mrstephenw Posted February 10, 2010 Posted February 10, 2010 We're about to set up a new server in our primary school, but before we do that we'd like to know what group policies other primary schools tend to implement. Thinking about the restrictions we should put on the pupil's accounts. Any examples of the group policies other primary schools have used would be much appreciated. Is there any standard set of group policies other schools use? Thank you very much. Steve
SimpleSi Posted February 10, 2010 Posted February 10, 2010 I'll give you one side of the fence I don't have any group policies in any of myschools and all users have full admin rights The only times this has negative repercussions is with Reception classes who can trash a desktop in about 15 seconds and with 1 of my schools where year 6 recently discovered screen rotation via hotkeys Thats the disadvantages I can remember. Advantages are that any adult can install software/sort out printer problems etc without a computer (or a techncian/ICT co-ordinator) saying no This is with surburban schools near Preston in Lancs. regards Simon PS I use another method called WPKG to deploy software to workstations so I don't miss that facility.
Tricky_Dicky Posted February 10, 2010 Posted February 10, 2010 Ours a locked down heavily. Remove all desktop and start menu items and redirect both to where we want. No System tray for pupils, remove windows commands such as run and System properties. IE is where we do a lot of restrictions such as proxies, control panel, security. Rich
krisd32 Posted February 10, 2010 Posted February 10, 2010 Ours a locked down heavily. Remove all desktop and start menu items and redirect both to where we want. No System tray for pupils, remove windows commands such as run and System properties. IE is where we do a lot of restrictions such as proxies, control panel, security. Rich All the primaries i go to have been locked down similar to this.
penfold Posted February 10, 2010 Posted February 10, 2010 Advantages are that any adult can install software/sort out printer problems etc without a computer (or a techncian/ICT co-ordinator) saying no This is with surburban schools near Preston in Lancs. regards Simon PS I use another method called WPKG to deploy software to workstations so I don't miss that facility. Not sure if your joking or not there...but there is normally a reason for saying no, such as copyright/licencing issues. Who ends up responsible for them if your running a load of illegal software on machines? Sorry, if I missed the point of your post, think I need to go for lunch:p
BrianG Posted February 10, 2010 Posted February 10, 2010 My schools are locked down heavily. They have no rights over the machines at all other than to open applications, print, view the internet and access shared drives. Their documents are redirected to the server. The students can't do anything. The can't even right click on the desktop. The staff are the same. They are locked down too. I find it's often staff who are better at breaking computers than the kids. We have one GRO sitting at the top which covers all the security settings, proxy settings, wallpaper etc.. We then have a GPO for the staff OU and the student OU which deals with mapping drives in. ( The staff have student and staff shared drives mapped in. The students just have the students drive mapped in) I give each department an OU which i then link GPOs for mapping printers
TechSupp Posted February 10, 2010 Posted February 10, 2010 Yes, we are similar in that most things are locked down, redirected desktops, locked profiles, no control panel etc etc, but I can see where Si is comming from. We dont generally get children messing (unless its as the case with Si the very young ones) and so its only the adults that mess things up generally. Locking things really down does have its downside especially blocking acces to c: drive with some of the primary software. Got around some of the restrictions using RunAs. As with most things GPO's in primary have their pros and cons but in general I'm in favour the more I have used them.
Craggus2000 Posted February 10, 2010 Posted February 10, 2010 I'll give you one side of the fence I don't have any group policies in any of myschools and all users have full admin rights The only times this has negative repercussions is with Reception classes who can trash a desktop in about 15 seconds and with 1 of my schools where year 6 recently discovered screen rotation via hotkeys Thats the disadvantages I can remember. Advantages are that any adult can install software/sort out printer problems etc without a computer (or a techncian/ICT co-ordinator) saying no This is with surburban schools near Preston in Lancs. regards Simon PS I use another method called WPKG to deploy software to workstations so I don't miss that facility. I'm with you on this one. We apply very few policies and restrictions, all users have full admin rights to the machine. Except we go one step further... We use Reborn cards, kind of a hardware version of deepfreeze kind of thing. If a kid trashes a machine, just switch it off and on, and voila They also have the added benefit of being able to clone from a master PC to the rest. Better than imaging, as I have cloned nearly 90 PCs within an hour! Imaging is usually nearer 15... Let me know if you want to know about our reseller. 1
SimpleSi Posted February 10, 2010 Posted February 10, 2010 Not sure if your joking or not there...but there is normally a reason for saying no, such as copyright/licencing issues. Who ends up responsible for them if your running a load of illegal software on machines? The head/govenors are responsible not me The way I work is that if I find that a piece of software has been installed without the number of licences - I point it out to the head/ICT Co-ord and point out that I cannot help with problems with such software as I would be aiding and abetting with illegal software - those words ususally have an effect I also generally don't install more copies if I think the licences don't permit it. regards Simon
penfold Posted February 10, 2010 Posted February 10, 2010 The head/govenors are responsible not me The way I work is that if I find that a piece of software has been installed without the number of licences - I point it out to the head/ICT Co-ord and point out that I cannot help with problems with such software as I would be aiding and abetting with illegal software - those words ususally have an effect I also generally don't install more copies if I think the licences don't permit it. regards Simon Fair enough. It's just that I have always worked somewhere where it has been my responsibility to check licences which meant I didn't allow other people to install stuff. Of course this mentality came from starting my first job in a school which had about 30 licences for MS Office but installed allsorts of software on the entire network. They weren't happy when I told them either buy more licences or I remove them.
