-
Posts
81 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by DEvans
-
Or Group Policy preferences. Its all windows 7 with (i assume) a 2008 R2 Server. Saves you messing with scripts then. I found it to be quite reliable and quicker to do it. Can apply it to all sorts of scenarios, like certain security groups, run as administrator if it needs to be done on a user login etc.. Group Policy Management Console User or Computer Settings --> Preferences --> Two folders in there containing tools to everything you ever need. Inc. registry.
-
I had a similar issue to this a long while back. It was caused by a hotfix for Internet Explorer 9. Have any windows updates been authorised during the time this problem occured? Would explain why some machines weren't affected then some began to be, then eventually the majority. Also are all the normal processes happening, like mapped drives, printer allocation etc?
-
I assume you are using Roaming profiles. Do you have any redirections in place? If you do, are your group policies applying to the machines when they login? If it doesn't apply the policies, it won't apply the redirection, no redirection and it will create a new profile on the client machine. What operating system are your clients running?
-
Startup hangs on Applying Deployed Printer Connections policy
DEvans replied to neilmc's topic in Windows Server 2008 R2
You haven't got User Account Control on have you? Additionally, have you allowed users to add printers. Chances are in the background there is a window popping up saying "are you sure you want to install this printer" as it comes from a unreliable source (due to a UNC path), which needs the user to click "install printer" and then type in an admin password probably. This commonly happens with Windows 7, you gotta think to any prompts it might give you if you tried to do this manually. -
I think it depends on your server operating system. In server 2003, whatever you set in DHCP is law and cannot be changed unless you remove and redo. I think in Server 2008R2 you can modify your DHCP and then just authorised the new scope. Though I have never done this before. Generally what you want to do, trying to stick to your examples is set up DHCP with a scope that covers your entire range. e.g. *.*.*.2 - *.*.*.100 And set in exclusions within that range for your statics *.*.*.2 to *.*.*.29 The left over then will be your DHCP scope.
-
RM do love to modify. Why on earth they looked at the volume control in XP and thought to themselves, hmm I like the slider, up and down, it's simple, elegant...... but what we could do is put in tick boxes! So they can choose "quiet", "loud" and "loudest". Yeh thats really.. useful that, can't tell you how empty my life was before that change.. Generally with RM networks to Group Policy you can't use the existing domain. You gotta redo it. They are so deep into the registry of all your clients and server(s) it's going to be technical suicide to even try. For the clients, rebuild. You have no choice really. The Server, go with what those who have done this before have said and start a seperate domain and do a intergrated upgrade, gradually shifting machines to the new network. Our team would take the school data from the server and then wipe it entirely and rebuild, just to be sure. Can get a quick network running in a couple days. Depends on how well you know Windows Server and it's features, also depends on the size of your school of course.
-
The trick here is to ensure the driver(s) you choose are not just compatible with your clients, but your server operating system as well. In 2008R2, you can stick in x86 drivers and x64 drivers and the clients will automatically take the drivers they need in order for the machines to work. However, sometimes you can have all sorts of issues where you put in the x64 driver and then when you try the x86 the server o/s simply gives you a load of rubbish saying sorry this cannot be the right driver and your left staring at the screening shouting "but it is, you fool!" Like Palellam said installing on the clients first is a good plan as you can do the tests there. Though again, you might stubble across issues when you set up the printer shares on the server. Server 2008 R2 is x64 only, so your printers need to have that driver. HPs tend to be the biggest headache I have found, especially the popular 2600 series. Those things hate mixed networks.
-
Primary School Network - any suggestions of layout?
DEvans replied to jinx4275's topic in How do you do....it?
