Jump to content

Oaktech

Members
  • Posts

    9,067
  • Joined

  • Last visited

Everything posted by Oaktech

  1. it's the very top of it, the tank is mainly in the V of the frame, basically right under where you sit. Because it's a single, a tank on top of a quite long stroke engine screws with the centre of gravity and the bike becomes top heavy and not nimble in town
  2. We use GSuite. Governors have their own isolated domain. I provide support for all new governors to install filtering certificates and get them up and running on our guest wireless. We also provide 4-6 school devices for each meeting logged in with a governor account which literally has just chrome accessible and that's about it via some pretty draconian GPOs.
  3. They're sneaky those Russians...
  4. I blame the Russians.
  5. Or you could use a GPO to create a scheduled task on all workstations - you can set scheduled tasks to be dependent on a lot of different triggers - I quite like on idle so no-one gets impacted while the task runs. Just use delprof2.exe as the program to run from whatever location - we have it on a readonly hidden share, and the parameters as above to specify behaviour. You can set the task to run as whatever user you like - system seems quite popular.
  6. Quite. No point having a bunch of servers running beautifully if no-one can connect to them or the connection is unreliable.
  7. I'm not seeing anything on that page that pumps out POE. It looks more like they will operate over POE from an upstream device.
  8. That rather depends on the wired network not being a massive cluster:censored: and you actually knowing what ports go where. My experience in schools is that this is rarely the case. I have Vlans set up at my main school, but my second school we have no idea where half the ports go. Our summer holiday project is to accurately map the ports and remove unused patches. I would always advocate VLAN with QoS for voice.
  9. You can go a lot further wrong that a mahoosive drive array, windows baremetal backups and a robocopy script to ensure you keep as many days as you have space for. But yeah, Veeam...
  10. Holy NecroThread... I'd just like to say that not all the drivers are in that folder, sometimes you need others. what you are looking for is the prolific ser2pl driver which can be found via a google search or on my onedrive... https://1drv.ms/f/s!AnkeacnDNvVsggVtlbtu8yWiIu2k
  11. dns delivery... it's a radio button on your connector.
  12. https://stackoverflow.com/questions/12855039/messages-using-command-prompt-in-window-7
  13. We're getting the consortium basic paper - seems OK as long as it is kept warm, jams like a if it gets damp. Best paper I've had recently has been Envirocopy but it's about 20p a ream more expensive than the consortium one. We've also recently had Rey Daily paper and it's awful - It states 80gsm, but there is no way it is. It jams constantly, and creases in the paper path. It's also the only paper I've ever seen get bleed through from a laser printer! Avoid!
  14. Oaktech

    Coffee

    Hot drinks were invented because boiling the water kills the nasties... Duh!
  15. I found one of those too... For about 12 hours, until Dave came back to me with a better deal.
  16. I've got a set (35) HP DM1 which have some $deity awful AMD low power chip in them. The SATA controllers are so poor that the difference in startup between a brand new 6Gbps SSD and a generic 5400 spinner is no more than a couple of seconds!
  17. It comes out 2 days before my wife's birthday... That's that sorted then! She was always way more of a gamer than me!
  18. Most software on client machines has the ability to run as admin, so most of the time I just do that. It's worth remembering that just because I don't have an admin account it doesn't mean that I get the same GUI as staff, I see everything, whereas they don't see anything of the control panel, windows updates, standard start menu etc. Rightly or wrongly, I very rarely use the machine's local admin accounts - they tend to be for getting me out of the poop. What usually happens, is the I will sign into a client machine using my ordinary domain account and then RDP the server I need to administer using my DA credentials. This is for 2 reasons - one because auditing then attributes my actions to my domain admin account, secondly I have a GPO applied to all servers (except RDP) that only Domain Admin credentials can be used to sign into them. Likewise for software updates I'll sign into the client machine using my non admin domain credentials, start the update off as my ordinary account and then enter some sort of admin credentials at the UAC prompt. Most of the time these are DA credentials as local admin credentials won't have the rights to download software through the filter.
  19. I see what you're saying, but I really do think 90 days is an acceptable length of time for a password to last. They are obliged to create a complex password every time and it can't be one of the last 4 - so they can't reuse a password within a year.
  20. It sucks, but once you've done it once you have it and it'll work for ages!
  21. I have a user account. I have a domain admin admin account that is mine by name too. We also have a renamed domain admin account that is the one that gets given to trusted contractors - we used to have an external support company, now it's the one that gets given to our ISP if he needs to do something like modify our directory sync for filtering. It gets disabled when it's not actively being used. No user accounts have any admin permissions local or otherwise. There is a local admin account that gets created on all client machines by WSUS. It's the same for all machines. All servers have a local admin account - it's got the same name for each server but the password is different. We also have single purpose accounts that get created with only the rights they need to function - things like ldap bind for moodle, filtering and copiers. These are named for function and all have randomly generated passwords that don't expire but are stored in an on/offline password manager.
  22. You need a bootable USB stick my friend. I've written some instructions somewhere - I'll look them out. Startech USB 3 PXE network adapter. Or a non pxe network adapter and a USB stick. This was done for the Linx pro tablets and the Acer w510, but I've followed an almost identical procedure for w10. Things you need: a working WDS server the AIK for your version of windows 1x usb stick for initial build media 1x usb hub 1x usb keyboard 1x usb mouse 1x USB NIC card with drivers (I've got a startech one) 2x 4gb or bigger usb sticks What I did was to place the windows media on a usb drive, use the usb host cable to connect a usb hub, connect the boot usb and a keyboard and mouse to the hub and boot the tablet off the stick. Install whatever flavour of windows you want - we used 8.1 enterprise and all of your software. Sysprep the machine as you would normally Use the WDS server to create a capture image using the process in this article: http://social.technet.microsoft.com/...ge-in-wds.aspx when the image is created, mount it in the WDS console and inject the drivers for your usb nic, dismount it and copy it to one of the 2gb or bigger USB sticks. This is your capture stick. It is architecture dependent. Use the capture stick to run through the process of sysprepping the machine onto your WDS server Follow the instructions here to use the AIK to create a discover image https://technet.microsoft.com/en-us/...(v=ws.10).aspx mount the discover image in WDS and inject the USB drivers again. Use this to boot and build the machine from your WDS server using the image you created before. Simples! Hopefully this will help you. It's PITA, but it is doable.
  23. We still use password expiration - it happens at 90 days for staff otherwise they'd all still have the one they started with.
  24. you can't target an OU - I spent an hour troubleshooting a policy to discover this! You can however target a security group and whilst dipping into ADSI edit is always a nervy thing to do it's actually apiece of cake. I set the most complex requirements in the default domain policy and then create a fine grain policy via adsi edit for the lower requirements. There is a hierachy in which password policies apply - msDS-PasswordSettings object, default domain policy, any other GPO. I'm using a domain with 2008r2 functional level. I go in via adsi edit, then connect to a DC, default naming context, system, password settings container, new, object and then follow through the wizard - defaults are usually fine except for the things you want to change which is likely lockout duration, lockout threshhold, minimum and maximum password ages, password length, complexity requirements and history length.
  25. Already there...
×
×
  • Create New...