As was foretold, we've added advertisements to the forums! If you have questions, or if you encounter any bugs, please visit this thread: https://forums.penny-arcade.com/discussion/240191/forum-advertisement-faq-and-reports-thread/
Options

[SYSTEMS ADMINS & IT MONKEYS] TrackPoint is trademarked. Call it a clit mouse instead.

16263656768101

Posts

  • Options
    lwt1973lwt1973 King of Thieves SyndicationRegistered User regular
    I have a user who encrypted a file on the 2003 file server using a Windows XP box some time ago with no issues. Now the user can't gain access to the file at all. I tried having the original XP box log in, I tried having the admin log in, I tried copying the file, I tried changing the properties, I tried having the user login to the file server.

    So, any thoughts on how to decrypt it?

    "He's sulking in his tent like Achilles! It's the Iliad?...from Homer?! READ A BOOK!!" -Handy
  • Options
    TL DRTL DR Not at all confident in his reflexive opinions of thingsRegistered User regular
    lwt1973 wrote: »
    I have a user who encrypted a file on the 2003 file server using a Windows XP box some time ago with no issues. Now the user can't gain access to the file at all. I tried having the original XP box log in, I tried having the admin log in, I tried copying the file, I tried changing the properties, I tried having the user login to the file server.

    So, any thoughts on how to decrypt it?

    Look at the security properties and see if you can take Ownership with the admin account. I guess from his workstation, though I don't have experience with XP file encryption.

  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    Also try http://ss64.com/nt/cacls.html in Cmd prompt.

  • Options
    lwt1973lwt1973 King of Thieves SyndicationRegistered User regular
    urahonky wrote: »
    Also try http://ss64.com/nt/cacls.html in Cmd prompt.

    No go on either of these. I can grab ownership but it's still access denied when trying to do anything with it.

    "He's sulking in his tent like Achilles! It's the Iliad?...from Homer?! READ A BOOK!!" -Handy
  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    What kind of file?

  • Options
    lwt1973lwt1973 King of Thieves SyndicationRegistered User regular
    urahonky wrote: »
    What kind of file?

    Excel. He wanted a password file so decided to create an Excel file on the file server and then encrypt it using the Windows XP built-in encryption. He moved machines about 6 months ago without having an issue and then a week ago started having the access denied error but told me today about it.

    "He's sulking in his tent like Achilles! It's the Iliad?...from Homer?! READ A BOOK!!" -Handy
  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    Does it get to a point where you can enter a password, or is it just access denied the moment you double click it?

  • Options
    lwt1973lwt1973 King of Thieves SyndicationRegistered User regular
    Double click on it. Microsoft swung and missed, giving up and saying to go third party on it.

    "He's sulking in his tent like Achilles! It's the Iliad?...from Homer?! READ A BOOK!!" -Handy
  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    Jeeze, yeah I'm sorry I'm no help here. If it was just a password thing you could brute force your way in, but if you're not even able to access that's crazy.

  • Options
    ueanuean Registered User regular
    Well I lost my portable hard drive at a client site which had a nifty little security permissions/ownership script thingy I used to delete all sorts of weird crap I couldn't access. Of course this is of no help to you but if I find the stupid thing I'll send it over.

    Guys? Hay guys?
    PSN - sumowot
  • Options
    ueanuean Registered User regular
    TL DR wrote: »
    So there's an issue with out ESET clients; some of them lost connection to the server, are trying to update directly from ESET (and failing, since they don't have our current license info), and won't respond to updates.

    I have the registry edit here to change the server address, but it can't be edited while the ESET service is running and that service can't be stopped, disabled, or delayed.

    Is there a way to run the .reg file during startup or from safe mode or something, so I don't have to touch all of 30+ workstations today?

    Probably too late, but Computer startup GPO?

    Guys? Hay guys?
    PSN - sumowot
  • Options
    TL DRTL DR Not at all confident in his reflexive opinions of thingsRegistered User regular
    Thanks, uean. We ended up using scripts to uninstall -reboot -reinstall.

  • Options
    SiliconStewSiliconStew Registered User regular
    edited May 2012
    lwt1973 wrote: »
    urahonky wrote: »
    What kind of file?

    Excel. He wanted a password file so decided to create an Excel file on the file server and then encrypt it using the Windows XP built-in encryption. He moved machines about 6 months ago without having an issue and then a week ago started having the access denied error but told me today about it.

