-
Posts
1,643 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ajbritton
-
Nephilim, how did you copy the profile if the 'CopyTo' button was greyed out? Do you mean you just copied the files? I don't consider myself an expert on profiles on Win 7, but in the XP days, this would not have worked as it would not reset the permissions inside the user registry file NTUSER.DAT. This would mean the group policies would not be applied. Interestingly, I note that on my home PC (Windows 7 Home Premium), the CopyTo button does become enabled if I select the 'Default Profile' entry. Not sure what this means.
-
This sounds to me like an account security elevation issue. As I'm sure you know, when you run apps in Win7, it runs as a limited user, even if you have local admin rights. The Copy To button is presumably part of the Explorer shell process or is launched by it and therefore runs in the same security context. I've not looked at Windows Enabler, but my guess is that it allows you to use shell features in an elevated context. EDIT - Ignore all the above. There is more to this than security levels and Windows Enabler does not affect privilege levels. Also turned up this... The Deployment Guys : Configuring Default User Settings
-
How do you restrict access to network folders
ajbritton replied to gill's topic in How do you do....it?
If you aren't using AD then I'm not sure how much use the CACLS approach would be. You could script the creation/deletion of the share though. This script would have to run on the server where the share is hosted. Net Share Syntax: Net share -
I believe that our school support team are looking at MDT to prepare images. From the outside it does look like a fair old learning curve, but then so was RIS.
-
Not true I'm afraid. One of the files in the profile (NTUSER.DAT) contains the registry for the HKEY_CURRENT_USER hive. This has permissions on the registry structure INSIDE the file. This is unconnected with the ACL on the file itself. Using CopyTo will modify these permissions. If you don't do this, the only option is to use RegEdit to manually connect to registry settings in NTUSER.DAT and modify the permissions. However, since there is no documentation as to what permissions should be set across all the keys under HKEY_CURRENT_USER, it's best to let the OS do it for you in the way that is known to work and as Microsoft intended. IMHO I've lost track of the number of times I've had to explain this to people. That's one of the reason I wrote up the WIKI article in the first place. I've certainly seen failures to apply group policy due to this issue on several occasions and if you think about it, it's logical. When Windows creates a new profile, it grants the user who creates it permissions to the files and in the registry. If you then copy the profile and try to let someone else use it, that user won't have the necessary permissions to update it. Looking at the registry permissions on HKEY_CURRENT_USER\Software\Policies on my PC shows me that the only users with access are Administrators, System and myself. Since the group policy extensions run under the security context of whoever logs on, that user must have the necessary rights to write to the registry or policy settings cannot be applied. Another option might be to enable verbose USERENV logging (http://support.microsoft.com/kb/221833). This gives a wealth of information on what goes on during logon but can be rather tedious to pick through. It might also be worth disabling caching on the share (http://support.microsoft.com/kb/287566)
-
Here's the main man presenting a round table discussion on pilot & deployment of 7. Must admit I've not watched it through but the first 5 minutes looked interesting. Springboard Series Virtual Roundtable
-
When you create the original mandatory profile, how did you make the initial copy? Unless you use the Copy Profile utility built into Windows and set permissions in the profile (not the file/folder permissions), the profile will never work properley. See 'Creating Mandatory Profiles' here: Mandatory Profiles - Wiki
-
What access to give a long term, mature, work experience user?
ajbritton replied to reggiep's topic in General Chat
Give him a standard account (e.g. JoeBloggs) . If he needs anything more than that then create a second (AdmJoeBloggs) account and grant it the minimum permissions you can get away with. Have him log on using the standard account and then use the AdmXXX account to remote log on to servers or to 'RunAs' tools like AD Users & Computers or MMC and so forth. -
LGFL synetrix web filtering
ajbritton replied to lionsl2005's topic in Internet Related/Filtering/Firewall
Many thanks Tom. To be honest, there is no particular problem I'm trying to solve other than just trying to understand what is and isn't possible. I'll PM you with more details rather than hijack this thread any more. -
LGFL synetrix web filtering
ajbritton replied to lionsl2005's topic in Internet Related/Filtering/Firewall
Thanks Tom, that's exactly what I thought. I was hoping to get confirmation from someone who has been there and done it. The only doubt I had was that I was unsure if a local proxy was able to link to an upstream proxy. I'm still not 100% clear on how SSL traffic is proxied unless the proxy just acts as some kind of router, passing packets between the client and server. Do you know of any good explanations on the net? Just found this (Tunneling SSL Through a WWW Proxy) which seems to explain it. I cannot see any reason in principle why there could not be a chain of proxies, each one sends the CONNECT message on to the next in order to prepare for the connection. Once all proxies are 'alerted', then the client can set up the TLS connection and all the proxies would presumably just pass it through. Indeed, the line suggests that this would work. This would mean that the filtering could be applied at each proxy. Any reason why this would not work? -
LGFL synetrix web filtering
ajbritton replied to lionsl2005's topic in Internet Related/Filtering/Firewall
Those of you running local content filters - I'm interested to know how this works for SSL/TLS traffic. I assume you are configuring browsers to connect to local proxy servers and the traffic is then sent on to the upstream proxy at Synetrix. If this is the case, are you still able to take advantage of the content filters at Synetrix to block the really nasty sites that operate over SSL/TLS? My understanding is that this is problematic since in this configuration, the Synetrix content filters are effectively 'transparent proxies' and it's not possible to transparent proxy SSL/TLS due to chain of trust issues (unless running as man-in-the-middle). Thanks.. -
[pics] Collective Nouns [For Supernatural Entities?]