mrstephenw Posted February 10, 2010 Author Posted February 10, 2010 (edited) Thanks for all your comments. I got a lot more than I bargained for here. I'm still quite keen to apply some group policies, but not lock down all the PCs fully. @ SimpleSi We're due to start fresh a suite of 30 PCs, so I'm quite keen not to allow unrestricted access. I do however like the advantages that you've stated: 'Advantages are that any adult can install software/sort out printer problems etc without a computer (or a techncian/ICT co-ordinator) saying no' WPKG is one thing I shall explore further, nice one ) @Tricky_Dicky I like what you've suggested: Remove all desktop and start menu items and redirect both to where we want. No System tray for pupils, remove windows commands such as run and System properties. @BrianG 'The staff are the same. They are locked down too. I find it's often staff who are better at breaking computers than the kids.' I agree, although restricting our staff to such an extreme may hinder creativity within the team, so I'm quite keen to have good 'restore' procedures (not the Microsoft variety!) in place should the worst happen. @TechSupp Wowzers, I can see how restricting access to C: would be beneficial, but I envisage there being problems associated with this. @Craggus2000 Nice one, I'll take a look into those cards. May be relevant for future projects. Just off the top of your head; how much a machine? Great, thanks for all your responses, you've given me something to chew on, looking forward to the implementation ) Steve Edited February 10, 2010 by mrstephenw
Craggus2000 Posted February 10, 2010 Posted February 10, 2010 Nice one, I'll take a look into those cards. May be relevant for future projects. Just off the top of your head; how much a machine? The cards are about £30 off the top of my head, and come in 100mb or 1gb options, pci or pci-express. They also do a software version for laptops for about £20, also has the clone function. You can do other fancy stuff like auto ip allocations (if you don't use dhcp) and host names, but the best bit is the being able to set up 1 PC as you want it, and then clone to nearly 100 in less time than it takes to sneeze.
t_h Posted February 10, 2010 Posted February 10, 2010 Wow, full admin rights on client machines for staff and pupils? *shudder* I work in a Primary/Nursery and ALL of our user accounts, including my own day-to-day account, are standard user accounts. My philosophy is to keep things as simple as possible. With Group Policy I redirect the Desktop and My Documents to the NAS, run a couple of login scripts to map network drives and printers and configure little things like the IE homepage and favourites. This works well for us - it keeps computers across the network consistent, doesn't allow individuals to trash the configuration and keeps malware to a minimum.
EduTech Posted February 11, 2010 Posted February 11, 2010 Y'see, Simon likes fixing problems so that is probably why he does that also, he probably has quite understanding staff that may/maynot abuse it and if you have seen Simon you would know not to mess with him But Seriously, I do understand why.. and espeically as they do not have someone there full time it does save them making Simon's ears hurt and if it is working and not causing any problems then i suppose it is fine... Would never see that happen round the schools i live by, but i suppose the area is worse here than there 1
p858snake Posted February 11, 2010 Posted February 11, 2010 (edited) I'm with you on this one. We apply very few policies and restrictions, all users have full admin rights to the machine. Except we go one step further... We use Reborn cards, kind of a hardware version of deepfreeze kind of thing. If a kid trashes a machine, just switch it off and on, and voila They also have the added benefit of being able to clone from a master PC to the rest. Better than imaging, as I have cloned nearly 90 PCs within an hour! Imaging is usually nearer 15... Let me know if you want to know about our reseller. We can image a classroom of 25/30 in like an 30 mins or less. I do know some switch settings and stuff can make images take longer to deploy though and/or the actual images themselves and the compression they are done at depending on the imaging solution. The head/govenors are responsible not me You are employed to manage the IT systems so it falls under your duties... so unless you have it clearly documented otherwise in your contract..... Edited February 11, 2010 by p858snake
laserblazer Posted February 11, 2010 Posted February 11, 2010 We'll probably find Ofsted agreeing with Simon. After all, how are kids going to learn how to f*** things up if we don't give them the opportunities? 1
enjay Posted February 11, 2010 Posted February 11, 2010 We use CC3, and our Primary (and Secondary) have the standard restrictions which go with that - no local admin rights, no command prompt, read-only access to most of the network. Users not having admin rights proves invaluable in the management of copyright and licensing, and also does a lot to limit virus infection, as most viruses require higher rights than our users have. The thought of letting people loose with admin rights scares me, and I wouldn't say I was doing my job properly if I permitted it. SLT agree, by the way.
