-
Posts
116 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by swpmre
-
Hi, I've just configured and set up a brand new Windows 2008 Server. It's going to be our first AD server. I've created a couple of test users, and I can logon to a laptop using their username / password, in the newly created domain. I've created a organisation unit (called student) and moved the users into that OU. I've then created a GPO, linked it to that OU and setup some test settings (prevent access to Control Panel / hide recycle bin etc etc). However, when I logon on to the laptop, using a username that is definitely inside that OU, the Group Policy is never applied. I've tried rebooting everything, forcing Group Policy Updates, creating a new GPO from scratch, creating a new user, but nothing works. Since I am effecitvely following a test lesson from the Fundamentals of Win Server 2008 course that I did a few weeks ago, I cannot see what I am doing wrong. Perhaps there is something else that is not setup correctly that I've forgotten, because everything else seems fine. Any ideas?
- 9 replies
-
- active directory
- gpo
-
(and 1 more)
Tagged with:
-
Backup Domain Controllers in an era of austerity
swpmre replied to swpmre's topic in Wireless Networks
"I've never bothered with a backup DC and guess what? I've never encountered a problem, even when the PDC has died." Problem is that all our sites have connections that have been known to die. So the site were the PDC is likely to be sited has fallen off the network a couple of times in the last year for a day or so. It's because we use cachepilots and they're not the most reliable pieces of kit tbh. So having a backup, somewhere else on the network is a sensible choice for us. -
Backup Domain Controllers in an era of austerity
swpmre replied to swpmre's topic in Wireless Networks
Thanks matt. Unfortunately we're not buying new hardware at all. But we've got a stock of decent old PCs. This will have to do until the recession ends. Or the economy collapses further, in which case we'll all be living by bartering twigs and it won't matter anymore. -
Hi, I've been given the task of rolling out Active Directory and Server 2008 across our multiple education sites. These are small Adult Education centres. At the moment, these use a minimum of network resources. We have a Win 2008 server at on site which hosts the shared folders and does the backups. At the same site, I'll be introducing a AD server. However this will create a single point of failure. Loosing connection to this site means that all the remote sites will loose their ability to contact the Domain Controller. So I want to put in at least one, maybe two secondary DCs at the various sites. However we don't have money for any extra servers...... So. The Million Dollar Question is, is there any reason why I couldn't install Win SErver 2008 on an ordinary PC and use that as a backup DC? The minimum spec is certainly fine. But anyother reason why not? I'd value your thoughts. Thanks for your help!
-
Hi.... can you clarify.... when you say HKLU, do you mean HKLM (because I don't have an HKLU in regedit)? and I presume you do this operation logged on as a local administrator?
-
Sadly, one of the registry changes is to prevent access to the registry on that user...... :-(
-
Hi all, I have a logon for a local Windows XP user. This has had a number of registry changes made to restrict or prevent certain actions (prevent access to command prompt, prohibit access to control panel etc). I want to create a second local user, and copy the registry settings from the existing one to the other. Or, to put it another way, I would like to create a second user, by coping the first. I've tried to do it by copying the old user profile to a new user, in Control Panel>System>Advanced>User Profiles but this doesn't seem to copy all the registry settings. Is there another way to do this? By the way, this is a standalone Windows XP (SP3) machine, with no network / internet connections. Thanks in advance for any help,
-
I tried. Sadly, since we are not subsiduary of the education department, and don't hold the license agreement ourselves, we couldn't get anyone to talk to us. While awaiting a reply from the bureacracy above, I thought I'd ask those on this forum, who might have some insight.
-
Hi, We have Office 2010 etc licensed for use by staff and students on site. We got an Education discount for this. I have been asked to look at providing public access terminals (see other thread here). I've been told however, that these terminals aren't going to be restricted to existing registered students, but are accessible for the general public. Is there any impact on our licensing here? Since anyone can use the terminals, technically are they no longer education only use, and should we change our license agreement? Anyone else spot any other issues that might arise, licensing wise or anything else? Thanks Martin
-
I've been asked to look into setting up some public access computers at one of our sites. This is an Adult Education centre, and the idea is to allow the public to come and use computers and printers for things like writing CVs / looking for jobs / learning IT skills. In order to manage this, we'd like some "Internet Cafe" style software - to limit access by time etc. Ideally this would be cheap or free. It would also have to allow us to manage printer use, and if possible filter the internet. A quick google produces a myriad of examples of such software, but I thought there might be some one here who has some experience. Anyone got an experience of this? Anyone think of any issues / problems that I might need to think about? Are the software licensing issues for instance?
-
Hi. We'd like to purchase a UPS for our servers. We have two of these, both HP Proliant ML-310 (Spec sheets here) According to that page, I think they are rated at 410W each. We'd like a UPS that would allow us enough time for some sort of automated shut-down (so we'd also need the relevant software). Anyone recommend anything? Cheers Martin
-
Hi. Found the problem which I'll post here for the benefit of anyone else who might search the forums for a similar problem. If you're using the L3 search, you are limited to the number of IP addresses you can list. Because when we set up our first site, we similar put in the whole address range, adding extra IP addresses wasn't possible once we'd reach the maximum (I assume 254). The test site I used yesterday worked, because it was within the IP range we'd already entered. Removing one of the IP addresses allows us to add a new IP. If anyone else is using a similar D-link setup in school/college etc and wants to pool knowledge our share experiences in the future, please feel free to PM me. Thanks for your help keith, Cheers Martin
-
Hi Keith, I am not sure that it is a problem with the firmware - all our APs were bought at the same time. Though it is possible that earlier installed ones have downloaded a later version. I will check later. Our setup is particularly complicated, requiring as it does, the sharing of a network infrastructe with the council. But our Adult Education centres are at a various remote sites. They each have a Cachepilot which acts as a DHCP server, we also have a centralised DNS server and file server. Each site has a unique IP address range (172.15.x.1 - 254). I have asked the third party that maintains the infrastructure and the cachepilots to look into their setup to see if there is a difference between the setup at the problem site and the others. Apparently we also have manual routes setup for traffic between the cachepilots. As an extra test, I've tried manually adding the IP address of the new AP (and I've tried a couple of spares too) at the new site, in the L3 discovery section of the D-link maintenance interface. But this rejects the IP address, saying it cannot add it. No idea what this means, and can't find an explanation anywhere online! I am going to another site today to setup an AP there. If this works, I can only assume a network problem at this particular site. If it doesn't, then I must be doing stuff wrong with the D-link setup. Many thanks for any further thoughts you might have, Cheers Martin
-
Anyone use D-link DWS-3024 wireless management servers? Paired with DWL-3500AP access points? We have a multiple site arrangement here. Each site with a specific IP address range. But all on the same subnet. The Wireless Management system should, assuming that the AP's have been configured correctly simply find them and add them to be managed. At one of our sites, the AP's just aren't found. I've tried and tried again, double-triple checking the settings. I know that the rest of it is working, because I've gone to another site this afternoon and added an extra test AP just to prove it works. Can't find anything unusual about this one site that might prevent me doing this work. Anyone got any experience of D-link Wireless management in this sort of context? Would love to have a chat or some advice. Thanks Martin
-
Apologies, but I don't understand what you mean by "copy the profiles on the other machines". We don't have this working for any user / logon yet, so I can't copy those profiles :-(
-
Hi, no we're not using network logons. This is just a local profile.
-
Wait for the letter. Even if they have offered it to you, it's unlikely they'll actually be able to "give" you the job until they had all sorts of other information - references, CRB forms etc. SOme of these can take a while (took me 3 months to get the various authorities to fill in all the forms for my last job). Without these, they can't start paying you anyway. Hang in there, despite how much you want to go. In these times of economic uncertainty, you don't want to risk something going wrong down the line and being left without a job to go back to.
-
Hi all, Perhaps I am not using the correct words when I google this, but I can't find an answer, so I'll try here! I'm trying to lock down a particular user on some Windows XP machines. We don't use Active Directory, so I can't do a Group Policy. I would like (for instance) to restrict access to various programmes, control panel etc, but only on one user account. I'd like all the others to remain the same. I've tried using gpedit.msc, but Group Policy Editor changes the settings for all users on the PC. Any other ideas? Martin
-
Hi all, We're just rolling out a Wireless network to be used across our sites by students logging on only from our own laptops, stored in laptop trolleys. We'd like to create a "WiFi Use Policy" that they have to agree to. This needs to be a short piece of text that they "Ok" or "Cancel" before they can do anything wirelessly. I've googled for this, but only come up with long usage policies that are not suitable for a simple acknowledgement at logon. Any one got some text that we can adapt? Anyone do anything similar? Thanks for your help Martin
-
Turns out it's a client side setting. Needs to set to Wan not Lan. Undocumented feature.
-
Hi all, We're trying to use the Deepfreeze Console to update and manage our Deepfreeze installations. We've had the deepfreeze workstation installed on a variety of sites across the city. Unfortunately, when we install the Console we cannot see any of the workstations, either those locally or those at remote sites. I've doubled checked that the appropriate port on local firewalls is open (in fact I've tested with it turned off completely) and it doesn't make a difference. There doesn't seem to be much help out there and the manuals don't tell us anything. Anyone out there got any experience with this product? We've got version 6.5 of the Enterprise install. Thanks Martin
-
We've got a weird network setup. Our Adult Ed service piggy backs onto the city council's network. We have multiple sites, with a handful of PCs at each place. Each site has a cache pilot as the interface between the PCs and the outside world. Currently we have our PCs connect to the internet over night and get updates. I've just learnt that the outside party responsible for our network admin, has a WSUS server which we could connect to. However I've been told that the WSUS server simply downloads all updates, there is no checking or testing process. My question is, is there any benefit to us using their WSUS. I'm not convinced that we'll be reducing network traffic, because the updates will still effectively have to come from "outside" each site. We're not getting any benefit of testing, because they don't do any. My only potential saving is that if the updates website fails, we can still get our updates from their server. But that's more likely to happen the other way around. Thoughts? Thanks Martin
