I'm glad I started this thread, lots of good inputs. It seems this is a complicated subject though with plenty of devotees for each approach. I'm not convinced there is one solution that fits all.
I think I'm going to stick with using GPOs and mandatory profiles to lock everything. Thanks all.
Andy
Thanks all for the latest replies. That clarifies things regarding NTUser.MAN. I'd still be interested in a specific GPO setting that stops icons being added to or moved on the desktop. I can't spot it and I've tried a fair few as well.
Andy
I've used PlusNet for a couple of years now without any real issues. No cap, lots of support for things like PHP, MySQL, CGI, etc, ample webspace, etc, etc.
Andrew
Thanks for this info. Going back to one of my earlier questions, if you do use mandatory profiles, how does the installation of new software, new icons, start menu items, etc get affected. Surely the use of NTUser.MAN prevents any updates or other changes to these things?
Andy
Thanks for the spreadsheet, really useful to see it all in one place.
I've already made use of many of these and they seem to do the job but the one thing I can't stop is the ability to save shortcuts & icons or move things on the desktop itself. "Don't save settings on exit" doesn't prevent it". Any idea which one should I use for that, as it's not obvious to me after reading through everything.
You're right, I am using 2000 but I do use the GPMC on one of the XP SP2 machines to manage everything. I'd be interested to know what the extra updates to 2000 are and what extra lock-down they provide.
Thanks again.
Andy
Thanks everyone for the quick feedback.
I did look through the threads but the ones I saw seemed to be anti-roaming profiles rather than mandatory ones.
I will only have around 30-40 PCs max. I assumed that by redirecting My Documents via GPO the bulk of the data would not get transferred at logon.
Any chance of seeing an example of what this script looks like?
I must be missing something here. I can find a GPO for most things but I can't find anything to stop files and icons being saved on to or moved on the desktop. How do you achieve that via GPO? That was one of the main reasons I was looking at a mandatory profile.
All this via GPO?
Thanks for the help, much appreciated.
Andy
Hi there
Just joined this after seeing the letter in PC Pro a month back. Well done.
I'm trying to set up a new network at a Primary School which consists of the following so far:
Windows 2000 Server SP4.
Clients running XP Pro SP2.
Domain + Active Directory + GPOs to configure PCs.
(The GPMC for XP and WS 2003 makes GPO management a lot easier!)
Redirected My Documents via GPO.
I'm now trying to arrive at the best way to stop those meddling fingers by locking things down tightly. What I want to do is use mandatory profiles on the server, i.e. by changing NTUser.DAT to NTUser.MAN. My questions are:
- Is this a typical scenario that people are using in schools?
- What are the implications for installation of new software (i.e. additions to start menus, new icons, etc) if the desktops use mandatory profiles?
- Is there another way?
All help gratefully received.
Thanks
Andy