-
Posts
1,643 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ajbritton
-
Could be corrupt file association... Check the 'advanced' settings against a working XP PC with same version of Word.
-
Problems (and varied suggestions) about user profiles (which we CANNOT escape, like it or not) seem to be regular subjects for threads. I'm proposing to write some stuff in the WIKI about the various options. This would include... - Brief explanation of what a user profile is and it's constituent parts - Implications for network management - Roaming profiles - Mandatory profiles - Local profiles - Temporary profiles - Folder redirection - Hybrid profiles - Suggestions for different users/environments My motivation here is so that rather than simply pronouncing certain ways of doing things as 'evil' (naming no names), members can refer to a common explanation and set of suggestions. Before I get RSI writing all that, I'd be interested in comments from those with strong opinions on the matter as well as those who feel confused by the whole subject! If it's OK, I'll post a reminder next week after the hols just to get the thread back in the top 10.
-
You need to modify the Directory table. It's worth looking at the MS Windows Installer Database Reference pages, but briefly; the Directory field contains the internal reference name for the directory the Directory Parent field refers to another entry in the same table the DefaultDir field refers to the actual directory name. So, for example, if your app installs to C:\Program Files\AppName, there will probably be an entry whose 'Directory Parent' field points to ProgramFilesFolder, and whose 'DefaultDir' is 'AppName'. You should just be able to change 'AppName' to whatever you want. I would reccomend that you create a transform (.MST) file with your changes in it although I have had few problems directly editing MSI files.
-
Poor old DOS_BOX, just because he couldn't get roaming profiles to work, he assumes they are no good for anyone! I think you need to do 3 things 1 - Modify the MyDocs redirection policy and untick the box that says 'Grant the user exclusive rights to My Documents' 2 - Create a computer policy which will apply to all computers and under Admin Templates\System\User Profiles, enable the 'Add the Administrators group to roaming user profiles' and 'Do not check for user ownership of Roaming Profile Folders' settings. 3 - Seperate user documents and profiles onto different shares e.g. profiles... \\server\profiles$\%username% files... \\server\users\%username% Roaming profiles are not evil, but you do need to understand what they are and how they work to get the best from them. climbs down off soapbox...
-
Try Angry IP Scanner - it's small and light and doesn't fill you up in between meals! Tried and trusted.
-
You can remove the 'security' tab from explorer via a group policy setting, but you would also need to prevent access to the command line (use of cacls, xcacls or similar). Any file/folder created by any user becomes 'owned' by that user and when a user 'owns' a file/folder, they can always modify the permissions, regardless of the permissions set on the parent folder. The only suggestion I have ever seen to prevent this is to modify the permissions on the share that users connect via such that they are limited to 'modify'. I always redirect 'My Documents' to the home directory and XP refused to do this when it realised that the user did not have full access to the folder.
-
If you are still looking, the following sites might be useful... AppDeploy InstallSite I used to use WinInstall LE 2003 (when it was free), but it was fairly crude compared even to InstallShield repackager, which in turn is crude compared to Wise Package Studio. You can get a free 30 day trial of MaSaI editor which I think still works but with less functionality after the 30 days (not sure).
-
Delayed Write Failed when saving over a network
ajbritton replied to indiegirl's topic in Wireless Networks
Look in the event logs on the workstations and servers at around the time of the error. If the problem is client side, or network related then there may be messages to that effect on the workstation. If there are problems with the hard disk on the server then there may be info in the server event log. Other than that, general troubleshoot advice applies. Change one thing at a time. If possible, swap the entire PC out and see if the problem goes with the PC or stays at the network point. You get the general idea! -
In the 'quick question about redirecting folders' topic, Mark mentioned that he needed to have individual start menus for individual machines. The way I deal with this is to use a combination of organisational units and computer group membership. Generally, I map OUs to physical locations (e.g. ICT Suite, Library, Class 5 etc.) and if there is a logical sub-group of machines within and OU (say 5 machine in the ICT suite with Photoshop), then I put those machines in an AD group and use the group to control both the installation of the software (a filtered policy) and the content of the Start Menu (my logon script can check group membership before building start menus). I was wondering what everyone else uses their OUs for....
-
Best one ever though came from a manufacturer (I won't name). We bought a load of their wireles PC cards and proceeded to install them in Win98SE PCs (fully supported by manufacturers driver). Worked fine until we put WEP on then they would not correctly log on. If you bypassed the logon however (so that the shell loads and executes everything in HKLM\sw\ms\cv\run), WEP worked fine. When we reported this to the manufacturer support, their official response was that 'they did not anticipate that anyone would want to use their WIRELESS NETWORK CARD on a NETWORK)!!! We got it to work though!
-
Yep, I'm also a fan of the 'problem exists between keyboard and chair' or PEBKAC excuse.
-
@Ric_: A typical mandatory profile in one of my sites is no more than a couple of MB and I generally have no more than one per academic year (total size = 15MB tops!). There is a GP setting which can limit the size of roaming profiles. I would point out that, if you are redirecting Application Data to a server, you are still storing most of the profile content anyway. If you are not redirecting Application Data, then you don't have anything like the same functionality as roaming profiles. Also, if space is a concern, (ooh those hard disks are SO expensive - NOT!), there are GP settings which allow you to control which parts of a profile actually roam (ie get copied to the server). Daniel Petri has some useful tools for writing CMD style logon scripts which need to determine Group or OU membership.
