-
Posts
384 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by azrael78
-
Assuming you are using an AD 2003 Domain, you can simply create a batch file or VBS that sets the resolution to what you want and then resets it - you use the logon/logoff scripts area of the Group Policy. User Settings\Windows Settings\Scripts (Logon/Logoff) HTH Az
-
If you remember, lemme know Az
-
Well I've tried Ultrasound but the silly agent thing won't install - when I try to install it manually it just says it can't install and rolls itself out again. So I've not had much luck with that - but I've certainly thought about it and tried it.
-
Righty - just spoke to my 'Supervisor' - he's agreed with me that the issue MUST be dealt with sooner but has told me to not start anything today as I can't garauntee I can have it all up and working for Monday AM. Instead I've been told to get the infrastructure (for using DFSR) in place as much as I can without changing stuff. So, I'm leaving NTFRS on today - turning it off before I leave later, re-rolling the NETLOGON share back out and hoping that on Monday the things just work okay. What a NIGHTMARE! Az
-
They are all connected up to some really good kit - all on Gigabit Ethernet and bandwidth doing other tasks (like file copies, logging in etc) are all fine, no problems or complaints. Az
-
I've done this wonderful thing before - not because of NTFRS but because of SYSVOL corruption on a knackered RAID array which replicated itself... it was great fun - thank god for off-disk backups. (I used to copy the whole SYSVOL folder to my PC before we got our backups sorted out) But yeah it is extreme - I don't think the issue is consistency, I think it's more because NTFRS is choking to death under the sheer bulk and size of the data we are asking it to handle. DFSR (In Server 2003 R2 and Server 2008) should handle this much better (as we currently use DFSR to replicate profiles between servers and they aren't small little things either). Az
-
Yeah, that's why I was thinking drop NTFRS and use DFSR. Server 2008 uses DFSR for everything even SYSVOL, so I can't see why I can't use the same idea. I understand what you are saying here - but it's hard to differentiate between scripts and the larger chunks of data without seriously rewriting alot of the scripts and as I only have 1 day to do this in, I figure move the whole lot for speed - make changes later when it's all working. Oddly enough we do have a startup and shutdown script - but they seem quite happy with the default permissions (as they run as NT AUTHORITY\SYSTEM on the workstations) and seem content with the default NETLOGON permissions - however I will certainly keep your suggestion in mind. A whole heap of BIG MSIs - damned QCA Testing stuff and a whole heap of them stored here - simply because we figured NTFRS could handle it without choking and dying it has been. How wrong we were... and how wrong I was for not telling my juniors to NOT fill the NETLOGON share full of MSIs and other fun items Az
-
Morning Everyone! I just wanted to run this past as many of you as possible (and I will of course run this past my 'Supervisor' who's on holiday.). Here we have 2 Forests. 1x Forest (Curriculum) - 4x Server 2003 DCs. 1x Forest (Admin) - 4x Server 2003 DCs. Both Forests have member servers also within them. The problem I've hit in the past week (or so) has been NTFRS in particularly with the NETLOGON share (not SYSVOL). We have a large NETLOGON share (1.28GB) which I suspect may be the cause of my woes but I'm not certain. (Only noticed this when I changed the share from 700MB to 1.28GB) NTFRS seems to start up okay - no problems here, yet when it comes to replicating the NETLOGON share - some of the DCs (in either domain) end up with xxx_NTFRS_xxxx folders. The original folders are no longer present, just these NTFRS folders. I understand this is to do with NTFRS replication - but I cannot find a cause or reason as to why these folders keep appearing. So I've done the following: 1) Stopped NTFRS, Cleared the NETLOGON share - Rolled the contents back out to each server WITHOUT NTFRS running. 2) Stopped NTFRS, Cleared the NETLOGON share - Rolled out the contents back to 1 server in each domain, turned NTFRS back on. 3) Stopped NTFRS, Cleared the NETLOGON share - Rolled out the contents out to each server, turned NTFRS back on. With the exception of #1 - I keep getting these folders. I get no errors or complaints via NETDIAG, DCDIAG or the Event Viewer. I have cleared down the NTFRS staging area caches and restarted the service, also to no avail. The files in each NETLOGON share on each DC are identical. So what I'm planning to do is have just 1 little script in the NETLOGON share that points the clients to a DFSR share instead - and we allow DFSR to handle replication of this large chunk of data instead - so we keep NTFRS turned on but use DFSR for the replication of this huge chunk of data. I know I will have to make substantial changes to Group Policy deployments (software) and anything that points to the %LOGONSERVER%\NETLOGON area but I'm prepared for that. What I'm asking is the following: 1) Have any of you got similarly-sized NETLOGON shares on your AD Network? 2) Do you have issues with NTFRS on this share? 3) Would you forsee any obvious problems with how I plan to change the whole NETLOGON deal? I know in theory I can't forsee any issues or problems with what I'm proposing here - but for such a large change, I like to run it past as many people first incase they have tried it or know about other issues I may hit Any feedback would be appreciated as I either have to start and finish this today or pencil it in for Summer... and I'd rather get it done ASAP than leave NTFRS on - having to re-roll out the NETLOGON share contents daily... Thanks. Az
-
In short: 1) You can't 'hack' rights to a program that you don't have access to. 2) It's clear that you shouldn't be even doing this - I understand that students can get curious and such - but the program is locked for a reason. If you really want it to work - venture toward a career in IT, take the exams, get a job and then you will be on the other side of the fence, you will be wanting to keep people out of your system, not try to find ways in. Az
-
We had a similar problem on a 2600... one disk died which in turn caused the controller to go crazy and fail another disk and knock the array offline. Suffice it to say - it was a fun time trying to get the array back - call Dell and tell them that their disk was dead. Credit though once they agreed it was dead - we got 2 new ones sent out which arrived the following morning. Az
-
It's possible to redirect favourites - it's an option in Vista/2008 GPOs but it's also possible to do this in XP/2003. If you plan to redirect favourites - suggest placing them inside the home drive itself - so they get backed up. Az
-
Why not set the Loopback section to 'Merge' rather than replace and change the link order so that your IE Homepage policy is last - that would allow your IE homepage stuff to be set AND your main Student OU policies to be set as you like. We have lots of policies that use Loopback here (because some suites want this and others want that...) so I've had alot of hair-raising experiences with it. Hope this helps. Az
-
You can happily use 2K8 as your admin server until the RSAT comes out for Vista. That's what I've been doing in our trial lab - Server 2008 is nice, just wish I had more time to play and less time to actually work.
-
HOW TO: Quick guide how to block students running EXE`s from Zipped files
azrael78 replied to burgemaster's topic in Windows
This works well, there are a few points you might want to be aware of - particularly if you use any kind of compiled scripts. By default they extract to the users %TEMP% directory which resides inside the Local Settings folder. Typically these include the interpreters (WKIX32.exe and KIX32.exe if you use KIX). By disallowing the EXE files here, you then stop these scripts from running. So it may be worth including an allow rule for KIX32.exe and WKIX32.exe or whichever interpreter for the scripting language you are using. -
They are indeed available. Windows XP: http://www.microsoft.com/downloads/details.aspx?FamilyID=e60b5c8f-d7dc-4b27-a261-247ce3f6c4f8&DisplayLang=en Server 2003: http://www.microsoft.com/downloads/details.aspx?FamilyID=bfe775f9-5c34-44d0-8a94-44e47db35add&DisplayLang=en Vista: http://www.microsoft.com/downloads/details.aspx?FamilyID=ab60dc87-884c-46d5-82cd-f3c299dac7cc&DisplayLang=en
-
So let me get this straight, for the preferences stuff, we either have to go 2008 Server and use the Windows XP/2003 CSE's OR we have to find a copy of PolicyMaker that we can still register/buy. Was hoping to use this in our 2003 environment without having to go to 2008 just yet but the features it offers are rather nice
-
A small word of caution here - we tried to redirect Application Data before but for staff (who had their own profiles) and we have never seen so many issues. Soon as we cleared the redirection, all was well again. However if you redirect AppData to a common folder for mandatory profiles, they can't save things in it as it should (if it's a super-mandatory at least) stop them writing anything back to it. Keeps logins fast - at least for us it does. We also have different software in different suites but have never seen the problem you describe.
-
Same here. Plus we give them a local admin account (so we don't make their domain account a local admin) - so they can just login using their normal login information to work - and local admin account to install software/etc.
-
We have had R2 running here for at least the last 6 months. No errors or issues that we found with R2 specifically. Only thing to note is if you use DFS Replication - the staging area is created at the root of the share. So if you share out \\server1\profiles - and want to DFS replicate this - it will place a folder called 'DFSRPrivate' directly in the \\server1\profiles share. This might not sound like an issue, but if you also use file screens or quotas, you may end up quota'ing the DFS staging area which wouldn't be good for DFS Replication. (I know about this, because I did it... oops!) I'm currently debating installing 2003 SP2 or not, out of time during this half-term break but at Easter we may have time. Anyone hit any issues with SP2? I've heard that on certain hardware it has an issue or 2, but I've not been able to verify this. Az
-
I'm playing with Server 2008, and I see alot of new policies (obviously ones that say 'requires Vista' won't work with XP) - my question is that several of the other features (the preferences folder in GPMC springs to mind) - would these work on XP SP2 or are they Vista only? If they are Vista only, then the reasoning for us to go Server 2008 just dropped considerably, but if not - I see an upgrade coming. Cheers, Az
-
Eset's NOD32 here at home and CA E-Trust AV as it's LEA-supplied. I personally prefer NOD over CA by a long way, but they won't change to NOD as CA is free. Ah well, at least at home I'm better protected Az
-
We are on the 50/50 route - they can do whatever they want with their laptops (as they have local admin) but they must have our site Anti Virus installed and active, they also must understand that if their wireless doesn't work at home but it works here at school - then we will help them but the priority is that the laptops work in school. If they want it to work at home more than school, then we disconnect it from the domain. The problem is the laptops (here at least) are considered as 'personal resources' - therefore we have to give them the ability to do anything with the laptops they may want - however if they break it - it might take a while to fix it back up
-
Just to expand on this a little - if you want Offline Files gone (or to never return) - ensure that caching is disabled on shares on the server. Set GPOs so that offline files are disabled at the machine and user level (this may or may not be important, but we have multiple forests so for us we set it in both places just to make damned sure it doesn't come back). As for us... we use a super mandatory profile for the kids, start menu redirection (but not desktop), my documents redirection and a very thorough logon script. We also have various other scripts and tools that handle problems (such as app specific settings in certain rooms) and one that may of interest - we have Office XP and 2003 - yet we use 1 icon for both - we have a script handle office versions for us. Alot of our 'value-added' services (such as the background active-x wallpaper) have mostly been written in-house by yours truely (because as we know, schools hate spending money!). If anyone has any questions or such about things - feel free to PM me, I check the forums almost daily Az
- 42 replies
-
- downsides
- mandatory profile
-
(and 1 more)
Tagged with:
-
While I've read your posts - what is it exactly you are trying to do? There is an 'Administrators' group on the DCs and member servers and there is 'Administrators' on the local PCs. While you can add users directly to the 'Administrators' group, it's usually best to create a group to house these users, and then add that group to the 'Administrators' group - the Domain Admins group is a member of the 'Administrators' group on a DC, so it may be worth adding people to that group instead of 'Administrators'. It's worth noting that giving someone Local Admin (on a workstation/member server) and giving someone Local Admin (on a DC) are very different in terms of what they can do. Local PC/Member Server - Same deal, they have full administrative access to the PC or Server, but their access (unless you grant them more access elsewhere) - remains at that server. DC - Giving anyone Admin access here grants them full admin access to this DC and any other DCs in your forest - this means they can do literally 'anything' with your domain - from adding users/computer accounts to using ADSIEDIT and playing with the schema. What I'm not sure is if 'Administrators' on a DC gives you full admin rights across child domains as well or whether it only gives it to you for a single domain. Hopefully some of this was helpful. Az
-
You need a trust inplace so that the curriculum domain trusts the admin domain. You have the option of a 1-way or 2-way trust, it won't harm anything if you use a 2-way trust - HOWEVER - you really need to double-check group policies and share/NTFS permissions before you do this. Anything with 'Authenticated Users' or 'Everyone' will suddenly apply to both your curriculum and admin domains. A 1-way trust is just as good as 2-way (and can be converted later if you wanted) - it's just easier to remember how to create a 2-way than a 1-way. In AD Domains and Trusts - you need to create a new outgoing trust from Curriculum to Admin so that the Curriculum domain TRUSTS the Admin domain. (This might be round the wrong way, but it won't harm anything if it is, you can easily delete the trust and recreate) Once your trust is established - give it a minute and try to add the member of staff again. However, to be honest - it may be a better idea to create a group, add the group to the share/folder and add the member of staff to the group (so any other staff who may need the same access, can be given it easily without having to dive into the file system or shares). Hope this helps Az Edit: And I've just noticed the last post date/time... it's one of those days so far...
