I used this example:
http://www.silentcrash.com/2012/06/copy-files-multiple-computers-group-policy-gpo/
main thing being that the file needed to be a .cmd extension
I also changed the switch to overwrite current file without prompting
Xcopy \\server\netlogon\scratch.ini "C:\Program Files\Scratch\" /Y
I used netlogon but not sure its needed, had a few issues trying to use a .vbs file initially.
Tuesday, 25 June 2013
Monday, 17 June 2013
how to view group policy preferences on local machine - rsop.msc
I was wondering what to use to view settings applied in the group policy preferences section of group policy. I liked rsop.msc :-(
The preferences section is not on show.
I read some stuff here : rsop.msc and gpresult not including preferences
I briefly tried GPRESULT /H rsop.html (if ran from run command the output of this seemed to go to my users root e.g. c:\users\username) but still didn't see the group policy preferences section (which is under Computer) displayed.
Then elevated rights worked, see here: http://answers.microsoft.com/en-us/windows/forum/windows_7-networking/why-doesnt-gpresult-r-display-computer-settings/597f945c-1be4-4af5-9bed-622e54c82b1e
Therefore open a cmd prompt to run, "GPRESULT /H rsop.html" and change to suitable file path for generated output
The Computer section of group policy needed administrative rights to display.
Addendum
I adding another point to this post so its all together.
Regarding running rsop.msc as a restricted user and being unable to view 'Computer' policies due to being a restricted user.
I would like to right click command prompt and run as an elevated user, but the right click context menu is disabled....errr...
A workaround for this is to use type command into search box and instead of clicking enter click Ctrl+Shift + Enter this brings up the UAC asking for admin login.
I can then navigate to a user folder, as I cannot seem to change drives??? Run "GPRESULT /H rsop.html", then run rsop.html all from command prompt. This fires up the browser with my results.
All stated here: http://www.howtogeek.com/howto/windows-vista/run-a-command-as-administrator-from-the-windows-vista-run-box/
The preferences section is not on show.
I read some stuff here : rsop.msc and gpresult not including preferences
I briefly tried GPRESULT /H rsop.html (if ran from run command the output of this seemed to go to my users root e.g. c:\users\username) but still didn't see the group policy preferences section (which is under Computer) displayed.
Then elevated rights worked, see here: http://answers.microsoft.com/en-us/windows/forum/windows_7-networking/why-doesnt-gpresult-r-display-computer-settings/597f945c-1be4-4af5-9bed-622e54c82b1e
Therefore open a cmd prompt to run, "GPRESULT /H rsop.html" and change to suitable file path for generated output
The Computer section of group policy needed administrative rights to display.
Addendum
I adding another point to this post so its all together.
Regarding running rsop.msc as a restricted user and being unable to view 'Computer' policies due to being a restricted user.
I would like to right click command prompt and run as an elevated user, but the right click context menu is disabled....errr...
A workaround for this is to use type command into search box and instead of clicking enter click Ctrl+Shift + Enter this brings up the UAC asking for admin login.
I can then navigate to a user folder, as I cannot seem to change drives??? Run "GPRESULT /H rsop.html", then run rsop.html all from command prompt. This fires up the browser with my results.
All stated here: http://www.howtogeek.com/howto/windows-vista/run-a-command-as-administrator-from-the-windows-vista-run-box/
Thursday, 6 June 2013
IE 10 proxy settings group policy not being applied
Same as this issue: http://www.edugeek.net/forums/windows-8/114433-ie-proxy-windows-8-server-2008r2.html#post979207
Had to start using Group Policy Preferences , the bottom part of group policy editor 'user configuration->preferences->control panel settings->internet settings'
I tried this and it worked:
I searched google and used this extra info:
http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/58939ec8-1396-453e-af54-f03603e10723
the post timestamped Wednesday, April 17, 2013 4:57 PM by Babylon78.
This is what I did:
Open up the policy, and create an IE8 Preference: User Configuration --> Preferences --> Control Panel Settings --> Internet Settings --> New --> Internet Explorer 8.
Set my proxy settings.
Navigate to C:\Windows\SYSVOL\domain\Policies was an easier route, then sort by date for the recently created IE entry.
Navigate to User\Preferences\InternetSettings
"Open up the "InternetSettings.xml" file, and change the MAX value to something above 10.0.0.0 (I usually put 10.5.0.0). This way, the policy won't trip up later on if IE 11 comes out and doesn't support any of these policies, but at least you'll be safe until 10.5.0, or until a hotfix is available. " -babylon78
max="10.5.0.0"
Had to start using Group Policy Preferences , the bottom part of group policy editor 'user configuration->preferences->control panel settings->internet settings'
I tried this and it worked:
I searched google and used this extra info:
http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/58939ec8-1396-453e-af54-f03603e10723
the post timestamped Wednesday, April 17, 2013 4:57 PM by Babylon78.
This is what I did:
Open up the policy, and create an IE8 Preference: User Configuration --> Preferences --> Control Panel Settings --> Internet Settings --> New --> Internet Explorer 8.
Set my proxy settings.
