CheckEmoji Community · the emoji forum
🏠 Home 🆕 What's new ❓ Unanswered 🔥 Popular 📡 RSS Members 👥 0 online log in · register
Home › IT › IT Support › Windows 7 administration tips and tricks

Windows 7 administration tips and tricks

Started by Sandra Davis7 · · 👁 2 views · 16 replies

📡 Subscribe to replies

Participants Sandra Davis7wiredcanyon94Kyle Johnson2crimsonharbor313graniteeagle25Donna Garcia
Sandra Davis7 Sandra Davis7 NewcomerOP
5 messages
joined Feb 2015
#1 ·
Hey everyone, I’ve got a bit of a situation at work I need to tackle. We have a bunch of machines running Windows 7, and my main Windows 7 goal is to keep them totally clean. I really want to stop users from cluttering everything up with files they grab from the web or via USB drives. I was thinking maybe I could handle this by setting up some rules in the Task Scheduler, so basically, every time a computer boots up, it just wipes out all the data my colleagues saved the day before. Am I on the right track with using Task Scheduler for this? If anyone knows a better way to get this done, let me know. Thanks!
wiredcanyon94 wiredcanyon94 Active Member
129 messages
joined Nov 2022
#2 ·
Sandra Davis7 said:Hey everyone, I’ve got a bit of a situation at work I need to tackle. We have a bunch of machines running Windows 7, and my main Windows 7 goal is to keep them totally clean. I really want to stop users from cluttering everything up with files they grab from the web or via USB drives. I was thinking maybe I could handle this by setting up some rules in the Task Scheduler, so basically, every time a computer boots up, it just wipes out all the data my colleagues saved the day before. Am I on the right track with using Task Scheduler for this? If anyone knows a better way to get this done, let me know. Thanks!

You're heading down the wrong path. You can't just go around deleting user data on the machines they actually use to work.
It’s better to just stop them from installing stuff they shouldn't be touching in the first place. If someone downloads a document—say, a PDF—why on earth would you delete that? You probably meant you don't want them installing whatever junk they find online. In that case, just strip away their admin rights. That solves most problems.

If you're genuinely worried about people hoarding "too much data," just set up disk quotas. Deleting people's files is a recipe for disaster. How is a script supposed to tell the difference between a critical work file and actual "time-wasting" junk?
Sandra Davis7 Sandra Davis7 NewcomerOP
5 messages
joined Feb 2015
#3 ·
They don't have admin rights—I do. They really don't need anything besides their specific work apps, and I definitely don't plan on touching those. It’s fine if they download PDFs for themselves; that isn't the issue. I can't exactly force them to delete everything immediately, though, so files just pile up until I start getting low memory alerts. Plus, there's all kinds of stuff like torrents, poker sites, you name it. As for blocking installations, I end up having to manually block every single program I catch them downloading one by one. And it's a constant cycle—once a new version of an app comes out, they can download it again, and I have to go from machine to machine all over again. Maybe I'm wrong about this, but if I am, please tell me: how can I just block all software installations permanently? Sorry, but please don't lecture me on what I should or shouldn't allow my coworkers to do. Their computers are meant to run one specific application smoothly, not crash because they won't or don't know how to clear their history or the movies they downloaded that day. Like I said, they can download what they want, but the data shouldn't just sit there clogging things up. I'm stuck cleaning up after them on nearly 100 🙂
different machines.
Kyle Johnson2 Kyle Johnson2 Newcomer
1 message
joined Feb 2015
#4 ·
Sandra Davis7 said:Am I even on the right track with this Task Scheduler thing? If anyone actually knows the best way to handle this, let me know. Thanks!

