Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. Might be useful: Run control panel applets as another user
  2. Here's another good one to vote for... Remove ""Cancel"" option on SIMS Upgrade screens
  3. There's no need to create a single share for every user. Just create one share and then let folder redirection take care of the rest. eg Create - D:\Users Set permissions on D:\Users as follows; - Administrators: Full Control (This folder, subfolders and files) - System: Full Control (This folder, subfolders and files) - Domain Users: Create Folder (This folder only) - CREATOR OWNER: Full Control (Subfolders only) Share D:\Users as Users Set Share permissions to Everyone: Full Control Set MyDocs folder redirection for users to \\server\Users\%username%\MyDocs If you still need a drive mapped to home directory, set path to \\server\Users\%username%\MyDocs If you want to do Application Data or Desktop redirection, then you can redirect to \\server\Users\%username%\AppData and \\server\Users\%username%\Desktop respectively
  4. Another gotcha with redirected folders is when you come to migrate them to a new server. Unless you can guarantee that your new server will have the same name (in which case you can just move the files and recreate the root shares), it's best to implement DFS so that the redirection target is not directly linked to a particular server.
  5. ajbritton

    AutoIT help

    The correct way to do this would be to author the MSI so that the script runs in installation only. To do this you need to add the 'NOT Installed' condition on the custom action.
  6. http://www.2x.com/
  7. ... and now we have another list to look through. At least the page on the wiki is categorized and can be updated by anyone (when the wiki is working!). I don't want to sound ungrateful, but this does not seem like a very good way of maintaining a list.
  8. I should perhaps make it clear that I support a lot of primary schools. It's rather difficult enforcing a secure password policy on primary school teachers. ..and primary school kids as well of course
  9. Issues relating to saving things on drives that are not accessible to other users are nothing whatsoever to do with how many domains you have, they are simply to do with configuration or having more one server. As long as the domains trust each other (implicit when the domains are in the same forest), rights can be assigned to users and groups from either forest, so the issue is really where the files are located, not who can be made to access them. There is nothing to stop users who have accounts on an 'admin' domain having access to folders on a server in the 'curric' domain and vice versa. As regards to resilience, it's easy enough these days to run a virtual DC as an additional domain controller to provide resiliency. How about this scenario for a small site; 2 servers (call them A and C) - Server A is the DC for the admin domain - Server C is the DC for the curric domain Install VMWare server on both servers Install a virtual server on each server and make it an additional DC for the other domain (eg Server A hosts a VM which is a DC for the curric domain) That way you get 2 servers, 2 domains and resilience. I agree with broc about 'making an informed decision', but lots of people seem to think that 2 domains make it harder to share information and that is simply not the case. EDIT: As regards to logon issues, if both domains are in the same forest, then the 'user principal name' can be used, so that users don't have to worry about which domain they are logging on to. The UPN is unique throughout the forest.
  10. But why have one domain when two is actually better. You can isolate SIMS and have greater flexibility with domain level security (password policies). If you have a single domain and it goes kaput, then that's your whole school system down for as long as it takes to fix it. The only argument that I've heard is that a single domain is 'easier' to manage or maintain. Why? Management is all done through ADUC or GPMC which can easily switch between domains.
  11. One possible way around this would be to add a scheduled task on each PC to perform a shutdown at a specific time. This could be installed/managed from a startup script.
  12. Part of the problem may be that the software wants to create temporary files under C:\Program Files\Digital Blue\PC Digital Movie Creator 2.0\User Files\Temp (and Temp Content) Seems I was wrong about this being a permissions problem. The installer sets permissions on the 'User Files' folder to give Everyone Full Control. Nice one Digital Blue, you just shot people using Software Restriction Policies in the foot.
  13. Elsewhere I proposed having some kind of 'EduGeek mark' whereby software that was easy to maintain could be hilighted.
  14. @techyphil: You may want to have a look at BackupAssist (http://www.backupassist.com). It's a much friendlier front-end that uses NTBACKUP as it's backup engine. It will take care of all the scheduling for you and allow you to select a backup strategy that suits you. It will then email you with reminders when you need to change tapes or clean tape drives. You can download a 30 day trial.
