Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi folks, I need your help and advice for the following.

 

I will be moving the teachers laptops from the Admin domain to our Curriculum any day but I can't get the policies correct. I am happy with what I have before we introduce the wireless element. Fairly quick logons, different wallpapers (Teachers have one type pupils have another) and secure. Users also bring down a set start menu for the installed apps, different menus for the different user groups on the domain.

 

Here is the problem - I would like the teachers to be able to see their own start menu and desktop for the laptops but revert back to 'my' settings when on a desktop machine in an ict suite. Local logon accounts isn't a road I would like to go down and my budget doesn't exist anymore so I can't afford to purchase anything else. I tried loopback but It hasn't made any difference. GP’s are set at the User and Computer level laptop/desktop and both Computer and User Configuration have been enabled on both OU’s.

 

Your help on this matter would be greatly received. :?

Posted

Loopback is what you need for this but, as you have found, it can be a little temperamental. When testing, make sure you wipe the locally cached profile and run gpupdate after each policy change.

 

You will also find that some wireless cards are tricky to set up to connect to the domain before logon. I've found that the Intel ProSET tool for the 2200BG chipset is the best at making this work and you can even export the configuration to a EXE for setup on other machines.

Posted

Ric_ I've tried the those suggestions already (It can be a pain waiting each time for it to update but I've got to try) Do you know at which OU I should be applying the loopback?

 

As for the cards I'm using Cisco Aironet 802.11a/b/g with the latest driver set. ( It also has an export facility) Authentication is done through LEAP to a Cisco Wireless Solution Engine Express.

Posted

The loopback should be applied to the GPO which is doing the settings. Make sure that your other settings are not configured to override these.

Also check that the laptops are definately connected before login - a quick ping should suffice for this.

Posted

The wireless authenticates first before passing forward the Domain credentials fpr authentication.

 

What should I do if the settings controlling the start menus etc are on the users OU? I can't apply loop back in this instance as it would effect the desktops as well.

Posted

OK... didn't explain myself well.

 

You need a GPO on the OU containing your laptops. We shall call this Laptop GPO.

 

Set up all the user settings within Laptop GPO and then set the loopback up on Laptop GPO.

 

IIRC any settings that are configured in Laptop GPO will override settings higher up as long as 'do not allow override' is not set above.

 

Personally, I have never had any luck with loopback and am probably not the best bod to ask. You want to ask someone like ChrisH ;)

Posted

"Since when does logging off involve pressing the reset button!?!"

 

On a different note. A few years ago I had to upgrade all of the nics so at the same time pulled the reset cable from the mobo. The kids didn't like that!

Posted
OK Sounds good. I'm not after freebies but if you could point me in the right direction I'll try and work it out from there. Scripts aren't my best subject.
Posted
Just to confirm you do have your machine accounts in their own OU as suggested is Ric's last post and that the laptops in question are in their own OU/sub OU?
Posted

The quick answer is yes. See below for more detail

Manager Users -

Staff -

Teaching

Support

Pupils

-

Upper

Lower

Managed Desktops -

Area 1

Area 2 etc...

Managed Laptops

Staff

Pupil

Posted

LAPTOP USERS GPO

System/Group Policyhide

Policy Setting

User Group Policy loopback processing mode Enabled

Mode: Replace

Posted
Sorry i meant the specific start menu setting. What I am trying to determine is if you have tried to set it to something else or left it blank.
Posted

Desktop

Setting: Basic (Redirect everyone's folder to the same location)hide

Path: \\Asc-dc-01\profiles$\teacherdesktop

 

Options

Grant user exclusive rights to Desktop Disabled

Move the contents of Desktop to the new location Disabled

Policy Removal Behavior Leave contents

 

My Documents

Setting: Basic (Redirect everyone's folder to the same location)hide

Path: \\%HOMESHARE%%HOMEPATH%

 

Options

Grant user exclusive rights to My Documents Enabled

Move the contents of My Documents to the new location Disabled

Policy Removal Behavior Leave contents

 

Start Menu

Setting: Basic (Redirect everyone's folder to the same location)hide

Path: \\Asc-dc-01\Menus$\Start Menus\Teachers

 

Options

Grant user exclusive rights to Start Menu Disabled

Move the contents of Start Menu to the new location Disabled

Policy Removal Behavior Leave contents

 

The above is set in the User Configuration of the Staff OU

Posted

How have you changed it in the loopback policy though? This part specifically

 

Start Menu

Setting: Basic (Redirect everyone's folder to the same location)hide

Path: \\Asc-dc-01\Menus$\Start Menus\Teachers

Posted

Ok so its set to not configured then? Also have you ticked the box on the setting tab that says

redirect the folder back to the user profile when policy is removed?

 

If you have done all that then try setting the policy to some like redirect to:

 

%userprofile%/start menu

 

Sometimes with GP if you do nothing it just keeps the settings. If you try and replace them with something else you may have more luck.

 

Also make sure you have the setting "Wait for the network" which will be machine setting to give you a better chance of the GPOs getting read properly during startup.

 

If your still struggling I have an idea for a script which will be fairly short.

Posted
Thanks for all your help ChrisH. I'll try that over the rest of today and tomorrow. If i have no joy can I post again Tuesday pm or Thursday?
Posted

If all this GP twiddling fails, here's another way you could do it...

 

1 - Redirect all Start Menus to C:\StartMenu (or anything on the local PC) - Do this for ALL USERS.

 

2 - Apply a startup script to the desktop machines OU which copies the managed start menu from the network down to C:\StartMenu. (This can be done if you include the files being copied in the actual GPO alongside the script)

 

3 - Apply a startup script to the laptops OU which simply copies the contents of the original start menu (%ALLUSERSPROFILE%\Start Menu) to C:\StartMenu

 

This way you still take control of the Start Menu contents. Too whacky?

Posted

I had a problem fairly similar to this a while ago.

 

We're in the process of deploying a terminal server. I wanted the standard student policy to be applied to the terminal server but I also wanted an additional policy to be applied to users logged onto the terminal but not those who were logged onto standard workstations.

 

I tried farting around with loopback policies with very limited success. Sometimes they worked, more frequently they didn't. So I had an idea: WMI filters!

 

On the student OU, there are two policies: The standard one which applies to both terminal server users and fat client users. The second one only applies to the terminal server. The second one has a WMI filter attached to it which looks for the serial number of the machine they're logging onto. If it matches the TS's serial number, it applies; if not it doesn't.

 

Try something similar. I don't know the specifics of your network, what brands of PCs you use or whatever but there must be a WMI setting somewhere where you can differentiate between your workstations and your laptops. Hell, you could probably do it by machine name alone.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...