I'd probably just use it. Deep Freeze. Simple as that.
wiredcanyon94 wiredcanyon94 Active Member
129 messages
joined Nov 2022
#5 ·
Sandra Davis7 said:They don't have admin rights—I do. They really don't need anything besides their specific work apps, and I definitely don't plan on touching those. It’s fine if they download PDFs for themselves; that isn't the issue. I can't exactly force them to delete everything immediately, though, so files just pile up until I start getting low memory alerts. Plus, there's all kinds of stuff like torrents, poker sites, you name it. As for blocking installations, I end up having to manually block every single program I catch them downloading one by one. And it's a constant cycle—once a new version of an app comes out, they can download it again, and I have to go from machine to machine all over again. Maybe I'm wrong about this, but if I am, please tell me: how can I just block all software installations permanently? Sorry, but please don't lecture me on what I should or shouldn't allow my coworkers to do. Their computers are meant to run one specific application smoothly, not crash because they won't or don't know how to clear their history or the movies they downloaded that day. Like I said, they can download what they want, but the data shouldn't just sit there clogging things up. I'm stuck cleaning up after them on nearly 100 🙂
different machines.

You mentioned in your first post that you have "plenty" of computers. How many is "plenty" to you?
And also, do you have a domain? Active Directory? Do you have a centralized internet gateway, or is everyone just browsing through their own little setups?

One question though—how is someone even able to download torrent clients or install random software if they aren't an admin? You need admin rights to install things. And how are they pulling torrent traffic (or any unwanted traffic) on a controlled network where there's a single admin in charge?
If you really have "plenty" of machines, you should at least have a central firewall, antivirus, and things like that.

I wasn't trying to tell you what to restrict or not restrict for your users. That's your call, obviously. Or rather, it's management's call, and it's the admin's job to enforce company policy.

Edit:
Also, if you had a domain, you could just use Group Policy to block all (or some) USB ports, so nobody could even move files via thumb drives.

Edit 2:
Ah, I just realized you're going "from computer to computer." So, no domain. In that case, there's nothing. Without central administration, this is way harder than it needs to be.

Edit 3:
I'm exhausted today. You say you have 100 computers and you're walking from one to the next. Wait... you have 100 machines and no domain?
Good luck!
Sandra Davis7 Sandra Davis7 NewcomerOP
5 messages
joined Feb 2015
#6 ·
I'm honestly not sure how I'm supposed to handle downloading torrents; I just recently got tasked with administering these machines, and I haven't really dealt with this stuff before. I feel a bit more comfortable with routers and switches, though I guess I'm still pretty much a rookie there too. Anyway, aside from using this Deep Freeze app—which seems like a solid option right now—is it actually possible to convert the workgroup into a domain so I can manage them through Active Directory or something similar? Right now, each computer is just its own thing running standard Windows 7. They aren't connected to a Windows server or anything like that, so I'm wondering if a third-party app like Deep Freeze is my only real move here?
wiredcanyon94 wiredcanyon94 Active Member
129 messages
joined Nov 2022
#7 ·
Sandra Davis7 said:I'm honestly not sure how I'm supposed to handle downloading torrents; I just recently got tasked with administering these machines, and I haven't really dealt with this stuff before. I feel a bit more comfortable with routers and switches, though I guess I'm still pretty much a rookie there too. Anyway, aside from using this Deep Freeze app—which seems like a solid option right now—is it actually possible to convert the workgroup into a domain so I can manage them through Active Directory or something similar? Right now, each computer is just its own thing running standard Windows 7. They aren't connected to a Windows server or anything like that, so I'm wondering if a third-party app like Deep Freeze is my only real move here?

If you haven't done this before, honestly, just find someone to set up a decent domain for you. Trying to manage 100 computers without a domain is an absolute nightmare. Anything over 10 or 15 machines needs a domain. A hundred? Forget about it. How are you supposed to actually get anything done? How are they sharing files? How are you handling backups? What about software installs? Running a workgroup of 100 machines is just asking for chaos.

Of course, you're going to need a proper server to run a domain.

By the way, what kind of company are we talking about here? What do they actually do? Is it private or some government agency?
And how on earth have they managed to leave this part of their business such a mess until now?
Sandra Davis7 Sandra Davis7 NewcomerOP
5 messages
joined Feb 2015
#8 ·
We're a private call center handling inbound calls for a massive telecom giant. Most of us run one specific app, but the hardware is just... weak. Seriously, the RAM is struggling. I'm just typing this right now and the service app is running in the background, and my CPU Meter shows we're already sitting at 73% RAM usage. Of course, apps keep crashing, and we constantly get those annoying alerts saying memory is low and we should probably just restart the PC. So, I'm trying to find a way to optimize things, but I can't just download whatever I want. Even if people do download stuff, I want to make sure that data doesn't stick around and clog up the RAM and memory the next day. There's also the issue of the director—he definitely doesn't want people browsing YouTube or anything like that while they're on the clock, so he wants a fix. They tried blocking YouTube, but I ended up launching Tor to bypass all the restrictions. Now, the Tor browsers have been wiped from all the machines, so everyone is back to watching YouTube freely. That could have landed me in hot water, but since they heard I'm a computer science student and might actually know how to fix things, they decided to bring me on as an admin. So, here I am, looking for a solution to 😁
wiredcanyon94 wiredcanyon94 Active Member
129 messages
joined Nov 2022
#9 ·
Sandra Davis7 said:We're a private call center handling inbound calls for a massive telecom giant. Most of us run one specific app, but the hardware is just... weak. Seriously, the RAM is struggling. I'm just typing this right now and the service app is running in the background, and my CPU Meter shows we're already sitting at 73% RAM usage. Of course, apps keep crashing, and we constantly get those annoying alerts saying memory is low and we should probably just restart the PC. So, I'm trying to find a way to optimize things, but I can't just download whatever I want. Even if people do download stuff, I want to make sure that data doesn't stick around and clog up the RAM and memory the next day. There's also the issue of the director—he definitely doesn't want people browsing YouTube or anything like that while they're on the clock, so he wants a fix. They tried blocking YouTube, but I ended up launching Tor to bypass all the restrictions. Now, the Tor browsers have been wiped from all the machines, so everyone is back to watching YouTube freely. That could have landed me in hot water, but since they heard I'm a computer science student and might actually know how to fix things, they decided to bring me on as an admin. So, here I am, looking for a solution to 😁

Sorry, but you've got a problem that a random online forum isn't going to solve for you.
If they've officially put you in an admin role when you haven't done this before, ask them to send you to some training. Or pay for it yourself. Getting an MCSA would be a solid starting point.

And yeah, I get it—management usually hates spending extra cash on maintaining their IT infrastructure. They’d love for everything to run perfectly for zero dollars while still pumping out profit.
But reality works differently. You get what you pay for.

You can't expect a few sentences of advice on a forum to teach you how to manage 100 workstations. I mean, you *can* ask, but...
If you're responsible for 100 computers, you can't just "download" some software because some guy with a username on a forum told you it was cool and worth installing. What happens if that software chokes the system even harder or causes a total meltdown? What are you going to tell the boss? "Some guy on a forum told me it was fine"?
crimsonharbor313 crimsonharbor313 Newcomer
7 messages
joined Feb 2014
#10 ·
From what I understand—and I’m just a computer science student, not an expert—you should set it up the way they teach at a university. You’d have a central server and network all the workstations together. From there, you can deploy whatever software you need to handle the blocking. For instance, if you strip users of their admin rights, it pretty much guarantees they can't install anything extra. You could also implement disk encryption and web filtering. If you split the drive into two partitions and keep one strictly for admin tasks, you could even configure it to wipe everything clean whenever the machine shuts down, preventing any unwanted changes from sticking.

Besides, manually walking from desk to desk every single day? There's just no sense in doing that.
wiredcanyon94 wiredcanyon94 Active Member
129 messages
joined Nov 2022
#11 ·
crimsonharbor313 said:From what I understand—and I’m just a computer science student, not an expert—you should set it up the way they teach at a university. You’d have a central server and network all the workstations together. From there, you can deploy whatever software you need to handle the blocking. For instance, if you strip users of their admin rights, it pretty much guarantees they can't install anything extra. You could also implement disk encryption and web filtering. If you split the drive into two partitions and keep one strictly for admin tasks, you could even configure it to wipe everything clean whenever the machine shuts down, preventing any unwanted changes from sticking.

Besides, manually walking from desk to desk every single day? There's just no sense in doing that.

Let me say this one more time.
In a professional business environment, you simply cannot (or at least, you shouldn't) wipe everything an employee worked on the moment they shut down their computer.
That kind of setup makes sense for a public internet cafe, sure, but not for a company where that same employee is expected to show up and pick up right where they left off tomorrow.
It’s just not how things work. And it's not because employees would throw a fit—it's because it's fundamentally bad practice.
graniteeagle25 graniteeagle25 Newcomer
1 message
joined Feb 2015
#12 ·
Besides setting up disk quotas and getting those ACLs dialed in just right, you’ve also got mandatory user profiles to play with. And honestly, if you're looking at any kind of mass deployment, you're definitely gonna need a solid base image sitting on a network share—maybe something like an SMB share—and then you can just roll it out using the right tools (I'm thinking WinPE and ImageX come to mind here). As for deleting data like you mentioned... yeah, I wouldn't recommend it, but hey, if you're really dead set on doing that, maybe try using logon/logoff scripts instead of the Task Scheduler.

You could always put together a firewall based on an open-source solution (pfSense is a great shout).

Trying to handle 100 Windows-based machines with "amateur hour" administration is just pure madness.
Sandra Davis7 Sandra Davis7 NewcomerOP
5 messages
joined Feb 2015
#13 ·
How much RAM and virtual memory does a virtual machine actually eat up compared to just running standard Windows? I guess we're working with really limited RAM on our machines, and I'm a bit worried that SSD space might run dry eventually once Windows updates start rolling in. Would setting up a server, assigning domains, and spinning up VMs on these computers end up being too heavy on our resources?
wiredcanyon94 wiredcanyon94 Active Member
129 messages
joined Nov 2022
#14 ·
Sandra Davis7 said:How much RAM and virtual memory does a virtual machine actually eat up compared to just running standard Windows? I guess we're working with really limited RAM on our machines, and I'm a bit worried that SSD space might run dry eventually once Windows updates start rolling in. Would setting up a server, assigning domains, and spinning up VMs on these computers end up being too heavy on our resources?

Honestly, I think I got a little lost in your last post. I'm not entirely sure what you're asking here.

Setting up a domain makes administration easier, sure. But you don't need virtual machines just to migrate a system over to a domain.
As for how much memory a VM "eats"—it eats exactly as much as you decide to give it.

Look, if you're already strapped for memory and disk space, you're stuck. There's no magic fix. If you have so little space left that you're expecting Windows updates to wipe out the remaining capacity, there isn't much you can do. No matter what move you make, that space is still going to vanish.

And yeah, you mentioned "creating" a server. You usually have to buy one. Unless, of course, you already have hardware sitting around. Actually, if you're looking at 100 workstations and want room to grow, you should probably have at least two servers for redundancy.

Also, how are all these machines getting online? Is it just one single connection, or are there multiple gateways? What's the bandwidth looking like? Won't that choke your internet connection? Is the whole company in one building or spread across different sites? Are all 100 computers independently pulling updates from Microsoft?
Maybe consider setting up a proxy? It would save a massive amount of bandwidth. And is every single machine pulling its own antivirus updates? That alone eats up a ton of data. I'm guessing you don't even have an antivirus server right now—like a corporate setup that downloads the updates once and distributes them locally.
You mentioned users are browsing the web, downloading music, watching videos, reading news... everyone is burning through bandwidth individually. A proxy could be a lifesaver here. Not by throttling them, but by preventing 100 machines from downloading the exact same files 100 times; once one machine grabs a file, the others pull it from the proxy instead. Of course, configuring a proxy properly isn't exactly child's play.

Anyway, I'm rambling. Managing 100 workstations isn't something you can just wing. Well, maybe if it's some government agency where profit doesn't actually matter.
Donna Garcia Donna Garcia Member
19 messages
joined Mar 2015
#15 ·
wiredcanyon94 said:Honestly, I think I got a little lost in your last post. I'm not entirely sure what you're asking here.

Setting up a domain makes administration easier, sure. But you don't need virtual machines just to migrate a system over to a domain.
As for how much memory a VM "eats"—it eats exactly as much as you decide to give it.

Look, if you're already strapped for memory and disk space, you're stuck. There's no magic fix. If you have so little space left that you're expecting Windows updates to wipe out the remaining capacity, there isn't much you can do. No matter what move you make, that space is still going to vanish.

And yeah, you mentioned "creating" a server. You usually have to buy one. Unless, of course, you already have hardware sitting around. Actually, if you're looking at 100 workstations and want room to grow, you should probably have at least two servers for redundancy.

Also, how are all these machines getting online? Is it just one single connection, or are there multiple gateways? What's the bandwidth looking like? Won't that choke your internet connection? Is the whole company in one building or spread across different sites? Are all 100 computers independently pulling updates from Microsoft?
Maybe consider setting up a proxy? It would save a massive amount of bandwidth. And is every single machine pulling its own antivirus updates? That alone eats up a ton of data. I'm guessing you don't even have an antivirus server right now—like a corporate setup that downloads the updates once and distributes them locally.
You mentioned users are browsing the web, downloading music, watching videos, reading news... everyone is burning through bandwidth individually. A proxy could be a lifesaver here. Not by throttling them, but by preventing 100 machines from downloading the exact same files 100 times; once one machine grabs a file, the others pull it from the proxy instead. Of course, configuring a proxy properly isn't exactly child's play.

Anyway, I'm rambling. Managing 100 workstations isn't something you can just wing. Well, maybe if it's some government agency where profit doesn't actually matter.

In those public sector or municipal jobs, they don't really care about the bottom line, so things actually tend to run smoother there.
Private companies are the ones who stingiest when it comes to this stuff; they'll hire a college kid and think they've checked all the boxes.
wiredcanyon94 wiredcanyon94 Active Member
129 messages
joined Nov 2022
#16 ·
Donna Garcia said:In those public sector or municipal jobs, they don't really care about the bottom line, so things actually tend to run smoother there.
Private companies are the ones who stingiest when it comes to this stuff; they'll hire a college kid and think they've checked all the boxes.

Those kinds of private outfits don't stay in business long. And when their whole operation crashes because of bad IT, they immediately blame the government, politics, or everyone else under the sun.

The private owners who actually understand where their money comes from usually stick around a bit longer.

In a government office, you’ll often find someone's cousin or a former driver or a failed accountant sitting in an administrator role. Most competent American admins are either working for major corporations or have moved abroad.
Of course, you still have those "fake admins" in government jobs too. It isn't all black and white. But it's rare to find anyone truly skilled who stays in a public sector role. They stick around just long enough to learn the ropes and then they bail. What's left behind are just the "fake admins."
Donna Garcia Donna Garcia Member
19 messages
joined Mar 2015
#17 ·
wiredcanyon94 said:Those kinds of private outfits don't stay in business long. And when their whole operation crashes because of bad IT, they immediately blame the government, politics, or everyone else under the sun.

The private owners who actually understand where their money comes from usually stick around a bit longer.

In a government office, you’ll often find someone's cousin or a former driver or a failed accountant sitting in an administrator role. Most competent American admins are either working for major corporations or have moved abroad.
Of course, you still have those "fake admins" in government jobs too. It isn't all black and white. But it's rare to find anyone truly skilled who stays in a public sector role. They stick around just long enough to learn the ropes and then they bail. What's left behind are just the "fake admins."


Of course, that's how government agencies operate. They have an "admin" on the payroll who basically just swaps out toner cartridges all day. Meanwhile, they pay several outside contractors monthly to actually handle the hardware, software, and networking.

You must log in or register to reply here.

Log in Register

🔗 Similar threads