Redirected homefolder – the correct way…

https://support.microsoft.com/kb/274443

1. Set Share Permissions for the the correct group to full access (Sudgestionname: RDS_access_all_user)

2. Use the following settings for NTFS Permissions:

CREATOR OWNER – Full Control (Apply onto: Subfolders and Files Only)
System – Full Control (Apply onto: This Folder, Subfolders and Files)
Domain Admins – Full Control (Apply onto: This Folder, Subfolders and Files)
RDS_access_all_user – Modify (Apply onto: This folder only)
RDS_access_all_user – Read & Execute (Apply onto: This folder only)
RDS_access_all_user – List fodler content (Apply onto: This folder only)
RDS_access_all_user – read (Apply onto: This folder only)
RDS_access_all_user – write(Apply onto: This folder only)

SSL issues with old appliances etc – Lower Security temporary

In a new tab, type or paste about:config in the address bar and press Enter. Click the button promising to be careful
* In the search box above the list, type or paste ssl3 and pause while the list is filtered
(3) Double-click the security.ssl3.dhe_rsa_aes_128_sha preference to switch it from true to false (this usually would be the first item on the list)
(4) Double-click the security.ssl3.dhe_rsa_aes_256_sha preference to switch it from true to false (this usually would be the second item on the list)

That’s it, you can test using: https://www.ssllabs.com/ssltest/viewMyClient.html

Gain local admin password

To gain a local admin password is rather simple on any machine that is not bitlocked or some how protected offline.

Setup:
Have/Make a bootable windows 10 USB stick…

#1 Boot windows media Press Shift+F10 to gain Commandprompt
#2 Change dir to local windows drive c:\windows\system32
#3 copy utilman.exe utilman.old
#4 copy cmd.exe utilman.exe

# ALT is to use sethc.exe… activates with Shift 5 times…

#5 reboot computer and boot into windows
#6 Press Windows + U and now a command prompt will appear outside windows logon. (Or shift 5 times…)

#7 Change current admin password with
Net user administrator newpassword
net user administrator /active:yes

If needed make a new account with
net user NewAdmin /add
net localgroup administrator NewAdmin /add
#8 Reboot and login with the new/changed account

Cleanup:
This probably needs a bit of extra high rights – installer etc..
Reset it the same way you setit up above will always work.

# Start a commandprompt as admin.
#Change dir to local windows drive c:\windows\system32
delete utilman.exe
Copy utilman.old utilman.exe

Press Windows + U to se controll comming upp ok
Or Shift 5 times if you are using Sethc.exe

Tested and works on:
Windows Server 2016 Technical Preview 5
Windows 7
Windows 10 1909
Windows Server 2012 R2

Schemalägga en omstart vid en viss tid snabbt..

Good to know, Good to not have to remember…

Startar om maskinen 23.00, kör som system, tar bort schemat efter utfört uppdrag…

 

[codesyntax lang=”powershell” container=”none”]

schtasks /create /RU "SYSTEM" /RL "HIGHEST" /sc once /tn "Restart Once" /tr "shutdown /r /t 010 /f /c RestartOnce" /st 23:00 /V1 /Z

[/codesyntax]

 

Ingen MAPI kompatibel epost klient finns installerad

Öppna registereditorn genom att skriva regedit i sökfältet i startmenyn.
Bläddra fram följande nyckel: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Messaging Subsystem\.
(Om du har 64-bitars operativsystem hittar du samma nyckel under HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows Messaging Subsystem\)

Kontrollera att MAPI, MAPIX och MAPIXVER finns upplagda med datavärden 1, 1 respektive 1.0.0.1.

Om exempelvis MAPI inte finns upplagd högerklickar du i det högra fältet och väljer Nytt – Strängvärde. Ge det nya strängvärdet namnet MAPI. Tryck enter och dubbelklicka sedan på namnet MAPI.
Skriv 1 i Data och klicka OK.

WMI Filtering in Grouppolicy

Filtrera ut olika saker med WMI filter i Grouppolicy

Exempel:

SELECT Version, ProductType from Win32_OperatingSystem Where Version like ”6.1%” and ProductType = ”1” = Window 7 klienter
SELECT Version, ProductType from Win32_OperatingSystem Where Version like ”6.3%” and ProductType = ”1” = Window 8 klienter
SELECT Version, ProductType from Win32_OperatingSystem Where Version like ”10.0%” and ProductType = ”1” = Window 10 klienter

Select Caption,ProductType from Win32_OperatingSystem Where Caption LIKE ”%Windows 10%” and ProductType=”1″ = Windows 10 .. ok 2016

Filtrerar ut alla maskiner med version 6.1% samt har ProductType = 1 (1= Client, 2=Server, 3=Member server)

 

 

 

 

 

WPA2-Enterprise Grouppolicy WMI Filtering

In this example GPO will be used to push an SSID configured for machine authentication using PEAP-MSCHAPv2 to Windows 7 domain member systems.

1. Open the domainGroup Policy Managementsnap-in.
2. Create a new GPO or use an existing GPO.
3.Editthe GPO and navigate to Computer Configuration>Policies> Window Settings>Security Settings>Public Key Policies>Wireless Network (IEEE 801.X) Policies.
4.Right ClickWireless Network (IEEE 801.X) Policiesand chooseCreate a New Windows Vista Policy.
5.Provide aVista Policy Name:
6.ClickAddforConnect to available networks…
7.ChooseInfrastructure.
8.On theConnectiontab, provide aProfile Name:and enter the SSID of the wireless network forNetwork Name(s).ClickAdd.
9.Click theSecuritytab. Configure the following:
Authentication:WPA2-Enterprise or WPA-Enterprise
Encryption:AES or TKIP
Network Authentication Method:Microsoft: Protected EAP (PEAP)
Authentication mode: User Authentication

10. ClickProperties.

11.ForTrusted Root Certification Authoritiesselect the check box next to each CA in the Active Directory PKIinfrastructure and clickOK.
OR Choose to ignore cert by just removing ”Validate Server Certificate”


12.ClickOK toclose out and clickApplyon wireless policy page to save the settings.

13.Apply the GPO to the domain or OU containing the domain member computers.

Filter computer with WMI is handles on another post

Office 2016

office-2016

 

 

 

 

 

 

 

 

 

 

AKA office 16 !
Size: Office 365 ProPlus are approximately 850 mb for the core files plus approximately 200 mb for each language deployed (1GB)
Update:
You can continue to receive updates for the Office 2013 version of Office 365 ProPlus until September 2016.
After September 2016, there will be no additional updates for the Office 2013 version.

If you’ve configured your users to get updates directly from the Office Content Delivery Network (CDN) on the Internet, the update to
Office 2016 is scheduled to begin in February 2016.
At that time, the Office 2016 files will be automatically downloaded to users’ computers and the update of Office 365 ProPlus will occur.
If you don´t want these users to be updated automatically, configure them, before February, to get updates from a location on your
internal network.

Installing from the Office 365 portalUntil February 2016, the version of Office 365 ProPlus that gets installed from the
Software page on the Office 365 portal will remain the Office 2013 version.
In February that will change to the Office 2016 version and it will be the Current Branch for Business release.

If, before February, you want some or all of your users to be able to install the Office 2016 version of Office 365 ProPlus from the
Software page, you can enable the First Release program for Office 365 and select which users you want to include.
Those users can then install either the 2013 or 2016 versions from the Software page.

Enable FirstRelease this way: Go to Admin center -> Service Settings -> updates -> Choose Select people and choose the
persons or Entire organization.


Admin Tools

Deployment

Spelling in swedish/english etc aka proofing tools Download here(Takes time to deploy)