Thursday, 15 December 2016

Pre-Planing and Planing Worksheets for SCCM 2016 / SCCM 1511 Implementation

Below are the Pre-Planing and Planing Worksheets for SCCM 2016 / SCCM 1511 Implementation

 

 

 

 

 

Organizational Data Preplanning Worksheet

Organizational structure

Example data needed, where applicable, and by location

Collected Data

 

 

 

High-level organization charts to help determine the divisional structure of your organization, the design of your Configuration Manager hierarchy, and your method of communicating Configuration Manager implementation updates to departments

 

Organizational structure

 

Reporting hierarchy

 

Communications methods

 

Service level agreements (SLAs)

 

IT organization and administrative policies

You should consider the following factors:

 

 

The structure and technical level of local and remote IT divisions, their reporting hierarchies, and local and global IT administrative policies

 

Organizational structure

 

Reporting hierarchy

 

Local administrative policies and SLAs

 

Global IT administrative policies and SLAs

 

Long-term business direction

Any major business changes planned for the future, such as mergers, acquisitions, major physical moves, or network migrations

 

 

 

 

Information Technology Organization Preplanning Worksheet

IT organization

Example data needed, where applicable, and by location

Data collected

IT Organization

Collect information about your IT organization. You should also create an organization chart that maps your IT organization to your geographic profile.

 

 

IT reporting hierarchy.

 

 

IT departmental divisions that produce an overlap in Configuration Manager  tasks (for example, a department separate from the Configuration Manager team manages all database servers, including computers running Microsoft SQL Server)

 

 

Points where management control or policy issues exist.

 

 

Level of technical sophistication and security clearance of IT staff members who will be working with Configuration Manager  before, during, or after deployment.

 

 

Auditing policies.

 

 

Service level agreements for departments, end users, and IT groups.

 

 

Operating systems used to support the network and end users.

 

 

Sensitivity to security risks.

 

 

Change control policy.

 

 

 

 

Geographic Profile Preplanning 

Geographic information

Example data needed, where applicable, and by location

Collected Data

Date and time zone information

List the time zone for each location, and list any date and time difference between the remote site and headquarters.

 

 

 

 

 

Time zone.

 

 

 

 

 

Date and time differences.

 

 

 

 

Operating systems and international operating system versions

List the operating systems in use and locations that use language versions that are different from those of your platform operating systems.

 

 

 

 

Active Directory Preplanning

Active Directory preplanning

Example data needed, where applicable, and by location

Data collected

Logical Structure

The logical structure of your organization is represented by the following Active Directory components: organizational units, domains, trees, and forests.

 

Physical Structure

The physical structure of your organization is represented by the following Active Directory components: Active Directory sites (physical subnets) and domain controllers.

 

 

 

 

Network Topology Preplanning

Network topology

Example data needed, where applicable, and by location

Data Collected

High-level WAN/LAN architecture

Links, gateways, firewalls, extranets, virtual private networks, and

 

perimeter networks

Network size

Number of servers and clients at each location

 

Network bandwidth

Link speeds and available bandwidth, including any known bandwidth issues

 

Network usage and traffic patterns

Categorize as Light, moderate, or heavy, and note times of day when network usage is heaviest (peak times) and scheduled times for backup and maintenance (nonpeak times)

 

Network types

Windows NT, Windows 2000, or Novell NetWare and other third-party network operating systems

 

Network protocols

TCP/IP, IPv6, NetBEUI, IPX/SPX, AppleTalk, DLC, and so on, and name resolution methods such as DNS and WINS

 

IP subnet structure

The Internet Protocol (IP) subnets on your network by subnet ID

 

Active Directory site structure

Active Directory organizational units, site names, trees, and forest

 

 

 

 

Server Environment Preplanning

Server

Example data needed, where applicable, and by location

Data collected

Location and function

Document the location and function of the computers that run the core services of your network, such as global catalog servers, domain controllers, DNS and WINS servers, Internet Information Services (IIS) servers, computers running Microsoft SQL Server or Terminal Services, Microsoft Exchange servers, print servers, and file servers.

