0

Windows 10 / Server 2016 Suck on “Downloading updates 0%”

Posted by paris on Feb 21, 2017 in Random

This is a problem for Release Candidate 1 (RC1 ) for Server 2016 and Windows 10 pointing to Microsoft Update or a WSUS Server

You will need to manually install this CU Update on the machines for Windows Update to start working

http://www.catalog.update.microsoft.com/search.aspx?q=kb3197954

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: +1 (from 1 vote)

Tags: , , , , ,

 
0

GPO’s For Enterprise Windows 10 Roll Out

Posted by paris on Oct 4, 2016 in Research

There is a big list by Microsoft I went through – https://technet.microsoft.com/itpro/windows/manage/manage-connections-from-windows-operating-system-components-to-microsoft-services#BKMK_WiFiSense , Microsoft also provides a DISA STIG Baseline ( here )  however I have gone a bit further on security

Computer Configuration – Administrative Templates – Windows Components – Data Collection and Preview Builds

Disable access to pre-release features – Disabled

Configure telemetry to level 0 – Enterprise Only

Do not show feedback notifications – Enabled

Toggle user control over Insider builds – Disabled

 

Computer Configuration – Administrative Templates – System – Log on

                Show first sign-in animation – Disable

                Turn on convenience PIN sign-in – Diable

Turn off picture password sign-in -Enable

 

Computer Configuration – Administrative Templates – Windows Components – Search –

Allow Cortana – Disabled

 

Computer Configuration – Administrative Templates – Windows Components – Cloud Content

                Do Not Show Windows Tips – Enabled

                Turn off Microsoft Consumer Experiences – Enabled

 

Computer Configuration – Administrative Templates – Control Panel

                Do not display the lock screen – Enabled

 

Computer Configuration – Windows Settings – Security Settings – Local Policies – Security Options     

                Accounts: Block Microsoft Accounts – Enabled From Longon and Adding

 

Computer Configuration\Administrative Templates\Network\WLAN Service\WLAN Settings\

Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services – Disabled 

 

Computer Configuration\ Administrative Templates\ Control Panel\ Regional and Language Options\ Allow Input Personalization and set to Disabled.

We also collect your typed and handwritten words to improve character recognition and provide you with a personalized user dictionary and text completion suggestions. Some of this data is stored on your device and some is sent to Microsoft to help improve these services.

Is it possible that any collected words may accidentally include patient information?

 

Computer Configuration > Administrative Templates > Windows Components > OneDrive > Prevent the usage of OneDrive for file storage – Enabled

 

Computer Configuration > Administrative Templates > Windows Components > Search> Don’t search the web or display web results in Search – Enabled

 

Computer Configuration > Administrative Templates > Windows Components > Search> Don’t search the web or display web results in Search over metered connections– Enabled

Why might you want to disable web search?  It is a good idea if you don’t want your local search queries sent to Bing.

Computer Configuration> Administrative Templates> System> User Profiles> Turn off the advertising ID

Turn off the advertising ID to disable targeted ads –  Enabled

Computer Configuration > Administrative Templates > Windows Components > Store >Disable all apps from Windows Store.
You can turn off the ability to launch apps from the Windows Store that were preinstalled or downloaded. This will also turn off automatic app updates, and the Windows Store will be disabled. On Windows Server 2016, this will block Windows Store calls from Universal Windows Apps.

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

Tags: , , ,

 
0

Activating Windows 10 – Office 2016 Windows Srv 2012R2 DataCtr/Std KMS for Windows 10

Posted by paris on Jun 22, 2016 in Random

kms[1]

A client recently wanted to Add Windows 10 Activation to his KMS Server , you need this https://support.microsoft.com/en-us/kb/3086418

Proves you need some Windows Updates as well as a “Windows Srv 2012R2 DataCtr/Std KMS for Windows 10” Key

The update just downloads a file and extracts a pkeyconfig-csvlk.xrm-ms to C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\VAMT3\pkconfig  if the windows update doesn’t work for you. You will need to reopen the VAMT3.1 app after adding this file

It seems you need to call VLSC  ( https://www.microsoft.com/licensing/servicecenter/Help/Contact.aspx ) Services to get this key added to your portal as they don’t release it online

Option 4 , then 2 

You will need to give them your agreement number ( Login online and go to Administration , My Permissions ) and Read out the Agreement Number ( Started with V )  under Licensing ID

However I was only being given Windows Srv 2012R2 DataCtr/Std KMS after multiple calls

The “Windows Server 2012 R2 with Windows 10” KMS key is only displayed using the Microsoft Article above or on the phone but to get that key, you need to have an active Software Assurance for Windows Server 2012 R2.

It relies on Server Datacenter having SA. It’s a new Class C key.

The 2012 R2 Datacenter key (of the past) activated Windows 8.1 Enterprise but it wasn’t aware of Windows 10. This is a new Datacenter key that also activates Windows 10 Enterprise (and below).

