Posts Tagged ‘Windows 10’


UEFI requires USB media to be in FAT32 format, which has a 4GB file size limitation. The install.wim file for Server 2012R2 is about 4.5GB, so needs to be split up as follows:


Step 1. Split install.wim image

  • Extract ISO contents, go to the Sources folder and locate the install.wim file
  • Copy the file to a separate folder (e.g. C:\Temp)
  • Open a Powershell window with admin rights and browse to this newly created folder
  • Run the following command:

Dism /Split-Image /ImageFile:install.wim /SWMFile:install.swm /FileSize:4000

This will create two files: install.swm and install2.swm

  • Copy these two files to the Sources folder and delete the install.wim file


Step 2. Format USB key

  • Run cmd



> SELECT DISK (pick appropriate disk)








  • Copy all the folders from extracted ISO into the USB stick. Now you should be able to boot and install Windows from it
VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

User’s in an environment had their Recycle Bin redirected , however whenever you tried to delete large items for the users remotely it would not let you and the size of the folder / file would show as 0KB

This is obiously a change in Windows 10 / Server 2012 how it stores these files as in Windows 7 / 2008 R2 you could delete selectged items

The work around is to delete the whole $recycle.bin Redirected Folder and this will get recreated next time the user deletes something.

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

A windows update to Windows 10 has stopped the Camera on a x360 HP laptop working on Windows Hello ( Camera Login ) however the camera works for everything else

HP has released a driver update which fixes this problem , which you can download from below

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

There is a big list by Microsoft I went through – , Microsoft also provides a DISA STIG Baseline ( here )  however I have gone a bit further on security

Computer Configuration – Administrative Templates – Windows Components – Data Collection and Preview Builds

Disable access to pre-release features – Disabled

Configure telemetry to level 0 – Enterprise Only

Do not show feedback notifications – Enabled

Toggle user control over Insider builds – Disabled


Computer Configuration – Administrative Templates – System – Log on

                Show first sign-in animation – Disable

                Turn on convenience PIN sign-in – Diable

Turn off picture password sign-in -Enable


Computer Configuration – Administrative Templates – Windows Components – Search –

Allow Cortana – Disabled


Computer Configuration – Administrative Templates – Windows Components – Cloud Content

                Do Not Show Windows Tips – Enabled

                Turn off Microsoft Consumer Experiences – Enabled


Computer Configuration – Administrative Templates – Control Panel

                Do not display the lock screen – Enabled


Computer Configuration – Windows Settings – Security Settings – Local Policies – Security Options     

                Accounts: Block Microsoft Accounts – Enabled From Longon and Adding


Computer Configuration\Administrative Templates\Network\WLAN Service\WLAN Settings\

Allow Windows to automatically connect to suggested open hotspots, to networks shared by contacts, and to hotspots offering paid services – Disabled 


Computer Configuration\ Administrative Templates\ Control Panel\ Regional and Language Options\ Allow Input Personalization and set to Disabled.

We also collect your typed and handwritten words to improve character recognition and provide you with a personalized user dictionary and text completion suggestions. Some of this data is stored on your device and some is sent to Microsoft to help improve these services.

Is it possible that any collected words may accidentally include patient information?


Computer Configuration > Administrative Templates > Windows Components > OneDrive > Prevent the usage of OneDrive for file storage – Enabled


Computer Configuration > Administrative Templates > Windows Components > Search> Don’t search the web or display web results in Search – Enabled


Computer Configuration > Administrative Templates > Windows Components > Search> Don’t search the web or display web results in Search over metered connections– Enabled

Why might you want to disable web search?  It is a good idea if you don’t want your local search queries sent to Bing.

Computer Configuration> Administrative Templates> System> User Profiles> Turn off the advertising ID

Turn off the advertising ID to disable targeted ads –  Enabled

Computer Configuration > Administrative Templates > Windows Components > Store >Disable all apps from Windows Store.
You can turn off the ability to launch apps from the Windows Store that were preinstalled or downloaded. This will also turn off automatic app updates, and the Windows Store will be disabled. On Windows Server 2016, this will block Windows Store calls from Universal Windows Apps.

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)


A client recently wanted to Add Windows 10 Activation to his KMS Server , you need this

Proves you need some Windows Updates as well as a “Windows Srv 2012R2 DataCtr/Std KMS for Windows 10” Key

The update just downloads a file and extracts a pkeyconfig-csvlk.xrm-ms to C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\VAMT3\pkconfig  if the windows update doesn’t work for you. You will need to reopen the VAMT3.1 app after adding this file

It seems you need to call VLSC  ( ) Services to get this key added to your portal as they don’t release it online

Option 4 , then 2 

You will need to give them your agreement number ( Login online and go to Administration , My Permissions ) and Read out the Agreement Number ( Started with V )  under Licensing ID

However I was only being given Windows Srv 2012R2 DataCtr/Std KMS after multiple calls

The “Windows Server 2012 R2 with Windows 10” KMS key is only displayed using the Microsoft Article above or on the phone but to get that key, you need to have an active Software Assurance for Windows Server 2012 R2.

