Jump to content

Recommended Posts

Posted

I think he was replying to you eejit lol

 

That should do it. BTW, I give full share and security permissions to Everyone on the driver share folder. No one knows it exists, and that way I know that the files will definitely be accessible by all.

 

What you could do is prevent directory listing - so that they can read/write but can't view the contents i.e. so even if they did manage to find the directory, they wouldnt be able to browse it :)

 

Regards

Nath

Posted
Right, I must admit that I always give full control to everyone for that kind of thing and deploying apps in AD. I'm never happy with the results of "sensible" permissions - i.e. read only - it just doesn't seem to work properly in my experience
Posted
eean - who was your post in reply to?

 

Sorry! It was a reply to

"Cheers for the link [novel thing], but it says "Grant Users and Power Users the ability to install USB mass storage devices." will that really allow users to add devices too?

Will test it shortly."

 

But I missed the second page, so I'm a bit behind. I've always been a bit special needs.

Posted
These are the files i use to allow all users write access on my CC3 RM network and it works a treat, these are adapted from messenger but should suffice. You should be able to adapt them to suite your system and use a gpo to push it out to the clients. Hope this works for you :)
  • 2 weeks later...
Posted

We add all users to the local admin group on all PC's, this lets users install all the USB devices they wish.

 

Then we let ranger do the locking down, dont have any problems with it this way.

Posted

@W32/Jbot: That doesn't sound like a sensible idea... this will allow those nasty IE-related toolbars and other crap to install itself. I know r

Ranger is quite good at locking down the machines but it isn't brilliant and won't stop some of these clever little things.

Posted

It all depends how much time you want to spend setting ranger up, they cant install any toolbars as they are all title check blocked.

 

I assume this is remarkable because i stated it works? Eejit please explain?

 

Besides which a desktop to be rangered is suposed to be configured in this way.

 

I have just taken this statement from the Rangersuite KB before you lot decide i should be hanged :lol:

 

"Please note that by adding the network domain users into the local power user or administrator group the inherent Windows security is being reduced or removed which is not recommended in environments without Ranger however because Ranger provided workstation security based on the users network group membership you can still enforce security over the user and prevent them exploiting this privilege and corrupting or changing the machine."

Posted
No, not remarkable because it works, but it seems to me a crazy thing to do. It just makes a load of extra work for you because of all the new locking down that you'll need to do.
Posted
in actual fact it makes for less work, things like the odd system file that poorly designed eduapps need access to dont get locked and cause us problems. USB devices work etc. i do hold my hands up and admit to actually questioning my NM about this in the first place, but if it works i can't argue with it can i?
  • 4 weeks later...
Posted

I am having problems with USB drives, when i log on as a teacher on some PC the USB drive works no prob, but on others it asks for the admin password.

 

We have a few different types of PC & we cant think what we have done different on the Image to make it not work.

 

The latest example is when we got 28 New PC & made 2 different Images (Admin & Class Room) which were started from fress 1 by me & 1 by another Technician, mine works ok for some reason but the other wants a PW every time, The head Technician thinks it could be due to a doggy slipstreamed automatic XP Installation CD?

 

I know we have the Driver signing to Ignore, we have allowed everyone to load & unload Device Drivers in group policy.

 

Could anyone help. (& sorry if i should have put this as a new Topic)

Thanks

Posted
Bit late but there's a script you can download from Novell's Cool Solutions site to fix the USB devices for non-admins.

 

http://www.novell.com/coolsolutions/tools/16306.html

 

Alas it doesn't fix the problem though Geoff. MS Certified drivers are fine and work no problems - but uncertified drivers can only be installed by administrators. Alas we find that kids sticking in devices that require uncertified drivers and trying to click through the permissions screen leaves the usb port in a sort of hung state where it becomes admin only for all drivers until you log in as admin and free it up again. IT staff and teaching staff are pretty exasperated with this - but days of googling have failed to produce a working solution :evil:

Posted

Ok SpuffMonkey, I can confirm that what you need to do is impossible according to Microsoft (BTW, not sure if you know that if you sign up to the Microsoft Partner program you can get some great free support as a registered member)

Have a read of my previous posts, but basically only signed drivers can be installed by non-admins via a network share.

Posted

Is this problem happening to you guys consistently? I have a similar problem but it it happening randomly, so I'm trying to figure out if it is related or if I have a whole new exciting problem of my own(!)

 

15 identical laptops (same XP image etc...), logged on as same non-admin user. Plug in 11 identical digital cameras, most will insall fine (using built in usb storage device driver - so therefore signed) but usually one always asks for a username and password. Happens with a different laptop and different camera each time. Also happens on desktops (including different brands of motherboards)

Also got gyration mice/keyboard: Installed itself no problems for 1 year (using native XP drivers), now asks for admin password (on 1 out of 4 PCs).

Also happened once (as far as I'm aware) on one pen drive. Teachers all have same brand of pen-drive and they've all worked fine for a year.

 

The Pen drives and mice aren't a problem but the digital cameras are intended to be used as a class set... so it can be irritating if one group can't download their pictures.

Any ideas?

  • 1 year later...
Posted

I'm also having a similar problem and hours on google is no help at all.

 

It's rather confusing as it works as intended on some machines but refuses on others. They're all set up exactly the same using the same RIS build and have the same software and policies.

 

I've went to the extent of upping the permissions of my test user account to have full filesystem and registry access which makes no difference. I've also checked that we have all of the correct settings in the GPO's we apply to the machines.

 

Has anyone figured this out yet?

Posted

No.

 

I still get the issue, and it looks like one of the images (out of two), that I am building for new machines this year, is having the problem, but the other isn't.

 

 

It is just the "unsigned" drivers that complains, all the rest seem to work for me.

 

I am tempted to go and buy all new students (and staff) a USB disk each... after making sure they are ones that will work first.

 

 

One of my suppliers is trying to see if she can get them sequentially numbered (or uniquely labelled), so that we can identify "lost" ones.

  • 2 months later...
Posted

Anybody shed any more light on this problem? It seems to be happening more and more frequently now... (perhaps it's just that more staff have lost their original school usb drive so have bought their own replacement. )

 

It only happens on certain machines and happens with USB pen drives, even though they should be using the Microsoft signed driver. When you do type in an admin password, it warns that the driver is not signed (surely it must be!).

Sometimes, once the admin password has been typed in, the machine is ok for a while, but with others, once they've taken this funny turn, will insist on the admin password every time the device is inserted!

 

Argh!

Posted

Even though I posted something I thought might work earlier in the thread (nearly a year ago :S) I had forgotten, however found this on the web

 

 

Question  -  Post 5 of 5 
Try this. 
If I remember this right: It should allow anyone who logs in from the keyboard (interactive user)to load a thumb drive.

Run secpol.msc
Security Settings
Security Options 

Devices: Allowed to format and eject removable media == Administrators and interactive users 
Posted: 10/04/2007 @ 01:40 PM (PDT) 

Chris910     60 
Job Role: Technical/PC Support
Location: Arroyo Grande, California
Member since: 02/28/2001

 

from http://techrepublic.com.com/5208-6230-0.html?forumID=101&threadID=228375&messageID=2332042

 

this is also how to DISable them, but might be reversed?

 

http://www.petri.co.il/forums/archive/index.php/t-2847.html

 

fooby

  • 1 month later...
Posted

I've figured out what was causing the problem (for me at least) at last :)

 

It seems that any machine that has protools related kit or drivers installed suffers from the problem. According to their site, they are aware of it and there is no fix yet.

 

That sorts out the majority of my machines but leaves me with one user who's laptop is affected and he doesn't use protools.

 

Barry

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...