Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ronnoco

Members
  • Posts

    275
  • Joined

  • Last visited

Everything posted by ronnoco

  1. Dave/Kris, Not sure if this well help but for us, if you have the following policy enabled, the Start Menu is empty. User Config\Admin Templates\Start Menu & Taskbar "Remove User's folders from the Start Menu"
  2. Hi Kris, If you're not running 2008R2, I wonder if the Win7 required ADMX files have ever been copied to a central store? If not, this may well be why you are having issues. I got the advise underneath from user Synastra and it worked perfectly for me. Browse your network and find \\DomainContoller\sysvol\your.domain.name\policies you should see GUID foldernames, in the policies folder, is there a folder called PolicyDefinitions? if no then Copy the PolicyDefinitions folder from a Win7 client computer with all the files and folder within, to do this, locate the PolicyDefinitions folder on the Win7 machine, C:\Windows as an example. Now copy the folder to the \\DomainContoller\sysvol\your.domain.name\policies folder. Use the remote server tools for Win7 to manage the new ADMX templates from the Administration tools. The new tools look at the new folder you created for all the policies. Hope it helps!
  3. I've got ours working....thanks janutall, it was a mistake in that I had ticked the 'Move the contents of the Desktop to the new location' box so it was trying to write to a folder where the pupils don't have permission. Both redirecting fine now. Kris, is yours a newly created policy without anything being inherited? Are you managing from a Win 7 PC or do you have a 2008 R2 DC? Have you tried (just as a test) logging on a pupil and letting it create a new V2 profile for them, just to eliminate it's not associated with a profile issue? - it shouldn't be but might be worth ruling out? Let me know how you get on when comparing your settings to mine.
  4. Same here, Desktop Redirection works fine for XP, just not Win7.
  5. If you look at the attachment, that shows all the policies I am using. The Start Menu redirection has always worked and ours is a huge one (that needs tidying!) It's just the Desktop for me that doesn't work. Are you using a DFS share for your folder redirection?....i'm not.
  6. Hi all, I'm making a brand new Win7 student policy. Nothing is being inherited. Managing GP from a Win 7 PC. I can get the Start Menu to redirect but not the Desktop? The setting is identical to our normal Win XP policy. Windows is up to date and I have applied some GP settings as recommended in other posts. The event ID is 1085 but can't find a huge amount specifically for this problem. Attached is a copy of all the GP settings I have configured so far (not many) If anyone has any ideas, suggestions or advise to remedy this problem, it would be much appreciated. Thanks very much in advance. Gary Student Policy.docx
  7. Hi all, Thanks for the replies, much appreciated. I will give thanks to all. What a strange problem this has turned out to be.....originally, we were using the default system account but couldn't open any document storage files. Called Serco, they advised to change to the Administrator account and this is what the Document Storage instructions state to do. Changed it, fixed the problem straight away but since then have had the problem whereby if you restart the services, you have to enter the Administrator password which obviously was mucking up the scheduled task batch file. I have put it back to the local account and now it's working fine....without changing anything at all! Maybe it was a bug that has been fixed in the latest build of eportal. Either way, we're running as usual. Thanks again for all the advise/help. Much appreciated. Gary
  8. On the share....we have system with full control already but if I set the eportal services to use the local account, document storage can't be accessed....thinking back, I don't remember having this issue when we use to use Server 2003 and that I believe used the local account for the services. Maybe it's a 2008 or 64 bit issue?
  9. Thanks for the quick replies. It is on the same server so maybe this will fix the problem. What should the local system account be listed as? system, service, etc? System currently has full control. Cheers.
  10. Hi, It works fine with the local account but then the document storage can't work. Serco generally performs better if you restart regulary and we often have changes made in Facility which wont filter through without the restart. We find it will just fall over if not restarted for around 5 days. We do have a hell of a lot of access though (students, parents, etc) Thanks Gary
  11. Hi All, I have a strange problem with Eportal. If we stop the services (which is usually done via a scheduled task every day) the services both won’t start unless you re-enter the account password. It always says the credentials are incorrect. We use document storage so have to use an account with access to the share where the document storage files are located. I have always used DOMAIN\Administrator in the past but have also tried using different accounts to resolve this problem. I know the password is correct and the only dependencies of the service is the other Serco service. It's been like this since we moved Serco to our new server with is running 2008 Standard 64 bit. Serco say they have never come across this problem before and advised researching it but I can't find anything. Anyone have any ideas or suggestions? Thanks very much in advance. Gary
  12. Hi Paul, I had been having quite a few issues with DPM so am using a 60 day Symantec trial now. I followed your instructions and everything is working fine, I’m managing from my Win7 PC. Took my ages just to get a wallpaper applied on Win7...needed a workaround. Not the best start!...roll on SP1! Desktop Redirection and maybe mandatory profile tomorrow! Cheers. Gary
  13. Hi Paul, Thanks for the reply. Well explained which was exactly what I needed. I did promote the 2008 R2 server to a DC but had problems using Microsoft Data Protection Manager 2010 to backup, aparantly it just doesn't work on a DC without some fixes which I didn't fancy. I have yesterday switched to Symantec BE which looks a lot better already so I guess I could try promoting it to a DC again but seeing as we can't raise the functionaility level as our other 2 DC's are 2003, I think I might go for copying the ADMX files from my Win 7 PC to our 2003 R2 DC and then manage it from the 2008 R2 server using the Administration Tools. I've not used the Win 7 AIK but will give it a go! Thanks again for your posts, really helpfull. Gary
  14. Hello all, We have a 2008 R2 server that we want to use to manage GP to create our new Win 7 policies. It can't be a DC so how do I go about getting the latest ADM templates, etc replicated? I have downloaded the Win 7 AIK toolkit but am not sure where to start and want to get it right. Does anyone have a step by step guide on how to do this? Thanks very much in advance. Gary
  15. Hello, I am following a Microsoft blog for setting up DNS scavenging as we have far too many old and in some cases multiple entries in our DNS records. One of the first steps is to set the aging properties. This should show a date of 7 days ahead but ours shows 01/01/1601. Have tried applying anyway to see if it changes but it doesn't and with this date wrong, I can't see how we can configure. Does anyone have any ideas or advice on scavenging and keeping DNS tidy? Thanks very much in advance.
  16. Our core switch is pretty much full. It makes sense to utilise the bandwidth from these free ports. If you buy another switch, you will have to uplink and even if you buy a 10/100/1000 switch, you are not going to be able to give the clients the full bandwidth as you are limited by how quick the connection is to the core switch. Hope this helps.
  17. That's a good post....it's just the catalog role I missed. We have 2 other DC's and have purchased a new server which will also be a DC. I'll add the catalog server role to the server which doesn't hold the FSMO roles next week then try removing this role from the server we want to retire. If all goes well, we can demote and job done! Thanks for your help, much appreciated.
  18. Thanks for the info...to be honest, I didn't even know about the global catalog role? I know about the FSMO roles and remember gritting my teeth moving them from this very server. What other non obvious roles could be running on this server and how do I check?
  19. Hi all, We have an old server which is a DC which we want to retire and replace. I decided best practice before demotion was to turn it off for a week and see if having it off causes any problems. It didn't until yesterday when we needed to create a new user account in AD. Failed because the global catalog could not be contacted as the server was not operational. I have since discovered that this server holds the role of storing the global catalog. Googled it and it looks pretty straight forward to move but there are very mixed opinions on whether it is actually required in a single domain, single forest environment. Global Catalog Server...did you know!!! - Bink.nu My question is, do we actually need it and am I likely to get any problems moving it (I play to move it to the server that holds all FSMO roles) Thanks in advance for any help/guidance that can be offered. Gary