ajbritton replied to 6Foot2's topic in Jokes/Interweb Things
We shouldn't feel left out either. Collective nouns for geeks; The collective noun for geeks Collective Noun for Geeks : Good Math, Bad Math The collective noun for Geeks! | Community Site My own suggestions; * A jitter of geeks * A jabber of geeks * A kludge of geeks * A packet of geeks * A stack of geeks * A rack of geeks * A subnet of geeks * A ridpool of geeks * A namespace of geeks bored now. going for lunch -
[pics] Collective Nouns [For Supernatural Entities?]
ajbritton replied to 6Foot2's topic in Jokes/Interweb Things
lol - a district of prawns -
I think you could achieve this as follows be creating an AutoIt GUI which has an 8 x 3 grid of buttons on it, the sizes and positions of which are determined at runtime, based on the @DesktopHeight and @DesktopWidth macros and a bit of simple maths to break up the screen into the appropriate number of pixels.
-
I also remember his time at PCW when I was an avid reader. A sad loss. Goodbye Guy.
-
A technique that I have mentioned a couple of times is to cache copies of mandatory profiles on the C: drive of the PC as follows; * Create a folder 'C:\Profiles' on all PCs where mandatory profiles may be used and set security so such that normal users have read-only permissions * Have a startup script use Robocopy (or similar) to copy the mandatory profiles folder down to 'C:\Profiles'. Configure the copy command such that it 'mirrors' the files on the server. * Modify user accounts such that they load mandatory profiles from C:\Profiles\(profile name). Profiles can still be managed centrally and will auto-update when PCs are rebooted.
-
There's a hundred and one ways to solve this, but one that just occurred to me would be as follows; On each PC... Create a folder; C:\Scripts Put a batch file in C:\Scripts called Printers.cmd Edit Printers.cmd to map printers appropriate to the location of that PC Have your logon script call C:\Scripts\Printers.cmd A more efficient method On each PC, set an environment variable called PCLOCATION and set it to the room name/number In a central location, create a Scripts folder (could use NETLOGON) and create a script for each room name/number Have your logon script call \\server\share\%PCLOCATION%.CMD
-
SID changing not required (and never was!) Mark's Blog : The Machine SID Duplication Myth
-
Saw them quite a few years ago now, not long after Broadsword & the Beastie was released. I loved that album at the time, but it's the older stuff that's really aged well I think. Speaking of 'prog', BBC4 has re-shown some good documentaries about prog lately.
-
K9 killed my laptop on 2 occasions forcing me to use Windows restore to previous state to recover. I'm now using Microsoft Family Safety: Family Safety - Windows Live
-
I have heard that it's JavaScript performance is much improved. Have you tried it?
-
Remotely query MS Office installed components
ajbritton replied to fafster's topic in How do you do....it?
Technically this should be possible either by examining the registry or using Windows Installer functions, but I suspect neither of these methods will be straightforward. If I had to do this, I think I would write a script that does the following (it would need to be run against each PC, perhaps as a startup script or pushed using something like PSEXEC). 1 - Determine the local Program Files location (usually 'C:\Program Files') 2 - Scan through the sub-folders looking for folders containing word 'Office' 3 - Fully scan each sub-folder with 'Office' in the name, searching for known Office executables (winword.exe, excel.exe, msaccess.exe etc). 4 - If necessary, you can detect the version from the executable (AutoIt can do this quite easily) and deduce which Office version the feature is from. I know that this sounds complex, but unless there is a Windows Installer expert out there who can tell me different, I think it would be the best way forward. Now you just need someone to write the script for you. -
Useful websites / guides on profiles?
ajbritton replied to kaphc's topic in Windows Server 2000/2003
You're welcome. I wrote a lot of the profile stuff myself a few years back. It was written in the days of XP/2003 so I can't vouch the the accuracy or applicability with Vista/7/2008