 

Naming conventions

Document current naming conventions for products you use with Configuration Manager , such as computers running Windows Server 2003 and SQL Server. This helps you establish and document naming conventions for Configuration Manager  hierarchy elements. These elements include sites, site codes, servers, and the objects that are used by or created in the Configuration Manager console. Because the Configuration Manager site code is used to uniquely identify each Configuration Manager site, it is especially important that these codes be assigned and tracked by the Configuration Manager central site administrators.

 

Hardware, software, network

Document hardware, software, and network information for each server that might be assigned a site role in your Configuration Manager site hierarchy.

 

For example, you should document at least the following information from each server that will be part of your Configuration Manager  hierarchy:

 

 

 

Azure Machine Type

 

Processor type and speed

 

Amount of RAM installed

 

 

 

Disk and array controller configuration and characteristics, including size, MB of cache, and the drive models and types (for example, ultra-wide SCSI, 18 GB, 7200 RPM)

 

 

 

Platform operating system, version, and language

 

 

 

Whether the Windows Cluster service or Windows Network Load Balancing Service is enabled

 

 

 

Relevant software applications located on servers, including antivirus software

 

 

 

 

 

 

Client Environment Preplanning

Clients

Example data needed, where applicable, and by location

Data collected

Number of clients

Total number of client computers in use on your network, and the physical and logical groupings of clients.

 

IP subnet size

Number and types (operating systems) of client computers on each IP subnet, including projected number of clients in the upcoming year.

 

Logon scripts

Whether or not users use logon scripts, and if those scripts are customized. Note file name and location of each script, and users and groups associated with each script.

 

Security rights

Desktop security rights granted to end users

 

Operating systems

Platform operating systems (including language version) in use on each IP subnet.

 

Client stability/mobility

Computers that are shared by multiple users, those that travel from one location to another, all home-based client computers having remote access to the network, and any other client computer environments.

 

Software

A database or spreadsheet of all major applications in use in the enterprise, categorized by organizational division or by IP subnet.

 

Special applications

Divisions or departments that use Windows Terminal Services to run applications, or use other special applications, such as internally manufactured or obsolete applications.

 

Connectivity

Types of connectivity different organizational groups are using, including remote client connection speeds (dependent on the remote access method in use, such as ADSL, wireless, dial-up, ISDN, or Site to Site VPN, Express Route or other).

 

 

 

 

Client Environment Preplanning

Security

Example data needed, where applicable, and by location

Data collected

Security policies

Collect information about your organization’s security policies, such as the following:

 

 

Account password policies

 

Account cycling policies

 

Account rights policies

 

Client and server lockdown policies (restrictions on disks and registry, services that are stopped, whether services use Domain Administrator accounts, and hidden shared folders that are removed)

 

Auditing policies

 

 

Separation of or delegation of duties between IT divisions within the enterprise.

 

 

The degree to which users must retain control of clients, and any exceptions to such policies (such as servers, or computers used by programmers).

 

 

You should collect information about how security-related issues will be handled and supported, such as the following information:

 

 

Sensitivity to security risks

 

Importance of ease of administration

 

Special needs you have for secure data access and transmission

 

Service level agreements (SLAs) for applying security updates

 

Mobile Devices Management

Is it required ?
If so are we planning for INTUNE or MDM

 

 

Friday, 2 December 2016

Windows 10 few Customisation based on batch file


%~d0
CD %~dp0

REM **********************Start of Modify Default User Hive ******************
REM **Load Default User Hive**
mapdu.exe

:: Windows 10  Time zone
tzutil /s "Pacific Standard Time"

:: Windows 10  Personalisation settings
:: Windows 10  Personalize your speech, typing, and inking input by sending contacts and calendar details, along with other associated input data to Microsoft
Reg Add "HKCU\SOFTWARE\Microsoft\Personalization\Settings" /v AcceptedPrivacyPolicy /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Personalization\Settings" /v AcceptedPrivacyPolicy /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" /v HarvestContacts /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" /v HarvestContacts /t REG_DWORD /d 0 /f

