Preparing to install USOSync in schools
•USO-AutoUpdate must be installed before the USOSync installation can take place. If your school does not have AutoUpdate please raise a support case to request it.
•The server has to be a Windows 2008 R2 and above. We will need to know the domain controller information and details on the home area server if different.
•Remote desktop needs to be enabled on the server in question.
•Wavenet Education needs to be provided with an administrative account on the server for use by Wavenet Education. This account needs to stay active after the installation.
Please make sure UAC has been turned off. If UAC cannot be turned off on the server Wavenet Education will need to use the administrator account for installation purposes.
If there are existing accounts within the Active Directory the school needs to decide if they are to migrate these or allow new accounts to be set up and the existing accounts to be phased out. If you wish to migrate the existing accounts, please convert their existing accounts to USO accounts.
Paperwork required for all schools
A USOSync form must be filled in and submitted to Wavenet Education. All USOSync forms can be obtained from the support site (under Resources >> Forms) and need to be attached to a case on the same site by a Nominated Contact for the school This has to be the same person who is the named person on the USOSync form. If a school has any additional technical questions regarding the installation process then they can be asked via the support case.
A purchase order or funds for the payment of the USOSync installation fee (£317.50 + VAT) must be received before installation can be booked. Normal follow-on support is included in the installation price. However, if the school makes any local changes which stops USOSync from working as intended, then Wavenet Education will undertake to resolve the issue at a cost of £100 per hour.
Preparing your server for USOSync
To prepare the server for a USOSync installation the school must do the following:
1.Make sure RDP is enabled on the server
2.Make sure the account to be used by Wavenet Education has sufficient permissions to carry out all necessary actions.
Change the password policy on the server (which maybe set via Group Policy) to include the following:
a.Enforce Password History: set to 0 – make sure defined policy is ticked
b.Max Password age: set to 0
c.Minimum Password age: set to 0
d.Minimum password length: set to 3 or 4
e.Complexity of passwords: disable
3.Physical home area location should be decided on and checked that there is enough space for the home areas.
To create the account to be used by USOSync please follow the steps below:
1.Create account in the AD with the SamAccountName/UserPrincipalName of “atomusosync” please set the same password as the original account you provided. If this is not possible please let us know what the new password is.
2.Add the new account to "Account Operators" and "Remote Desktop Users" groups in the AD.
3.In Active Directory Users and Computers, make sure Advanced Features is enabled in the view menu. Right click the root of the domain and go to Properties.
4.Under the Security tab, click advanced and add atomusosync, the Type is Allow, it applies to This object and all descendant objects and the only tick box in the permissions list is Create Organizational Unit Objects.
5.In the local security policy please make sure that under Local Policies > User Rights Assignment that atomusosync is added to the “Allow log on through remote desktop services”
6.If the server you are currently working on is also your home area server you, will need to add the atomusosync user to “Log on as batch job”
7.If your home area server is a different server, you will need to add the atomusosync user to “Log on as batch job” on that server.
8.On each server, where your home areas are created, you will need to give atomusosync full control over the folder where it creates users home areas so that these can be created as part of the account creation process.
USOSync can only be installed by an Wavenet Education engineer. Any changes to the configuration need to be made by an Wavenet Education engineer. Schools are not permitted to make changes to any software settings.
The following changes will be made to your servers during the installation process:
A folder on the home area server called AWScripts will be created on the C: drive and will contain the scripts to generate home areas for the users.
A separate OU (Organisational Unit) is created for the USO-based accounts, with the following account structure:
•Contact
•Staff
•Students
•Year #
•Or
•Entry #
The home areas are created on a server and drive of the school’s choice. Permissions are set on this folder to allow new home areas to be created when new users are added.
A scheduled task, which runs every 15 minutes to create the users home areas on the server, is created. This scheduled task is created via a username and password combination created by the school and supplied to Wavenet Education. These credentials should allow administrative rights on the domain.
See also: