<?xml version="1.0"?>
<rss version="2.0"><channel><title/><link>https://www.edugeek.net/blogs/blog/196-thescarfedones-blog/</link><description/><language>en</language><item><title>SIMS Development Priorities and Technicial Update</title><link>https://www.edugeek.net/blogs/entry/935-sims-development-priorities-and-technicial-update/</link><description><![CDATA[<p>Ok, so this post needs to start with an apology to the team that gave up their time to speak to me - namely Phil Neal, Graham Cooper and Cath Lane for excellent organising skills as always.</p><p> </p><p>
Back in the Summer, I was privileged to attend the Capita SIMS Annual Conference - where I was treated to the latest news and developments from the inside. This post serves both as a record of the event - and as a eye-opener to where Capita are taking SIMS. There's some really interesting things coming up, some of which some people may already know about. Its fitting in some ways that this is posted on the dawn of BETT - where you will get to see some of the great work that is going on. At the same time, its key to see that there is not just "new-ness" here, Capita are listening; and some of the developments are in direct response to customer (ie us Technica folk!) feedback.</p><p> </p><p>
<strong>Priorities...</strong></p><p> </p><p>
Straight from the horses mouth "Sims easy to deploy easy to configure" - Phil Neal. Well theres a gauntlet laid down then. A cursery browse of the forums show a selection of member gripes about installations and upgrades. Well - both of these are going to be the focus of a lot of time. Im also told that there will be published recommended configurations, going much further than the current "specifications" documents. This is very "Microsoft", and can only be a good thing. It provides extra support for technical services on the ground.</p><p> </p><p>
Improving the installation and upgrades process should also be helped by reducing the need for patches by AMPARK and PI resources - by putting these online. As has now happened, the patching and database numbering has been changed. Why? Well this is to help a move towards consolidated patches. Now that the SIMS ecosystem has grown to more than just SIMS.net, there is a need to consolidate some of the code and services as well. Look at a machine with Discover and all the rest on it! Integration is the key - and work to unify SiMs windows services and ensure services do not require restarts is coming. This will also increase performance especially on startup. Products continually evolve, and as new features have been added in the past - some of the routes have become a bit cluttered. So, the team want to look at the big picture again. This will aim to "remove niggles" as Graham put it - on extra clicks, screen redraws. I guess what we are really talking is completing polish on high traffic areas, eg registers and assessment. Nice.</p><p> </p><p>
Under the hood things are happening too - XP and Vista are "dying", so support is ending. Take note! Server OS and Platforms (ie SQL) continue to develop - and te product is improving and taking advantage of new features. Solus upgrades and SQL version support are moving on. That means migrations. Tools are coming (some are already out there) for SQL migrations. The best time will be Spring - although that, in reality means most Schools will be considering this for Summer.</p><p> </p><p>
This next one is bound to get a cheer...move installers to MSI wrappers. Yes, really - commitment from Phil himself. A nod to the community there. See... feedback makes a difference.</p><p> </p><p>
The desire to improve team support is a nod to the excellent work by LA support teams. Information is scattered so far and wide about performance etc, so one idea to combat this is to effectively manage complete set of assessment resources. This would unify Capita and LA/National Curriculum guidelines. How could this look? Well, one clear example would be to provide Discover with pre configured templates and graphing.</p><p> </p><p>
There are some interesting statistics around surrounding use of SIMS and the associated products in the Classroom. Harking back to previous posts about the importance of the centralised data and use of it, show the difference it can make in School Improvement. Aside from that, its a component Ofsted look at too. Schools must be data literate throughout. On this note, Phil has set himself and the team the challenge of improving uptake in classroom. I guess the Technical Teams will say once the earlier notes above are completed it will be easier! well, take that a step further and "melting-pot" ideas include...</p><p> </p><p>
..teacher setup can be done remotely, dump a configuration file onto a machine for example</p><p>
..increase primary widgets for home page</p><p>
..develop AFFORDABLE tablet apps</p><p> </p><p>
Yes, I did just say develop Apps. Capita are coming to the App party. Capita have always supported the great work that Partners do, but now - they are taking this one on themselves. Apps are great for delivering and consuming data. Everyone uses them now. However, they are often poor for input, although HTML 5 improving this. I strongly suggest you take a look at what Capita are showing at Bett. Its very, very exciting. This is only the start though, and its important you remember this. That being said though - it is complete and very exciting.</p><p> </p><p>
So, I hear you say, what does that mean for SIMS.net and the future? That one is relatively simple as an observer -Sims as a service</p><p>
..hosted Sims and FMS (already provided by Capita direct, some LAs and also some Academy groups0</p><p>
..hosted SLG (as above)</p><p>
..inTouch</p><p>
..Agora</p><p>
..SIMS Multiview (Multiview takes data from Academy Schools, to central repository with dashboards)</p><p> </p><p>
So, why now announce all this? Key to SIMS for the furture is that customers (and by that I mean Academies and LAs) understand what future developments are underway - and to inform future purchases. Sims 8 is a long way away, and the market needs to know the more immediate future. Its key that SIMS isn't seen to be stagnating and just "following legislation" changes.</p><p> </p><p>
Its well accepted that the move to the cloud fully will happen. It has already started - Agora is a cloud product, and many LAs and Schools run Local clouds. Growing school of thought that this is how apps will be developed, to link to cloud based resources.</p><p> </p><p>
So... go and take a look at what is changing. Keep posing the difficult questions. Here, is a case of a product changing to meet changing School, Academy and Free School needs. Im hoping to post a follow up article post-Bett after I "pester" the team again. Any questions, please send them over...</p>]]></description><guid isPermaLink="false">935</guid><pubDate>Tue, 21 Jan 2014 14:43:36 +0000</pubDate></item><item><title>Guest Blog: Technology&#x2019;s role in closing the gap</title><link>https://www.edugeek.net/blogs/entry/934-guest-blog-technology%E2%80%99s-role-in-closing-the-gap/</link><description><![CDATA[<p>Here's a first for me - a guest blog! Whilst Ive been busy writing new articles (there are about 5 part written at the moment...note to self, must finish those) - technology continues to move on. Xbox One, Google Glass and many more - and with BETT around the corner, that list of "new" will continue to grow! So, it was quite fitting that I was approached by Cath Lane and her team (<a href="http://www.catherinelane.co.uk" rel="external nofollow">http://www.catherinelane.co.uk</a>) with an interesting post about how technology can be used to bring equality. Now, this is right up my "integrated" street - so here it is...</p><p> </p><p>
<strong>Technology’s role in closing the gap by Jonathan Ovenden</strong></p><p><strong>
</strong><a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2014_01/CRC008JonathanOvenden.jpg.12b7482d892b2780237b513586df1179.jpg" data-fileid="257" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CRC008JonathanOvenden.jpg.12b7482d892b2780237b513586df1179.jpg" data-fileid="257" data-src="https://www.edugeek.net/uploads/monthly_2014_01/CRC008JonathanOvenden.jpg.12b7482d892b2780237b513586df1179.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p><strong>
</strong></p><p>
The increasing focus from the government on closing the stubborn gap that persists between higher and lower achievers means schools are having to focus much of their time and effort ensuring they make progress in this area. </p><p> </p><p>
As schools’ minister, David Laws, so succinctly put it, “If gaps are not being narrowed, Ofsted will want to know why not.” </p><p> </p><p>
The problem is that schools are still having to meet all the other objectives laid down for them at the same time. Technology has a role to play here; giving teachers access to resources designed specifically to raise the achievement of the hard to reach so they can make progress more quickly. But what sort of technology will have the biggest impact?</p><p> </p><p>
<strong>Give children the skills to learn</strong></p><p>
“One of the issues you can find with lower ability learners is that they are often spoon fed learning and so are unable to apply what they have learnt in one subject to other learning,” says David Godfrey, the principal of two schools in a deprived area in the North East. </p><p> </p><p>
As a result, choose resources that are designed specifically for lower ability learners. You want something that does not simply revise key topic areas, but also helps children understand the topic by breaking it down and encourages them to discover things for themselves. </p><p> </p><p>
<strong>Online means flexible</strong></p><p>
Online tools are the most flexible as a pupil can access resources from class, at a breakfast club or at home with their parents by their side. “Parents hold the key to a child’s achievement so anything that offers the ability to share results or activities with parents is ideal,” says David. </p><p>
According to a report by the Centre for Social Justice, if parents engage with their child’s education, their attainment increases by 15 per cent, regardless of the social background of the family; reason enough to ensure parents are given access to tools to help their children.</p><p> </p><p>
<strong>It’s all about you</strong></p><p>
The time teachers have with a pupil to make a difference is very limited so you do not want children covering topics that they have already mastered. The best resources help teachers diagnose a child’s weak areas and deliver content that is specifically designed to work on these gaps – meaning learning is personalised and time is not wasted. </p><p> </p><p>
By choosing the right online learning technologies that are suited to this hard-to-reach group, you can have an impact on their achievement and make the most of available teaching time. </p><p> </p><p>
Jonathan Ovenden is a director at vision2learn who will be at Bett 2014 (stand F346) if any readers want to discuss these issues with him further.</p>]]></description><guid isPermaLink="false">934</guid><pubDate>Tue, 21 Jan 2014 13:44:14 +0000</pubDate></item><item><title>Inside SIMS and its development - an interview with the Team</title><link>https://www.edugeek.net/blogs/entry/840-inside-sims-and-its-development-an-interview-with-the-team/</link><description><![CDATA[<p>So, back at the end of January, I got the opportunity to sit down with a number of the key people behind SIMS, namely Jon Wood, Graham Cooper, Ben Jones and Phil Neal.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015PhilNeal.jpg.a64b8c49e42460bd88b69686d5143119.jpg" data-fileid="219" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CAP1015PhilNeal.thumb.jpg.23f2b2ba1b3c8d7fc56630c5ed0aa19a.jpg" data-fileid="219" data-src="https://www.edugeek.net/uploads/monthly_2025_03/CAP1015PhilNeal.thumb.jpg.23f2b2ba1b3c8d7fc56630c5ed0aa19a.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a>  <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015GrahamCooper.jpg.064f43734b335fc17d843e133311c74b.jpg" data-fileid="220" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CAP1015GrahamCooper.thumb.jpg.c879141ea4047ef8b1c5d799dcffab79.jpg" data-fileid="220" data-src="https://www.edugeek.net/uploads/monthly_2025_03/CAP1015GrahamCooper.thumb.jpg.c879141ea4047ef8b1c5d799dcffab79.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Above - Phil Neal (MD); Graham Cooper (Head of Product Strategy)</p><p> </p><p>
This follows my article on SLG; and the hints at what was to become the Spring 2013 SIMS.net release.</p><p> </p><p>
It was refreshing to get to speak so candidly with the team behind SIMS - arguably, these guys come in for a fair amount of grief from the community. This particularly applies to Jon - fielding the questions about SIMS updates, patches and issues.</p><p> </p><p>
<strong>"Challenges of market"</strong></p><p>
Capita SIMS has the largest share of the market - this is no secret; and this is despite those voices in the community that would have you believe the failings of SIMS. For all the so-called dominance - the team are "not content to rest on their laurels" as Graham put it. The market is changing - academies and free schools have contributed to that change. There is a growing specialism in schools - a better understanding of technology and of choice.</p><p> </p><p>
Figures later sent by David Grashoff shows a growth in the number of partners creating add ons and expanding the SIMS ecosystem. The team have recognized that little niches are often best served by these smaller vendors; and it all helps build a better product. Capita have deliberately built a scheme with different levels of charge and involvement to encourage partners. Further information on their Partners can be found here <a href="http://www.capita-sims.co.uk/our-partners." rel="external nofollow">http://www.capita-sims.co.uk/our-partners.</a></p><p> </p><p>
That's not the end of the story - there are other <abbr title="Management Information System">MIS</abbr> vendors in the market and they are actively developing their products. If Capita merely "kept up" with DfE changes and bug fixes - the likelihood of customer base change would increase.</p><p> </p><p>
The key is to recognise that schools have a choice, and also to see that the market is actually growing. You only need to take a look at the vendor lists, year on year, at school technology events such as Bett, explained Phil. </p><p> </p><p>
According to Graham "SIMS is not finished, never will be" - which is a very candid statement on the surface; but when you think about it - it makes perfect sense. You have to watch the market, particularly one which is changing. Watch the schools and engage with them, then bring solutions through to meet these ever changing needs - including supporting others to do the same. The power balance is changing, schools have more freedom and more understanding than ever before; they have access to a wealth of information.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015SIMSAgora2.jpg.22f4b077a8bbd435cbfa2c890befd4cd.jpg" data-fileid="221" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CAP1015SIMSAgora2.thumb.jpg.9ff454dcbbfb3d2ae978e830bee1aa67.jpg" data-fileid="221" data-src="https://www.edugeek.net/uploads/monthly_2025_03/CAP1015SIMSAgora2.thumb.jpg.9ff454dcbbfb3d2ae978e830bee1aa67.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a>  <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015SIMSAgora.jpg.282825c920bea468d3a5c8595df3f74c.jpg" data-fileid="225" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CAP1015SIMSAgora.thumb.jpg.d49bedc63c7d1efe9ec01182de13ec42.jpg" data-fileid="225" data-src="https://www.edugeek.net/uploads/monthly_2025_03/CAP1015SIMSAgora.thumb.jpg.d49bedc63c7d1efe9ec01182de13ec42.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Above - SIMS Agora</p><p> </p><p>
This is why there has been such a focus on new products such as SIMS Discover and SIMS Agora over the past year. Schools have been saying it’s "Easy to get data into SIMS, but there is a lack of ability to analyse", says Phil. Schools are so data rich, too data rich maybe - it has got to be easy to "ask questions of the data in SIMS". Arguably, the greatest power of the data is to put it in the hands of those in a position to use it best. The idea behind SIMS Discover was to make it easy to spot patterns in data, and be able to act on it. </p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015SIMSDiscover.jpg.af9a3182120bcb8490b55488bf964a81.jpg" data-fileid="222" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CAP1015SIMSDiscover.thumb.jpg.9240f65da20f0649fb98356e0ef68c8d.jpg" data-fileid="222" data-src="https://www.edugeek.net/uploads/monthly_2025_03/CAP1015SIMSDiscover.thumb.jpg.9240f65da20f0649fb98356e0ef68c8d.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a>  <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015SIMSDiscover4.png.1d864f609d8c803a90e45a3c4fbb5e83.png" data-fileid="226" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CAP1015SIMSDiscover4.thumb.png.eb14b75e23663ec547eeed6b5df61eae.png" data-fileid="226" data-src="https://www.edugeek.net/uploads/monthly_2025_03/CAP1015SIMSDiscover4.thumb.png.eb14b75e23663ec547eeed6b5df61eae.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Above - SIMS Discover</p><p> </p><p>
<strong>"The challenge was to make teachers want to use it"</strong></p><p>
The market has been flooded by a new breed of consumer devices - tablets, smartphones et al. All these have slick, easy to use interfaces - people expect this now. This has led to a new discipline - "User Experience Developers", with a sole purpose of stretching what is possible with SIMS and make the software easier to use.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015SIMSSpring2013Home.png.2fd5baf0b97e425936ffc892a4ef46b1.png" data-fileid="223" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CAP1015SIMSSpring2013Home.thumb.png.cfd3ba6e754f003d53a4f517f488db2d.png" data-fileid="223" data-src="https://www.edugeek.net/uploads/monthly_2025_03/CAP1015SIMSSpring2013Home.thumb.png.cfd3ba6e754f003d53a4f517f488db2d.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Above - SIMS Spring 2013 Redesigned Homepage</p><p> </p><p>