Doesn't matter how big the network is, just keep it all simple. I see people saying Hyper V solutions, 3 Servers, 4 and now 5?! All you need for a primary is 2 servers. No More. One for redundancy. You could even go for just 1, though not recommended of course. You need to have a safety net. The Company I work for maintains over 130 Primary/Firsts/Middle Schools on a face to face basis, so we know that when there is a budget set, there is little/no room for negotiation. Generally I do think sticking in a 2003R2 Server is a little mad, you need to think long term, with money getting tighter, the likelihood will be that you won't be doing a big rebuild like this for many years and when you are troubleshooting problems you will find many solutions that only apply to features for 2008R2 networks and "Server 8". There is no harm in going down the Server 2008R2 route and sticking with XP clients. Especially since your client machines are old anyway. Though you will need new Client Access Licenses for the new 2008R2 Operating system. About £5 a machine with education prices. Stick to the basics. A Microsoft Server Operating System with the following roles • Dynamic Host Configuration Protocol (DHCP) - Unless your router/firewall deals with this of course • Domain Naming Service (DNS) • Windows Deployment Services (WDS) • Windows Server Update Service (WSUS) • Active Directory Domain Services (AD) • Group Policy Management (GPO) Now you need to consider your active directory structure. e.g. School Name ->Computers -->Room Names or School Name ->Computers -->Whiteboard (IWB) -->Class Computers You will need a naming convention for your computers as well. Knowing Primary Schools they do tend to have their computers moved about a lot, moving from one room to another, so I try to avoid putting room names, stick to generic names like School Initials - Make - Number. e.g. ASN-DELL-01 , ASN-HP-01 or just generic Class ASN-CLASS-01, 02. So if you move computer Class-04 to from room 10 to 11, you don't need to change its location in your directory. Once you have AD sorted out. Group Policies. Apply your computer policies, such as Basic Utilities (Flash, Shockwave, Silverlight, Media Player 11, codex etc..) and a policy for your curriculum software. Then User Restrictions, User Redirections etc. Put your Shared areas on your server. Set your permissions. Use a Script or (if 2008R2, group policy preferences) to map your network drives and printers. Technically from then on you have a network. Your method of operating system deployment is up to you. If you are familiar with Linux then go down the FOG Route. Very quick. If you want to experiment with some advanced technologies (while not paying for anything) go down the Microsoft Deployment Tools (MDT) Route, bit of a learning curve but is very powerful. If you want to go down the legacy route, you would need a Server 2003 box and you can use RIS. You could have it in Hyper V, but now we are over complicating things. It's so easy to go off on track. Lots to play with yet little time to learn it. You need to then consider your backups. Stick to what you know, there is no harm. Tape Drives, Hard Drives or NAS. All easily implemented. Tapes are expensive but are reliable, faster and cheaper over a loooong period of time. Hard drives are portable and easier to take off site, NAS is good for automated procedure, just ensure its in the furthest part of the school from the server. Generally the best backup is offsite, but that costs money, which you don't have. You will need a reliable backup application to manage all this, backup exec will come for next to nothing when bought with a Dell Server, Macrium reflect is cheap for a server license and Acronis isn't too shabby. Just don't rely upon the inbuilt Windows Server Backup. It's just dangerous to rely on something that's free with a server and made by Microsoft. Limited in functionality as well and not compatible with Tapes, so forget about that right now. Just keep it all simple. 2 Servers at most for a primary is all thats needed. People may call me mad, but unless you work in primarys' (notice the plural) its not as straight forward as people think to just go out there and implement 5 servers, there is a budget and you're lucky to have that in schools like this. Hope this helps. /Dan -
You can play with GPO all day for this to work. Your system Tray policy will need to be turned off to allow them to see their networking icon. Or you can allow access to it through the start menu, just put a link on those laptops to the network and connections area in the control panel. Need to ensure that your control panel restrictions don't affect the wireless settings controls as well. Otherwise you'll have a system tray but no ability to access the actual panel. Additionally for Proxy Settings you can do either: 1. A Proxy Pac -> Checks the IP address of the machine and sets the proxy accordingly. e.g. If IP address of machine is between the IP range of your schools DHCP, assign your school proxy and if the IP address is in the 192.168 range, its at home assign no proxy. Benefits Automatic, no need for anyone to access the internet properties. Negatives Proxy pacs can be a little alien to write, so needs to be tested. Also found that in some odd occasions it doesn't work and needs the user to restart. 2. A Proxy Question on Startup - Everytime the machine starts up, a vbs script runs asking if the user is in school or not. They say Yes and it performs regedits to apply the proxy for the school, they say no and it takes the proxy out. Benefits Reliable Semi-Automatic No need to give user access to internet properties Can be pushed out to the startup folders from a server easily Negatives Needs User Input - Even a Yes or no can be an issue for people Registry permissions are normally never a problem, but its an extra check. They will need to know how to trigger the script manually if they can't answer a simple question correctly, or you can tell them to logoff and log back on. 3. Third Party Proxy Setter - Proxypal is good, though I find them to be a little unreliable. 4. GPO apparently there are ways, but i've never spent too much time to get it to work, plus you need to question reliability.
