Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. ajbritton

    Exchange

    You can do MAPI access using RPC over HTTP. This allows you to connect the full Outlook client over the Internet using HTTP. It's obviously nice to have domain integration but by no means a necessity. When Outlook is launched, it would simply prompt for logon details.
  2. Advanced installer (http://www.advancedinstaller.com/) is free if you want to author from scratch. Wise Package Studio is about the best if you need to repackage existing installations (or author from scratch).
  3. ajbritton

    Exchange

    I've recently found out that of local broadband consortium (LGfL) will be providing an enhanced email service based on Exchange, providing full Outlook access, OWA and even secure email.
  4. ... or this ... http://www.communiqueconferencing.com/meetingmanager_msi.pdf
  5. Is this any user? http://support.webex.com/support/downloads.html
  6. ajbritton

    Admin Network

    It's abput 80 - 20 for a Single Domain for a Single School.... So only 20% are making additional work for themselves... ... and the other 80% not doing their jobs properly :twisted:
  7. I really enjoyed helping out last year and would love to do it again. My situation is slightly different know so getting approval from my employer may not be as simple as before. Does anyone know if Art, the Moodle guy will be there? I thought he was pretty cool.
  8. Main thing you will need is DNS resolution for DCs in each domain. You generally need to set up forwarders or secondary zones. Do you have seperate DNS infrastructure for each domain?
  9. If you want an inexpensive SQL backup solution, you could have a look at BackupAssist, which has an SQL plug-in available. Educational pricing available.
  10. Backup logs?
  11. ajbritton

    Exchange

    Another vote in favour on Ex2K3. I had some bad experiences having to do disaster recovery on Ex2K boxes, but I've found 2K3 to be very solid. DR should be simpler with the recover storage groups. Installing Exchange should not be an 'install it and forget it' operation. The fact is that email very quickly becomes the life blood of most organisations when it is rolled out to everyone. Any downtime is viewed as unacceptable so I would say the following; 1 - Learn about it before you roll it out. Install it on a test server and fool around with it. If possible go on a course which covers installation, configuration, management and recovery. Exchange is a complex product and you don't necessarily uncover everything you need to know just by playing with it. 2 - Do a phased implementation. Don't go big bang to the whole school. 3 - Monitor the server regularly. This is probably the best way to avoid downtime. 4 - Have a proper DR plan. This should include more than just doing backups. You need to test the recovery steps so that you know what to do when the day comes you have to do it. I've run Ex2K3 in VMs running on Core2Duo PCs with 1Gb RAM with no trouble. RAM is the key thing for Exchange, along with a solid disk platform.
  12. The StopNetBrowse is ripping through the CPU cycles because it is running a tight loop looking for Windows containing the text '\\'. All this should need is a short time delay (say 500ms) in the loop which would give the CPU time to do something else. A quick look in the AutoIt help file suggests that Opt("WinTitleMatchMode", 2) Opt("TrayIconHide", 1) while 1 if WinExists("", "\\") Then MsgBox(4112, "Caught!", "Gotcha!", 1) ;WinKill("on", "\\") EndIf sleep(500) wend should do the trick.
  13. Good point Maniac. That's definitely worth checking.
  14. Although I have 'dissed' the idea of using regedit to set the registry permissions in a profile, it might be worth using it to check the registry permissions on network default user profile 1 - On an XP machine, run REGEDIT 2 - Select the HKEY_USERS hive root 3 - Open the File menu and select Load Hive... 4 - Browse to \\(yourservername)\netlogon\Default User 5 - Select NTUSER.DAT and click Open 6 - Enter a name (eg NETDEFUSER) and OK 7 - Open up the HKEY_USERS key 8 - Select the key with the name you entered (eg NETDEFUSER) 9 - Open the Edit menu and select Permissions... 10 - Check and record the configured permissions for each group/user 11 - Click Cancel to close the Permissions dialog box IMPORTANT - Make sure you do the following steps 12 - Ensure the key with the name you entered is still selected 13 - Open the File menu and select Unload Hive... then click Yes 14 - Close regedit Report back with the permissions that you find.
  15. As Maniac says, you can edit the permissions in the user.man file using regedit, but how do you know what they are supposed to be? My understanding is that when you use the 'Copy To...' function to modify the permissions (eg grant permission to Everyone), it does more than just a blanket grant of Full Control to the whole registry hive. Permissions on policy related keys are not the same as permissions elsewhere in the user hive. If I were chrbb, I would want to re-create the profile from scratch.
  16. @chrbb, The permissions in a profile cannot simply be changed my modifying the file system ACLs as per your example. When the profile is copied from the source PC to the network, it MUST be copied using the 'Copy To...' function and the permissions modified at that point. This modifies not only the ACLs on the files, but also the ACLs within the registry (within the NTUSER.DAT file). If this is not done, then GP settings cannot be applied because the user trying to load the profile does not have the necessary permissions to write to the registry.
  17. Hi chrbb You should certainly never have to deny access to the local default profile. Just to confirm (as it's not 100% clear from your post), how did you copy the profile from the source computer. If you dragged/dropped from 'C:\Documents and Settings\username' to the network and then modified the file system ACLs, then this is not sufficient. You must use the 'Copy To...' function from the user profile list in the System Properties dialog box. Have you checked the event logs on the PCs after logging on as a test user?
  18. Anyone remember llamatron on the atari?
  19. Sounds like permissions on the profile. Was the profile originally copied using the GUI copy function and permissions changed to allow access to Everyone? See the wiki guide on mandatory profiles for more details.
  20. Everyone on this thread should love hey hey 16k over on b3ta...
  21. If you really want to prevent this, one way would be to use switches that lock themselves to the MAC address of the connected device. Any ports that are not connected are deactivated automatically. If a student brought in a laptop and plugged it into an empty port, they would not be able to access the network (and therefore DHCP server would not be able to hand out IP addresses). If they unplugged a PC and plugged the laptop in, the switch would lock the port out as soon as it detected the new MAC address. In theory, the only way around this would be the the laptop to spoof the MAC address of the PC that was plugged in. Perfectly possible of course.
  22. This any use? UltraVNC MSI Creator
  23. There is a group policy setting (its a machine setting), that causes the Administrators group to be added when roaming profiles are created. Well worth setting this one. There is another group policy setting (machine again), that causes XP (not sure about 2K), to be less fussy about the ownership of files it finds in users' roaming profiles. In essence, you need to do the following; 1 - Take ownership of the whole folder, making sure the changes apply to all files/folders 2 - Add the Administrators group (or Domain Admins) to the folder and again, make sure the changes apply to all files/folders 3 - Depending on whether or not you deploy the 2nd GP setting mentioned above, change the ownership of the whole folder and files back to the user to whom the profile should belong. You should now be able to edit the profile.
  24. If you are sharing a single mandatory profile then the easiest way would be to update that, as you suggested.
  25. AWE sounds a bit like EMS if anyone remembers that!
×
×
  • Create New...