Navigate to C:\Windows\SYSVOL\domain\Policies was an easier route, then sort by date for the recently created IE entry.
Navigate to User\Preferences\InternetSettings
"Open up the "InternetSettings.xml" file, and change the MAX value to something above 10.0.0.0 (I usually put 10.5.0.0). This way, the policy won't trip up later on if IE 11 comes out and doesn't support any of these policies, but at least you'll be safe until 10.5.0, or until a hotfix is available. " -babylon78
max="10.5.0.0"
Tuesday, 21 May 2013
User not receiving proxy settings. precedence disabled win 7
This issue seems to suggest that the precedence of GPO rules is at fault, that some entry is overriding something else, but this is not the case I do not think. After reading a million nonsensical posts by microsoft pros i end up none the wiser.
I eventually opt to delete the locally cached profile for the user, and its solves the issue.
On the affected machine, right click my computer-> properties,->advanced system settings->user profiles
I eventually opt to delete the locally cached profile for the user, and its solves the issue.
On the affected machine, right click my computer-> properties,->advanced system settings->user profiles
Tuesday, 15 January 2013
IE certificate . Continue to this website. Not working
Internet Explorer Certificate Security Warning, cannot continue (blocked)
But even if we click on "Continue to this website (not recommended).", nothing happens. totally blocked!
Because of the latest updates : KB2661254
IE prevents connection to any website that use a certificate with less than 1024 bits key
To fix it, you can add a dword key in the registry :
HKEY_LOCAL_MACHINE\Softwar
DWORD (32 bit) : MinRsaPubKeyBitLength
value : 512 (decimal)
Thanks: berneyi of experts exchange
Wednesday, 10 October 2012
Could not start the net logon service
c:\>netsh winsock reset
Network card not getting an IP address
or more accurately...
When I attempt to logon to a domain I just joined I
cannot and when i go into services the net logon service
is stopped I attempt to start it and get this message -
Could not start the net logon service on the local
computer. Error 10106: The requested service provider
could not be loaded or initialized.
Solution:
How to determine and to recover from Winsock2 corruption in Windows Server 2003, in Windows XP, and in Windows Vista
http://support.microsoft.com/?kbid=811259
Network card not getting an IP address
or more accurately...
When I attempt to logon to a domain I just joined I
cannot and when i go into services the net logon service
is stopped I attempt to start it and get this message -
Could not start the net logon service on the local
computer. Error 10106: The requested service provider
could not be loaded or initialized.
Solution:
How to determine and to recover from Winsock2 corruption in Windows Server 2003, in Windows XP, and in Windows Vista
http://support.microsoft.com/?kbid=811259
Tuesday, 9 October 2012
Powershell: Adding users to active directory with a csv
Creating users in AD from a csv file using Powershell
Using Import-Csv and New-ADUser
Some examples in the links
this is good:
http://gallery.technet.microsoft.com/scriptcenter/ed20b349-9758-4c70-adc0-19c5acfcae45
better than this:
http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/374dca0b-6b93-4a77-b53b-51602b2b4544/
And worth a look? simple automation straight from a csv, and adding to a group also
http://www.simple-talk.com/sysadmin/exchange/active-directory-management-with-powershell-in-windows-server-2008-r2/
Having problems with execution? see:
http://technet.microsoft.com/en-us/library/ee176949.aspx
Import-Module ActiveDirectory
$Users = Import-Csv ".\myusers.csv"
foreach ($User in $Users)
{
$OU = "OU=MyUsers,OU=MyStuff,DC=mydomain,DC=local,DC=com"
$Detailedname = $User.firstname + " " + $User.lastname
$Firstname = $User.Firstname
$FirstLetterFirstname = $Firstname.substring(0,1) #not used this but left it in
$SAM = $User.Firstname.tolower() + "." + $user.lastname.tolower()
$userprinci = $SAM + "@mydomain.local.com"
$logonscript = "logscript.vbs"
$homedir = "\\server\myarea\" + $SAM + "\My Documents"
#tried this alternative
#$homedir = "\\server\myarea\%username%\My Documents"
New-ADUser -Name $Detailedname -SamAccountName $SAM -UserPrincipalName $userprinci -DisplayName $Detailedname -GivenName
$user.firstname -Surname $user.lastname -Path $OU -HomeDrive "H:" -HomeDirectory $homedir -scriptpath $logonscript -
PasswordNeverExpires $True -PassThru
#the password is blank on this example
}
Still issue with creating home directory for user, seems that i have to create this after by using the %username%, then apply this, then add My Documents.
I dont know if this is due to the user not being in a group(i.e. with correct privileges) or what. But cannot have the user in a group till user exists anyway!!??
So therefore I also needed to manually add to group.
This is the part mentioned earlier that adds users to groups, a bit pointless for now
add users to group"OU=MyUsers,OU=MyStuff,DC=mydomain,DC=local,DC=com" | ForEach-Object {Add-ADGroupMember -Identity 'ggGroupName' -Members $_}
Labels:
active directory,
ad,
csv,
import-csv,
new-aduser,
powershell
Subscribe to:
Posts (Atom)
