Hi All,
Been a loooooong time since I've posted here.
Keeping ahead of times as always I'm upgrading a system to Windows 8.1 and found my external USB HDD is constantly prompting to be encrypted with Bitlocker. If I refuse it's marked as read only and I can't use it.
After alot of digging around I finally found a solution:
Open regedit and look for the following:
HKLM\System\CurrentControlSet\Policies\Microsoft\FVE!RDVDenyWriteAccess
HKLM\Software\Policies\Microsoft\FVE!RDVDenyCrossOrg
Set them to 0 and see if it gets you anywhere!!! worked a treat for me.
These are the ramblings of a 30 something (going on 60) year old disgruntled IT Professional. This is gradually evolving into a Windows SCCM blog but there's a bit of "me stuff" in here too as I like to write so have a look at some of my work. Please feel free to leave a comment...
Showing posts with label USB. Show all posts
Showing posts with label USB. Show all posts
Tuesday, 5 July 2016
Wednesday, 5 November 2014
Thursday, 30 January 2014
Operating System Deployment with USB Dongles (Lenovo in my case)
With the advances in technology we have seen in recent years, devices have become smaller, thinner and lighter than ever before.
With this we are finding that some devices are loosing functionality - ie. Some devices are having ports omitted to retain their slender profile.
The Lenovo X1 Carbon adopted this approach and required a USB dongle which I posted about the pitfalls of PXE boot here: Lenovo X1 PXE Issues
I've seen an increase in the issues these dongles are causing us deployment techs, one of those being that each of these dongles have their own MAC address. In true tech style when we see this new wizardry the first thing we say is "MINE"... Well actually the first thing we normally say is "Ooh Shiney" but then there's a Smeagle like "My Precious" when we claim the Shiney as our own.
I did this. I had my very own dongle. It worked great. ONCE! Every subsequent build failed. I did a bit of research and found that it had it's own MAC that was registering in SCCM so I had to surrender my Shiney and give it on to the user.
I now use the supplied dongles for each build as it isn't worth the trouble but I have it on good authority that with the latest gen of Lenovo kit they are shipping certain models with on-board NICs (therefore unique MACs) and the dongle is purely a port extender utilising USB to present an Ethernet port.
If you have fallen prey to this (and insist on using one dongle to rule them all) you need to read my earlier post to search SCCM for machines by their MAC address.
Have fun...
DocN
With this we are finding that some devices are loosing functionality - ie. Some devices are having ports omitted to retain their slender profile.
The Lenovo X1 Carbon adopted this approach and required a USB dongle which I posted about the pitfalls of PXE boot here: Lenovo X1 PXE Issues
I've seen an increase in the issues these dongles are causing us deployment techs, one of those being that each of these dongles have their own MAC address. In true tech style when we see this new wizardry the first thing we say is "MINE"... Well actually the first thing we normally say is "Ooh Shiney" but then there's a Smeagle like "My Precious" when we claim the Shiney as our own.
I did this. I had my very own dongle. It worked great. ONCE! Every subsequent build failed. I did a bit of research and found that it had it's own MAC that was registering in SCCM so I had to surrender my Shiney and give it on to the user.
I now use the supplied dongles for each build as it isn't worth the trouble but I have it on good authority that with the latest gen of Lenovo kit they are shipping certain models with on-board NICs (therefore unique MACs) and the dongle is purely a port extender utilising USB to present an Ethernet port.
If you have fallen prey to this (and insist on using one dongle to rule them all) you need to read my earlier post to search SCCM for machines by their MAC address.
Have fun...
DocN
Wednesday, 26 June 2013
Creating a Windows 2 Go USB device
So our IT Director managed to break his Windows 2 Go (W2G) pen I created for him a few months back. I kicked myself that I hadn't blogged the steps back then so as I've had to recreate it I'm taking the opportunity to blog it now.
The Windows 8 W2G GUI didn't let me see my .wim - I'm guessing this is due to the size of it. I opted to build it via Powershell which worked a charm.
I used a Windows8 wim that I'd captured from our corporate build - I already have this so this is one of my assumptions that you will have it too.
