Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ADMaster

Members
  • Posts

    1,402
  • Joined

  • Last visited

Everything posted by ADMaster

  1. I agree with Zenden, an OU structure is easier to manage. I have something like; Staffusers Staffcomps Studentusers Studentcomps Then sub OUs based on building / lab etc, this allows me to target the policy. I then can disable half of each policy that is disable the user section of a computer policy, and computer section of a user policy. This reduces policy processing times, but with today’s computers I don’t think you’d see a big difference. However it is possible to accomplish what you want with a little administrative overhead. Create security groups for each set of computers and Users then apply your security settings to that group. Also are your computers, and users in the same OU? If not you’ll need to apply the policy to both OU’s or enable loopback processing. Hope this helps,
  2. Badaz52, You need to disable network level authentication in gp on the RDS server. Configure Network Level Authentication for Remote Desktop Services Connections hope this helps
  3. Same here, disable updates and push chrome with gpo.
  4. I’ve never switched from MAK to KMS, but I can tell you the KMS key is for the KMS server not the clients. The last I read that server key could only be activated 5 or 6 times, so you don’t want to activate it on your clients. Try selecting “automatically select client KMS key GLVK” when you install a key. If that doesn’t work try manually installing the client keys. KMS Client Setup Keys
  5. Same as above, but this one will also look at firefox chrome etc. I like to map a drive to \\comp\c$\users or \\comp\c$\users\username Then I just point the tool at that drive. BrowsingHistoryView - View browsing history of your Web browsers
  6. Same here as Chazzy I first couldn’t image the win8 laptop because of uefi, so I had to disable it and turn on legacy boot options. Then the image wouldn’t activate, it said KMS was only good for upgrades, and I needed to purchase windows. I ran the wga diag to find it didn’t have the proper windows flag. I suspect it is because win7 and 8 use a different version of SLIC I ended up using a MAK key as well.
  7. It sounds like you are putting all of the FSMO roles on one machine. If you only have one DC that will do, but if you have multiple DC’s the FSMO roles should be split. See this MS article FSMO placement and optimization on Active Directory domain controllers
  8. There are a number of logon tracker ideas on here. I use a vbscript that runs a logon and logoff, all it does is write the username, computer name, ip, mac, date and time to log file. It’s crude, but gets me the basic info of who logged on last to a machine. Here is the EDU logon tracker EduGeek Logon Tracker Here is an old thread that might help. http://www.edugeek.net/forums/scripts/4882-script-track-user-logins.html
  9. Ass17, I have a surge suppressor on my PC, I’ll be looking at others though. MathewL, The net comes in through the phone line, but if that is how it got into my network why is the modem and firewall machine not fried. They are first in line. Cybernerd, I have insurance, but the deductible is either $500 or $1,000 I’ll have to look to be sure. The board was RMA’ed so no cost there. I could get a new PC for less than the deductible, and a new router. So insurance would only help if it took out all the electronics. The DVR is on the network so is it possible that the dish picked up the lightning sent it to the DVR and the DVR put it on the network? That doesn’t entirely make sense either because the other receiver, not on the network still works. Thanks,
  10. I recently set this up and was searching the forums for these answers. Yes, you need ASP.net installed under development to get the forms authentication option.
  11. Hello all, My home network and Home PC have had a bad few weeks. About 2 weeks ago lightning struck across the street and I lost the onboard NIC in the PC. I also lost the switch port that the PC and the DVR were connected to. I just installed the new RMA’ed MB last Thursday and sent the bad one back yesterday. Last night there was another storm and lightning struck a tree in the back yard. I get home from work today to find the onboard nic is out again, the DVR is dead, and the port my PC was connected to is dead. The DRV port is probably dead to, but I haven’t got that far. I don’t really want to RMA the board again, so I found an old NIC in the office to get me back online. My equipment is connected with a patch panel in the basement with jacks going to most of the rooms. They are on surge protectors, but it’s getting into the network somehow. My question is what can I do to protect my equipment from this? Any ideas and suggestions are appreciated. Thank you,
  12. To delete the leaving year groups folders without sifting through 650 folders to find the correct ones.
  13. why not? Money is one reason, but technically they can have member 2003 servers. I ran a 2008 and 2003 DC together on the same domain until I demoted the 2003. I currently have 2008 DC's with 2003 member servers and a 2012 eval member server. I plan to do similar with 2012, install a 2012 DC then a some point in the future demote 2008.
  14. Edutech, If I understand your latest work around, I think you’ll be right back where you started. You are mapping the home folder to \\server\share\user\docs, and also redirecting my documents to the same location correct? This will take you back to the desktop.ini renaming folders on you. Here is a screenshot of group policy I mentioned. Notice all I need to do is add \\srv\share and it fills in the username \ my docs This screen shot is to specify different locations for staff and students. You can do this or just create separate policies. Hope this helps,
