-
Posts
1,402 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ADMaster
-
Not to go off topic but this type of post would be perfect for the wiki. Is the in the plans post VBulletin
-
Do you use disk quota's? I found if you use the old NTFS disk quotas on the volume, space showing to users is their quota. If you use the new file resource manager then they can see the total space. I'd be interested in an answer as well.
-
Hello, To be clear I’ll say this has two answers. Yes an account can be disabled from the client. I use a combination of RSAT / ADUC, powershell scripts, and other tools to manage accounts from my client machine every day. No local admin should not have any effect on domain accounts. I suggest that you do the following; Review permissions of the accounts in question to see if someone has been given permission to them before. Turn on auditing to see who / when the account was changed. Change passwords if you suspect someone else may be using your domain admin credentials. I know you said there are no policies or no one else managing accounts, but do you have any automated process that disables accounts if they are no longer in the SIS etc. Cheers,
-
Hello, You will need to configure all of your switches with the other vlan as well. Depending on how your wifi handles traffic you will need to trunk each ap or trunk the controller. You will need to setup and ip helper address on each vlan pointing to you dhcp server. Cheers;
-
Problems creating user collections from security groups
ADMaster replied to birchanger's topic in O/S Deployment
Do you have it set to discover groups. I have a staff user collection and I just made the staff group the member of the collection and not each user. I can pull the sql query for it tomorrow if you like. Cheers. -
Helpdesk system with more than one department?
ADMaster replied to afc123's topic in Network and Classroom Management
I use webhelpdesk, it is only free for one tech though. It is multi department support, and each can have their own email address. Users can open tickets via email, or web page. -
For the least amount of admin overhead / management / policy processing, put the ACL on the single vlan that you want to block access to. The best practice is to put the rule nearest the destination. For example you want to block vlan 1 and allow 2 and 3; If I am in vlan 2 and try to contact vlan 3 no policy needs to be processed. If you put the policy on vlan 2 and 3, the switch needs to processes the policy just to do nothing. I hope I explained that clear enough. Cheers.
-
Slight thread hi jack here. We use media cast it is pricy, proprietary and can be clunky. I want a replacement. I have a few questions about Xibo; Can the users tune into digital TV / record TV? Can I get the enterprise support over here in the US? (EDIT: doesn’t appear to be) Can the users browse for media in addition to the signage aspect? Mediacast allows for display of media content in the classroom, digital TV and the ability to record TV. It also allows the teachers to clip segments of a video for their lesson. It also has a digital signage aspect but it isn’t very flexible. They are certainly stronger at the media / TV then the signage. We would like to find a better signage program, but I’m sure some folks would still like to do the media if possible, but it hasn’t been widely adopted by the teachers here. Edited to answer one of my own questions. Thanks,
-
Hi Gongalong I think you will need to allow them to list / traverse the entire path of the share. Here is a previous post I made with a permission screenshot. http://www.edugeek.net/forums/windows-server-2008-r2/101587-student-folder-redirection-issues.html#post874322 Some applications such as word needed to see the whole path. What application are you using? Also note that because you deny delete doesn’t mean they cannot erase the contents. I suggest you setup up a test account and try a few different things. IIRC from my lab experiments if you have read and write but not delete, you can simply open the file erase the text and save. Even if you deny read if they know the name they can copy in a blank file with the same name. Your remote access tool make take care of that though. Cheers
-
I had full system backups before I ran the upgrades, but there were no issues.
-
I did this with my 2012 DC, and a few VM's I had running 2012 without a problem. For the hyper-v servers I moved the VM's to another host, and did a fresh install of 2012 r2.
-
Over here in the US one of our major vendors has negotiated a giant volume purchase agreement with Adobe for their customers. This is based on FTE like Microsoft, for this pricing I can cover the whole school for three years, for the same price it would cost me to cover one lab with a perpetual license for CS6 In our case the CC is better value. Perhaps one of your vendors can negotiate a deal with adobe on behalf of all the schools interested in Adobe CC.
-
No you need to right click the deployment and the click update it will ask you to do full or optimized. For this case you should do full. The import the updated image into wds. This will take awhile depending on drivers On the mobile please excuse typos
-
Do you have a dedicated IP for web access already? My webserver runs on apache so I’m using the apache proxy modules. We do have an external ip dedicated to our website that forwards to an apache server. From there I can serve the main webpage, or reverse proxy to other internal web services. I have entries such as /hap and /moodle that will reverse proxy those sites through the single address. I’ve found some things just don’t work well with a proxy though. What web services are you try to reverse proxy?
