-
Posts
1,643 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ajbritton
-
@ICTNUT: If you don't configure roaming profiles, what happens to any information stored in the user registry when users log off? Do you use the same strategy form staff and students?
-
I made an MSI using InstallShield Repackager. No particular problems, except that the SuccessMaker client registers the .WSF file type to one of RM's own applications (can't remember which one). This stopped my logon script from running!
-
You can have as many mandatory profiles as you like. I usually try to get away with as few as possible (minimize management), but some schools like to have different configs. Mandatory profiles are assigned to users though, not groups, although there is no reason why you should not have a number of mandatory profiles which align with a set of groups. Biggest hassle with mandatory profiles is modifying them. I maintain a single user account (mpman - Mandatory Profile MANager), which has full file access to all the mandatory profiles.When I want to edit one, here's what I have to do... 1 - Make a copy of the existing mandatory profile 2 - In the copy, rename NTUSER.MAN to NTUSER.DAT 3 - Set the profile path in my MPMAN (mandatory profile manager) account to point to the temporary copy 4 - Log on to a PC as MPMAN and make profile changes 5 - Log off PC 6 - Rename NTUSER.MAN to NTUSER.DAT 7 - Make another backup of the original profile (just in case) 8 - Replace the original profile with the modified copy Acutally, I got bored doing this and wrote a script to automate most of it!
-
Could Ranger be preventing the additional .DLL files which certain codecs require from loading?
-
I'm sure some of you clever people out there have set up remote access to your school systems in one way or another. I'm a bit daunted by the whole prospect. Any advice on how best to do this would be helpful. Here's what I need to achieve... 1 - Remote file access (upload / download) files 2 - Network access (I suppose a VPN) to allow SIMS.NET access from remote site 3 - Web access for sites with Exchange to enable remote access to email 4 - (Possibly) Terminal Services access mostly for SIMS FMS until it's integrated with SIMS.NET
-
There's Microsoft Operations Manager (MOM), but it's probably expensive!
-
@dos_box If you do a site search for Parago, you will find all the forum entries which relate to it. The site http://www.parago.com has been added to the Essential Software List and Essential Web Sites wikis.
-
tosca, If you want the kids to have a mandatory profile (ie ntuser.man), you need to create a profile, put it on the network in a shared location and point all the kids' user accounts at that profile.
-
If you want to do registry stuff via policy, I highly recommend the (free) Policy Maker Registry Extension (see essential software list).
-
I see that the Parago website has been added on both the 'essential' software and website lists. I also notice what looks suspiciously like an advert for Parago posted in one of the forums. :? Now Parago may be a wonderful bit of software, and if so I guess it deserves it's place on the essential software list (maybe we should split that list up between free software and payed for), but I question it's validity on the essential website list. I don't know what other users' views are on suppliers posting adverts on the site (maybe there should be a specific forum for suppliers to post such info), but I would have thought that it should be the 'educational IT professionals' who decide what goes on the essential lists. Please shoot me down in flames if you think I'm wrong about this
-
Do you have a network wide Default User profile with NTUSER.MAN in it? If so, then new users would get a profile based on it.
-
My two cents... Single physical network (natch) Single/multiple subnets (as required) but not designated to either admin or curric VLAN (as required) to control traffic flow, but not particularly for security Single AD forest, admin domain is forest root, curric domain as additional domain in the same forest. Having both domains in the same forest means you can get away with a single Exchange server. Also, the trust relationship is implicit so cross domain permissions can easily be set up. Having seperate domains means you can think clearly about what links are required between admin and curriculum, then set them up specifically, rather than worrying about what security you need to put in place to prevent inappropriate access to admin work. Workstations are generally in the admin domain for office staff/smt and the rest are on the curric domain. Users can log into either domain from any workstation because of the implicit trust relationship however. SIMS.NET and FMS will both happily run from curric workstations, and the SQL server takes care of security Single AV & WSUS server can service the entire site
-
Try the GPO solution for power management... EZGPO
-
Another PlusNet happy user for several years. No significant problems. I'm on the Broadband Plus at 2Mb service with no cap. You might like to check out what others say about them at ADSLGUIDE.ORG.UK
-
What's the best way to configure teacher laptops so that when they take them home, they can still log on, do work, use their own Internet connection and generally mess about , but when they bring them back to school, the Internet connection still works and does not trash their home settings? When XPs logon cacheing, teachers can go home and still use their network logon. Offline folders mean that their 'My Documents' folder will also be available to work on. The real hassle is Internet. If I set up local logons, then we get into the issue of transferring files and file permissions (yucky). Also, if laptop needs rebuilding, it's more complex to automate the rebuild. Any suggestions or experiences welcome
-
@tarquel: Yes, that's right. All software is deployed with AD. I create OUs and policies which install the appropriate software on the appropriate PCs. If I need to get a certain piece of software on just a handful of machines (say 3 of the 16 machines in the ICT suite) then I create a new GPO and filter it using machine group membership - it's a little bit icky but it does the trick. There's actually quite a lot of software that comes in MSI format and is ideal for deployment with AD. MS Office, Acrobat Reader, Sun JRE, DaemonTools to name but a few.
-
The reason I have avoided RIPREP is because I want my builds to be 100% clean every time and not accumulate the cruft associated with an image which evolves over time (new programs added, old ones removed, updates etc.). Downside to this method is every application has to be in MSI format which can mean repackaging and lots of messing about. I provide support to lots of schools though, so I usually get to reuse repackaged applications.
-
Let me correct myself! When I say that 'my PCs go through the same setup sequence', I mean that the 'automatically' go through the setup sequence, adding themselves to the domain and so on. I was just trying to point out the timings of the various bits of the RIS installation. My PCs still take 15 to 20 minutes to build themselves, showing the same XP setup screens, but not asking me any questions. When the setup completes, the PCs reboot, pick up group policy settings, install assigned software, then do an auto-logon and use the RunOnceEx method to install any software included in the build (e.g. PowerDVD, Roxio or Nero). NB - I am NOT using RIPREP to create my builds. Could this be why they are slower???? :?
-
@Ric: 5 minutes still seems like an incredibly fast time. My builds take about 5 minutes to copy files down to the PC which then reboots and goes through the normal XP setup sequence. The XP setup takes a good 15 to 20 minutes. This is for a basic install from an XP SP2 slipstreamed build! Where d'you think I could be going wrong?
-
Another question for all you RISsters (not easy to say that!); Have you tried creating a build using Bashrat the sneaky's driver packs?
-
Added the following site Unattended Windows WIKI - uAwiki The pages on application installation switches looks good
-
Nice... I used to run this ZX6-R, but the crushing financial responsibility of family life snatched it cruely from my oily mits Never ever ever let your bike go! http://img318.imageshack.us/img318/289/bike11kp.jpg
-
That's amazing
-
Except for those odd servers that all have the same GUID Yeah ... we just came acoss this with a bunch of RM workstations. How do others get around duplicate GUIDs? It's usually possible to obtain a utility from the manufacturer (done this with Viglen & Tulip, can't speak for RM). Basically there is a DMI setting which holds the UUID. There is obviously a standard for reading the UUID so I assume that there is also a standard way of setting it, but I know of no generic utility.
-
Not really. The Windows firewall is one way only; incoming. Which is negated by said infected floppy\CD. A fair point, but the firewalled PCs would have extra protection against rogue laptops which may be connected to the network from time to time. It only takes one careless member of staff...
