Jump to content

Byford-Rew

Members
  • Posts

    29
  • Joined

  • Last visited

Everything posted by Byford-Rew

  1. Hi, we've just installed a Windows Server 2012R2 RDS Session Host server [x6] and am about to look at locking access down using group Policies. Initial things that come to mind are hiding the C drive but there are many more. To save reinventing the wheel is there a 'best practice' or 'white paper' document available with this in?
  2. What do you do in your school to control access to you tube? Some schools ban it completely for students while others leave it completely open. Is there any detrimental effect to having free access to YouTube or is it a myth?
  3. Thanks to the wonders of Server 2012 R2 and its granular password policy, I am now in a position where I can force regular password changes on our staff to tighten security just that little bit more. Before I do this I want to be aware of the things that may go wrong by doing this. I am really interested in the experiences of anyone else that has enforced a password policy. Did your users experience frequent locked out accounts because their phones or iPads were trying to log in to retrieve email using the old password and therefore locking the account? Were there any problems with exchange access using Outlook becoming problematic? If I know of as many of these types of things now then I can forewarn users so that they are at least aware of the issues which may arise. All feedback gratefully received - thank you, >end!
  4. Are these still available? PM me with more details please. Thank you.
  5. Check out ADAudit it does ALL this and more. I've found it so beneficial that I've purchased a years subscription. http://www.manageengine.com/products/active-directory-audit/
  6. Our login times went down from 2 minutes plus to 40 seconds. Here are the list of folders currently excluded: Application Data\Macromedia;Application Data\Sun;Application Data\Adobe;Application Data\U3;Cookies;Application Data\Citrix\PNAgent;Application Data\Skype;Application Data\Dropbox\cache;Application Data\Mozilla\Firefox\Profiles;Start Menu;NetHood;Application Data\Google;Application Data\Macromedia\Dreamweaver 8\Configuration\Menus\Cache\Menus;Application Data\Macromedia;Downloads; Scratch Projects;pnlinks;AppData\Roaming\Dropbox;Desktop;PrivacIE;Application Data\vlog;Application Data\Google;Application Data\CodeRush for VS .NET;Application Data\VisualStudio;Application Data\Dropbox;Application Data\Microsoft\VisualStudio;Application Data\LogSys;Application Data\Mozilla;Application Data\Dropbox
  7. Which server OS are you using? There are Group Policy settings which can be applied to the local computer to prevent profile bloat at log off. Also check out the 'exclude from profile' group policy settings as there are MANY files in group policies which don't need to be there as they are copied from the local machine at login if they are missing / required which is much faster than moving them around at login. This link will help here:http://support.microsoft.com/kb/814592 doing this and folder redirection can reduce the size of your profiles to less than 20mb.
  8. Yes it does - has done for many years. It requires a licence but I believe that this is bundled as standard now. If you're under support with AdvancedLearning they will defiantly be able to assist you here. Regards Martin
  9. We are minimising the number of accounts in our AD with Domain Admin rights. One account that has it's rights reduced is the account used in the ePortal controller for SSO to set properties in AD for PortalUser and PortalPassword. Now the process of mapping Resource passwords/users to AD accounts fails with insufficient rights. We want to give the appropriate rights to the SSO user to make these changes but are (so far) unable to do so. Can anyone help me out? It seems that the advice from AdvancedLearning is to use an account with elevated rights but I want to avoid this if I can. What rights should be given to the user to enable them to make the changes necessary? Thank you.
  10. Hi fellow edugeekers. I have an issue at present where a user called ANONYMOUS LOGON is randomly making changes to an Acrive Directory objects. I want to limit the availability to make any changes to specific users, it's the first time that I've come across this.
  11. Is there a way of monitoring a NetApp SAN FAS2240-4 that gives more detailed performance statistics than the OnCommand System Manager? The SAN HQ tool provided by Dell gives excellent performance / diagnostic information and I can't see a comparable system for the NetApp.
  12. So today I was asked to do the update to fix the census error associated to Free School Meals and 6th Forms students. When I click the relevant links I don't see a patch to apply - instead I see the entire install file for Facility and ePortal. Am I missing something? Surely I don't need to do a full install do I? I have many customisations and SSO to set up. The last time the process took three hours. Meny here appear to have applied the fix - am I missing something? HELP!!
  13. Thanks James, I've spent the best part of 1 1/2 hours on the phone with them today trying to get to the bottom of the mystery. They were very helpful. It's still not solved but at least it's a step in the right direction.
  14. Thank you, That's a job for tomorrow. Regards, Martin
  15. Updata are the ISP. That address is ours but the hostname is incorrect.
  16. I am unsure. I make requests to the our service provider to have the changes made but other than that I do not know.
  17. thomasdeaconacademy.peterborough.sch.uk This is the one that will not validate. Regards Martin
  18. Hi Pete, Thanks for the pointer. There is a txt tag on our Domain but it is the one I had placed there as part of the setup process. Despite its existence MS still can't validate against it. Any clues? Also the hint about mxtoolbox.com was a great help!
  19. I have successfully created a .onmicrosoft.com domain name for use in the Academy where I work, however when I try to validate my Domain I keep getting informed that my domain is associated with another MS Service. I am confident that it is not, but no matter what I try to do I am unable to get my preferred Domain name recognised by O365. The error message received is: Has anyone else experienced this and if so, how did you solve it? Thanks, Martin
  20. Has anyone used Viglen to provide computers to their schools? If so, how was the service and quality of product? Their offerings look competitively priced and the value added services make an interesting proposition.
  21. I'm using HP t610 terminals to connect to XenDesktop 5.6. I downloaded the HDX Ready Thin Client Plugin (13.0.0.6695) from HP and applied it and it works perfectly by locking the terminal for anything apart from a VDi connection to XenDesktop. When users log in they are required to enter their username, password and domain. As the domain will always be the same I want to pre-populate it for them to make it easier. I've trawlled through loads of Reciever docs from CItrix and also scanned ini files and registry keys to find where I can set ths domain property. Has anyone managed to do this? If so, can you please share the secret. Thanks.
  22. Problem: A physical host [HP Thin Client] with a Hostname of T01TCD01 connects to a XenDesktop hosted Virtual Desktop with a Hostname of WIN7VDI01. To enable printing to local printers within the room Kixscript is used to map the correct printer based upon the first three letters of the physical Hostname. However, when logging in to the XenDesktop the Hostname of the physical device is unknown. Is it possible to identify the Hostname of the Physical host? Is the hostname passed through to Citrix via Citrix Receiver somehow?
  23. Two reasons : 1. To get Single Sign On [sSO] to work for a user logging into a Citrix VDi Session through Citrix Receiver 2. To ensure that the logged on user is authenticated to used the ISA firewall to process html request when Flash is redirected using HDX Flash redirection. If the terminal is left as stand alone when the request is made then a username / password requested comes requesting details.
  24. I have a number of HP t610 Thin Clients that I am planning to use in the network for a Citrix VDi system. These devices are running Windows Embedded Standard 7[E] so that I can ensure that Flash compatability and HDX continues to function. Should these devices be added to the Domain or left as Stand alone devices? If I leave them as stand alone devices I have issues with authentication for web sites when called by HDX Flash Redirection unless there is another way to configure them.
  25. We work the same way as well but some students deliberately use this as a way of getting out of the lesson. Teachers can deal with password issues themselves as well as locked AD accounts without impacting upon teaching and learning and it would really be a valuable feature if we could give them the power to log off Citrix Sessions too.
×
×
  • Create New...