-
Posts
384 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by azrael78
-
Looks like a pretty serious bit of kit there If you are up for a few suggestions or ideas, I have a few for you .INI Files - have these in a central location (or user profiles for personalised toolbars) - use the INI files to determine icons, paths to programs, names of shortcuts etc. Something like: [AppName] (as shown in toolbar) Path="Path\to\executable" Parms="Any parameters the program may need" Icon="icon file to use for the program" (not sure how you could make it pick icons out of an .EXE/.DLL tho. Visible=1/0 (Should we show this icon or not?) Using those will allow each admin/school to customise your admin-bar to their own needs without trying to reinvent the wheel. I'd have a crack at this myself but I'm not an AutoIT scripter (I could learn I guess) - I spend most of my time in VBS/KiX so making something there would be a nice project for me to do but a) My manager would never authorise my time like that and b) Why reinvent the wheel? Az
-
I'd almost wonder why all this stuff was so expensive if I didn't know that it was essential to have good backup/restore options on high-use services. After beating management down with a 'if we use poor software, then our disaster recovery will be a joke or unusable' line - he's going to get quotes for NetBackup and Acronis with the relevant options because I think he hates the thought of critical servers being down (for a considerable amount of time) rather than spending the small chunk now to get the problem addressed and solved while we have a stable array of servers. Not quite sure what he will go for yet - or whether I will even get a choice in the matter. I've used Acronis Trueimage Workstation with Universal Restore and I find it very easy to use, scheduling works well and the restore options (boot from CD) and restore direct onto hard disks - invaluable - so that's my first choice, I've got nothing against NetBackup - but I didn't realise Symantec still had BackupExec... might be worth checking prices on that as I used Veritas BE before and found that good.
-
We did have Veritas BackupExec but management didn't like the price-tag associated with renewals and the fact we had to buy more licenses for servers... Acronis Personal? Never heard of that one, is that suitable for a Server OS backup and handles SQL and bare metal restore? Az
-
Looking at these posts, it looks like Symantec NetBackup is a front-runner in schools. We currently use Tapeware on old Tape Drives - I've been told to drag our disaster recovery scheme and backup scheme into the 21st century. So I've put a server up with removable Hard Disks and to do the backup this way (as it's cheaper and faster) - however, backing up the OS's is a pain. So, what I'm looking for is a backup solution that allows backup of SQL, allows disaster recovery (incase a server blows up, we can throw in a CD and have it restore from network) and allows easy backup/restore with some reasonable logging/reporting. Does NetBackup do this with a few extra agents? I've looked at Acronis Enterprise Server and that does it all but it comes with a very heavy pricetag that management just won't stretch to. Any recommendations? Az
-
If the XP Firewall was on, you would still get Group Policy through it, we have the XP Firewall disabled via GPO here and we have new PCs, we boot 'em up - log 'em in and viola - no firewall. Things to try: 1) WINS - Clear everything out of your WINS Database - NETBIOS will eventually repopulate this itself. 2) DNS - Can't be stressed enough, fire up DNS and check through the _msdcs.domain container and everything therein. If you didn't manage to remove the old server via DCPROMO, it may still have some footprints in DNS. 3) RSoP - See if an RSoP on an affected machine gives you anything back. 4) Event Viewer - Check this on Server and Client (try to use the same client for all testing, so you have a reference point). I'm guessing when you used NTDSUtil - did you clear out metadata, seize any FSMO roles and such? We had a similar issue when a 'middle' PC was used to upgrade one of our DCs from NT 4 to 2003 - what fun that day was. If only county had known about ADMT. Oh... try running 'netdiag /v' on a DC and 'dcdiag /v' - these are always good things to check. Let us know how it goes. Az
-
We have had this too - entirely with Laptops and Offline Files though. Best bet we found was to remove Offline files configuration (once ensuring that the laptop was infact on the network) - backup the offline files cache (just incase) and completely reconfigure Offline files. It seems to happen when a laptop goes offline, despite the network still being present - so it then still points you at 'your documents' but it points you at the offline version, rather than the online version. Personally, I HATE offline files and I'd love to stop it being used but some SMT members had it setup for them by county and they refuse to give it up.
