Jump to content

MordyT

Members
  • Posts

    530
  • Joined

Everything posted by MordyT

  1. Scare tactics. There are several ways around this, esp if rooted. Rebooting into safe mode. Package remove via adb (Remove via custom recovery)
  2. Create on GPO to deny and link it in the user ou. Make a security group and add those 2 users, apply security filtering for that group, and you are set.
  3. If you plan on making the changes in the registry, then it might work. But I doubt you will be able to change it once a person logs in without a reboot. I actually remap the keyboard via scancode in my edulocker program.
  4. I could wipe up a exe that disables the spacebar via the scancodes (easy to do)(or any other key), but it won't work at login screen. That's a secured screen....
  5. Simplest way is SRP is whitelist mode. Only whitelist the software, windows, and done. Custom shell is nice, but doesnt prevent a savey person from breaking out. SRP does.
  6. Since when did Bitlocker work on Windows 7 Pro? Enterprise and Ultimate only I thought? About 90% Yes. Bitlocker usually does software based encryption, which means you can reformat and its gone. Unless you have hardware encryptable drives...
  7. There is a clean option in the perc. Why not use that?
  8. That looks fine to me. Just a regular GPP scheduled task then. Was unsure if you were pushing some software out which could delay the start up, etc, but that looks fine.
  9. What does your policy look like?
  10. Cross posting from technet. All they could say was use a script... ---- Hello, Setting up HDD quotas. The environment: about 100 users, about 25 Windows 7 PCs, DC = Server 2003 SBS, AD, local profiles with redirected desktops, documents, start menus. The request - each user is allowed 50MB of local HDD space. See images for what happens. I set the policy (done locally for testing): https://mordyt.com/MS/settings.PNG I try logging in as a new user: https://mordyt.com/MS/newuserlogin.PNG and get the error. I check the quota entries: https://mordyt.com/MS/qouta%20management.PNG I then update the entries so the 3 NT Service / NT Authority have no limit: https://mordyt.com/MS/updated%20qouta%20management.PNG The the user is then able to login. It will be a massive pain to manually update each workstation and update those 3 entries to no limit, esp. as they get reimaged constantly. I would like to push these settings into GPO - and when I do - I get the exact same result. How can I exclude those 3 accounts from being counted in quota settings?
  11. Cross posting from technet.... Hello, The environment: about 100 users, about 25 Windows 7 PC, DC = Server 2003 SBS, AD, local profiles with redirected desktops, documents, start menus. The special case: Some (generic) accounts are not supposed to be allowed to load media from external sources, such as flash drives. They must get their media from a server location. The part of the solution I have: Using User GPO, you can block access to removable devices for these accounts. This works - flash drives, external cd roms, hard drives, etc do not open when using those accounts. The issue: It is possible for a user who has external drive access to login, copy the files to his local profile on the HDD. Then it is possible for him to add the generic account that should not have access to the security permissions, allowing that generic account access to media they should not be able to access. Does anyone have any way of preventing a user from adding anyone to their local profile on the HDD? As the user is a owner on their local profile, and the profile doesn't get created until they log in for the first time, they can change any permissions and add whoever they want in. Please try to avoid a solution that runs a script after a user logs in and changes the permissions. We have 0 login scripts, everything done through group policy, and we want to stay that way if at all possible. Thanks
  12. Several things to look at, such as is it doing full disk, or only the data on the disk currently? SSDs are quick, was the 2 hours a normal disk? Also, does the drive support hardware encryption?
  13. WScript.Sleep 300000 That should do it...
  14. That why I said make a shortcut... Not browse with explorer. Right click, new shortcut...
  15. If you think you have the hard drive blocked fully, try this.... Make a shortcut to c:\windows\system32\cmd.exe. if while making the shortcut you get an error, try again. ( hit okay in the error and then hit next again) Or, make a shortcut to \\localhost\c$ Suddenly the high HDD got a lot harder to block
  16. Easy way to tell if cmd is elevated... Look at the starting path. If system32, elevated. If users home folder, not elevated.
  17. MDT can be used for app deployment as well. Not as slick as Altiris, but works none the less.
  18. To be honest, setting up MDT would take less then a day from scratch for someone who never used it before. You could simply setup one PC, open MDT, tell it to capture a image, and it does the rest. Other alternatives such as fog or clonezilla as well. Just don't setup each one. Ghost works as well.
  19. Please don't. If you don't have the time or equipment to setup a full blown wds or mdt at the very least capture an image with imagex sysprep that image and then deploy that to the other 29
  20. I'm sorry, but what is the advantage of this over bitcoin exactly? Seems like another clone of the concept, but why would people want this over bitcoin, etc?
  21. Article seems to be full of amazon link bait. Also seems poorly written - Epson as the number 1 printer? I actually own a 2540 they mention, and while it works, a good HP printer (like a 8600) is far superior. TL;DR Don't know if spam
  22. Just to make sure we are talking about the same thing.... You are using GPP to set a local password on a machine. You edited the XML file in the sysvol folder on the server and that's what it showed? And, I would be more then happy to destroy any misconceptions you have about preventing users from being able to access the c drive.
  23. I can't caution people away from Justhost fast enough. Nothing but grief.
  24. Someone pointed out to me that is a bad idea as someone can edit the XML files and see the password in plain text
×
×
  • Create New...