:: Windows 10  Send typing and inking data to Microsoft to improve the recognition and suggestion platform
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f

:: Windows 10  Let apps use your advertising ID for experience across apps
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo" /v Enabled /t REG_DWORD /d 0 /f

:: Windows 10  Smart Screen filter: Turn off
:: Windows 10  Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d Off /f
:: Windows 10 Reg Add "HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost" /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9 /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnabled /t REG_DWORD /d 0 /f
:: Windows 10 Reg Add "HKU\Defaultuser\Software\Microsoft\Windows\CurrentVersion\AppHost" /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnabled /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9 /t REG_DWORD /d 0 /f

:: Windows 10  TURNOFF NOTIFICATION ON LOCK SCREEN
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f

:: Windows 10  HIDE ONE DRIVE
Reg Add "HKEY_CLASSES_ROOT\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6" /v System.IsPinnedToNameSpaceTree /t REG_DWORD /d 0 /f
Reg Add "HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /v System.IsPinnedToNameSpaceTree /t REG_DWORD /d 0 /f

:: Windows 10  DISABLE ONE DRIVE
Reg Add "HKLM\Software\Policies\Microsoft\Windows\OneDrive" /v DisableFileSyncNGSC /t REG_DWORD /d 1

:: Windows 10  TURN ON TABLETMODE
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell" /v TabletMode /t REG_DWORD /d 1
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell" /v TabletMode /t REG_DWORD /d 1

:: Windows 10  Disable wifi sense (NEED TO BE TESTED ON A MACHINE WITH WIFI)
Reg Add "HKLM\SOFTWARE\Microsoft\WcmSvc\wifinetworkmanager\config" /v AutoConnectAllowedOEM /t REG_DWORD /d 0 /f

:: Windows 10  Show colour on Start, taskbar and action centre AND  Automatically pick a color from my background. 
Reg Add "HKCU\Control Panel\Desktop" /v AutoColorization /t REG_DWORD /d 1 /f
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v ColorPrevalence /t REG_DWORD /d 1 /f
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\DWM" /v ColorPrevalence /t REG_DWORD /d 1 /f

Reg Add "HKU\Defaultuser\Control Panel\Desktop" /v AutoColorization /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v ColorPrevalence /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\DWM" /v ColorPrevalence /t REG_DWORD /d 1 /f

:: Windows 10  Make Start, taskbar and action centre transparent
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v EnableTransparency /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v EnableTransparency /t REG_DWORD /d 1 /f

:: Windows 10  Show app notifications - Turn Off
Reg Add "HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications" /v ToastEnabled /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Windows\CurrentVersion\PushNotifications" /v ToastEnabled /t REG_DWORD /d 0 /f

:: Windows 10  Hide notifications while presenting
Reg Add "HKCU\SOFTWARE\Microsoft\MobilePC\AdaptableSettings" /v SkipBatteryCheck /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\MobilePC\AdaptableSettings" /v SkipBatteryCheck /t REG_DWORD /d 1 /f

Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_SUPRESS_TOASTS_WHILE_DUPLICATING /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_SUPRESS_TOASTS_WHILE_DUPLICATING /t REG_DWORD /d 1 /f

:: Windows 10 To also be able to run the Windows Mobility Center on your Desktop computer, you need to add the following value as well 
Reg Add "HKCU\SOFTWARE\Microsoft\MobilePC\MobilityCenter" /v RunOnDesktop /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\MobilePC\MobilityCenter" /v RunOnDesktop /t REG_DWORD /d 1 /f

:: Windows 10 To Turn Off Offline Maps
Reg add "HKLM\SYSTEM\Maps" /v AutoUpdateEnabled /t REG_DWORD /d 0 /f

:: Windows 10  Disable RDP
Reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 1 /f
Net Stop UmRDPService
Net Stop TermService

