Group policy and access connections?

Is it possible to disable this option:
Control Panel -> Lenovo Internet connection -> Switch to advanced -> tools tag -> global settings -> allow wifi to be turned off when inactive (disable)
I already tried with the acplgin50.exe -> Tvtacad.adm but I don't have the option.

Try going back to AC 4.52, which solved the problems i was having with AC5.02 (freezes, BSOD, loss of wireless connections when coming out of standby, GUI problems) on Vista Home Premium.  Scroll down for prevous versions of AC5.02 here:
http://www-307.ibm.com/pc/support/site.wss/document.do?lndocid=MIGR-67283
 I do not use a VPN system so AC4.52 may not help your 3500 Thinkpads.
Lenovo (Mark_Lenovo) knows there are problems with AC5.02 for the last three (or more ) months and have stated that AC 5.1 will solve the problems, but it has not been released as far as I know. There are many threads on AC5.02 on this forum and also on thinkpads.com
the Lenovo Blog site also has an update on AC5.02 ;under "Design Matters" on how they selected the graphics for wireless connections - the responses there offer some suggestions to fix the problems. 
T60: 6371-CTO, VISTA Home Premium+SP1, 2GB....R51: 1836-Q4U,XP,1GB...600...755CD

Similar Messages

  • Group Policy and GroupWise Attachments

    My company uses the "Run only allowed Windows Applications" feature from Group Policy to lock down what can be run on our workstations. We have 2 main policies, a standard (lockdown) policy and an admin (open) policy.
    Ever since a 7.0.2 GroupWise client/server upgrade, under my lockdown policy some of my users have complained that when they click the attachment button in GroupWise it no longer goes to the location of the last attached document, instead it goes to a default location. It might be the D drive, the GroupWise directory, it changes from computer to computer. I have confirmed that this is the behavior of the lockdown policy, and when I switch to the open policy the attachment button goes to the previous attachment location as is expected.
    I've placed addrbook.exe, grpwise.exe, gwmailto.exe, gwreload.exe, gwsync.exe and notify.exe in my allowed list for executables and can't figure out what I might be missing. In the past I ahve found OCX and DLL files that have had to be specifically added to the policies as well to get certain functions to work, is it possible that this may be the case in my situation or could it be a completely different policy that I should be looking at?
    I'm getting ready to push the 8.0.2 clients to my users and this is something that I'd like to try to resolve before I do that push. Thanks!

    I just tore apart my group policy and found that using the Hide These Specific Drives and hiding the C: drive is what is causing this attachment behavior issue. Any ideas why it is causing this and any possible work arounds other than unhiding the C: drive?

  • How can I deploy EFS using Group Policy and automatically encrypt computers for ALL users who login?

    How can I deploy EFS using Group Policy and Active Directory with a goal to automatically encrypt computers for ALL users who login? (NOT an option for me to use BitLocker)
    I was asked to deploy EFS to encrypt the user my documents folder and profile on all of the users laptops. The laptops are in common areas (board meeting rooms, etc) and security of files is a must.
    I successfully created a recovery certificate in AD. I created an OU and setup an EFS policy and users can now login and select to encrypt their own files. The issue is that management would like to have automaticy Encrypt ALL users my documents AUTOMATICALLY
    when a user login.
    Can this be done?
    Please help

    Hi,
    Any update?
    Just checking in to see if the suggestions were helpful. Please let us know if you would like further assistance.
    Best Regards,
    Andy Qi
    TechNet Subscriber Support
    If you are
    TechNet Subscription user and have any feedback on our support quality, please send your feedback
    here.
    Andy Qi
    TechNet Community Support

  • MSI Package Software Installations and uninstallations by group policy and sccm

    Hi,
                I have a domain comprising approx. 30 ADCs, 5000 clients and 50 OUs. Our developers have created a c# Program for fetching some information from client machines and displaying them on their
    screen on bootup (presence of 2 particular softwares, antivirus presence and its update date, OS patches updation etc... ). This program(.msi) and .net framework 4.0 is required to be pushed to all client machines. We have SCCM server through which we can
    push software to be installed on clients. There are no. of ADCs for controlling different sites and OUs. Now I need to push this msi and .net framework to all clients. Dotnet  framework I pushed from SCCM & it is successful.
    Till today I have pushed this .MSI package using Group policy software installation settings using a local sharepath & sysvol.
    In Local Share path , MSI source is availbale at only one ADC and all clients  contact this adc only to install software and its taking very long time to boot.
    Using Sysvol share path , MSI Source is available at All ADC and All Clients Contact their Site's ADC to install software.Only Win 7, win 8 machines are getting install and software is  not able to install on XP and vista machine. What might be the
    problem for xp machine getting it from sysvol path?
    The error for XP machines is that Sysvol path is not accessible/ source is not available.
       Now I need to have some other fullproof method to apply it. How I need to push this .MSI packages to all sites (ADCs) in my child domain from my PDC.
       I want to know the steps & methods for installing & uninstalling this .MSI package using Group policy and SCCM as well.
       Thanks for replying...

    Hi,
    Based on your description, I want to confirm whether we have more than one domain. If we have more than domain, it is suggested that we can push the
    MSI package from each domain.
    Regarding how to use Group Policy to remotely install software, the following article can be referred to for more information.
    How to use Group Policy to remotely install software in Windows Server 2008 and in Windows Server 2003
    http://support.microsoft.com/kb/816102/en-us#method1
    In addition, you also mentioned how to use SCCM to do this, in order to get better assistance, we can ask help in the following SCCM forum.
    System Center Configuration Manager
    http://social.technet.microsoft.com/Forums/systemcenter/en-US/home
    Best regards,
    Frank Shen

  • Group-Policy and Inheritence

    I have a Group-Policy created with all the attributes that my SVC clients should be using -- this GP is called GP-SVC.  My client wants to add different access-levels for different sets of users.  I would like to do this by having three new Group-Policies inherit attributes from GP-SVC, except for the VPN Filter ACL which will be different on each of these "child" GP. 
    So here is how I want inheritence to work:
    DfltGrpPolicy
    |
    +-- GP-SVC
           |
           +--GP-SVC-Users
           +--GP-SVC-Devs
           +--GP-SVC-Admins
    But for some reason, its not letting me choose a group to inherit attributes from for my child GPs:
    asa5505#    show run group-policy GP-SVC
    group-policy GP-SVC internal
    group-policy GP-SVC attributes
    dns-server value 172.17.96.181
    vpn-tunnel-protocol svc
    split-tunnel-policy tunnelspecified
    split-tunnel-network-list value SPLIT-SVC
    default-domain value something.local
    split-dns value something.local
    address-pools value SVC-POOL
    asa5505(config)# group-policy GP-SVC-Users internal ?
    configure mode commands/options:
      from  Specify group to initialize attributes from
    asa5505(config)# group-policy GP-SVC-Users internal from GP-SVC
    ERROR: source group GP-SVC does not exist
    Anyone have any ideas as to what I'm doing wrong?  My goal was for the "child" group-policies to only have one attribute assigned, the VPN Filter, and for the rest of their attributes to be inherited from GP-SVC.
    My Device:
    Cisco Adaptive Security Appliance Software Version 8.2(5)3
    Hardware:   ASA5505, 512 MB RAM, CPU Geode 500 MHz

    Hi jcarvaja
    Looks like you're right.  Strange that it errors out:
    student10#  show run group-policy
    group-policy PARENT internal
    group-policy PARENT attributes
    dns-server value 1.1.1.1 1.1.1.2
    vpn-access-hours none
    vpn-idle-timeout 111
    vpn-session-timeout 111
    split-dns value one.com one.one.com one.one.one.com
    student10#
    student10# conf t
    student10(config)# group-policy CHILDa internal from PARENT
    ERROR: source group PARENT does not exist
    student10(config)#
    student10(config)# show run group-policy
    group-policy PARENT internal
    group-policy PARENT attributes
    dns-server value 1.1.1.1 1.1.1.2
    vpn-access-hours none
    vpn-idle-timeout 111
    vpn-session-timeout 111
    split-dns value one.com one.one.com one.one.one.com
    group-policy CHILDa internal
    group-policy CHILDa attributes
    dns-server value 1.1.1.1 1.1.1.2
    vpn-access-hours none
    vpn-idle-timeout 111
    vpn-session-timeout 111
    split-dns value one.com one.one.com one.one.one.com
    student10(config)#
    So it creates the CHILD GP, but it only copies the configurtion, doesn't truly inherit.  Which is to say, if I make a change to the parent group, it is not replicated to the child:
    student10(config)#
    student10(config)# group-policy PARENT attributes
    student10(config-group-policy)# dns-server value 3.3.3.3
    student10(config-group-policy)# exit
    student10(config)# exit
    student10#  show run group-policy
    group-policy PARENT internal
    group-policy PARENT attributes
    dns-server value 3.3.3.3
    vpn-access-hours none
    vpn-idle-timeout 111
    vpn-session-timeout 111
    split-dns value one.com one.one.com one.one.one.com
    group-policy CHILDa internal
    group-policy CHILDa attributes
    dns-server value 1.1.1.1 1.1.1.2
    vpn-access-hours none
    vpn-idle-timeout 111
    vpn-session-timeout 111
    split-dns value one.com one.one.com one.one.one.com
    I guess I have my answer then, the "from" keyword is to simply copy the settings from another group-policy, not set up a parent-child relationship.
    Thanks for your help, Jcarvaja.  I'll mark your respone as the answer.

  • Group Policy Service Access denied

    Hi,
    i had a working Azure RemoteApp deployment with custom image.
    From one day to another the users couldn't login any more with the attached Error Message (German), saying the access is denied because of an error logging in at the Group Policy Client Service.
    That's the second time I get this error in an RemoteApp deployment which was working for weeks before.
    I hope somebody has a quick answer as I have a customer presentation tomorow on this system.
    Thanks
    Bernd

    Hi Bernd, if you're getting an error message like that which isn't very useful then you'll need to seek assistance from Azure Support (http://azure.microsoft.com/en-us/support/plans/). 
    They have a process for seeing what's going on in the backend of our service for your Azure subscription and escalating to the right people as needed. This will both get you unblocked and help us determine where we might have bugs or can at least provide better
    error messages.  That said, given you're looking for a quick fix, it looks like there are a bunch of suggestions online for how to fix this error message (e.g.
    http://answers.microsoft.com/en-us/windows/forum/windows_vista-security/group-policy-client-service-failed-the-logon-help/20fb861a-49dd-4859-b903-492e65b43d52).  My best guess based on the limited info is that your domain controller is intermittently
    unavailable or you've customized something in the default profile of your template image which is causing issues. Apologies for the inconvenience.

  • Vista SP2 and Access connections requiring manual reconnect

    Hi,
    I'm experiencing a problem after the installation of Windows Vista SP2 on my Vista Business. After a reboot, I must always manually 1) disconnect the WLAN connection and then 2) reconnect to establish a working WLAN connection and to gain access to Internet. Before I disconnect, the WLAN connection is alive, but I cannot access any websites. Everything worked just fine before installation of SP2.
    I'm running Access connections version 4.42 on Thinkpad R61. I've read that someone has had a similar problem with wired LAN and with newer version of Access connections: http://social.technet.microsoft.com/Forums/en/itprovistasp/thread/17ba267e-0bb1-4621-b81f-04afa0d806...
    Does someone know how to solve this issue and make the connection to work without a manual disconnect -> reconnect step?
    BR,
    Miika

    After some searching, I found a working solution:
    http://www.darthcontinent.com/2009/05/no-internet-after-installing-vista.html
    Everything works fine now.

  • Group Policy Guru? Group Policy and Windows 7 erratic and inconsistant.

    (*If you don't feel like reading everything, skip to the bottom two paragraphs for my questions)
    I've had a premier call open with MS since August. This week I had a Microsoft Technician in-house.  Though we eliminated some possibilities, we're not really closer to a cause or solution.
    Every time we work with an expert, I get a different explanation to describe the situation we are viewing.
    Quick summery of the issue:  We've been using Group Policy to manage most Windows XP and 7 settings for years, but starting the middle of last year, we began having clients with machines where some or all group policies would fail to apply. 
    These could be long assigned policies, new polices, or changes to policies.  It would never affect everyone or even a majority at once, and the resolution is never the same.  Sometimes a GPUDPATE /FORCE sometimes fixed automajically the next day,
    sometimes (but very rarely) longer.
    Troubleshooting History:
    What we found in early troubleshooting, that these machines, had errors in Event Viewer for Netlogon, Time-Sync, and Group Policy.  The other issue we noticed, was that our GPRESULT /H reports were missing security groups and the denied section was
    nothing but SSID's.  The first issue pointed me to:
    Event ID 5719 and event ID 1129 may be logged when a non-Microsoft DHCP Relay Agent is used
    I installed these Hot Fixes.  No change to any of the errors in event viewer, or to our Group Policy problems.
    Initial work with Premier Support found that Netlogon, Time-Sync, and Group Policy, were failing before loading of the network stack.  The suggestion was to apply the group policy setting "Always wait for the network at computer startup and
    logon".  At the time, this seemed not to work.  The policy was set on a test bed of laptops and desktops, and no changes in behavior were seen after 3 days.
    Windows 7 Clients intermittently fail to apply group policy at startup
    For some time after this, we were collecting GPSVC and NetTrace logs for Premeir Support, trying to document and troubleshoot the problem.  Eventually we got fed up and asked our TAM to call in a pro to get this resolved.  We were sent an engineer
    for 3 days.  For three days we banged away on this issue.  We verified AD and replication health, we tried numerous fixes and workarounds.  I learned 3 different desriptions of how Group Policy works, and in the end we thought we had a workaround
    using the "Always wait for the network at computer startup and logon" because of a single success late in the day.  On day 3 we tried replicating this fix, and quickly realized that the same issue we were having preventing other GPOs to apply,
    were also preventing our "fix" GPO from applying.  So we went the route of using a registry entry.  I also had a problem that even though it was making the process more consistant, it was still taking 3 reboots for a Computer Policy, assigned
    to a computer object via Security Group, to fully take affect on a computer.
    I used the registry methods in the above article.  It didn't work, no sign it was having the same affect the GPO had had.
    Our support engineer claimed this was the proper method, but that path wasn't even close in a Windows 7 SP1 registry, and after creating all the keys that were not present, it still didn't work.
    Always wait for the network at computer startup and logon - AzureWeb
    We ran out of time, our engineer returned home.
    I can understand how these errors indicate a problem applying Group Policy at boot.  But to me it doesn't explain why it doesn't correct post boot, and after a GPUDPATE /FORCE and a reboot.
    It also doesn't explain why we were working fine for years, then all of a sudden DHCP is being outrun by background services.  (By the way logging showed DHCP wasn't significantly delayed, out boot process was actually excellent, health wise.) 
    Why all of a sudden is this not behaving optimly?  No changes to network design or function.  No changes to the domain since 2008 R2 was installed in 2011.
    Today I'm reading through all these KB's and articles again, and took some time to read:
    [Forum FAQ] Common steps to start troubleshooting Group Policy
    application and it's links below.
    We ran though all of that before and during the 3-day onsite.  It's not getting us any closer to the cause or a solution.
    I found and begin some deep reading in this link today.  It has some additional information I will try to use next week:
    Group Policy Basics - Part 3: How Clients Process GPOs
    The one unanswered question I have is this.  How is group policy supposed to apply to a computer, when that policy is applied to a AD Security Group, in which the computer object is a member?
    Before we began having this problem, we would assign a computer GPO, then ask the user to reboot.  If it were a user GPO, we'd ask the user to log off, or reboot.  Either way, if we allowed a few minutes for AD and FRS replication, the user would
    log back in with that new policy in affect.  A new imaged machine would boot with all the GPO's linked to that domain and assigned to "Authenticated Users", already in affect.  Admin groups would be present in administrators, proxy settings
    would be set in Internet Explorer, etc.
    Now I'm aked to beleive this was never the case from Premeier Support and Microsoft Engineers.  That those policies require the equilent of a "GPUPDATE /FORCE" that was executed by the Local_System account.  That 3 reboots may
    be nessessary for a group policy to be applied.  One for the AD Security Group to be applied.  One for the Computer Policy to be applied.  And a final one for the policy in the GPO to be applied to Windows.
    Can someone confirm or correct this information please?  It's imperitive to my troubleshootng.
    There's no place like 127.0.0.1

