Re: [NTSysADM] Update on the broken DFSR issue

2016-11-17 Thread Kurt Buff
Ye gods and little fishes What a c* f***. That's certainly one of the strangest stories I've heard in this industry in a while. My deepest sympathies for you, though I suspect your wallet won't be hurt out of all of this. It won't be, if there's any justice in this world. Kurt On

[NTSysADM] Update on the updated broken DFSR issue

2016-11-17 Thread Webster
Microsoft can't fix it. They wanted to uninstall McAfee because they said it may be causing issues. Customer said no. MS said nothing else we can do then. Customer thought they could just dcpromo down the last DC, bring up a new AD with the same name as the old and be back in business. Nope,

Re: [NTSysADM] Update on the broken DFSR issue

2016-11-17 Thread Andrew S. Baker
So much process to get the right stuff in place, but for vetting crazy restore policies?  Not so much process…   Sigh. Regards, ASB http://XeeMe.com/AndrewBaker Providing Expert Technology Consulting Services for the SMB market… GPG:860D 40A1 4DA5 3AE1 B052 8F9F 07A1 F9D6 A549 8842

[NTSysADM] RE: How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread James Rankin
I don't mind, I do my best work under the influence :) 322 pages of notes is quite heavy though. I just dump everything into OneNote - to the extent I now need to start a project to rationalize the file :-0 From: listsad...@lists.myitforum.com [mailto:listsad...@lists.myitforum.com] On Behalf

RE: [NTSysADM] Update on the broken DFSR issue

2016-11-17 Thread Webster
Yep, they are in a "highly secure" industry with federal oversight. When I proposed adding a 2008 R2 or 2012 R2 DC, it was quickly shot down by a list of acronyms I had never heard of before. They said they have to get security baselines for any server that is involved with authentication and

RE: [NTSysADM] Windows 7 asking for network after expanding dhcp range form /24 to /22

2016-11-17 Thread Chad Leeper
No there is not a DC on /22. Interesting idea though and it makes sense. Both of my DCs do triple duty as DHCP and DNS. (only 117 nodes.) From: listsad...@lists.myitforum.com [mailto:listsad...@lists.myitforum.com] On Behalf Of Melvin Backus Sent: Thursday, November 17, 2016 1:15 PM To:

Re: [NTSysADM] Update on the broken DFSR issue

2016-11-17 Thread Andrew S. Baker
Too bad you can't write a book about this one. Regards, ASB http://XeeMe.com/AndrewBaker Providing Expert Technology Consulting Services for the SMB market… GPG:860D 40A1 4DA5 3AE1 B052 8F9F 07A1 F9D6 A549 8842 On Thu, Nov 17, 2016 2:16 PM, Webster webs...@carlwebster.com

RE: [NTSysADM] Group Policy cleanup/maintenance

2016-11-17 Thread Webster
I look for GPOs that are completely disabled, not linked anywhere, no security filtering, empty or orphaned in SYSVOL. Give the customer a list of each category and let them decide. Thanks Webster From: listsad...@lists.myitforum.com [mailto:listsad...@lists.myitforum.com] On Behalf Of

Re: [NTSysADM] Group Policy cleanup/maintenance

2016-11-17 Thread James Rankin
How do you define "stale"? As in not being applied to anything any more? Or being applied but no longer relevant? Obviously the former is much more achievable than they latter, IMHO Sent from my slightly schizophrenic, but rather cool, BlackBerry Android From: joseph.hea...@wildlife.ca.gov

Re: [NTSysADM] Windows 7 asking for network after expanding dhcp range form /24 to /22

2016-11-17 Thread D R
I would get a laptop and take it to where one of your desktops are located and take the network cable from the desktop and plug that into the laptop. Power up the laptop and see if what you are reporting happens with the laptop. If it does, shut the laptop down and take it to the server and plug a

