Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. Script is simple... NET LOCALGROUP "Administrators" "MYDOMAIN\Local PC Admins" /ADD
  2. @rusdev: I've looked at the EULA that comes with PsTools and it does not mention scripting anywhere....
  3. Be aware license terms of pstools dosnt allow scripting anymore Ouch. Thanks for pointing that one out. It's a big shame, PsTools are priceless IMHO. I generally use them attached to the likes of VNCNeighbourhood or AngryZiber IP Scanner. Is that within the license I wonder?
  4. You can let them install local applications by giving them access to a user account which is a member of the local Administrators account on the workstations. I run a startup script which adds certain domain groups to the local Administrators group to automate this. e.g. 'Local Computer Admins'. Add the staff accounts to the Local Computer Admins group.
  5. Try PsLoggedOn from the PsTools suite available from SysInternals. It will tell you who is logged on to a particular workstation. You'll have to script the rest though.
  6. If we're talking about EFS, then there's one big issue in the following scenario 1 - User encrypts their home folder (or even just a few files) 2 - User forgets password P 4 - You change the users password 5 - Encrypted files cannot now be accessed unless user remembers original password. I believe it is possible to get around this by setting up a recovery policy (never done this though), which would enable you to recover the data. Either way then you'll be able to get at the data.
  7. @Snuffkins: Here's what I would try... 1 - Using RISETUP.EXE, create a completely new build from a volume license XP SP2 CD (don't use an nlite created build). Make sure you give the build a name with NO spaces in it eg GENERIC_XPSP2. 2 - If the NICs you are using are not built into XP, then add the .SYS and .INF from the NIC drive to the i386 folder created. This should be enough for the build to go ahead. Don't bother trying to integrate any other drivers, $oem$ files or messing with the .SIF. 3 - Restart the BINLSVC (Remote Installation Services) service. 4 - Try RIS building a PC. This will prove the mechanism is working. If it fails, then it sounds like a problem with your RIS infrastructure. If it works, then I suspect your other builds.
  8. Well, we have experimented with auditing on SIMS servers and not had any problems. I think it depends on what you audit.
  9. A quick google for 'MFT Entry Modified' has turned up this... any use? EDIT:Oops! Just realized that SleuthKit is a Linux thing./EDIT
  10. Not true. You need to enable auditing and set the events you want audited, but it can be done.
  11. You have to ask yourself two questions? 1 - 'how valuable is the user data?' If the user data has no value, then you need not back it up. If it is essential then it should be backed up as often as possible. Somewhere inbetween is usually the trafe-off. 2- 'how long can I afford to be offline?' If you enjoy setting up systems from scratch and can do it at the drop of a hat, then no 'system' backup is necessary. If, more likely, your system constantly evolves, and rebuilding from bare metal would take days they you need to backup the 'system'. The 'system' is really everything that is not 'user' data. Assuming your workstations are 'ghosted' and there is no user data on them (all data should be kept on the server, that's what it's for after all), then you don't need to back them up. The only data you don't need to backup are those that can be automatically rebuilt (eg WSUS content, AntiVirus updates). If your server has room, you could add a couple of internal SATA/IDE drives (cheap 250gb jobs would do), then mirror them (using 2003 volume mirror function). Data could then be backed up to these drives using NTBACKUP/ROBOCOPY. Downside to this is that if the server dies (mobo/PSU) you have no easy access to the data. Better to have the backup drives in some kind of external box either USB connected or NAS (terrastation).
  12. 'attaboy contink. I forgot to mention that EduGeek and the various other setup/install related website forums are obviously good places to browse for MSI info.
  13. Congratulations SYSMAN, your life will never be the same again, I can guarantee it!
  14. Your OUs are there to make management easier. Unless you are using them to set different policies then you don't need to have them. Won't the kids change class every year anyway? Sounds like a good way to make work for yourself. Are you creating individual user accounts for all the Early Years children? Surely they won't be logging on or even saving any work at that stage. Almost all the primary schools I deal with use shared accounts right up to Year 6 although some are considering individual accounts for KS2. If you must create individual user accounts, I suggest creating 'intake xxxx' OUs (so this year would be 'intake 2006'). That way you don't need to move them every year.