I also have an approved Windows 2 Go USB pen (Kingston DataTraveler Workspace 32GB)
These are the devices currently supported by Microsoft:
Also you will need to change your BIOS boot order to boot to USB first.
Instructions
Assumptions:
2. The following commands will prepare your USB device to be used with W2G. Type them in the Powershell window:
3. Now we need that Windows 8 image. For the sake of this example we'll say the image is on C:\ and it's called windows8.wim.
We will use DISM (Deployment Image Servicing Management) to aplpy the image to the USB drive - it could take 30 mins or longer so time to sti back and enjoy a brew...
4. Now we will use BCDBOOT to move the boot componants to the sys partition.
W:\Windows\System32\bcdboot W:\Windows /f ALL /s S:
5. To prevent the native HDD from being fired up whilst within W2G we need a policy in place. Here's one I prepared earlier - copy the san_policy.xml file to the root of your USB device: http://sdrv.ms/149ZHV1
6. Apply the policy file we just created by running this command:
Dism.exe /Image:W:\ /Apply-Unattend:W:\san_policy.xml
7. Create an answer file (unattend.xml) that disables the use of Windows Recovery Environment with Windows To Go. You can use the code from the sample here to create a new answer file or you can paste it into an existing answer file (or just use the file itself):
8. Once the answer file has been saved, copy unattend.xml into the sysprep folder on the Windows To Go drive (for example, W:\Windows\System32\sysprep\)
Now boot to your new shiney Windows2Go boot device :)
docN
The Windows 8 W2G GUI didn't let me see my .wim - I'm guessing this is due to the size of it. I opted to build it via Powershell which worked a charm.
I used a Windows8 wim that I'd captured from our corporate build - I already have this so this is one of my assumptions that you will have it too.
I also have an approved Windows 2 Go USB pen (Kingston DataTraveler Workspace 32GB)
These are the devices currently supported by Microsoft:
- IronKey Workspace W300 (http://www.ironkey.com/wtg)
- Kingston DataTraveler Workspace for Windows To Go (http://www.kingston.com/wtg/)
-
Spyrus Portable Workplace (http://www.spyruswtg.com/)
We recommend that you run the Spyrus Deployment Suite for Windows To Go to provision the Spyrus Portable Workplace. -
Spyrus Secure Portable Workplace (http://www.spyruswtg.com/)
Important You must use the Spyrus Deployment Suite for Windows To Go to provision the Spyrus Secure Portable Workplace. For more information about the Spyrus Deployment Suite for Windows To Go please refer to http://www.spyruswtg.com/. -
Super Talent Express RC4 for Windows To Go
Super Talent Express RC8 for Windows To Go
(http://www.supertalent.com/wtg/) - Western Digital My Passport Enterprise (http://www.wd.com/wtg)
Also you will need to change your BIOS boot order to boot to USB first.
Instructions
Assumptions:
- You already have Windows 8 image (.wim) file - OOTB or captured.
- You have an approved USB device from the list above.
2. The following commands will prepare your USB device to be used with W2G. Type them in the Powershell window:
#The following command will set $Disk to all USB drives with >20 GB of storage
$Disk = Get-Disk | Where-Object {$_.Path -match "USBSTOR" -and $_.Size -gt 20Gb -and -not $_.IsBoot }
#Clear the disk. This will delete any data on the disk. (and will fail if the disk is not yet initialized. If that happens, simply continue with ‘New-Partition…) Validate that this is the correct disk that you want to completely erase.
#
# To skip the confirmation prompt, append –confirm:$False
Clear-Disk –InputObject $Disk[0] -RemoveData
# This command initializes a new MBR disk
Initialize-Disk –InputObject $Disk[0] -PartitionStyle MBR
# This command creates a 350 MB system partition
$SystemPartition = New-Partition –InputObject $Disk[0] -Size (350MB) -IsActive
# This formats the volume with a FAT32 Filesystem
# To skip the confirmation dialog, append –Confirm:$False
Format-Volume -NewFileSystemLabel "UFD-System" -FileSystem FAT32 `
-Partition $SystemPartition
# This command creates the Windows volume using the maximum space available on the drive. The Windows To Go drive should not be used for other file storage.