    Was his password reset by admin last week? Does the certificate listed under Properties->Advanced->Details match the user and does it still exist on his machine? Does it list a recovery agent cert in the same place?

    SiliconStew on
    Just remember that half the people you meet are below average intelligence.
  • Options
    lwt1973lwt1973 King of Thieves SyndicationRegistered User regular
    lwt1973 wrote: »
    urahonky wrote: »
    What kind of file?

    Excel. He wanted a password file so decided to create an Excel file on the file server and then encrypt it using the Windows XP built-in encryption. He moved machines about 6 months ago without having an issue and then a week ago started having the access denied error but told me today about it.

    Was his password reset by admin last week? Does the certificate listed under Properties->Advanced->Details match the user and does it still exist on his machine? Does it list a recovery agent cert in the same place?

    The certificate vanished for some reason. Microsoft couldn't find it and the default recovery agent isn't turned on by default in 2003 or higher domains. So, it's encrypted without a key and now he'll have to recover the passwords by contacting all the places.

    "He's sulking in his tent like Achilles! It's the Iliad?...from Homer?! READ A BOOK!!" -Handy
  • Options
    mrt144mrt144 King of the Numbernames Registered User regular
    lwt1973 wrote: »
    lwt1973 wrote: »
    urahonky wrote: »
    What kind of file?

    Excel. He wanted a password file so decided to create an Excel file on the file server and then encrypt it using the Windows XP built-in encryption. He moved machines about 6 months ago without having an issue and then a week ago started having the access denied error but told me today about it.

    Was his password reset by admin last week? Does the certificate listed under Properties->Advanced->Details match the user and does it still exist on his machine? Does it list a recovery agent cert in the same place?

    The certificate vanished for some reason. Microsoft couldn't find it and the default recovery agent isn't turned on by default in 2003 or higher domains. So, it's encrypted without a key and now he'll have to recover the passwords by contacting all the places.

    Wah wah wah waaaaaaaaaaaaah.

  • Options
    ThanatosThanatos Registered User regular
    edited May 2012
    God.

    God fucking dammit.

    So, I have a report that lists file numbers, and what boxes those files are in. I have to go through and put file names and associated staff to the file numbers by hand. The report also takes about four or five hours worth of formatting before I can even do this. I have spent about six or seven hours putting names to file numbers (about halfway through). And I just noticed that the box numbers aren't lining up with file numbers.

    So, at some point, I think I may have accidentally sorted one column without sorting the other.

    In addition, some files are associated with multiple staff members, so I have to create a duplicate entry for each time that file appears in any box, one for each staff member.

    Is there any sort of VLookup I can write that will fill in the information I've done so far? Or am I, like I suspect, completely fucked?

    Edit: Here's an example of my data, just to make it a bit clearer:

    Capture-2.jpg

    Thanatos on
  • Options
    lwt1973lwt1973 King of Thieves SyndicationRegistered User regular
    edited May 2012
    5 freaking CMOS batteries dying on our handheld computers.

    I mean really?

    And Amazon sends 3 inch usb extenders instead of 3 feet. I double check the item description and it's 3 feet.

    lwt1973 on
    "He's sulking in his tent like Achilles! It's the Iliad?...from Homer?! READ A BOOK!!" -Handy
  • Options
    SiliconStewSiliconStew Registered User regular
    Thanatos wrote: »
    God.

    God fucking dammit.

    So, I have a report that lists file numbers, and what boxes those files are in. I have to go through and put file names and associated staff to the file numbers by hand. The report also takes about four or five hours worth of formatting before I can even do this. I have spent about six or seven hours putting names to file numbers (about halfway through). And I just noticed that the box numbers aren't lining up with file numbers.

    So, at some point, I think I may have accidentally sorted one column without sorting the other.

    In addition, some files are associated with multiple staff members, so I have to create a duplicate entry for each time that file appears in any box, one for each staff member.

    Is there any sort of VLookup I can write that will fill in the information I've done so far? Or am I, like I suspect, completely fucked?

