Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Killer_Bot

Members
  • Posts

    122
  • Joined

  • Last visited

Everything posted by Killer_Bot

  1. Isn't there a setting in GP that makes a computer wait for a network connection before displaying the logon screen, something like 'always wait for connection'? Just wondering if there's a delay and the Computer displays the CAD screen and allows logon before kicking in the Client Side Extensions for the GPO. Also, is there anything set in the User Attributes RE there home folder? I remember we had issues with something similiar and had to apply the location through the User Attributes in AD and then cancel them out just so that the folder and permissions were set up as necessary.
  2. Ok, when you do a GPResult on a machine does it list the GPO as an object that has been applied? Also, is the GPO setup to only apply the Documents redirection? If not then could you set one up that is solely for the redirection, just to make the troubleshooting simpler. Apply it to the users OU but get rid of the 'Authenticated Users' and apply it only to one test account. Check the Group Policy Modelling for that user on a particular machine and see what comes up.
  3. I sometimes delete them from the registry though as Andy mentioned the Advanced Properties way is probably the cleanest though it can take a good while to load if you have alot of Local Profiles. If you get a 'Not Responding' just leave it be.
  4. Have you configured the 'Folder Redirection' > 'Documents' User-Side GPO? If so how are you typing in the path and where are you applying it?
  5. You could do reservations for the switches though you'd want to configure the switches to DHCP then (to pick up the reservation) though I imagine leaving them as static would be fine. Plus setting anything that requires a Static IP as a DHCP reservation can end badly should the DHCP go down whereas statics would obviously survive. If I were you though I'd just set up a new exclusion range for ***.***.***.204 - ***.***.***.205 (e.g 192.168.1.204 - 192.168.1.205). Those IPs would never get dished out then.
  6. I'm with qcomer on this, we tend to turn all our Computer based Firewalls off as they cause more trouble sometimes than they are worth. It's one of those good side bad side things I suppose.
  7. Was going to suggest Logon Hours too but as a few peeps have said, it's not really an IT problem. If they are really annoying you though I think Logon Hours would give you some satisfaction, it'd just be a case of how do you target it to those that abuse it.
  8. I may be wrong here but I'm fairly sure you can't have the backup location as a folder in this instance. You have to specify the Drive Letter only. Perhaps you could make a script to run the backup to the D: drive and then, when it's complete, move it to a directory if that is absolutely vital.
  9. So can you ping 204 & 205 when the computers you're talking about aren't online? If you can then you need to find where those IPs are or maybe just exclude them if you can't be bothered. Deleting them from the database wouldn't help until they come to renew the IP with the DHCP server and get refused, and depending on your lease time you could be waiting a couple hours or weeks. There is another option on the DHCP server where you can configure conflict detection so that it attempts to ping an IP before issueing it to a client. Maybe configure that and if it gets a response on 204 it'll try 205 to which again it'll get a response and got to 206. Depends how you want to go about it.
  10. You need to deploy a GPO and set the option to enable without TPM on the particular machine/s. You have to use a new method though which requires that a USB Key be inserted at startup and if that key is lost then you need to have it backed up else the entire drive is unusable.
  11. Solution copied from Windows 7 Gotcha as posted by Deano above; --------------------------------------------------------------------------------- When viewing redirected folders share you may see many "My Documents" When Windows sets up a new redirected My Documents it creates a hidden desktop.ini file which means that when you browse the share/location from Windows you may see a huge amount of folders called "My Documents"/"Documents" rather then the folder name it should be (e.g. \\server\share\username as the path could look like \\server\share\documents) The folders are correctly named but when Windows sees the existance of the hidden desktop.ini in each directory it displays the folder as "My Documents"/"Documents" rather then the real folder name. This can happen with any special folder I believe such as Favourites. The solution: Remove the desktop.ini file in each my docs redirected folder. This can be done with script or using Group Policy Preferences. You can also redirect to a sub folder which hides the issue (e.g. redirect to \\server\share\username\documents\)
  12. We have a similiar issue though never really bothered me too much. I tend to go to the directory and just start typing the username at the end of the UNC path. When you go into it it then highlights the relevent 'My Documents' folder in the left explorer bar. Just out of interest, could we not just delete the desktop.ini? What purpose does it actually serve for the users?
