-
Posts
1,598 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Duke5A
-
What do they mean, "bringing pricing in line with the Euro?" You guys have one of the strongest currencies in the world. Funny how prices will be raised though when currencies slip, but never come back down. Cost of digitally delivered games anyone?
-
There should be an option in the BIOS to disable the POST screen logo. This way you could actually see what it is doing in the background.
-
Does this person have an office? Swap it out for a desktop. If the person is going to keep it until their contract runs out, but is actually going to be done with work sooner then odds are they're just keeping it out of spite and have no intention of using it. Breaking it probably wouldn't do anything.
-
IE 10 has caused me some issues with sysprep on my x64 image as well. What do your sysprep log files look like? You're looking for two files: setuperr.log and setupact.log. C:\Windows\Panther C:\Windows\Panther\UnattendGC C:\Windows\System32\sysprep\Panther In my most recent case this was the solution to the problem: After installing IE10, sysprep fail with error: SYSPRP LaunchDll:Could not load DLL C:\Windows\SysWOW64\iesysprep.dll[gle=0x000000c1] If IE doesn't turn out to be an issue, Smart Ink has always given me the most grief of the Smart suite. It intertwines pretty deeply with how Windows are drawn and would actually cause certain pieces of software to crash on me.
-
Well, the problem isn't with Chrome itself; it's only because of it that I discovered the issue. Windows itself doesn't have system proxy settings until IE is opened up when using GPP to dish proxy settings with IE10. I'm curious if anyone else has discovered this or can even reproduce it. I've already changed the Chrome GPO to specify proxy settings (instead of pulling them from Windows) as a work around. The problem is I've got other pieces of software beside browsers that rely on the computer having proper proxy settings. This is driving me nuts....
-
I'm currently rolling out IE10 on my Windows 7 workstations this summer. I already had GPP setup and it appeared everything was working as intended. Well, one of the additions to the image this round is Google Chrome. I had it set in GPO to pull proxy settings from Windows, and I've noticed if you logon to a machine and open Chrome first it doesn't use the proxy. If you open IE it'll work and then Chrome functions. Near as I can tell the GPP for setting proxy settings isn't being applied to Windows until you actually open Internet Explorer. Has anyone else come across this? Thanks...
-
I've used a couple different classroom management solutions and I can say the LAN School is the best I've ever used. It's fully deployable via Active Directory, comes with GPO templates, and flat out works. The pricing is more than fair and they even offer crazy discounts if you're still using a competitors product.
-
Machine password changes by default every 30 days. Being away from the network longer than that doesn't break the trust though; the computer would simply give AD the same expired password and as long as it matches the one AD has everything is fine and it will be renewed. The problem as stated earlier is if the computer ran start-up repair and restored a snapshot from before the password changed. The next time it checks in with a domain controller the DC will see the passwords don't match and you'll get the error. There is two things you can do: either you can change it so the password never expires, or disable system restore. I chose to disable system restore in my base image, but if you wanted change the password expiration policy you can find it here: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Disable machine account password changes Microsoft doesn't recommend using this policy though. And if memory serves when you change this it will force one last password change. I hope this helps...
-
Google Chrome Updater vs Proxy
Duke5A replied to Rammie's topic in Internet Related/Filtering/Firewall
We use Chrome in our district and I just disabled the auto-update and updates are pushed via Group Policy. To get the update servers addresses you'll probably have to turn off authentication on your proxy and watch the logs as you force the update. I didn't see anything pertaining to Google Update server addresses in a quick search.- 3 replies
-
- chrome
- proxy bypass
-
(and 1 more)
Tagged with:
-
pfSense + Squid or just Squid
Duke5A replied to SovietRussia's topic in Internet Related/Filtering/Firewall
I use straight up Squid 3.1.x configured with Kerberos authentication and an upstream proxy. Works great... -
I would just plug the drive in, create a new container for it, and Ghost your volume over. If it works then you're all set, and if not, at least you haven't modified the original drive set.
-
You can get the policy templates for Chrome here: Policy Templates - The Chromium Projects The policy templates to control Google Update are here: https://support.google.com/installer/answer/146164?hl=en
- 1 reply
-
- google chrome
- gpo
-
(and 1 more)
Tagged with:
-
Plugging single wireless routers into network ethernet points...