- 4 replies
-
- group policy
- server 2008 r2
-
(and 1 more)
Tagged with:
-
Don't attempt to Merge your exisiting with your New. Just start from fresh, get the data you need (recommend doing a full Image backup of your current server, Macrium Reflect is what we use often as its a complete copy of your server). You don't get opportunities like this that often if you work full time there, so make the most of it. Start from complete fresh. Trying to stick to your requirements. Need Windows 7 and XP clients to be able to login I suppose this would help. Problem is that your having a mixed enviroment which is a bit of a pain, especially when it comes to profiles as the profile type for XP and 7 are completely different. You'll get used to the expression "it's a v2 profile" fairly quickly. Are you using XP x86 or x64? Same for Windows 7, x86 or x64? You'll find that your folder redirections will be tricky as sharing favourites and silly things like that across the two operating systems can be a bit flakey even If you set it up in the way Microsoft wants you to. In Server 2008R2 you can redirect every profile folder, unlike in Server 2003, however these new redirects only apply to Windows 7, not XP. So when they login to an XP machine and save a favourite in IE, that only saves to the XP profile and not the Windows 7. Unfortunately, there doesn't seem to be a reliable fix to this unless your good at powershell/vbscript as you can transfer favourites across profiles as a scheduled task, but you need to have a decent script to do this and your permissions need to be spot on. The most important issue are your documents. The document redirect applies for both XP and Windows 7, which is handy as their documents will be available on both operating systems, but with the introduction of the "libraries" in Windows 7, you need to test your redirection to ensure documents are visible in both XP and 7. Redirecting to the Users home directory is the way to go with a mixed network. You set these redirections up in Group Policy and set their home directory in AD. All staff and junior classes to have individual logons / infant classes to have single class logon Easy to do. Wisesoft has a good tool for bulk imports of users, just make sure you have excel installed. Being a Primary school I setup the Class logins to save to a location where the teachers of the nursery and foundation classes can access the work done by the pupils. We are talking very young kids, ideally we just want them to press save, don't want them going through file structures. For examples Junior Children Save Locations -- \\server\users\pupils\yearofentry\Username eg.. \\dc01\users\pupils\yoe2012\JSmith Class Login Save locations -- \\server\users\pupils\classlogins\Class eg.. \\dc01\users\pupils\classlogins\Class1 --Teachers of your lower school then get a mapped drive to the "\\dc01\users\pupils\classlogins\" area. Teachers can then review and tidy up this drive as they wish. Ensure your permissions are setup correctly of course. Any user to be able to login to any workstation (My issue here is I've seen Win7 be quite awkward about security permissions on who logs in where - Just need this simple and reliable) Your talking a mixed network, unfortunately you sacrificed the word "simple" when you tried to merge XP and 7. Any user will be able to login to any machine as long as they have a username to login with. Security permissions aren't really a factor here. As long as their redirections are setup correctly. The only way to keep it all really simple is to say no to data safety, have no redirection and tell people their responsible for all the data on the network.. Yeh.. We are talking about teachers here. They are a.. interesting bunch. Staff to be able to use their laptops off the network at home You can be really clever, slightly clever or just keep it all simple. Really Clever would be using VPNs and they can access all their resources in and out of school. Since your talking of a primary school, your firewall is probably controlled by your local authority or something like that. So this is out the question. Slightly clever would be setting up offline files (which since you have a mixed network would be suicide. If it was just windows 7, you would be fine) and a proxy script that ensures the correct proxy settings are set up relative to the location they are. In school, they get proxy, outside they get no proxy (allowing it to work at home) Simple would be to keep them off the domain but give them access to the shared resources. Need to have a script that asks if they are in school or not, they answer yes to being in school, the script sets the proxy, authenticates with the server with a generic user and maps their drives and printers. They say they are at home, the script does the opposite. Removes any mapped drives and printers and turns off the proxy. Locked desktops, with "Programs" folder on the desktop, that is stored on the server with program shortcuts Group Policy - Start Menu and Desktop Redirection. Applies to both XP and Windows 7. Warning If you have XP x86 clients and Windows x64 clients, you will need to have two different start menus and desktops. The links you distrubute out for XP x86 clients will be a path to C:\program files\developer\start.exe, for x64 machines this would need to be