-
Posts
1,402 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ADMaster
-
also look at the file / folder permissions. If the permissions are set to allow the administrator vs Administrators or Domain Admins, you will get this. Change the file / folder permissions to reflect the group and not the user. For AD as long as they are in the domain admins group they should be able to do anything. You could also look at the delegation of control wizard to assign specific roles to them without making them a domain admin.
-
Thanks, I'll investigate that and run it by the principals wanting the usernames.
-
Hello, Another thread on here sparked a question I have about my lightspeed. First I should say I don’t have full control of the box, I am a tier admin. I have noticed under the authentication tab I can make all devices authenticate or just if the identity is unknown. Can I have this apply to only one subnet, or exclude a subnet from this? I have two cases where I want opposite settings, and I’m not sure how it will all work out yet. 1 we have reports of students trying to look up inappropriate material, but it is coming from the Ipad subnet, so usernames are not in the reports. I have not had a chance to look at the lightspeed ipad app but that is one solution I will explore. However if I could force the ipads to web auth it might be a nicer solution than the app. 2 on the other hand we are talking about opening our wifi to guests, these guest devices would not have AD credentials to login to lightspeed. If the guest ip range could be excluded from auth that would be great. Also is there a url a user could go to get the login page, currently the only way to web auth is to hit the login link from the blocked page, without forcing all devices to auth of course. Thanks for any help and advice.
-
@BarryBKS Java update 15 was a nightmare for me. I tested on a few random machines they reported no problems. I also deployed a JNLP reg fix I found on another thread here. I then deployed java across the network, they reported a successful install, however looking in program files the .exe’s and several other files just were not there. Along with program files the exe are copied to system32 or syswow64 depending on your system. I use pdq deploy and I noticed in the package library java 15 and java 15 alternate. They said there were issues upgrading from java 11. The alternate installer included a couple commands to delete the iava 11 installer information from the registry. I modified this to delete the installer information for java update 15. Then on all the effected computers I ran the alternate installer to reinstall the update. This worked for most of them. I had one computer that did not copy the needed files to system32, which is where the jnlp fix looks for the exes. I had to copy the files manually. I now have everyone on Java 7u15 Java updates are chaos because our grade book system uses java, and if the install breaks you have a mob of teachers that can’t do grades. Now I find out another critical update was just released.
-
I don’t use SCCM so can’t help on that front, but here is the command you want Reg add I have used the reg add command to modify the registry, but never tried inserting a variable. You can use the %computername% variable or the hostname command to get the computer’s name. Hope this helps
- 1 reply
-
- batch file
- computer name
-
(and 3 more)
Tagged with:
-
Reservations issue for tightvnc purpose.
ADMaster replied to macsit's topic in Windows Server 2008 R2
Bit of a pain, I would like to be able to modify the address field as well. When I need to make a reservation I just make the reservation like you did, copy out the mac, delete it, then add a new reservation manually. Like I said a pain. When I have a lot to do I use the command line. Export a list of leases, change the ip address to what you want. Then manipulate them in excel for the command line. Netsh commands for DHCP: Dynamic Host Configuration Protocol (DHCP); Scripting -
I have used light speed for about 3 years, first TTC8 then the new rocket. The agent on all the PC’s is nice, because I can set different filters for staff students, subnets etc and it is mostly transparent. I however do not have a say in the matter, our filtering and firewall is all handled by our ITC . They have the light speed box setup with tiered administration so each school can manage their own settings. I am glad to see light speed support on here now, even on my local listserv light speed seems to me a minority. I’ll start another thread so I don’t hijack this one with my question.
-
@synaesthesia I am glad it works for you because I am switching over from deploying tcp/ip printers in computer preferences to shared printers in user preferences. I've only moved one over as a test and did not use loopback processing. I just used Item level targeting. The problem I have with switching to the shared method is my users printer connections to not show up in my inventory program. Any advice on that?
-
MimioStudio 10 Released... and Deployable
ADMaster replied to SYNACK's topic in AV and Multimedia Related
Thanks @SYNACK I will be looking into this soon.- 2 replies
-
- active directory
- deploy
-
(and 5 more)
Tagged with:
-
Hello all, I revamped our software restriction policies a few months ago with very few issues, but some computers are still hanging on to old settings. I have the default policy set to disallow and have rules to allow program files, system32, netlogon, etc. Effectively anything that is installed properly system wide will run. Anything on the desktop home drive, flash drive etc is blocked. I have several machines that will not allow users to run Google chrome, and it is installed in program files. The first machine was w7, a few weeks ago and I ended up reimaging it after trying various methods of cleaning out group policy. I now have several more, but xp with the same symptoms. Here is what I tried on the w7 machine before reimaging I ran gpupdate I deleted and let windows recreate the user profile. I messed in the registry and deleted policies to let them reapply I edited the history registry key to force a policy update. On the xp machine the only thing I have done so far is gpupdate and delete user profile. This afternoon I added another rule to the SRP to specifically allow chrome and that did not work either, but I’ll try again tomorrow to make sure it had time to propagate. Any suggestions for making chrome work on these machines bar reimaging, that would be last resort. Thank you,
-
I use webhelpdesk its not free but it is what our ITC uses so that's what we got too. It used to be made my mac design studio but they got acquired by solar winds this past summer. It is very customizable, accepts tickets through email or web interface. You can set up a number of locations and categories etc.