    Edit: Here's an example of my data, just to make it a bit clearer:

    Capture-2.jpg

    Assuming a 1:1 match between file numbers and box numbers, and that your file numbers/file name/staff columns are still correctly lined up:

    Create a new sheet with the file numbers in the first column, matching box numbers in the second column. Set E3 on the original sheet to "=vlookup(B3,Sheet2!A:B,2,FALSE)" and fill down. Then do a copy and paste special (values) on the E column so you don't recalc every time you change something. You can do this directly over the A column if you want, but I don't want you to lose anything.

    Just remember that half the people you meet are below average intelligence.
  • Options
    ThanatosThanatos Registered User regular
    Thanatos wrote: »
    God.

    God fucking dammit.

    So, I have a report that lists file numbers, and what boxes those files are in. I have to go through and put file names and associated staff to the file numbers by hand. The report also takes about four or five hours worth of formatting before I can even do this. I have spent about six or seven hours putting names to file numbers (about halfway through). And I just noticed that the box numbers aren't lining up with file numbers.

    So, at some point, I think I may have accidentally sorted one column without sorting the other.

    In addition, some files are associated with multiple staff members, so I have to create a duplicate entry for each time that file appears in any box, one for each staff member.

    Is there any sort of VLookup I can write that will fill in the information I've done so far? Or am I, like I suspect, completely fucked?

    Edit: Here's an example of my data, just to make it a bit clearer:

    Capture-2.jpg

    Assuming a 1:1 match between file numbers and box numbers, and that your file numbers/file name/staff columns are still correctly lined up:

    Create a new sheet with the file numbers in the first column, matching box numbers in the second column. Set E3 on the original sheet to "=vlookup(B3,Sheet2!A:B,2,FALSE)" and fill down. Then do a copy and paste special (values) on the E column so you don't recalc every time you change something. You can do this directly over the A column if you want, but I don't want you to lose anything.
    What do you mean by "a 1:1 match?" Some files are in multiple boxes, most boxes hold multiple files, and there is a file/box combination entry for each staff member on files with multiple staff on them.

  • Options
    SiliconStewSiliconStew Registered User regular
    edited May 2012
    Thanatos wrote: »
    Some files are in multiple boxes

    Then you can't match a file to a box and can't use vlookup.

    SiliconStew on
    Just remember that half the people you meet are below average intelligence.
  • Options
    ThanatosThanatos Registered User regular
    Thanatos wrote: »
    Some files are in multiple boxes
    Then you can't match a file to a box and can't use vlookup.
    Yeah, that's what I figured. God dammit.

    Feral gave me another option I'm gonna try, and I ordered a copy of Access 2010 that I'm gonna use for this instead of fucking Excel from now on.

  • Options
    ueanuean Registered User regular
    edited May 2012
    Thanatos wrote: »
    God.

    God fucking dammit.

    So, I have a report that lists file numbers, and what boxes those files are in. I have to go through and put file names and associated staff to the file numbers by hand. The report also takes about four or five hours worth of formatting before I can even do this. I have spent about six or seven hours putting names to file numbers (about halfway through). And I just noticed that the box numbers aren't lining up with file numbers.

    So, at some point, I think I may have accidentally sorted one column without sorting the other.

    In addition, some files are associated with multiple staff members, so I have to create a duplicate entry for each time that file appears in any box, one for each staff member.

    Is there any sort of VLookup I can write that will fill in the information I've done so far? Or am I, like I suspect, completely fucked?

    Edit: Here's an example of my data, just to make it a bit clearer:

    Capture-2.jpg

    Assuming a 1:1 match between file numbers and box numbers, and that your file numbers/file name/staff columns are still correctly lined up:

    Create a new sheet with the file numbers in the first column, matching box numbers in the second column. Set E3 on the original sheet to "=vlookup(B3,Sheet2!A:B,2,FALSE)" and fill down. Then do a copy and paste special (values) on the E column so you don't recalc every time you change something. You can do this directly over the A column if you want, but I don't want you to lose anything.

    Instead of copy/paste values to prevent recalculating, just turn off Auto Recalculating (its in Excel options somewhere). Then use F9 to recalculate the workbook, or shift-F9 to recalculate the current worksheet. Why? Because vlookups are FAST (unlike any sort of indexing or array formula) and you can very quickly reassign staff to files in the base list without having to do everything over again by keeping the formulas in place.