New products aside - Capita have a major technological challenge, one which they are keen for the community to have a greater understanding of.</p><p> </p><p>
Windows Server 2003 and XP Systems are coming towards the end of their life from Microsoft - and an expiry warning was given to SIMS customers a year in advance. The cycle of complaint and extensions with Microsoft has only led to many IT users (not limited to SIMS) continuing to run these older Operating Systems. Capita have been listening to feedback to provide continued support on the aging OS - but think about the compromise that has been made here. SIMS now has a massive breadth of possible client and server configurations. This leads to a complex development process, and it is inevitable that some users will be left frustrated by the pace of development. These different configurations are compounded by a history of data. The team would much rather spend time on new features and functions, but have to support the community who are not able or inclined to upgrade.</p><p> </p><p>
A common question is the disparity between sections of the system, and some ask could there possibly be a time when the interfaces may match? In this case, we are talking about SIMS.net and the older modules like Exams, Nova and Options.</p><p> </p><p>
Graham talked about Exams, and the challenge of "Constantly moving goalposts", and he's right. The exam board and Ofsted/DfE requirements surrounding exams must make for a nightmare. Exams are such a core component that Capita simply cannot afford to get it wrong. In reality, the Exams module is constantly evolving - but there are not the wholesale  interface changes, instead more subtle ‘under the hood’ enhancements and statutory requirements. We can also turn to Nova T6, which Phil comments to be "world class". Finally, Options is over ten years old, but it’s a component that has a limited use time window, with one maybe two users per School. Arguably, this is the reason it has not been GUI refreshed.</p><p> </p><p>
The crux of the matter is that in reality, they are all changing under the hood, but it is the interface which is left familiar to the niche group of users. Again though, think of the work involved to update these components and test with all the variety of possible configurations.</p><p> </p><p>
In some ways, one of SIMS' greatest strengths - its breadth of support and wide customer base; is also its weakness.</p><p> </p><p>
Despite all the fears about academies and the future of Local Authorities (as discussed in an earlier post here <a href="https://www.edugeek.net/blogs/thescarfedone/1734-capita-la-conference-2012-alton-towers-key-note-tony-travers.html" rel="">http://www.edugeek.net/blogs/thescarfedone/1734-capita-la-conference-2012-alton-towers-key-note-tony-travers.html</a>), most of the concerns have never been realised. Over 3,000 schools (as of January 2013) currently licence and take support direct from Capita; with countless more across the 150 Local Authorities (LAs) who also also provide and support SIMS. With the actual growth in use, there have had to be increased helpdesk processes and also increased agents in the field. That being said, lots still buy via their LA, according to Jon. "Schools value their LA, as do we - there is a great wealth of knowledge in the local support teams." In fact, it is still the preferred model, rather than direct, explained Graham.</p><p> </p><p>
<strong>"Everything has to have a line in the sand. Everything has a finite life"</strong></p><p> </p><p>
So, what about the future of SIMS? What about the question of platform independence? Well, the answer was quite interesting "We don't have a cloud offering per se, but are developing cloud solutions." I guess this is where products like Agora come in - based as it is on Windows Azure. Capita are, to that point, sticking to their new mantra of the customer base determining the software.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015SLGSpring2013.png.96dd6c310b23a0cd7d292555f9a6d492.png" data-fileid="224" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="CAP1015SLGSpring2013.png.96dd6c310b23a0cd7d292555f9a6d492.png" data-fileid="224" data-src="https://www.edugeek.net/uploads/monthly_2013_04/CAP1015SLGSpring2013.png.96dd6c310b23a0cd7d292555f9a6d492.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Above - Sims Learning Gateway (SLG) Spring 2013</p><p> </p><p>
Attention should also turn to SLG - which only started life as a tool to provide information for parents. This grew to become more than that - arguably catching them out, they admit. Countless schools use it to take registers and reports. Originally designed to be an interface for the teacher and parent at home; but it is increasingly being seen in school. The behaviour component is one classic example - it wasn't expected to be used in the classroom; but is, and the software is being adapted to meet these new needs. More information about the changes in SLG can be found in my earlier article here - <a href="https://www.edugeek.net/blogs/thescarfedone/1947-capita-sims-developments-2013-sims-learning-gateway.html" rel="">http://www.edugeek.net/blogs/thescarfedone/1947-capita-sims-developments-2013-sims-learning-gateway.html</a></p><p> </p><p>
So what of the strategy for the SIMS of the future? Well, the team explained it like this. Think of an oak tree. Originally, SIMS was in the school office. You had to go there to get it, and there were only about four or five installs. The tree matures and grows. There was the impact of lesson by lesson registration - which spread SIMS into the classroom. Profiles made it possible to write reports in the product, before SLG puts these digitally into the home. New initiatives are seeing a growing use by pupils to monitor their own progress.</p><p> </p><p>
All this is making SIMS and the data it holds, the heart of the school. The breadth of the solution is increasing as new products such as SIMS Discover and SIMS Agora come to the market. We also mustn't forget the partners supported by Capita who pick up the edges - which is the equivalent of "pushing down the roots".</p><p> </p><p>
So, to close - we return to the point of new initiatives. Ofsted expect our schools to be data literate. The Ofsted process is changing - tell the story of progress, rather than initial opinion of inspection and exam results. So much of this revolves around the students having an increased understanding of their progress, expectations and standings within the year. The teacher must know about year groups, classes and the individual. There is a focus on the ability to tell stories about progress supported by data. Data must be turned into actionable information, making it relevant, which in turn makes SIMS more than just a data repository.</p><p> </p><p>
Thanks must go to the team at Capita SIMS (<a href="http://www.capita-sims.co.uk" rel="external nofollow">http://www.capita-sims.co.uk</a>) for agreeing to give up their time for this discussion; and to Catherine Lane PR (<a href="http://www.catherinelane.com" rel="external nofollow">http://www.catherinelane.com</a>) for arranging the meetings.</p>]]></description><guid isPermaLink="false">840</guid><pubDate>Sun, 28 Apr 2013 18:13:25 +0000</pubDate></item><item><title>HyperV Clusters</title><link>https://www.edugeek.net/blogs/entry/813-hyperv-clusters/</link><description><![CDATA[<p>Some of you may have read from my previous Microsoft School Blog posts that I run a HyperV Clustered network. This consists of 3 HyperV Hosts, running Server 2008 R2 (considering when to upgrade to 2012)... with the VHD server data files located on a SAN.</p><p> </p><p>
This allows me to use the Failover Clustering feature to manage the resilience of the network.</p><p> </p><p>
This week; I came across an odd problem.</p><p> </p><p>
I was getting ready to do some maintenance across the system - and running a backup across the Hosts of each of the VMs located on them. As part of this process I wanted to move the owner of a Cluster Shared Volume (CSV) disk first. Cluster Shared Volumes are the bit of power that allows you to seemlessly present the same pool of storage with all the VHDs on to all the servers simulataneously. This make the live migration work - yes, thats the feature in VMware land called VMotion - that you pay for!</p><p> </p><p>
So, anyway - I digress... I go into Failover Manager find the CSV resource and select migrate to other node…. Only to be presented with</p><p> </p><p> </p><p>
<strong>Operation has failed.</strong></p><p><strong> </strong></p><p><strong>
The action ‘Move to node &lt;nodename&gt;’ did not complete</strong></p><p><strong> </strong></p><p><strong>
Error code: 0×80071398. The operation failed because either the specified cluster node is not the owner of the group, or the node is not a possible owner of the group</strong></p><p> </p><p> </p><p> </p><p>
What the!! Ive  had enough problems with this cluster/SAN/CSV’s in the past - and its usually the DHCP virtual server cluster that refuse to connect their iSCSI disks...</p><p> </p><p>
So.. lets have a look at the “Possible Owners list”  - and sure enough this server was missing a few command laster and were are back in business.</p><p> </p><p>
To tell who are the possible owners run:</p><p> </p><p>
Cluster res &lt;resource name&gt; /listowners</p><p> </p><p>
 To to add a server to the list</p><p> </p><p>
Cluster res &lt;resource name&gt; /addowner :&lt;servername&gt;</p><p> </p><p>
Job done... oh, but remember, Server 2008 R2 needs you to run these commands from an elevated command prompt.</p>]]></description><guid isPermaLink="false">813</guid><pubDate>Sun, 17 Feb 2013 20:01:07 +0000</pubDate></item><item><title>Capita SIMS Developments for 2013 - SIMs Learning Gateway</title><link>https://www.edugeek.net/blogs/entry/801-capita-sims-developments-for-2013-sims-learning-gateway/</link><description><![CDATA[<p>A departure from my normal blog topics to something even more relevant to a lot of schools than my normal writings.</p><p> </p><p>
<strong>Introduction</strong></p><p>
SIMS is a School Management database, written and supported by Capita Education Services. 6 months has passed since I was invited to join Capita at their Annual Conference to see and write about forthcoming changes, as well as report back on the year (and ask the awkward questions from the community). In this post, Im going to pick up on SIMS Learning Gateway (SLG for short) - which as I keep reminding them, needs to be renamed! My last post on the subject is here - <a href="https://www.edugeek.net/blogs/thescarfedone/1735-capita-la-conference-2012-alton-towers-learning-gateway-product-update.html" rel="">http://www.edugeek.net/blogs/thescarfedone/1735-capita-la-conference-2012-alton-towers-learning-gateway-product-update.html</a></p><p> </p><p>
Before I get started, I would like to thank Product Manager Ben Jones for his time and the information he supplied so I could write this post. There will also be a follow up post to this as I will be interviewing Ben at the BETT show. If you have any questions you would like me to put to him, please send them to me via Edugeek or Twitter.</p><p> </p><p>
<strong>SIMS Learning Gateway in 2013</strong></p><p>
One of the biggest drawbacks of SLG has always been the very data driven view it offers. Now, in most systems, this would be great - but in this case, remember the target audience. Sadly, the viewpoint has been from most "users" that it is unfriendly and not very pretty or inspiring. I'd have to agree, even though I can apprieciate technically what is going on within the product and the restrictions it has on its method of surfacing the data from the SIMS database. People often forget that is all the webapps (well to give their proper title data view web parts) are doing. This inherantly makes them data driven and blocky as shown below...</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture2.PNG.77dbb52e74fb7e55e70ef64b0ab08f98.PNG" data-fileid="194" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture2.PNG.77dbb52e74fb7e55e70ef64b0ab08f98.PNG" data-fileid="194" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture2.PNG.77dbb52e74fb7e55e70ef64b0ab08f98.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture3.PNG.4422051d847c131e02844aeccc83a04d.PNG" data-fileid="195" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture3.PNG.4422051d847c131e02844aeccc83a04d.PNG" data-fileid="195" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture3.PNG.4422051d847c131e02844aeccc83a04d.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
This is pre Spring 2013. Im thankful to Ben and his team who have given me access to their entire rewrite of the way SLG brings data to the user. Rewind to last summer, and Ben gave me the inside information that he was revitalizing the SLG team with a big user interface overhaul; and reassessment of SLGs purpose. This started with the introduction of news and headlines which came in last year. </p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture1.PNG.0ddd28ca78a8d2cc83e97740cf013388.PNG" data-fileid="196" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture1.PNG.0ddd28ca78a8d2cc83e97740cf013388.PNG" data-fileid="196" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture1.PNG.0ddd28ca78a8d2cc83e97740cf013388.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Then, attention turned data tidying. A data system is only as good as the data it contains. We know how quickly a database of contact details can get out of data - so the team refreshed the good old fashioned "Data Collection Sheet" for the 21st Century. This feature gave an indication of what Ben and his team had in mind for SLG. The new Data Collection Sheet was a complete break with the "boxy" SLG of old.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture5.PNG.ed0fbeb7cb68cc3ca5b7c265696193a1.PNG" data-fileid="193" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture5.PNG.ed0fbeb7cb68cc3ca5b7c265696193a1.PNG" data-fileid="193" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture5.PNG.ed0fbeb7cb68cc3ca5b7c265696193a1.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
All data sent back into the School still needs to go through the approval process internally, so there is no fear of compromising the SIMS database.</p><p> </p><p>
The next quick win for the system would be to improve the main Student Details panels. These panels (well, web parts really) are re-used multiple times across the system. So, whether you are viewing Student Details as a Parent, Staff or the Student themselves - you get the same new view.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture4.PNG.47c50314ddd1e4fa91f0cf6245eecfb2.PNG" data-fileid="197" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture4.PNG.47c50314ddd1e4fa91f0cf6245eecfb2.PNG" data-fileid="197" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture4.PNG.47c50314ddd1e4fa91f0cf6245eecfb2.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
The timetable link opens the student timetable in a Sharepoint Calendar view - this screenshot has been taken from a Sharepoint 2007 demo install. Sharepoint 2010 looks a bit different.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture6.PNG.eafc1e01cbe186db377ae83e0d2bdb18.PNG" data-fileid="198" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture6.PNG.eafc1e01cbe186db377ae83e0d2bdb18.PNG" data-fileid="198" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture6.PNG.eafc1e01cbe186db377ae83e0d2bdb18.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Other parts of the Student details page webparts will launch similar details panes. For example, the attendance we can drill down to choose a term, and also then look at an expanded view.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture7.PNG.1c2f9ff93000bc094ae57d7a1bbdae49.PNG" data-fileid="199" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture7.PNG.1c2f9ff93000bc094ae57d7a1bbdae49.PNG" data-fileid="199" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture7.PNG.1c2f9ff93000bc094ae57d7a1bbdae49.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
All graphs on webparts can be panned back and forth and have their views filtered via the calendar button located to the top right of the webpart, and choosing the term or period from the drop down provided. The webparts respect the settings you make within SIMS.net, exactly as before, where you can control what information is shown (so hide conduct etc); or the periods of time that can be shown.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture8.PNG.047baba63c50d2a39e8d04431009b63e.PNG" data-fileid="200" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture8.PNG.047baba63c50d2a39e8d04431009b63e.PNG" data-fileid="200" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture8.PNG.047baba63c50d2a39e8d04431009b63e.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
At the moment, Conduct details will still take you back to the same raw data "old style" view webparts.</p><p> </p><p>
Building on the success of the Key Performance Indicators used on the front page, development on a graphical view has also just been completed.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Capture9.PNG.2cc061331b2840ac92abacdc5c3e945d.PNG" data-fileid="201" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Capture9.PNG.2cc061331b2840ac92abacdc5c3e945d.PNG" data-fileid="201" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Capture9.PNG.2cc061331b2840ac92abacdc5c3e945d.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
As with all of the new style webparts, hover over them and you can "slide" left and right to change your view. All the views are configured from within SIMS.net.</p><p> </p><p>
So, hopefully, this has whetted your appetite for a new SLG - where the emphasis is now on usability rather than the data. This year is going to be a big year for SLG, with lots more development in the pipeline. Migration for original 2007 installations to 2010; and support for the new 2013 version are well underway. Tie into that, the developments with Agora - which is all hosted on the Microsoft Azure platform; this speaks of a changing SIMS product.</p><p> </p><p>
