This message was deleted.
# citrix-vad
s
This message was deleted.
k
if you have cache in ram I think that is harder to tell but you can use some of the Sys internals tools
d
cache in ram with overflow. and overflow file is filling up cache drive
s
i've used the nirsoft tool 'folderchangesview' before and it worked well.
n
Nirsoft truly does have a utility for everything.
βœ… 1
Never used it before, but that FileActivityWatch utility may also work well for this case.
j
FWIW, last time I was bit by this it was https://support.citrix.com/article/CTX338425 NTFSDisableLastAccessUpdate due to outdated Citrix Optimizer in my seal process
s
interesting, wish they would have included specific versions
oh it's the value, not the version
n
Interesting. I swear that was an old requirement in App Layering.
My image still has that disabled.
j
Procmon with writefile filter
Writeconfig filter as well
d
looks like NTFSDisableLastAccessUpdate is set correctly. 😞
but a bunch of other things are not optimized
yea just checked another machine. 30GB vdiskdif πŸ€¦β€β™‚οΈ
and no changes to C drive either. same size as at boot
j
cm/branch cache? That has bitten me when cm clients were updated before
d
yea checked that too. it was enabled once before but now its disabled.
and yea its totally inconsistent I have been sitting look at the server and zero change to cache. I am guessing this is happening in spurts
s
AppV? Print Spooler? Tanium? the folderchangesview program should be able to pin point, especially if it blows up quickly
the slow spurts are harder to see, however you can log the changes in excel format to the write-cache drive or somewhere else
d
could be appv. how would I tell?
s
you pointing the shared content store to your writech cache drive?
d
nope
s
think that was always a big one
j
how did you disable branch cache? PS:\Disable-BC? Regedit, service disable? if so, know that when CM client checks in it may reenable it. I can check with my CM guy, but I think you need to configure BC in CMC for it to be disabled
d
let me check branch cache from VDA
I asked the sccm guys to disable it when I saw it was on earlier this year.
j
perfect
d
looking for folderchangesview....
@Steve Noel folderchangeview saves the day. its
only question is wtf is it downloading
s
windows updates disabled?
d
ha πŸ™‚ they are not. It uses defender so I think killing updates would stop defender upd as well
s
ah, hmmm, well at least we are on the hunt
d
also question is why are the updates 10s of GB?
i can see cache filling up in front of my eyes πŸ˜„
s
is there a 'delta' checkbox for how you receive updates?
d
probably not. I think I see what is going on. its failing on a rollup update and looks like it keeps retrying
s
nice, there ya go
d
and there are a bunch of other updates too that are included. Visual Studio even
ok well mystery solved. Now just need to figure out the updates. Thanks again @Steve Noel. Your help was HUGE.
🀘 4
s
think i remember @Nick Panaccio or @Ray Davis talking about Defender best practices for non persistence, kind of a bunch of documents cobbled together if i remember correctly.
d
yea I had that in the back of my mind as well. but never got around to it since defender by itself never consumed that much space
r
Yea we have it if needed.
I downloaded "folderchangesview" about 2 months ago, and security was all over me like stink on poop. it flagged something in their scanners. But yea they have some great tools.
πŸ˜„ 1
j
nice! that's a "walk off win" on a friday!
πŸ‘ 1
n
Yeah, I would definitely change your Defender update settings so that Windows Update and Microsoft update are last in the list. If you're looking for a way to simply prevent windows update from working entirely in a non-persistent image, let me know. I changed methods recently and it has been flawless for me.
d
@Nick Panaccio definitely interested in redesigning Defender updates in non persistent settings. Let me know how I can obtain some of that knowledge πŸ™‚
n
This thread has all of the details, I think: https://worldofeuc.slack.com/archives/CLSHNTWLW/p1653987969746889
And before Kasper says it, yes, I feel bad about not just writing a blog about it.
πŸ˜‚ 1
s
lol
n
If it can wait until Tuesday, I can tell you what I did for Windows Update blocking. Not in the office until then.
πŸ‘ 1
d
I dont see the thread. Probably because Unlock messages prior to June 6th in World of EUC To view and search all the messages in your workspace’s history, rather than just the 10,000 most recent, upgrade to one of our paid plans.
s
yeah, i had to search for it too
n
No worries, I think I have it written up in a Word doc, too. I can grab that on Tuesday.
πŸ‘ 2
Gonna write one blog, on Defender, and dedicate it to Kasper.
r
Hahaha. But it would get a lot of traction for sure.
n
Maybe I'll take the plunge and see if I can write one for mycugc.com
πŸ‘ 1
πŸ”₯ 1
⬆️ 1
d
what did I start πŸ˜„
r
Do it man. We all need it haha
j
From your Citrix Delivery Controller, run this script as a scheduled task, it will download the latest defender updates and create a share. Then modify your Citrix VDA GPO to point to that share for Defender updates. https://github.com/JonathanPitre/Scripts/tree/master/Get-MicrosoftDefenderUpdates
πŸ’― 1
πŸ™ 1
πŸ‘ 1
n
Windows Update blocking: Aside from disabling the Windows Update service via GPO, I also set the following items:
Basically, you're telling Windows Update to only use loopback for updates. This will prevent Defender updates from coming down, as well, which is why you also need to set the Define the order of sources... setting to both your local fileshare where the updates are downloaded to as well as MMPC, which is Microsoft's dedicated hosting site for Defender updates. It's usually a last resort option, as the downloads are larger in size, but it works fine for this method.
Also worth noting that this setting must be baked into your image, as it requires a reboot to take effect. I have it enabled via GPO just for enforcement, but I do bake it in with my sealing script:
Copy code
Write-Host "Updating Defender..." -ForegroundColor Yellow -NoNewLine
Start-Process "C:\Program Files\Windows Defender\MpCmdRun.exe" -ArgumentList "-RemoveDefinitions -DynamicSignatures" -Wait -PassThru | Out-Null
Start-Process "C:\Program Files\Windows Defender\MpCmdRun.exe" -ArgumentList "-SignatureUpdate" -Wait -PassThru | Out-Null
Write-Host " Done" -ForegroundColor Green

Write-Host "Scanning the image with Defender..." -ForegroundColor Yellow -NoNewLine
Start-MpScan -ScanType FullScan
Write-Host " Done" -ForegroundColor Green

Write-Host "Configuring Defender..." -ForegroundColor Yellow -NoNewLine
Set-MpPreference -SharedSignaturesPath \\<http://domain.com|domain.com>\Citrix\WDAV\wdav-update
Set-MpPreference -SignatureDefinitionUpdateFileSharesSources \\<http://domain.com|domain.com>\Citrix\WDAV\wdav-update
Set-MpPreference -SignatureDisableUpdateOnStartupWithoutEngine $False
Set-MpPreference -SignatureFallbackOrder 'FileShares|MMPC'
Write-Host " Done" -ForegroundColor Green
πŸ‘ 1
r
Great information @Nick Panaccio
d
to circle back to the original issue. The KB that kept trying to install over and over somehow corrupted WinSxS. I spent a long time running various dism restores before giving up and copying WinSxS from another image. There are others who are seeing similar problem with the update on reddit and microsoft support