Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. You need to copy the template profile to the NETLOGON share on your domain controllers eg '\\server\netlogon\Default User'. Also, be sure to use the Windows GUI to copy the profile so that you can set the 'permitted to use' list to Everyone. Another way around this is to create a startup sript which updates the Default User profile on the PCs with a copy from a server based location. Personally, I would never tinker with the Default User profile on individual PCs as it can be useful to be able to log on to them as local Admin for troubleshooting.
  2. Maybe a moderator could rename this thread '2 down, 5 to go' 'cos I just passed my MS 70-290 this morning. Modesty forbids me from revealing my score, but it was 1110100000 in binary! If anyone else is about to do it, make sure you know your backup types, share permissions, NTFS permissions, performance and monitoring procedures... EDIT - Just rename it myself. No forum expert yet me!
  3. You need a gateway so that you can route traffic to other networks. If, for whatever reason you proxy server is not on your local subnet, then traffic for it is routed via the gateway. This is not usually anything to do with stuff running at the application level however. The network layer should take care of it.
  4. You need to set the 'run logon scripts synchronously' policy.
  5. I don't know if there is an easy way, but I'm sure the Flex Profile Kit will enable it to work.
  6. Sorry, but this is NOT true. When a user creates a file, they are the owner of it and regardless of the permissions that the file may inherit, the file owner has the permission to change the permissions. It does appear to be possible to prevent this by limiting the overall permission via the share (ie using Change instead of Full Control), but IIRC, Windows will not let you redirect My Documents to a folder that you do not have Full Control over.
  7. Hear hear. Maybe we need an 'I came hear for an argument' forum where we can 'take it outside'...
  8. Given what I was saying, that sounds very odd. What are the NTFS folder permissions and what are the permissions on the share that the users connect to? EDIT: And just in case, what AD groups are your students in. Any chance they are accidentally domain admins?!?
  9. I would also point out that when you copy profiles, you MUST MUST MUST use the GUI copy (ie My Computer, properties, Advanced, User Profiles Settings, (select profile to copy), Copy To, (enter or browse to target location), Permitted to use Change, Enter Everyone (for Default User profiles), OK, OK. This is necessary for the permissions on the registry to be changed. I don't mean the file permissions on NTUSER.DAT. There are permissions INSIDE the registry that will not be altered if you just copy NTUSER.DAT using explorer.
  10. Move the ServicePackFiles folder MS KB article - Although the article states that it applies to Win2k3, it may be 2K only. Delete $NTServicePackUninstall...$ folders from C:\WINDOWS - If you do this you will not be able to unintsall service pack. Delete $NTUninstallKb....$ folders from C:\WINDOWS - If you do this you will not be able to uninstall hotfixes.
  11. Agree with everyone. Script is the way to go. If you must have different Default User profiles on a per room basis, then I would create an OU structure which isolates the rooms, then create a GPO for each room 'OU' which has a startup script whose job it is to copy down a specify Default User profile to the PC
  12. AFAIK, Capita do not test SIMS.NET on Terminal Services although I believe some have made it work.
  13. It will if they are in the same forest.
  14. Just in case anyone out there is confused by the Intel Xeon range (I sure was), then this is very roughly how it appears to me... 3000 series - Basically a Core 2 Duo with a different badge - Limited to single CPU operation 5000 series - Dual core but based on older Pentium D style NetBurst architecture - Limited to dual CPU operation 5100 series - Again, basically a Core 2 Duo - Limited to dual CPU operation 7000 series - Dual core but based on older Pentium D style NetBurst architecture - Multi processing 7100 series - You guessed it.. It's a Core 2 Duo - Multi processing Unless of cours, you know different
  15. It may be overkill, but the FlexProfile kit will let you create a hybrid profile which is basically mandatory, but with the bits you want to keep.
  16. Outlook Express certainly can connect to an Exchange Server. Exchange has SMTP and POP services, and Outlook Express will quite happily work with them.
  17. Thanks Steve. I've not had much of a chance to play with R2 yet, but from what I can see of Technet, that certainly looks like one way around the problem.
  18. Thought of a possible problem scenario... 1 - Disk quotas are in use on the volume where students store data. 2 - Students have discovered that they can lock staff out of files/folders by modifying the permissions on them. 3 - Tech staff decide to run a script to normalise the permissions on all student files/folders. This fails because they no longer have access to the files/folders in question. 4 - Tech staff modify the script to take ownership of the files back before modifying the permissions. This works, but in the process, all files now no longer 'belong' to the students, so the quotas are all stuffed up. The solution I guess is to assign ownership of the files/folders back to the correct students. I believe this can be done (might need SetACL). I would be interested to know if anyone has achieved it.
  19. Actually - being the owner of the file is not the same as having full control. The rule is that the file will inherit the permissions of its parent directory. Being the owner means that you are granted change permissions permission (try saying that after 12 pints), but unless the user then makes use of that they will still only effectively have modify permission and unless they remove inheritence or explicitly deny you permission you will still have access. A script to audit access denied run overnight is sufficient to pick these up. I take your point, but in essence, if you create a file, there is nothing to prevent you from having full control over it. I know of at least one school where this was discovered by students and exploited. It helps to remove the security tab, remove CACLS and use Software Restriction Policies to ensure students cannot execute any code that you have not sanctioned.
  20. As I said though. When a student creates a new file, they become the owner of it. This automatically gives them full control on the file, ragardless of the permissions on the folder. To my knowledge, the only way to prevent this behaviour is by restricting the permissions on the share. This can cause problems with folder redirection however.
  21. I have an AutoIT script which I am still developing (taking ages to get it just right), and will share it when I can trust it. There are a couple of things that might help you though... You do not need to map a drive to install SIMS. It will happily install from (and indeed run from) a UNC path. I explicity share the SIMS Setups folder (as SIMSSETUPS), so I execute the installs from \\server\simssetups\SIMSInfrastructure.exe etc.
  22. ajbritton

    sus errors

    Some WSUS resources WSUS Info forums WSUS WiKi WSUS Deployment Guide (MS)
  23. ajbritton

    sus errors

    SUS no longer supported as of last December IIRC.
  24. Be aware that there is a limit on the length of time a computer waits for startup scripts to complete. There is a GP setting which can change this.
  25. Si, Download and install at least the 'base edition', to the root of a USB drive. Re-insert the drive. If it does not 'autorun', then open the drive and double click 'StartPortableApps.exe' The backup utility is on the PortableApps menu which should now appear in the system tray. Autorun is a computer property.
×
×
  • Create New...