Jump to content

zebwainwright

Members
  • Posts

    6
  • Joined

  • Last visited

Everything posted by zebwainwright

  1. This guide is a good one. I have been going through this migration from Deep Freeze for the past year and there are lots of little gotchas you will run into. I'd be happy to help in any way I can.
  2. Hi, We are having a lot of difficulty getting mandatory profiles to work on our Asus T100TA tablets. We really need to lock them down and Deep Freeze is not an option as they don't have Ethernet ports so we can't WOL to thaw them and push out updates and software. And we have 1200 of them, so manually touching them is not an option. The OS is Win 8.1 Enterprise x86. Basically, as soon as we log on with an account set as a mandatory profile everything works but the Modern and Native apps. When you first go to the start screen they all show up. Then a little progress bar appears next to them and they error out. My understanding is that it is trying to "Install" the apps for the new user. Since it is a mandatory profile it is considered a new user every time right? I don't think it's permissions because all domain users are set as standard users but if I make that account a standard profile it works fine. There error I get when I try and actually open an app is "This app cannot be installed. Check the Windows store for more info." I am open to other ways of locking down these computers, but really want to use mandatory profiles. There has to be something obvious that I am missing. Here is what I have tried so far: - Make that account a normal, non-mandatory account and log in. The apps work. Then I copy all the data from C:\USERS\\AppData\Local\Packages to a flash drive. - Delete that account and then make it mandatory again and log-in with the mandatory profile. - Log-off and log in as admin and copy all the files into the Local\Packages folder - Give the user full permissions to Program Files\WindowsApps Tried the same thing but copied the entire LOCAL folder over. I know the apps and settings are user specific, so there is something in the way I am creating my mandatory profile, or in the profile itself. I am creating the profile by creating a profile, naming it Default, and then editing the registry to change all instances of the current user to %uersname% and giving everyone permissions when I copy the profile.
  3. I think we might need to go that direction.
  4. Ok, I posted something similar to this already, but didn't get many responses. We can hide all the drives and prevent them from getting getting there using most methods, but the problem is if they open a program like paint, they can save as and it lets them type in c:\ and then they can create new folders and files on the root of the C: If I could find a way to prevent write access to the root without messing stuff up then I would be all for it. Either that or have a script that deletes every file and folder except the ones that are there when the computer is imaged (windows files etc.) Any thoughts on how to do this??
  5. Thanks for your reply. We were not planning on going that direction because of the amount of variables in the schools. I guess we could have many different redirected start menus and desktops, but our district has decided that they give every student a blank start menu and they can just search for their software. I might end up doing a start menu with 99 percent of the programs they need, and leave all programs so they can browse to anything else. They just wont be able to search.
  6. So, my district is very antiquated and stuck in their ways. They have been using Deep Freeze forever as a crutch. I have been tasked with locking down student labs with Group Policy and have it almost all the way done except for one specific part. I need to prevent students from writing to the root of the C: drive. Here is what I have tried. The students are standard users, so they can't modify other parts of the C:\ but they can create folders and add files to the root. 1. I can hide the drives. This works, but they can still browse to the drive by typing in the path. Thus, they can still write to the root. 2. I can prevent access to the C:\ through GPO, which works, but here is the kicker....they must retain search functionality using the search box on the start menu. If I enable this policy, then programs like Word, Powerpoint, Chome don't show up. I would be ok with that, but the people in charge want this functionality. 3. I can not enable either policy, and go into the drives Properties > Security > Authenticated Users > Advanced > Change Permissions for Authenticated Users > Disallow Create Folders/Append Data and Create Files/Write Data ------->I can do this, but I am not sure if it will break anything, and also, I can't for the life of me figure out a way to script it. I find some articles on doing similar stuff in PowerShell but not for this exact scenario. And just so you can have some background info, currently every student in our district is using a generic login. no password. AND that generic accound is a local administrator. Getting rid of Deep Freeze has been such a battle. Our techs are worthless and don't know how to troubleshoot. thats why they like it. "Just reboot the computer." It's a crutch. My challenge is to basically give them a computer that functions as much like a normal computer as possible. I can lock down everything on the computer, but management won't allow that. The students are taught to search for their program in the start menu. We don't pin anything there. The theory is that we don't want to give them a dumbed down workstation because when they get out into the real world they will have full-blown access to their computer and won't know how to use it.....uhhhh hello???? Universities aren't going to give them full admin access!!!! And most likely their work won't either!!!! Sorry, but I feel like I am fighting with morons.....
×
×
  • Create New...