Showing posts with label 5118. Show all posts
Showing posts with label 5118. Show all posts

Thursday, July 10, 2008

Are UAC related problems permission related or security related?

This is effectively the debate going on in my virtual classroom right now. One of the questions in Assessment 3-1 triggered the debate, as two of my students didn't choose UAC as a possible cause of a security related issue and two did.
The one side is arguing based on the material in the book. Several questions are expecting a textbook answer and UAC is explicity referred to in a paragraph above the security related issues and not under the security related heading.

This is the way I see it:
UAC is based on controlling access to ressources based on which privileges a user has at the time of executing a program. with UAC on, that would be the least priviliges required to run an applicaiton. Priviliges mean effectively permissions on files, settings and folders.
When we talk about security we usually differentiate between physical security, securing access to the data and securing the information itself.
  • We put our servers into locked rooms to secure the physical aspect
  • We put firewalls and passwords in place to secure access to the data
  • We put encryption in place to secure the information itself contained in the data.
Where does UAC belong? in the middle section. Securing access to data. By requesting elevated permissions or even an username and password to continue executing a piece of code or accessing a certain file or setting, we have another layer of access security in place to protect our systems.
Thus when anybody asks me if UAC could be a possible cause for security related installation or execution problems I'd go for "yeah, sure it is. look there first!"

Be sure to mention to your students that the paragraph in Module 3-1 headed "Security-Related Problems" should reall be labelled "Other Security-Related Problems" to avoid this discussion :-)

Wednesday, July 9, 2008

5118 AL Module 3-1 Demonstration

Something I noticed today and want to share with fellow MCTs.
In Module 3-1 there is a flash based demo showing how to use the compatibility settings wizard through control panel.
The steps are really simple and you should demonstrate this directly on the vpc instead.

The reason I say that is twofold.
  1. one of my students actually had a problem loading the demonstration and missed out on it, which forced me to give everybody a quick run down anyway.
  2. you can easily answer questions using the vpc directly and show alternate paths. For example show the students that right clicking a exe file and changing the compatibility settings there will also allow you to troubleshoot that particular application.

Scenario IE7 Problem

One of my Students had problems getting the toolwire scenarios to run. The whole intro would work but when it came to the lab it simply would not load.
The labs use a vpc activeX control which in his case did not run under the custom security settings he had in IE7. After adding the site to the Trusted Sites Zone AND resetting the trusted sites settings to its defaul level of medium, the lab excercicse loaded correctly.

Just a tip if you come across this particular problem with your students in future

Friday, July 4, 2008

5118AL Teaching Tips

Over the next few Posts I will share with you all my experiences from teaching 5118 using MODL and Livemeeting.
Today I'll start with some general tips on organising the material

  1. Add page refrerences to the instructor manual & Slides

    The page numbering in the instructor manual does not match the student workbook. That makes it really hard to point things out to students in the book. I found it really useful to create references in my instructor manual and on the slides to the individual pages in the student course book so I could direct them to the correct pages without having both books open all the time. Directing the students is an important task during the session to encourage them to write into the book.

  2. Add Headings to the whiteboard pages

    to instruct the students about the task at hand. Using the slide name can be sufficient in most cases. That really helps the student remember what they are supposed to be doing right now.

  3. Create real world demonstrations

    Create a copy of one of the vista vpc images and bust it by killing the bcd config or deleting winload. That will show nicely how a startup failure looks like. and allows you to fix it in the demonstration. How to bust it? start the vpc using either a Vista DVD and enter Recovery Environment or make your own WinRE PE iso file. Before busting it, activate System Restore and create a manual restore point. You can use that in one of the demonstrations too! Much bettern than "ahhm, and now you would see XYZ". This image cna now be fixed using the console, the startup-repair or the system restore tool in RE.

  4. Upload flash animations and web pages to web server

    Normally I'd upload the flash animations for the course directly to the livemeeting session. But with 5118 the flash files don't work by themselves and only work in a web page. Thus I uploaded them to our webserver and made them available via a Web Page in livemeeting. As each student can control the media individually this way I asked them all to change their colour to green once they had finished viewing the content. That worked like a charm.

  5. Upload flash games to the web server

    uploading all flash media to a web server instead of to the livemeeting session directly also allowed each student to try out the sorting game themselves. and that was definately more fun than writing down the answers in the book or aksing them to start the game from the student cd.

  6. Check the assessment forms before you send them out!

    Most of them have Polarbear's Logo on the Feedback worksheet and I assume you might want to exchange that with your company logo. Also fix up the references on the feedback sheet. Two cells (E14 anf G17) are not referring to the answer sheet but have fixed values instead.

Monday, June 16, 2008

5118AL Maintaining and Troubleshooting Windows Vista Computers

Alas, I will be holing a 5118AL Distance Learning session next week. Starting 23rd June through to 07 July we will be holding three sessions a week and are planning on having loads of fun along the way. Vista has proven to be a groovy new OS and demand for training is rising steadily.
If anybody wants to join in on the fun, contact Felicity Neate at Ace training ltd info@ace.co.nz.
Here is the general outline of the distance learning course and what we will be covering over those two weeks:

Course Outline
Module 1-1: A Troubleshooting Methodology
This module explains what a troubleshooting methodology is, its role in an enterprise, and how it can be used to improve the support function within an organization.
Lessons:
  • Overview of a Troubleshooting Methodology
  • Overview of Troubleshooting Stages
  • Troubleshooting Component Areas
Lab 1-1: Preparing for Remote Troubleshooting
After completing this module, students will be able to:
  • Identify the users of the troubleshooting methodology.
  • Identify the most important troubleshooting component areas.
  • Determine which issues directly affect the troubleshooting process.
Module 1-2: Troubleshooting Operating Systems
This module explains how to identify and troubleshoot issues that affect the operating system's ability to boot and the services that it is running.
Lessons:
  • Overview of the Windows Vista Startup Process
  • Troubleshooting the Windows Vista Startup Process with Windows RE
  • Troubleshooting Operating System Services
Lab 1-2: Troubleshooting Operating Systems
After completing this module, students will be able to:
  • Identify the available recovery options in Windows Vista.
  • Determine the capabilities of each recovery option.
  • Troubleshoot operating system services.

Module 2-1: Troubleshooting Hardware-Related Problems
This module explains how to troubleshoot hardware-related problems and how to use Windows Vista tools to troubleshoot device problems.
Lessons:

  • Overview of Troubleshooting Hardware
  • Dealing with Physical Failures
  • Dealing with Device Driver Failures
  • Troubleshooting Printing in Windows Vista
  • Troubleshooting BitLocker-Protected Computers

Lab 2-1: Troubleshooting Hardware

After completing this module, students will be able to:

  • Identify basic types of hardware-related troubleshooting problems.
  • Determine problems related to hardware failures.
  • Determine problems that are caused by device drivers.
  • Diagnose common printing problems in Windows Vista.
  • Identify the recovery options for computers protected by BitLocker.

Module 2-2: Troubleshooting Security Issues
After completing this module, students will be able to troubleshoot issues that are caused by security-related configurations, such as User Account Control (UAC) and Windows Firewall.
Lessons:

  • Overview of User Account Control
  • Troubleshooting User Account Control
  • Implementing Windows Firewall
  • Implementing Windows Defender

Lab 2-2: Troubleshooting Security Issues
After completing this module, students will be able to:

  • Explain the User Account Control architecture.
  • Apply best practices for working with User Account Control.
  • Troubleshoot User Account Control-related problems.
  • Troubleshoot Windows Firewall-related issues.
  • Configure Windows Firewall by using Group Policy.
  • Troubleshoot Windows Defender-related issues.
  • Configure Windows Defender.

Module 3-1: Troubleshooting Applications
After completing this module, students will be able to troubleshoot problems that are caused by some applications which are not compatible with Windows Vista.
Lessons

  • Windows Application Troubleshooting
  • Web Application Troubleshooting

Lab 3-1: Troubleshooting Applications
After completing this module, students will be able to:

  • Troubleshoot Windows application problems.
  • Troubleshooting Web application problems.

Module 3-2: Maintaining and Optimizing Windows Vista
After completing this module, students will be able to identify tools that can be used to maintain a healthy operating system and optimize its performance.
Lessons

  • Maintaining Windows Vista
  • Optimizing Windows Vista Performance
  • Monitoring Windows Vista

Lab 3-2: Maintaining and Optimizing Windows Vista
After completing this module, students will be able to:

  • Identify Windows Vista maintenance tasks.
  • Identify Windows Vista optimization tools.
  • Explain the Windows Vista monitoring process.

Thursday, April 3, 2008

5118 Vista Recovery Environment ISO File

I've been prepping 5118 as well as 5119 and came a cross a great idea. How about creating a real startup failure and recovery process for the students in the lab instead of using the simulation.

Following things you will need to do for this:
1) create a copy of one of the lab machines (Vista-CL1-02 is as good as any)
2) capture your favourite PE, RE or Vista Insall ISO
3) delete a super important system file like the winload.exe
4) make sure to save the changes by merging the disks

Ok, Maybe step 2 is not as easy as it sounds. So here is some help along the way:
Vista PC Guy has a nice article on creating PE images, where he also talks about creating bootable USB versions. http://www.vistapcguy.net/?p=71
But we want a recovery image and not a PE image. More importantly we need the Startup Recovery tools "srt" loaded at startup. This is what you do:

1) Follow PC Guy's teps 1 thru to 8 to create a clean winpe image. Or use the one you extracted out of the 5119 course iso file using WinRar or PowerISO or IsoBuster or whatever ISO app you like.

2) Add the RE tools to the image by using the BuildWinRE tool located in the "C:\Program Files\Windows AIK\Recovery" folder. Remember to use the WinPE Command Prompt instead of the standard one to have all paths properly loaded. It is as simple as defining the source and destination. In my case (having created the pe folder myself using AIK) it looked like this:

C:\Program Files\Windows AIK\Recovery>BuildWinRE /source "C:\winpe_86\ISO\sources\boot.wim" /target "C:\winpe_recovery\ISO\sources\boot.wim"


3) final step is to take this RE image and make a bootable ISO file using oscdimg:

C:\Program Files\Windows AIK\Tools\PETools>oscdimg -lVistaRecovery -b"C:\Program Files\Windows AIK\Tools\PETools\x86\boot\etfsboot.com" -n -h c:\winpe_recovery\iso winrecovery.iso

Important here is to remember to reference the etfsboot.com, otherwise the iso won't start at bootup.

That's all, now you can start up your virtual machine using the recovery console, start the command prompt, and kill c:\windows\system32\winload.exe and then close the machine commiting changes.
The next time your student will start up that machine he/she'll see a wonderful error message and can boot into the recovery console and choose to repair the system following the steps outlined in the coursebook and simulation. No need for ten Vista Installation CDs!

By the way, it is a great iso file to burn to CD and use as Desktop Support Engineer to troubleshoot users computers.