tickmike Posted August 5, 2006 Posted August 5, 2006 Hello All. Help please with setting up this server for the first time. Just need a basic set up to run AD ,do updates and be in control of the workstations to stop the little darlings changing all the settings. W2K adv. Server. to serve 30 computers On DHCP 'server options' do I select :- 004 Time server. 006 DNS. 015 DNS domain name. And on DNS do I have to set up the 'Reverse look up zones' ?. Any tips about setting up Active Directory.with Mandatory Profiles from scratch. Regards Michael.
Ric_ Posted August 5, 2006 Posted August 5, 2006 If you have decided that mandatory profiles are the way to go, check out the wiki page at http://www.russdev.com/edugeek/doku.php?id=how_to_set_up_mandatory_profiles for full instructions
ChrisH Posted August 5, 2006 Posted August 5, 2006 Yes do set up the reverse lookup. You may also need the gateway or router option (which ever it calls itself) setting.
kingswood Posted August 5, 2006 Posted August 5, 2006 Hello All. Help please with setting up this server for the first time. Just need a basic set up to run AD ,do updates and be in control of the workstations to stop the little darlings changing all the settings. W2K adv. Server. to serve 30 computers On DHCP 'server options' do I select :- 004 Time server. 006 DNS. 015 DNS domain name. And on DNS do I have to set up the 'Reverse look up zones' ?. Any tips about setting up Active Directory.with Mandatory Profiles from scratch. Regards Michael. Hi. You don't need a reverse lookup zone- it's not essential. But I would put one in there anyway. It helps if you plan on running any reverse lookups- so a web server internally etc. And it can also help some other things on your LAN work more efficiently. The WIKI on here is great for profile information. Best of luck! Paul
tickmike Posted August 5, 2006 Author Posted August 5, 2006 Hi Thanks for comments. Still unsure if I have to select DCHP server options if I want these services to run or does work with out ticking the options box's From Michael.
ChrisH Posted August 5, 2006 Posted August 5, 2006 There are the server options which are the global DHCP options and the the scope options if you want to do something different in one of your scopes of which most people will only have one anyways. You have to tick the boxes to enable them.
ajbritton Posted August 6, 2006 Posted August 6, 2006 Assuming xall your clients are win2k/xp then you don't need to set the dns domain name as this is set when they join the domain.
kingswood Posted August 6, 2006 Posted August 6, 2006 Hi. These are optional services so that DHCP can supply the information to clients. See here: http://www.windowsnetworking.com/articles_tutorials/w2kdhcpc.html Hope that helps!
tickmike Posted August 8, 2006 Author Posted August 8, 2006 Hello all thanks for your help and the link (that is a good site). but need some more help !. Setting up Group policy's for my users and there computers. open AD users and computers>properties>GP tab>New>give it a name>press enter>edit>configure>Save. But Its changed the DC settings as well ?. eg. I set up that users could not turn off computers ... so I end up not being able to turn of the DC when I have finished working on it tonight . Where have I gone wrong this time. From Michael.
ajbritton Posted August 9, 2006 Posted August 9, 2006 Oops - which container/ou did you link your policy to? It sounds like you linked it to the root of the tree. Policies are inherited down the tree (unless you specifically block inheritance). Best pratcise is to create Organizational Units (like containers) to put your computers/users in. I use a structure as a bit like this... \Managed \Managed\Computers - (computer accounts are all in here) \Managed\Users \Managed\Users\Staff - (staff user accounts are all in here) \Managed\Users\Students- (student user accounts are all in here) When you want a policy to apply to all your users, you can create it at the \Managed\Users level. Policies for staff or students would created at the appropriate level to just apply to those users. You should also create OUs for other objects (eg Groups, Service Accounts, Admin Accounts). You should also avoid editing the default policies (default domain policy, default domain controller policy, default site policy).