It relies on Server Datacenter having SA. It’s a new Class C key.

The 2012 R2 Datacenter key (of the past) activated Windows 8.1 Enterprise but it wasn’t aware of Windows 10. This is a new Datacenter key that also activates Windows 10 Enterprise (and below).


How to Add Office 2016 Key to VAMT 3.1

Download from VLSC “SW_DVD5_Office_Professional_Plus_2016_W32_English_-2_KMS_MLF_X20-96058.iso”

Mount or Extract the ISO

Run kms_host.vbs in command prompt as admin , however this doesn’t work

Copy from Win8 folder pkeyconfig-office-kmshost.xrm-ms to C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\VAMT3\pkconfig 

Once done , restart VAMT and try adding the key as well


—————————————— How to increase the KMS count to 25

As an easier alternative, we advice using the following script that allows to increase the activations count on the KMS server. Install the necessary version of the OS (in this example, it is Windows 7 Professional), create an any directory and copy the following BAT file into it. Then in the same folder create two empty files named:


Run increase_kms_count.bat:

@echo off
for %%i in (. . . . . . . . . . . . . . . . . . . . . . . . . .) do call :Act %skms%
slmgr /ato
sc stop sppsvc
goto :end
sc stop sppsvc
xcopy "7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0" "%systemroot%\system32\*" /H /R /K /Y
xcopy "7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0" "%systemroot%\system32\*" /H /R /K /Y
sc start sppsvc
cscript "%systemroot%\system32\slmgr.vbs" /skms %1
cscript "%systemroot%\system32\slmgr.vbs" /ipk FJ82H-XT6CR-J8D7P-XQJJ2-GPDD4
cscript "%systemroot%\system32\slmgr.vbs" /ato
sc stop sppsvc
:end is a DNS name or an IP address of your KMS server.

The number of dots in the line 3 is the necessary amount of requests to the KMS server (in this example, we drive up to 25 requests)

After the script is executed, check the KMS count:

slmgr –dlv

or you can try the app

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: -1 (from 1 vote)

blue-wallpaper_windows_10_hd_2880x1800[1]Had a user that could not open .jpg’s , and when she did it would crash explorer.exe. Trying to change the default programs did not work , and the open with right click in explorer would not display.

Checking Event viewer I had the below

svchost (2148) TILEREPOSITORYS-1-5-21-2633014675-3390063305-1885502253-1001: An attempt to move the file “C:\Users\%username%\AppData\Local\TileDataLayer\Database\EDB.log” to “C:\Users\%username%\AppData\Local\TileDataLayer\Database\EDB0000A.log” failed with system error 183 (0x000000b7): “Cannot create a file when that file already exists. “. The move file operation will fail with error -1022 (0xfffffc02).

I just renamed \AppData\Local\TileDataLayer\Database Folder to \AppData\Local\TileDataLayer\Database.old in Windows and restarted explorer.exe which created a new one straight away , and fixed the issue

VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)

Windows 10Recently we had a problem where network shares were dropping in and out on some windows 10 machines. We used pings to make sure network connectivity was not to blame which it wasn’t ( no pings dropped ) some people online where complaining about having to roll back drivers for network cards to older versions

I have seen this on Vista before , so we forced it to use a lower version of Samba : 

To access said setting go to the control panel in Windows 10 (or 7), in Category view click on the text “System and Security”, then click on the text “Administrative Tools”.

Now double click and open “Local Security Policy”.

In the Local Security Policy screen on the left navigation tree, expand the “Local Policies –> Security Options” then about 2/3rd’s the way down the list you’ll see a Policy called “Network Security: LAN Manager authentication level”. Double click and change the setting to be “Send LM & NTLM – use NTLMv2 session security if negotiated.”

Then just press OK and close all of the open windows and then try again


n the case of Windows 10 Home, Local Security Policy does not exist; therefore make the change in the registry (use regedit).
Value Type: REG_DWORD – Number (32 bit, hexadecimal)
Valid Range 0-5
Default: 0, Set to 1 (Use NTLMv2 session security if negotiated)
Description: This parameter specifies the type of authentication to be used.


VN:F [1.9.22_1171]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.22_1171]
Rating: 0 (from 0 votes)