    Also yeah what Thanatos said. Excel was basically built so you never have to manually type anything in apart from the base data. Vlookup/hlookup was built for what you're doing. Sorry to hear you had to spend so many hours before hearing that :(

    uean on
    Guys? Hay guys?
    PSN - sumowot
  • Options
    ghost_master2000ghost_master2000 Registered User regular
    edited May 2012
    I posted a response to something regarding this in the programming thread, but does anybody else abhor the term "the cloud"?

    ghost_master2000 on
  • Options
    SentretSentret Registered User regular
    I don't hate it as a term for 'we put your stuff on random servers hosted somewhere cheap', but I am getting tired of the cloud being in every single damn sales pitch.

    A subset of recent sales calls: Cloud vpn, cloud ip phones, cloud storage, cloud email, cloud crm, cloud inventory, cloud asset tracking, cloud ticketing, cloud server monitoring, cloud based monitoring of other cloud services.

    I wouldn't be half surprised if the next can of spray air I bought came with 'Cloud Based!' on the label.

  • Options
    ghost_master2000ghost_master2000 Registered User regular
    Sentret wrote: »
    I don't hate it as a term for 'we put your stuff on random servers hosted somewhere cheap', but I am getting tired of the cloud being in every single damn sales pitch.

    A subset of recent sales calls: Cloud vpn, cloud ip phones, cloud storage, cloud email, cloud crm, cloud inventory, cloud asset tracking, cloud ticketing, cloud server monitoring, cloud based monitoring of other cloud services.

    I wouldn't be half surprised if the next can of spray air I bought came with 'Cloud Based!' on the label.

    Yeah that's the main reason I hate it. They're trying to do everything with the cloud, and no I will not trust every aspect of my computer operations to a remote server I don't have full control over... What's so hard to understand about that? I swear, half of these sales people don't even know what "the cloud" fucking means. O_o

  • Options
    Mr_RoseMr_Rose 83 Blue Ridge Protects the Holy Registered User regular
    Uh, they're sales people; actually knowing what theyre talking about is a hindrance* in their line of work. Or they wouldn't need engineers to come along on sales pitches.


    *from my personal experience, anyway.

    ...because dragons are AWESOME! That's why.
    Nintendo Network ID: AzraelRose
    DropBox invite link - get 500MB extra free.
  • Options
    itzerokewlitzerokewl Registered User regular
    I agree, it does seem that most sales guys have begun to add "cloud" to their ever growing list of buzzword bingo words. At my previous job my boss and I (2 man IT shop) actually had our CFO (who was over IT) sit us down and ask us straight faced, "So when are we going to turn our cloud on." Words escaped us.

    signature.png
  • Options
    DjeetDjeet Registered User regular
    Being involved in a lot more demos and POCs as a sales engineer I like the term. When I hear "cloud" being dropped then I know I can tune out and check my email while a sales/marketing guy handles stuff, confident that it's BS and when it goes technical I can say "could you repeat that?". No one discusses clouds in the meetings where I'm struggling to keep up.

  • Options
    bowenbowen How you doin'? Registered User regular
    edited May 2012
    Wrangling with MSE because it UNinstalled itself sure is fun.

    Had to freaking boot into safe mode and run their windows onlive uninstall bullshit in order to reinstall it because some update to .NET uninstalled it and left shit all over. And their error code was unhelpful too. Everything on the web was like "oh you're infected!" and it's like I use my computer to play vidja games I don't even get on the web or check email. So, no, well, guess I was right god damnit.

    (it uninstalled itself not installed itself)

    bowen on
    not a doctor, not a lawyer, examples I use may not be fully researched so don't take out of context plz, don't @ me
  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    Ugh upgraded one of our user's printers from an inkjet to laser. Big mistake.

    He prints roughly 400 pages a week so we were replacing the ink cartridge weekly. But since putting this laser printer in I've received a half a dozen emails with "problems" with it. I shouldn't have tinkered with the support beams.

  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    Before: "Yeah I don't need to print in color."

    *company buys monochrome Samsung printer*

    Now: "Oh it doesn't do color? I print off a lot of color envelopes."

    Ugh now I remember why I got out of the IT world.

  • Options
    bowenbowen How you doin'? Registered User regular
    ... print off a lot of color envelopes ...

