Jump to content

Recommended Posts

Posted

@norphy:

 

Sounds about right. I see that sometimes when logging on, it starts to cache other things - one of them being the shared [hidden] drive where *all* the staff's home folders are.... wonder how long that would take lol

 

Do you [or anyone] set the disallowed file extentions when using offline files at all? stop the process from copying back and forth *.zip or *.tmp files for example.

 

I think i will turn off the offline files option on the shares of the server to prevent it mirroring everything on the server lmao ;)

 

@Ric:

The default is to automatically cache any redirected folders (handy since these will include the home drive, start menu and desktop).

 

Yep - but alas when I disconnect the lan cable or try and log on without the cable in, I get the error messages that it cannot load the desktop, app data, [roaming profile]... etc. Have I forgotten to change another setting here or something?

 

Cheers

Nath

  • 1 month later...
Posted
We use a package called Ezback on your student laptops. all the students activates is written to a buffer, then when the machine is rebooted, the buffer is lost and everything is returned as you left it. C: drive is protected and D: drive is unprotected so that they can save their work to it if they loos wireless connection to the server. Reboot and reconnect copy work onto server.
Posted

We're a primary school with a wireless network. I currently install all software via group policy. I try to have everything running locally, so reduce the burdon on the wireless network.

Staff laptops are not conneted to the wireless network, but I would like to, and have all the software available for them to use at home. However, imagine the scene:

Teacher brings in their laptop after 6 months at home. Group policy spends 25 minutes on startup installing tons of software that has built up! Is there any way of allowing a 'Skip Instillation' button? Or an easy way for staff to install software on their own?

Posted

You could aways put the affected machines in a different organisation unit in Active Directory.

 

Another possibility is to publish rather than assign the software to the macine. That way the administrator can choose to install rather have the install forced on them at boot time.

Posted

We just add the allstaff domain group to the local administrators group on laptops to give staff full priviledges on their own machines. All student laptops are rangered.

 

We also create a local admin account for them to use at home so they dont have to keep changing our proxy settings to use their own broadband connections.

 

We have very few problems like this.

Posted
We just add the allstaff domain group to the local administrators group on laptops to give staff full priviledges on their own machines.

 

This is abit dangerous as it makes any member of staff an administrator on any staff laptop whether or not they have signed for it. This means an attacker just has to get of staff crendentials from a careless member of staff then they could mount remote attacks on any laptop. You may get some protection if the staff laptop has an operational software firewall (XP or 3rd party) with well defined exceptions. Or maybe a kid gets physical access to a teachers laptop to give a power presentation. While he's groups preparing he could do the odd runas install the odd keylogger.

 

That's on the extreme end, more likely it just increases the chances of a member of staff causing a problem on someone else's machine. They come in to cover a lesson and borrow someone's laptop for electronic registration. They may browse the web install the odd tool bar or spyware etc. User education and good manners should stop a lot of this but there is no safety net if everyone is an admin on everyone else's machine.

 

All student laptops are rangered.

 

We also create a local admin account for them to use at home so they dont have to keep changing our proxy settings to use their own broadband connections.

 

Does Ranger have offline logging? Once a kid has admin they own the machine in the hacker sense. They can do all the nauhgty stuff at home, even disabling the Ranger client.

 

We have very few problems like this.

 

Ultimately, a good school displinary record is probably the only defence when you have to give admin to kids and staff with varying levels of IT expertise.

Posted
We just add the allstaff domain group to the local administrators group on laptops to give staff full priviledges on their own machines.

 

This means an attacker just has to get of staff crendentials from a careless member of staff then they could mount remote attacks on any laptop.

 

I agree with ITWombat; also, am I right in thinking that a virus or malware that infects one staff laptop could use the logged-on teacher's credentials to infect all the others when networked? (I know we all have virus scanners, but they are only part of the solution)

If staff must have admin rights, would it not be safer to just add the laptop owner's username to the local admin group?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...