-
'pologies in advance for the length of this post! What I don't get about not using any form of Mandatory or Roaming profile, is what happens to the local profile when the user logs off. Does it stay there, do you have some kind of startup script to delete them or is there some GP setting that I have never seen which deletes 'standalone' profiles when the user logs off? If the profile is not deleted, then you have no further control over it's content. If you add more software, you need to delete all the local profiles on all the PCs (not a problem I suppose if you still use Ghost). Any damage done to the profile by a student will also persist on the machine in the profile until such time as it is deleted and recreated. I'll assume then that you are deleting local profiles somehow. If the profile is deleted, then a new one will be created each time the user logs on. If this is the case and there is no domain level profile, then all the required software settings need to be in the local default user profile on every machine. Again, somewhat tedious to manage with lots of machines. I'll now assume that a domain level default user profile is the way to go. OK, so you use a domain level Default User profile. You can modify this as necessary and every new profile that gets created will pick up the new settings. Now if this is happening every time a user logs on, then you are no better off than if you were using a Mandatory profile. In fact you are worse off, because you can only have one domain level Default User profile, whereas you can have as many or as few Mandatory profiles as you need. Please feel free to point out what I'm missing !!! For what it's worth, here's how I deal with the problem of different software setups on different PCs... 1 - Staff get Roaming profiles and can see the content of the All Users profile. This means they can always see everything on the Start Menu and anything placed on the All Users desktop. As the All Users profile contains data specific to the individual PC, Staff see valid start menu/desktop items on every PC they logon to. 2 - Students share one or more Mandatory profiles, but are denied the All Users start menu/desktop. They only see the start menu/desktop which is part of the mandatory profile. The Mandatory profile does NOT contain any extra Start Menu/Desktop shortcuts but read on... 3 - When the student logs on (they always get a fresh new profile based on their assigned mandatory profile), the logon script identifies the location of the PC (using an ADSI call which returns the position of the PC in the AD tree). The script then copies down additional Start Menu and Desktop items from a central location on the server. This gives me complete control over the content of student desktops and start menus. 4 - When the student logs off, the local copy of the profile is deleted (via GP setting). This means that no matter where the student logs on, they are guaranteed to get the profile that I set up without any changes they may have managed to make to it in their last logon session.
-
Final update on the security tab issue... There is a user based Group Policy setting under User Settings, Admin. Templates, Windows Components, Windows Explorer, Remove Security Tab
-
Hmmm...Sounds like a job for ICTNUT. Perhaps the Nasty File Search could be expanded to look for dodgy permissions!
-
Yep, that works. Of course we would also need to restrict things like CACLS, XCACLS or any other app students could get onto a PC!
-
This looks more hopeful... Remove Security Tab
-
@ChrisH: I also use a single share for all users, but I still have the same problem. You might want to try to reproduce the problem as follows... 1 - Log on as a normal user 2 - Create a new folder in your home directory 3 - Go to the security tab and click Advanced 4 - Untick the 'inherit' box, and select Copy 5 - Remove the Administrators (or Domain Admins, whatever you have) 6 - OK Try accessing the folder from the server as Administrator. You can still take ownership if you need to, but forget about the folder being backed up! I have just found this Microsoft article which claims to remove the Security tab. I assume this would apply to all users of the machine however.
-
@ChrisH: I have found that even if you give users Modify on their home directory, they can still change the permissions on anything that they create. I think this is because the user is the owner of anything that they can create and have some kind of implicit admin status. I'd love to know of a way around this. I have heard people suggest limiting the permissions on the share that the users connect through, but I could not get that to work.
-
As Administrator, you should be able to 'take ownership' of the profile folders and thus gain access. Unfortunately (as I think you may have found out), XP no longer recognises the profile folder as belonging to the user who created it. This is because, by default, there is a policy setting which tells XP to test the ownership of a profile folder before using it. You need to enable the 'Do not check for user ownership of roaming profile folders' policy setting (Computer Settings, Admin. Templates, System, Logon, Do not check...). At the same time, if you enable the 'Add the Administrators security group to Roaming user profiles' setting, then any new profiles will already have the Administrators group in the ACL, thus allowing you access. The policy you modify should be at a level in the AD structure such that it affects all you workstations.
-
Not quite sure what you are asking here. Do you mean 'where was the MSI installed from'? or 'Which GPO had the instruction to install the MSI'? Not sure how you would track back to find the installation source path as the MSI is copied to the PC when it is installed (and renamed to boot!) You could looking for the Windows Installer registry entries. If you are trying to track down a software assignment, try Group Policy Management Console RSOP or GPRESULT on the PC in question.
-
Well, I'm booked to go on the official Wise Packaging course in November. I'll let you know how it goes!
-
NetOp's not my choice for doing remote support/management, it's used by curriculum staff (teachers or whatever) to either transmit a single screen to all other PCs in the room, or to lock all the PCs in the room etc. I use UltraVNC as a means of PC remote control.
-
Yes, the Student deployment feature works well, but as I said, I really need my PC builds to be complete and not require extra bits of software to have to be squirted on to them after a rebuild. My most recent install of NetOp (4.0) had a problem because of a missing line in C:\WINDOWS\NETOP.INI. This caused the Teacher module to load with an error message about TCP/IP sockets. It was clashing with the Student module. I got it working, but had to write a VB script to manually modify the INI file and assign it as a startup script - yuk :oops:
-
Surely, as long as your BIOS supports modifying the boot order (to put the network card first), then a cheapo PXE NIC would do the trick? I tried long and hard to get Etherboot working. It felt like I got really close, but never quite got there. I have since read somewhere that it is not compatible with RIS. If anyone knows how to get Etherboot working with RIS, I would love to know exactly what has to be done!