-
Developmental server? Use it to play with when you plan to make big system or network changes, so you can get a feel of how to do it in a safe environment? I'd love that ability here, but - to slightly change a Black Adder III quote: Money is like socks, plenty of it about but we never seem to get any.
-
Without breaking into the thread too much - here, no-one has access to all student folders except IT Support staff. Staff USED to have R/W access, but a few teacher accounts got compromised due to carelessness - students' work got wiped out/overwritten so the decision was made to give then just R/O. Even with R/O - students still got into a teachers' account - copied off other students' work, badged it as their own etc... In the end we took the decision (in conjunction with SMT) that no-one outside of IT Support Staff should have access to ANY student folders except the student themselves. This gives them ultimate responsibility for their home folder - so if there is stuff in it that shouldn't be - it's discipline time. A few teaching staff here have moaned about not having access to student home folders - so to compromise we gave them a 'drop box' where both students and staff can retrieve work for each other. We explained the risks and they agreed - it's been working well ever since. Az
-
Is there any particular reason your students NEED full control over their own home folders? Ours here have modify - so they can still read/write, but not change permissions (even if they somehow got the security tab or via 3rd party tool). I might be missing something, maybe there is some reason that students need full and not modify, but I've not run into it yet here.
-
We were the opposite - we've had good support from Softlink - they migrated our old LIMES system to Alice. We've had no end of hassles with Alice, things not working as they should etc. But their support has been great. Oliver - a few teething issues but once they were cleared up, it just works for us.
-
Oliver, less hassle to maintain than Alice - our librarians seem happy with it. You just need to watch those macro security levels and VBA group policy settings with Oliver.
-
Quick question - we upgraded from Alice to Oliver semi-recently, unfortunately our librarian was off at the time, now she's back and wants some stuff she did in Alice that didn't (for one reason or another) get moved to Oliver. Not really a problem - until she told me she can't remember the master password for Alice. So my question is - is there a quick way to just force this to be reset or will I have to jump through hoops at Softlink? Az
-
I thought they also ran from %TEMP%.
-
We are looking at using software restriction policies here too - any chance you could throw me a copy of your policy using GP Management Consoles' HTML reporting if you don't mind? Az
-
We don't have this issue - we have a ton of GPOs enforced but the one we have set is 'force classic start menu'. I don't see a need at all for anyone to have the XP start menu, so they don't get it. If we ever go Vista - I will be enforcing that policy with Vista too.
-
The templates attached are the same ones we use here for securing Word XP and Word 2003. If you try these templates, hopefully it should help. templates.zip
-
We use KIX pretty much exclusively here, moving from a combined legacy of .BAT and .VBS. Took some time to get my head around it but now I use it for pretty much everything. .BAT files are good, if it's a simple job - use them, for anything more complex I use KIX. I can always convert .VBS to KIX relatively easily anyway, plus the support network for KiX is fantastic
-
While this doesn't directly contribute to the flow of the thread... We have 2 AD Domains - Staff and Students. They are connected via 2-way trusts - so any staff PC can logon a student and vice-versa (because it was one of the goals here that staff could use ANY PC to access SIMS, regardless of what network or domain it's in). Staff access SIMS via the Staff network in the normal way - via the SIMS Client. Staff access a cut-down version of SIMS via the Students network via Terminal Services (RDP). It's cut-down as they can't save anything, they can't print, they can only view and update information in SIMS. While they complain about not being able to print in classrooms, the possibilities if they could - are endless - confidential reports printed on a classroom printer for all to see... great. Students (even while on a staff PC) cannot access SIMS - all Staff PCs automatically lock themselves after 5 minutes I believe. We don't use firewalls or IPSec internally because we haven't had (touch wood) any serious security issues with data confidentiality. If it gets to the point where the security of the internal network is questioned or my line-manager or head decides we need to seriously 'up' the internal security - then I'm all for it. XP Firewalls and IPSec here we come.
-
Mark, Try one thing at a time - disabling the computer browsing services etc will stop computers showing up when the kids decide to browse the network, but it won't stop them browsing. If you want to stop the computer browser service, you need to set the 'Computer Browser' service to Disabled. This should be done for all workstations and servers (if you want to hide everything). Best way to do that is via Group Policy -> Computer Configuration -> Security Settings -> System Services -> Computer Browser. Set this to disabled here (perhaps try it for a limited OU). On a side-note, it's also worth disabling the Messenger service also - unless you need WinPopup/NET SEND capabilities. If you are still having problems, I will fish out the exact steps I took to disable browsing here.
-
Blocking UNC in Windows will stop plenty of other services working. In terms of handling Windows and UNC, suggest you disable the Computer Browser service on everything via AD. Configure it so no workstation is ever set as a Master Browser. Lastly, use NET CONFIG SERVER /HIDDEN:YES This will make all your PCs invisible on the browse lists (even if the kids somehow get to network neighbourhood). As far as Office 2002/2003 go: Get hold of the Office 2002/2003 Reskits (freely downloadable). Unpack the .ADM files that are present. Create a new GP (suggest you do this in a limited OU to minimise risk to start with). Add the WORD10.ADM and WORD11.ADM files into it. Navigate to the following: User Config -> Administrative Templates Microsoft Word 2002 (or Microsoft Office Word 2003) Tools... Autocorrect -> Autoformat as you type. You should see 'Internet and Network paths with Hyperlinks'. Disable this (as this stops it working). Next... While still under the Word 2002 heading in your GP: Go to Tools... Options -> Edit You should see 'Use CTRL + Click to follow hyperlink'. As before, disable this. Repeat this for Office 2002 or 2003, whichever you didn't change above. Login as a student (who will get this new GP) and test away. We've got this all in use here and even though our kids can still use \\uncpath in the open box - they won't get anywhere they can't get to anyway via drive letters. Hope that helps. Az
-
You mention a regedit - I'm guessing in theory you would only need to place the contents of the Office XP Media Content disk on the Network and then point the clients to it - rather than running around with an installer of sorts or is the installer the only way to do this? (Don't you just love it when Microsoft make huge sweeping changes like this?)
-
Hey there, We have CorelDraw 11 at our school, the head of our DT department has changed the way certain aspects of using Corel are done for the students. Unfortunately this has meant I need to find a way to stop Corel from trying to save Print-Styles in the users profile. I can't find anything on the Corel website about changing this path (and thus believe it's hardcoded in Corel - grrrreat) and I can't find any mention of it in the registry. Has anyone got any idea how I'd do this? (The students have mandatory profiles, application data isn't redirected and I'd rather not redirect it as it can mushroom really quickly) Thanks. Az
-
That's the way I would have done it too - but I was told to use the software by management.
-
Appreciate all the suggestions so far and it is looking very much like I can't do what I'd like. Unfortunately the dialog isn't a standard Windows one and even if it were, I'd need a way to fire up NIRCMD or a script when the box appears so that it can handle it without intervention... that would probably need something that sits there on the desktop and routinely checks Window-titles, when it spots the one I want to OK, it has to leap into action... ugggh. I think for now we're just gonna have to accept it as it is and remote into the PCs to clear it.
-
Yeah that's right - even with the GPO 'Hide these drives...' and 'Prevent access to these drives...' settings - they can still create shortcuts to paths on the drives you block, but I may not be 100% correct on that. Try enabling the GPO for 'hide these drives...' and 'prevent access to these drives...' in a test GPO (so that you don't impact the whole network) and then test it with a student login, see if you can make a shortcut to a 'hidden' drive (C: would be a good choice). You should still find that your applications will still happily run even with the GPOs in place - it's only when you start using NTFS permissions to lock down the drives that applications may start to complain at you.