-
If you run allmodules it does not matter what modules are commented out because it will build them all. But to answer your question, yes I would run ./build –allmodules The other option would be to uncomment the video modules you need and rebuild with just ./build
-
Hello vitmac, Your setup is very different, I am using server 2008 as the pxe server, however you have that part working. The chrome issue There is a section in the build.conf for packages, just comment out chrome. The usb issue The path may be different for you but I added this to the RDESKTOP_OPTIONS line in the file that defines your connections -r disk:usb=/mnt/usbdevice Here is an example of my session setup SESSION_1_TITLE="Classroom Desktop" SESSION_1_TYPE=rdesktop SESSION_1_SCREEN=0 SESSION_1_RDESKTOP_SERVER=10.1.2.3 SESSION_1_RDESKTOP_OPTIONS=" -a 24 -r sound:local -r disk:usb=/mnt/usbdevice -f" SESSION_1_AUTOSTART=Off SESSION_1_ICON=On What part of 5.1.1 is not working, look through the conf files to make sure everything is set correctly and try building with all modules. Keep me posted on your progress.
-
Great article, I’ve done this procedure for the last several years with a couple exceptions. In a school most staff do not have admin rights, I can login as admin and clean up this kind of malware very quickly. I have Hiren's BootCD on hand if needed and skip the safe mode step. Another tip the article didn’t mention is that some of these mess up the registry and windows doesn’t know what to do with an exe. You will need a reg file with the correct keys to reset these to default.
-
Yes this is how I did it. I've updated to 5.1 since then, but that should be close enough. What is your environment? What part is not working? Please give more detail and I'll help as much as i can. Oh and I see this is your first post, so welcome to the forums.
-
I use MDT 2010 and WDS for imaging 2012 is out now but I haven't used it yet. I use Admin Arsenal PDQ for post image software install and updates. This is not free but priced well.
-
I have not done any research on android yet, it is something I am curious about though. for IOS apple configuator will deploy apps to IOS but only if you are connected via USB. This past summer I tried various MDM tools to push apple apps, that all claimed they could. In reality they can only push home grown apps, for apps purchased in the app store or via VPP the user is prompted for the iTunes account password. This is not ideal for schools. I have heard that IOS 6 address this and you can push apps with no prompts to the end user. If someone can confirm this I would appreciate it.
-
If you are on a 2008 or above domain functional level this is possible. AD DS: Fine-Grained Password Policies search for fine grain password policy. I set this up to allow the younger students to have weak passwords and keep staff on strong passwords. I don't recall all the details but here is the gist. use ADSI edit to create the policy in the domain edit the properties to meed your needs (length complexity etc) assign the applies to property to the group you want it to apply too. I recommend creating a security group call passwordpolicy xyz and then you don't have to change the policy every time someone needs added, just put them in that group. Hope that helps.
-
I have had this process fully automated, I posted my script here. Tech Blog: Add Users Script Have a look and see if it will do what you need.
-
Sophos offering free Unified Threat Management for Home Use
ADMaster replied to psydii's topic in General Chat
Wow lots of Sophos fans here... -
Sophos offering free Unified Threat Management for Home Use
ADMaster replied to psydii's topic in General Chat
I replaced my Ubuntu squid iptables gateway with this over the weekend. I have to say I highly recommend it. It provides so much insight into the network and where bandwidth is going. The best part is that different filtering policies and overrides are a breeze compared to Dan’s guardian. We already use Sophos here at the school, now I can have Sophos on all my PC’s at home too. I know for home use I won’t use half of the features but it is excellent and doesn’t seem to be too resource hungry either. -
When you say two networks do you mean two domains, two vlans etc? If it is only showing the sid the server cannot contact the domain to lookup the user name / group associated with the sid, or the user / group was deleted. I would make sure it is contacting the domain correctly or look into any cross domain trust issues.
-
I use WDS and MDT 2010, I have not made the jump to 2012 yet, it is supposed to be better. I have not used the other two you mention. WDs / MDT pros free, works well for what we do SmartDeployment, or Acronis Snap Deploy cons costs hopefully someone who has used the others can give a better answer.
-
Google Apps, Microsoft 365 or local Microsoft?
ADMaster replied to NetmanDH's topic in Cloud Services
I’m not worried about any technical difficulty; I’m worried about the mob of staff that will be looking for me. We have an EES agreement and I think we get plan a2 with that. It is just a point of curiosity right now. On one hand adding a new service will add confusion and will inhibit the sharing of documents if users are using both. On the other hand I could provide flexibility and a choice to the users. I would not want to use the exchange part because of the mob with pitch forks outside my office, but I think when office 2013 comes around users will ask about saving to skydirve etc. I would rather have office 365 skydrives then have a teacher telling students to create or use a personal account. Our school subscribes to curriculum that teaches the latest office, depending on how fast they update I expect to be installing office 2013 for next falls curriculum . I have plenty of time to play with office 2013 before then. Sorry if I hijacked this thread, but thought this would be a good place to put out my curiosity, and see if this is something other schools do. Thank you, -
Google Apps, Microsoft 365 or local Microsoft?
ADMaster replied to NetmanDH's topic in Cloud Services
I marked other, we have google apps for staff and students, but they also have MS Office locally. The question I would like to know is do schools use both Office 365 and Google Apps? We went Google two years ago and I don't look forward to changeing email providers again. I just read about the new office 2013 integration with office 365 and wonder if it would be good to support both GAFE and Office 365 for documents?