 

How to Add Office 2016 Key to VAMT 3.1

Download from VLSC “SW_DVD5_Office_Professional_Plus_2016_W32_English_-2_KMS_MLF_X20-96058.iso”

Mount or Extract the ISO

Run kms_host.vbs in command prompt as admin , however this doesn’t work

Copy from Win8 folder pkeyconfig-office-kmshost.xrm-ms to C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\VAMT3\pkconfig 

Once done , restart VAMT and try adding the key as well

 

—————————————— How to increase the KMS count to 25

As an easier alternative, we advice using the following script that allows to increase the activations count on the KMS server. Install the necessary version of the OS (in this example, it is Windows 7 Professional), create an any directory and copy the following BAT file into it. Then in the same folder create two empty files named:

7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

Run increase_kms_count.bat:

@echo off
set skms=kmssrv1.woshub.com
for %%i in (. . . . . . . . . . . . . . . . . . . . . . . . . .) do call :Act %skms%
slmgr /ato
sc stop sppsvc
goto :end
:Act
sc stop sppsvc
xcopy "7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0" "%systemroot%\system32\*" /H /R /K /Y
xcopy "7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0" "%systemroot%\system32\*" /H /R /K /Y
sc start sppsvc
cscript "%systemroot%\system32\slmgr.vbs" /skms %1
cscript "%systemroot%\system32\slmgr.vbs" /ipk FJ82H-XT6CR-J8D7P-XQJJ2-GPDD4
cscript "%systemroot%\system32\slmgr.vbs" /ato
sc stop sppsvc
:end

kms1.woshub.com is a DNS name or an IP address of your KMS server.

The number of dots in the line 3 is the necessary amount of requests to the KMS server (in this example, we drive up to 25 requests)

After the script is executed, check the KMS count:

1
slmgr –dlv

or you can try the app https://forums.mydigitallife.info/threads/39665-KMS-Client-Emulator-for-Increasing-KMS-Server-Client-Count

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: -1 (from 1 vote)

Tags: , , , , , , , , ,

 
0

Block Group Policy to Stop Windows 10 Installing from Windows Updates

Posted by paris on May 25, 2016 in Random

Create a Group Policy ( Software Restriction Policy ) to block .exe’s running from this location

 C:\Windows\system32\gwx\

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

Tags: , , ,

 
0

Windows 10 crashes explorer opening images

Posted by paris on Apr 26, 2016 in Fixes

blue-wallpaper_windows_10_hd_2880x1800[1]Had a user that could not open .jpg’s , and when she did it would crash explorer.exe. Trying to change the default programs did not work , and the open with right click in explorer would not display.

Checking Event viewer I had the below

svchost (2148) TILEREPOSITORYS-1-5-21-2633014675-3390063305-1885502253-1001: An attempt to move the file “C:\Users\%username%\AppData\Local\TileDataLayer\Database\EDB.log” to “C:\Users\%username%\AppData\Local\TileDataLayer\Database\EDB0000A.log” failed with system error 183 (0x000000b7): “Cannot create a file when that file already exists. “. The move file operation will fail with error -1022 (0xfffffc02).

I just renamed \AppData\Local\TileDataLayer\Database Folder to \AppData\Local\TileDataLayer\Database.old in Windows and restarted explorer.exe which created a new one straight away , and fixed the issue

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

Tags: , , ,

 
0

WIndows 10 Clients dropping network shares to 2008 Server ( Samba/SMB 2 )

Posted by paris on Nov 30, 2015 in Fixes

Windows 10Recently we had a problem where network shares were dropping in and out on some windows 10 machines. We used pings to make sure network connectivity was not to blame which it wasn’t ( no pings dropped ) some people online where complaining about having to roll back drivers for network cards to older versions

I have seen this on Vista before , so we forced it to use a lower version of Samba : 

To access said setting go to the control panel in Windows 10 (or 7), in Category view click on the text “System and Security”, then click on the text “Administrative Tools”.

Now double click and open “Local Security Policy”.

In the Local Security Policy screen on the left navigation tree, expand the “Local Policies –> Security Options” then about 2/3rd’s the way down the list you’ll see a Policy called “Network Security: LAN Manager authentication level”. Double click and change the setting to be “Send LM & NTLM – use NTLMv2 session security if negotiated.”

Then just press OK and close all of the open windows and then try again

 

n the case of Windows 10 Home, Local Security Policy does not exist; therefore make the change in the registry (use regedit).
 
HKEY_LOCAL_MACHINE\System\CurrentControlSet\control\LSA
Add:
LMCompatibilityLevel
Value Type: REG_DWORD – Number (32 bit, hexadecimal)
Valid Range 0-5
Default: 0, Set to 1 (Use NTLMv2 session security if negotiated)
Description: This parameter specifies the type of authentication to be used.

 

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

Tags: , , , , , ,

Copyright © 2017 Welcome to Pariswells.com All rights reserved. Theme by Laptop Geek. Privacy Policy