Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. Adding to Pete's list... All software should comply with Microsofts Guidelines for software - Executables in 'Program Files' - Application data which can roami in 'Application Data' - Application data which should not roam in 'Local Settings\Application Data' - User data storage defaults to 'My Documents' See Microsoft site for full details
  2. Apparently it's big with those funny Citrix people
  3. eh??? Is this a typo? When I talk about copying with the GUI, I'm referring to the section under My Computer Properties, Advanced, User Profiles where the local profiles are listed and may be copied.
  4. It's 3rd from the top 'Download >>> FPK v5.0 <<<', then click on the attachment link in the first post 'fpkv5.0.zip'. There's an admin guide in PDF format in the ZIP file. I've had a quick look throug (searching for 'redirect') but cannot find anything about Folder Redirection being slow with GP. It is though. If you do not use any folder redirection (or mandatory/roaming profiles), then logon times are very fast.
  5. If using 2003 server, you can also make bulk changes simply by selecting all the users you want to change, opening properties and entering the new value using %username% to represent the user name eg. \\newserver\%username%$ or \\newserver\usershare\%username%
  6. You may want to take a look at the Flex Profile Kit, which is a sort of hybrid mandatory roaming profile. In there somewhere is a comment that using the MS folder redirection feature is very slow and it is therefore better to do it in the mandatory profile or using registry manipulation.
  7. I use mandatory profiles and have no problems with Group Policies applying to them. When making a Mandatory or Default User profile, you MUST MUST MUST use the GUI to copy the profile. When copying the Mandatory or Default User profile, make sure you set the 'allowed to use' to Everyone. If this is not done, then the eventual user of the profile will not have the necessary permissions to write policy settings into the profile. It is not enough to copy the folder from C:\Documents and Settings. The GUI allows you to change the permissions on the profile. The permissions are NOT JUST on the files which the profile is made up of, but also in the registry which is stored in NTUSER.DAT. Changing the file permissions on NTUSER.DAT do NOT affect the regitry permissions therein.
  8. @wesleyw: Why do you redirect start menu? If you leave them alone, then they will automatically show the software installed on the machine. Here's what I do... 1 - Students have mandatory profiles and are restricted from seeing the All Users stuff and only get the basic XP start menu. When a student logs on, a script copies the AllUsers stuff to their Start Menu for that session except it filters out the stuff I don't want them to see (uninstalls, readmes etc) 2 - Staff have roaming profiles and are NOT restricted from seeing the All Users stuff.
  9. I just set up a new Dell PowerEdge 2900 (dual Xeon 1.6GHz 5110, 2Gb RAM, PERC5 RAID array etc). Very nice server with plenty of spare capacity so I stuck Virtual Server 2005 R2 on it and imported an XP SP2 virtual machine. For a while the XP VM worked fine (faster than some PCs in the school), but then for no apparent reason, every time I started it, the server lost network connectivity. Only symptons (appart from loss of connectivity) where some Info messages from Virtual Server with could not be displayed properly (missing DLL type message). Has anyone had this?
  10. Try swapping mice with 'known good' units. This will elliminate the actual mice. If they are PS/2 then try a USB and vice versa to narrow down the possibilities.
  11. Does your school not have a nominated ICT Coordinator? In the schools where I work they act as an interface between the teachers and the IT support service. We generally request details of what software will be required with a list of titles and versions and all media & serial/license details. If this is not forthcoming even after continual reprompting the the installation has to go ahead with whatever software has been made available. Having said all that, most of my work is in Primary schools and the seemingly quite high turnover of ICT coordinators means they are always trying to get a handle on what has been left them by the previous occupant of the post. You must have a line manager though. They should advicse you as to what to do. Make them aware that if you have to add the software piecemeal it will take a lot more of your time than if you have it all up front.