    What is that even?

    not a doctor, not a lawyer, examples I use may not be fully researched so don't take out of context plz, don't @ me
  • Options
    mrt144mrt144 King of the Numbernames Registered User regular
    itzerokewl wrote: »
    I agree, it does seem that most sales guys have begun to add "cloud" to their ever growing list of buzzword bingo words. At my previous job my boss and I (2 man IT shop) actually had our CFO (who was over IT) sit us down and ask us straight faced, "So when are we going to turn our cloud on." Words escaped us.

    We're a similar structure but our CFO has been razzed enough times about her lack of technical aptitude so that she doesn't dare mention sizzle words.

  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    bowen wrote: »
    ... print off a lot of color envelopes ...

    What is that even?

    He needs color printing because our logo on the envelope is supposed to be blue, but since it's monochrome it's black.

  • Options
    bowenbowen How you doin'? Registered User regular
    Seems like you'd benefit from branded envelops.

    It'd be far cheaper than inkjet/laserjet printed color envelops, that's for sure.

    not a doctor, not a lawyer, examples I use may not be fully researched so don't take out of context plz, don't @ me
  • Options
    urahonkyurahonky Resident FF7R hater Registered User regular
    bowen wrote: »
    Seems like you'd benefit from branded envelops.

    It'd be far cheaper than inkjet/laserjet printed color envelops, that's for sure.

    Yeah then use a sticker for the address in which you can print onto.

  • Options
    ueanuean Registered User regular
    edited May 2012
    Ok, I can't get this logon script to fire.

    Here's what's going on. Have a client and the way the computers and users are setup, printer mapping makes way more sense to happen by general location. I've created different OUs in active directory for each location, and slotted all domain machines nito the proper OU. Then I created a new GPO and have linked it to the OUs:
    Set objSysInfo = CreateObject("ADSystemInfo")
    strName = objSysInfo.ComputerName
    
    arrComputerName = Split(strName, ",")
    arrOU = Split(arrComputerName(1), "=")
    strComputerOU = arrOU(1)
    
    Set objNetwork = CreateObject("WScript.Network")
    
    Set WshNetwork = WScript.CreateObject("WScript.Network")
    Set Printers = WshNetwork.EnumPrinterConnections
    For i = 0 to Printers.Count - 1 Step 2
        If Left(ucase(Printers.Item(i+1)),2) = "\\" Then
    	'WScript.Echo Printers.Item(i+1)
            WSHNetwork.RemovePrinterConnection Printers.Item(i+1)
        End IF
    Next
    
    Select Case strComputerOU
        Case "Resource Centre - Clients"
            objNetwork.AddWindowsPrinterConnection "\\srv\HP4250"
            objNetwork.SetDefaultPrinter "\\srv\HP4250"
        Case "Resource Centre - Staff"
            objNetwork.AddWindowsPrinterConnection "\\srv\RICOH2075"
    	objNetwork.AddWindowsPrinterConnection "\\srv\HP4250"
    	objNetwork.AddWindowsPrinterConnection "\\srv\Lexmark e332n Hallway"
            objNetwork.SetDefaultPrinter "\\srv\RICOH2075"
        Case "Shared Lab"
    	'This location does not get any printers mapped!
        Case "testingarea"
    	objNetwork.AddWindowsPrinterConnection "\\srv\RICOH2075"
    	objNetwork.AddWindowsPrinterConnection "\\srv\HP4250"
    	objNetwork.AddWindowsPrinterConnection "\\srv\Lexmark e332n Hallway"
            objNetwork.SetDefaultPrinter "\\srv\RICOH2075"	
        Case "Upper Floor"
            objNetwork.AddWindowsPrinterConnection "\\srv\Xerox3300MFP"
            objNetwork.SetDefaultPrinter "\\srv\Xerox3300MFP"
        Case "Settlement"
            objNetwork.AddWindowsPrinterConnection "\\srv\Lexmark x642e"
            objNetwork.SetDefaultPrinter "\\srv\Lexmark x642e"
        Case Else
    	WScript.Echo strName,": <-- Please contact theuean with this message. No printers mapped. Machine needs to be moved to a supported AD OU."
    End Select
    

    I've put a machine into the testingarea OU. If I run the script from that machine's desktop, it fires, deletes the current printer connections, and maps the printers I want flawlessly.

    Ok so the script works. Now to get it to run when the machine starts.

