Tuesday, 25 June 2013

Copy file to multiple PCs with group policy

I used this example:
http://www.silentcrash.com/2012/06/copy-files-multiple-computers-group-policy-gpo/

main thing being that the file needed to be a .cmd extension

I also changed the switch to overwrite current file without prompting
Xcopy \\server\netlogon\scratch.ini "C:\Program Files\Scratch\" /Y

I used netlogon but not sure its needed, had a few issues trying to use a .vbs file initially.

Monday, 17 June 2013

how to view group policy preferences on local machine - rsop.msc

I was wondering what to use to view settings applied in the group policy preferences section of group policy. I liked rsop.msc :-(

The preferences section is not on show.

I read some stuff here : rsop.msc and gpresult not including preferences

I briefly tried GPRESULT /H rsop.html (if ran from run command the output of this seemed to go to my users root e.g. c:\users\username) but still didn't see the group policy preferences section (which is under Computer) displayed.

Then elevated rights worked, see here: http://answers.microsoft.com/en-us/windows/forum/windows_7-networking/why-doesnt-gpresult-r-display-computer-settings/597f945c-1be4-4af5-9bed-622e54c82b1e

Therefore open a cmd prompt to run, "GPRESULT /H rsop.html" and change to suitable file path for generated output

The Computer section of group policy needed administrative rights to display.

Addendum

I adding another point to this post so its all together.

Regarding running rsop.msc as a restricted user and being unable to view 'Computer' policies due to being a restricted user.

I would like to right click command prompt and run as an elevated user, but the right click context menu is disabled....errr...

A workaround for this is to use type command into search box and instead of clicking enter click Ctrl+Shift + Enter this brings up the UAC asking for admin login.

I can then navigate to a user folder, as I cannot seem to change drives??? Run "GPRESULT /H rsop.html", then run rsop.html all from command prompt. This fires up the browser with my results.

All stated here: http://www.howtogeek.com/howto/windows-vista/run-a-command-as-administrator-from-the-windows-vista-run-box/



Thursday, 6 June 2013

IE 10 proxy settings group policy not being applied

Same as this issue: http://www.edugeek.net/forums/windows-8/114433-ie-proxy-windows-8-server-2008r2.html#post979207

Had to start using Group Policy Preferences , the bottom part of group policy editor 'user configuration->preferences->control panel settings->internet settings'


I tried this and it worked:

I searched google and used this extra info:
http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/58939ec8-1396-453e-af54-f03603e10723

the post timestamped Wednesday, April 17, 2013 4:57 PM by Babylon78.

This is what I did:
Open up the policy, and create an IE8 Preference: User Configuration --> Preferences --> Control Panel Settings --> Internet Settings --> New --> Internet Explorer 8.
Set my proxy settings.

Navigate to C:\Windows\SYSVOL\domain\Policies was an easier route, then sort by date for the recently created IE entry.
Navigate to User\Preferences\InternetSettings 
"Open up the "InternetSettings.xml" file, and change the MAX value to something above 10.0.0.0 (I usually put 10.5.0.0). This way, the policy won't trip up later on if IE 11 comes out and doesn't support any of these policies, but at least you'll be safe until 10.5.0, or until a hotfix is available. " -babylon78

max="10.5.0.0"

Tuesday, 21 May 2013

User not receiving proxy settings. precedence disabled win 7

This issue seems to suggest that the precedence of GPO rules is at fault, that some entry is overriding something else, but this is not the case I do not think. After reading a million nonsensical posts by microsoft pros i end up none the wiser.

I eventually opt to delete the locally cached profile for the user, and its solves the issue.

On the affected machine, right click my computer-> properties,->advanced system settings->user profiles

Tuesday, 15 January 2013

IE certificate . Continue to this website. Not working


Internet Explorer Certificate Security Warning, cannot continue (blocked)

But even if we click on "Continue to this website (not recommended).", nothing happens. totally blocked!

Because of the latest updates : KB2661254

IE prevents  connection to any website that use a certificate with less than 1024 bits key

To fix it, you can add a dword key in the registry :

HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDLLCreateCertificateChainEngine\Config\
DWORD (32 bit) : MinRsaPubKeyBitLength
value : 512 (decimal)

Thanks: berneyi  of experts exchange

Wednesday, 10 October 2012

Could not start the net logon service

c:\>netsh winsock reset

Network card not getting an IP address

or more accurately...

When I attempt to logon to a domain I just joined I
cannot and when i go into services the net logon service
is stopped I attempt to start it and get this message -

Could not start the net logon service on the local
computer. Error 10106: The requested service provider
could not be loaded or initialized.
Solution:
How to determine and to recover from Winsock2 corruption in Windows Server 2003, in Windows XP, and in Windows Vista

http://support.microsoft.com/?kbid=811259

Tuesday, 9 October 2012

Powershell: Adding users to active directory with a csv


Creating users in AD from a csv file using Powershell

Using Import-Csv and New-ADUser

Some examples in the links
this is good:
http://gallery.technet.microsoft.com/scriptcenter/ed20b349-9758-4c70-adc0-19c5acfcae45
better than this:
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/374dca0b-6b93-4a77-b53b-51602b2b4544/

And worth a look? simple automation straight from a csv, and  adding to a group also
http://www.simple-talk.com/sysadmin/exchange/active-directory-management-with-powershell-in-windows-server-2008-r2/

Having problems with execution? see:
http://technet.microsoft.com/en-us/library/ee176949.aspx

Import-Module ActiveDirectory
$Users = Import-Csv ".\myusers.csv" 
foreach ($User in $Users) 
{ 
    $OU = "OU=MyUsers,OU=MyStuff,DC=mydomain,DC=local,DC=com"
    $Detailedname = $User.firstname + " " + $User.lastname
    $Firstname = $User.Firstname
    $FirstLetterFirstname = $Firstname.substring(0,1) #not used this but left it in
    $SAM =  $User.Firstname.tolower() + "." + $user.lastname.tolower()
    $userprinci = $SAM + "@mydomain.local.com"
    $logonscript = "logscript.vbs"
    $homedir = "\\server\myarea\" + $SAM + "\My Documents"
    #tried this alternative
    #$homedir = "\\server\myarea\%username%\My Documents"
    New-ADUser -Name $Detailedname -SamAccountName $SAM -UserPrincipalName $userprinci -DisplayName $Detailedname -GivenName
$user.firstname -Surname $user.lastname -Path $OU -HomeDrive "H:" -HomeDirectory $homedir -scriptpath  $logonscript    -
PasswordNeverExpires $True -PassThru
#the password is blank on this example
}



Still issue with creating home directory for user, seems that i have to create this after by using the %username%, then apply this, then add My Documents.

I dont know if this is due to the user not being in a group(i.e. with correct privileges) or what. But cannot have the user in a group till user exists anyway!!??

So therefore I also needed to manually add to group.

This is the part mentioned earlier that adds users to groups, a bit pointless for now
add users to group"OU=MyUsers,OU=MyStuff,DC=mydomain,DC=local,DC=com"  |  ForEach-Object {Add-ADGroupMember -Identity 'ggGroupName' -Members $_}