-
Powershell is the way to go here this can be done with just a few lines. What OS is your server, do you have access to Microsoft's adcmdlets Active Directory Cmdlets in Windows PowerShell If not Quest AD cmdlets will work as well Also bulkadusers by wisesoft will be a great tool for this, you can load users by list of usernames. Bulk AD Users Here is a rough outline off the top of my head, you will need to adjust syntax etc. Cheers $userfile = import-csv pathtooldusers.csv for each ($user in $userfile) { $aduser = get-aduser $user set-aduser -identity $aduser -enabled 0 -[i]Description "disabled by script" } echo "done" [/i]
-
I’m interested in all of this as well. Currently all of our staff laptops have local documents. I’m considering redirecting them and making the files available off line. I have been testing this with windows 8.1 but the first sync doesn’t appear to be starting. It shouldn’t take too long because I created a new test user and just dropped a few text files in their my documents. I went to sync center and started the sync and got an error messages stating it was unable to sync. I also clicked view off line files and it showed at 45% I’d also like to know if this is a sync percent or drive space. The only documents available was a text file on the desktop, but not the text files I dropped in my documents Also after forcing the machine offline the desktop had the sync icon and the documents had the grey X However if the first sync takes a bit maybe I’ll give it another go and let it sit overnight. @Bankesy Here are a few group policy tips, instead of going through all of your settings manually. If you don’t have it installed already install group policy management console. You can click on a policy and get report of all of its settings. From a command prompt on the client type Gpresult.exe /h report.html This will write out all of the settings applied to that use and machine along with what policy applied it. You can also get the same information from the GPMC with the group policy modeling and results wizards. I hope this helps you find the conflicting settings. Cheers,
-
Hi Kol, You didn’t mention wifi so I assumed this is on the wired network. It is typical to have computers authenticate when dealing with wireless, unless you have an open unsecured ssid. It is possible to have the same authentication setup on the wired network, but you would have to have the switches, and the PC’s configured correctly. When I started testing some of these settings on my wired network last year, it is the only time I have seen authenticated / unauthenticated on the wired network adapter. Here is an MS page detailing how to enable 802.1x in windows, you can check the settings and do the reverse if they ware enabled. Enable 802.1X authentication - Windows Help I hope this helps, Cheers
-
Are you using 802.1x authentication on the wire? If not try disabling the wired autoconfig service.
-
deploying registry settings via prefernces with targeting
ADMaster replied to GoodheadDC's topic in Windows 7
The top of the collection should be the only place you need it. -
I’m running core on one of my file servers, but not on my DC’s. I have other apps installed on it such as GADS the require the gui. If you do not have any apps the require a gui though I’d use core. I use RSAT most of the time anyway.
-
Hello again all, So I put this issue aside for a while and just connected the androids to guest last year. I started searching for an answer again this summer and came across this post. I’ve finally got it working now. The ipad profile had my domain in the trust cert section. Once I removed this for the android profile it worked. One would think that the Meraki folks could have pointed this out when I opened a case with them last fall, but it is working now.
-
I just want to update everyone on this. I never did figure out the MDT issue, but I’ve got OSD working with SCCM now, and it images the hyper-v VM. I now have a place to test my images. Thanks
-
Hello, The email can be solved by using OU’s which it sounds like you’ve done now. Google does not have a password expiration feature. They do have a password policy section to set the minimum password length. See attached. If anyone knows of a way for google to expire passwords I’d like to hear about it too. Cheers,
-
The OP looks like they are in the US so stone probably couldn’t help. Personally I think the whole thing would get very messy, and I like having all the same machine model, it makes it nice on images and spare parts. To take it a step further I would like to stop issuing teacher laptops all together and put a PC in the room. But I don’t think that will go very far around here. My reasons for suggesting this are that half of the staff never take them home and they stay in the classroom plugged in all the time as a desktop. This kills the battery, it is the part I’ve replaced most. Second reason is for those that do take them home when they call off I have to scrounge up a spare for the substitute. If I had a PC in the room this wouldn’t be an issue.
