ChrisH Posted December 19, 2007 Posted December 19, 2007 Some of the indirect ways of running of running IE have it run as system which can bypasses certain things. This is apparently improved with IE 7.
Gatt Posted December 20, 2007 Posted December 20, 2007 jcollings.. Run GPResults to make sure that the proxy settings are still being applied to the security group. If you have GPMC installed it should tell you what GPO is being applied.. We use SchoolGuardian and have a security group called G No Internet which blocks internet access to members of that group How do you apply the policy - are the users moved to another (sub-)OU or is the GPO set to only apply to the security group? We have a similar setup for denying USB drives where we have SUb-OU's in each Year's OU called "No Drives" - a GPo is then attached to this Sub-OU to disable pen drives and the "Enforced" flag is set.. Craig.
TheCrust Posted December 20, 2007 Posted December 20, 2007 On connecting to the room with netsupport we found the same user logged onto 3 machines Have a look at CConnect on the Windows server resource kit if you get a mo. We use this to restrict the maximum number of concurrent logons that will be accepted for any one student user ID. It also comes with a handy admin front end that shows you where the little scamps are logged on, and allows you to remotely log them off too.
Gatt Posted December 20, 2007 Posted December 20, 2007 On connecting to the room with netsupport we found the same user logged onto 3 machines Have a look at CConnect on the Windows server resource kit if you get a mo. We use this to restrict the maximum number of concurrent logons that will be accepted for any one student user ID. It also comes with a handy admin front end that shows you where the little scamps are logged on, and allows you to remotely log them off too. Other than LimitLogin - is there a non RM equvelant to this?
Ryan Posted January 24, 2008 Posted January 24, 2008 I create a sub OU (not internet access) with a new GPO and enter false proxy server settings. then under User Config/Admin Template/System/Don't Run Specified Windows Applications (add iexplore.exe, firefox.exe and firefoxportable.exe) to the list. Also make sure that the user cannot logon if their profile fails to load (ie student may remove network cable during logon so that GP settngs are not applied) Comp Settings/Admin Templates/System/User Profiles/ Log User off when roaming profile fails Wow, just tried this (as we wanted to block a couple of little darlings from all web activity due to misuse while letting the rest carry on) - works perfectly. Nice one. I thought this'd be a huge operation, but all i need to do is drop them into the sub OU that denies the above - sweeeeet.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now