C:\program files (x86)\developer\start.exe. Two different links that will work on one and not the other. On your server you would have Redirect All users desktops to the same location For windows XP - \\server\desktops\windowsxp\ For Windows 7 - \\server\desktops\windows7\ You need to know a decent amount of stuff about group policy in order for the correct policy to apply to the correct computers. Really Clever - Working with WMI filtering Semi Clever - Working with secruity group filtering Simple - In AD, you put XP machines and 7 machines in two totally different organisation units (OU) and apply the right group policy to the right place, this will mean replicating policies. Makes it a little messy but its easy. Printers that default based on the PCs location in the school - ie. ICT suite printers print in ICT suite, if using one in the staffroom it prints to the staffroom printer.... Unsure entirely how to achieve this in Win 7- Group Policy Preferences You will need to ensure the Group Policy preferences hotfix is installed on Windows XP for it to work on those machines, but in group policy in Windows Server 2008R2, preferences are the easiest, fastest and most secure way to do this. Can make your own IF statements, like IF this machine is part of THIS Secruity Group AND/OR This User Then map this printer and put as default. etc. It's easy to do and it has an easy to use GUI. Private and shared user directories on the network... Again I'm only used to Netuse scripts from an NT box Group Policy Preferences also does your map drives. - Policies in force for different users Standard Group Policy. Make sure you know what your Active Directory structure is going to look like then apply policies to the relevant areas. Staff and Pupils should be in their own OUs and you apply a staff restrictions policy to staff and a seperate pupil restrictions policy to the pupils. Click and Drag. Profiles so that desktops, settings etc the same where-ever the user works Hardest Bit. Two Operating Systems using totally different profiles. Windows 7 to Windows 7 a typical roaming profile would be more than enough. 7 to XP though and vice versa. Your favourites and net apps are going to need some extra cleverness to sort out, unless someone knows of an easy way. Mentioned a lot of this in the first part, but this takes a lot of testing for it to work perfectly, as by default, they are not designed to work. This is why Vista came out, as Microsoft now can talk about a merge network of their latest two operating systems Windows 7 and Vista, ignoring XP. Vista and 7 work ok together. Plan A Figure out your folder structure and your Active Directory Structure. Your naming conventions for your machines, your security groups. I've built fresh networks for over a dozen primaries and a couple middles as well as a College. Server builds is what our team does, so these problems are things we have experienced along the way. Hope this helps. Any problems, just message me or something. I'm happy to talk through things with you.
-
I have used a hell of a lot of MSI creators/packaging tools and in my opinion the best one out of all these beasts. Is a free, tiny piece of software that is actually quite tricky to find now on the internet called Installer Wrapper Wizard. If there is a silent install switch you can use to run the application silently, such as /q, -s, /quiet etc etc. This little tool literally just takes the .exe, puts the silent install switch on it and "wraps" it up in a single, completely basic msi. Containing just the information needed by Server 2003, Server 2008 and R2 to deploy it successfully on the network. If you've ever opened up an MSI there is so much stuff in there, but only about 10% of all that is needed to simply deploy it out via GPO. This wrapper uses the exe with the silent switch and thats it. All the msi does is tell the server what to do with it. Wininstall LE is so long winded, need clean machines to build it on, so your constantly recovering a VM machine, which in itself took you a small time to actually make. I can take a piece of software, look at it, oh its an installshield, fine, do the required switches, wrap it up, quick test on a client. Works. Done, next piece of software. Don't even need to batch script and deploy out via startups. Fully managed this way, so can just right click and uninstall if I ever need to in the future. No need to wait for a snapshot to be done, then an aftershot and all that jazz. No need to write scripts that will populate my startup scripts folder. Highly recommend it, its no longer supported, I don't even think it was truely released, but it works and works well. Just need to know the basics. I've taught this application to other techies in like 10 minutes, its so basic which is probably why it never fails. Since I can say i've wrapped well over 400 applications and never seen it fail, that will do me just fine in comparison to any of these "super msi studio 5000" applications lol. I'm writing up a guide on this and will be publishing it out at some point, just finding some example applications to demonstrate it on as no two pieces of software are the same. Windows Installer Wrapper Wizard it was called. I'll update this post if I find a copy of it, also i'll post a link to the guide whenever I get round to doing it.
