-
Posts
1,643 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ajbritton
-
So, the files which cannot be deleted are not part of the user profile then. User profiles can certainly be deleted fully.
-
@Marcus - If what you are saying is true then all the products that claim to erase your internet tracks are worthless?
-
Question - What if a user delete's his/her own temp internet files and history?
-
Try this MS KB article
-
I'm after a cheap laptop (refurb with warranty would be OK) for use as a 2nd home machine. I already have an OK PC (P4 2.8GHz, 1Gb RAM DVD+-RW etc), and a WLAN. My only requirements are as follows - Bargain basement price (< £400) - WLAN (ideally integrated, but a USB/PC-CARD dongle would be OK) - DVD-ROM (so I can watch movies) - 14.1" or better screen I've looked at Morgan and ComputerBargains. Anywhere else I could try?
-
IIRC, you cannot use RIS from a multi-homed server (ie, one with more than one network card). If possible, try disabling one of the interfaces, reboot then try a client again. This may or may not prove it. Try googling for 'RIS' and 'Multi-homed'
-
Go through the concept with us here and now if it really exists. I'm beginning to seriously doubt it though. So far you have given us nothing about how the product works. Either it is very clever, in which case revealing a little about how it works will not really do any harm as it will still be marketable, or it is extremely simple, in which case you would obviously not want to talk about it on a forum of experts who, between them, have probably more knowledge of computer networks than yourself and are not likely to be impressed. It's not my intention to offend, but 'put up or shut up'.
-
EduGeek regulars will know that I'm a pedantic SOB, so here goes. Mitch, the service must by definition be a log analyser of some form. If detection is 'post-occurence' as you have stated, then the information must be retrievable after the event. The information must therefore be logged somewhere (wether it be in proxy logs, event logs or a database of some kind). Your service must be accessing this data and performing analysis/reporting upon it. QED - Log file analysis. If your service can retrieve information which has not been stored then maybe you can also solve the Black Hole Information Loss problem
-
Mitch has described the system as 'post occurrence', which means that it must be a log file analyser and report generator. If this is not the case then perhaps Mitch will tell us how it works? If he's not willing to give more details about how it works then it woud be difficult to assess it's suitability for use on any particular network, I guess it's the overall service that makes the product unique.
-
I should also have pointed out that you don't actually need SetACL to do this now as it can be done from the root directory which contains all your student folders ie. intake2005. 1 - To do this via the Windows, browse to one of the root folders eg intake2005 and bring up the file/folder security dialog. 2 - Add the Teachers group into the list and give the group the required access eg. Modify 3 - Click the Advanced button, select the Teachers group and click Edit 4 - Change the 'Apply Onto' setting to 'Files only' 5 - OK, OK, OK Should have the same effect as the SetACL line.
-
It sounds like good advice to prevent non-technical staff from mucking about in student folders, but if you still really want to do it, here's the command. Note that this can be set on the root folder that contains the student folders, rather than having to run it against every students folder individually. NB - Please test this before running it against the actual student folders. When I tried it, existing permissions were unaffected, but I'm still only 85% sure that I know what's really going on with permission inheritence etc. SetACL -on "D:\Users\Intake2005" -ot file -actn ace -ace "n:Teachers;p:change;i:so,io" The key thing in the command is in the -ace string. There are 3 sub-parameters specified; n:Teachers - This parameter specifies the (n)ame of the trustee to whom permissions are being granted/denied p:change - This parameter specified the actual (p)ermissions being set i:so,io - This parameter specified the inheritence. In this instance 'so' sub-objects (ie files) and 'io' inherit only.
-
Why not just use Group Policy User Configuration to set the proxy?
-
It's possible. I'll figure out the SetACL command and get back to you.
-
Sorry Tosca, I thought you meant change to all files/folders under the user root folder, but not on the root folder itself (which would prevent the dropping one user folder into the another). Let me see if I understand now. You want Teachers to have change on the documents (regardless of which folder they are in) but not be able to do anything to the existing folder structure. Am I getting close..?
-
SetACL Give your scripts ultimate control over ACL editing. Forget CACLS. Forget XCACLS. Forget ADSSecurity.dll. This is the dog b******ks. IMHO (just noticed, also recomended by here by E1uSiV3)
-
I assume you want the teachers to have full access to the contents of each user directory, but not to the directory itself. Setting the permission on the user directory, but changing 'apply to' to 'subfolders and files only' means the teacher can still do whatever they want to files/folders within the user folder but will not necessarily have any power over the folder itself. As to wether it can be done from a script...Yes, anythings possible. If you are a certified genius, you can attempt to use the ADSSecurity.dll in the ADSI SDK. An easier way might be to use SETACL (an open source access control list command line tool). I've done a single quick test, and the following appears to produce the desired results setacl -on "D:\USERS\INTAKE2005\USER01" -ot file -actn ace -ace "n:Teachers;p:change;s:n;i:so,sc,io;m:set;w:dacl
-
The trick is to change the 'Apply To' setting, which is only available in the Advanced dialog box. Using this, you can change how permissions are applied. The default is that the permissions affect 'This folder, subfolders and files' - This is the default setting, and will affect the folder itself as well as all files/folders within it that are inheriting permissions. If you change the setting to 'Subfolders and files', then the user only gets permissions on files/folders within the folder on which the permission is set. This should prevent them from moving it.
-
Just to share with you all my joy at the birth of my second child, a baby girl weighing in at just over 8lbs late on Thursday night. It's the 2nd EduGeek baby in a week!
-
Sorry Gecko, looks like I couldn't count. It sounds like you've sussed it all out though.
-
Gecko.. Please don't take this the wrong way, but from looking at your script (and the fact that you've asked me to help you with it) I'm guessing that you're still learning VB Script. I think the best way of learning is by doing, so rather than rewrite your script, I'll try to help you along the way as follows... The InStr function is just like the InStrRev function, except that it starts looking for the for the substring from the beginning of the source string, rather than from the end, so... TwoPos = InStr("12345678987654321", "2") ...returns the value 2 Whereas... TwoPos = InStrRev("12345678987654321", "2") ...returns the value 14 Here's the function to determine if a computer is in an OU. You can just add the function to the end of your existing script. Function IsComputerInOu(sOU) dim oAdSysInfo, sComputerDN set oAdSysInfo = CreateObject("AdSystemInfo") sComputerDN = oAdSysInfo.ComputerName IsComputerInOu = (InStr(1, sComputerDN, "OU=" & sOU, vbTextCompare) > 0) End Function Usage: IsComputerInOU() Returns: True if computer account is in or below an OU with the name 'OU Name' Example: If IsComputerInOu("IT1") Then oWshNet.AddPrinterConnection("\\cse2k01\KyoceraM") end if The function works because of what is returned by the AdSystemInfo.ComputerName method. This returns not just the Computer Name, but the Distinguished Name (DN) (see RFC 1779) of the computer account object. If you imagine that your computer is call IT1-01, that it is in an OU called IT1, which in turn is in an OU called Computers, which is in the domain School.Local, then the Distinguished Name (DN) of the computer account object would be cn=IT1-01,ou=IT1,ou=Computers,dc=School,dc=Local It's then a simple matter to use InStr to see if, for instance the string 'ou=IT1' exists in the full DN string. If it does, then computer account is in (or below) the IT1 OU.
-
I think this is an excellent idea. Get them all to do at least the following; - Provide an MSI based installation which has been tested in a network environment (failing MSI, a working FULLY silent installer) - Default to saving documents in the 'My Documents' folder (which has been standard Windows procedure since Win95 for f**ks sake) - Where software is 'licensed', it should be possible to enter the license details during an 'administrative' install of the product (just like Office) - All software should work for normal users - Do not install desktop shortcuts or 'uninstall' shortcuts (although these are quite easy to fix on MSI based installations) Let's get a list together and starting hassling those developers!
-
As I think I mentioned earlier, my logon script is a bit stupidly big, but the essence of what you need to do is here. I've added some comments ' Declare object variables dim oAdSysInfo, sCompPath ' Create the AdSystemInfo object set oAdSysInfo = CreateObject("AdSystemInfo") ' Create the Wscript.Network object set oWshNet = CreateObject("Wscript.Network") ' Obtain the full path to the computer account sCompPath = oAdSysInfo.ComputerName ' Check to see if the computer is in (or below) a particular OU if InStr(1, sCompPath, "OU=ICT Suite", 1) then ' Add a printer connection based on computer OU membership oWshNet.AddWindowsPrinterConnection "\\ServerName\PrinterShareName" end if Hope this helps
-
I assign printers based on computer OU membership. Basically, it's all done using the ADSI extensions. You can get the full computer path from ADSystemInfo.ComputerName and then check for the presence of particular OUs. dim oAdSysInfo, sCompPath set oAdSysInfo = CreateObject("AdSystemInfo") sCompPath = oAdSysInfo.ComputerName if InStr(1, sCompPath, "OU=ICT Suite", 1) then ' Code here to map printer(s) for ICT Suite end if
-
Are you using Exchange?
-
Personally I'm looking forward to rewriting all my scripts in the new MS shell (MONAD) which is slated to replace WSH. There's a beta out now.