:: Windows 10  Disable remote assistance
Reg add "HKLM\SYSTEM\CurrentControlSet\Control\Remote Assistance" /v fAllowToGetHelp /t REG_DWORD /d 0 /f

:: Windows 10  Disable System Restore
Reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v DisableSR /t REG_DWORD /d 1 /f
:: Windows 10  sc config srservice start= disabled
:: Windows 10  net stop srservice

:: Windows 10 feedback and diagnostic disable
Reg Add "HKCU\Software\Microsoft\Siuf\Rules" /v PeriodInNanoSeconds /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Siuf\Rules" /v PeriodInNanoSeconds /t REG_DWORD /d 0 /f

Reg Add "HKCU\Software\Microsoft\Siuf\Rules" /v NumberOfSIUFInPeriod /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Siuf\Rules" /v NumberOfSIUFInPeriod /t REG_DWORD /d 0 /f

Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f

:: Windows 10 Disable Error Reporting
Reg Add "HKLM\SOFTWARE\Microsoft\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f

:: Windows 10 Always_install_best_driver_software_from_Windows_Update
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSearching" /v SearchOrderConfig /t REG_DWORD /d 1 /f

:: Windows 10 Never_Notify_or_Check_for_Updates
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /t REG_DWORD /d 1 /f

:: Windows 10 Turn_Off_alarms_reminders_VoIP-calls_on_Lock_Screen
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f

:: Windows 10 Turn_Off_Location_for_this_Device
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f

:: Windows 10 Reg Add "HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f
:: Windows 10 Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f

:: Windows 10 Disable Check for solutions to problem reports
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f

:: Windows 10 Enable_Automatic_Maintenance
Reg Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Maintenance" /v MaintenanceDisabled /t REG_DWORD /d - /f

:: Windows 10 Turn Off File History
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\FileHistory" /v Disabled /t REG_DWORD /d 1 /f

:: Windows 10 Turn Off Windows defender Settings
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpynetReporting /t REG_DWORD /d 0 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f


:: Windows 10 Turn_Off_Clear_Tile_Notifications_during_log_on
Reg Add "HKCU\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f
Reg Add "HKU\Defaultuser\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f

REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaveActive" REG_SZ "1"
REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaverIsSecure" REG_SZ "1"
REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaveTimeOut" REG_SZ "1200"

ping 127.0.0.1 -n 20 > NUL
REM **Unload Default User Hive**
mapdu.exe /U
ping 127.0.0.1 -n 20 > NUL

Windows 10 few Customisation based on batch file


%~d0
CD %~dp0

REM **********************Start of Modify Default User Hive ******************
REM **Load Default User Hive**
mapdu.exe

:: Time zone
tzutil /s "Pacific Standard Time"

:: Personalisation settings
:: Personalize your speech, typing, and inking input by sending contacts and calendar details, along with other associated input data to Microsoft
Reg Add "HKCU\SOFTWARE\Microsoft\Personalization\Settings" /v AcceptedPrivacyPolicy /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Personalization\Settings" /v AcceptedPrivacyPolicy /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" /v HarvestContacts /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore" /v HarvestContacts /t REG_DWORD /d 0 /f

:: Send typing and inking data to Microsoft to improve the recognition and suggestion platform
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection" /v AllowTelemetry /t REG_DWORD /d 0 /f

:: Let apps use your advertising ID for experience across apps
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\AdvertisingInfo" /v Enabled /t REG_DWORD /d 0 /f

:: Smart Screen filter: Turn off
:: Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer" /v SmartScreenEnabled /t REG_SZ /d Off /f
::Reg Add "HKCU\Software\Microsoft\Windows\CurrentVersion\AppHost" /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9 /t REG_DWORD /d 0 /f
Reg Add "HKCU\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnabled /t REG_DWORD /d 0 /f
::Reg Add "HKU\Defaultuser\Software\Microsoft\Windows\CurrentVersion\AppHost" /v EnableWebContentEvaluation /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\FlipAhead" /v FPEnabled /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\MicrosoftEdge\PhishingFilter" /v EnabledV9 /t REG_DWORD /d 0 /f

