-
Posts
1,643 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ajbritton
-
I'm considering using these as backup devices in primary schools. What I want to know is how secure they are. Do they integrate with Windows security enough so that data is not accessible across the network without a domain level username and password? Also, if anyone is using them as backup devices, what software do you use to manage the backup sets?
-
I looked into ADAM a little more, and I pretty sure it's not up to acting as a temporary domain controller. Good for testing ADSI scripts on though. I also had a quick look on the Samba FAQs and get the impression that version 4 might be up to the job but it is not yet a stable release.
-
In the near future, my team will need to upgrade several sites which have single server networks from Windows 2000 to Windows 2003. In some of these situations it will be easiest to just backup the data, reinstall the server, restore the data, reinstall AD and recreate user/computer accounts. In other situations however, it will be desirable to retain the existing AD database. I'm trying to work out our options and so far I have the following... 1 - Do in-place upgrade of the server to 2003 (which I never like), backup the AD and data then wipe and reinstall the server, reinstall AD, restore AD and data. I'm not sure if this would work... restoring the system state of an upgraded server over a freshly installed server. 2 - ADPrep the existing forest & domain, make a temporary server on another PC (or Virtual Server), make it a DC, replicate, transfer FSMOs, make it GC. Un DC-Promo old server, remove from domain, delete old server account from domain. Reinstall the old server and reverse the process. Or is there another way? Using LDIFDE to dump the AD to a file. How about using ADAM on a PC as a temporary DC? What about Samba. It would be slightly easier to carry a virtual pre-built Linux server with Samba than a virtual pre-built 2K3 server. Any ideas? Oh, and feel free to point out any errors in my logic before I make any more serious f**k ups!
-
Important the user data and profiles are not on the same share. Windows complains if you do not disable caching on the roaming profile share, but this is required on user data shares to support offline folders.
-
Yep, agree with that. Check the path in the user account. Check the share permissions allow everyone (or equivalent) full control. Check the folder where the profile will be created has permssions like this - Administrators: Full Control (All subfolders and files) - System: Full Control (All subfolders and files) - (everyone/authenticated users/domain users): Create folder (this folder only) - CREATOR OWNER: Full Control (Subfolders and files only).
-
@GrumbleDook - Why not redirect the Desktop folder? @DMcCoy - You could of course exclude the Cookies folder from the roaming profile.
-
Gordie, It sounds to me like you need to sort out some system of managing your user profiles. There are several methods available (have a look at the WiKi entries relating to user profiles to get an idea of the possible options. I personally use Roaming Profiles for staff and Mandatory Profiles for students.
-
@RoyG: When a student logs on and has local admin rights, does this also give them implied admin rights on all the other PCs? This would certainly be the case on a Windows network if the students were using domain based user accounts. Would this not mean that a student could remotely cause havoc on any other PC, presumably including those used by teachers.
-
What about working from local disks then backup up to NAS overnight?
-
Yet another Logon Script This looks interesting. I downloaded it and looked at it but I have not tried it. It's an AD driven logon script which can be configured to do lots of things without modifying the script. Configuration details are recorded in some of the lesser used AD object fields (notes, description). It's also skinnable so you can either have a completely silent logon or a display with progress bar and information as to what's going on. Add to that a 'simulator' for debugging and it looks impressive.
-
I believe PSSHUTDOWN (part of PSTOOLS from SysInternals) is a bit more successful at remote shutdowns when screensavers are active. The other way around this is to remotely kill the screen saver process first. You can use PSLIST to view the list of tasks running on a remote PC. If you want to manipulate power settings via GPO, then you need Energy Star EZ GPO. Works like a charm (although a charm with an MMC interface :? )
-
There are those that seek the third way and use RIPREP to get the worst of both worlds!! I'm only saying it like that because I could never make it work! Seriously though, using RIPREP, you can make a workstation build including software and then deploy the whole caboodle using RIS. My main issue with this method is that if you find the build to be corrupt in some way and you can't fix it, there is no way back other than to recreate the complete build from scratch. I favour a basic RIS build (with drivers only) and then deploy software with MSI. Most MSI based apps can be deployed via AD with little or no tweaking. Many more apps which can be silently installed (e.g. setup.exe /s) can be deployed as pseudo-MSI files using Windows Installer Wrapper Wizard. This leaves a fairly small proportion that need to be 'repackaged'. Good repackaging tools are not cheap. In my opinion, Wise Package Studio is one of the best. A possible alternative if you are handy with a script is to automate a non-silent installation using AutoIT. The resultant package can then be deployed as a pseudo-MSI again. Until all software vendors supply software in MSI format (or Altiris give away Wise Package Studio), I don't think there will be a perfect solution. Recently though, another possibility has come to light in the form of Altiris SVS (Software Virtualisation Services). It's quite clever. Essentially, each piece of software you want to deploy is 'repackaged' into a virtual layer which can be switched on and off at will. When the layer is switched on, the software appears to be installed. When the layer is switched off, the software is gone. It ought to be possible to repackage all applications as virtual layers, deploy them to PCs using simple batch scripts and them activate them with a startup script. The basic SVS tools are free so you can experiment to your heart's content. Having invested quite a lot of time and money in repackaging though, I'm staying with it for now.
