Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ajbritton

Members
  • Posts

    1,643
  • Joined

  • Last visited

Everything posted by ajbritton

  1. I guess having Citrix leaves you with plenty of time on your hands
  2. Surf on over to Streamload and get your 25Gb online storage for nowt!
  3. The only good reasons I can currently think of are where students are working on projects which are too large to move around by email e.g. digital video
  4. I just found this article on the excellent Daniel Petri website. I've not tried it, but it looks a lot simpler than some solutions I've seen.
  5. Don't care, I just want the badge!
  6. I've had this to. I get errors in the log mentioning Internet Explorer and RSoP logging. I gave up and wrote a script. To be quite candid and perfectly frank, I 'm increasingly of the opinion the Group Policy is a load of s**t. (not that I've had a bad day or anything..) :twisted:
  7. Ever since XP SP2 came out, it's been a pain to run HTML with embedded Flash or whatever from the C: drive. I've been looking for a Group Policy workaround for this and today I found it (courtesy of IBM!!). I've tested this on my Virtual PC setup and it appears to work. Configuration of the Policy: Open the Group Policy console by clicking the Windows Start button, then clicking Run. In the Open field, type the following: gpedit.msc - Computer Configuration - Administrative Templates - Windows Components - Internet Explorer - Security Features - Local Machine Zone Lockdown Security Change the "Internet Explorer Processes" and "All Processes" settings from "Not configured" to "Disabled".
      • 2
      • Thanks
  8. ajbritton

    Group Policy

    Did someone say roaming profiles... If anyone's interested, the Flex Profile Framework has been updated again. It looks really good. I'm just waiting for the right opportunity to try it out.
  9. Use Policy Reporter (see the WiKi) to enable full UserEnv debug logging and analyse the UserEnv log. This can help if it's a client issue.
  10. The nice thing about 11a is that it gives you more non-overlapping channels so it is possible to have a denser mesh of APs that will not interfere with each other. 11b/g only gives you 3 non overlapping channels so if you are going for blanket coverage it can be difficult to come up with a design with no dead spots and no interference. I tend to agree with Ric that the way to go is to have an access controller which manages the APs and also provides authentication services/policy management.
  11. Hmmm...How would that cause the errors on the DC?
  12. There's always Password Control
  13. Oh poo. Would I be better off converting to AMD then?
  14. Does anyone know if it's possible to upgrade older systems to the Intel Core CPU? I have a P4 2.8Ghz Prescot (I think) with HT. I should be able to upgrade this right :?
  15. Quite right.
  16. Yep, tried that. It did work on one site but then made no difference at another. The only way I could make it work was to use the driver supplied with XP SP2. I tried every other driver (the one supplied by the OEM and the latest from SIS), but they all had the same problem. Went back the the MS one and it worked OK. The really nasty thing about it was that thought the PC thought it was no longer on the domain. All the existing policies removed and software uninstalled.
  17. @ZeroHour: BTW, have you looked at V4 of D-Tools yet? Sadly no MSI I understand. I put it on a test PC and couldn't really see any difference.
  18. @ZeroHour: I just re-read your original post. I read the first couple of lines and thought you were looking for a solution, not offering one. Yes please, your app and MSI sounds a lot better than my cruddy VB script. Please post it. I for one would be most appreciative!
  19. Use Policy Reporter. This wonderful tool will help you to enable full USERENV debug level logging and then analyse the log for you to help make sense of it. If you pick through it (following a reboot of the PC), you should be able to see exactly what is going on. I too have had problems with SIS900 LAN in combination with SOPHOS AntiVirus. This gave me various errors in the system log during boot up.
  20. Just to throw in my two cents... For software roll-out I would still suggest Group Policy. (be sure to deploy applications to Computers and not to Users BTW) I have deployed hundreds of different packages using this technique, most of which I have repackaged using InstallShield Admin Studio or Wise Package Studio. Repackaging is not a technique which is learnt overnight, however, and there are ways of deploying non MSI based apps using Group Policy. If you need to deploy a non-MSI based app, then provided you can make it do a silent install (most if not every InstallShield based application can be made to do this), then you can 'wrap' it in an MSI using the Windows Installer Wrapper Wizard (see WiKi - Essential software list). The other option is to use WPKG (again, see WiKi - Essential software), which is an alternative to using GP to install software on your PCs. As far as remote management is concerned, it depends on what you need to do. Here are some options; 1 - As an admin, you can use MSTSC to remotely log on to XP based PCs to perform diagnostics etc. This does NOT let you 'take over' the PC to see what a user was doing on it however 2 - UltraVNC will let you 'take over' a PC to provide assistance or to perform diagnostics 3 - Use the 'Computer Management' console (right click 'My Computer', select Manage, when the console appears, right click 'Computer Management (local)' and select 'Connect to another computer'. Enter the name of the PC you want to 'manage' (or browse via AD) and OK. You can also use this feature from within AD Users & Computers by right clicking a computer account and selecting Manage. 4 - If you want to browse the files system on a remote computer, as an admin you can browse to \\(computername)\c$ 5 - If you need to access the registry on a remote computer, using REGEDIT, you can 'connect network registry'. 6 - If you want to execute code on remote computers you can use the excellent PSTOOLS from System Internals. These tools also let you view the active processes on the PC (this can be very handy in a group policy software install gets 'stuck' during installation) There really is very little that you can't do in terms of software installation or remote management with the standard windows tools or a couple of bits of freeware. I think the strength of the network management systems is in their user/desktop management, monitoring, security and reporting functions. Whatever you decide to do, it's obviously your choice, but as was mentioned elsewhere in the thread there are many very experienced EduGeeks who will be happy to help if you decide to steer the righteous course of Win2K3, XP and a few select third party add-ons!
  21. There's also Superior SU, which looks very impressive. It does not appear to work on my ageing Win2K Dell however.
  22. It's possible (but a bit crude) to manipulate the registry entries under HKLM\System\MountedDevices. If you rename the appropriate \DosDevices\(driveletter): to the letter you require e.g. \DosDevices\E: to \DosDevices\H: and then reboot, it seems to work. The trick is making sure you rename the right one!
  23. all right, all right !! Not the most popular idea ever expressed!! What some form of hardware access token?
  24. What about giving them usernames which cannot easily be guessed?
  25. I suppose my other option is some kind of boot camp and do the whole thing in a couple of weeks. Has anyone tried this?
×
×
  • Create New...