WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby Karthigan » 15.03.2016, 13:31

Hi All,

I have a question: does WOUTempAdmin A/C created when you select "auto-login / reboot" option when running UpdateInstaller, does it not work for domain-joined (AD) laptops?

Our environment is unique, in which we have a "legal" login disclaimer that the user must acknowledge (click on the OK) button prior to logging into the Windows Environment, plus, our login format for user name is (as an example): thecompany.net\jsmith, password: Password123$

Is there anything that I can accomplish to fix the login issue? Or should I proceed with the local admin A/C for manually running the UpdateInstaller program?
Karthigan
 
Posts: 10
Joined: 02.03.2016, 14:43

Re: WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby Karthigan » 17.03.2016, 04:14

Hi again,

It appears that the auto login is working on a AD domain joined laptop with the WOUTempAdmin account that is created by the WSUS tool.

Now, I only got it to work on one Lenovo T430 series laptop. Another identical one from another employee - it does not.

This leads me be believe that it has to do something with the Domain Configuration - our company has lot of GPOs (e.g. disable other A/Cs from having local admin authority - which would eliminate WOUTTempAdmin administrative access), possible auto-login disabled, complex password requirements or something else*

Question: does anyone know what the auto generated password for the WOUTTempAdmin A/C is?

If anyone was able to deploy this tool on a domain joined laptop in their environment - any feed back would help.

I am going to work with my System Administrator and rule out one GPOs at a time (Group Policies) - perhaps one would trigger the failure and I'll know what it is.
Karthigan
 
Posts: 10
Joined: 02.03.2016, 14:43

Re: WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby WSUSUpdateAdmin » 17.03.2016, 12:36

Hi.

Concerning the password for WOUTempAdmin, please see ...\client\cmd\CreateUpdateAdminAndEnableAutoLogon.vbs:

Code: Select all
  strResult = "!Wou_" & Int(90000 * Rnd) + 10000
  objWOUTempAdmin.SetPassword strResult

This probably may not match your password complexity rules, of course.

Regards
Torsten Wittrock
WSUSUpdateAdmin
Administrator
 
Posts: 2245
Joined: 07.07.2009, 14:38

Re: WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby Karthigan » 18.03.2016, 02:09

Thanks.

Just a follow-up: we started to deploy this tool across various other laptops that are AD domain joined, out of 4 laptops, 2 was able to auto-boot and auto-install, and 2 didn't.

Still looking into it. :)
Karthigan
 
Posts: 10
Joined: 02.03.2016, 14:43

Re: WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby aker » 18.03.2016, 09:20

@WSUSUpdateAdmin
Could we write WOUTempAdmins password to the command line or to the log, to be able to manually continue the update without having to cancel it?
Wer Rechtschreibfehler findet, darf sie behalten oder an den Meistbietenden versteigern. / Everybody finding a misspelling is allowed to keep or sell it.
aker

WSUS Offline Update „Community Edition“
https://gitlab.com/wsusoffline/wsusoffline/-/releases
aker
 
Posts: 3999
Joined: 02.03.2011, 15:32

Re: WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby boco » 18.03.2016, 11:45

I disagree. Writing the password of an account with Admin rights in clear text into a log that about everyone can read? Please don't (or only on request).

A better way would be to mail the password to an admin-configured mail address, using a command-line mailer (or a solution likely already present in A/D environments). That way the Admin, and only the Admin, could continue.
Last edited by boco on 18.03.2016, 12:23, edited 1 time in total.
Reason: typo
Microsoft update catalog: http://catalog.update.microsoft.com/v7/site/
Windows Install media download: https://support.microsoft.com/en-us/help/15088/windows-create-installation-media
boco
 
Posts: 2398
Joined: 24.11.2009, 17:00
Location: Germany

Re: WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby aker » 18.03.2016, 11:55

Then to cmdline on creation would be the best idea. The script has to be run as admin, so no security impact.
Wer Rechtschreibfehler findet, darf sie behalten oder an den Meistbietenden versteigern. / Everybody finding a misspelling is allowed to keep or sell it.
aker

WSUS Offline Update „Community Edition“
https://gitlab.com/wsusoffline/wsusoffline/-/releases
aker
 
Posts: 3999
Joined: 02.03.2011, 15:32

Re: WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby boco » 18.03.2016, 12:33

Yes, but... Upon restart the commandline will be closed. If admin returns and is faced with blocked login, the fact the password once was written to the commandline is, well, funny.

How about asking for the password (or source passphrase to generate a password hash) to be used for the WOUTemp account, upon checking the box? Would that be acceptable?
Microsoft update catalog: http://catalog.update.microsoft.com/v7/site/
Windows Install media download: https://support.microsoft.com/en-us/help/15088/windows-create-installation-media
boco
 
Posts: 2398
Joined: 24.11.2009, 17:00
Location: Germany

Re: WOUTempAdmin: Does Not Login - RE: Domain Joined Laptops

Postby aker » 18.03.2016, 19:46

The first run doesn't take that long; it would be OK to wait for the output. But a TextBox would solve the problem in a nice way, too.
Wer Rechtschreibfehler findet, darf sie behalten oder an den Meistbietenden versteigern. / Everybody finding a misspelling is allowed to keep or sell it.
aker

WSUS Offline Update „Community Edition“
https://gitlab.com/wsusoffline/wsusoffline/-/releases
aker
 
Posts: 3999
Joined: 02.03.2011, 15:32


Return to Installation / Updating

Who is online

Users browsing this forum: Google [Bot] and 34 guests