Ric_ Posted August 9, 2006 Posted August 9, 2006 @tickmike: Also nip off to MS to download the Group Policy Management Console (GPMC) - it makes dealing with GPOs a bit easier since you can see which OUs have GPOs linked to them at a glance and you can get a display of what policies are set.
tickmike Posted August 9, 2006 Author Posted August 9, 2006 Hi . A very very big oop's .. I now cannot access the DC . ( it now thinks it's a user workstation !!! ) HELP..... all I can get to is C:\ in safe mode. Does anyone have any idea's how I can get my DC back. ??? From Michael.
Ric_ Posted August 9, 2006 Posted August 9, 2006 I would restore from backup if possible. Otherwise you may need to re-install depending on how much you have crippled. You appear to have learnt the hard way that you should not edit GPOs on the server and that you should set GPOs up at an OU level that won't affect your DC
tickmike Posted August 9, 2006 Author Posted August 9, 2006 Hi . Loads of them, went down the list and configured what I did not want the users to change . I want to get access to the GP and delete it and configure like you suggests above. I think it must be the root GP. Can only get to safe mode C:\ or directory restore mode ( but in that still cannot get in to Active directory) From Michael. Edit ... just seen other post . Backup what backup ? not got around to doing any back up's yet !!! . do you think it will be quicker to do yet another reinstall . I will get it right. Edit
tickmike Posted August 9, 2006 Author Posted August 9, 2006 @tickmike: Also nip off to MS to download the Group Policy Management Console (GPMC) - it makes dealing with GPOs a bit easier since you can see which OUs have GPOs linked to them at a glance and you can get a display of what policies are set. Hi Ric, do you have a link for this please. Is it a small file to download ?. Michael
tickmike Posted August 9, 2006 Author Posted August 9, 2006 Hello. I'm getting there . Re installed again, set up AD, DNS,DHCP. Thanks Ajbriton for putting it down how to set the ou's up (did not set these up before oop's ) . I have done this, now I have to put all the workstations names in the "managed\computers" ou . eg..........managed\computers,lib1, lib2,office1,class1a, etc. but not any routers (member servers) etc. Then similar for the staff . eg "managed\users\staff,ann a, pat b, etc. Then similar for the pupils . eg "managed\users\pupils,ben a, sam b,mary xyz etc. Re You should also create OUs for other objects (eg Groups, Service Accounts, Admin Accounts). Do these come off the main tree or from the 'managed' ou ?. I can also see that I can set the GP for each ou. for ..say the workstations I would set things that would affect how the users can use there workstations and what they can have access to ? On this site have I seen some of these GP's I can download to use or is every school different ? I have seen that there are some 'template ' GP in w2k server. Michael.
Ric_ Posted August 10, 2006 Posted August 10, 2006 The GPMC can be found at http://www.microsoft.com/downloads/details.aspx?FamilyID=0A6D4C24-8CBD-4B35-9272-DD3CBFC81887&displaylang=en an is 5.6MB (apparantly). You must install it on a XP SP2 machine though (and you may also need .NET on there too but these are all pretty standard things). You can set up your OUs wherever you feel like and give them whatever names you like too. For instance my free looks like: My School -> Administrators (basically me and my computer - different GPOs applied) -> Citrix (for my Citrix servers) -> Computers |-> Admin |-> Laptops |-> Workstations |-> Classrooms |-> Classroom 1 |-> Classroom 2 |-> ... |-> Library |-> Offices |-> Staff Room -> Users |-> Admin Staff |-> Pupils |-> Year |-> ... |-> Sixth Form |-> Year |-> ... |-> Staff Obviously, you would lay it out in whatever way is logical for you. Lots of OUs makes for easier application of GPOs and you can always link one GPO to several OUs.
ajbritton Posted August 10, 2006 Posted August 10, 2006 You'll probably find that your OU structure will change as your network evolves and you better understand what it needs to do and how you need to manage it. For what it's worth, here's my complete standard structure. \Managed \Computers \ICT Suite \Classrooms \Library \School Laptops (these seldom leave the school) \Staff Laptops (these go home with staff and connect to Internet) \Groups \Servers \Service Accounts \Users \Managers \Staff \Students
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now