  15. I changed the way folders are redirected, not how home folders are created. Home dirs. \\server\staff\user\ My docs are then redirected to a subfolder of the home dir. The GPO option is “Create a folder for each user under the root path” My docs becomes \\server\staff\user\my docs Hope this helps.
  16. I had something similar last week on an old machine that I don’t use much, and had not been patched. So I don’t know if it was a virus, or something that snuck in on an installer. In any case go to your uninstall programs and sort by date. You should find the culprit then. Good luck.
  17. Bat, I can’t think of any “gotchya's” that will hinder you. I think the biggest difference is terminology, which your wife can tell you. I’ve been on this forum for a few years and didn’t have much trouble picking up your terms. There is no SIMS.net that I know of, the SIS systems are Powerschool, progress book, and DASL. There may be more, but those are the ones I’ve heard of. Some schools host their own SIS systems, and others, particularly the smaller ones go through an organization similar to your LEA. I think the staffing depends on the size of the district. I work in a small district with 1 Elementary, 1 Middle School, and 1 High School. There are two of us at the district level, although 3 would be nice sometimes. There are some tech savvy teachers in each building that can help out on minor issues. However the total number of students in the entire county only matches a medium sized district across the state. I know of some districts that have 20 Elementary schools. These larger districts employ staff that are assigned at the building level, possibly multiple buildings. The qualifications may vary, you shouldn’t have any trouble with those and your background in EDU IT. It seems that standards are ever changing. I remember when the degree was everything, then the certifications were everything. Then you have the camp that says you have all these certs but no experience to apply it, and the camp that says all these certifications and degrees make you over qualified. I’m only in one of these fifty states, and Florida is not it. Some of this may vary state to state. My advice is to look for postings that match your qualifications, and send in your resume to places you’d like to work. If you have any questions I’ll be happy to answer to the best of my knowledge. Good luck
  18. I'd like to setup SCCM this summer, but in the mean time I use a combination of GPO software install, and PDQ deploy.
  19. Hello, Are these workstations logged on with a generic account or does each student log on when they use the computer? If it is the latter, look at a log on tracker. There are a few on here, from writing to a text file on a share, to a SQL database with web interface. The basic log on, log off times should give you the info you’re after. Regards,
  20. Hello @revingtosh , KMS does not download all of your licenses from MS. The machines that are already activated will remain activated if they have a valid key / OEM activated. For any new installs, if you use the volume edition of windows it will have the Volume key pre-installed, with this key the OS will try to find and activate against a KMS. This is where that SRV record comes in. You can also change to a volume key as well. KMS Client Setup Keys Yes you can have office and windows activations on the same server. You just have to activate the proper KMS host key. You can check the status of your activations with slmgr.vbs display basic info about your main kms key Slmgr /dli display detailed info about your main kms key Slmgr /dlv display basic info about all kms keys Slmgr /dli all display detailed info about all keys Slmgr /dlv all VAMT is a good tool to have as well. Introduction to VAMT 3.0 Another thing I’ve read about recently that wasn’t around when I setup my KMS is active directory based activation, it may be a fit for your scenario. Active Directory-Based Activation Overview Hope this helps.
  21. I’ve had recent experience with the ideas presented here. SLT brings on contractors with shiny new kit. IT doesn’t know about it until some of the decisions were made. We could have provide the same or better advice then the vendor, it we knew we had the budget for the new kit. SLT is sending a few teachers on a chrome book management course. I don’t need a course to manage a chrome book. Are they trying to cut us out of the picture? Who will manage the wireless, core infrastructure, routing, DNS, DHCP, AD, filtering, etc etc? Me, myself and I Someone will have to give them admin privileges in GAFE Not me
  22. I don’t setup fully automatic builds either, afraid a machine will get imaged that shouldn’t. I skip everything but machine name and task sequence.
  23. I use CPAU from joeware for this. Encode the program parameters username and password into a job file, then create a bat file to decode the job file. Change the icon of the bat file to that of the program and the user doesn’t notice too much. I’ve done this for a few old programs, I can post a copy of my bat files if you like. CPAU
  24. Hello, You will want to setup port mirroring on the port you want to monitor. Switches only send traffic to the port it is Destin for, unless it is a broadcast. Port mirroring will send a copy of the traffic to the port you specify. This will allow wire shark to capture it. Regards,
×
×
  • Create New...