[NTSysADM] Update on the broken DFSR issue

2016-11-17 Thread Webster
Boss man got on out GTM and explained the history of the issue. About a year ago they moved from FSR to DFSR for SYSVOL. Sometime after that, an admin who no longer works there, restored the main DC from a snapshot pre DFSR migration and pre adprep for 2008 R2. So you had the main DC now

Re: [NTSysADM] Win 10 admx files

2016-11-17 Thread James Rankin
Main issues for me are things being device based rather than user, like FTAs and start layout files. FTAs are the biggest issue we seem to get people complaining about. Sent from my slightly schizophrenic, but rather cool, BlackBerry Android From: joseph.hea...@wildlife.ca.gov Sent: 17

[NTSysADM] RE: How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Webster
Not at all, he has no screenshots! LOL But seriously, I would have reached out for help before three months had passed. My personal limit is one hour for something this critical. Just ask MBS and Brian Desmond, I am not afraid to reach out for help. BUT, I make sure I have done my research

RE: [NTSysADM] How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Webster
We demoted the "bad" DC and on the DC that holds all FSMO roles, dcdiag reports "Could not open DFSR Service on , error 0x424 "The specified service does not exist as an installed service". Google returns nothing. How do we get DFSR Service back? Thanks Webster From:

RE: [NTSysADM] Time change on a member server

2016-11-17 Thread David McSpadden
Looks like just a hardware fault and a bios clock with the wrong time. Still suspect of it but can find nothing. From: listsad...@lists.myitforum.com [mailto:listsad...@lists.myitforum.com] On Behalf Of Micheal Espinola Jr Sent: Wednesday, November 16, 2016 11:29 AM To:

RE: [NTSysADM] Windows 7 asking for network after expanding dhcp range form /24 to /22

2016-11-17 Thread Chad Leeper
My DHCP servers live on the /24 network. Yes, I do have Helper IPs configured. From: listsad...@lists.myitforum.com [mailto:listsad...@lists.myitforum.com] On Behalf Of Don Ely Sent: Thursday, November 17, 2016 10:27 AM To: ntsysadm@lists.myitforum.com Subject: Re: [NTSysADM] Windows 7 asking

[NTSysADM] RE: Group Policy cleanup/maintenance

2016-11-17 Thread Brian Desmond
GPOs I look at whether or not the GPO is referenced in the gpLink attribute of any OUs. If it is, I also look to see if all of its links are disabled. Empty GPOs also are candidates to go. Thanks, Brian Desmond w - 312.625.1438 | c - 312.731.3132 From: listsad...@lists.myitforum.com

Re: [NTSysADM] Win 10 admx files

2016-11-17 Thread Markus Klocker
Hey, I suggest you read this article and also that one and decide for yourself if it is wise :). Best, Markus Am 17.11.2016 um 17:14 schrieb Heaton,

Re: [NTSysADM] How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Richard Stovall
Thanks for that link. On Thu, Nov 17, 2016 at 12:21 PM, Michael B. Smith wrote: > Yes, that was a change. Regardless of which, you won’t get much support > for either. > > > > https://support.microsoft.com/en-us/help/17140 > > > > “Extended Support will be available to

[NTSysADM] RE: Group Policy cleanup/maintenance

2016-11-17 Thread Jon Harris
I used to move Computers to a "HOLD Computer" container and Users to a "HOLD Users" container then disable them for 60 to 90 days depending on time of the year. If no one complained within that term deleted them. DCs were done immediately since I was the only IT person to work on them. Jon

[NTSysADM] RE: How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread James Rankin
322 pages of notes? Is he related to you? ;-0 From: listsad...@lists.myitforum.com [mailto:listsad...@lists.myitforum.com] On Behalf Of Webster Sent: 17 November 2016 12:13 To: ntsysadm@lists.myitforum.com Subject: [NTSysADM] RE: How to force an authoritative and non-authoritative