$OSPartition = New-Partition –InputObject $Disk[0] -UseMaximumSize
Format-Volume -NewFileSystemLabel "UFD-Windows" -FileSystem NTFS `
-Partition $OSPartition
# This command assigns drive letters to the new drive, the drive letters chosen should not already be in use.
Set-Partition -InputObject $SystemPartition -NewDriveLetter "S"
Set-Partition -InputObject $OSPartition -NewDriveLetter "W"
# This command toggles the NODEFAULTDRIVELETTER flag on the partition which
prevents drive letters being assigned to either partition when inserted into a different machine.
Set-Partition -InputObject $OSPartition -NoDefaultDriveLetter $TRUE
$Disk = Get-Disk | Where-Object {$_.Path -match "USBSTOR" -and $_.Size -gt 20Gb -and -not $_.IsBoot }
#Clear the disk. This will delete any data on the disk. (and will fail if the disk is not yet initialized. If that happens, simply continue with ‘New-Partition…) Validate that this is the correct disk that you want to completely erase.
#
# To skip the confirmation prompt, append –confirm:$False
Clear-Disk –InputObject $Disk[0] -RemoveData
# This command initializes a new MBR disk
Initialize-Disk –InputObject $Disk[0] -PartitionStyle MBR
# This command creates a 350 MB system partition
$SystemPartition = New-Partition –InputObject $Disk[0] -Size (350MB) -IsActive
# This formats the volume with a FAT32 Filesystem
# To skip the confirmation dialog, append –Confirm:$False
Format-Volume -NewFileSystemLabel "UFD-System" -FileSystem FAT32 `
-Partition $SystemPartition
# This command creates the Windows volume using the maximum space available on the drive. The Windows To Go drive should not be used for other file storage.
$OSPartition = New-Partition –InputObject $Disk[0] -UseMaximumSize
Format-Volume -NewFileSystemLabel "UFD-Windows" -FileSystem NTFS `
-Partition $OSPartition
# This command assigns drive letters to the new drive, the drive letters chosen should not already be in use.
Set-Partition -InputObject $SystemPartition -NewDriveLetter "S"
Set-Partition -InputObject $OSPartition -NewDriveLetter "W"
# This command toggles the NODEFAULTDRIVELETTER flag on the partition which
prevents drive letters being assigned to either partition when inserted into a different machine.
Set-Partition -InputObject $OSPartition -NoDefaultDriveLetter $TRUE
3. Now we need that Windows 8 image. For the sake of this example we'll say the image is on C:\ and it's called windows8.wim.
We will use DISM (Deployment Image Servicing Management) to aplpy the image to the USB drive - it could take 30 mins or longer so time to sti back and enjoy a brew...
dism /apply-image /imagefile:c:\windows8.wim /index:1 /applydir:W:\
4. Now we will use BCDBOOT to move the boot componants to the sys partition.
W:\Windows\System32\bcdboot W:\Windows /f ALL /s S:
5. To prevent the native HDD from being fired up whilst within W2G we need a policy in place. Here's one I prepared earlier - copy the san_policy.xml file to the root of your USB device: http://sdrv.ms/149ZHV1
6. Apply the policy file we just created by running this command:
Dism.exe /Image:W:\ /Apply-Unattend:W:\san_policy.xml
7. Create an answer file (unattend.xml) that disables the use of Windows Recovery Environment with Windows To Go. You can use the code from the sample here to create a new answer file or you can paste it into an existing answer file (or just use the file itself):
8. Once the answer file has been saved, copy unattend.xml into the sysprep folder on the Windows To Go drive (for example, W:\Windows\System32\sysprep\)
Note
Setup
unattend files are processed based on their location. Setup will place a
temporary unattend file into the %systemroot%\panther
folder which is the first location that setup will check for
installation information. You should make sure that folder does not
contain a previous version of an unattend.xml file to ensure that the
one you just created is used.Now boot to your new shiney Windows2Go boot device :)
docN
Thursday, 30 May 2013
HP DC7800 will not boot from USB Boot Pen
First model I came across in the roll out was a HP DC7800. My first task was to deploy our Windows 7 image and then check which drivers were missing.