Many thanks to Ben Jones and the SIMs Learning Gateway development team for sharing their information; and allowing me to publish it in advance.</p>]]></description><guid isPermaLink="false">801</guid><pubDate>Wed, 30 Jan 2013 11:10:27 +0000</pubDate></item><item><title>Intranet and Extranet SSO and Usability Project - Part 2</title><link>https://www.edugeek.net/blogs/entry/795-intranet-and-extranet-sso-and-usability-project-part-2/</link><description><![CDATA[<p>This post is a continuation of my battle to compelte a cohesive intranet; and some more ramblings about Sharepoint. Its turned into a monster of a project this one. The external single sign on (SSO) was a breeze - thanks to Forefront Threat Management Gateway (TMG) - but this presented an issue - internal or external, you would be faced with a logon screen. Not ideal - internally we wanted a double SSO which would use your Active Directory logon session to SSO with the TMG HTTP session.</p><p> </p><p>
<em>Lets pick up that story....</em></p><p> </p><p>
<strong>A quick review</strong></p><p>
Where did we get to? We had just finished with creating our Split DNS infrastructure - and Id outlined the need to then play with your web publishing and listeners in TMG.</p><p> </p><p>
We need a new web listener, which will be waiting for incoming requests only from the internal network. As you probably already know, a Web Listener is a software component that is used by Web Publishing Rules. The Web Listener accepts incoming connection requests for published Web servers. Web Listeners define the authentication methods that can be used by the TMG firewall to authenticate users before the connections are allowed to the published Web server. This is often referred to as “pre-authentication”. There are many security advantages to pre-authentication and if your site requires authentication, you should always take advantage of this option.</p><p> </p><p>
<strong>TMG Configuration - Step by step...</strong></p><p> </p><p>
1. On the New menu, click the Web Listener option - which brings up the Welcome to the New Web Listener Wizard page</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/TMG1.png.3c7c651e8627894974319da20c19e16a.png" data-fileid="185" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TMG1.png.3c7c651e8627894974319da20c19e16a.png" data-fileid="185" data-src="https://www.edugeek.net/uploads/monthly_2013_01/TMG1.png.3c7c651e8627894974319da20c19e16a.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a>  <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/TMG2.png.6a4b07486dfb5aa3fae5437c43cd7db3.png" data-fileid="186" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TMG2.png.6a4b07486dfb5aa3fae5437c43cd7db3.png" data-fileid="186" data-src="https://www.edugeek.net/uploads/monthly_2013_01/TMG2.png.6a4b07486dfb5aa3fae5437c43cd7db3.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
2. Enter a name for the Web Listener here. In this example, we’ll name the Web Listener HTTP Listener, with the intent that this Web Listener will be used for accepting incoming connections to using HTTP Authentication.</p><p>
3. To match up our external to internal (really just to not confuse users - and think here, we are using HTTP authentication; you should really use some kind of encryption for security) you should ensure that you choose "SSL".</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/TMG3.png.135a12e9b5588910b4d9bca8d9ad95c7.png" data-fileid="188" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TMG3.png.135a12e9b5588910b4d9bca8d9ad95c7.png" data-fileid="188" data-src="https://www.edugeek.net/uploads/monthly_2013_01/TMG3.png.135a12e9b5588910b4d9bca8d9ad95c7.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
4. This will need HTTP authentication not forms authentication (which our external network will be using) - this allows it to use the same details that TMG/ISA itself is using to recognising our clients already for things like proxy (if you are using it).</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Listener1.jpg.04dd5a6837d0cf657d1bc7acb8467b5a.jpg" data-fileid="191" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Listener1.jpg.04dd5a6837d0cf657d1bc7acb8467b5a.jpg" data-fileid="191" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Listener1.jpg.04dd5a6837d0cf657d1bc7acb8467b5a.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
NB-Image from the "Edit Properties" version, rather than the Wizard screen - so your screen may look slightly different)</p><p>
5. Next up is telling this listener to only wait for traffic from our internal NIC. So - in the image below - you will see Internal network is selected only. Your other external listener needs to have Internal de-selected, which you can change by editing its properties.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/TMG4.PNG.9a1aec4a3ad199b41e916932eccec555.PNG" data-fileid="187" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TMG4.PNG.9a1aec4a3ad199b41e916932eccec555.PNG" data-fileid="187" data-src="https://www.edugeek.net/uploads/monthly_2013_01/TMG4.PNG.9a1aec4a3ad199b41e916932eccec555.PNG" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
That finishes off your listener configuration.</p><p> </p><p>
We than also need to change our existing rule so that it only listens on the external network. That's not where it ends though - as we then need a load of new publishing rules for our services to match up to our listener. This should be relatively simple though, as you can copy (select rule, right click and choose copy, and then right click and paste. I would then disable the copied rule while you do the editing.</p><p> </p><p>
Your new "internal" rules should be above your external rules so make sure you move them up. You also need to change the listener used in the new rule, and the authentication delegation. When you change to internal http listener services, you cannot use ntlm as your authentication method. </p><p> </p><p>
For things like Sharepoint and Exchange, this means moving to Kerberos. Now, from the Application point of view, this is quite easy to do. You will need to set up several srv records, and also allow TMG to act on behalf of your Sharepoint and Exchange servers when it comes to credential delegation. Sounds scary? Well, some of it can be if you haven't done it before. It also gets a bit more complicated if you are running a farm for these services, as you cannot authorise a server which to all intents and purposes doesn't exist. </p><p> </p><p>
The rest of this article will cover the TMG steps, the next one will cover the Sharepoint/Exchange and Kerberos side of things.</p><p> </p><p>
Kerberos Constrained Delegation (KCD) is a primary functionality of the Kerberos protocol introduced in Windows Server 2000 domain environments for authenticating users, services and computers. If a published Web server like the SharePoint needs to authenticate a user that sends a request to it and if the Forefront TMG computer cannot delegate authentication to the published Web server by passing user credentials to the published Web server or impersonating the user, the published Web server will request the user to provide credentials for a second time. ISA Server 2006 introduced support for Kerberos constrained delegation to enable published Web servers to authenticate users by Kerberos, after their identity has been verified by the ISA Server using a non-Kerberos authentication method. The same continued into TMG 2010. When used in this way, Kerberos constrained delegation eliminates the need for requiring users to provide credentials twice. To get Kerberos Constrained Delegation to work, we must change the Authentication Delegation method to Kerberos Constrained Delegation in the Forefront TMG Management console for the SharePoint publishing rule. The Service Principal Name (SPN) is host/InternalDNSFQDN of the SharePoint Server.</p><p> </p><p>
So, on the properties of the rule (make sure you are still working on your internal rule here, and don't break your external one), on Authentication delegation, choose Kerberos. You will then need to enter/amend the Kerberos SPN name.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/Kerberos1.jpg.5bb969d2ee27b6bfce78378d68408305.jpg" data-fileid="192" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="Kerberos1.jpg.5bb969d2ee27b6bfce78378d68408305.jpg" data-fileid="192" data-src="https://www.edugeek.net/uploads/monthly_2013_01/Kerberos1.jpg.5bb969d2ee27b6bfce78378d68408305.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Next up, in Part 3 will be the SETSPN tools you need to use to allow the delegation to work; how to check this - and also making the changes in Active Directory.</p>]]></description><guid isPermaLink="false">795</guid><pubDate>Sun, 27 Jan 2013 17:07:20 +0000</pubDate></item><item><title>Intranet and Extranet SSO and Usability Project - Part 1</title><link>https://www.edugeek.net/blogs/entry/790-intranet-and-extranet-sso-and-usability-project-part-1/</link><description><![CDATA[<p>Its been a long time since I last wrote about Sharepoint - the platform for our Intranet; but now with the rest of the ongoing projects nearing completion - I've been able to return to this monster of a project.</p><p> </p><p>
<strong>Introduction</strong></p><p>
So, lets go back to the start and show what the end goal was.</p><p> </p><p>
1. Intranet Portal - containing Departmental, Staff and Student Areas. Department areas would have staff and student storage as well as news, events, discussions, blogs and all the usual suspects</p><p> </p><p>
2. Booking System - does what is says on the tin, web system for booking rooms and resouces</p><p> </p><p>
3. Helpdesk System - does what is says on the tin, access to our existing online <abbr title="Information and Communications Technology">ICT</abbr> helpdesk system</p><p> </p><p>
4. SSO (Single Sign On) - enter username and password once for all services, and transparently log in to all the others</p><p> </p><p>
<strong>Progress to date</strong></p><p>
Progress was good! The web based helpdesk (GLPI) was installed and has been in use for over a year now. Sharepoint was installed as a farm, and branded up with custom designed Academy theming. All the departmental and staff areas were added, and the supporting Active Directory groups put in place. The excellent Home Access Plus is being used successfully for bookings - and we work with the team to tweak the development.</p><p> </p><p>
Forefront TMG was installed to replace the out of date ISA 2006 software. This gave the SSO we wanted - but also presented a challenge. Externally - we wanted the logon dialog presented; but not internally. This actually started to become a bit of a barrier to adoption... and thats where this blog post picks up the story.</p><p> </p><p>
<strong>Split DNS</strong></p><p>
So, some of you may have seen this term "split dns" banded around before. Well - that is what you need here. In simple terms, split dns allows your dns server to respond and act as if it was authoritative for a domain other than the name of your Active Directory domain. Take the following example:</p><p> </p><p>
Domain Name: school.internal</p><p>
External Name: school.authority.sch.uk</p><p> </p><p>
Now, your external access will likely come through an address such as webmail.school.authority.sch.uk or gateway.school.authority.sch.uk.</p><p> </p><p>
What you need to do is add the domain "school.authority.sch.uk" as a forward lookup on your dns server. Once we've created the zone, we can then add the hosts that we want to internally resolve. Any hosts that we don't add to our own copy of the  "school.authority.sch.uk" domain will have their requests sent out onto the upstream local authority/internet provider dns servers as normal. If you want to find out a bit more about this, and what it all really means - then there is a great write-up of it here <a href="http://www.isaserver.org/tutorials/you_need_to_create_a_split_dns.html." rel="external nofollow">http://www.isaserver.org/tutorials/you_need_to_create_a_split_dns.html.</a></p><p> </p><p>
Lets create a new dns zone for "school.authority.sch.uk"...</p><p> </p><p>
1. Load up the DNS administration snap in, and browse down through one of your dns servers followed by "Forward Lookup Zones".</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS1.png.523bae55f60a3b51416498b2b9c04892.png" data-fileid="176" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS1.png.523bae55f60a3b51416498b2b9c04892.png" data-fileid="176" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS1.png.523bae55f60a3b51416498b2b9c04892.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
2. Right click on "Forward Lookup Zones" and choose new zone. This will start the wizard. Click Next.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS2.png.e81634b8764c3675352b079381441d33.png" data-fileid="177" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS2.png.e81634b8764c3675352b079381441d33.png" data-fileid="177" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS2.png.e81634b8764c3675352b079381441d33.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
3. We will be creating a "Primary" zone, so select this. Also, ensure that the "Store in AD" check box is selected. This will ensure that all AD DNS servers will respond to requests for the site. After clicking next, you should also select the option for all DNS servers in the domain for the same reason.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS3.png.bb6d30524fc8bba33b3f7edc48fd7d01.png" data-fileid="178" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS3.png.bb6d30524fc8bba33b3f7edc48fd7d01.png" data-fileid="178" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS3.png.bb6d30524fc8bba33b3f7edc48fd7d01.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a>  <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS4.png.9b6a5a74f29f8bf371193169670ce037.png" data-fileid="179" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS4.png.9b6a5a74f29f8bf371193169670ce037.png" data-fileid="179" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS4.png.9b6a5a74f29f8bf371193169670ce037.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
4.  Next up, its time to enter the DNS name itself. If you are wanting your internal network to resolve webmail.school.authority.sch.uk; then the dns name is "school.authority.sch.uk". Enter this here.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS5.png.9b41be46a21a7c9c3680e2d88857a594.png" data-fileid="180" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS5.png.9b41be46a21a7c9c3680e2d88857a594.png" data-fileid="180" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS5.png.9b41be46a21a7c9c3680e2d88857a594.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
5. We all know about DNS security (don't we?) - so the obvious choice on the next screen is "Secure transfers only" - back to how dns gets updated in step three. Only secure updates should ever be used on AD domains. Choose it, click next and then finish! That's it... simples??</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS6.png.65c89853225dc36952d1f4ed5b248f6e.png" data-fileid="181" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS6.png.65c89853225dc36952d1f4ed5b248f6e.png" data-fileid="181" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS6.png.65c89853225dc36952d1f4ed5b248f6e.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a>  <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS7.png.260a3ec9906d57833ef92ac35ea05f14.png" data-fileid="182" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS7.png.260a3ec9906d57833ef92ac35ea05f14.png" data-fileid="182" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS7.png.260a3ec9906d57833ef92ac35ea05f14.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Well - yes, but at the moment - our split dns doesn't actually do anything. We haven't got any hosts in yet, so all requests still go out to our isp. </p><p> </p><p>
1. Choose our newly created zone, and right click. </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS8.png.f7f38a39085f721ddbcd3fd527d8f283.png" data-fileid="183" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS8.png.f7f38a39085f721ddbcd3fd527d8f283.png" data-fileid="183" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS8.png.f7f38a39085f721ddbcd3fd527d8f283.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
2. From the popup menu, choose "New Host (A)". This will present the new host entry screen. </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS9.png.21af93149029881c75c877481b848517.png" data-fileid="184" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SplitDNS9.png.21af93149029881c75c877481b848517.png" data-fileid="184" data-src="https://www.edugeek.net/uploads/monthly_2013_01/SplitDNS9.png.21af93149029881c75c877481b848517.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
You will need to know the internal ip address of your host to publish at this point. For me - that was simple - its our ISA/TMG server. Why? Well, remember right at the top of this article.... all our services are published via our ISA/TMG box. Ensure at this point you also enter the name as used externally too (so this would be webmail or gateway in our example... nb, you don't need to put the rest of the address in as that is the dns domain).</p><p> </p><p>
<strong>Internal SSO without logon dialogs</strong></p><p>
So, the last bit needs some changes on TMG. We need a new web listener, which will be waiting for incoming requests only from the internal network. This will need HTTP authentication not forms authentication (which our external network will be using) - this allows it to use the same details that TMG/ISA itself is using to recognising our clients already for things like proxy (if you are using it). </p><p> </p><p>
We than also need to change our existing rule so that it only listens on the external network. That's not where it ends though - as we then need a load of new publishing rules for our services to match up to our listener. </p><p> </p><p>
That will be the subject of the next post - as will the playing with the three-headed dog that is Kerberos!</p><p> </p><p>
Also in the writing is my BETT preview post; and following that, some interesting interviews from BETT 2013 itself.</p>]]></description><guid isPermaLink="false">790</guid><pubDate>Sun, 20 Jan 2013 21:02:10 +0000</pubDate></item><item><title>Improving the Remote Desktop / Thin Client experience</title><link>https://www.edugeek.net/blogs/entry/788-improving-the-remote-desktop-thin-client-experience/</link><description><![CDATA[<p>Those who follow my blogs will know that I run a Thin Client section of my network - powered by Windows Thin PC (aka Windows 7 lite... it runs NT6.1) with Server 2008 R2.</p><p> </p><p>
This post follows <a href="https://www.edugeek.net/blogs/thescar...nt-part-2.html" rel="">http://www.edugeek.net/blogs/thescar...nt-part-2.html</a> and </p><p> </p><p>
Introduction</p><p>
Last time out on RDS, we set up Single Sign on, so that our users would log onto a Windows Thin PC as themselves, and changed the shell from "explorer.exe" so that instead a Remote Desktop session was triggered. This would automatically use the details of the user, without showing the real local desktop on the Thin PC.</p><p> </p><p>
There was only one problem with this, the users were slowed down by a double log on. Once to the Thin PC, and once to the RDS farm server. So, back to the original plan... A single autologon user, with a restricted environment. This environment would need no start menu or desktop, except for a single shortcut to launch the Remote Desktop. This is where the actual user login would happen.</p><p> </p><p>
So, we need to undo the below, which I've copied from my original article...</p><p> </p><p>
Allow Default Credential Usage for Single Sign-On (SSO)</p><p>
Now that we have authentication configured, we need to finish the process. To do this, you need to go to the client system (Vista, or 2008) and configure the Local Group Policy Editor. On your client computer open the Local Group Policy Editor. To open Local Group Policy Editor, go to Start, and in the Start Search box, type gpedit.msc and then press ENTER. In the Editor, look in the left pane and expand Computer Configuration =&gt; Administrative Templates =&gt; System =&gt; and then click Credentials Delegation. Double-click the Delegating Default Credentials setting to open it. </p><p> </p><p>
Next, in the Properties dialog box on the Setting tab, select Enabled, and then select Show. In the Show Contents dialog box, click Add to add servers to the list. In the Add Item dialog box, type the prefix termsrv/ followed by the name of the Terminal Server you will be connecting too. Once you have added the server name, click OK to close the Add Item dialog box. Click OK a few times until you are back in the Local Group Policy Editor and close the MMC. </p><p> </p><p>
We also need to change a few other registry keys to enable the auto login, and put the shell back. As I'm writing this on my ipad, I will upload the script or screenshots of the GPOs later on.</p><p> </p><p>
As usual, any queries or things you would like me to cover... Drop me a line or find me on the usual social network spaces!</p>]]></description><guid isPermaLink="false">788</guid><pubDate>Wed, 26 Dec 2012 16:32:31 +0000</pubDate></item><item><title>System Centre... playing with Service Manager</title><link>https://www.edugeek.net/blogs/entry/775-system-centre-playing-with-service-manager/</link><description><![CDATA[<p>Ok, so I think people who follow my work often will know that Im a bit of a fan of the whole System Centre thing (yes - I know ive spelt System Centre properly, not the American "Center" that gets used everywhere!).</p><p> </p><p>
You see, Configuration Manager - formerly Systems Management Server has always been a winner for me; but the real power now comes if you extend the stort by combining the elements of the suite together. System Centre is designed so that its components share information with eachother - to give you a complete picture and management of your system.</p><p> </p><p>
Take this scenario...</p><p> </p><p>
A machine develops a fault, or a bit of software fails to install. Operations Manager sees the fault and records it. Service Manager picks up information from Operations Manager, and generates a ticket. The ticket generation is assigned a category by the rules set up in it, which in turn sets of an automated routine "Workbook", which could be to instruct Configuration Manager to push the software again - or rebuild the machine.</p><p> </p><p>
Neat eh... or scary depending how you look at it.</p><p> </p><p>
So, in this post, Im going to deal just with Service Manager. This nice little (well big) bit of kit is Microsoft's answer to ITIL, and it has to be said, theyve made a pretty good go at it too. To start with, you will think its a complicated beast. There are some great getting starting guides for it out there though. The bit I was most concerned with was how to integrate it into my existing procedures. You see, Ive had a helpdesk system for a while - Ive been a big fan of GLPI (<a href="http://www.glpi-project.org" rel="external nofollow">http://www.glpi-project.org</a>). So, its web interface was customised and built into our Sharepoint Intranet (I'll return to blogging about Sharepoint in the future); as well as having email submission and alerts.</p><p> </p><p>
SCSM has a web portal component... great! Bad... it usually installs its own Sharepoint instance and site collection. Not what we want here. I want to integrate it into my existing Sharepoint install. Oh, and just to top off the complicated-ness...this needs to work via TMG (formerly known as ISA)...</p><p> </p><p>
Theres a few gotchas with this process...and thats the point of this article.</p><p> </p><p>
To begin my journey, lets start with the Shared Services Portal or SSP. The SSP is fundamental, it’s not that difficult to install, but there are some gotchas. The blank Silverlight screen has been seen a lot - just try googling Service Manager Portal Blank. For me there were two main hurdles to setting this up, first was the whole "already having an existing Sharepoint", and second getting the SSP to work through our Forefront TMG server. I’ll walk through the whole process and hopefully it may help any out there needing to do the same.</p><p> </p><p>
OK, so a dead simple setup really; install Service Manager - followed by the Web Content part (on the same server), which plugs into the Service Manager’s SQL backend. Then, we need to deal with getting the Sharepoint solution (WSP file, for those who dont usually play with Sharepoint) out of the installation so that it can be instInitially getting internal users up and running, then getting external access working later on.</p><p> </p><p>
The basic structure of how you would usually install SCSM is shown below.</p><p> </p><p>
[ATTACH=CONFIG]16152[/ATTACH]</p><p> </p><p>
Now, the actual install for the main SCSM application and database is quite simple.</p><p> </p><p>
[ATTACH=CONFIG]16154[/ATTACH]</p><p> </p><p>
From the installer, you want the Management Server first; then you want the Web Portal. The first part is relatively self explanitory, the second - we need to be a bit more careful with.</p><p> </p><p>
1. Tick just Web Content Server</p><p>
2. The usual Name, Organization, and the obligatory tick license agreement</p><p>
3. Keep the installation location as default, unless you really need to change it.</p><p>
4. The installer will check over your system. On the next page it will run through the pre-reqs, often warnings are for the SQL Management Objects or Memory - it can be a bit hungry!</p><p>
5.  OK, heres where things get a bit more complex. So that our external access will work properly (and Im assuming here that your Intranet login uses HTTPS [443] here) you need to set the port as 443 for SSL. You will also need to import your certificate for the content server (note - this needs to be the same certificate you are using on your external access TMG/ISA box).</p><p>
6. Change the Database Server and Instance to point to the SCSM SQL server, and select the database</p><p>
7. Enter the Service Account for SCSM and test the credentials</p><p>
8. On the following pages make a choice for Customer Experience and Updates</p><p>
9. Review selections, Install</p><p> </p><p>
This will have done the Web Content Server bit, but now we need to deal with the Sharepoint end, that actually gives the user interface. A full guide on this can be found at <a href="http://blog.scsmsolutions.com/2012/02/install-scsm12-web-parts-to-existing-sharepoint/" rel="external nofollow">http://blog.scsmsolutions.com/2012/02/install-scsm12-web-parts-to-existing-sharepoint/</a></p><p> </p><p>
In summary though, you need to get the WSP from the install. This means going routing through the installation media to get it! Search for *.wsp and you should find it - it is called "Microsoft.EnterpriseManagement.ServiceManager.Portal.SharePointSite.wsp".</p><p> </p><p>
Then, run the sequence of commands on your Sharepoint server...</p><p>
1. Launch the “SharePoint 2010 Management Shell” (PowerShell) </p><p>
2. To install solution run command: Add-SPSolution “c:\SMPortal\Microsoft.EnterpriseManagement.ServiceManager.Portal.SharePointSite.wsp” (where you have copied the wsp to the path C:\SMPortal)</p><p>
3. To install solution run the command: Install-SPSolution Microsoft.EnterpriseManagement.ServiceManager.Portal.SharePointSite.wsp –GACDeployment </p><p>
4. To activate solution run command (also you can do the same at Site Properties): Enable-SPFeature SMPortalSharePointSiteFeatures -Url <a href="http://portal" rel="external nofollow">http://portal</a> where <a href="http://portal" rel="external nofollow">http://portal</a> – full URL of the site collection where you plan to use SCSM web-parts.</p><p> </p><p>
Next up - a bit of web.config editing!</p><p>
So that dd new setting named “SMPortal_WebContentServer_URL” and set its value to “http://webcontentserver:port/ContentHost/ClientBin/” where webcontentserver:port is name and port of prevision installed SCSM web content server. Note to protocol (http or https). Now, this is another cause of the blank screens. This path needs to match your external path followed by "/ContentHost/ClientBin/". Seems odd, but once we configure TMG, it will make sense. We are making it so that all the communication routes are always available throught one consistant path.</p><p> </p><p>
Over to TMG now...</p><p> </p><p>
We need an access rule, that publishes our /ContentHost path higher up than our main Sharepoint rule - otherwise the /ContentHost path will never be processed.</p><p> </p><p>
Create a new access rule in TMG</p><p>
Now I needed to create a Web Publishing Rule on the TMG server to allow the bridging from 443 outside to 444 inside. Luckily for here the Silverlight web part uses specific paths, I can use these so as not to disturb my rule for the SharePoint web site.</p><p> </p><p>
1. Logon to the TMG server</p><p>
2. Start-up the Forefront TMG console</p><p>
3. Create a new Web Publishing Rule above the SharePoint web site access rule, and set the following…</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_11/clip_image059.jpg.402168f7c4770df3af92bbef085614ac.jpg" data-fileid="165" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="clip_image059.jpg.402168f7c4770df3af92bbef085614ac.jpg" data-fileid="165" data-src="https://www.edugeek.net/uploads/monthly_2012_11/clip_image059.jpg.402168f7c4770df3af92bbef085614ac.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_11/clip_image061.png.920861997a9e0a75149f5faaf6f94eae.png" data-fileid="166" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="clip_image061.png.920861997a9e0a75149f5faaf6f94eae.png" data-fileid="166" data-src="https://www.edugeek.net/uploads/monthly_2012_11/clip_image061.png.920861997a9e0a75149f5faaf6f94eae.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_11/clip_image063.png.b871d20fe588ad7530ac9564d2826342.png" data-fileid="167" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="clip_image063.png.b871d20fe588ad7530ac9564d2826342.png" data-fileid="167" data-src="https://www.edugeek.net/uploads/monthly_2012_11/clip_image063.png.b871d20fe588ad7530ac9564d2826342.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_11/clip_image065.jpg.751d4a99ef2d11d862e31d2031257f03.jpg" data-fileid="168" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="clip_image065.jpg.751d4a99ef2d11d862e31d2031257f03.jpg" data-fileid="168" data-src="https://www.edugeek.net/uploads/monthly_2012_11/clip_image065.jpg.751d4a99ef2d11d862e31d2031257f03.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
4. Once these change were made the SSP worked internally and externally, all using the same URL and same certificate.</p><p> </p><p>
Bingo!</p>]]></description><guid isPermaLink="false">775</guid><pubDate>Fri, 30 Nov 2012 23:26:42 +0000</pubDate></item><item><title>Setting Printers through Group Policy...an encore... (and the death of Scripts)</title><link>https://www.edugeek.net/blogs/entry/770-setting-printers-through-group-policyan-encore-and-the-death-of-scripts/</link><description><![CDATA[<p>Well, I know its been a long time since my last published blog post! The truth is Ive been working on a few for a while now - but just never got round to finishing any of them.</p><p> </p><p>
Heres the first of my next batch... a return to an earlier thread of posts, originally related to Printing on Remote Desktop.</p><p> </p><p>
First, a bit of background... traditionally, most systems will be set up to map printers via a logon script. The script typically checks a machine name and adds the appropriate printers based on that.</p><p> </p><p>
Because we add some Wyse Thin Clients into that mix, the old machine naming thing doesnt work, so we have to start looking at grouping users. Thankfully - Group Policy Preferences covers this. That was my last post on the subject.</p><p> </p><p>
Now, I like completeness and uniformity across the system - so the fact that part of the system had printers set through group membership and a group policy preference that checked that membership; whilst the rest used a script was a faff! Add to that that our Windows Thin PC remote desktop terminals had a different way - they had to use a startup script meant that any changes meant three different sets of updates.</p><p> </p><p>
Well, in the bin that went after following up the capabilities of the Group Policy Printing Preferences a bit more... it became clear that we could also use the same kind of machine name based check in there too.</p><p> </p><p>
Next up, just the Windows Thin PCs. Actually, they were even simpler as Microsoft have done their homework on this. There is actually an option for Remote Desktop (Terminal Server) Client name. Bingo... as our Thin PCs also used a sensible naming convention, we could target based on this</p><p> </p><p>
A bit of bedtime reading on this - heres a good article found whilst researching writing this up. </p><p> </p><p>
<a href="http://www.virtualizationadmin.com/articles-tutorials/vdi-articles/general/printing-microsoft-rds-environments-how-evolved-todays-technology.html" rel="external nofollow">http://www.virtualizationadmin.com/articles-tutorials/vdi-articles/general/printing-microsoft-rds-environments-how-evolved-todays-technology.html</a></p><p> </p><p>
This is a great resource to use for lots of VDI and Remote Desktop updates...</p>]]></description><guid isPermaLink="false">770</guid><pubDate>Wed, 21 Nov 2012 22:25:11 +0000</pubDate></item><item><title>Exporting SQL Logons</title><link>https://www.edugeek.net/blogs/entry/741-exporting-sql-logons/</link><description><![CDATA[<p>Another diversion from my usual blog posts - but this one came out of necessity, when I had issues with my SQL databases for SIMS and FMS. Many of you may know that FMS has its own "SQL" logins, as does SIMS - but at least with that, you can set it to use Windows Authentication.</p><p> </p><p>
Anyway, my problem - I was greeted by FMS with the lovely "Cannot rollback atomic" error whenever logging in. It turns out this error (after some digging) has lots of causes - none of them really to do with SIMS or FMS.</p><p> </p><p>
This error is documented here <a href="https://www.edugeek.net/forums/mis-systems/99696-fms-fault.html" rel="">http://www.edugeek.net/forums/<abbr title="Management Information System">mis</abbr>-systems/99696-fms-fault.html</a> most recently, and <a href="https://www.edugeek.net/forums/mis-systems/25956-fms-problem.html" rel="">http://www.edugeek.net/forums/<abbr title="Management Information System">mis</abbr>-systems/25956-fms-problem.html</a> historically. There are also some SupportNet articles on it too. </p><p> </p><p>
 It is, as the error states an SQL error. Essentially - what has happened is that a transaction is in a "stuck state" relating to a login. Ways of clearing it... well first off - when was your last backup - and have you been doing backups using DBAttach. </p><p> </p><p>
If not, then we are going to need a copy of all the SQL logins so we can recreate them. If you detattach and reattach a SIMS/FMS DB without it (ie move a server) - then you wont have you logins brought across. </p><p> </p><p>
The script to do this is as shown below. You need SQL Management Studio for this, and then you are thinking - how do I run it? Well, copy and paste it into a "New Query" (yes - click the "New Query" button in Studio. Then, its Execute. The output from this needs saving somewhere safe.</p><p> </p><p>
Next up, run DBAttach to dettach the database. This will run its own backup - but I would still take your own first. Then - go into your SQL Data folder, and copy (yes, copy) the two database files for FMS (and or SIMS) out somewhere else for safe keeping. Rename them something sensible (like add the date and time on the end). Remove them from the SQL Data folder... as when you run DBAttach to re-attach the DBS (point at your backup, or the files you just had) - it will copy them back into the SQL Data folder.</p><p> </p><p>
Check after doing the DBAttach (to dettach...confused with all that yet!) that the DB has gone from SQL Studio. Also look in the Logins under Security whether your user accounts are still there. If the first time of this full procedure fails, I would try removing your offending logins - as the import script (the output of running the query script shown here) will recreate them.</p><p> </p><p>
Hope this helps.</p><p> </p><p>
Of course - this is all at your own risk, and will not be supported by Capita. That being said, this is likely what they do if they have to have your DB to look at - and its what I did with my local support team.</p><p> </p><p>
</p><pre class="ipsCode">
USE master