-
Thats an interesting method paul, we just setup a direct share for the desktops. e.g. For staff Redirect all users to one location --> \\servername\desktops\Staff Then I stick all the software shortcuts into this folder, making sure they are shortcuts to the .exes on the local machine and not a .exe itself, that can cause all sorts of grief on a locked down system. Staff cannot add/delete any files to their desktops and if they want to do that I need to alter the policies to grant users exclusive access to their desktops, that way it saves in their roaming profile and doesn't mess around with my share. Same for the Start menus Redirect all users to one location --> \\servername\startmenu\staff\ (if you are using Windows XP make sure you redirect the start menu to the root (like mine above) and put a "programs" folder within that. So for example I am redirecting to ..\startmenu\staff but inside that folder I have another folder called programs and then put my links into that, makes it nice and neat, doing it like that. Like it should look. For Windows 7 though, thats a totally different ball game haha.
-
We redirect the desktops like you tried, however we lock them down to prevent deletion of the icons. If you are using profiles you can allocate a default desktop and they can have exclusive rights to their own desktop, allowing them to add and remove data. However, to keep things simple (from a backup pespective) we redirect all their documents to a certain location, so by locking down the desktop it forces them to save data in the "my documents", so when we backup we don't need to worry about different locations of data. In my opinion, locking down the desktop and redirecting it is more ideal, as you can then manage which icons appear for certain users. You can script it of course, depends on how many icons you want to add. I'm sure there is a point where the script will be so long, that a redirection might be the faster option. Script method I've seen used 'Set a path to the executable on the computer for your chosen software in a constant Const strSoftwareA = "C:\Program Files\Software\certainfile.filetype" 'Check if that software Exists on the computer using your Constant IF objFSO.FolderExists(strsoftwareA) = true Then 'If a certain file exists, that means it is installed and therefore we make the link 'The lnk file is a shortcut to the executable. MakeIcon "\SoftwareA.lnk", (strSoftwareA & "certainexe.exe"), "", "", (strSoftwareA & "certainexe.exe, 1"), "Software A Name", strSoftwareA End If
-
2008R2 has the primary partition marked as D drive
DEvans replied to edutech4schools's topic in Windows Server 2008 R2
Unfortunately there is no way in changing the primary partition once its built and any "third party" crazy idea on how to do it will most likely result in problems later down the line. I need to agree with ChrisMiles here and it sounds like you left the second partition highlighted, when you concentrate too hard you can miss out the obvious. Clear all the drives, format the lot so you have a single partition, create a new partition of whatever gig (think MS recommend 80GB (81920), unsure if thats changed due to SP1) It will create your 100MB Drive for BitLocker, then ensure you choose and highlight that partition for the installation. Taking a page out of the book of user FN-GM. Do the final partitioning in the Disk Manager when you have the operating system installed. Avoids this whole thing and simplifies the build process since all you need to do is create a single partition of a certain size. There is nothing I have found on google about a bug in 2008R2 that would cause this. Unless you had a crazy RAID setup or something. Of all the servers i've built 2008R2 has never been a problem for me and I've built all sorts of different kinds with all sorts of RAID controllers and HDD Sizes. 2008R2 should be a piece of cake. The key word being "should", as being Microsoft, not everyone will have the same experience. -
Anyone use the built in 2008R2 backup software
DEvans replied to edutech4schools's topic in Windows Server 2008 R2
Works fine with me. Backup to a bunch of NAS Drives on a daily basis. Quick to backup and quick to restore from. To be fair, I don't really need it for much else. If we want to do a ultimate backup we use Macrium Reflect, as that has never let us down. Relying soely on 2008's New Backup Role is like walking in naked to a woman's only spa. Can't predict how that might go, but you have your fingers crossed. -
I had the exact same issue on one of my school's networks. The whole network failed on the logon and only the local admin was able to login. The cause of mine was Internet Explorer 9. Deployed it via group policy using the IEAK to build the MSI. As soon as it installed on the machine, no user was able to log in. Didn't have anything to do with corrupt profiles etc, just an epic fail on the machine itself. Uninstalling IE9 also did not solve the issue, needed to be rebuilt. Sticking to WSUS deployment now as another technician I know found that it works far better than MSI deployment. That was the cause of mine anyway.