    I create the GPO. GPO --> Computer Configuration --> Policies -> Windows Settings --> Startup. I copy the script into the proper GUID. Go back to the client and do gpupdate /force and the machine reboots but nothing happens. There is also nothing in the logs. So I check permissions - the GPO Scope is for Authenticated Users, but I added Everyone as well. Try again, does not fire. From the test desktop I can access the locatino of the script in the SYSVOL share, but just to be sure I add read and execite permissions to SYSVOL and all subdirectories. I can navigate all the way to the script itself and run it and it fires. But it doesn't fire when the machine boots.

    I then changed it to a user logon script, same everything above. Can navigate all the way to (\\srv\SYSVOL\domain.local\Policies\{GUID}\User\Scripts\Logon\ and execute the script and it fires, but it won't fire at login.

    I lastly tried referencing the script in the sysvol directory via UAC (so instead of the logon script being MyScript.vbs, it's now \\srv\SYSVOL\...\MyScript.vbs). Still no worky.

    So I'm stumped.

    Code above is a .vbs file. My only thoughts now are:

    .vbs files don't run from GPOs and I have to call it from a .bat
    I have to move the vbs to NETLOGON and call it from the individual user login scripts.

    But the point of this thing is that the script will fire per machine despite who logs on, so I want to avoid that, and keep it within group policy as other members of my company have a tendency to create a billion scripts and I know this printer connect script will fall away at some point.

    Ok. I barfed it all here. Someone help me. :)
    edit - I'm admittedly completely self-taught on all this stuff so please be kind if I have made an absolutely retarded mistake somewhere

    uean on
    Guys? Hay guys?
    PSN - sumowot
  • Options
    KrisKris Registered User regular
    edited May 2012
    uean wrote: »
    Ok, I can't get this logon script to fire.

    Here's what's going on. Have a client and the way the computers and users are setup, printer mapping makes way more sense to happen by general location. I've created different OUs in active directory for each location, and slotted all domain machines nito the proper OU. Then I created a new GPO and have linked it to the OUs:
    Set objSysInfo = CreateObject("ADSystemInfo")
    strName = objSysInfo.ComputerName
    
    arrComputerName = Split(strName, ",")
    arrOU = Split(arrComputerName(1), "=")
    strComputerOU = arrOU(1)
    
    Set objNetwork = CreateObject("WScript.Network")
    
    Set WshNetwork = WScript.CreateObject("WScript.Network")
    Set Printers = WshNetwork.EnumPrinterConnections
    For i = 0 to Printers.Count - 1 Step 2
        If Left(ucase(Printers.Item(i+1)),2) = "\\" Then
    	'WScript.Echo Printers.Item(i+1)
            WSHNetwork.RemovePrinterConnection Printers.Item(i+1)
        End IF
    Next
    
    Select Case strComputerOU
        Case "Resource Centre - Clients"
            objNetwork.AddWindowsPrinterConnection "\\srv\HP4250"
            objNetwork.SetDefaultPrinter "\\srv\HP4250"
        Case "Resource Centre - Staff"
            objNetwork.AddWindowsPrinterConnection "\\srv\RICOH2075"
    	objNetwork.AddWindowsPrinterConnection "\\srv\HP4250"
    	objNetwork.AddWindowsPrinterConnection "\\srv\Lexmark e332n Hallway"
            objNetwork.SetDefaultPrinter "\\srv\RICOH2075"
        Case "Shared Lab"
    	'This location does not get any printers mapped!
        Case "testingarea"
    	objNetwork.AddWindowsPrinterConnection "\\srv\RICOH2075"
    	objNetwork.AddWindowsPrinterConnection "\\srv\HP4250"
    	objNetwork.AddWindowsPrinterConnection "\\srv\Lexmark e332n Hallway"
            objNetwork.SetDefaultPrinter "\\srv\RICOH2075"	
        Case "Upper Floor"
            objNetwork.AddWindowsPrinterConnection "\\srv\Xerox3300MFP"
            objNetwork.SetDefaultPrinter "\\srv\Xerox3300MFP"
        Case "Settlement"
            objNetwork.AddWindowsPrinterConnection "\\srv\Lexmark x642e"
            objNetwork.SetDefaultPrinter "\\srv\Lexmark x642e"
        Case Else
    	WScript.Echo strName,": <-- Please contact theuean with this message. No printers mapped. Machine needs to be moved to a supported AD OU."
    End Select
    

    I've put a machine into the testingarea OU. If I run the script from that machine's desktop, it fires, deletes the current printer connections, and maps the printers I want flawlessly.