GO
IF OBJECT_ID ('sp_hexadecimal') IS NOT NULL
 DROP PROCEDURE sp_hexadecimal
GO
CREATE PROCEDURE sp_hexadecimal
   @binvalue varbinary(256),
   <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/14938-hex/" data-mentionid="14938" data-ipshover-target="https://www.edugeek.net/profile/14938-hex/?do=hovercard" data-ipshover="">@Hex</a>value varchar (514) OUTPUT
AS
DECLARE @charvalue varchar (514)
DECLARE @i int
DECLARE <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/40871-leng/" data-mentionid="40871" data-ipshover-target="https://www.edugeek.net/profile/40871-leng/?do=hovercard" data-ipshover="">@leng</a>th int
DECLARE <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/14938-hex/" data-mentionid="14938" data-ipshover-target="https://www.edugeek.net/profile/14938-hex/?do=hovercard" data-ipshover="">@Hex</a>string char(16)
SELECT @charvalue = '0x'
SELECT @i = 1
SELECT <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/40871-leng/" data-mentionid="40871" data-ipshover-target="https://www.edugeek.net/profile/40871-leng/?do=hovercard" data-ipshover="">@leng</a>th = DATALENGTH (@binvalue)
SELECT <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/14938-hex/" data-mentionid="14938" data-ipshover-target="https://www.edugeek.net/profile/14938-hex/?do=hovercard" data-ipshover="">@Hex</a>string = '0123456789ABCDEF'
WHILE (@i &lt;= <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/40871-leng/" data-mentionid="40871" data-ipshover-target="https://www.edugeek.net/profile/40871-leng/?do=hovercard" data-ipshover="">@leng</a>th)
BEGIN
 DECLARE <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/18983-temp/" data-mentionid="18983" data-ipshover-target="https://www.edugeek.net/profile/18983-temp/?do=hovercard" data-ipshover="">@temp</a>int int
 DECLARE @firstint int
 DECLARE @secondint int
 SELECT <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/18983-temp/" data-mentionid="18983" data-ipshover-target="https://www.edugeek.net/profile/18983-temp/?do=hovercard" data-ipshover="">@temp</a>int = CONVERT(int, SUBSTRING(@binvalue,@i,1))
 SELECT @firstint = FLOOR <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/18983-temp/" data-mentionid="18983" data-ipshover-target="https://www.edugeek.net/profile/18983-temp/?do=hovercard" data-ipshover="">@temp</a>int/16)
 SELECT @secondint = <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/18983-temp/" data-mentionid="18983" data-ipshover-target="https://www.edugeek.net/profile/18983-temp/?do=hovercard" data-ipshover="">@temp</a>int - (@firstint*16)
 SELECT @charvalue = @charvalue +
   SUBSTRING <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/14938-hex/" data-mentionid="14938" data-ipshover-target="https://www.edugeek.net/profile/14938-hex/?do=hovercard" data-ipshover="">@Hex</a>string, @firstint+1, 1) +
   SUBSTRING <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/14938-hex/" data-mentionid="14938" data-ipshover-target="https://www.edugeek.net/profile/14938-hex/?do=hovercard" data-ipshover="">@Hex</a>string, @secondint+1, 1)
 SELECT @i = @i + 1
END

SELECT <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/14938-hex/" data-mentionid="14938" data-ipshover-target="https://www.edugeek.net/profile/14938-hex/?do=hovercard" data-ipshover="">@Hex</a>value = @charvalue
GO

IF OBJECT_ID ('sp_help_revlogin') IS NOT NULL
 DROP PROCEDURE sp_help_revlogin
GO
CREATE PROCEDURE sp_help_revlogin <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/31126-log/" data-mentionid="31126" data-ipshover-target="https://www.edugeek.net/profile/31126-log/?do=hovercard" data-ipshover="">@log</a>in_name sysname = NULL AS
DECLARE @name sysname
DECLARE @type varchar (1)
DECLARE <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/35550-has/" data-mentionid="35550" data-ipshover-target="https://www.edugeek.net/profile/35550-has/?do=hovercard" data-ipshover="">@has</a>access int
DECLARE <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/16775-den/" data-mentionid="16775" data-ipshover-target="https://www.edugeek.net/profile/16775-den/?do=hovercard" data-ipshover="">@den</a>ylogin int
DECLARE @is_disabled int
DECLARE @PWD_varbinary  varbinary (256)
DECLARE @PWD_string  varchar (514)
DECLARE <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/7368-sid/" data-mentionid="7368" data-ipshover-target="https://www.edugeek.net/profile/7368-sid/?do=hovercard" data-ipshover="">@sid</a>_varbinary varbinary (85)
DECLARE <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/7368-sid/" data-mentionid="7368" data-ipshover-target="https://www.edugeek.net/profile/7368-sid/?do=hovercard" data-ipshover="">@sid</a>_string varchar (514)
DECLARE @tmpstr  varchar (1024)
DECLARE @is_policy_checked varchar (3)
DECLARE @is_expiration_checked varchar (3)

DECLARE @defaultdb sysname

IF  <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/31126-log/" data-mentionid="31126" data-ipshover-target="https://www.edugeek.net/profile/31126-log/?do=hovercard" data-ipshover="">@log</a>in_name IS NULL)
 DECLARE login_curs CURSOR FOR

     SELECT p.sid, p.name, p.type, p.is_disabled, p.default_database_name, l.hasaccess, l.denylogin FROM 
sys.server_principals p LEFT JOIN sys.syslogins l
     ON ( l.name = p.name ) WHERE p.type IN ( 'S', 'G', 'U' ) AND p.name &lt;&gt; 'sa'
ELSE
 DECLARE login_curs CURSOR FOR


     SELECT p.sid, p.name, p.type, p.is_disabled, p.default_database_name, l.hasaccess, l.denylogin FROM 
sys.server_principals p LEFT JOIN sys.syslogins l
     ON ( l.name = p.name ) WHERE p.type IN ( 'S', 'G', 'U' ) AND p.name = <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/31126-log/" data-mentionid="31126" data-ipshover-target="https://www.edugeek.net/profile/31126-log/?do=hovercard" data-ipshover="">@log</a>in_name
OPEN login_curs

FETCH NEXT FROM login_curs INTO <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/7368-sid/" data-mentionid="7368" data-ipshover-target="https://www.edugeek.net/profile/7368-sid/?do=hovercard" data-ipshover="">@sid</a>_varbinary, @name, @type, @is_disabled, @defaultdb, <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/35550-has/" data-mentionid="35550" data-ipshover-target="https://www.edugeek.net/profile/35550-has/?do=hovercard" data-ipshover="">@has</a>access, <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/16775-den/" data-mentionid="16775" data-ipshover-target="https://www.edugeek.net/profile/16775-den/?do=hovercard" data-ipshover="">@den</a>ylogin
IF (@@fetch_status = -1)
BEGIN
 PRINT 'No login(s) found.'
 CLOSE login_curs
 DEALLOCATE login_curs
 RETURN -1
END
SET @tmpstr = '/* sp_help_revlogin script '
PRINT @tmpstr
SET @tmpstr = '** Generated ' + CONVERT (varchar, GETDATE()) + ' on ' + @@SERVERNAME + ' */'
PRINT @tmpstr
PRINT ''
WHILE (@@fetch_status &lt;&gt; -1)
BEGIN
 IF (@@fetch_status &lt;&gt; -2)
 BEGIN
   PRINT ''
   SET @tmpstr = '-- Login: ' + @name
   PRINT @tmpstr
   IF (@type IN ( 'G', 'U'))
   BEGIN -- NT authenticated account/group

     SET @tmpstr = 'CREATE LOGIN ' + QUOTENAME( @name ) + ' FROM WINDOWS WITH DEFAULT_DATABASE = [' + @defaultdb + ']'
   END
   ELSE BEGIN -- SQL Server authentication
       -- obtain password and sid
           SET @PWD_varbinary = CAST( LOGINPROPERTY( @name, 'PasswordHash' ) AS varbinary (256) )
       EXEC sp_hexadecimal @PWD_varbinary, @PWD_string OUT
       EXEC sp_hexadecimal <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/7368-sid/" data-mentionid="7368" data-ipshover-target="https://www.edugeek.net/profile/7368-sid/?do=hovercard" data-ipshover="">@sid</a>_varbinary <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/7368-sid/" data-mentionid="7368" data-ipshover-target="https://www.edugeek.net/profile/7368-sid/?do=hovercard" data-ipshover="">@sid</a>_string OUT

       -- obtain password policy state
       SELECT @is_policy_checked = CASE is_policy_checked WHEN 1 THEN 'ON' WHEN 0 THEN 'OFF' ELSE NULL END FROM sys.sql_logins WHERE name = @name
       SELECT @is_expiration_checked = CASE is_expiration_checked WHEN 1 THEN 'ON' WHEN 0 THEN 'OFF' ELSE NULL END FROM sys.sql_logins WHERE name = @name

           SET @tmpstr = 'CREATE LOGIN ' + QUOTENAME( @name ) + ' WITH PASSWORD = ' + @PWD_string + ' HASHED, SID = ' + <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/7368-sid/" data-mentionid="7368" data-ipshover-target="https://www.edugeek.net/profile/7368-sid/?do=hovercard" data-ipshover="">@sid</a>_string + ', DEFAULT_DATABASE = [' + @defaultdb + ']'

       IF ( @is_policy_checked IS NOT NULL )
       BEGIN
         SET @tmpstr = @tmpstr + ', CHECK_POLICY = ' + @is_policy_checked
       END
       IF ( @is_expiration_checked IS NOT NULL )
       BEGIN
         SET @tmpstr = @tmpstr + ', CHECK_EXPIRATION = ' + @is_expiration_checked
       END
   END
   IF  <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/16775-den/" data-mentionid="16775" data-ipshover-target="https://www.edugeek.net/profile/16775-den/?do=hovercard" data-ipshover="">@den</a>ylogin = 1)
   BEGIN -- login is denied access
     SET @tmpstr = @tmpstr + '; DENY CONNECT SQL TO ' + QUOTENAME( @name )
   END
   ELSE IF  <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/35550-has/" data-mentionid="35550" data-ipshover-target="https://www.edugeek.net/profile/35550-has/?do=hovercard" data-ipshover="">@has</a>access = 0)
   BEGIN -- login exists but does not have access
     SET @tmpstr = @tmpstr + '; REVOKE CONNECT SQL TO ' + QUOTENAME( @name )
   END
   IF (@is_disabled = 1)
   BEGIN -- login is disabled
     SET @tmpstr = @tmpstr + '; ALTER LOGIN ' + QUOTENAME( @name ) + ' DISABLE'
   END
   PRINT @tmpstr
 END

 FETCH NEXT FROM login_curs INTO <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/7368-sid/" data-mentionid="7368" data-ipshover-target="https://www.edugeek.net/profile/7368-sid/?do=hovercard" data-ipshover="">@sid</a>_varbinary, @name, @type, @is_disabled, @defaultdb, <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/35550-has/" data-mentionid="35550" data-ipshover-target="https://www.edugeek.net/profile/35550-has/?do=hovercard" data-ipshover="">@has</a>access, <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/16775-den/" data-mentionid="16775" data-ipshover-target="https://www.edugeek.net/profile/16775-den/?do=hovercard" data-ipshover="">@den</a>ylogin
  END
CLOSE login_curs
DEALLOCATE login_curs
RETURN 0
GO
</pre><div></div><p></p>]]></description><guid isPermaLink="false">741</guid><pubDate>Wed, 15 Aug 2012 08:44:17 +0000</pubDate></item><item><title>Network Managers Event - 11th July 2012</title><link>https://www.edugeek.net/blogs/entry/739-network-managers-event-11th-july-2012/</link><description><![CDATA[<p>On Wednesday 11th July, I was pleased to be able to welcome collegues from the Plymouth area to a “pilot” meeting – where we could discuss and collaborate on the various challenges we faced. We were also fortunate to be joined by a number of industry specialists to offer their advice and details of emerging trends. </p><p> </p><p>
The event started with Paul Harris, from the Micrsosoft Schools Business Team. Paul opened with the advert for Microsoft Surface – and that is the new Microsoft Surface, the tablet/slate; not the table which used to have the same product name. The original “Surface” is now called PixelSense. </p><p> </p><p>
The video – and the new site – can be found here <a href="http://www.microsoft.com/surface/en/us/default.aspx" rel="external nofollow">http://www.microsoft.com/surface/en/us/default.aspx</a> </p><p> </p><p>
The stirring introduction over, we moved into the Microsoft Lync managed presentation and demo – sadly Paul couldn’t join us in person. Paul talked about the forthcoming Windows 8 release – and announced the RTM in August; for Software Assurance customers this would be available nearly instantly. We were shown how Windows 8 was designed to bridge the gap between the personal device and the corporate device – one environment on both, which was everything you needed at the time. Office 365 for Education now being free was another big announcement which was discussed – and how it can encourage collaboration and efficiency. The slide deck for the presentation can be viewed here: <a href="http://sdrv.ms/S3buhe" rel="external nofollow">http://sdrv.ms/S3buhe</a></p><p> </p><p>
Next up was Chris Lim from Trustmarque Solutions – the first of two “industry insight” sessions from them. Chris presented about Processes and Procedures for the Success of IT Support. ITIL is the framework used in industry, the education sector has its own implementation of this – FITS. The slide deck can be viewed here: [ATTACH]14898[/ATTACH]</p><p> </p><p>
A break followed, then we moved into a brief discussion and presentation from yours truly about recent partnership work with Microsoft. As many have noticed, there has been a blog series on the Microsoft Schools Blog about systems implementation and change – IT Systems for the Future. The platform – HyperV; and the management system – SCCM, were both shown – and the fact that this was only part of the story when we want to talk integration. Bringing the FITS processes in, designed to bring structure; I overviewed how theses “landed” in real life. If anyone would like any further information about this; or would like a site visit – please let me know. </p><p> </p><p>
With all the recent talk of Academies – Terry Watts (scomis), updated us about recent changes to their support model for Schools. SIMS changes, service updates and performance were all on the agenda! A brand new training suite was also opened at their offices in Exeter two days later, where further evidence of their growing partnerships with industry players was clear.  </p><p> </p><p>
Lunch followed, where there was plenty of opportunity to catch up with colleagues and the presentation team. There certainly seemed to be lots of collaboration and networking going on, new and long standing colleagues alike. </p><p> </p><p>
Sean from Smoothwall joined us to talk us though how the "Bring your own" (BYOD) agenda can be safely implemented with your systems to ensure esafety. We were shown details of the product range in brief, but the discussion centred more around the concepts of safe internet access - and the perennial filtering argument. Their slide deck can be viewed here: [Coming Soon]</p><p> </p><p>
Also involed were the team from Overland Storage. The change in the curriculum is having a significant impact on all our systems - with ever increasing demands on space. Digital media is becoming the defacto standard for curriculum delivery, and it is well recognised that the most inspiring content is audio and video. Overland discussed how they have seen industry deal with the same challenges - which can be equated to the increasing training and supporting literature demands. Further to this, there is then the challege of security of this data, ie backing it up. A pilot project is expected to start over the coming months with Schools backing up to eachother. A slide deck provided by the team can be viewed here: <a href="https://www.edugeek.net/applications/core/interface/file/attachment.php?id=158" data-fileid="158" data-fileext="pptx" rel="">The Storage Conundrum - Plymouth IT Mgrs.pptx</a> </p><p> </p><p>
Another break - and then it was back to TrustMarque for their second presentation of the day. This time, it was centred on Licensing - and how to get the most from it. Most are familiar with EES, and the benefits it has had for the UK market. Often misunderstood - Fiona talked to us about the product set available, and the ways to ensure best value. We then moved on to Adobe - and I was thrilled that Fiona was able to announce a new "EES like" model is being developed by them for the Creative Suite. This has the potential to save schools thousands - and it wont just be limited to single Schools. Confederations will be supported so long as there are "defined links" between establishments. More information will follow on this as soon as it is available from Adobe UK. For now - Fiona's deck is available here: [ATTACH=CONFIG]14897[/ATTACH]</p><p> </p><p>
Lastly, it was over to Simon from Ruckus. Wireless has always been a contentious issue in Schools, ever since it was put out there as "the solution" by the media. In dense high use areas, Schools just havent been able to take advantage of it - with staff complaining of poor coverage, speed etc. Simon talked to us about what makes Ruckus different - based on its use in industry. He talked about the technology, not the product - and why wireless systems traditionally don’t work well. We were also shown the future. His slide deck will be added shortly. </p><p> </p><p>
I would like to thank all the Schools who gave their time to join us for what I hope was an enjoyable and informative day. Thanks must also go to all the Suppliers and Manufacturers who supported the event. Finally, a big thanks to Paul Harris from Microsoft for the Keynote; as well as the unseen names and assistants in setting the call up – Tim Bush and Mark Reynolds. </p><p> </p><p>
Contacts:</p><p> </p><p>
Paul Harris</p><p>
Consultant Internal Schools Business Manager to Microsoft Ltd</p><p>
<a href="mailto:" rel="">v-paharr@microsoft.com</a></p><p>
 <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/31327-paulnharris/" data-mentionid="31327" data-ipshover-target="https://www.edugeek.net/profile/31327-paulnharris/?do=hovercard" data-ipshover="">@paulnharris</a></p><p>
0118 909 4437</p><p> </p><p>
Chris Lim</p><p>
Solution Manager – Microsoft &amp; Integrated Solutions - TrustMarque Solutions</p><p>
<a href="mailto:" rel="">chris.lim@trustmarque.com</a></p><p> </p><p>
Terry Watts</p><p>
Engineer - scomis</p><p>
01392 385300</p><p> </p><p>
Neil Cogger</p><p>
Pre-Sales Manager - Overland Storage</p><p>
<a href="mailto:" rel="">ncogger@overlandstorage.com</a></p><p>
0118 989 8027 </p><p> </p><p>
Sean Lazenby</p><p>
Education Sales Manager - Smoothwall Ltd</p><p>
<a href="mailto:" rel="">sean.lazenby@smoothwall.net</a></p><p>
0113 3874 183</p><p> </p><p>
Fiona Gemmell</p><p>
Education Specialist - TrustMarque Solutions</p><p>
<a href="mailto:" rel="">fiona.gemmell@trustmarque.com</a></p><p>
01904 561 663</p><p> </p><p>
Simon Hollister</p><p>
Ruckus EMEA</p><p>
