-
Posts
114 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ArchersIT
-
We have ISA 2004 and it does not record the client name, just the client IP address, so I believe that this would not be possible. Jonathan
-
Unfortunately I think you are. I have several students who tell me that their aim is to hack the systems before they leave. I have pointed out that it is illeagle but they dont see the problem. The sanctions that stop normal office users from abusing the systems (disciplinary processes, affecting salaries etc) dont apply at school. They believe the worst that will happen is them being suspended or in detention and the "fame" that they would get by being able to do it seems to them to be worth it. Anyway - FWIW, right mouse click is disabled here - which is a shame (IMO) but I understand the reasons. Jonathan
-
ISA only likes checking the first few bytes of the body - it warns of performance problems if you check too much (although if the server is not exactly stressed so it would probably be OK). Jonathan
-
If you mean blocking the word proxy in the URL, then yes this is possible in ISA 2004 by RMC on the rule and selecting configure http. You can then put in a signature to ban based on the response or request headers, url, bodies etc. We use this for games websites, with a whitelist higher up the order to allow access to educational games sites. Jonathan
-
From http://www.microsoft.com/technet/isa/2004/plan/faq-urldomainnamesets.mspx It looks like this may help as you have listed the url with a trailing / Cheers Jonathan
-
Deny Login to Machines to all except certain OUs
ArchersIT replied to Nick_Parker's topic in Windows
Group policy allow you to set a machine setting that will block log on locally rights to certain security groups. It is in Windows Settings/Security Settings/Local Policies/User Rights Assignmebt and is called "Deny log on locally". We have this set to deny access by students to certain computers. Hope this helps. Jonathan -
One thing to possibly check - the 2007 compatability pack says that Office 2003 has to be up to date before it is installed, so I suspect that a patch (or service pack) may be required somewhere along the line. Ours were at SP2 with some patches done (not all) when we deployed the comaptability pack and I have not had any reported problems since. Jonathan
-
Hi there, I had a similar problem here when I first came - we realised when a student was spatted using firefox to get to a banned site. There was a setting in ISA that had been misconfigured (well kind of). It had been set to allow staff to pass through to the staff LEA proxy - but it allowed anyone to bypass it. This was under ISA 2000 - so your options may vary. For us it was in Extensions/Application Filters/HTTP Redirector Filter. This was set to send the requests out to the requested web server. Changing this back to Redirect to Local Web Proxy sorted it - but of course made the staff go through the ISA filter and onto the student proxy as well. Hope this helps Jonathan
-
So far the only difference seems to be that it requires the profile to be loaded or they cant log in - this is different from a mandatory profile where if it cant be loaded it will try to load the default profile. Jonathan
-
Ok - thanks for all the responses. I have set the Group Policy setting and started to change the mandatory profiles to Super Manditory (I said I believed in belt and braces!). This has done the trick on my test account, I will let you know if there are any problems with rolling out to the rest of the school. Many thanks again Jonathan
-
I would love to Any hints.... Jonathan
-
I have redirected folders on one of my year groups - but it is one of the other year groups that these students have been in! Thanks for the thought though - I will have an investigate around. Jonathan
-
Yes - the madatory profile itself is working fine - we have over 1000 students and it has been working for two weeks, it is just that yesterday and today (with no changes being made) one or two children have failed to pick up the profile and receieved the default one instead. This would be fine if the GP was then applied, but it seems to stop the GP as well. Jonathan
-
They are running as limited users, but without the GP they have access to the C drive and all the desktop settings etc. So far they have only mucked about with desktop colurs etc, but the teachers want to know why they can suddenly do this when it was banned before. Without the GP applied they will also be able to run all the programs that are currently banned. Also, I learned a long time ago that it is better to have many layers of security. While I believe they cannot do any damage, I would rather them not have access to begin with. I am just confused as to why it would not apply the group policy to their new temporary profile when it was applying OK before... Jonathan
-
Hi there, We have a well locked down group policy that has been protecting our systems for some time (Windows 2003 domain - XP SP2 clients). We have recently started applying a mandatory profile to the students to change some settings that are not GP enabled and to speed up the setting up of new profiles. Unfortunately there are occasionally problems loading this profile and if that happens it attempts to load a default profile. In this case the group policy is not applied to the student and they have access to everything. Obviously they dont have permissions to do harm to other computers or the servers but they can make a mess of the one they are on. Looking back through posts on here I have enabled the GP settings to log students off if the roaming profile does not load properly, but this does not seem to have made a difference. Has anyone had any experience of this? Any thoughts what to do? Cheers Jonathan
-
Visual Express not working after cloning.
