-
Posts
1,791 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by clareq
-
That's how I set it up the first time. Bitlocker enabled itself, but suspended. When I tried to manually enable I got an error message about not being able to delete all keys. I don't remember it exactly I'm afraid.
-
SCCM is in place. We have remote access when the users are on site. Unfortunately our users are not the most technologically able, some struggle with saving to the default location, so trying to get them to save to a second drive would be "interesting". Our AUP already states that anything not saved in their user area won't be backed up and could be lost if we need to rebuild their machine - we won't go hunting for work to back up. Basically I'm trying to replicate, as far as I can, the RM Privileged User set up, while at the same time making small changes to improve security. I have managed to get my boss to sign off on them not having local admin rights, which they currently have, so I'd like to give them saving to the C drive. I'm expecting a revolt over not saving to the desktop, I'm picking my battles carefully.
-
I've looked at that, but it appears to be for SCCM 2007 - I'm using 2012, and so can't get the task sequence to import, so I can see exactly how he's done it.
-
OK, I'm putting that aside for the minute. I can bitlocker manually but running it within the task sequence doesn't seem to work. I'm going round in circles now. Does anyone know of a working guide to enabling bitlocker during OSD for any model of laptop (I can see guides which point to a Dell utility for Dell laptops, but we have a mixture of models)
-
Easiest way to install software on a single machine is to open locations, then navigate to the machine. Right click on it, select assign, then select the program from the list that appears. I believe there is a search box at the top of the software list, but I'm not near a console at the moment. You can assign to a location the same way, and tick the "copy settings to computers" box to have it install on all machines in that location. Assigning to a location means any machine built in that location will pick up the software automatically, assigning to a single machine will need re-assigning on rebuild.
-
Yes, lexia requires a licence file on the workstation then runs from the web, from memory. Symphony has proved very easy though - as I say, I haven't needed to touch it - just put it on a shared drive.
-
Following advice further up the thread, I've removed them from the local admin group, added them to the local Network Configuration Operators group, which will allow them to add their home wireless, used loopback processing to allow them to see and save to the local drive for working at home. I don't want to make redirected folders available off-line - some redirected My Documents contain over 10Gb of files, but I have allowed redirected appdata and favorites to be available. To a certain extent it needs to be a "work in progress" and I'm sure various thinks will have to be "tweaked" one the system is used in anger, but I've been given plenty of time to develop a new domain, so I'm trying to pre-empt as many problems as I can.
-
We run it here - I've had very little to do with it to be honest - installed it on a shared drive and pointed a shortcut at it.
-
Prince Phillip had to give up his right to the Greek throne to marry Princess Elizabeth. I know wikipedia isn't the font of all knowledge, but it was the first link on google: Line of succession to the former Greek throne - Wikipedia, the free encyclopedia
-
Can't use WMI - there are some shared laptops I want them to have restricted rights on.
-
I'll give it a go in the morning - thanks for the help
-
Probably not - there is some sharing going on, I'm sure, but our Laptop agreement does state they won't loan it to another member of staff. I see where you're coming from - a loopback to allow all staff elevated permissions on the staff laptops, on the basis it's their fault if they share it.
-
They need to be able to set up their home wireless and printing, save any work they've done at home to the Hard Drive, possibly install software for testing, that sort of thing. I want them locked down on any other machine they use - if they break their laptop due to their stupidity they only inconvenience themselves, on a shared machine they affect other users.
-
We have over 100 staff laptops - would we therefore need over 100 separate OUs? That seems very messy - there must be a better way.
-
The settings that are holding are set in the user policy, but I only want to undo them for one particular machine per user. Would a loopback policy allow me to do that? I've come from a RM background, and I'm on a very steep learning curve here. We're using Server 2012 R2 and SCCM if that helps.
-
On our new domain we are trying to lock down staff as much as possible on desktop PCs, but give them local administrator access on the laptop they are assigned. However, when I add their domain account to the local administrator group on the laptop, they are still affected by the domain GPOs - even off the network. Ideally I'd like them to be able to save on the desktop or in a folder on the C drive and be able to install a printer or program if necessary, but as they can't see the C drive and only get the redirected start menu, none of that is possible. Am I missing something obvious? I really don't want to loosen the GPOs that affect their use of shared machines.
-
I'm attempting to get bitlocker to work within a task sequence. I've tested that the machine will bitlocker manually, and then hit my first issue - once a machine is "bitlockered" how do you rebuild it? I'm getting an error at the beginning of the task sequence, as there is no room for any files to write to the c drive. It's not even hitting my "disable bitlocker" task. I've used diskpart to wipe the drive for my testing, but we can't do that in production. Is there a way of automatically running a diskpart script before the task sequence is started?
-
Do you allow youtube in your school?
clareq replied to Ben_Stanton's topic in Internet Related/Filtering/Firewall
We use Bloxx, which has a quota system. Staff have unfettered access to youtube, KS3 and 4 are blocked, KS5 have a quota of an hour a day - they can use that quota on youtube, facebook and other similar sites. Staff have the hour a day quota for facebook and other social media sites. No-one has been able to justify needing more time. Youtube also has safe search enabled for all, so inappropriate comments are blocked. -
+1 for Salamander - always ready to go the extra mile. Can't fault them.
- 15 replies
-
- active directory
- ad tool
-
(and 1 more)
Tagged with:
-
We find problems when using IE, the site works fine in Chrome.
-
meru reporting restricted ip addresses being issued
clareq replied to jjohnsoncantell's topic in Wireless Networks
I can't remember how we tracked it down, I'm afraid. -
meru reporting restricted ip addresses being issued
clareq replied to jjohnsoncantell's topic in Wireless Networks
Have you a rogue DHCP server anywhere? We had a member of staff plug in a home broadband router for some reason once, and saw a similar issue. -
We don't really have that many printers - we moved to a new print server this year, but retain the data in papercut for the old print server - it sees each printer as two, one for each server.
-
System Status System uptime 27d 5h Users2,336 Printers 213 Recent errors 0 Recent warnings 1 Total Pages 2,709,764 Pages today 5,422 Hold/release jobs 0 Active user clients 116
-
I've just drawn up a Po to pay someone else to do this. SIMS is too important to mess up.
