Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. Hi edie209, It sounds like you are ready to try Policy Reporter. It's great for tracking down nasty little policy problems. Basically, you can use it to enable verbose Userenv logging and then to analyse the resulting Userenv.log. Good luck...
  2. From a practical point of view; There are plenty of ways you could give pupils greater control over PCs and still keep them reliable (eg Deep Freeze, Net Runna, Shared Computer Toolkit or even Virtual PC). As long as the PC get rebooted before the next lesson then it should be back to the same state. As far as Internet is concerned, as long as you have a decent firewall/proxy solution then it should be possible to limit access where necessary and broaden it when required. Responsibility; The nature and complexity of IT systems surely make it difficult for staff to take full responsibility for them (why do we have tech staff if not to support pupils/staff). In many cases in primary schools (and possibly many more in secondarys), the pupils know more about the systems than the teachers.
  3. On. If a nasty worm/virus does get onto your network (yes, I know AV should pick it up but you never know...), then your PCs are still protected. It's really easy to configure it, so why not!
  4. ajbritton

    Net-runna

    (looking for an argument) What's the point of these things? A limited user can't do any damage to an XP PC anyway. They can only write to their profile folder, and that can be reset at every logon using Mandatory Profiles. (brace for attack...)
  5. How do you individual mail box recovery or do you just scoop up messages from the journal. Isn't that what the M: drive is for? I believe the other way is to restore to an off-line server and retrieve the mailbox that way.
  6. I've tried this on a basic SIMS installation and it seems to work....
  7. I want to deploy and run the SIMS.NET client from a UNC path. I'm going to do some quick virtual testing, but I wonder if anyone knows or has tried this?
  8. Available here. Any use?
  9. Do you have other GP settings which are definitely working? Also, check the event logs...
  10. @e_g_r: From your first post, it looks to me like the profile was NOT a mandatory one. Mandatory profiles have NTUSER.MAN, not NTUSER.DAT. You cannot share non-mandatory profiles between users. Either make the profile mandatory (rename NTUSER.DAT to NTUSER.MAN) or give users individual roaming profiles. (See the wiki for further details)
  11. This will give you 36Gb storage, not 74Gb. You will lose some space due to formatting, more for 2003 server then even for for the swap file. You'll be doing well to have 30Gb left.
  12. R U saying that user settings or computer settings are not being applied? Bear in mind that that for policies to apply, they must be set at an appropriate level in AD. It is generally good practise to keep your computer accounts seperate from your user accounts. Most people create specific OUs to do this. It is then easy to assign computer policies to OUs containing computer accounts and user policies to OUs containing user accounts.
  13. Funny, I've never had a problem with ownership on home folders / redirected MyDocs. I know XP likes to have Full Control when it redirects to the folder, but I almost always pre-create the folders and have never bothered assigning ownership. Sometimes folders owned by 'Administrators' are acceptable..
  14. Basically, the Custom Installation Wizards helps you create an custom transform file (MST) which tailors the installation of Office at install time on your PCs. 1 - Create an Admin installation point for your version of Office 2 - Download the appropriate resource kit tools for the version of office you are using and install it on a PC 3 - Use the Custom Installation Wizard, pointing it at the main MSI file in the admin installation point for Office. Follow the wizard making any settings you require. 4 - When you get to the Outlook pages in the wizard, you just need to specify the name of the exchange server and to use %username% as the mailbox alias. 5 - Install Office on your PCs using the MST file created by the Custom Installation Wizard. This can be done manually or using GP. In the resource kits for the most recent versions of Office, there is a Custom Maintenance Wizard, which looks very similar to the CIW. This might be useful if you need to reconfigure lots of existing Office installations, but I have never used it.
  15. Could you maybe use CCleaner in command line mode from a startup or logon script to clear the IE settings you need to?
  16. ajbritton