- 8 replies
-
- dns
- reverse lookup
-
(and 2 more)
Tagged with:
-
How are you going about deployment of the network? Are you using Roaming or Local Profiles?
-
I am very much for the idea of NAS drives. Hard Disk Drives have a Low mean time between failure, so technically they would be more reliable than tapes, also that tapes are generally more vunerable to enviromental issues. Stick a tape in a damp room and the chance of recovering data is lowered by a massive percentage. NAS drives, I can stick up in all parts of the building(s), with a healthy Gigabit Transfer rate to them every night. Thats sorta where I personally want to go. Elimates human error. Plus the idea of being able to recover data via Random Access is far superior to needing to suffer the slow recovery times of a tape. Lets be honest, when it comes to actually using your backups, 9 times out of 10 its because a teacher has walked into your room moaning they just deleted a file they shouldn't of. The need to do a full system recovery is rare, obviously it happens and we will need to be prepared for that. I like the idea of a combination, maybe a weekly backup to tape, but unfortunatly that still means purchasing a expensive drive, thats only good if we had one already. I just want to do good by my schools and as times are hard financially, I don't want them wasting money on something there is a good chance they will forget to actually do. At some of my schools they located the server too high to put a damn tape in the drive or even worse keeping all the tapes together.. next to the server! It's got to a point now where I've recorded myself on my Iphone saying to them they need to move their tapes to a safe location, so if the system does collapse it's not muggins here you gets the blame.
-
My boss has always been bias when it comes to tape drive backup solutions. We cover many primary/first schools in our local LA and in every school that needs a new server, they end up buying a "built for purpose" Server with a LTO 4 Itanium Tape Drive. We buy our servers through Dell and those tape drives alone are £1300+ without the tapes. So if we quoted a server for £3500, i know that £1300 of that is for a tape drive which I need to rely on someone in the school to change over on a daily basis, as i'm only here once a week, (sometimes once every two weeks) depending on what the school have paid for. Thing is, teachers are difficult to teach and money is so tight these days, its probably best, imo, to get them to spend that £1300 on something else, maybe upgrade their 100Mbit switch to a Gig, or perhaps add more memory, a better processor etc. I'm trying to argue that tape drives in schools might not be the best solution and we should start thinking of alternatives, my favourite and the most popular being hard disk drives. My bosses main argument was that tape drives are many, so there are many backups so if one goes wrong then we have others to choose from, but with the cost of hard drives being so low these days (<£100 for a TB) if we got 5 HDD for £500 thats still a saving of £800. I'm trying to be diplomatic and need a convincing argument to put forward to try and convince my boss that this should be the way to go. Of course however, I am bias towards HDD backup solutions, so I might not be in the wrong, but after a lot of Googling, Its difficult to ignore that all "advantages" of tape drives are now being outnumbered by all the disadvantages and the fact that HDD are also stealing the show and are demonstrating better reliability over Tape drives. What are your opinions? Am I wrong or should HDD be the way forward?
