Jump to content

GVadmin

Members
  • Posts

    2
  • Joined

  • Last visited

Reputation

0 Neutral

About GVadmin

Personal Information

  • Location
    United States
  1. We do not have a GPO to hide the drive. We have found that causes more headaches for us in the past, though it may be a thought to revisit. As for how we are doing the image, we are using the MDT. We have created an Answer file to use with our generalized image and we are using a VM to create the image before uploading it using a Fog Server. Maybe we are missing something in the answer file or the imaging process that is allowing all users access to all user's files? Also, we have just noticed that the "tech" folder we have created is populating itself in EVERY user's My documents on login. IE- when the image was created, the only user was a local admin. After imaging, the machine is added to our domain, and when any domain user logins in for the first time, the files that were originally in the Admin's my documents are also showing up in that domain user's folders as well. What could be causing that?
  2. Hey everyone, unsure if this is the correct location for this question, but here goes, First post here as we are having some issues at my job. We're a small sized school district and we are in the process of currently attempting to create a universal image to roll out across the district. As part of the initial process, we are following a spiceworks directed tutorial to create the image and we are enabling the local administrator account. After imaging, there are a few other things that need to be done on each individual machine so we have a "tech" folder set up to allow our techs to go step by step to get the machine to where we want it to be. Once a machine is imaged, it is then added to our domain. The issue we are having is that whether we place this folder on the desktop, the Admin's desktop, or the Admin's My Documents folder: any other user on the computer (even non-admins) are getting access to the Administrators user folders (including desktop and documents). This means that any enterprising student can search hard enough and find it, and then access the files in the tech folder. Now, it is our practice to then disable the local admin account after imaging, before sending the machine out. However, on the off chance one of the techs forgets or has a lapse in procedure, this could result in a few non-critical, but still important, pieces of software being accessible to all users. Our question is this: What could be causing this lapse in policy? Or are we misunderstanding the way Win7 operates the local Admin account? Our understanding is that no users should by default have access to the Admin's files, so there must be something in the way we are creating the image that is causing this issue. Is there something we can do using domain GPOs or local GPOs to prevent this? The image we are using is a SYSprepped, generalized image of Windows 7 professional, 64bit. Our domain is using Windows Server 2008 R2. We have fairly strict GPOs on our domain, but are unsure where to locate this specific issue. Any help would be greatly appreciated, and if there is any other information needed, I will be glad to provide what I can. Thanks!
×
×
  • Create New...