Duke5A replied to MrBitey's topic in Wireless Networks
You really shouldn't be using a router for this. I would hit up eBay or the like and search for Linksys WAP54G access points. They're cheap, compatible with Radius servers and would do exactly what your looking to do. -
Should get you started. Group Policy Management Setting Path: Explanation Print Close No explanation is available for this setting. Supported On: Not available Student Policy Data collected on: 6/18/2013 10:09:05 AM hide all Computer Configuration (Enabled)hide No settings defined. User Configuration (Enabled)hide Policieshide Administrative Templateshide Policy definitions (ADMX files) retrieved from the central store.Control Panelhide Policy Setting Comment Prohibit access to the Control Panel Enabled Control Panel/Printershide Policy Setting Comment Prevent addition of printers Enabled Prevent deletion of printers Enabled Desktophide Policy Setting Comment Don't save settings at exit Enabled Hide Network Locations icon on desktop Enabled Prevent adding, dragging, dropping and closing the Taskbar's toolbars Enabled Prohibit adjusting desktop toolbars Enabled Remove My Documents icon on the desktop Enabled Remove Properties from the Computer icon context menu Enabled Network/Network Connectionshide Policy Setting Comment Prohibit access to properties of a LAN connection Enabled Prohibit access to the New Connection Wizard Enabled Network/Offline Fileshide Policy Setting Comment Prevent use of Offline Files folder Enabled Start Menu and Taskbarhide Policy Setting Comment Add Logoff to the Start Menu Enabled Clear history of recently opened documents on exit Enabled Prevent changes to Taskbar and Start Menu Settings Enabled Remove drag-and-drop and context menus on the Start Menu Enabled Remove links and access to Windows Update Enabled Remove Network Connections from Start Menu Enabled Remove Recent Items menu from Start Menu Enabled Remove Run menu from Start Menu Enabled Remove the Action Center icon Enabled Turn off personalized menus Enabled Systemhide Policy Setting Comment Don't display the Getting Started welcome screen at logon Enabled Prevent access to registry editing tools Enabled Disable regedit from running silently? No Policy Setting Comment Prevent access to the command prompt Enabled Disable the command prompt script processing also? No System/Ctrl+Alt+Del Optionshide Policy Setting Comment Remove Lock Computer Enabled Remove Task Manager Enabled Windows Components/Internet Explorerhide Policy Setting Comment Disable changing Advanced page settings Enabled Disable changing font settings Enabled Disable changing home page settings Enabled Home Page http://www.google.com Policy Setting Comment Disable changing Temporary Internet files settings Enabled Disable Internet Connection wizard Enabled Windows Components/Internet Explorer/Delete Browsing Historyhide Policy Setting Comment Disable "Configuring History" Enabled Days to keep pages in History Windows Components/Internet Explorer/Toolbarshide Policy Setting Comment Disable customizing browser toolbar buttons Enabled Disable customizing browser toolbars Enabled Lock all Toolbars Enabled Windows Components/Microsoft Management Consolehide Policy Setting Comment Restrict the user from entering author mode Enabled Restrict users to the explicitly permitted list of snap-ins Enabled Windows Components/Task Schedulerhide Policy Setting Comment Prohibit New Task Creation Enabled Windows Components/Windows Explorerhide Policy Setting Comment Hides the Manage item on the Windows Explorer context menu Enabled Remove DFS tab Enabled Remove Hardware tab Enabled Removes the Folder Options menu item from the Tools menu Enabled Request credentials for network installations Enabled Windows Components/Windows Updatehide Policy Setting Comment Remove access to use all Windows Update features Enabled Configure notifications:
-
I had this exact same issue when I took my new job. The district I'm in handed out domain admin credentials like it was candy on Halloween; there must have been almost a dozen media paras and teachers that had it. It was their easy solution to getting people the access they needed to do their job. I spent about a week creating restricted accounts/groups that had the access to do particular job functions and handed them out to the people that needed them. Once I weened everyone off of their domain admin addiction I changed the passwords. Don't just take away access they need. One example of the issues I faced was select staff would reset student passwords in the buildings, so I created a .Net app with search functionality that would allow them to reset/unlock student accounts. If you give them an alternative to do their job that is easier you shouldn't have any problems.
-
Unless you've been directed otherwise by the SMT then I would leave it alone. They get paid to deal with the hot button issues.
-
Thanks guys. I'll give them a try.
-
I am in fact using the /MIR switch. MS Security Essentials is installed on the machine with scheduled scans turned off.
-
I periodically backup my personal media collection with Robocopy to a FreeNAS setup. It seems that Robocopy thinks a significant chunk of my collection has changed since the last sync and it is copying files over to the NAS that I know for certain haven't. My collection was originally hosted on an Ubuntu install with LVM across four disks and now sits in Windows 7 with a Perc 5i. Does Windows do anything to alter files without user intervention? Perhaps just browsing directories while it tries to pull thumbnails out of them? Thanks...
-
Here is another vote for HAP. I'm still using v7.9 in a district of about 250 teachers and haven't had any real issues with. Staff loves it and it is one of the few things I can setup and forget about (with the exception of security updates of course). I will admit though the documentation is a bit lacking.
-
Squid, negotiate and WPAD.dat
Duke5A replied to localzuk's topic in Internet Related/Filtering/Firewall
I was thinking about consecutive requests for the WPAD script once it has already been cached by IE. I actually had an issue where I forgot to add the web server hosting the WPAD file to exceptions and had this happen. So I was curious if it was subsequent gets for WPAD triggering a request for credentials or whatever the start-up page your browser is set to. The only other thing I could think of is if you're using the Kerberos helper in Squid then the proxy has to be called out by its FQDN instead of by IP. It will continually prompt for credentials if this were the case. -
Squid, negotiate and WPAD.dat
Duke5A replied to localzuk's topic in Internet Related/Filtering/Firewall
Can you see the request for the WPAD file in the access log? IE does some goofy things with caching the WPAD script and I don't believe IE sends credentials with WPAD gets. I would try two things: first, disable caching of WPAD through GPO, and second, edit the WPAD file to instruct the browser to connect to whatever web server is hosting the WPAD file directly. User Configuration>Administrative Templates>Windows>Components>Internet Explorer: Disable caching of Auto-proxy scripts if shExpMatch (url, "http://webhost/wpad.dat") return "DIRECT"; -
[wds] Putting a Second Reboot intruction into SysPrep
Duke5A replied to soveryapt's topic in O/S Deployment
You could try adding this to your run once command in the answer file: reg add HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce /v Reboot /t REG_SZ /d "shutdown -t 0 -r" It'll add that value to RunOnce for the user you have set for automatic logon. As long as the same account is used for the second logon that event will fire and reboot the machine. -
Yeah, I'll most certainly agree with this. Sometimes the overly complicated technical solution is in fact the easier approach than having to deal with humans.
-
Live network map, has anyone seen one?
Duke5A replied to Yeo695's topic in Network and Classroom Management
I setup The Dude last week in a VM and added all six of our sites along with a WAN Map using a snapshot from Google Maps as a background. The auto-discover seems a bit wonkey, but other than that it is pretty cool. I even setup email notification via our Exchange server.
