Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

kiwid posted:

Has anyone tried doing WDS + MDT with Windows 8.1 yet? Does it work well? If so, any good tutorials/documentation out there? (I've never done this before or used sysprep)

Here you go!

http://mdtguy.wordpress.com/2013/11/09/deploy-windows-8-1-with-mdt-2013-and-the-adk-8-1/

That link is extremely basic but a quick Google search shows a few people who made in depth deployment guides for Windows 8.1.

Adbot
ADBOT LOVES YOU

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

lol internet. posted:

SCCM2012 question here. I got a pretty basic SCCM 2012 (non r2) setup. 1 Server, with all roles.

I've worked with SCCM 2007 in the past. I noticed in 2012, any OSD task sequences need to have the option "Copy contents to distribution point" in order to actually work. (When deploying the task sequence, it gives you the option to "Access Content Directly")

1. Does this mean for regular application deployment to existing clients, that doesn't have to be checked off to deploy?

2. I've installed cumulative updates 1, 2 and 3 for SCCM 2012. When pushing out the SCCM client updates, can I just push out CU3? Or do I need to go CU1 > CU2 > CU3

I can answer #2, you only need to install CU3. It includes all the updates of CU1 and CU2. This is also true of CU for SQL and Exchange.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

It can track installations but not licensing per say. Through SCCM we found out a poo poo ton of people connected their email to phones and since we pay per device CALs and not per user CALs we're on the hook for about another 150 CALs or so.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

lol internet. posted:

Wait. 150 Cals for SCCM? or CALS for exchange? Not following you on this.

Exchange CALs. It's way cheaper for us to buy 150 more device CALs than to switch all of our CALs to user CALs.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We were told to install a KMS server and use that. As long as the OEM desktops have keys on it, it's fine to have them all activate with KMS even if you don't own volume licensing.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Yes, but we don't have software licensing for KMS but Microsoft gave us a key right below the MAK.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We use Orion which has been pretty awesome albeit expensive. We use it to monitor all our switches, routers, servers, esx hosts, voip and wan connectivity.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I haven't deployed a 2012 RDS yet but just by using 2012 the biggest hurdle is getting people used to Metro.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Probably be easier to build a new DC and migrate the roles over and promote/demote.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Snorri posted:

Will renaming cause that much of a headache you think? I figured it would but had to ask. Thanks SkippDogg and nexxai for that info, will use dot com if I do end up renaming.

Do you want to take the risk of it all blowing up? Would be good experience to migrate it, and you lessen the risk of disaster.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

FISHMANPET posted:

I upgrade our SCCM 2012 to R2, becuase I was really excited about some of the new Powershell Cmdlets.

And what a crock of poo poo. Incomplete documentation, wrong documentation, functions that just plain don't do anything.

Specifically, get-cmdevice is supposed to return an object to be used with commands like new-cmdevicevariable, but get-cmdevice returns an object of a different type than new-cmdevicevariable expects. new-cmdevicevariable can also use a resourceID, but when you actually use that, it just doesn't do anything.

I've actually done the best I can to file a bug on the first issue: https://connect.microsoft.com/Confi...mdevicevariable

Keep us updated on this. We're looking to update to R2 as well but more for Windows 8.1 imaging support.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Why delete from AD? I just delete from SCCM and then I have a vbs file run during the task sequence requesting a computer name. It then auto adds to the domain.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We have Sophos spam and web appliances and apparently AV is free with it now. We found that out after spending all the hours implementing Forefront.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

SCCM is a beast as you can see with all the SCCM questions that aren't getting answered.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I have a GPO question for y'all. I've been tasked with pushing down our corporate wifi via GPO. I created it, went to computer config -> policies -> windows settings -> security settings -> wireless network (802.11) policies and did my thing. Everything looks good. I link it to our Users OU, remove the Authenticated Users group and applied it to my account, for testing.

My test laptop shows via gpresults /H - the new Wireless GPO is Denied. Reason: Empty.

The gently caress? The settings are clearly there in the GPMC.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Nevermind, I'm an idiot. A computer policy won't work if you only link it to a User OU. Duh.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Yeah I just applied it to entire desktop OU and added my test pc in the Security Filtering. What is better when we go live - add the Domain Computers group or apply loopback processing and add Authenticated Users group?

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Bob Morales posted:

What's the best way to do a migration from MS SQL 2008 R2 on a 32-bit system, to a 64-bit system?