  15. Could be file permissions...
  16. Apologies everyone! Having never even used CSVDE, I misread one of the ComputerPerformance pages which seemed to say CSVDE was for use on 2003 only. I stand corrected. Since it works on 2K and 2K3 then the CP pages look like an even more useful resource for those trying to do bulk user creation for the first time. (That's who I guess my original post was aimed at, but I appreciate those who have set me right.) Protocol question: Should I edit the original post to correct my error? Again, I'm thinking of those admins seeking methods of bulk user creation.
  17. Assume you have already got ORCA, which is THE essential MSI utility. It's part of the Microsoft Windows SDK but may be available as a standalone .exe elsewhere if you look around... EDIT I would add that MSIs are horribly complex and the logic is by know means clear even if you read everything on MSDN. I went on a Wise Package Studio course which by necessity included a fair bit of MSI stuff and it was hugely useful. If you possibly can, get on some kind of Windows Installer course. Other than that, go to AppDeploy, DesktopEngineer and InstallSite and scour the site for MSI info and links to other site with MSI info. It is mostly out there if you can find it!/EDIT
  18. Just noticed the CSVDE pages over at ComputerPerformance.co.uk. Looks very useful for those who need to bulk import/export user accounts. CSVDE is 2003 only though
  19. Before you demoted the DCs, did you make sure that the FSMO roles and Global Catalog were held elsewhere? Also, did you check that the demotion events were processed by the other DCs? If so, then AD should be fine and as Roberto says, you need to use the special customized copy of AD Users & Computers with Exchange puts on.
  20. In the past we have used POP Beamer to collect email from POP3 mailboxes and push onto Exchange. Works fine. But as Geoff said, the best way is to get your ISP to forward to your mail server. EDIT: IIRC, Windows 2000 Small Business Server had an extra component which allowed collection of email from POP mailboxes. I don't think the component was available anywhere else. If you have SBS then this may be an option. EDIT: If you are setting up Exchange for the first time, don't forget to think about backups and routine maintenance. You might also like to think about setting limits on mailbox size.
  21. I've been out and about for a few weeks doing installations and upgrades in schools so haven't had the chance to get into the office to finish testing. I've got a big SIMS roll-out in a secondary school coming up though so I'll have to get it working. Watch this space...
  22. Do the builds appear if you look at the properties on the computer account of your RIS server in AD? There's an extra tab 'Remote Install' on RIS server computer accounts which show this info.
  23. Using WIWW is very easy, compared to repackaging which can range from trivial to horribly complex depending on the application. The only tricky part about using WIWW is working out how to do a 'silent' command line install of your application so that WIWW can create the MSI wrapper for you. If the app won't install silently then WIWW is no use. You can of course use something like AutoIT to automate an awkward installation which insists on interacting with the user, then compile the AutoIT script to an EXE and wrap the whole caboodle in an MSI. Yuck! but it does work, I've had to do it a couple of times (thanks Clicker 4), when initial attempts at repackaging failed.
  24. Are you saying that either script, referred to above your post, can be wrapped into an MSI for deployment through GPO? If so, how did you create the relevant MSI? Or, is the script run as a startup script? Sorry if I am being a bit dim here! By the way, I have been able to run the script whilst logged in as an administrator at the client, but this defeats the object of rolling out at startup! Thanks. I used WIWW (Windows Installer Wrapper Wizard) to create an MSI which executes the various SIMS installers. I think tweaked the MSI to set some essential INI values for SIMS.INI (or was it CONNECT.INI, I'm not sure now).
  25. Not quite. It seems that System has 'anonymous' network access, so as long as 'Everyone' has access by the share and file permissions, then this can be made to work.
×
×
  • Create New...