<a href="mailto:" rel="">simon.hollister@ruckuswireless.com</a></p>]]></description><guid isPermaLink="false">739</guid><pubDate>Tue, 07 Aug 2012 11:32:06 +0000</pubDate></item><item><title>Capita LA Conference 2012 - Alton Towers - Learning Gateway Product Update</title><link>https://www.edugeek.net/blogs/entry/724-capita-la-conference-2012-alton-towers-learning-gateway-product-update/</link><description><![CDATA[<p>Post 3 in this mini-series giving you the information from the Capita LA Event... and up this time; a bit of history of the SIMS Learning Gateway product with where it's headed. Incidentally at this point - this is probably the worst product name! It is NOT - never has been, never will be, was never supposed to be - a Learning Gateway. Nor was it ever going to be a replacement for SIMS.net! I did have some great discussions with Phil Neal and new product manager Ben Jones about this.</p><p> </p><p>
Now we have got that out of the way - what was this session all about? In short - the latest developments to the SIMS Learning Gateway [sLG] (grrr - there's that name again!). Ben Jones (and a nice big welcome to the new product manager) told us how his intention is to revitalise the product into playing a key role in a school's parental engagement policy whilst providing return on investment for schools.</p><p> </p><p>
Ben Jones, took over in Feb 2012... and was frank (as most of us as an audience were with him)  about the need for updates in a dramatically changing market place. The original product has been around since 2006; and Home School communications have changed a lot since then. There are many more products on the market - many with significantly more polished interfaces.</p><p> </p><p>
However, despite that backdrop - over 41 LAs host SLG. This is roughly 1 in 2 Secondaries and 1 in 8 Primaries.  450 are self hosted, 650 hosted on Capita Platform. Those are massive statistics, and its still rising...</p><p> </p><p>
This is a changing market - and not surprisingly after the demise of BECTA, there was a drop off in school take up. Since then, there has also been a push back against the drive.</p><p> </p><p>
Making good progress with the Assessment for Learning, driven by changes in the primary sector. Drive for quicker feedback and monitoring of truancy.</p><p> </p><p>
So what has been the success driving SLG adoption? This all centres around maximising the potential of SIMS. From the first post in this mini-series, I talked about Schools being data rich, and not quite knowing what to do with it... well SLG can help. It provides simple tools for viewing data, and can be a way of getting it in. The less IT literate amongst us are often happier with browser access - this is direct feedback from Schools. The future development of SLG is targetted to allow access from all tablets inc iPads.</p><p> </p><p>
The other driver is still parental engagement - which still forms part of Ofsted requirements. Despite some of the perceptions, it can offer cost and efficiency savings through reporting to parents online rather than on paper. In turn, this can drive up School standards and the School Community thought better feedback to parents and increasing reporting timescales. As a direct correlation to this, one of the latest updates to SLG surrounds parents. Data collection sheets are a classic case of inefficiency. These are traditionally printed and sent home with Students or completed on parents events. The online version will allow changes to be reported at the time, directly. An important note - the School stays in control of data at all times, choosing what changes get made; and like with the rest of the SLG framework - what information is shown.</p><p> </p><p>
What schools who are using the product actually say then? This may surprise you - direct honest feedback on the failings!</p><p> </p><p>
Communications and messaging</p><p>
Lack of understanding of capability. Redesigned marketing materials, with real life implementations</p><p>
Template how to guides and starter sheets available, based on real schools</p><p>
How to videos and guides</p><p>
Production of news letters, to keep users informed</p><p> </p><p>
The most important part of this discussion - and it was more of a discussion than a presentation - was outlining what was coming up.</p><p> </p><p>
<em>Summer</em></p><p>
</p><ul><li>Parental two way communication... Data collection sheets. Parents view what you want them to see, and allow them to modify it for approval by school.<br />
</li><li>Online reports will open in new window<br />
</li><li>Profiles, screen jumping to top of the page on refresh fixed<br />
</li><li>Report card, hide historical reports<br />
</li><li>Data collection sheet (more detail below)<br />
</li></ul><p></p><p> </p><p> </p><p>
Data collection sheet detailed discussion...</p><p>
This  feature was driven by the desire to reduce the need for paper copies (which get lost) and school chasing parents.</p><p> </p><p>
The system works through reusing drop down lists populated by options in SIMS - helping ensure data consistency. That being said, in certain areas, you will also be able to add free text where option not available.</p><p> </p><p>
To ensure legal compliance, you can hide contacts where "Do not disclose is set"</p><p> </p><p>
Marking a shift in the development in SLG - you might be surprised to seen that the screen is in a wizard format - actually making it visually pleasing for the user. According to Ben, this is part of a drive for the "new SLG" to be much more user friendly. The wizard displays as a series of screens:</p><p> </p><p>
</p><ul><li>Basic details<br />
</li><li>Contacts <br />
</li><li>Medical<br />
</li><li>Dietary<br />
</li><li>Travel<br />
</li><li>Ethnicity<br />
</li></ul><p></p><p> </p><p>
Currently missing is parental responsibility, eg when to teach PHSE. This is coming in autumn, when ability to choose which wizard screens are available.</p><p> </p><p>
As to be expected with a wizard - a "finish" option shows you the entries you have made with confirmation. This removes the ability to make other changes after, until they are approved. The School can view the information in Routines, SLG, Data Collection. This is not auto copying yet. Instead, until added in Autumn, there is a copy option with a link to where the data needs to go. You then mark them as actioned and closed.</p><p> </p><p>
<em>Autumn</em></p><p>
</p><ul><li>Auto writeback, with validation<br />
</li><li>SLG teacher attendance iPad compatibility, popup with bigger buttons<br />
</li><li>Homework enhancements to include homework data fields in reporting<br />
</li><li>Mark sheet autosave<br />
</li></ul><p></p><p> </p><p> </p><p>
<em>Coming soon</em></p><p>
</p><ul><li>Mobile view versions<br />
</li><li>Drive adoption of student use through above<br />
</li><li>Options web part for choosing from above<br />
</li></ul><p></p><p> </p><p> </p><p>
And the future of SLG? The roadmap on SupportNet shows all - and is being regularly updated by Ben. The product can only grow with the support and feedback from the community.</p><p> </p><p>
</p><ul><li>Ui refresh of web parts for student details... Spring<br />
</li><li>Mobile views<br />
</li><li>Password reset process<br />
</li><li>Discover integration... Could lead to governor website, <abbr title="Senior Leadership Team">slt</abbr>, parents view of their child as part of cohort<br />
</li><li>Homework enhancements<br />
</li><li>Pick which documents to publish<br />
</li></ul><p></p>]]></description><guid isPermaLink="false">724</guid><pubDate>Tue, 10 Jul 2012 15:00:00 +0000</pubDate></item><item><title>Capita LA Conference 2012 - Alton Towers - Key Note: Tony Travers</title><link>https://www.edugeek.net/blogs/entry/723-capita-la-conference-2012-alton-towers-key-note-tony-travers/</link><description><![CDATA[<p>This post continues from my last - discussing the themes and news from the Capita LA Conference. I know this will come as a surprise to some, who will have been expecting more "geeky" System Centre or HyperV stuff - but my community work will also form my blogs too!</p><p> </p><p>
The Key Note speech at the event was made by Tony Travers. Tony Travers is Director of the London School of Economics and Political Science, a research centre at the London School of Economics. He is also a Visiting Professor in the LSE’s Government Department; whos research interests include local and regional government and public service reform. He is currently an advisor to the House of Commons Children, Schools and Families Select Committee and the Communities and Local Government Select Committee. He has published a number of books on cities and government, including Failure in British Government, The Politics of the Poll Tax (with David Butler and Andrew Adonis), Paying for Health, Education and Housing: How does the Centre Pull the Purse Strings (with Howard Glennerster and John Hills) and The Politics of London: Governing the Ungovernable City. </p><p> </p><p>
Here though - he talked to us about the way in which management and support of Schools has changed.</p><p> </p><p>
Looking back, Schools started and were maintained locally by bodies often formed by churches. After 1945 onwards, e state stepped in, with LEAs. Were schools then a local service or a national service, really a mix of the two.</p><p> </p><p>
From 1976 onwards, there was greater Government involvement - increasing to the general "tinkering" which every successive power has felt the need to do.</p><p> </p><p>
The national curriculum was introduced, followed by endless fiddling with curriculums and exams - which continues to this day. You only have to look at the news lately to see a new <abbr title="Information and Communications Technology">ICT</abbr> Curriculum (now this one I do agree with); changes to the GCSE system, changes to numeracy and literacy expectations from Primary and more.</p><p> </p><p>
All of this "tinkering" has had a purpose though. The new models have been designed to drive improvement, but how much of is a remodelling of the past, academies and free schools are similar to and an evolution of the old grant maintained schools. We now have a mixture of types of school, giving choice to parents. League tables and inspections allow that to be an informed choice, and to enforce performance. The pupil premium drives improvement by competition between schools. More students equals greater funding. Has this led to a reduced role for local government?</p><p> </p><p>
What is the role?</p><p> </p><p>
Admissions, centrally provided services and ensuring capital investment by ensuring places are available.</p><p> </p><p>
Little power to close failing academies, or plan the system of local schools. Loss of fiscal power too.</p><p> </p><p>
However, the growth area has been that Councils can also provide ancillary services... Free School Meals, insurance, supply, under achieving pupils, insurance, information services, economies of scale services are just some examples of this.</p><p> </p><p>
The long and short of it is that LAs have moved from being providers and controllers, to more limited role. Instead, new and strengthened central bodies from Whitehall - Ofsted, Education Funding Agency, DfE.</p><p> </p><p>
So, what does the future hold, and what issues could it present?</p><p> </p><p>
The economy is the obvious first point. The constant drive to cut costs brings the challenge of weak growth and likelyhood of school funding being held at below inflation levels. There is bound to be the continuation of new policies - the move to introduce more Academies and the growth of Free Schools. Only in the news in the past few weeks were the announcements to push failing Primaries into Academy Status. To gain a perceived better control of costs, there is also likely to be a further centralisation of funding.</p><p> </p><p>
Where does all of this leave LAs? It all looks bleak for them, indeed many thought the LA IT role would all but disappear. Instead, a new LA role has grown - to be the invisible guiding role. There to be supporting, able to give guidance; and taking an active interest locally - which central powers cannot do.</p><p> </p><p>
They are also in a position to be delivering value for money though economies of scale projects and services - on a local level, coordinating the needs of their cluster. Despite the fears to the contrary, they are plenty of examples where LAs continue handling finance for central capital projects as well.</p><p> </p><p>
Why does the role of the LA matter anyway - and what could explain this "phoenix from the flames"?</p><p> </p><p>
</p><ul><li>Greater trust of local councillors rather than MPs<br />
</li><li>Balanced local ear to the ground abilities<br />
</li><li>Emergency support via local secured and invested funds<br />
</li><li>Responsibility for other key services such as social care, public health, planning, crime and disorder<br />
</li></ul><p></p><p> </p><p> </p><p>
And why is this important? Well these relate to education because of the wider impact of the environment out children grow up in. They change the way people feel - change their perception and confidence in a way that Central Government cannot achieve.</p><p> </p><p>
So, in conclusion - although there has been a move away from Local Government responsibility over the last 50 years, there is still a major role for it.</p><p> </p><p>
Still a need for the efficiency and scale that Local Government has, despite the press coverage. It is a surprising statistic some may say, but Local Government is more efficient than Central and any small organisation (such as a school on its own).</p>]]></description><guid isPermaLink="false">723</guid><pubDate>Sun, 08 Jul 2012 19:00:00 +0000</pubDate></item><item><title>Capita LA Conference 2012 - Alton Towers - The Year in Review</title><link>https://www.edugeek.net/blogs/entry/722-capita-la-conference-2012-alton-towers-the-year-in-review/</link><description><![CDATA[<p>A departure from some of my more recent posts about System Centre - now time to concentrate on more of the Consultancy and Technology Evangelism Im also involved with.</p><p> </p><p>
This time, I was very fortunate to be invited to the Capita SIMS LA Conference, held at Alton Towers. Thanks must go to Cath Lane and her team, as well as Phil Neal and the Product Managers who spared their time to talk to me. This is the first of a selection of posts which will appear this week discussing the themes of the event.</p><p> </p><p>
So, on to the actual event, which centred around the way in which the Schools ecosystem is changing. Even Capita (who I know some of my audience will suggest otherwise) appreciate the need to better understand the market - and what we need. IT as a technology, as a platform for use in Schools is changing. Schools are very data rich - but often are not in a position to understand, filter or use this data properly. This is where SIMS, and other Capita products and services come in.</p><p> </p><p>
Phil Neal spoke on stage about the demanding competitive landscape which exists, both in terms of product and also the ancilliary services such as LA support services. Again - I know some of my audience wont believe that the <abbr title="Management Information System">MIS</abbr> market place could be seen as competitive, but the simple truth is it is. The Academy system has changed the ecosystem - Schools and Colleges have a choice.</p><p> </p><p>
There are more developers and products on the market, and there is a greater awareness of them. I think a lot of this has to do with the changing professionals in Schools, and groups such as Edugeek.</p><p> </p><p>
There are more decision makers - no longer is it an LA decision which <abbr title="Management Information System">MIS</abbr>, or other systems a School uses. Schools in isolation are making this decision, although - that being said - there are also Federations of Schools choosing a product or service. Software and support providers are having to change the way they market themselves and their products - to make themselves understood to a different audience.</p><p> </p><p>
The move to the cloud also is having an impact. Product launches such as the competitive Serco Progresso raise the conversation "is there going to be a Cloud SIMS". </p><p> </p><p>
Despite the bleak outlook when the Academy system started, Capita have been making gains in 2011/12 of roughly 50 schools. They also won Norfolk LA, and that is despite the concern of LAs "loosing control" of their Schools.</p><p> </p><p>
The change to Academies has brought on its challenges.  Academies have to go to market to asses what is available to choose what is needed for them. Converted academies are doing well, sponsored academies less so - as they tend to be groups or adopt whatever the sponsor is using.</p><p> </p><p>
LA tenders are progressing, and there have been gains such as the Norfolk LA gain earlier. The new DfE framework brings its own challenges, the problem is that the tender can be all about the terms and conditions rather than the functionality and software. This is where the definition of core and non core models is important. The staggering truth there is that according to the framework, Exams and Upgrades are not part of the core, while cashless management is. Go figure?! So, in short, if you are a School or LA tendering - make sure you check carefully what components you want/expect to be included in your costs, or you risk getting stung! After the demise of BECTA, some may see it as no surprise that there is also no mention of parental engagement. If you are a School or LA who has rolled this out already, or has plans to do so (bear in mind that this is still part of Ofsted monitoring and evaluation) - you need to check carefully that you include this too.</p><p> </p><p>
Capita have understood one clear thing from the community - and that is the quality of their communications with people on the ground. Their surveys of the user group showed some interesting results. Quality of training materials and Uptake of SIMS in the Classroom - key drivers were varied. There is going to be a lot of work taking place to improve this soon. There has been limited takeup Discover and Solus 3 - but those where it has been implemented, it has taken off. Discover is changing the market place. Whole industry around developing aspects for Discover.</p><p> </p><p>
Also questioned was whether support to schools was direct or via LA.</p><p> </p><p>
So - what is changing soon? </p><p> </p><p>
