s1mon321 Posted April 3, 2011 Posted April 3, 2011 Anybody got a successful school group policy structure that they'd like to share? Do you have one policy linked to all students? A number of individual policies linked to all students? Different policies linked to different year groups? Also, we currently have a student policy that provides proxy server details. How do we create a policy to block certain students internet access when they are linked to the policy that supplies those details? Is a separate policy that only acts upon users in a 'blocked internet' security group going to work? Any advice would be really appreciated!!
mtdmitchell Posted April 3, 2011 Posted April 3, 2011 in regards to blocking internet, i used to have a OU below the students Ou ( so it picked up the Normal student policy) applied to the New Ou i would have a policy applied that would just set an incorrect proxy..or just blank. As this policy is applied last it would stop the internt from being used. then all i would do is move the student to that OU when i wanted them blocked from the internet. hope that makes sense 1
glennda Posted April 3, 2011 Posted April 3, 2011 I have it set so we have a student ou and a staff ou and a computers ou - students have on main group policy which supplies most of the settings then further down the tree there are some specifics for year groups etc. as for internet i just add individual users to the blocked lists in dansguardian. 1
s1mon321 Posted April 4, 2011 Author Posted April 4, 2011 Cheers for all the advice folks. We have just created another OU for the 'blocked internet' students and have linked an incorrect proxy policy to it. Any students in that OU can no longer access the internet :-)............unless they use a PC that they've logged onto before :-( If they do that then the internet is still accessible. Any ideas??
glennda Posted April 4, 2011 Posted April 4, 2011 what proxy are you using? I find it's easier blocking it at that end rather then on the client.
s1mon321 Posted April 4, 2011 Author Posted April 4, 2011 Unfortunately its through the local authority and we don't have access rights to make changes.
s1mon321 Posted April 5, 2011 Author Posted April 5, 2011 Any ideas why this doesn't seem to be taking effect on machines that the 'blocked users' have logged onto before??
Hedghog Posted April 5, 2011 Posted April 5, 2011 Hi This sometimes happens when the PC is not deleting local profiles on exit. It can also happen if the PC is not updating Group Policy - try running "gpupdate /force /boot" at the command line and then testing. 1
glennda Posted April 5, 2011 Posted April 5, 2011 If you are running XP try installing the User hive Cleanup Service from MS. Also look at implementing a local proxy (will help with speed to well webpages used a lot (like google homepage)) there are lots of free softwares out there which will do it such as smoothwall express squid/dansguardian. 1
eddyc Posted April 12, 2011 Posted April 12, 2011 We have an internal ISA here before our connection to our LEA. We have a group which is set to deny internet access called banned users and we simply add any banned pupils into this group. This does not then matter whether the pupil has logged in before or not as the ISA server blocks in it real time. It's also great for caching frequently visited websites 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now