ataylor Posted October 21, 2014 Posted October 21, 2014 Hi all, Having some trouble finding what is the best method to use. I have recently made a lot of changes to our group policy and how our user profiles are built but I am encountering a number of problems and would like some opinions on the best way to go about this. 1. How do you guys setup the user desktop/start menu, I have setup a mandatory profile which works pretty well and make our logins like 10x faster although whenever a user first logs onto a computer It will not map all of their network drives, If they log of and back on again all of the network drives will appear. 2. How does everyone deal with library's(My documents, pictures, etc)? I have attempted to disable them but it seems to be more trouble than what it is worth as many programs use my documents as a default place to save, meaning when they try to save it throws out an error. Thanks in advance.
mikkydoos Posted October 21, 2014 Posted October 21, 2014 (edited) 1. That is fairly normal. I get that too. 2. Are you using Folder Redirection ? Edited October 21, 2014 by mikkydoos
Arthur Posted October 21, 2014 Posted October 21, 2014 2. How does everyone deal with library's Folder redirection + editing the .library-ms files to point to the redirected folders.
RobD Posted October 21, 2014 Posted October 21, 2014 You can set the libraries in the mandatory profile, this guide is great: How to create a Mandatory profile with Folder Redirections - RobinHobo.com
ataylor Posted October 21, 2014 Author Posted October 21, 2014 Ok, thanks for the comments. I am playing around with the folder redirection now, just found if you delete the redirected documents, it dose not remap on next login unless the profile is deleted on that local machine. Also - what is the best method for restricting executable's? I am currently using "Run only specified Windows applications" It only allows files according to their name so essentially they could rename 'minecraft.exe' to 'chrome.exe' and it will launch but they have not figured that out yet. It does work pretty well for blocking a lot of the system programs though. The only issue is that it is causing driver installation problems if a student uses a USB stick.
Arthur Posted October 21, 2014 Posted October 21, 2014 what is the best method for restricting executable's? AppLocker, if you have the Enterprise edition of Windows. The only issue is that it is causing driver installation problems if a student uses a USB stick. Are the flash drives encrypted and require the student to run an executable in order to access the data?
jaminben Posted October 21, 2014 Posted October 21, 2014 1. Folder Redirection for Desktop, start menu is a folder on the redirected desktop (Windows 8 like it better) and mapped drives in GPP... ours appear on first logon. 2. Disabled them using Registry Hacks... not perfect but works.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now