Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

powdarrmonkey

Edu Supporters
  • Posts

    5,017
  • Joined

Everything posted by powdarrmonkey

  1. I'm not sure the BS allows for exotic cable exits in 13A plugs, but you'd have to ask AndrewC.
  2. I don't know if policy extensions can do redirections; I use the registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  3. You mean these? right angle iec lead - Google Product Search
  4. You will need to keep many other things to make the profile useful. I have successfully reduced a mandatory profile down to about 1.5MB before now, by pruning the file system and registry, but keeping base settings for all installed applications (so for example, the user isn't prompted to configure Office every time they log in).
  5. Profile types: Local - default type, gets created on a machine and stays there on the local disk, does not follow the user around. On each machine they log into, a new local profile is created. Changes are not propogated between machines, and profiles must be deleted from each machine by hand. Roaming - created from a template defined by the administrator, then kept on the server from then on. During login, the profile is created or downloaded, and at logout the changes made are uploaded back to the server. Follows the user around between machines, but a cached copy is left on each local disk to speed up the next login (changes are replicated through deltas). The user gets the same environment on each machine, but unless carefully managed profiles can quickly become large and unwieldy, consuming server storage and making logins slow. Mandatory - like a roaming profile, but changes made by the user during the session are discarded at logout. Cached copies are not kept on local disks. One template can be applied to many users, making mandatory profiles very efficient, but customisations by the user are lost after each session. Some hacking in the registry can produce a balance by storing some parts of the profile in a different location, such as putting the Favourites folder into My Documents. Although the profile itself is discarded, the favourites are not, so the user's changes are kept. Given the choice, I use carefully managed roaming profiles for staff and split mandatory profiles for students, so they can't go crazy customising things but do get useful things between sessions, like Favourites, History and so on.
  6. The short answer is: no, not on a hardware level like you need.
  7. (this is a personal purchase, not a school one) I'm hunting high and low for a network switch of at least four ports with wireless built-in, but not a router, modem etc. It should act just like a combined switch and wireless access point, and preferably for less than about £50. I'm hoping Simon or Dan will have some bright ideas Bonus marks if it also supports WPA(2)-PSK, beer if it supports WPA(2)-Radius or 802.11a (having both doesn't get you double beer, sorry). kthxbye
  8. An intranet web page?
  9. Not at all, I just meant that all MS activations have a reasonable grace period.
  10. Set the install time for 18:00 and use your favourite shutdown solution for 20:00, and you win everything.
  11. There's always been a grace period - thirty days, fifty executions of Office, etc.
  12. Shutdownertron will do the nuking for you, but I've had to grow my own WOL solution to tie into Active Directory (it's not suitable for public release though, sorry). AD can't handle it by itself. To be honest, if the difference is ~£9, I'd rather just plug my sky box straight into the wall. Nice idea, but the best thing about the solution is its simplicity - adding features like configurable sockets complicates things.
  13. As submitted to ServersPlus:
  14. Shame the BBC author thinks Linux is a 'desktop OS'; otherwise, an unusually factual article for them...
  15. One day, I will introduce you to my friend the port scanner. In the meantime, just moving the service to another port doesn't give you any kind of security, except again opportunism I suppose. Hiding things doesn't make them any less vulnerable.
  16. Or, 22,000 evaluated the three big players and said 'SIMS is the least evil'...
  17. Performance is a consideration, but usually: - maintain continuous service by failing over gracefully - protect you by sharing out the Master roles and keeping replicated copies - localise DCs to subnets to reduce backbone traffic, make DFS lookups sensible, etc
  18. I still do (on all counts). I took to making a noise at one stage, but it's difficult to tell who's scratching their head and who's on the phone until it's almost too late.
  19. Excellent, I didn't know that magic. Thanks.
  20. IIRC sysprep has to be updated each release - has a Win 7 version been published? (and are you using it?)
  21. It's worth it if a) your current provider agrees and b) you actually save enough in the long run (with a cheaper contract) to make it worth while.
  22. Currently there are two problems with Windows Vista and Windows 7: the local configuration tool doesn't run at all, because it doesn't get allocated a privileged process the shutdown warning dialog appears on the secure desktop, so the user gets a confusing message first, then potentially only sees it after the timer has expired For now, I have made a service release (1.3.3214.1) that fixes the first problem by launching the local configuration tool as a UAC-enabled program. You will see the usual dialog asking if you want to allow LocalConfig.exe to make changes to your machine. I'm not going to service the second problem until Shutdownertron 1.5, which will have full UAC compatibility amongst other things. A temporary workaround is to add trust to the Shutdownertron service, but I do not advise that you do so. Currently, I advise that you do not re-deploy Shutdownertron, but you do keep a copy of the MSI handy for the service release and install it as required when you need to use the Local Configuration Tool. Download: Shutdownertron
  23. Note: you don't activate Windows directly, you install the server service somewhere and activate that, then Windows picks it up from your DNS infrastructure and works some magic itself.
×
×
  • Create New...