I came to boot from USB by pressing F9 to get to the boot menu and choosing "USB"
My pen fired up and flickered away whiles loading the initial boot file. The progress bar galloped across the screen like a trusty steed on Derby Day until it reached the end and froze.
3 pens and 2 machines later I discovered there is a BIOS setting under security that required disabling: Data Execution Prevention.
As soon as this was disabled, subsequent boots worked like a charm.
I came to boot from USB by pressing F9 to get to the boot menu and choosing "USB"
My pen fired up and flickered away whiles loading the initial boot file. The progress bar galloped across the screen like a trusty steed on Derby Day until it reached the end and froze.
3 pens and 2 machines later I discovered there is a BIOS setting under security that required disabling: Data Execution Prevention.
As soon as this was disabled, subsequent boots worked like a charm.
Wednesday, 10 October 2012
Create a bootable USB pen for SCCM Windows 7 Build Deployment
If you are ever in a situation where deploying your OS by SCCM's more conventional methods (ie PXE or LAN based deployments) isn't feasable (bandwidth/no connectivity) then you can prepare a USB pen and deploy to machines via a USB boot.
I've found the SCCM built in method of making a USB pen to be quite unreliable so I opt for the manual method.
Just a few heads up first:
We are still using a drive letter "U:" so we want to type:
format U: /fs:fat32 /q YOU WILL LOSE EVERYTHING ON THE PEN HERE
Enter a label for the drive - this is how it will show in "Computer"
I copy the files manually - it works - but if you want to do it "properly" use this command:
In command prompt navigate to the location of your build files - this is what would have been extracted from the ISO that was produced in SCCM when you "Created Removable Media" from the OSD task sequence - if you need a guide on this mail me or leave a comment...
Type xcopy\*.* /s/e/f \
With our extracted ISO in C:\Win7Build and our pen being U:\ This would look like:
Type xcopy c:\Win7Build\*.* /s/e/f U:\
Don't forget you may/will need to adjust the boot order in the BIOS to accommodate booting from USB - you can find a guide here: http://bit.ly/TvndIW
I've found the SCCM built in method of making a USB pen to be quite unreliable so I opt for the manual method.
Just a few heads up first:
- I'd recommend at least an 8GB drive but in reality your build (if corporate) will eventually exceed this.
- The pen will be totally wiped clean - all data will be lost.
- Open command prompt
- Type diskpart and press enter
- Type list disk and press enter
- Find your disk in the list
- Type select disk * (* being your number)
- Type clean and press enter - you should see "DiskPart succeeded in cleaning the disk."
- Type create partition primary and press enter - you should see "DiskPart succeeded in creating the specified partition."
- Type select partition 1 and press enter - you should see "Partition 1 is now the selected partition."
- Type active and press enter - you should see "DiskPart Marked the current partition as active."
- Type assign and press enter - you should see "DiskPart successfully assigned a drive letter ..."
- Type detail disk and press enter. For this example we will work with a drive letter "U" for USB
- Type exit to leave the Diskpart command and return to a standard prompt
We are still using a drive letter "U:" so we want to type:
format U: /fs:fat32 /q YOU WILL LOSE EVERYTHING ON THE PEN HERE
Enter a label for the drive - this is how it will show in "Computer"
I copy the files manually - it works - but if you want to do it "properly" use this command:
In command prompt navigate to the location of your build files - this is what would have been extracted from the ISO that was produced in SCCM when you "Created Removable Media" from the OSD task sequence - if you need a guide on this mail me or leave a comment...
Type xcopy
With our extracted ISO in C:\Win7Build and our pen being U:\ This would look like:
Type xcopy c:\Win7Build\*.* /s/e/f U:\
Don't forget you may/will need to adjust the boot order in the BIOS to accommodate booting from USB - you can find a guide here: http://bit.ly/TvndIW
Subscribe to:
Posts (Atom)