jertsy
Members-
Posts
315 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by jertsy
-
I have just set 'basic user' in userconfig>policies>Windows settings>security settings>Software restriction policies>security levels. It was on 'unrestricted'. I'm currently testing to make sure this does not have any adverse affect on pushing software out.
-
Hi I have a new 2012R2 domain and a 2012R2 test domain, by default on both domains users appear to be able to run .msi. I have tried installing a .exe and that get's an administrator prompt but not .msi. I have configured Computer configuration >policies>administrative template>Windows components>Windows installer>Turn off windows installer (enabled, for non managed applications only) but to no avail. I have run group policy modelling and the policy is applying and winning. Any ideas please? Thanks, Jertsy
-
Hi there, I am in exactly the same boat as you, ex RM now configuring 2012R2 domain with windows 7 clients. I am doing pretty much what you are in that I'm creating test users and locking things down and deploying other things via GPO's. It would be good to compare them to someone else's. Let me know if you want to compare notes etc...
-
I have been at two schools that became academy's separately, and the only difference was that in effect we broke employment and tuped across to the new academy, otherwise no difference in employment terms or anything else. If it was not for this change we would no have noticed. I guess it depends on the particular establishment and what the long term plans are.
-
Thanks for the info, that seems quite logical to me.
-
Cool, one last question, is that linked to your staff top level OU and students GPO to your students top level OU? I'm just trying to get an idea as to where people link them as I have read different ideas on this. I want to enforce the interactive logon: do not display last username setting, I was thinking of doing this on the default domain policy as I would like it to be a domain wide thing. I just want to keep it simple really.
-
Thanks, do you have a "staff internet settings" GPO too? I was thinking of doing this so that I could say let staff have a bit more freedom compared to the student's. i.e. less locked down internet settings for staff.
-
Hi all I was wondering how you approach GPO's, do you group similar settings into one GPO, for example, internet settings? Or do you have several GPO's applying various settings? Do you have separate GPO's for staff and pupils applying the same settings so that you can be more granular, for example, internet settings? I would guess that if you have a policy applying to both staff and pupils link it higher up in AD and more granular link lower down. My AD is setup quite granular as opposed to say all users\computers in one OU. I know there is a speed trade off to having too many GPO's applying so I was plumbing for the grouping similar settings together in separate GPO's but I would welcome any advice from anyone. Cheers
-
Our IT support said don't bother with domain local just use global but I just wanted to see what other folks thought as when I did my exams in 2000\2003 domain local was all the rage. Cheers for the info on OU's too as this is something I am tackling in conjunction with the groups.
-
Hi all OK as of today I have a spanking brand new flat 2012R2 domain, my question is what do you guys do with groups, I know MS used to say in the days of 2000\2003 server, users into global\universal and then into domain local but I just wondered if anyone sticks them straight into global. We have one domain and I cant ever see us having another domain requiring access to our resources. Also what groups do you have setup for access to resources? I'm guessing a student group and a staff group but any other groups? As I say, I have a flat network that I am going to start work on tomorrow in preparation for data migration in the summer. Cheers.
-
I quite like this format as it uses the student name and shows year group.
-
Thanks for the suggestions, I have some food for thought and will discuss with SLT. Cheers, Jertsy
-
That is a consideration. Cheers
-
I might try and link it to SIMS too.
-
Thanks Dave, middle initial is a good idea for duplicates as we used to double the initial but that can lead to confusion when you have a number of pupils with the same surname.
-
Of course, my bad. We never used that at my last establishment which is why it never came to mind! Cheers
-
Yeah, I'm kind of thinking I might put the intake year in too as it splits them up a bit more for the OU's and will help with distribution lists for exchange year group lists. Cheers
-
Interesting SovietRussia, how do staff locate a pupil if they need to email them, is there a list with the corresponding student name for example? Cheers
-
Hi I was wondering what format you all use for usernames, previously I managed an RMCC3\4 network and we had 01-bloggs-j for pupils and st-bloggs-j for staff with OU's for each year group. My current school has joe.bloggs for staff and pupils and they are all lumped together in 2 OU's, staff and pupils. I am creating the AD structure from scratch and I just wondered if anyone has any suggestions or good practice. Cheers, Jertsy
