Adding Students to AD
PREPARE THE CONTAINERS:
AD Users and Computers -> Crossroads.local -> Crossroads -> Students
Right-click and New Organizational Unit, name it GY2025
AD Users and Computers -> Crossroads.local -> Crossroads -> Students -> Student Groups
Right-click and New Group, name it GY2025, leave scope as Global and type as Security
CREATE THE SHARE:
Go to D:\ drive -> Students, right-click, New Folder, name it GY2025
Server Manager -> File and Storage Services -> Shares -> Tasks -> New Share
For Profile, pPick "SMB Share Quick" and click Next
For share location, select "Type a custom path" and click Browse and point it to the GY2025 folder you made AND CORRECT THE CASE!
For Share Name leave as-is
For settings, check box for "Enable access-based enumeration" and "Allow caching of share"
For Permissions, click Customize Permissions
Click Disable Inheritance
Select "Convert inherited permissions into explicit permissions on this object."
Click Add
Click "Select a Principal"
Type GY2025, make sure Type is Allow and "applies to" is "This folder, subfolders and files" "Read and execute" + "list folder contents" + "read" are checked
Back in the Permission entries screen, click the line for "students" and remove it. Same for "Creator owner". Edit fileadmins and add "modify" + "read" + "write." Check against this screenshot:
FIXME WHY DOES THIS RESULT in Everyone with full control in the "Share" subtab? WTF??????????????????????
CREATE A TEMPLATE USER:
Go into AD Users and Computers -> Crossroads.local -> Crossroads -> Students -> GY2024 (the PREVIOUS year)
Right-click "_GY2024 Template User" and select "Copy"
Change his first name to "_GY2025" and last name to "Template User" and User Logon name to "_GY2025 Template User" and let it truncate the pre-Win2k logon name, doesn't matter. Click Next
Set his password to "changeme" (or whatever, I don't care) an make sure "user cannot change password" and "password never expires" are both checked.
Right-click that new user and MOVE him to Crossroads -> Students -> GY2025
Go to AD Users and Computers -> Crossroads.local -> Crossroads -> Students -> GY2025, right click on the template user you just moved, and go to the "Member Of" tab and remove GY2024 and add GY2025, then go to "Profile" tab and correct the home folder path
CREATE A NEW USER FROM THE TEMPLATE USER:
AD Users and Computers -> Crossroads.local -> Crossroads -> Students -> GY2025
Right-click and "Copy"
Enter kid's name, logon name (first initial, last name), click Next
Enter their student ID number as their password, click Next/Finish