[NTSysADM] Group Policy cleanup/maintenance

2016-11-17 Thread Heaton, Joseph@Wildlife
How do you guys deal with Group Policy objects, in regards to discovery and cleanup of "stale" objects? I have to come up with a procedural document for this process. Joe Heaton Information Technology Operations Branch Data and Technology Division CA Department of Fish and Wildlife 1700 9th

RE: [NTSysADM] Win 10 admx files

2016-11-17 Thread Charles F Sullivan
There’s a mistake in one of the ADMX file names, but just Google the exact error you get when you open GPMC and you’ll find the fix, which involves renaming the ADMX. I can’t remember what older settings will be missing, but I think I’ve heard a complaint or two on the Patch Management list.

RE: [NTSysADM] How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Michael B. Smith
Yes, that was a change. Regardless of which, you won’t get much support for either. https://support.microsoft.com/en-us/help/17140 “Extended Support will be available to all customers*. Extended Support includes paid technical assistance** (technical assistance that is charged on an hourly

Re: [NTSysADM] How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Richard Stovall
https://blogs.technet.microsoft.com/rmilne/2014/07/24/save-the-date-end-of-exchange-2010-windows-7-and-2008-mainstream-support-t-minus-6-months/ Looks like 2008 and R2 are on the same schedule? Currently out of mainstream support and in extended support? Not true? On Wed, Nov 16, 2016 at 10:18

RE: [NTSysADM] RE: HP notebook touchpad issues

2016-11-17 Thread Damien Solodow
May have a fix; finally got a hold of someone at HP support with some knowledge. ☺ Apparently there is a touchpad firmware update for the 840 G2 intended to resolve exactly this issue. Of course that doesn’t apply to the G1, but that may have been due to mistaken identity as the two models are

[NTSysADM] Win 10 admx files

2016-11-17 Thread Heaton, Joseph@Wildlife
Just downloaded the Win 10 admx files, and getting ready to put them in the central store. I did see some talk of issues with them; other things that needed to be done after adding them, some older settings not being there anymore, etc. Have those issues been ironed out, or are there still

Re: [NTSysADM] Windows 7 asking for network after expanding dhcp range form /24 to /22

2016-11-17 Thread Don Ely
Where does the DHCP server live? Do you have IP helper/DHCP relay configured on the L3 interface for your new /22 VLAN? On Thu, Nov 17, 2016 at 8:01 AM Chad Leeper wrote: > All, > > > > So when my network was originally created (Novell 3.x) the admin at the > time

[NTSysADM] Windows 7 asking for network after expanding dhcp range form /24 to /22

2016-11-17 Thread Chad Leeper
All, So when my network was originally created (Novell 3.x) the admin at the time used a /24 address for static AND dhcp range. Fast forward 20 years and we are running out of addresses. I have kept all static devices on /24 but, have setup a new dhcp scope on /22. We have Hp switches

RE: [NTSysADM] How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Charles F Sullivan
I’ve had to do this a few times over the last couple of years when I have recovered our DCs for DR testing. It seems to be needed every time and I agree that the part of the article you mention is confusing. Despite that, I’ve followed the article the best I could and I’ve got the problem resolved

[NTSysADM] RE: How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Webster
Now that I am back in the "office". Got brought into this call yesterday at 1500 and the customer had a hard stop at 1630. Here is what I know: Customer has two DCs, one in each datacenter on opposite sides of the state. This issue of SYSVOL not replicating has been going on for over two

Re: [NTSysADM] How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Webster
yes, it looked like it went out january 2015. webster Get Outlook for iOS From: listsad...@lists.myitforum.com on behalf of Richard Stovall Sent: Wednesday, November 16, 2016 9:09:54 PM

Re: [NTSysADM] RE: How to force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL (like "D4/D2" for FRS)

2016-11-17 Thread Webster
from the dc holding all fsmo roles, dfrsmig shows the state as eliminated. web Get Outlook for iOS From: listsad...@lists.myitforum.com on behalf of Michael B. Smith Sent: