Jump to content


janhoedt

Established Members
  • Posts

    16
  • Joined

  • Last visited

Posts posted by janhoedt

  1. Thanks for your reply.
    I just want to test that laptops "out of the box" will be TPM enabled during task sequence.

     

    Note: after some adaptations it does not work anymore. I wonder if xcopy.exe ".\Dell\CCTK\X86_64\*.*" "x:\CCTK\X86_64\" /E /C /I /Q /H /R /Y /S is correct whereas the package source points to ... \Bitlocker\Dell\CCTK\X86_64, should the xcopy then not be xcopy.exe *.* (without the path)?

  2. Hi,

     

    I used your task sequence for enabling bilocker on a Dell laptop (Windows 7x64) and it was working great!
    Then I explictely disabled the TPM on the Dell and restarted the task sequence as doublecheck and now the last step (enable bitlocker) failed(!).

    So, looking at this forum I wonder what I should do

    *when restaging a bitlockered machine, should I remove a recovery key first from AD?

    *Should I enable a Windows driver for bitockering (which one then)?

    ...

     

    Thanks for your input.

    Regards,
    J

  3. Hi,

     

    We need to enable bitlocker on a Dell laptop in a SCCM 2012 MDT task sequence. I haven’t configured bitlocker yet, so I’m trying to get the big picture here, therefore this post.

    I posted this item on technet forum then thought actually it belongs to Windows noob since here is the great aritcle coming from in the first place :-)

     

     

     

    So, what we have = working bitlocker config in another deployment framework (vbscript based) for this Dell laptop.

    What we will implement: this guide http://www.windows-noob.com/forums/index.php?/topic/3875-customising-windows-7-deployments-part-5/ .

    So as far as I can see:
    1.Use Dell Client Toolkit (CCTK)

    2.Create CCTK package on SCCM 2012

    3.Create bitlcoker script package

    4.rollout via task sequence

    Questions:
    *Is this a valid reference for deploying bitlocker with MBAM and are the steps I’m mentioning correct?
    *Where do you put this bitlocker in the task-sequence: @ the end or beginning, in the middle?

    *What about the WINRE (windows recovery partition for bitlocker), what’s the deal about this/how does that work?
    *Where is the recovery info stored, AD? How does this work?

     

    Please advise.
    J.

  4. Hi,

     

    I have SCCM 2012 sp1 with mdt integrated. I tried to change the keyboard of winpe by:

    *changing C:\Program Files\Micosoft Deployment Toolkit\Templates\Unattend

    _PE_x86.xml but that did not work. There is mentioned
    *using prestart command but there is already a wscript.exe Deploy\Scripts\ZTIMediaHook.wsf in my prestart, not sure what it does or howto chang that
    *using this guide: http://www.windows-noob.com/forums/index.php?/topic/2348-guide-creating-a-bootimage-with-another-keyboard-layout-winpe-3/ but did not work (get access denied and isn't it the windows pe it uses and not the mdt pe (which it should)?

    Please advise.
    J.
  5. Hi,

     

    I’m totally lost here.

     

    *You’re reverting to WSUS and policies for updates whereas the goal for SCCM 2012 is to do updates via the client, not use GPO anymore.

    *In SCCM 2007 you disable the WSUS policy, now you re-enable it again?

     

    Then, if not working with policies (what is the goal, I thought, now you’re handing out management to wsus again so you need sccm- + wsus-console):

     

    *In 2007 you created a “blank for staging” collection, you don’t create a here anymore?

    *If you don’t create the “blank for staging”, you could create autodeployment rules “critical updates windows 2008 R2”, “windows 2008 R2” etc, what would mean you download twice (critical updates are already in “windows 2008 r2”); you could then point in “critical updates” to “windows 2008 r2” but then you can’t see the hierarchy/dependency (f.e. if you would delete “windows 2008 r2”, all updates depending on it would be gone

    *in wsus you define what to download (products), then you need to define again in deployment the categories, but if wsus doesn’t download, what sense does it make to select a download that wasn’t done by wsus?

    *wsus downloads it and sccm downloads it again? Or sccm gets it from wsus, meaning it is the same content on two locations? What a waste of storage

     

    As mentioned: totally lost howto correctly configure.

    Please advise.

     

    J.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.