  12. Been there, done it, got T-shirt etc.
  13. @Geoff: Maybe 'cos in the days before NTFS, share permissions were the only option? Also I suppose, share permissions are easier to manage if you don't need the more granular control afforded by file permissions. I know what you mean though. When I moved to NT from NetWare (good security/directory model but it crashed a lot!) I couldn't figure out why share and file permissions were required. It would be good if Microsoft gave us the option of either disable share permissions, or defaulting new shares to a predefined value (maybe Admins: Full and Authenticated Users: Modify would have made more sense) Here's a thought though. Any time a user creates a file, they automatically become the owner of it and can therefore modify the permissions. You may be able to prevent this behavour with the use of a specific Deny entry in the DACL, but presumably if the user is connected through a share which limits their permissions to Modify, they would not be able to change the permissions.
  14. The GPO setting 'Add Administrators to Roaming Profiles' is NOT 2003 specific. It works on XP clients also, no matter what server their profiles are stored on. I've been using it on 2000 servers with XP clients for yonks. You do have to edit your GPOs on an XP PC though to get the latest ADM file. You may find SetACL useful.
  15. Did you by any chance forget to change them from their default values of Everyone: Read?? Thanks a lot Microsoft for that one. 1 - Get RMTSHARE 2 - Work out the command you need to change the share permissions RMTSHARE \\server\sharename /GRANT Everyone:Full 3 - Build a text file which lists all the shares you want to modify (could use 'RMTSHARE \\servername > sharelist.txt') 4 - Manipulate the text file so that you have a series of rows resembling the command line given in step 2 5 - Save the text file as SHAREFIX.CMD 6 - Execute SHAREFIX.CMD by double clicking on it.
  16. Interesting. I thought that the system context was denied access to the network.
  17. @pmassingham: Yep, I've had that with WIWW before now. What OS are you running on? I find it's OK on XP SP2. Yes, a batch file will do it, but you'll have to visit every machine, log in and run the batch file. I've not reviewed the thread, but it may be possible to run it remotely using PSEXEC (from sysinternals.com). I'm working on an AutoIt script (which compiles to .EXE). When I've tested it a bit more, I'll post it.
  18. If you are interested, here's what happened.
  19. I would strongly advise against repackaging SIMS for the following reasons; 1 - It's a .NET app, which makes it more complicated. 2 - SIMS update it every other week which means your package will soon be out of date. 3 - The SIMS automatic update mechanism might be defeated by Windows Installer self repair. If you need to deplpoy by GPO, use wrap the silent install commands in an MSI (using something like Windows Installer Wrapper Wizard - mentioned in the WiKi)
  20. @Ric_: I've never been comfortable doing that because of the warnings about superceded updates. I would have assumed that it was OK to approve all superceding updates whilst removing all superceded updates. There are warnings against doing this in WSUS though.
  21. I think the problem is that the AutoApproval only works when updates are initially synchronised. When the WSUS server finds out about a new update, it applies the AutoApproval rules then and then only. I tried using the Server Debug Tool to do a resetanchor and then did a synchronize. This caused a lot of new updates to be downloaded (which suggests they got approved), but there are still several hundred which are set to detect only.
  22. Strange problem. I've configure WSUS to approve for detection & installation the following categories; Critical, Security, Service Packs, Update Rollups & Updates. All updates are being approved for detect, but not all for install. Anyone had this? How do I fix it? Thanks...
  23. It only does it once. What's the big deal? Seriously though, try using Regshot to snapshot the registry before and after and 'first run' of notebook. This should show you which registry entries have changed. Once you've got that info, create a transform (MST) with ORCA which sets the appropriate entries and apply it to the MSI at install time.
  24. There is a category in the knowledge library on the following path; Educational Software \ SuccessMaker \ SuccessMaker Enterprise \ Installation & Setup Try the documents relating to moving the system to another server.
  25. There's full documentation on the RM support site. I've always found the SuccessMaker support people really helpful.
×
×
  • Create New...