znova Posted June 25, 2009 Posted June 25, 2009 Hello, I am hell-bent on changing the admin password for the server because even the neighbours' cat knows it!(When I first started to work here it was taped to the wall ) The implications are this: being a small school with limited space, the server itself gets used for internet/Word/Facility. Is there a built-in account that will give a limited access to the server itself but will accomplish the above? I trawled through the built-in accounts but nothing seems to quite fit the bill. Anyone else in a similar situation and found an account that works? Since noone will listen to me and they will find a way of using server anyway, let's limit the impact they might have. Thanks!
localzuk Posted June 25, 2009 Posted June 25, 2009 Just using a normal domain account will provide the functions you want? Why do you want a local account?
Michael Posted June 25, 2009 Posted June 25, 2009 You need to make sure the admin password isn't used for something else, such as a service or an application for example. You could (as a recommendation), copy the domain administrator account, then name it and password it as appropriate. You can then proceed to change the password and see if it breaks anything. If it does or you cannot logon, you can use the secondary admin account you copied/created earlier.
Michael Posted June 25, 2009 Posted June 25, 2009 To answer your other question, you can use a limited account on a server, but you'll be seriously limited as to what you can do. Although Microsoft does recommend to use accounts with less privileges, it really doesn't work that well in practice. Just stick with a single, well secured account. Preventing physical access to a server is also a consideration you should look at if necessary. Is the room where the server is hosted secure or locked when you are out of it?
znova Posted June 25, 2009 Author Posted June 25, 2009 To answer the questions: Server is in the school office. The office only has 1 computer which is shared by up to 3 people. So they go on the server, print their stuff, do their reports, check e-mails etc... They do not need access to anything on the server really apart from facility, which is only installed on the admin pc(but that would be just the matter of adding priviliges to that program). I wasn't too keen on the idea of adding a domain account with admin privilages since only the server needs be accessed as a normal PC.
znova Posted June 25, 2009 Author Posted June 25, 2009 And yes, I tested one of the limited accounts(Print Operator) and it wouldn't even let me access the internet, so totally useless.
localzuk Posted June 25, 2009 Posted June 25, 2009 To answer the questions: Server is in the school office. The office only has 1 computer which is shared by up to 3 people. So they go on the server, print their stuff, do their reports, check e-mails etc... They do not need access to anything on the server really apart from facility, which is only installed on the admin pc(but that would be just the matter of adding priviliges to that program). I wasn't too keen on the idea of adding a domain account with admin privilages since only the server needs be accessed as a normal PC. Why would it need admin privileges? Why not just a normal, domain account?
znova Posted June 25, 2009 Author Posted June 25, 2009 Why not just a normal, domain account? And adding the log in locally to GP? Off to test it..
jamesb Posted June 25, 2009 Posted June 25, 2009 A normal domain account with permission assigned to log on to the DC by adding them to the Allow logon locally permission under Default Domain Controllers Policy should work fine. I assume that's why you were going to use an admin account? I'd be surprised if any of the Operators groups could do anything outside of their own function, that's the idea behind them. Print Operators can manage print queues, Server Operators can do basic maintenance tasks, Backup Operators can manage backups, and so on. Internet access isn't part of any of those roles.
Michael Posted June 25, 2009 Posted June 25, 2009 The office only has 1 computer which is shared by up to 3 people. So they go on the server, print their stuff, do their reports, check e-mails etc... This is really unusual. The usual approach is the server itself just hosts Facility, the database and maybe user files. Admin staff should have a workstation each, which they can logon to, access their files (typically through mapped network drives) and all be able to use Facility simultaneously.
localzuk Posted June 25, 2009 Posted June 25, 2009 This is really unusual. The usual approach is the server itself just hosts Facility, the database and maybe user files. Admin staff should have a workstation each, which they can logon to, access their files (typically through mapped network drives) and all be able to use Facility simultaneously. It isn't unusual at all, I know of lots of primary schools who do it the way the OP says. Not that it's the right way to do it, or even a legal way to do it (Data Protection Act etc...) but that's how many small schools do it. It adds a layer of complexity, and a layer of danger to a system that isn't needed though. All for the sake of buying a PC to do the job instead (a couple of hundred quid).
znova Posted June 25, 2009 Author Posted June 25, 2009 I will have to think about this one a bit more. Office users need to acces their docs but I don't want to allow the logon locally right because it will redirect their docs - no space for that. If I copy their account(office2) and take the doc redirection out, they won't be able to see their docs on the office PC, right? They can see them now when they log on the server as an admin...hmmm, don't tell I tweak the settings there! The staff just using the server as a workstation(any suggestions for names ?) shouldn't be a problem now.