  20. Well the instructions are all naff but i've got it up and running but pretty much everything it tries to back up fails suring the process with this error : - Type: Tape backup Status: Completed Description: The job completed successfully with the following warning: File copy failed due to an I/O error. Source location: \\nwhserver8.nwhs.local\MTATempStore$\d2512569-82b5-45c7-b764-ea0ccec2e5e9.mbc Destination location: C:\Program Files\Microsoft DPM\DPM\Temp\b9e8fb35-d1b0-4278-9df2-6617dd66da0a.mbc. (The specified network name is no longer available. ) Exception trace : at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.File.InternalCopy(String sourceFileName, String destFileName, Boolean overwrite) at Microsoft.Internal.EnterpriseStorage.Dls.ArmCommon.FileCopyBlock.DoFileCopy(Object msgObject) (ID 30123) More information End time: 24/09/2010 09:07:29 Start time: 24/09/2010 09:03:52 Time elapsed: 00:03:36 Data transferred: 13,901.00 MB Cluster node - Source details: D:\ Protection group: Daily Tape Backup Library: IBM ULTRIUM-HH3 SCSI Sequential Device Tape Label (Barcode): Daily Tape Backup-00000003 (None) Anyone got an ideas?
  21. Hi, Has anyone got 2010 version up and running? It looks very powerfull but tricky to initially configure. There is a 270 page MS guide but it's driving me crazy! I would just like to get up and running so our entire server is being backed up to LTO3 tape. Can anyone shed any light or got any quick start guides they have found? Thanks very much in advance. Gary
  22. Hi, I have setup SSO before and have pretty much just finished doing it on a new server. It is a complicated process but here goes!.... Presuming you have purchased the SSO module and entered the new license code, launch Facility Controller, click on Data Server Settings button and scroll across the end to find the SSO module. Tick the box to enable SSO and select the Attempt login bypass mode. Enter your LDAP server name. In the LDAP Base User DN box you need to enter the paths for the OU's in AD for which you want users to be able to access SSO, separated by semi colon, for example : - OU=Network Admin Staff, DC=NWHS, DC=LOCAL; OU=Office Staff, DC=NWHS, DC=LOCAL; OU=Staff, OU=Mobile, OU=LightlyManaged, OU=Users, OU=CommonScenarios, DC=NWHS, DC=LOCAL Next, click on the credentials button and enter the DN of an Admin account (make sure your admin account actually has the First name written in AD (mine didn't by default, took me ages to work out why SSO wasn't working!) The DN will look something like this: CN=Administrator, OU=Network Admin Staff, DC=nwhs, DC=local Next from Controller, click on Server, login name table, Single SignOn Logins and your table will be built. From here you will be able to map the Serco userIDs to the AD record. There is a tool to automatically do this but it will only work well if your Serco userID's actually have similar names to AD. Alternatively, if you are already using Resource passwords, the first time a user enters their credentials, it will do the mapping saving you a lot of time. Also, just checking but if you use IIS you will need to have altered the settings.xml file to change the value from false to true for 'UseIISAuthenticationForSingleSignOnBypass and you will need to have edited the IsapiRewrite4.ini located in ePortal\bin\win32\i386 with your domain name. Finally, you will have to disable Anonymous Authentication and add the isapirewrite4.dll filter in IIS I worked from a Serco manual called Facility ePortal v09.2 (an old version) Single Sign On (LDAP) Guide. Get this or the latest version if you don't already have it. Hope this helps. Gary
  23. Damn!...thanks for letting me know though John. I thought it wasn't officially supported yet but would work. It was 64 bit on Server 2008 Standard that would work but is not officially supported until November. Oh well....lucky I didn't do the job earlier! Cheers.
  24. Hi, We are currently licensed for 2005 and as it's supported main stream until 12/2011 and extended until 12/2016, would rather just stick with this....especially as it looks like Serco is going to be web based in the pretty near future. Never mind, Can't be helped...I should have thought about not having the 64 bit media. Gary
  25. Hi, Thanks for replying. I'm only in until Wed and it's only me in the school so can't really order anything now and even if I did, by the time it arrived, probably wouldn't have time to finish the server install. Cheers. Gary
×
×
  • Create New...