my answer would just be "send an email".
If they're so tied to using some sort of IM, why not keep it all in house and set up an OpenFire server and deploy Spark to those who need it? It takes about 20 minutes to set up and go, and then you can be sure that no one outside of your company can snoop on your internal conversations?

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Snorri posted:

2) How much of a pain is it to rename my DC from dot whatever to dot local? I thought I was a clever boy and matched our external domain suffix to our internal. Turns out I am a dumb gently caress and this causes intermittent DNS issues. Obviously this is my first DC from scratch.
Do NOT do this. Rename it to .internal.company.com - as of November 1, 2015, you will never be able to get a publicly-trusted SSL cert signed for any PC with a .local hostname as it can't be verified by the CA.

Source: http://support.godaddy.com/help/article/6935/phasing-out-intranet-names-and-ip-addresses-in-ssls

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Maneki Neko posted:

Why wouldn't you just have an internal CA at that point?
Exchange 2007 and up requires a SAN certificate which includes both the internal and external hostnames. If even one of the hostnames in the SAN is a ".local" one, they won't issue the cert. Then you're stuck doing a bunch of DNS fuckery which is not supported my Microsoft, if you ever have to involve them for help. Might as well do it right the first time, so if you're gonna do the rename, rename it to something that will work with other services.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Hadlock posted:

I need a way to OCR images (screenshots) that are dropped in a folder and output a text file. Or some other scriptable fashion.

Surely there's something out there that will do this for less than $10,000

To get a faster rate of adoption for our ticketing system, we'd like users to be able to email our ticketing system and auto-OCR the screencap (generated from snip-tool)

So it doesn't need to be very sophisticated OCR, it just needs to be able to read the three or four most common windows fonts in about four different font sizes.

So you're saying you want to go from digital text (e-mail) to picture to OCR to digital text (ticket)?

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Hadlock posted:

Sorry let me rephrase

The software we support is awful, and users can't (or won't) select copy and paste the error message.

The users are very efficient at using the windows snip tool to take a "screenshot" of the error and email it to our external helpdesk/internal support department

So I want to go from

Error -> user sends email with screenshot -> ticketing front end -> OCR in-line image -> write to database email content + text from OCR'd in-line image

The end result being that we have a text-searchable database of all the errors and resolution

This is the very definition of a situation where you're trying to use technology to solve a personnel problem. At a certain point, you can't make things any easier for people. Obviously they care enough to use snip-tool to send you a screenshot, so teach them to use "CTRL-C" when the error message appears which will (if the software was written correctly) copy the title and text of the prompt.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Bob Morales posted:

Ran into an interesting setup today. Imagine a bunch of folders on a file share:

Marketing
Accounting
HR
..
..

Instead of users being in an AD group named 'Marketing', and then having permissions assigned to the Marketing folder to the 'Marketing' AD group, there's a 'MarketingShareRead' and 'MarketingShareWrite' group with people in it, and then those groups are given permissions to that folder.
If there are large enough groups of people that having separate read and write groups makes sense, this setup is exactly how I'd do it. I may name them slightly different (e.g. "MarketingRead" / "MarketingWrite") but the idea would be the same.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe
I discovered the wonder that is MDT yesterday, and my god, I don't know how I lived with out it. I've been using WDS and WSUS for the last few years to automate a basic deployment process always thinking that the automated software deployment side of things was either the absolutely basic Group Policy deployments or having to pay for SCCM (which isn't happening in our company). Knowing that I can push out an updated image that automatically runs through however many WSUS cycles it needs to to get up-to-date without a single touch beyond booting off PXE is awesome. Thank you guys for giving me the information in this thread to push me to investigate it as an option.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

LmaoTheKid posted:

They already are dude :smith:
I had to convince myself they were just cancelled this year :smith:

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Dr. Arbitrary posted:

I made a shortcut and I want it to have the same icon, but I can't seem to get windows to extract the icon graphic from dsa.msc.

How do I make my desktop pretty? Where the hell does windows store that icon graphic?
Make a shortcut that just points to "dsa.msc" to use that icon, then update it with the full string you want to run after it's made.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

MrMoo posted:

I normally use:
code:
w32tm /config /manualpeerlist:sapporo.hk.miru.hk,0x8 /syncfromflags:MANUAL
net stop w32time
net start w32time
w32tm /resync

Yeah, I thought 0x8 was what you needed, not 0x1.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

MC Fruit Stripe posted:

I can only use IPs and not DNS in only this one environment
I feel like I'm going to hate myself for asking, but uhhh why?

