Platinum Edition Using Windows 98

Previous chapterNext chapterContents


- 45 -

Windows 98 Network Administration


by Christopher Gagnon

Windows 98 is a good choice for a client operating system in a network. This version of Windows has several built-in features that help ensure consistency of the desktop in a networked environment. Microsoft also provides several methodologies and tools that you can use to install and administer Windows 98.

User Profiles

User profiles define the Windows 98 environment for a particular user. They enable a user to make changes to the system without affecting other users. To accomplish this goal, the user profile consists of several different components. When you enable user profiles on a Windows 98 machine, you have the option of including Start Menu items, Network Neighborhood contents, and Desktop icons in the profile. In addition to these components, user profiles also store wallpaper selections, color schemes, screen saver selections, and sound schemes. This section describes how the system stores a user profile.

Anatomy of User Profiles

When user profiles are activated on a Windows 98 machine, the system stores each user's profiles in the C:\Windows\Profiles folder. Looking through this folder structure for a specific user can help you understand how profiles work. Figure 41.1 shows the basic structure of the profile for user JohnDoe.

FIG. 41.1 A user profile is stored in the Windows folder.

Notice that the profile structure contains many of the folders that you can find under the C:\Windows folder. When you enable user profiles, Windows 98 creates a structure for each user that mimics the standard profile structure. The following folders are created in a user's Profile folder:


NOTE: Depending on the software you install, the program group may be placed in the profile of the user who installed the software or it may be available for all users. Microsoft Office places icons for all users on the system, whereas other programs may not do so. You can make programs available to all users by copying the program group to the All Users profile, which is located in C:\Windows\All Users. 

Enabling User Profiles

The process for configuring roaming user profiles in Windows 98 is identical to the process used for Windows 95. The first step is to enable user profiles on the machine (see Figure 41.2). To enable user profiles, follow these steps:

1. Open the Control Panel.

2.
Double-click on the Passwords icon.

3.
Select the User Profiles tab.

4.
Select the second box: Users Can Customize Their Preferences and Desktop Settings.

5.
Select the user profile settings you want.

6.
Click OK.

Roaming User Profiles

Roaming user profiles enable you to define a standard desktop that follows a user from machine to machine. This feature is ideal for users who have to log on to several different machines and want to maintain the same look and feel on each machine. This section describes the process of creating roaming user profiles.

The first step in setting up roaming profiles is to enable user profiles as just described. The second step is to modify the user's account on the Windows NT domain to specify a home directory that resides on a Windows NT server. Windows 98 saves a copy of the user profile on the home directory during the shutdown process. When the user logs on at a different machine, the profile is read from the server.

FIG. 41.2 User profiles are enabled in the Control Panel's Password Properties window.

Troubleshooting Roaming User Profiles

One of the most common problems with roaming profiles is an unstable connection to the server where the profile is stored. If a user receives a standard profile when logging on to a system, you should check the following areas:

Zero Administration Kit

The Zero Administration Kit (ZAK) is a collection of processes and procedures for installing Windows 98 workstations that require little administrative overhead. These processes can be used to automate an install process or even to design an entire connectivity solution for non-power users.


A Note from the Author
Because ZAK is a set of documents and methodologies, this book does not cover the process of creating a Windows 98 load in great detail. The actual process of designing a ZAK installation depends on the requirements of the users. I strongly recommend that you read all the ZAK documents before attempting to design a ZAK solution.

Overview

Microsoft operating systems have traditionally contained procedures for implementing an unattended setup. Although these features have been around for several OS versions, their use has been poorly documented. The ZAK is an attempt to bring these features into the light. ZAK consists of several documents and utilities that distribute and control Windows 95, Windows 98, and Windows NT workstations. As any administrator knows, every business has its own specific IT needs. In addition, every department in the business has specific functions that may not be needed by other departments. Granting levels of access and control to users that do not need them can lead to an administrative nightmare.

Consider the following example:

Two departments found in many medical centers are the fiscal and pharmacology departments. The fiscal department requires both billing and office productivity software. The pharmacology department may require patient records and pharmacology software.

A possible IT solution might include placing a Windows 98 PC on every desk in each department with the required software installed. This solution would meet the needs of each department but can also lead to some user issues. People are naturally curious and will undoubtedly want to explore the system.

ZAK provides procedures that enable you to create a standard Windows 98 load for pharmacology that allows the machine to access the pharmacology software and the patient records database only. You can use the same method to create a standard load for the fiscal department. By restricting access to the required software, you considerably lower the risk of problems on the machine.

Because there is no customization on the desktop, you can replace a bad machine quickly and easily. For example, if someone in the fiscal department is experiencing problems with a machine, you can replace the machine with one that has a fresh load installed. Because there are no individual settings, the user will be ready to start working the minute you boot the new machine.

This solution also saves time for your IT staff members by allowing them to fix a user problem without worrying about a lengthy troubleshooting process.

System Policies and Profiles

System policies and system profiles are two ways of securing a user's environment. System profiles define the user's workspace. When you use individual policies, each user that logs on to a particular machine can modify the environment without affecting the environment of other users on the same machine. System policies enable the administrator to define a set of security policies that govern how a machine is used by any particular user. For example, you can use system policies to prevent users from running an MS-DOS command prompt. ZAK provides instruction and methodologies for applying system profiles and policies.


CAUTION: System policies edit the Registry of the client machines and can easily cripple a machine to the point of requiring the operation system to be reinstalled. It is a good idea to setup several "crash and burn" systems so that you can test all aspects of the profile before you implement it in a production environment.

Unattended Installation

One of the biggest issues with installing a client operating system at a large site is the installation process. Installing 1,000 Windows 98 machines using the standard installation process can be a grueling and unruly process. Not only do you have to touch every machine, but you also take the risk of accidentally configuring each machine differently. Standardizing your machines greatly reduces troubleshooting time. In addition to the control features, ZAK provides a method for creating an unattended, standardized installation process for your workstations.

ZAK Windows 98 Configuration Options

ZAK defines two specific workstation types that can be used to create an overall solution for a specific IT need. In addition to these two types, you can use ZAK to create an unattended installation of Windows 98 that does not apply policies and profiles. This feature enables you to use ZAK to install Windows 98 in a standard format with no restrictions applied. The three types of ZAK installation types are vanilla, Appstation, and Taskstation.

Vanilla Install  

A vanilla install results in a workstation that is virtually identical to a workstation that was installed with the Windows 98 distribution media. You can use this process to speed the installation of Windows 98 on a large number of machines that require no specific access restrictions. This process is similar to cloning machines with products such as Ghost. The process involves configuring a reference machine with all required software, taking a snapshot of the system, and using this snapshot to implement an unattended install of Windows 98. All machines created in this manner are exactly the same, which helps you standardize your site.

Appstation  

An Appstation is a Windows 98 machine that allows access to certain applications only. At first glance, an Appstation looks like any other Windows 98 machine. The difference is seen when you click on the Start Menu. The Start Menu contains links only to approved applications. The applications reside on a network server and run over the network. All user data is saved to a network location as well. This type of workstation is easily replaced if problems develop because the local machines do not store any data. In addition, users cannot change their settings because the workstations have no link to the Control Panel or to the MS-DOS prompt.

Taskstation  

A Taskstation takes the control one step further. Some users only need access to one specific task. For example, an order entry clerk only needs to access the order processing database. If you configure the clerk's workstation as a Taskstation, the machine boots to the order processing application and the screen has neither a Taskbar nor a Start Menu. The user has no reason to use anything else on the system. A Taskstation is designed for running one specific task and basically turns Windows 98 into a kiosk.

Internet Explorer Administration Kit

The Internet Explorer Administration Kit (IEAK) is a suite of utilities that enables you to customize the Internet Explorer and web interface settings for Windows 98. Because IE 4.0 is integrated with Windows 98, these tools can be invaluable to the administrator of a Windows 98 network.

Overview

IEAK consists of two utilities that can be used to fully administer the Internet Explorer components of Windows 98. The IEAK Wizard is used to create a custom distribution of Internet Explorer 4 and is not as important when you are administering a Windows 98 network, because IE 4.0 is integrated with the operating system. You can use the IEAK Profile Manager to create profiles to control the clients. As an administrator, you can use these tools to control how your users view the web components of their systems.

IEAK Wizard

The IEAK Wizard creates distribution media for Internet Explorer 4.0. However, this handy tool is unnecessary when your clients are running Windows 98. The IEAK Wizard is used primarily for creating the distribution media for Windows 95 and Windows NT Workstation machines. This tool is less important in a Windows 98 environment and, therefore, is not covered here.

IEAK Profile Manager

The IEAK Profile Manager enables you to create an Internet Explorer profile that you can use to control your clients. You can then use the Windows System Policy Editor to apply the Internet Explorer policies to your users.

Wizard Settings

The Wizard Settings (see Figure 41.3) properties enable you to change some of the basic properties of Internet Explorer. These options are identical to the options in the IEAK Wizard but can be used here to modify the properties with an Internet Explorer policy. The Wizard Settings options are described in this section.

Browser Title  

The Browser Title component enables you to customize the browser with your company name. The selections are as follows:

FIG. 41.3 The Wizard Settings enable you to modify the settings for the browser itself.

Support Page  

The Support Page section enables you to specify the URL that will be accessed when the user chooses Online Support from the Help menu. This feature is handy if you have an internal web site that deals with system support issues.

Favorites  

You can use this section to customize the Favorites folder for every client. This way you can have a list of URLs available for every user. The selections are as follows:

User Agent  

A user agent string is what a web browser uses to identify itself to web servers. You can use this section of the IEAK Profile Manager to add a text string such as your company name to the user agent string. This string generally keeps Internet usage statistics.

Proxy Settings  

You can use this setting to define any proxy servers that may be in use on your network. This component is one of the handiest for a network administrator. Because all users on the network use the same proxy servers, controlling this section centrally eliminates the burden of changing this setting on each machine.

Start and Search Page  

This section enables you to define both the Home page and the Search page. The Home page is the page that opens when you first launch Internet Explorer. The Search page can be accessed by pressing the Search button on the Internet Explorer button bar. To modify these settings, simply type the desired URL for each page.

Import Channels  

The Import Channels section enables you to modify the Channel bar. This section has options for adding, deleting, and importing channels.

Import Software Updates  

This section is similar to the Import Channels section in that you can customize the Software Distribution Channels. To make changes to this section, you should keep the IEAK Profile Manager open while you make changes to the Software Distribution Channels. Any changes made while the IEAK Profile Manager is open are saved into the profile.

Outlook Express  

This section enables you to configure the mail settings for Outlook Express. The available options are

LDAP Settings  

This section enables you specify a server that uses LDAP to provide directory access services to your client machines. The options are as follows:

Outlook Express Customizations  

You can use this section to customize the Outlook Express Info Pane to display the HTML file of your choice. You can also specify a welcome message that will be placed in every user's inbox. The options on this page are as follows:

Signature  

This section is used to attach a block of text to every email message and Usenet posting sent from Outlook Express. For example, you might want to place a disclaimer at the end of every message for legal purposes. The Signature section has two text boxes so that you can define separate messages for mail and newsgroup messages.

My Computer and Control Panel Web View Customization  

You can use this section to add specific web views to both the My Computer and Control Panel windows. This feature can come in especially handy as you can create an HTML file that has instructions on how to complete a task in My Computer and have those instructions displayed as the background of the window. You can also create a file that says Keep Out! for the background of the Control Panel window.

Automatic Browser Configuration  

This section defines the INS file that updates Internet Explorer on each client machine. Without this setting, Internet Explorer would have to be reinstalled for the changes to take effect.

Security Zones and Content Ratings Customization  

This section enables you to customize the settings for the Security Zones and Content Ratings on each client. You can use this tool to prevent access to sites with questionable content that is against corporate policy. Choosing the Modify Settings button for either option launches the Internet Explorer dialog box for that option.

Site Certificate and Authenticode Settings  

You can use this section to modify Site Certificate and Authenticode settings. By modifying these settings, you can prevent your users from accepting and running unauthorized browser plug-ins. Changes here can also prevent the users from designating any software publishers as safe. As in the Security Zones section, choosing Modify Settings launches the Internet Explorer dialog boxes for the settings.

System Policies and Restrictions

The System Policies and Restrictions section contains configuration parameters for the additional components of Internet Explorer such as Outlook Express and Microsoft NetMeeting. It also enables you to set general interface and connection policies (see Figure 41.4).

FIG. 41.4 You can use the Policies and Restrictions settings to enforce restrictions on some of the additional components of Internet Explorer.

Microsoft Chat  

This section enables you to predefine the settings for Microsoft Chat. This application is a utility similar to Internet relay chat (IRC) that combines comiclike graphics with real-time chat. The options for this section are as follows:

Microsoft NetMeeting  

This section restricts usage of Microsoft NetMeeting. The following options are available:

Internet Restrictions  

This section enables you to set the options available in the Internet Properties control panel. The settings are as follows:

Internet Settings  This section enables you to set miscellaneous Internet Explorer default properties. The settings are as follows:

Outlook Express  

This section enables you to set up Outlook Express security policies. The options are as follows:

Web Desktop  

This section enables you to restrict access to certain components of the operating system for users that are using the web desktop. The components are as follows:

Subscriptions  

This section enables you to control the amount of information downloaded from channels that your users are subscribed to; that is, to regulate the bandwidth being used. This section has the following options:


Previous chapterNext chapterContents


© Copyright, Macmillan Computer Publishing. All rights reserved.