  13. They certainly do with Windows 7 so id assume its the same with Vista. I always remember the order of inheritence as LSDOu (Local, Site, Domain, Ou). That's why I asked if you'd disabled or set as not configured. Though you can only have 1 lot of password requirements (without going into 2008s PSOs)it could be worth checking out. If it were me though I'd leave everything as it is if it works fine elsewhere and join a workgroup with the comp, delete the AD object for the comp before rejoining it to the domain.
  14. Not if they used these; Double USB concept ends your fear of USB plug rejection -- Engadget (Pretending they were actually a product right now and not a concept!)
  15. It's another layer of protection so why not. As you say it's only temporary. Otherwise could a user not "accidentally" copy some contents onto there unencrypted stick? Not sure if it works like EFS where it unencrypts before copying? You could maybe set up BitLocker ToGo though and insist sticks be protected with that?
  16. Luckily that's not my decision to make, I just do as I'm told by my boss BitLocker is by no means fully secure either, especially if it's set for the USB keys. Granted, it's much more secure than an unencrypted drive but requires far more staff training RE things like storage, social engineering, passwords, etc. Just to be clear I'm not against BitLocker, I just don't think it's something to take on lightly when EFS and training with it can do almost the same thing.
  17. That's true but on the other hand they don't have to rely on a USB to do any work at all, if they lose it on a weekend and can't see you for a day or two it's pretty much a brick in the meantime. It's one of those pros vs cons things isn't it. Ideally I'd love to BitLocker all our laptops here but I know without a doubt that USBs would be constantly lost or left with the laptop itself out of convenience. Either way it's a headache we could do without though I appreciate that sometimes you really do need this level of security.
  18. Have the laptops already been partitioned accordingly, i.e. with the 1.5Gb system partition? If not then you're going to have to format as you may already know. Also, my understanding of BitLocker is that it will hit the performance but if the laptops aren't used for anything that rely on fast performance I can't see it being an issue. Could be worth looking into EFS for folder encryption if there's only a select few files that really need encrypting. Unless you're worried about the pagefile and whatnot.
  19. Did you actually disable the complexity requirements or set it as 'not configured'? Just wondering if the Local Policy could be enforcing any requirements if you didn't 'disable' it at a higher level. Also, I'm assuming you tried multiple passwords yourself of varying complexities? Could be worth trying to change the password directly on the machine again to see if it now works, could just be one of those weird things that computers do every now and again Is the Server 2003 set as a DC or just a Domain Member also?
  20. I've only had a brief play with Preferences but for example I used a Preference GPO targetted to a machine to make a user an administrator only on said machine. However I've had issues where other settings made in another GPO (which contains 100s of settings (not my idea!)) such as hide C drive, remove add programs and other general 'lock-down' settings still apply to that user and so restrict alot of the stuff that an admin user should be able to do. I've had a play around with Willot's suggestion but that stupid GPO contains so many settings that it'll take me ages to disable those I no longer want applying in another GPO. Did start to work my way through but lost attention after the first 40 or so
  21. That's an interesting idea...... would work if I used Replace I'm assuming as the sub OU would take precedence. Will have a look now
  22. We're trying to figure out a way to block a particular group policy object from applying to a particular machine only when a particular user logs on to it (too many particulars??!). We've figured ways of doing it by moving users into different OUs or outright denying them the 'apply group policy' permission on a GPO but would much prefer a more viable solution. So for example, we have a Staff Redirection Policy in a GPO purely dedicated to the User Side. We want that GPO to apply to Joe Bloggs where-ever he logs on, unless he logs on to a client called 'joe-client'. I've tried denying the client the apply permission but that just stops it applying the computer side of a GPO as opposed to the User side which is no good. Does anyone have any ideas?
  23. Local Firewalls are more trouble than they are worth if you ask me Was going to suggest deleting any profiles that were cached locally via the 'Computer' properties user profiles tab as I've found sometimes I have to do that after disabling offline files before it works. Sounds though it was the firewall in your case though, atleast you figured it out.
  24. How is it exactly they are failling? We have a few Stone laptops here and the only issue we've ever had it them randomly displaying the 'OS is not found'. No actual hardware errors for us though.
  25. Atleast as a final option you could reset the Network Admin password, bit of a ball ache though if you're running any services off of it (which you shouldn't be...... but meh). I'd imagine it would chuck up another prompt then.
×
×
  • Create New...