Michael Posted June 25, 2009 Posted June 25, 2009 Well I've yet to see one, but as you say, for the sake of a couple of hundred £'s it seems ridiculous to have all this trouble. Allowing staff access to a server is extremely risky. Installing workstations of course allows you to lock down access with GPOs. You can actually lock down servers, but I wouldn't recommend it.
znova Posted June 25, 2009 Author Posted June 25, 2009 And don't get me started on the data protection! No encryption in sight here, the deputy head isn't aware of how she is supposed to secure data, no training on this - I would stick my two-penny in but it wouldn't do any good.
Michael Posted June 25, 2009 Posted June 25, 2009 Office users need to acces their docs but I don't want to allow the logon locally right because it will redirect their docs - no space for that. If I copy their account(office2) and take the doc redirection out, they won't be able to see their docs on the office PC, right? They can see them now when they log on the server as an admin...hmmm, don't tell I tweak the settings there! As a recommendation each Admin user should have a dedicated workstation. Their documents and Facility remain on the server, but creating a shortcut on a workstation would allow them to access Facility securely and to access their documents using a network drive \\Servername\Share and allocate it a letter such as H:\ You'd also be required to map the Facility share and this could be T:\ for example. I presume you must have something like this setup as you already have one workstation. You just need a few more and you copy the configuration so all Admin staff can work at the same time. Makes sense really
cookie_monster Posted June 25, 2009 Posted June 25, 2009 All for the sake of buying a PC to do the job instead (a couple of hundred quid). or even a cast off from a local secondary would probably do the job.
znova Posted June 25, 2009 Author Posted June 25, 2009 It's not just the server issue, it's a space issue as well. There isn't physical space to put another PC in(old victorian building). Besides, there is plenty of money for school PCs/laptop; office had to work long and hard to get a new pC and that only happened when an important update failed because it wouldn't run on Win 2000. Also, the school is moving to purpose built one in 2010 so the idea is spend as little as pos since it's left behind!
znova Posted June 25, 2009 Author Posted June 25, 2009 or even a cast off from a local secondary would probably do the job. Actually, the local secondary seems to be using cast-off themselves! In this case, when we move they'll probably be glad of our cast-offs! (just not the office one...)
znova Posted June 25, 2009 Author Posted June 25, 2009 I've been to see another primary i the area and their server isn't connected to a monitor so the appeal to use it as an extra PC is diminished. I wish! Mind you it IS connected to IWB so potentially a whole class could play with the server at the same time...
Michael Posted June 25, 2009 Posted June 25, 2009 Mind you it IS connected to IWB so potentially a whole class could play with the server at the same time... Seriously worrying! Joke aside if it all goes wrong the Technician won't have a fun time restoring the damage. I am really surprised schools are still using servers as a workstation.
witch Posted June 25, 2009 Posted June 25, 2009 In one of my schools, the finance officer uses the server as her machine, and in my old school the admin officer did. I tend to work on the server in one school as there is no space for either a computer for me or a place where I can use a pc. In the other I have a PC and remote into the server when necessary.
znova Posted June 25, 2009 Author Posted June 25, 2009 I've settled in now with the admin lady: add office to server logon locally for facility and their own docs; everyone else will have a limited account so they can use Word/internet etc. It will probably discouraged them from using it so often if it doesn't have all the bits and bobs their laptops have Now where was I: Oh yes, changing the administrator password... I guess this is a bit of a wakeup call to all you secondary techs, wellcome to Primary world!!!
znova Posted June 26, 2009 Author Posted June 26, 2009 Thanks for the help! The ofiice staff now don't want their docs when they log onto the server as office because HORROR! we don't have MS Office installed on the server and they are worried about using the same docs in open office.. OH, and the fallout has begun already - one teacher aproached me this morning - I can't log on to my laptop as an administrator, why?...explaining why..response: Oh, I am entitled to it, so please just speak to the headmistress for me(I'm sure she'll ok it) and give me the admin password. I do not know what this teacher does to computers but they do not work in her presence. She only needs the admin password because after 2 years of trying to connect to internet at home she had somone out who 'fixed' it but the internet only works when she's logged on as an admin. Needles to say I've not obliged, the head isn't here and I'm making lovely enemies - just before I leave This is after I've dug up this lovely document from the council about the Computer Misuse act(not using user ids/password that don't belong to you etc.) and displayed it prominently on my desk! Don't you feel sometimes this a thankless task...
znova Posted June 26, 2009 Author Posted June 26, 2009 And she didn't think to bring the laptop in for me to have a look at, aparently I can troubleshoot it over the phone...
jamesb Posted June 26, 2009 Posted June 26, 2009 And she didn't think to bring the laptop in for me to have a look at, aparently I can troubleshoot it over the phone... Get a recording of an old modem, ask her to hold the phone up to the laptop and play the recording on a loop. See how long you can get her to stand there holding the phone up to her laptop.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now