:suicide:

You can't, easily. http://social.technet.microsoft.com...serverMigration

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Swink posted:

PDQ inventory good enough for inventory?

Yes, I purchased it last week even though we have SCCM. Way easier to get info out of. Try the free ver, it has everything but scheduled updates.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I got rid of a lot of old poo poo a few years ago saying they "weren't Windows 7 compatible".

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Less attack vectors and less system requirements, but the later doesn't really matter nowadays much.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We have a standing policy for users to give their password to IT as requested, per the CEO.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Yeah, the majority of our users have email on their phones and it's a pita when a user changes his password because they'll be god damned if they know how to edit their phone password.

EMAIL ON MY PHONE IS BROKEN!!!!

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

What do you guys use for iPhone management? I just had to replace ~50 phones and by god it was fun trying to get peoples unlock codes and itunes passwords so I could format the old ones.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

kiwid posted:

We use Meraki and it's not bad for a free product.

Oh cool. I'll check it out.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I've spent all morning playing with Meraki and it's pretty badass. Of course I don't have much experience with mobile device management.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Don't ask, don't tell.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

kiwid posted:

My boss wants me to update every user in Active Directory with their address and phone numbers (approx 300 users). We have all the address and phone number information in csv format. What is the best way to import this information into Active Directory?

I was thinking maybe dumping Active Directory to a csv with their ID (is it objectSid or sAMAccountName?), matching up the info in the csv and then importing it back via a powershell script?

Do you guys use Exchange? We talked about doing that but then privacy concerns came up such as everyone in the company now knowing where you live.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We use Solarwinds and I like it quite a bit. Has built in counters for drat near everything.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

LmaoTheKid posted:

How does WDS handle OEM licenses for Windows?

Is it as long a sI have the sticker on the box I'm good to go?

I'd really like to start having imaging on my network to make poo poo easier but I have such a hodgepodge of licensing.

According to our MS rep, we can use KMS keys when deploying images as long as each box has the OEM key sticker on it.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We used a sort of pricy Quest tool to do our domain migration. Migrated all the workstations and profiles too.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Do you already have SCCM licensing through corporate SA? If so, yes I'd use that. Might be too costly if you need to buy it though. The benefit of SCCM, other than imaging and app deployment, is that it comes with antivirus.

And yes, you can use KMS for client activation as long as you have OEM stickers on each machine.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Simpleboo posted:

Ok i created a test OU and linked the GP to that OU but I am not seeing a change. I am trying to create a public desktop shortcut by using a GP, however no shortcuts are being created.

On your test pc, you can go to a cmd prompt and run gpupdate /force to force the gpo and if it still doesnt work run gpresult >gp.txt to see if there are errors.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

All the time is like once a month for patches.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Touchy? You mean spoiled. I'm sure management lets that happen.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

BaseballPCHiker posted:

Not this exact problem but SCCM itself but I've ran into similar issues when remoting onto Win 7 machines with multiple displays.

SCCM related and I can't believe I never learned this sooner. Apparently you're not supposed to click the maximize button in service manager console! It heavily strains your sccm and sql servers as well as your desktop I guess. You can stretch it out to fit your monitor however and that is fine.

I don't see that problem in 2012 R2 CU1.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Martytoof posted:

Maybe I'm loving blind, but where do you disable Validate Server Certificate for 802.1x on a Windows 7 machine? I'm trying to play around with AD-integration for WiFi authentication, but I don't want to buy a server cert for my NPS server until I'm sure this works.

I'm able to connect with my Win8 laptop because it seems to just ask me whether I'm expecting to see this SSID here (likely due to the lovely self signed cert) rather than rejecting it outright.

My win7 laptop I'm having no luck with. It can't connect and everything points to the self signed cert but I have no idea where to go to disable the Win7 machine's validation of the cert.

You should really do this with a wireless gpo and just add yourself as a user, test that way. As hihifellow said, you can set this in the gpo itself.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I was asked to add everyones pictures to AD so it gets used in Outlook and Lync. They gave me 400+ pictures and each one a huge fuckoff 40 meg tif on a terabyte drive.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

IE passes login rights through to sharepoint. I bet if he tried that with firefox it would just work.

Adbot
ADBOT LOVES YOU

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

skipdogg posted:

We are not allowed to ever delete a user account from AD. Yes, it sucks.

What the gently caress? Do you have an OU titled "old employees" with thousands of user accounts?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply