Is it doable, or are there security flaws in the design? It's something I drew up really quick in class.
Any suggestions would be appreciated!
Server Spec's - 8 Core / 16 Gig's / Raid 1 hardware controlled configuration
Main OS - Citrix (Debian)
VM1 (2 CPU cores / 4 Gigs) - Debian
VM2 (2 CPU...
I'm changing from using Debian as a firewall (can only block ports for IP's, nothing more), an I'm making everything KISS. So I'm switching the firewalls to Server 2008 with Forefront.
Internal IP Addressing - works great! Everything is fine.
External IP Addressing - issues;
I set the IP...
Server 2008 can not remove "Log Off" from Windows 7.
GPO > User Config > Policies > Administrative Template > Start Menu and Taskbar
Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands "Enabled"
Remove Log Off from the start menu "Enabled"
I need to make "Log...
GPO > User Config > Policies > Administrative Template > Start Menu and Taskbar
Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands "Enabled"
Remove Log Off from the start menu "Enabled"
And still, in Windows 7 "Log Off" remains. But in Windows XP it doesn't exist.
Question!
Why are you using a DC with AD in your house?
You can name your DC "DC" and your network "HOME". All the computers would join "HOME" and would be "ComputerName.HOME"
Also, why not log in the as local admin. "My Computer (right click) > Users Groups > Users" now here you want to...
Well, the XP .MAN Profile is not an issue. Created another user, that wasn't linked to the .MAN profile.
Same GPO
nhpac (.MAN user)
nhpac7 (not linked to .MAN profile)
Same result, "Log Off" not there.
Well, through editing the registry, I was able to remove Switch User and Lock PC from the Start Menu. I'm still stuck on removing "Log Off" from the start menu.
Not sure why, but Active Directory will not do this even though I have it set to remove it already.
Another side note!
The XP machines load a ".MAN" remotely stored profile from the Server. Windows 7 doesn't use this style profile any more, or at least that I know of. I'm not sure if this could be causing any issue or not. But it still doesn't explain the two issues I'm having, as these are...
This is probably an easy fix, but I'm pounding my head over it.
DC's on Server 08
PC's on Win 7
I have for a specific user "Command Prompt" is disabled.
I too have "Log off" removed through AD.
For some reason, even w/ the DNS's set properly, the "Log off" is NOT removed from the startup...
Domain Controllers are Server 08
Local machine my fellow employee is using is Windows 7 x64
My Boss put another PC on the domain, and just gave it a name, but not the name I told him. So there was a name conflict and consequently caused a disconnect in the kerberos handshake. I fixed the name...
Batch file no longer needed. I was able to go though, and strenuously set permission for only 3 users for the specified Mandatory profile stored on the server. Nothing is saved upon exit/log off of the machine/user. Everything goes right back to square one!
Also having issue with Script's. Tried making a script to clean the 3 user desktops as such;
ECHO Y | DEL C:\"Documents and Settings"\nhpac\Desktop\*.* /s /q
ECHO Y | DEL C:\"Documents and Settings"\fapac\Desktop\*.* /s /q
ECHO Y | DEL C:\"Documents and Settings"\fwpac\Desktop\*.* /s /q
in a...
Almost exactly like the title says.
On my AD Server, I made a folder, shared it. Went to a local computer, deleted the user profile, logged in to create a fresh new one. Copied the user profile to a thumb drive, transported it to the Server. Changed "NTuser.DAT" to "NTuser.MAN" and changed...
Figured it out.
1) Log into a local machine, as user you want to create a Mandatory profile for.
2) Log out
3) Log back in as local admin
4) Copy the users profile from "Documents and Settings" that you would like to make Mandatory
5) Create a shared folder on local DC, and place the copied...
Okay, so I've only fought with this for roughly two days now.
I just did a bunch of updates, and set all the local computer profiles from ".DAT" to ".MAN"
For some reason, some of these, some how changed back to ".DAT"
Also, I changed permissions to the Desktop so that users CAN NOT...
Ahh!
Everything is working perfectly again! Everything's syncing as it should be, patrons are able to use the PC's like in the past. An now I've got to find out why my ".MAN" NTuser profile wasn't loading. But I just got that under wraps!
Thanks for the help all!
Scott
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.