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

peak debt posted:

DNS is a security risk because hackers can guess what a server does from its name.
After the stories of Dick Trauma and blackswordca, I honest to goodness cannot tell if you're being serious or not.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

CLAM DOWN posted:

Sounds like you're looking for access-based enumeration: http://technet.microsoft.com/en-us/library/cc784710(v=ws.10).aspx
Remove "Inherit permissions from object's parent" on the file, set correct read/write permissions on the file, apply. Remove read permissions on the folder. Now they have to use the exact file's path to open it, otherwise they get Access Denied when they try to browse to the folder.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

NevergirlsOFFICIAL posted:

I'm looking for "Carbonite but in ~my private cloud~" :yaycloud: in other words: I want a product that automatically backs up selected folders on my users' workstations to my data center over the WAN. I played with Work Folders on 2012R2 for a bit but I'd like something to offer my Mac users as well. Any ideas?

The goal is to cover my rear end when VPs save stuff on their local laptop, travel all the time, and then lose the laptop.
I don't use it myself but I've heard pretty good things about https://www.aerofs.com/

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

CLAM DOWN posted:

Please tell me at the very least that people are not logged in interactively with admin accounts, and they just use a separate admin account to elevate rights only when required.
lol are you new here

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe
Which eSATA card are you using? Updated drivers?

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

LmaoTheKid posted:

Ok, so I'm trying to wrap my head around this.

We have a mix of Adobe Reader and Acrobat in the company (don't ask, I hate it but my boss doesn't want to pay for seats for everyone).

So the people who have Acrobat keep getting file associations grabbed away by reader whenever I update it and I get frantic HELP I CAN EDIT PDFS ANYMORE emails.

I've never really done any Item Level targeting but it looks like I can set up a MSI query to say "if Adobe Acrobat is installed, don't install reader" correct? Does anyone have any good articles on MSI targeting filters for group policy?
You should be using the Adobe Customization Tool to generate a proper .MSI for Reader, and right within the configuration options is that exact setting.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe
If RDCman is what I think it is, you should really consider Terminals instead (http://terminals.codeplex.com). It supports a shitton of different protocols, is open-source, and just seems to "work".

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Maneki Neko posted:

I will admit I haven't looked at Terminals in a while, but I don't think I'm alone in being a past Terminals user who jumped ship to RDCMan because at some point Terminals became a godawful crashy mess.
Obviously this is anecdotal only, but I haven't experienced a Terminals crash possibly ever, although I've only been using it since last year maybe so perhaps they fixed the issues that were causing the crashes?

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Rhymenoserous posted:

gently caress no. Only go to spiceworks for obscure issues and or to hear some rear end in a top hat lecture you about how you don't really need to buy a SAN with a support contract you only need to string some random shitbox up with open filer and look at how much money you save!

If I'm getting some obscure error message I'll check spiceworks. But when I'm looking through the greatest and most up to date tech doodads to buy I'd probably get more mileage from consulting a local witch doctor, because some dumb rear end in a top hat on there is going to suggest a "Roll your own!" solution built out of a 10 year old dell poweredge and broken dreams. I've never met a more out of date group of assholes in my life.
This should pretty much be expected. Think about the SpiceWorks product: it's a free ticketing system in a sea of pay-for options. The guys who choose the free option are probably budget-restricted and have just got used to finding ways that "just work" without spending much/any money.

This is a terrible loving way to run an IT department and I disagree with the mentality at it's most basic level, but just trying to explain why the users are what they are.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Zero VGS posted:

There is an open-source program called Hobocopy that is just like Robocopy, but it can leverage Shadow Volumes to copy files that are in-use or otherwise locked. I used to use that with Schedule Tasks and it kicked rear end.

Just for the record (I know he was talking about backing up .baks, and not .mdbs) but do NOT loving do this to live database files. This will result in 100% unusable backups.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe
Seconding this. ScanSnaps are the end-all-be-all of desktop scanners. They're super fast, include full versions of Adobe Acrobat, and are insanely simple to use. Load your documents, press button, done. They don't fax, but gently caress fax.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Thanks Ants posted:

This can work over ADSL if you really can't get anything better, and there's no firewall configuration to mess around with (at least, not that would be your responsibility). This would get all the locations onto "your" network.

Why even do that? If you're going the "cheapy" route, just set up a VPN tunnel from each location (via the router at each locations) pointing back to your main office. That's gets everyone on-net and you don't have to wait for contracts to renew.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

kiwid posted:

We currently have an old as gently caress AD domain, started way back with Windows 2000.

We want to create a new domain and migrate people over to it rather than upgrade the current one. Reasons for this is a lot of ghost DCs, manual ADSI edits, and other general security concerns.

Anyway, our current domain is corp.example.com. I guess I can't really reuse the "corp" domain, so I was wondering what other short but to the point domains you guys use? I was thinking of maybe using internal.example.com, but that's a whole 4 extra characters to type every time I need to use the domain\username login convention.
"ad.example.com"

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Thanks Ants posted:

Question time: How long does Windows Server cache NXDOMAIN responses obtained from forwarders (so internet addresses, not internal zones), and can you change this? My Google-fu is weak because everything I can find refers to making changes to the DNS client caching expiry. We have a dev team adding DNS entries externally, immediately trying to hit them from inside the network and then having to wait an hour for the negative response to time out.
According to a quote here (http://social.technet.microsoft.com/wiki/contents/articles/26864.windows-server-dns-service-negative-caching.aspx), it looks like it's defaulted to an hour. "Now even if that host becomes available again, it's cached for an hour the host isn't available."

The term you want to Google is "negative caching".

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Zaepho posted:

I like DFS namespaces, because when inevitably the underlying servers/storage/etc changes, there is zero impact to the users. Bonus points since you can add servers to the namespace, replicate the content and then phase out the original server.

Scale-out file servers seems like more effort than it's worth except in very specific cases (VM storage for Shared Nothing Hyper-V Clusters and VMM is a really cool use case)

Big item for me is Access Based Enumeration. I would stay away from Claims, I haven't seen much adoption so I'm sure the bugs and "Features" aren't all flushed out and fully stabilized yet.
What this guy said, but also enabling File System Resource Manager (as described here [shameless plug]: https://fsrm.experiant.ca/) to help prevent against crypto infections. It's obviously not the end-all/be-all, but it's just another layer of security to make your life easier.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Thanks Ants posted:

Get a web traffic intercepting proxy and inject JavaScript into every page that spawns a new tab with your intranet site in.
slow down there satan

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

anthonypants posted:

What the gently caress? No, don't patch them. Replace them.

Seriously. The fact that they keep releasing these patches after the OS has been EOLd only legitimizes the C-levels who think that replacing "perfectly good computers" is a waste of money.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

peak debt posted:

There's this new product called Google Wave that will allow you to seamlessly co-edit documents. The demo video looks really cool I can't wait for the release.

I'm really hoping this is super-thick sarcasm

https://en.wikipedia.org/wiki/Apache_Wave - released in 2009.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Mr. Clark2 posted:

Hopefully this is just a one-off.
lmfao

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

The Fool posted:

Even Microsoft doesn't expect any real company to be 100% Azure AD
Which is hilarious because I am the Senior Cloud Analyst for a decent sized airline - we fly 737s (not the MAX8) - with several hundred employees spread out over the country and the continent and we are 100% in the cloud. We have *zero* servers on prem and run everything using Azure AD.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Tab8715 posted:

As a previous poster said, how does this work with printers and other weird devices that don't support modern auth?
Really simply: we don't buy those things

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Potato Salad posted:

it seriously looks like one of my client domains was used as an inefficient but highly available rainbow table
Mods: new thread title plz

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

H2SO4 posted:

oh i see you've also attempted to deploy a multi tier PKI infrastructure
This is like a rite of passage for "true" Windows sysadmins

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

Docjowles posted:

and then took down and started charging money for them
The besterer part of this is that if you visit his website (ajtek.ca), there is this wonderful piece:

https://www.ajtek.ca/wam/previous-users-of-adamj-clean-wsus-now-defunct-software/ posted:

Please be advised that the use of the early versions of our software known as Adamj Clean-WSUS is now strictly prohibited.
I wonder if he knows that he can't change the licensing status after the fact? And I wonder how many people saw this and thought "Oh god, now I *have* to buy a copy!" While I hope that number is 0, I think we all know that it isn't.

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe
Cross-posting from the [SPAM] thread:

Got a question for those of you on bigger teams - have you heard of software that can be deployed to a service desk that does some kind of conditional question asking?

Our offshore service desk doesn't do a great job of following instructions when they're all laid out in a single document and so what we're looking for is something that they can use that asks one question at a time, and then based on their answers proceeds through the troubleshooting steps like a choose your own adventure.

I feel like something like this has got to exist, but then again, maybe not?

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

MF_James posted:

At last job this was integrated into our ticket system, you'd select the high level issue and then the system walked you through questions/steps based on different selections.

Also some sections forced you to put notes in i.e. answering a question, so that if the ticket got escalated the person that picked it up would have a running start without having to badger the phone agent.
Do you remember what ticketing system this was part of? We currently use FreshService, so I don't know that we'd change, but I can't even come up with a proper Google-able search string to help me find any options, and so the ticketing system's website might have something that I can use to find a similar, broken-out piece.

Adbot
ADBOT LOVES YOU

nexxai
Jul 17, 2002

quack quack bjork
Fun Shoe

The Fool posted:

Freshservice has "dependent fields" they'd probably be a pain to set up for more complicated issues, but might help.
Yeah, that's kind of the system we're using right now, but for massive decision trees, it's effectively impossible to manage.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply