-
Posts
5,685 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by jthompson
-
I see what you're getting at. Worth bearing in mind that whilst you're not configuring a local user, you are still configuring a local group on the computer. By doing it under User Configuration, that would make them an admin on all of your computers (and servers?) anyway, so perhaps better to do it under Computer config and limit the scope of that GPO to the required subset of computers. Another approach you could look at (never tried this myself) could be to use item-level targeting. Where you have an item under Computer Configuration for updating a local group, you could enable the item-level targeting option in the 'Common' tab and set a condition there that the computer must be a member of a particular security group. You can then have a security group that contains whatever computers you want you user to have local admin on. So even if the GPO is being applied to more computers that you really want, that item-level targeting will allow you to be more surgical with which computers are affected.
-
You can still do that under Computer Configuration. Create a security group in AD for and add the relevant AD users to it. Then in a GPO, under "Computer Configuration > Preferences > Control Panel Settings > Local Users and Groups" update the local administrators group to add your new AD group as a member. Apply that GPO to whatever computer OUs you need. Since this touches on security and account separation practices, it's worth warning against applying the same setting to servers. You may still want to use the same method, but if so, do it with wholly different accounts and groups. I'd say this should go hand in hand with "Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment > 'Deny log on locally' and 'Deny log on through Terminal Services'" to prevent your workstation admin accounts from logging into servers and vice versa.
-
PM sent
- 17 replies
-
- 1
-
-
- python
- raspberry pi
-
(and 1 more)
Tagged with:
-
It means that you can't find letters by using words that you know won't be correct. It stretches your vocabulary a bit more, I reckon.
-
A convoluted, mandatory reputation system designed to stifle undesirable behaviours. If you're not welcoming that with open arms then you must have something to hide!!! /s
-
You can set a school-owned Chromebook to only accept logins from an individual account, but I don't think this is what the OP is asking for. You'd probably also want to avoid that for a device that's being taken home anyway, since it's likely to encourage account sharing at home when another member of the household wants to use the device. In terms of preventing an account from signing into anything other than a school-owned device, you may be able to do that using Context Aware Access (Admin > Security > Access and data control > Context Aware Access). Not something I've played with, and I don't know if it requires a certain tier of Google Workspace and MDM level (probably), but that's where you can create an access level rule specifying that the device must be a company owned device.
-
Oh, it'd be totally unworkable and plagued with misuse and abuse. Many's the time, however, that I've felt my IT admin privileges twitching helplessly whilst witnessing other drivers falling foul of the AUP, as it were.
-
I can't wait for the advent of technology to allow for upvoting and downvoting of other road users. Enough downvotes and you get kicked off.
-
That looks distinctly Heath Robinson-esque. I can't quite follow all of those threads!!
-
99+ times out of 100 when I'm opening my car door I'm either on my driveway or in a car park, so I can't see myself habitually using the dutch door thingy. I do make a point of checking mirror and blind spot on the odd occasions when I am actually opening the door into the road. The fact that loads of people apparently don't is something I find mind-boggling, frankly.
-
I guess Group Policy must have some way of accounting for the same version of the same package being applied more than once, either by the same GPO or from different GPOs, and skipping unnecessary installations as needed. It's version aware, after all, since you can load in newer versions of packages to be installed as updates.
-
Windows Admin Center - Constrained Delegation
jthompson replied to mitchell1981's topic in Enterprise Software
I just provide suitable credentials at each WAC session, rather than using any SSO. The account I use is a member of Protected Users, which I believe would prevent it from working with constrained delegation anyway. -
If people like the idea of good, simple puzzle games without any ads, trackers or IAP BS, I can heartily recommend Simon Tatham's Puzzles. There are some absolute gems in there. Available in all good app stores and on the web.
-
There's no mobile app, only the web version.
-
3 goes today. I use the same starter word(s) each time.
-
So that's why they've decided to have no spectators.
-
I must admit I thought pedestrains already had prioroty when crossing the minor part of a major to minor junction, but that it felt so counter-intuitive for drivers to give way in such a situation that I'd never assume that I wouldn't get run over and then bellowed at.
-
I suppose "right of way" is really about whether you can use that road/path/whatever at all. e.g. cyclists have no right of way on public footpaths, pavements, motorways. Priority then sorts out who waits for who amongst all the different road users exercising their right of way.
-
Well, the heirarchy of road users is not so much about changing who has the right of way, it's more about the relative weight of responsibility for not flattening one another. I don't think there are any changes to who has the right of way.
-
RDS Gateway doesn't do anything in and of itself to protect against brute forcing of passwords, so if you're using that, you'll need to supplement it with some kind of MFA to make it safe. That's something the Azure App Proxy approach would allow you to do (i.e. placing the RDS Gateway behind whatever protections you already have on your 365 user accounts). I did once look at using Duo with RDS Gateway, but it seemed a bit too flimsy for me to trust it. IIRC if the Duo service were to stop on the gateway server for any reason, RDS would just be left available as normal without any MFA protection.
-
Keep being drawn back into this thread. It's proving hard to ovoid.
-
So, you poached it?
-
Been doing this for years using VirtualBox. Students launch a VM that has an immutable vhd and no network connectivity. You can use the shared drives feature of VirtualBox to bring mapped drives from the host into the VM (e.g. the student's user area for saving files). Login scripts are used to lockdown VirtualBox to prevent students from adjusting VM configs or adding their own VMs. Have to say it's been bulletproof. Deploying the VM files to each workstation is a bit of work. Plenty of purely online options, too, which others on this forum will be able to recommend.
-
Wordle 215 3/6 🟨🟨[emoji834][emoji834][emoji834] 🟨[emoji834][emoji834][emoji834][emoji834] 🟩🟩🟩🟩🟩