    Ok so the script works. Now to get it to run when the machine starts.

    I create the GPO. GPO --> Computer Configuration --> Policies -> Windows Settings --> Startup. I copy the script into the proper GUID. Go back to the client and do gpupdate /force and the machine reboots but nothing happens. There is also nothing in the logs. So I check permissions - the GPO Scope is for Authenticated Users, but I added Everyone as well. Try again, does not fire. From the test desktop I can access the locatino of the script in the SYSVOL share, but just to be sure I add read and execite permissions to SYSVOL and all subdirectories. I can navigate all the way to the script itself and run it and it fires. But it doesn't fire when the machine boots.

    I then changed it to a user logon script, same everything above. Can navigate all the way to (\\srv\SYSVOL\domain.local\Policies\{GUID}\User\Scripts\Logon\ and execute the script and it fires, but it won't fire at login.

    I lastly tried referencing the script in the sysvol directory via UAC (so instead of the logon script being MyScript.vbs, it's now \\srv\SYSVOL\...\MyScript.vbs). Still no worky.

    So I'm stumped.

    Code above is a .vbs file. My only thoughts now are:

    .vbs files don't run from GPOs and I have to call it from a .bat
    I have to move the vbs to NETLOGON and call it from the individual user login scripts.

    But the point of this thing is that the script will fire per machine despite who logs on, so I want to avoid that, and keep it within group policy as other members of my company have a tendency to create a billion scripts and I know this printer connect script will fall away at some point.

    Ok. I barfed it all here. Someone help me. :)
    edit - I'm admittedly completely self-taught on all this stuff so please be kind if I have made an absolutely retarded mistake somewhere

    From the sounds of it, you have to add your users to the OU's as well, not just the computer objects:

    http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/71105071-cfd1-49d9-8e9a-3f95a74b194b/

    http://www.petri.co.il/setting-up-logon-script-through-gpo-windows-server-2008.htm

    Kris on
  • Options
    ghost_master2000ghost_master2000 Registered User regular
    edited May 2012
    What is your domain functional level? If you are on a 2008 (edit: or 2003, see link below) domain you can use the Print Management snap-in in conjunction with GPOs that have a startup and logon script that calls pushprinterconnections.exe

    On the domain I manage I have a separate GPO for each location/department. Each GPO has a startup and logon script as described above. Each user and computer of that location/department is in the corresponding OU, and that OU has the GPO object mapped to it (for example one GPO might be named "Map Printers - Marketing".

    Once all the OUs and GPOs are set up you go to the Print Management snap-in and find the printer you want to map, select it, then choose the option "deploy with group policy." you then select the GPO you want to tie it to, and check boxes of whether you want to deploy by user, or computer, or both.

    edit: looks like this works in 2003 as well.

    I do it for both users and computers, that way no matter where a marketing user logs in, they can still print to their big ass marketing printer, and no matter who logs in to a marketing computer they can print to a printer nearby. There are some exceptions, like the large format printer. I don't want someone printing their excel spreadsheet on a 40"x120" canvas.

    ghost_master2000 on
  • Options
    ueanuean Registered User regular
    edited May 2012
    I made a bit of progress with it. (2008 R2 by the way). With the Group Policy Modelling wizard I could see that the GPO wasn't even being referenced. I ticked Block Inheritance and it popped up. Then I unchecked block inheritance, and tested with Loopback (Merge) processing, which also worked, so I added Loopback processing into the Logon script GPO. According to the wizard it should fire, but still doesn't.

    It will be a bit messy to move the users into the same OU. I guess I could do it, but there are 8 sites and for consistency sake I'd rather not get away from the convention of computers and users in seperate OUs.

    I've not had much success with the Print Management snap-in either. But I might futz around withit more. I've just been intimidated with the PushPrinterConnections.exe as... I haven't found any good documentation on how to get it going. (like, where the heck do I find this .exe?)

    edit - just read that article about VBS and users in the same OU as machines. I'll test and see if it works or not. Hopefully it does, but hopefully it doesn't because that'll mean a bunch of meetings about AD structure blagh...

    uean on
    Guys? Hay guys?
    PSN - sumowot
This discussion has been closed.