  15. I to redirect App Data at many sites and have only had one issue with a piece of crummy software which appeared to dislike App Data being on a UNC path. Please bear in mind that there are know issues with placing .PST files on the network. This has been discussed elsewhere.
  16. You do not need to map the drive specified in AD. Windows does this for you.
  17. Reinstall the service perhaps? What is it exactly?
  18. Are you asking for individual titles or categories? I repackage mostly primary school software and TBH the biggest problems are those that use InstallShield installers. Where authors have gone down the ISScript route, there is the well known issue of the various ISScriptX MSIs using the same internal product code thus making deployment difficult. Recent InstallShield installs appear to register zillions of components in the registry which are very time consuming to remove. I also try to make sure I pick out any references to third party components (eg Flash), which is also tedious. Can you tell us more about the idea that you are looking into? I have mentioned to various people in the past the idea of a pressure group which promotes some sort of standard for software installation along the lines of - MSI based installers tested in AD software installation - All configuration to be done using public properties to enable simple transforms - License codes to be entered as part of an 'admin' install in the same way as Office Software which meets the requirements could be awarded the 'EduGeek Mark' or some such thing. We could also try to persuade authors to stick to Microsoft's guidelines for applications like not writing to 'Program Files' and HKLM etc.
  19. Look for SIMS.MDF. It's usually under MSSQL$SIMS\Data
  20. This is not a trivial task by any means if the only tool you have is Orca and not much experience. What I tend do to is to create a transform (.MST file) which adds a custom script that runs after the install. The script can then do whatever you need it to do, including copying in extra files from the installation source. Create a new Transform file Add these 2 entries to the CustomAction table Action=SetPostInstallScriptPath Type=51 Source=PostInstallScriptPath Target=[sourceDir]PostInstallScript.exe Action=RunPostInstallScript Type=3186 Source=PostInstallScriptPath Target= Add these entries to the InstallExecuteSequence table Action=SetPostInstallScriptPath Condition=NOT Installed Sequence=(a number just after PublishProduct sequence number) | Action=RunPostInstallScript Condition=NOT Installed Sequence=(as above)+1 Save this transform calling it something like PostInstallScript.mst. Create the post installation script in AutoIt, compile to PostInstallScript.exe and save it in the same folder as the MSI. Test, test and test again!! If you are assigning with AD then be sure to add the MST as a modification when doing the assignment.
  21. Would it be possible to do it like this... Create a share and set the following permissions Administrators: Full System: Full Creator Owner: Full (subfolders & files only) Domain Users: Read, List, Create Folders (this folder only) Now set up folder redirection to \\nasbox\share - Tweak the 'grant full permissions' accordingly The folders will be created when the user logs on and the permissions should be correct.
  22. Both these are delivered as MSI packages. It generally considered a 'bad idea' to attempt to re-package MSI based apps. You need to customise the install by creating a transform file (MST). This can be done using Orca if you are a Windows Installer expert, or using a tool like InstallShield Tuner.
  23. Assuming you are assigning IPs with DHCP, it should be possible to extract MACs from there. There is a freeware utility SpecOps GpUpdate which uses this technique to do WOL against computer accounts in AD.
  24. How exactly did you 'remove' the box? Do you have any other Exchange servers in the organization?
  25. You can try BackupAssist for free for 30 days, so there's no excuse not to have a look! As far as the permissions problem, it may be that students are modifying the permissions on their own work. There are a few things that can be done about this; 1 - Lock down the UI on student PCs so they don't have command line or 'security tab' access. They must also be restricted from executing non-approved scripts/programs which might modify security on files. 2 - Modify the root share permission that students connect to so that they get no greater than 'modify' or 'change' access (ie not Full Controll). That should prevent security changes, but also interferes with folder redirection. 3 - Run an overnight script (preferably prior to backup), which takes ownership of all files in the user area and makes sure the right groups have the right access (eg Administrators: Full, System: Full)
×
×
  • Create New...