    Net Use

    I use it in a logon script and it works fine. My logon scripts are assigned via GP (not user account property).
  17. Since I've gone over to using \\server\usershare\%username% for home drive and My Docs redirect I've had to add an ACE to the folder which is shared as 'usershare'. I just give Authenticated Users List and limit it to 'this folder only' so it does not propogate to the user folders. This solved my Office access issues.
  18. I've found V6 to much better the V5 in all respects execept the memory requirement on clients. I've never recomended schools try running XP in less than 256mb RAM, but a few have managed it. No longer. Every PC/laptop with 128mb RAM and Sophos V6 is effectively a non runner which just sits their paging its hard drive to pieces. Even some 256mb PCs seem to feel the pinch. I love the fact that I can populate the DB from Active Directory, assign then computers to the right group then use GP to install the client.
  19. It's certainly possible to use the Office Resource Kit's 'Custom Installation Wizard' to produce an MST with controls how Outlook connects to email services the first time a user runs it. I've done this lot's of times, and it works beautifully.
  20. If you are using Exchange server then I doubt this would work. The first member of staff to log on with the new profile would try to connect to Exchange as the user that you used to make the profile. If you are using POP/SMTP then I'm sure it won't work, as the POP logon details will only be right for the user you used to make the profile.
  21. According to SIMS KB54041, there should be no problem with having .NET 1.1 and .NET 2.0 installed on the same machines. It also points out that .NET 2.0 is NOT and upgrade to .NET 1.1
  22. Not sure what you mean by this. Are you trying to log on to the server with a non-admin user account? Sounds to me like Windows still thinks the profile is roaming. Did you change NTUSER.DAT to NTUSER.MAN? There are usually two NTUSER files in the profile directory (NTUSER.DAT and NTUSER.DAT.LOG). A common mistake is to rename the .DAT.LOG file. Make sure Explorer is showing you all files and not hiding file name extensions. Again, you're not trying to do this whilst logged on as a non-admin user are you? Here's the sequence (which extra details about where and whom to logon as). Server Infrastructure 1 - Log on to server as Administrator 2 - Create MPM user account as per wiki notes 3 - Create the server infrastructure as per wiki notes Create a mandatory profile as follows 1 - Log on to serve as Administrator 2 - Check that the MPM user account has no entry in Profile Path 3 - Select a PC where MPM has no local profile 4 - Log on to the PC as MPM and make any initial settings required 5 - Log off the PC 6 - Log on to the PC with an account with local and network admin status (eg domain Administrator) 7 - Use the Windows interface to copy the MPM profile to \\(servername)\MandatoryProfiles$\(new profile name), (eg \\myserver\MandatoryProfiles$\Profile1) remembering to assign access to Everyone. (You need to use the copy profile function from My computer, Properties, Advanced, User Profiles Settings, (select the profile), Copy To.) 8 - Log off the PC 9 - Logon to the server as Administrator 8 - Navigate to D:\MandatoryProfiles\(new profile name) and rename NTUSER.DAT to NTUSER.MAN Assign the mandatory profile to a user 1 - Log on to server as Administrator 2 - Modify a user's the Profile Path to \\(servername)\MandatoryProfiles$\(profile name) (e.g. \\myserver\MandatoryProfiles$\Profile1) Test the new profile 1 - Log on to a PC as the user that you modified to use the mandatory profile. 2 - Make some changes to the environment 3 - Log off the PC 4 - Log back on to the PC as the same user 5 - Changes should have disappeared. Good luck...
  23. You could always google for jokes
  24. That might be legal, and for apps with just a few files it might even work, but for an app with thousands of files it would be a bit tedious! The provider of the MSI would need to document very carefully all the files. They are listed in the MSI, but it's not trivial to work out where each file should be stored in the install source tree. If there were a tool that took an MSI install and stripped out all the files, documenting as it went, and a corresponding tool which could be used to suck all the files back in, it might just work. Coders... over to you.
  25. Find out why their profiles are so large. Chances are it's lots of data in either; MyDocuments Desktop ApplicationData Assuming one of these is the culprit then the trick is to make sure that folder is redirected. Have a look at the wiki section on setting up roaming profiles. You don't need a local user on your laptops. The trick there is to redirect the MyDocuments folder and XP will, as Ric says, automagically make it available offline. Laptop users can log on to their laptops using their network logon (cos XP cache's their logon details in some way) and still see their MyDocuments folder.
×
×
  • Create New...