:: TURNOFF NOTIFICATION ON LOCK SCREEN
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f

:: HIDE ONE DRIVE
Reg Add "HKEY_CLASSES_ROOT\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6" /v System.IsPinnedToNameSpaceTree /t REG_DWORD /d 0 /f
Reg Add "HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /v System.IsPinnedToNameSpaceTree /t REG_DWORD /d 0 /f

:: DISABLE ONE DRIVE
Reg Add "HKLM\Software\Policies\Microsoft\Windows\OneDrive" /v DisableFileSyncNGSC /t REG_DWORD /d 1

:: TURN ON TABLETMODE
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell" /v TabletMode /t REG_DWORD /d 1
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell" /v TabletMode /t REG_DWORD /d 1

:: Disable wifi sense (NEED TO BE TESTED ON A MACHINE WITH WIFI)
Reg Add "HKLM\SOFTWARE\Microsoft\WcmSvc\wifinetworkmanager\config" /v AutoConnectAllowedOEM /t REG_DWORD /d 0 /f

:: Show colour on Start, taskbar and action centre AND  Automatically pick a color from my background. 
Reg Add "HKCU\Control Panel\Desktop" /v AutoColorization /t REG_DWORD /d 1 /f
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v ColorPrevalence /t REG_DWORD /d 1 /f
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\DWM" /v ColorPrevalence /t REG_DWORD /d 1 /f

Reg Add "HKU\Defaultuser\Control Panel\Desktop" /v AutoColorization /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v ColorPrevalence /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\DWM" /v ColorPrevalence /t REG_DWORD /d 1 /f

:: Make Start, taskbar and action centre transparent
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v EnableTransparency /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Themes\Personalize" /v EnableTransparency /t REG_DWORD /d 1 /f

:: Show app notifications - Turn Off
Reg Add "HKCU\Software\Microsoft\Windows\CurrentVersion\PushNotifications" /v ToastEnabled /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Windows\CurrentVersion\PushNotifications" /v ToastEnabled /t REG_DWORD /d 0 /f

:: Hide notifications while presenting
Reg Add "HKCU\SOFTWARE\Microsoft\MobilePC\AdaptableSettings" /v SkipBatteryCheck /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\MobilePC\AdaptableSettings" /v SkipBatteryCheck /t REG_DWORD /d 1 /f

Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_SUPRESS_TOASTS_WHILE_DUPLICATING /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_SUPRESS_TOASTS_WHILE_DUPLICATING /t REG_DWORD /d 1 /f

::To also be able to run the Windows Mobility Center on your Desktop computer, you need to add the following value as well 
Reg Add "HKCU\SOFTWARE\Microsoft\MobilePC\MobilityCenter" /v RunOnDesktop /t REG_DWORD /d 1 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\MobilePC\MobilityCenter" /v RunOnDesktop /t REG_DWORD /d 1 /f

::To Turn Off Offline Maps
Reg add "HKLM\SYSTEM\Maps" /v AutoUpdateEnabled /t REG_DWORD /d 0 /f

:: Disable RDP
Reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 1 /f
Net Stop UmRDPService
Net Stop TermService

:: Disable remote assistance
Reg add "HKLM\SYSTEM\CurrentControlSet\Control\Remote Assistance" /v fAllowToGetHelp /t REG_DWORD /d 0 /f

:: Disable System Restore
Reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" /v DisableSR /t REG_DWORD /d 1 /f
:: sc config srservice start= disabled
:: net stop srservice

::feedback and diagnostic disable
Reg Add "HKCU\Software\Microsoft\Siuf\Rules" /v PeriodInNanoSeconds /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Siuf\Rules" /v PeriodInNanoSeconds /t REG_DWORD /d 0 /f

Reg Add "HKCU\Software\Microsoft\Siuf\Rules" /v NumberOfSIUFInPeriod /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\Software\Microsoft\Siuf\Rules" /v NumberOfSIUFInPeriod /t REG_DWORD /d 0 /f

Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f

::Disable Error Reporting
Reg Add "HKLM\SOFTWARE\Microsoft\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f

::Always_install_best_driver_software_from_Windows_Update
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSearching" /v SearchOrderConfig /t REG_DWORD /d 1 /f

::Never_Notify_or_Check_for_Updates
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" /v NoAutoUpdate /t REG_DWORD /d 1 /f

::Turn_Off_alarms_reminders_VoIP-calls_on_Lock_Screen
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications\Settings" /v NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK /t REG_DWORD /d 0 /f

::Turn_Off_Location_for_this_Device
Reg Add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f
Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceAccess\Global\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v Value /t REG_SZ /d Deny /f

::Reg Add "HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f
::Reg Add "HKU\Defaultuser\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Sensor\Permissions\{BFA794E4-F964-4FDB-90F6-51056BFE4B44}" /v SensorPermissionState /t REG_DWORD /d 0 /f

::Disable Check for solutions to problem reports
Reg Add "HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting" /v Disabled /t REG_DWORD /d 1 /f

::Enable_Automatic_Maintenance
Reg Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Maintenance" /v MaintenanceDisabled /t REG_DWORD /d - /f

::Turn Off File History
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\FileHistory" /v Disabled /t REG_DWORD /d 1 /f

::Turn Off Windows defender Settings
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealtimeMonitoring /t REG_DWORD /d 1 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpynetReporting /t REG_DWORD /d 0 /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f


::Turn_Off_Clear_Tile_Notifications_during_log_on
Reg Add "HKCU\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f
Reg Add "HKU\Defaultuser\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f
Reg Add "HKLM\SOFTWARE\Policies\Microsoft\Windows\Explorer" /v ClearTilesOnExit /t REG_SZ /d /f

REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaveActive" REG_SZ "1"
REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaverIsSecure" REG_SZ "1"
REGPOL.EXE HKCU "Software\Policies\Microsoft\Windows\Control Panel\Desktop" "ScreenSaveTimeOut" REG_SZ "1200"

ping 127.0.0.1 -n 20 > NUL
REM **Unload Default User Hive**
mapdu.exe /U
ping 127.0.0.1 -n 20 > NUL

Friday, 25 November 2016

What is New with Microsoft System Center Configuration Manager Software as Service ?