-
Hey guys and girls, The guys and myself are have major issues over the length of time Backup Exec is backing up the Shadow Copy Components. The size of the overall backup is roughly 500GB and is backed up by going over the network to our dedicated backup Server which then saves the data on an external hard drive connected via USB 2.0. Understandably, we expect it to be a little slow but at the moment the length of time it is taking is.. >110 Hours. Yeh.. The drive has been checked of course for any failures and has been fine. Generally all our other backups have been OK with no failures and Symantec Backup Exec is generally working in the way it should. Our Specs for the backup server: Microsoft Server 2008 R2 Pentium D 3.00Ghz 2.99hz 3GB RAM External Seagate 1TB Hard Drive with USB 2.0 connection Gigabit Infrastructure throughout Symantec Backup Exec 12.5 Obviously this is just stupid, We expect the time to be long but never this long, we want it done in at most a day! Never seen a backup to extend this long before. Our current theories are that Shadow Copy Components might have corrupt data within it or the fact that it technically is just hundreds (probably thousands) of individual files. It's not like backing up a database, its individual ones. If anyone can help or give advice it would be much appreciated. We will be updating Symantec soonish, giving us a fresh start on the backup procedure, but there is no guarantee that this would solve the issue. Thanks!
- 6 replies
-
- backup exec
- external hdd
-
(and 3 more)
Tagged with:
-
Hey guys, I work at a variety of primary schools which of course have a pupil shared area where staff can put stuff so the pupils can read/save to their hdd etc. Now the problem I'm having, which I am sure is common, is that kids, they love to click and drag don't they! They just love it! As a result obviously We find that folders go missing and eventually are found in other folders. The question I am asking is what, in your opinions, would you say the best set of NTFS permissions would be for a Pupil shared are. They will need the ability to obviously read and write to the area, the ability to rename their work if they mis-spelt something. But I want to restrict them being able to move and play with the folder structure I want no more "accidental" click and drags. I know that by restricting them to delete a file would result in them being unable to move a file (as apparently in Microsoft's eyes thats the same thing), but what if it's one of their own files. What if they honestly saved it to the wrong folder and need to move it to an alternative. What are your opinions. What combinations do you use? I'm interested. If I can get a perfect combination I'm more than likely going to turn that to a standard throughout my schools. Obviously there is no "perfect method", schools require different things, but ideas would be interesting. Thanks!
-
You know this might of been the site I was after. We'll give it a go. Thanks man. All these links are helpful, please do feel if you can assist even more leave a post. Thanks!
- 3 replies
-
- exchange
- forwarding
-
(and 3 more)
Tagged with:
-
Hey peeps, I am in the process of setting up OWA for the college, something I have never done before. I managed to setup OWA on the Exchange Server Localhost now I just need to find out how I can access it via the internet. After a lot of googling and talking to some companies that have done this before a quick an easy method is to apparently use a spare External IP address (which I have obtained from my ISP) and NAT that publc IP to my Private IP address. I have an internal and external ISA servers and a Exchange Server. I just don't know where to start really. Do I set up that NAT forward on the ISA server? Exchange is 2007 and Threat Management Gateway 2010 on the ISA. I also have a SSL certificate from my ISP which is setup, so obviously that needs to be applied to the whole login bit, but for now, I just need a push in the right direction. I have also looked at DMZs etc, but quick and easy for now, experimentation later lol Any help would be much appreciated, thanks guys!! /Dan
- 3 replies
-
- exchange
- forwarding
-
(and 3 more)
Tagged with:
-
Or alternatively you could simply perform an IF Statement to see if the printer's name begins with "\\" . Not sure how complex it is to check for USB or LPR, but I introduced a code in my login script to just check the name. Similar to the below. 'Remove all Network printers but not local printers Set Printers = WshNetwork.EnumPrinterConnections If ObjFSO.FileExists(strDirectory & strFile) = false Then For i = 0 to Printers.Count - 1 Step 2 If Left(ucase(Printers.Item(i+1)),2) = "\\" Then WSHNetwork.RemovePrinterConnection Printers.Item(i+1) End IF Next Obviously you would need to change to match your defined objects. Thats what I use anyway. In some cases a login script might not remove local printers, it depends on the script and what commands you have used, I think anyway.
-
Downfall of course of removing all printers is that you will lose any local printers you might have installed on local machines as well as delaying your login. If you're running a large network with many networked printers you might find it takes a while to remap them all. In your instance, its probably best to remove that troublesome printer and leave the other printers be. Saves you time and solves the issue. Unless of course you only have like < 8 printers or something, then it shouldn't make too much of a big deal, but watch your local printers. (if any)