ArchersIT replied to JimStokes's topic in Educational Software
I also had problems trying to achieve something similar. When reading the licence it is not intended to be used for deployment at a school. If you do need development software like this, you might want to think about the MSDN Academic Alliance agreement which will give you a licence to install the full visual studio (as well as many other pieces of software) on all the ICT computers for a single flat fee of (IIRC) approx 250ukp. Jonathan -
Thanks very much - bit of a lightbulb moment there! This should work admirably, although I am a little cross with myself - you see we currently use this method for creating the old directories (before we thought about using folder re-direction) - I never thought to combine them! Thanks very much Jonathan
-
Sorry - I did reply to your earlier message, but it did not arrive. Anyway, when I try this tick box, then when the folder is created (when they first log in) it blocks inheritance which stops administrators having access. I can obviously change this, but I am wondering if there is a way of achieving it without having to change the permissions after the event. Cheers Jonathan
-
That is the case - I can *change* the permissions - but the default permissions if you let it be created this way do not give the relevant permissions as inherited. Jonathan
-
Hi there, We have just started trying to use Folder Redirection for the students (we do not use roaming profiles). We have read lots on permissions and have setup the permissions as per the various KB articles but am still having a problem with permissions. The main KB article we have followed is Allowing administrators access to redirected folders. This is fine, when students log in they create all the folders and we can see them etc. Unfortunately if we copy a file into that area for them they do not have permission to see it. This is because the folders are auto created with Full Control - This folder only Creator/Owner Full Control - Subfolder and files only Now, the problem is clearly ownership - if we copy files into their areas for them they do not own them. Unfortunately we often do this when a file restore is needed and we would rather not have to reset permssions each time. We could get around this by creating the folders manually before they log in with Full Control (almost!) - This folder, subfolder and files but we kind of liked not having to do this? So - what does everyone else do - do you 1. Create the directories first or 2. Fix permissions when having to copy files in? Many thanks Jonathan
-
I would vote for MSI. We already have mechanisms in place to cope with deployment of large MSIs, so the size is of less importance than the other flexibility we will get. Jonathan
-
Ours our turned on before registration so this would help. However, the real key benefit for me would be an unattended MSI based install for the initial installation - the current method is a complete pain. Cheers Jonathan
-
I would also put the vote in for an MSI based install for SIMS, most of the rest of our software can be installed remotely, but SIMS requires a visit to install/reinstall. We could get round this by having two clone images, one for students and one for staff build, but as soon as SIMS is in the clone it is out of date and so need to be updated before we ship the new machine out to a new member of staff. As to upgrades, the current process is that SIMS checks to see if there is an upgrade and applies it if needed. If we were able to roll these out in a more controller way that would be great - but then we may have problems if people with different SIMS client versions were accessing the same central database. Anyway - definatly a strong vote for an unattended or MSI based install routine for SIMS - upgrades might require a bit more thought. Thanks for asking though! Jonathan
-
No thoughts from anyone? Jonathan
-
This may be a "grandmother sucking eggs" post but when I was playing with loopback in Group Policy modelling it never worked until I noticed the check box to turn on loopback processing. Once I ticked this it behaved as expected. I presume that it does not actually evaluate the policy and so does not know that it should be turned on for specific instances and so needs you to tell it. Hope that helps. Jonathan