-
Assuming all the changes are at the User Profile level (ie changing the settings only affects the logged on user), then you could use a Mandatory Profile (see WiKi). If the user needs to be able to configure the settings themselves, then a Roaming Profile (again, see WiKi) or possibly a Flex Profile would do the job.
-
The best command line tool for managing permissions I have ever used SetACL. It can do just about everything related to permissions on files, folders, shares, registry, printers and services.
-
I would also point out that if you need to give your students a 'sandbox' to play in, you could install Virtual Server (free) on XP Pro machines and give them an XP guest PC (not sure of licensing implications) whith as little or as much network access as you want. The guest could use an Undo disk which is automatically discarded on reboot.
-
If you use cards that protect your PCs, what protects any laptops on the network?
-
There appears to be a Windows update which locks down the registry and prevents Flash updates from installing in certain circumstances. If you do an XP install from the RTM CD, Flash 6 is installed automatically. Now do a full Windows Update and you will find some extra files in C:\Windows\System32\Macromed\Flash. In addition, some of the registry entries under HKEY_CLASSES_ROOT\CLSID\{D27......} have extra permission ACEs on them which DENY access to all users. This effectively stops updates from working. If you build your PCs using RIS and shove out Flash 8 by MSI, then this should be OK as Flash 8 gets installed before any Windows Updates are applied. The update does not install if Flash 8 is installed (presumably it's more secure). There are various threads on the Adobe and other sites which make no mention of the Microsoft patch. Do they really not know?!?? Anyone else had this or did I dream the whole thing?
-
I've rolled out 9.5 on a couple of sites now (using the MSI). The modification posted on the WiKi to disable AutoUpdate appears to work unchanged. The only problem I've had is getting the gallery content (seperate download) to deploy using the supplied MSI.
-
The GUIDS assigned to the PC are supposed to be unique. Some PC suppliers 'forget' to assign GUIDs to the PC and PCs report similar GUIDS. When this happens, PCs will try to take over the computer accounts of PCs with the same GUID. There are utilities which will change the GUID to make it unique, but these are not that easy to get hold of. I've always had to go back to the supplier. I'm not sure how the duplicate GUID detection logic works, but I've had instances of PCs hijacking each others computer account with no warnings about duplicate GUIDs. I configure my RIS server to assign computer names based on NP plus MAC (e.g. NP000080861892). When I build a PC for the first time, I try to remember the last 4 digits of the MAC which is displayed during the PXE boot phase, and compare it to the computer name which is assigned during the setup wizard just prior to the setup commencing. If the MACs don't match then something is wrong!
-
If your disks are formatted with NTFS, then you should have a pretty good level of control over what can be written to. Do you have a problem with a particular application/folder?
-
If you are using Active Directory (Win2K or 2K3), then you can use Group Policy Admin Templates (from the Office Resource Kit), to customize a lot of the Office functions. You can then apply these to whichever users you like.
-
Hmmm. Not that I'm at all in the business of bashing 3rd party security products, but... Wouldn't the shared computer toolkit do a similar job?
-
Used to use KiX, but moved away from it as was having trouble remembering the syntax for KiX, VB, VBS, VBA. Nowadays I have the same problem trying to remember syntax for VBS, CMD , AutoIT and soon PowerShell no doubt. What's good about each one? KiX - Some nice built in functions to ease logon scripts (group membership checking being the most obvious I suppose) VBS - No interpreter required. Will run on any Windows box these days. Can do most things with WMI, ADSI, ActiveX etc. CMD - Again, nothing extra required. Can do some very clever things but syntax seems less self explanatory. Can launch a 16bit app and wait for completion before continuing. Not easy from VBS/AutoIT (dunno about Kix). AutoIT - Great functions for automating tasks, watching for dialogs, clicking buttons etc. Plus it compiles to executable. Now supports creation of GUIs. Comes with comprehensive help and a reasonable IDE (SCiTE) PowerShell - Only had a brief look, but it can be very powerful. There's an an example single line command which iterates through all your Exchange servers looking for disconnected mailboxes and reconnects them to matching user accounts.
-
Intel seem to have sorted out their issue with duff .INF files as well.
-
ditto. I RISed a room full of GX60s the other day using the latest Intel driver.