    That key is empty on all of my machines I have checked today.  Working and problematic alike.
    GPRESULT logs, when ran as me, historically would show the group polices applied, denied, and the AD group membership all by name.  About 6 months ago I noticed this changed.
    Now they show the applied GPO's by name, a few of the denied GPO's by name, most by SID, and only 2 to 3 AD groups, though PowerShell shows all the AD groups assigned.  This happens after several AD security and distribution groups are added to the
    machine (Radia software distribution uses Dist groups to assign software).
    A check showed no groups with long legacy Kerberos keys.
    When we make a change to AD Security Group membership, to assign or deny a Group Policy, is usually when we encounter this problem.  It will usually fix itself in 24 hours of the machine being left up and running.  But no amount of GPUPDATE /FORCE
    and rebooting will cause the changes to take affect.
    During this time, the Group Policies will show assigned to the computer in the GPRESULT log.
    Yesterday I began looking into Spanning Tree configuration on our network being a possible cause for the boot up issues.  I'm waiting on responses from our Network group to confirm our configuration.
    There's no place like 127.0.0.1

  • Group Policy and Windows 8.1 questions

    I have a few group policy questions. Thanks in advance for taking a look.
    I’ve downloaded the Win 8.1/Server 2012 ADMX files. They look to  be the same file names as the Win 7 ADMX files. Can I copy them into the  PolicyDefinitions folder and still be able create GPOs for either win 7 or Win  8?
    If we use a windows 8.1 client with the GPO mmc to create the GPOs (instead of putting the ADMX files on the servers), will the GPO built from the win 8.1 client apply correctly even though its coming down from a DC that doesn’t have those ADMX files?
    Does it make a difference if the win 8.1 client we use to create/edit the GPOs is x64 or x86?
    We recently needed to add in an admx file for Lync 2013. I put the lync.admx file in the PolicyDefinitions folder on one DC. If we build the GPO from that server, when it replicates out to all the other DCs, does it matter that they don’t have that particular
    ADMX file for lync?
    How do we organize and structure our ADMX files wherever they end up so that we know which sets are for which operating system? Should we be thinking about deleting the Win 7 ADMX files when the point comes in the future that we are using only Windows 8
    and Windows 9?
    We are at AD functional level 2003. Do we need to go up in level for any of this to work?

    >  1. I’ve downloaded the Win 8.1/Server 2012 ADMX files. They look to  be
    >     the same file names as the Win 7 ADMX files. Can I copy them into
    >     the  PolicyDefinitions folder and still be able create GPOs for
    >     either win 7 or Win  8?
    Yes. Simply overwrite and you'll be fine.
    >  2. If we use a windows 8.1 client with the GPO mmc to create the GPOs
    >     (instead of putting the ADMX files on the servers), will the GPO
    >     built from the win 8.1 client apply correctly even though its coming
    >     down from a DC that doesn’t have those ADMX files?
    Yes. GPO processing doesn't need ADMX, only GPO editing needs them.
    >  3. Does it make a difference if the win 8.1 client we use to
    >     create/edit the GPOs is x64 or x86?
    No.
    >  4. We recently needed to add in an admx file for Lync 2013. I put the
    >     lync.admx file in the PolicyDefinitions folder on one DC. If we
    >     build the GPO from that server, when it replicates out to all the
    >     other DCs, does it matter that they don’t have that particular ADMX
    >     file for lync?
    If you have a central store for your ADMX, it will automatically
    replicate through all DCs. If not, "2." applies anyway.
    >  5. How do we organize and structure our ADMX files wherever they end up
    >     so that we know which sets are for which operating system? Should we
    >     be thinking about deleting the Win 7 ADMX files when the point comes
    >     in the future that we are using only Windows 8 and Windows 9?
    If you use a central store, update it as required. If not, do nothing
    and use a client with the OS version you want to target.
    >  6. We are at AD functional level 2003. Do we need to go up in level for
    >     any of this to work?
    AD level doesn't matter in any aspect. Schema version matters (Bitlocker
    and Wireless, eg...), but you can update the Schema easily to 2012 and
    have your DCs still run Server 2003.
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

  • Presentation Director and Access Connections when Docking

    When I dock my machine, it automatically selects the right presentation mode because of the way that I configured Presentation Director.  It would be nice if it could automatically select the right Access Connection too.  Is this possible?  Is there a way to select docking actions like there is a way to select eject options?

    Hi,
    in case you update Access Connection, you must already have also following updates installed:
    - Power Management driver
    - Power Manager
    -Hotkey utility
    - System interface driver
    - Wifi driver <for AC 5.x it must be 13.x version>
    <all of course with the latest version>
    Once this all is installed, you can install AC .
    Let me know, if you have also the latest version of the above driver/updates on the system prior to the installation of AC .In case not, just remove AC, install the above mentioned updates and then install AC 5.x
    Chers

  • Wireless is missing from Fn+F5 and Access Connections

    Hi,
    I just installed a new harddrive on my T60 and restored WinXP from recovery DVD, everything seems to be work fine, I have upgrade Windows to SP3 plus all hotfixes, and updated ThinkVantage software to latest version using System Update 3. Today when I try to use WLAN I found a problem, there's no way to add a WLAN profile in Access Connections, I can choose Intel PRO/Wireless 3945ABG when creating new profile in AC, but after I clicked Next, I couldn't find any wireless SSID even though there is one active. The #3 dropdown (wireless mode) is also empty, the security property button is also grayed out, so I cann't proceed further.
    I thought this may be becuase wireless is turned off somehow, so I used Fn+F5, to my surprise there's no wireless in it! It only has Bluetooth. I do have Wireless Network Connection 2 in Windows' Network Connections, it's listed as Not connected, the hardware manager also shows the wireless NIC without any problem, so I think WIndows does recognize the wireless NIC, but for some reason Thinkvantage refuses to recognize it, any ideas?
    Thanks
    Jim
    Message Edited by su27k on 01-24-2009 07:40 AM
    Solved!
    Go to Solution.

    I solved my problem by uninstall and reinstall WLAN driver and AC (maybe other related drivers, don't quite remember). The sequence of uninstall/install is important, I think you need to uninstall AC first, and install it last.

  • Location Switching and Access Connections 5.62

    Under Location Switching, I enable the "Include Ethernet connections..." option.  I then see my profiles for LAN connections at the bottom of the list and I can checkmark them.  I can't however select them and change the order in the list.  Is there a reason for this?

    Hi,
    in your situation, could you please make sure, that following Windows Services are started:
    - Windows Zero Configuration
    - Windows Presentation Foundation
    - Terminal Services
    There are the services, that are fully needed for the correct workflow of Access Connection.
    Also please make sure, that you are using the latest version of following apps/drivers, which are also needed for AC to work correctly:
    - Power Manager
    http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-70602
    - Power Management driver
    http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-4GXPEG
    - Hotkey features
    http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-74261
    - .NET 2.0 + SP2
    Can you also tell me which exact  AC service is taking the most CPU ?
    Cheers

  • Latest versions of Power Manager and Access Connections got borked.

     I have a T60p running a fully patched XP SP2, model 2007CS3, and I work for IBM. I'm posting this because our internal IT support team has no clue how to fix this.
    I updated Power Manager to 1.52 when it had initially released, and since then it always fails with  an error in pwmuictl.dll, however the taskbar indicator is working properly. So I have to rely on Windows' built in power management only.
    Couple of days back I updated the ethernet drivers  to 9.12.41.1001 as in the latest package listed on the site.
    After that Access Connections 5.2 stopped working- the AcSvc service would fail on startup and subsequent restarts.
    I rolled back the ethernet driver to the previous version- uninstalled the device and reinstalled specifying the older drivers- to no avail.
    After a lot of struggle I downgraded it to version 4.23 that is used internally- and now my LEAP based wifi does not work. If I create a new connection profile- Access Connections craps out after filling in wifi security parameters. I reset my LEAP password  and tried again- it still does not connect.
    So effectively, updating the ethernet drivers turned out to be a big mistake. I hope someone can help, if you need additional information/screenshots let me know.

    Hello Martin,
    you have AC 5.02 instead 4.52 installed, like your screenshot shows.
    Some user have been experienced problems with this version and the version of new Powermanager.
    So if your system runs satisfactionally then there is no need to update.
    I would roll back and see if your program became operationally again.
    Kind regards
    Andreas
    Follow @LenovoForums on Twitter! Try the forum search, before first posting: Forum Search Option
    Please insert your type, model (not S/N) number and used OS in your posts.
    I´m a volunteer here using New X1 Carbon, ThinkPad Yoga, Yoga 11s, Yoga 13, T430s,T510, X220t, IdeaCentre B540.
    TIP: If your computer runs satisfactorily now, it may not be necessary to update the system.
     English Community       Deutsche Community       Comunidad en Español

  • Hit with Virus that executed via PowerShell Scripting. Can I disable Powershell on my network via Group Policy and what implications does that have for me.

    Our network was hit recently with virus previously unknown, O97M.Crigent.  It is a nasty Macro virus that targets Microsoft Office Documents & Spreadsheets and uses a combination of Macros and Scripts via Powershell. 
    How do I disable PowerShell scripting via Group Policy?
    Will this raise any issues such as random application or network failures or other issues?
    Can I apply it to the entire domain or should I be selective and only apply it to the workstations?
    Network Summary: Windows 2008 Active Directoy Server, 75% Windows 7, 25% Windows XP workstations.
    DouglasOfSanMarcos

    Disabling Windows PowerShell can be done with GPO:
    Computer Configuration | Administrative Templates | Windows Components | Windows PowerShell
    From GPO Description: "This setting exists under both "Computer Configuration" and "User Configuration" in the group policy editor. The "Computer Configuration" has precedence over "User Configuration."
    By default this option is restricted any way on computers.
    I would be very selective when apply it at all:
    Workstations - I would apply to test group of workstations first, just to see that there are no side effects before applying to all computers. 
    Server - I wouldn't apply it at all. I have seen too many issues when setting this policy on Exchange and other systems.
     If you are using a Group Policy to define a PowerShell logon, logoff or computer script, that script will disregard any execution policy set locally or through a GPO.
    http://4sysops.com/archives/set-powershell-execution-policy-with-group-policy/
    http://technet.microsoft.com/en-us/library/hh849812.aspx
    Please take a moment to Vote as Helpful and/or Mark as Answer where applicable. Thanks.

  • Group Policy and shortcuts

    ok imagine there is a company "x" that has a group policy which allows certain softwares to be executed  . In one department of this company , employs uses a certain program called "y" . One employ create a shortcut of this program
    on the desktop and when he tries to open it , a error message comes out which tell him that a policy which allows certain softwares is in use . Can someone explain to me what happened ? I know the group policy which allows certain softwares is in use but if
    he can use the program why he cant use the shortcut ? :/ 

    Am 04.02.2014 11:47, schrieb KristAlbania:
    > One employ create a shortcut of this program on the desktop and when he
    > tries to open it , a error message comes out which tell him that a
    > policy which allows certain softwares is in use .
    AppLocker or SRP? AppLocker has an event log that will tell you what
    exactly was blocked...
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))

Maybe you are looking for

  • How to use the distinct key in formula field in SAP Crystal Reports

    I want to use the distinct key in formula field in SAP Crystal reports. When i'm using it shows an error. Please suggest me....

  • T61p - IEEE 1394 (Firewire) port does not show up in device manager in Windows 7 x64

    I have a T61p.  On the front, in the left corner, right next to the wireless on/off switch, is a IEEE 1394 (Firewire) port.  However, if I plug anything into it, it's not recognized by Windows, and if I go into the device manager in Windows, there is

  • Missing EUS_EDir.jar file

    Hello I have installed the following components: Component Version Oracle WebLogic Server 11gR1 (10.3.6) Oracle Identity Management 11g Patch Set 6 (11.1.1.7.0) for Linux x86-64 I am now trying to integrate OVD with EUS for users stored in Novell eDi

  • Interactions in Captivate 7 don't save

    When I build an interaction in Adobe Captivate 7 it remains there while I am in the file, but once I save and close the interaction defaults back to the original information.  How can I save this and go back for editing long term?

  • Should I get a brand new battery or just get a new player??

    I have an ipod mini I recieved almost 3 years ago. It now hardly holds a charge for 3 hours (maybe less). I bought a new nano, but now I'm thinking of selling it and getting a new battery for the mini. Except for a few nicks and a the lack of battery