James2k Posted February 11, 2010 Posted February 11, 2010 I remembered my secondary school introduced these cards that sit in a PCI slot that when rebooted would undo any changes to the system... Even though they were disliked by the deputy head who was also my head of year and my GNVQ teacher... A few minutes later and the cards had been removed from the computers in our classroom... as the open office version that was installed crashed left right and centre... The ICT Manager tried getting me done for theft... at which I laughed and said the deputy head had them and the ones I removed from the computers in the ICT room were sitting in the bottom of the cases... He didn't really talk to me after that... IIRC he got sacked after I left.... lol
HullFC Posted February 11, 2010 Posted February 11, 2010 I have a few different setups with differing options. What i find works best is to lock the stations down. As people have said it's more for protection from virus' etc. A few points that I think are important: Redirect document folders. Redirect favorites and desktops to a hidden folder in the users documents area. This makes it really easy to delete dodgy profiles without messing around with favorites etc. I also with server 2008 have a start menu policy which does a number of things: It locks down the start menu (hides run/etc) It prevents shortcuts in the all users folder form being listed. It deletes the users start menu on startup and recreates it all using group policy preferences. this is really powerful as each shortcut has a condition placed on it to check if the program exists. This means that laptops which are disconnected from the domain do not get shortcuts that don't work. I also use the prefs to hide the C: drive on stations and also hide drive maps that users don't need to see but applications need. Hope this helps and if you need me to send you some more info let me know. Shaun 1
mrstephenw Posted February 11, 2010 Author Posted February 11, 2010 Thanks Shaun, There's some helpful information in there and I'll look into some of this further when I start to implement the new GPs. I'm also grateful for the offer of further assistence, Nice one, Steve
eean Posted February 12, 2010 Posted February 12, 2010 It deletes the users start menu on startup and recreates it all using group policy preferences. this is really powerful as each shortcut has a condition placed on it to check if the program exists. This means that laptops which are disconnected from the domain do not get shortcuts that don't work. Interesting! Does this slow down the logon at all? The system must have to check the presence of each file.
HullFC Posted February 12, 2010 Posted February 12, 2010 Interesting! Does this slow down the logon at all? The system must have to check the presence of each file. Actually no. We thought that it would before we did testing but it doesn't seem to cause an issue at all. It is only parsing a local XML file in reality. It's really powerful as the one policy sets all shortcuts for all users and we use gp prefs to assign shortcuts by group/site/ou etc so the kids don't get stuff for staff and only system admins get admin tools. It's all neatly in one place. We also use gp and gp prefs to delete common startup reg keys (like adobe reader speed launch, quicktime startup etc) and disable some services (e.g. google update) which can really help startup times. Shaun 1
enjay Posted February 12, 2010 Posted February 12, 2010 CC3 does what Shaun is describing as standard, so to answer eean's question, the logon speed is still perfectly acceptable (can't comment on whether it slows it down, as I've not seen it without). The only slight issue is if you log in to one PC which doesn't have Application X on it, when you then log in to one which does, it can take it a little while to appear. People have come to know just to click away from the Start Menu and try again in a few seconds. 1
HullFC Posted February 12, 2010 Posted February 12, 2010 CC3 does what Shaun is describing as standard, so to answer eean's question, the logon speed is still perfectly acceptable (can't comment on whether it slows it down, as I've not seen it without). The only slight issue is if you log in to one PC which doesn't have Application X on it, when you then log in to one which does, it can take it a little while to appear. People have come to know just to click away from the Start Menu and try again in a few seconds. We have CC3 across a number of sites and were planning to write a script to do all this on our vanilla networks but GP prefs came along and solved it for us. We also have a branding policy which deploys BGInfo and creates the startup and logon keys for it as well. Depending on the user type (staff/student/admin) they get a different colour background so you can tell straight away if a member of staff has left a PC logged on in a room full of kids. BGinfo reads environment variables form the same policy which specify school name and support numbers etc so we can deploy the same policy across various sites and just tweak the variables. We have the found the environment variables particularly useful on our new admin network which is currently being rolled out across many school sites in Hull. All of the folder structures on servers, branding and localisation is done through GP prefs. For example we have a variable for the site's server hostname which is different based on ad site. This is then used in profile paths so the same policy to redirect folders works on all sites and adapts to each with little fuss. Shaun 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now