Jump to content

Recommended Posts

Posted

The little angels seem to have twigged that by pulling the network lead out during logon, they can interupt the group policy being applied and hence circumvent my software restriction policies. Doh, I knew they were being quiet.

 

The event log lists the interuption as:

 

Windows cannot obtain the domain controller name for your computer network.

(The specified domain either does not exist or could not be contacted. ).

Group Policy processing aborted

 

Is there a computer policy I can put in that will not allow logins unless group policy is implemented? Or any other ideas? (I'm not allowed to electrify the outside of the network cables)

 

Thanks as always

 

Phil

Posted
But if it was the first time the pupil logged on that machine, and logins are not cached it will download new settings each time you logged on and wont apply existing policies.
Posted

Yeah, we have had the little ruggers doing this trick - senior DT if caught doing it and letter home to mummy & daddy - so it doesn't seem to be happening much now. It doesn't help that this this trick is listed on some of the websites that list hacks and cracks for kids to use in schools, along with proxy redirection sites and all that malarkey.

 

Now, if I could only catch the little hickdead that keeps unplugging the usb cable to the printer in the library...

Posted
little gits aren’t they unplugging the USB cable, you should rig it up so they get an electric shock :D

 

Great idea but no, what I'm going to do is rig a rape alarm up inside so that when they open the panel to pull the usb cable out it pulls the pin out of the alarm and hopefully they wet themselves :twisted:

Posted
ISTR that if you set up a local computer policy to run a user logon script that logs you off (ie, local computer policy takes precedence as there is no network GP being processed, hence use local policy and run startup scripts)
Posted

I think somewhere in the GP there is an option to log users off if GP processing fails.

 

Try Computer -> Admin Templates -> System -> User Profiles -> "Log user off if roaming profile fails"

 

Craig

Posted

The answer is either super mandatory profiles, or by setting the GP to log off when roaming profile fails. If you also set the GP to delete cached profiles there should be no way in which they can get on without heving the correct profile, mandatory or roaming the same.

 

The microsoft documentation says that a super mandatory is just a matter of changing the profile folder to have the extension .MAN but I have not tried that yet as I cannot see how the computer would know if the user has not logged on before. Details of profile management can be found.

http://searchwinit.techtarget.com/searchWin2000/downloads/GroupPolch08.pdf

 

DC

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...