Microsoft System Center Configuration Manager 1511 What is New
Configuration Manager now has the ability to differentiate a Windows 10 computer that is directly connected via Windows Update for Business (WUfB) versus the ones connected to WSUS for getting Windows 10 updates and upgrades. 
Configuration Manager now supports using a SQL Server AlwaysOn availability groups to host the site database. When you install a new site, you can direct setup to use the availability group instead of a normal instance of SQL Server.
Service a server cluster : You can now create a collection that contains servers in a cluster, and then configure the cluster settings to use when you deploy updates to the cluster. You can control the percentage of servers that are online at any given time, as well as to configure pre-deployment and post-deployment PowerShell scripts to run custom actions.
Microsoft System Center Configuration Manager 1512 What is New
Device Health Attestation :Device health attestation lets the administrator ensure that client computers have trustworthy BIOS, TPM, and boot software configurations. To support device health attestation, client devices must be running Win10 with TPM 2 enabled. Device health attestation displays the number of devices enabled for each of the following: Early-launch antimalware,BitLocker,Secure Boot,Code Integrity
In order to preview the device health attestation view, in the Configuration Manager console go to the Monitoring workspace of, click Security node, and then click Health Attestation
Microsoft System Center Configuration Manager 1601 What is New
Improvements to Endpoint Protection policy settings:   Real-time protection: Block Potentially Unwanted Applications at download and prior to installation
  Scan settings: Scan mapped network drives when running a full scan
  Auto sample file submission settings:
Improvements to Microsoft Intune integration :Conditional access support for PCs not for windows 10
Client online status: shows in green and gray
Limitations Client online status is only available for Windows computers with the Configuration Manager client installed. Client online status is not supported for Mac computers, Linux or UNIX computer, or devices managed with On-premises Mobile Device Management.
Microsoft System Center Configuration Manager 1602 What is New
Improvements to mobile device management:
iOS Activation Lock
System Center Configuration Manager can help you manage iOS Activation Lock, a feature of the Find My iPhone app for iOS 7.1 and later devices. Activation Lock is enabled automatically when the Find My iPhone app is used on a device. After it is enabled, the user's Apple ID and password must be entered before anyone can:
Turn off Find My iPhone
Erase the device
Reactivate the device
Improvements to Software Center in the 1602 release:
Refresh PC machine and user policy from Software Center
A new option, Sync Policy has been added to the Options > Computer Maintenance page of Software Center that causes the PC to refresh it’s Configuration Manager machine and user policy.
Improvements to Windows 10 Servicing
New filter options for Servicing Plans. You can now filter for Language, Required, and Title. Only upgrades that meet the specified criteria will be added to the associated deployment.
When you select the Upgrades classification for software updates synchronization, a warning dialog is displayed to let you know that WSUS hotfix 3095113 is required to successfully synchronize software updates and for the Windows 10 Servicing to work properly. From the dialog, you can go to the knowledge base article for the hotfix.
Available Windows 10 upgrades now only display in the Windows 10 Servicing \ All Windows 10 Updates node of the Configuration Manager console. These updates no longer display in the Software Updates \ All Software Updates node.
End-users that start a Windows 10 Upgrade package will be prompted with a dialog that lets them know they will be upgrading their operating system
Microsoft System Center Configuration Manager 1603 What is New

New tiled view for apps :End users can now choose between a list of apps, or a tiled view of apps in the Applications tab of Software Center
Select multiple updates in Software Center : In the Updates tab of Software Center, you can now select multiple updates, or select Update All to begin installing multiple updates simultaneously.
Improvements to remote control:Limit shared clipboard access in a remote control session
You can now enable the new remote tools client setting Prompt user for shared clipboard file transfer permission to limit access to the shared clipboard in a remote control session.
When enabled, the end user who is sharing a remote session must grant permissions to the viewer of that session before the viewer can transfer files from the session to their local machine via the shared clipboard.
This adds a layer of protection for the end user as previously, if the viewer was granted full control of the end user’s computer, they would be able to use the shared clipboard to transfer files from the session to their local computer in a way that was entirely transparent to the end user.
Customize the RamDisk TFTP block size and window size on PXE-enabled distribution points:
In the 1603 Technical Preview, you can customize the RamDisk TFTP block size and window size for PXE-enabled distribution points. If you have customized your network, it could cause the boot image download to fail with a time-out error because the block or window size is too large. The RamDisk TFTP block size and window size customization allow you to optimize TFTP traffic when using PXE to meet your specific network requirements. You will need to test the customized settings in your environment to determine what is most efficient.


TFTP block size: The block size is the size of the data packets that are sent by the server to the client that is downloading the file (as discussed in RFC 2347). A larger block size allows the server to send fewer packets, so there are fewer round-trip delays between the server and the client. However, a large block sizes leads to fragmented packets, which most PXE client implementations do not support.
TFTP window size: TFTP requires an acknowledgment (ACK) packet for each block of data that is sent. The server does not send the next block in the sequence until it receives the ACK packet for the previous block. TFTP windowing is a feature in Windows Deployment Services that enables you to define how many data blocks it takes to fill a window. The server sends the data blocks back-to-back until the window is filled, and then the client sends an ACK packet. Increasing this window size reduces the number of round-trip delays between the client and server and decreases the overall time that is required to download a boot image.
Microsoft System Center Configuration Manager 1604 What is New

Windows Store for Business synchronization
Improvements to Microsoft Passport for Work management:You can now deploy Passport for Work policies to domain-joined Windows 10 devices managed by the Configuration Manager client
switch to a new software update point
Client settings to manage Client Cache Settings and client Peer Cache
Support for Passport for Work as a KSP
On-premises Device Health Attestation
SmartLock setting for Android devices

Microsoft System Center Configuration Manager 1605 What is New
Per-app VPN for Windows 10 devices:For Windows 10 devices managed using Configuration Manager with Intune, you can add a list of apps that automatically open a VPN connection that you have configured through the Configuration Manager admin console. You have the option of restricting VPN traffic to those apps, or you can continue to allow all traffic through the VPN connection.
Improvements to the Install software updates task sequence : New TS variable :A new task sequence variable, SMSTSSoftwareUpdateScanTimeout, is available to give you the ability to control the timeout on the software updates scan during the Install software updates task sequence step. The default value is 30 minutes.
There have been improvements to logging. The smsts.log log file will contain new log entries that reference other log files that will help you to troubleshoot issues during the software updates installation process
Improvements to the Prepare ConfigMgr Client for Capture task sequence step:
The Prepare ConfigMgr Client step will now completely remove the Configuration Manager client, instead of only removing key information. When the task sequence deploys the captured operating system image it will install a new Configuration Manager client each time.
Grace period for required application deployments:On the Computer Agent page of client settings, configure the new property Grace period for enforcement after deployment deadline (hours) with a value between 1 and 120 hours.
In a new application deployment, or in the properties of an existing deployment, on the Scheduling page, select the checkbox Delay enforcement of this deployment according to user preferences, up to the grace period defined in client settings.
All deployments that have this check-box selected and are which are targeted to devices to which you also deployed the client setting will use the grace period.
New experience for remote device actions:The experience for performing remote device actions from the Configuration Manager console has been improved.
Common actions such as Retire/Wipe, Reset Passcode, Remote Lock, and Bypass Activation Lock can now be found in the Remote Device Actions menu accessed from the Assets and Compliance workspace.
Windows Store for Business apps:
The Windows Store for Business is where you can find and purchase apps for your organization, individually or in volume. By connecting the store to Configuration Manager, you can manage volume-purchased apps from the Configuration Manager console, for example:
You can synchronize the list of purchased apps with Configuration Manager
Apps that are synchronized appear in the Configuration Manager console and you can deploy these like any other apps
Every 24 hours, Configuration Manager downloads app licensing information from the store, and you can review this in the Configuration Manager console
Will continue to add ... when I get some time :) 

Monday, 21 November 2016

SCCM 2012 Maintenance Tasks

Daily:

·    Monitoring Alerts on SCOM web console or SCCM status messages

·    Ensuring availability of SCCM site servers

·    Monitoring & Controlling SCCM site health status

·    Monitoring & Controlling client health status

·    Ensuring successful backup on all primary servers

·    Monitoring site system's inbox folder(s)

·    Ensuring ongoing production packages are copied to DPs

·    Monitoring long running queries

·    Monitoring Audit messages

Weekly:

·    Delete unnecessary objects

·    Delete unnecessary files from site systems

·    Check disk space on all site systems

·    Check advertisement status

·    Review Package status

·    Review sync between SCCM (Parent-Child) sites

·    Clean out old machines and user accounts


 

 

Monthly:

·    Defragment all sccm site systems

·    Perform Database Maintenance

·    Review advertisement success/failure rate

·    Review SCCM updates & SQL updates on all SCCM servers

·    Reviewing AD & SMS objects

·    Review SCCM site settings on all SCCM servers

·    Performance review & tuning

·    Stale object deletion from SCCM database

 

Quarterly:

·    Review SCCM Site boundaries

·    Review SCCM-OU Mapping

·    Capacity planning

Half Yearly / Bi-Annually:

·    Package Archival

·    SCCM hierarchy review

·    Review SCCM security

·    Review SCCM reports

·    Review security updates on SCCM servers

Yearly / Annually:

·    Perform DR test

·    Review SCCM Design

·    Review Documentation

·    Review Maintenance plan