Learning Gateway is due to have extensive developments, and now has a new Product Manager. The first big change is to add data collection sheets. The second will be a complete re-write of the "person webpart" - which is responsible for the old style Student and Staff details pages.</p><p> </p><p>
T4 is dead as a product. T6 now has all the functionality, and the Timetable printing functionality is all embedded in the main SIMS.net product. Finally, you can say goodbye to this relic of SIMS.</p><p> </p><p>
FMS has document management and cost centre manager permissions. Auditing reports and specific reports for Academies is also now included. This was one of the big criticisms of the product. Finally - and Phil was very proud to announce this - FMS is now Financial Authority Accredited. </p><p> </p><p>
In Touch is being revitalised as a product. There seems to be limited awareness of this nationwide. I guess, in part, this is due to the plethora of competitive products such as Groupcall, Teachers2Parents etc. However, ask youself this, why use these if the functionality can be "there" in SIMS. Anyway - coming soon to it are improved alerting and automated notifications.</p><p> </p><p>
And finally from Phil's stage section was another bit of pride for more awards - Finalist for BETT 2012 and Winner of ERA for innovation. Not bad for a years work!</p>]]></description><guid isPermaLink="false">722</guid><pubDate>Sat, 07 Jul 2012 19:28:08 +0000</pubDate></item><item><title>How to - System Centre Configuration Manager - Part 5 (Task Sequences - for OS/Apps)</title><link>https://www.edugeek.net/blogs/entry/641-how-to-system-centre-configuration-manager-part-5-task-sequences-for-osapps/</link><description><![CDATA[<p>Welcome to Part 5 of my now <strong>EPIC</strong> System Centre Configuration Manager (SCCM) series! Heres the 2nd of your "two for you money" weekend deal :-p. So - this time round we are going introduce a new dark art - Task Sequences. These are the power of SCCM; and will actually get your deployment off the ground. After anything specific Ive not covered, or that you think Ive missed, please comment or send me a PM. Alternatively, you can find me on Twitter <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/2292-thescarfedone/" data-mentionid="2292" data-ipshover-target="https://www.edugeek.net/profile/2292-thescarfedone/?do=hovercard" data-ipshover="">@TheScarfedOne</a>.</p><p> </p><p>
<strong>Introduction to a dark art</strong></p><p>
sequences are the power of SCCM… they are what actually controls what happens on your machines. There isnt much you cant do with them… they are incredibly powerful. Task Sequences can be linked to Operating Systems, Drivers, Applications, Scripts, Software Updates – well, most things like I said.</p><p> </p><p>
To start with, we need to create a Task Sequence (TS) to install Windows 7 in unattended mode to a target machine; and then to capture that install (including SysPrepping it – remember as you did in XP) and save it on the Server for us to use later. Thankfully – SCCM makes this easy for us, as one of the options on the New TS menu is “New Build and Capture”… nice work guys! See... not such a dark art maybe!</p><p> </p><p>
<strong>Creating your first TS</strong></p><p>
So, lets get started (I have attached a sample TS for Build and Capture which you can import if you wish – but its good to try doing it yourself once to get a feel for the TS environment… you will be doing a lot in here once you get running with SCCM!)…</p><p>
Now… I don’t like where TS has been put in SCCMs interface; as you can do more than OS’s with them. But, hey ho, it is under the Operating System Deployment node. So, right click and choose New Task Sequence from the options shown.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS1.jpg.ac450f3b202f9691920d0e38eff433a1.jpg" data-fileid="145" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMTS1.jpg.ac450f3b202f9691920d0e38eff433a1.jpg" data-fileid="145" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS1.jpg.ac450f3b202f9691920d0e38eff433a1.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> </p><p> </p><p>
As I said, the developers did a great job here (apart from where in the interface it appears… grumble grumble)… so choose the obvious choice - Build and capture a reference operating system image.</p><p> </p><p> </p><p>
Give the it a sensible name such as Windows 7 - BUILD and CAPTURE, followed by clicking on browse to choose your boot.wim file (the ones we created right back in the first posts in this series), choose the 32 bit one.</p><p> </p><p>
Next up -  SCCM needs to know what operating system we want to install – so it can do all its fancy stuff in the background. Now, assuming that you have followed my previous blogs on this series – you should see your Windows 7 DVD option in the browse and drop downs. If you don’t – you have probably fallen foul of the main mistake people make in SCCM. That is that you have built a Package (and that Package could be OS, Application, Drivers…) but not added distribution points! This happens a lot, but remember – every time you make a package – you MUST distribute it before it is available. With Applications and Drivers, it will tend to be a “Fails to install” or “Fails to run” with error 8004005.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS2.jpg.5c6cba9f7a6270a0d81b29f87118de30.jpg" data-fileid="146" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMTS2.jpg.5c6cba9f7a6270a0d81b29f87118de30.jpg" data-fileid="146" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS2.jpg.5c6cba9f7a6270a0d81b29f87118de30.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> </p><p> </p><p>
For the Build and Capture, you don’t need to worry about the Product Key. It doesn’t need it. When doing your actual deploy, then you should use your appropriate one. Again, on the password option – for your “Master image” you don’t need to do this – as you will actually set this on the Task Sequence you use to send out your captured image to machines.</p><p> </p><p>
Next up is setting the network configuration – where you should choose Join Workgroup. This is obvious really, keeping it off the domain will keep it clean.</p><p> </p><p>
We also need to specify the Configuration Manager Client installation package we created earlier from the predefined packages, select it by clicking on browse and selecting the package.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS3.jpg.51f94abfe976c4de076b7ded14f580f7.jpg" data-fileid="147" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMTS3.jpg.51f94abfe976c4de076b7ded14f580f7.jpg" data-fileid="147" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS3.jpg.51f94abfe976c4de076b7ded14f580f7.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> </p><p> </p><p>
SCCM has the power to install OS and other updates (supported by WSUS) as part of the build. Again, as this is a Master image, you will likely have already slipstreamed in SP1, or got the SP1 media. I would recommend that you choose 'don't install' any software updates. As part of your actual deployment of the captured image, you might want this enabled – and choose the set you have ready. That is outside the scope here – but as the feature appears here – it made sense to cover it off.</p><p> </p><p> </p><p>
<strong>Install software with your Master or after your Master</strong></p><p>
Ive split this section out from the main article – as there are two schools of thought on this. Some people prefer some of their applications to be included as part of their master image. Others think they should all go on after.</p><p> </p><p>
On as part of the image will slightly decrease the install time – depending how many apps you include, but on the flip side – your image will be bigger. This may take longer to transfer to your clients at build time, and maintenance of your image (see updating applications) be a bit more testy! Doing it after image time, as part of your deployment gives you more choice and control over where and when apps go out. You can also strip them back off machines reasonably easily.</p><p> </p><p>
The choice is yours!</p><p> </p><p>
Anyway – where is how you would do it. On the “Install Software” screen - click on the yellow star and select a software package you have created. The screenshots here show a Firefox package. Software packages must contain a program (the program tells the package what to do) – and each may contain more than one program. You select the one you want.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS4.jpg.9d4b5cf20d3ed761b48e431baf8319d0.jpg" data-fileid="148" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMTS4.jpg.9d4b5cf20d3ed761b48e431baf8319d0.jpg" data-fileid="148" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS4.jpg.9d4b5cf20d3ed761b48e431baf8319d0.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
<strong>Finishing off your Build and Caputure after our detour</strong></p><p>
Remember I mentioned SysPrep earlier. Well, if you were deploying XP -  then you would need to select the package here. However, all OSs since Vista have the sysprep built in so no need!</p><p> </p><p>
Next up, well nearly done, is giving some extra description information to our Image. This will help you identify it later when you are building up a catlogue of images.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS5.jpg.08082b95f40d4d0657bf3c6e1514d5f6.jpg" data-fileid="149" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMTS5.jpg.08082b95f40d4d0657bf3c6e1514d5f6.jpg" data-fileid="149" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS5.jpg.08082b95f40d4d0657bf3c6e1514d5f6.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> </p><p> </p><p>
Finally, we need to give SCCM all the details about where on the network we will store the image once it's built it. Remember in the last article we were creating a load of shares and folders? Well, we will be using one of those so \\SERVER\SCCM-IMAGES\SCCM-Win7-x86-DATE.wim should do nicely. Oh, you also need to give SCCM an account to logon to this share with.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS6.jpg.0de778eddc016cc5d232d6d86230fbcf.jpg" data-fileid="150" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMTS6.jpg.0de778eddc016cc5d232d6d86230fbcf.jpg" data-fileid="150" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS6.jpg.0de778eddc016cc5d232d6d86230fbcf.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> </p><p> </p><p>
You will get the usual summary screen next – and that’s it! Your first foray into the world of Task Sequences! Want to take a deeper dive and see whats going on under the surface? Why not…</p><p> </p><p>
<strong>Task Sequences… a deeper dive</strong></p><p>
When the Task Sequence is complete, you can right click on it and and choose Edit. By default, SCCM comes with 28 tasks that can be added to the task sequences. This includes everything from partitioning, joining the domain, formatting and setting up disks in addition; and -  the integration with MDT (Microsoft Deployment Toolkit) means that MDT adds an additional 9 tasks. This is where you could define where to add SERVER ROLES AND FEATURES for Windows Server 2008. </p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS7.jpg.e0dcb69c1f1cae0b67ef89ec100167e5.jpg" data-fileid="151" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMTS7.jpg.e0dcb69c1f1cae0b67ef89ec100167e5.jpg" data-fileid="151" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMTS7.jpg.e0dcb69c1f1cae0b67ef89ec100167e5.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Options can be added from the Add dropdown, and edited in the window on the right. At the moment, this TS does nothing – until we assign it to a Collection in SCCM.</p><p> </p><p>
And that’s whats coming up in Part 6, and Part 7 will show you the end results. That should be up shortly (Im writing them both at the moment!).</p><p> </p><p>
Enjoy!</p>]]></description><guid isPermaLink="false">641</guid><pubDate>Sat, 14 Apr 2012 14:09:11 +0000</pubDate></item><item><title>How to - System Centre Configuration Manager - Part 4c (OS Images - Drivers)</title><link>https://www.edugeek.net/blogs/entry/640-how-to-system-centre-configuration-manager-part-4c-os-images-drivers/</link><description><![CDATA[<p>Welcome to Part 4c of my System Centre Configuration Manager (SCCM) series! Yes.... this one has been a while coming - so Im going to give you two for you money today! So - this time round we are going to finish off the building your first Windows 7 image. After anything specific Ive not covered, or that you think Ive missed, please comment or send me a PM. Alternatively, you can find me on Twitter <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/2292-thescarfedone/" data-mentionid="2292" data-ipshover-target="https://www.edugeek.net/profile/2292-thescarfedone/?do=hovercard" data-ipshover="">@TheScarfedOne</a>.</p><p> </p><p>
<strong>Drivers - aka the HELL!</strong></p><p>
One of the issues you'll probably face sooner or later with deploying OS's is not being able to access network or storage resources due to missing drivers within boot.wim - or once the OS is building and installing (well trying to) applications as part of the Task Sequences.</p><p>
To deal with this - we need to give SCCM a pile of drivers, but before doing so create a share on your network and copy some into it.</p><p> </p><p>
Quick health warning here - PERMISSIONS! Make sure that the permissions for that share allow READ/Write access for your SCCM account (and preferably SYSTEM as well). In addition make sure that the SYSTEM account has NTFS permissions that give it full access.</p><p> </p><p>
A general rule of thumb here - go with a simple naming structure. So... I generally advise the following:</p><p> </p><p>
DATA DRIVE on SERVER</p><p>
:: SCCM-IMAGES (for SCCM Build and Capture to drop its image into)</p><p>
:: SCCM-SOURCES (for SCCM to read its information out of - contains subfolders of APPLICATIONS and DRIVERS)</p><p>
:: SCCM-PACKAGES (for SCCM to write and maintain its own package structure - contains subfolders of DRIVERS and APPV [NB APPV uses its own package maintenance structure in SCCM. Normal packages don't, they use a SMSPKG*$ where * is the drive letter])</p><p> </p><p>
As with everything in SCCM, drivers must be added to packages and deployed to distribution points before computers can use them.</p><p> </p><p>
<strong>Adding Drivers - and best practice</strong></p><p>
What I prefer to do with drivers is maintain a single massive repository. Some people prefer to have separate Driver Sets for their machines. This is fine, but what you might find is that you get a "Driver already exists" on importing.</p><p> </p><p>
So, in the DRIVERS folder in SCCM-SOURCES - I create an X86 and X64 folder. Then , in there go with the common hardware types - GFX, AUDIO, CHIPSET, LAN, WIFI, etc. Some who are familiar with drivers from the RIS days (shudder) will remember a great project called DriverPacks. Well, its still running - and has pre-built driver sets by type, which you can then import into SCCM. One issue - due to the size, they are now distributed as torrents - which I doubt you can download in School. Once you have got them (a series of 7Zip files ), extract into your folders as above. Then you are good to go. </p><p> </p><p>
You can find out more about the DriverPacks project at <a href="http://www.driverpacks.net" rel="external nofollow">http://www.driverpacks.net</a></p><p> </p><p>
So - the import process...</p><p>
In SCCM ConfigMgr, find the Driver node under Operating System Deployment section. Right click and create folder. What we are going to do is create a "virtual" folder structure in the console to mirror the layout of our share. It will make life easier later. So - the first folder is x86, and on the same level x64. Then in each of those - LAN, CHIPSET etc...! Right click the appropriate folder (we are doing LAN drivers here) and choose import.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV1.png.ee69280e37d6f4ca44334465a3c30e00.png" data-fileid="144" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV1.thumb.png.8ec236cb138d02a4fcf01253103352bc.png" data-fileid="144" data-src="https://www.edugeek.net/uploads/monthly_2025_03/SCCMDRV1.thumb.png.8ec236cb138d02a4fcf01253103352bc.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a><a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV2.png.aeec6e941049be07a7553cf519afc211.png" data-fileid="143" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV2.thumb.png.6d7fbe66134d786cb2eaa70f78bb46dd.png" data-fileid="143" data-src="https://www.edugeek.net/uploads/monthly_2025_03/SCCMDRV2.thumb.png.6d7fbe66134d786cb2eaa70f78bb46dd.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a><a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV8.png.7c98cba8cb330aa66cd72f0d595119a1.png" data-fileid="136" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV8.png.7c98cba8cb330aa66cd72f0d595119a1.png" data-fileid="136" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV8.png.7c98cba8cb330aa66cd72f0d595119a1.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a><a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV4.png.711b3cd509f77629a9c9f59458e4532b.png" data-fileid="141" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV4.png.711b3cd509f77629a9c9f59458e4532b.png" data-fileid="141" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV4.png.711b3cd509f77629a9c9f59458e4532b.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
When the wizard appears paste in the path to your network share containing the drivers, which should be something like \\SERVER\SCCM-SOURCES\Drivers\x86\LAN (I'm using LAN here for a reason - which will become clear in a moment....)</p><p> </p><p>
SCCM will go away and look at all the .inf driver files in the location. After a while it will list the driver(s) it found, and you can then click on categories to place them into a category. Categories are useful to help deal with limiting what drivers are available to what machines (i.e. x86/x64 and others, where you may in future add specifics for some laptops for example).</p><p> </p><p>
Click on <strong>Catagories</strong> to get to the options screen. As this is our first one, its bank. Just enter a new one (something sensible like Windows 7 - x86 - LAN), and click Add, and then OK. You will see it appear in the "Assign categories for filtering..." field. Click Next, and then Next again on the Packages screen. We will be coming back to this one, so you don't need to click the "New packages" option - but you could do if you wanted to do it from here. It will trigger the same wizard we will be coming to soon.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV5.png.4eea5755d395defc2869da0a6040dbb7.png" data-fileid="140" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV5.thumb.png.ba8421f61b61e48fa0f85ce1e960c8dd.png" data-fileid="140" data-src="https://www.edugeek.net/uploads/monthly_2025_03/SCCMDRV5.thumb.png.ba8421f61b61e48fa0f85ce1e960c8dd.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a><a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV6.png.7382167268604f88c1b152452ba5a5dc.png" data-fileid="139" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV6.thumb.png.288b913df9dcd9fead68447c4796e8ba.png" data-fileid="139" data-src="https://www.edugeek.net/uploads/monthly_2025_03/SCCMDRV6.thumb.png.288b913df9dcd9fead68447c4796e8ba.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Next you have the option to add these drivers to our boot.wim files, as we are adding Network drivers then you should select the X86 and X64bit SCCM boot.wim files listed, make sure to also place a checkmark in Update distribution points when finished.</p><p> </p><p>
You will be clicking Next twice, and then sitting back and waiting for a while. Seriously - this can take a while too, Ive thrown a set of 50 odd drivers at it once, it took about 45 mins. Bear in mind, with LAN drivers, it is also updating your boot.wim too. You only need to do this with LAN drivers. Some people do it with GFX as well, to make their boot screens look pretty, but thats up to you. Remember, the more drivers you put in - the bigger your initial wim - and the longer the first SCCM boot.</p><p> </p><p>
Next up, dealing with driver packages. Drivers have to be in packages to be assigned to machines. So far - all we have done it inject them into our boot file. You can think of this like adding a software app, without all of the setup files... it isn't going to work...!</p><p> </p><p>
<strong>Adding driver packages</strong></p><p>
As you will have got the idea of by now - most things in SCCM are where you'd expect them. We need the Driver Packages node in SCCM ConfigMgr and right-click, choose New Driver Package.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV7.png.a45441bcd7577625c1eb575b27548872.png" data-fileid="135" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV7.png.a45441bcd7577625c1eb575b27548872.png" data-fileid="135" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV7.png.a45441bcd7577625c1eb575b27548872.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a><a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV8.png.7c98cba8cb330aa66cd72f0d595119a1.png" data-fileid="136" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV8.png.7c98cba8cb330aa66cd72f0d595119a1.png" data-fileid="136" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV8.png.7c98cba8cb330aa66cd72f0d595119a1.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Remember earlier on we created that share SCCM-PACKAGES? Well, we need that now too. Have that open in one window - as annoyingly - you can't create a driver package in a folder that doesn't exist - and it will moan at you else. I went through in advance creating SCCM-PACKAGES\Drivers\x86\LAN; AUDIO; WIFI; GFX; CHIPSET... just to be ready.</p><p> </p><p>
In the wizard that appears fill in the details and point it to your share (its important to make sure that this share is separate from the drivers share - SCCM stores a load of extra information with the packaged drivers). Then, simply click ok to create the package, we now have an empty driver package.</p><p> </p><p>
Back in your SCCM tree, you then need to go to the Driver node again. Down to the LAN folder we made in x86 - and we should see all the LAN drivers we had imported earlier. If you can't see them - press F5. We need to select all of them (this is where when doing other Packages later - you could use the Create package and Add to package all as part of the import process; alternatively, pre make all of the packages then do the import and add at that point as the import wizard will show you the packages that exist). Once you have selected them all ("Ctrl - A"should do the trick) - in the <strong>Actions Menu</strong> on the right - choose <strong>Add or Remove Drivers from Package</strong>. You could right click, but you run the risk of loosing your selection!</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV9.png.baac6ca183327710d1fc75668fa7d8d4.png" data-fileid="137" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV9.thumb.png.03f7869a64220f58f5ba0a3cf84d401e.png" data-fileid="137" data-src="https://www.edugeek.net/uploads/monthly_2025_03/SCCMDRV9.thumb.png.03f7869a64220f58f5ba0a3cf84d401e.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a><a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV10.png.44d31a4d9cad4603a59561e9ffc4e934.png" data-fileid="138" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCMDRV10.png.44d31a4d9cad4603a59561e9ffc4e934.png" data-fileid="138" data-src="https://www.edugeek.net/uploads/monthly_2012_04/SCCMDRV10.png.44d31a4d9cad4603a59561e9ffc4e934.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
A bit of clicking next, and thats that done. You can check it by going to the Package under the Packages node - again, you may need to F5 for a refresh. </p><p> </p><p>
Now that we have our drivers imported into our drivers package, we need to Create a distribution point, so lets right-click on Distribution points and choose new distribution points. We only want standard "Server" ones again here - so don't choose the PXE one.</p><p> </p><p>
So - all you have to do is repeat that process for all your drivers and SCCM should be able to deploy onto any hardware (x86 or x64 - assuming you do both sets) - with all drivers. Now we have done that - time to actually make the master image in SCCM by doing that Build and Capture - the title of this section of the series. For that, we learn about a new concept called Task Sequences.</p><p> </p><p>
That will be next... so stay tuned!!!</p>]]></description><guid isPermaLink="false">640</guid><pubDate>Fri, 13 Apr 2012 15:55:14 +0000</pubDate></item><item><title>Using SSO (Single Sign On) with Remote Desktop for Thin Clients</title><link>https://www.edugeek.net/blogs/entry/638-using-sso-single-sign-on-with-remote-desktop-for-thin-clients/</link><description><![CDATA[<p>Those who follow my blogs will remember that last Summer, I set about building a single platform system - based around Windows 7/Server 2008 R2. This post deals with the final part of the jigsaw relating to the Thin Client section - powered by Windows Thin PC (aka Windows 7 lite... it runs NT6.1)</p><p> </p><p>
This post follows <a href="https://www.edugeek.net/blogs/thescarfedone/1108-remote-desktop-thin-client-part-2.html" rel="">http://www.edugeek.net/blogs/thescarfedone/1108-remote-desktop-thin-client-part-2.html</a></p><p> </p><p>
<strong>Introduction</strong></p><p>
So – if you are using Terminal Server, or to give it its new name – Remote Desktop Services (RDS) – you will want to know about Single Sign-On (SSO). This is an authentication method that allows users with a domain account to log on once – so take the scenario where your users logon to a Thin Client as themselves, but you then want it to automatically trigger an RDS session. To implement single sign-on functionality in Terminal Services, ensure that you meet (and for production systems – exceed) the minimum requirements. </p><p> </p><p>
The basic requirements needed to implement SSO are:</p><p>
</p><ul><li><br />
You can only use single sign-on for remote connections from a computer running Windows Vista (or later) or Windows Server 2008 (or later) to a Windows Server 2008 (or later)Terminal Server. <br />
You must ensure that the user accounts that are used for logging on to the Terminal Server have appropriate rights to log on to both the Terminal Server and the Windows Vista/2008 (or later) client computer (ie. Add them to the Remote Desktop Users group via Group Policy or manually via Local Policy) <br />
Your client computer and Terminal Server must be joined to a domain. <br /></li></ul><p></p><p> </p><p>
Understanding what the basic requirements are, more specific requirements for setting up SSO, is as follows:</p><p>
Servers:</p><p>
</p><ul><li><br />
Windows Server 2008 (or later) Terminal Server with TS/RDS Server Role and TS/RDS Licensing Server Role enabled <br />
Windows Server 2008 (or later) Domain Controller (Active Directory) <br />
Proper Hardware Requirements <br /></li></ul><p></p><p> </p><p>
Note: </p><p>
Although you can make a DC a Terminal Server, it is recommended that you split the roles and use separate servers based on the load that is expected. Obviously, whenever implementing a production system, you will want to make sure that you know what your application/traffic flows are and what load your users and the application puts on your network as well as the individual servers connected to it. </p><p>
Clients:</p><p>
</p><ul><li><br />
Windows Vista (or Windows Server 2008 used as a client system) <br />
Remote Desktop Client (RDC) with Network Level Authentication (NLA) Support. NLA support is only available with RDC 6.0 and with Vista or 2008 (or later).   <br />
Proper Hardware Requirements (exceed as needed) <br /></li></ul><p></p><p> </p><p>
To configure the recommended settings for your Terminal Server, complete the following steps:</p><p>
</p><ul><li><br />
Configure authentication on the Terminal Server, this can be done with AD, or locally on the server you want access to. <br />
Configure the computer running Windows Vista to allow default credentials to be used for logging on to the specified Terminal Server(s) on your network. <br />
You need administrative privileges on the Terminal Server you are configuring. <br /></li></ul><p></p><p> </p><p>
Now that you know what you need, let us begin configuring SSO with Terminal Services. </p><p> </p><p>
<strong>Configure Authentication on a Terminal Server</strong></p><p>
First, verify you have a working Terminal Server. Check the Server Manager for the roles being installed and operational. Remember, you will need to have (at minimum), the Terminal Services Role and the Licensing Server Role installed and ready to configure SSO. </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/TS1.png.c5ba26673c74e12e230337d659143cec.png" data-fileid="132" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TS1.png.c5ba26673c74e12e230337d659143cec.png" data-fileid="132" data-src="https://www.edugeek.net/uploads/monthly_2012_04/TS1.png.c5ba26673c74e12e230337d659143cec.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> </p><p>
Next, we will configure Single Sign-On (SSO) on the Terminal Server by opening Terminal Services Configuration. Go to Start =&gt; Administrative Tools =&gt; Terminal Services, and then click Terminal Services Configuration.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/TS2.png.4c4855a830c20b415e7c53695f7c2850.png" data-fileid="131" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TS2.png.4c4855a830c20b415e7c53695f7c2850.png" data-fileid="131" data-src="https://www.edugeek.net/uploads/monthly_2012_04/TS2.png.4c4855a830c20b415e7c53695f7c2850.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Once you open the Terminal Services Configuration console, find the Connections pane. You should, at minimum, have the default connection in place which should be <abbr title="Remote Desktop Protocol">RDP</abbr>-Tcp. To configure this (or any other connection) right-click the appropriate connection and then click Properties.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/TS3.png.3fb8c768220e84887ddddc17945185aa.png" data-fileid="130" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TS3.png.3fb8c768220e84887ddddc17945185aa.png" data-fileid="130" data-src="https://www.edugeek.net/uploads/monthly_2012_04/TS3.png.3fb8c768220e84887ddddc17945185aa.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> </p><p>
Once you open the Properties dialog box, on the General tab 4, you can verify that the Security Layer value is set to either Negotiate or SSL (TLS 1.0). Negotiation will allow the system to ‘negotiate’ with a client what type of Security Layer is needed. </p><p>
On the Log on Settings tab, ensure that the Always prompt for password check box is not selected or checked, and then click OK to close the <abbr title="Remote Desktop Protocol">RDP</abbr>-Tcp Properties dialog box.</p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/TS4.png.471354fd2f7fc27d35732d9fe2599b5c.png" data-fileid="129" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TS4.png.471354fd2f7fc27d35732d9fe2599b5c.png" data-fileid="129" data-src="https://www.edugeek.net/uploads/monthly_2012_04/TS4.png.471354fd2f7fc27d35732d9fe2599b5c.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Now, you have configured authentication, next we will configure the default credential usage to be used with SSO. </p><p> </p><p>
<strong>Allow Default Credential Usage for Single Sign-On (SSO)</strong></p><p>
Now that we have authentication configured, we need to finish the process. To do this, you need to go to the client system (Vista, or 2008) and configure the Local Group Policy Editor. On your client computer open the Local Group Policy Editor. To open Local Group Policy Editor, go to Start, and in the Start Search box, type gpedit.msc and then press ENTER. In the Editor, look in the left pane and expand Computer Configuration =&gt; Administrative Templates =&gt; System =&gt; and then click Credentials Delegation. Double-click the Delegating Default Credentials setting to open it. </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/TS5.png.f79c4805cb71d74c1a97958f4986d3aa.png" data-fileid="133" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TS5.png.f79c4805cb71d74c1a97958f4986d3aa.png" data-fileid="133" data-src="https://www.edugeek.net/uploads/monthly_2012_04/TS5.png.f79c4805cb71d74c1a97958f4986d3aa.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Next, in the Properties dialog box on the Setting tab, select Enabled, and then select Show. In the Show Contents dialog box, click Add to add servers to the list. In the Add Item dialog box, type the prefix termsrv/ followed by the name of the Terminal Server you will be connecting too. Once you have added the server name, click OK to close the Add Item dialog box. Click OK a few times until you are back in the Local Group Policy Editor and close the MMC. </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_04/TS6.png.a191c833a85024ca9abd4b0981df8347.png" data-fileid="134" data-fileext="png" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="TS6.png.a191c833a85024ca9abd4b0981df8347.png" data-fileid="134" data-src="https://www.edugeek.net/uploads/monthly_2012_04/TS6.png.a191c833a85024ca9abd4b0981df8347.png" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p>
Now you should be all ready to use SSO with Windows Server 2008 and 2008 Terminal Services.</p>]]></description><guid isPermaLink="false">638</guid><pubDate>Tue, 03 Apr 2012 22:41:08 +0000</pubDate></item><item><title>Dell acquires Wyse Technologies</title><link>https://www.edugeek.net/blogs/entry/636-dell-acquires-wyse-technologies/</link><description><![CDATA[<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-username="Arthur" data-cite="Arthur" data-ipsquote-contentapp="blog" data-ipsquote-contenttype="blogs" data-ipsquote-contentid="636" data-ipsquote-contentclass="blog_Entry"><div>It looks like Dell are on a spending spree.<p> </p><p>
<a href="http://www.dell.com/wyse" rel="external nofollow">www.dell.com/wyse</a></p><p> </p><p>
</p><blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="blog" data-ipsquote-contenttype="blogs" data-ipsquote-contentid="636" data-ipsquote-contentclass="blog_Entry"><div>DESKTOP PC FLOGGER Dell will buy thin-client vendor Wyse for an undisclosed sum.<p> </p><p>
Dell has spent the last five years trying to shrug off its image as a beige box shifter with a significant push into the enterprise. Michael Dell even said, "Dell is not a PC company". Now the firm is moving further away from its tin box roots by buying Wyse, a company that's well known for its thin-client products.</p><p>
Dell announced that the two firms have signed a definitive agreement that will expand Dell's range of products associated with the achingly fashionable cloud. While neither party disclosed financial terms, Dell said the transaction is expected to affect its earnings in the second half of its 2013 fiscal year.</p><p> </p><p>
Tarkan Maner, president and CEO of Wyse Technology said, "The combination of Wyse and Dell provides us with tremendous growth opportunities for our core desktop virtualization business, helps us expand into new and fast-growing market segments including mobility and cloud computing, and provides us with reach and scale we did not previously have."</p><p> </p><p>
Dell's purchase of Wyse shows the firm is trying to back up its impressive server sales by improving its lagging 'front office' sales of desktop and laptop PCs. As enterprises move towards hosted infrastructures running on cloud services, the need to upgrade desktops or laptops is fast diminishing as they are starting to be treated as thin clients.</p><p> </p><p>
So Dell is pre-empting any loss of desktop sales in the enterprise by picking up the biggest thin-client vendor in the industry. Also while Dell is presently nowhere in the highly competitive smartphone and tablet markets, Wyse already has software thin clients for Apple's Ipad and Google's Android, which can be expected to give Dell some traction there. (<a href="http://www.theinquirer.net/inquirer/news/2165426/dell-wyse-extend-cloud-client-range" rel="external nofollow"><strong>Source</strong></a>)</p></div></blockquote></div></blockquote>]]></description><guid isPermaLink="false">636</guid><pubDate>Mon, 02 Apr 2012 20:00:32 +0000</pubDate></item><item><title>Building School Networks for the Future - with System Centre and HyperV</title><link>https://www.edugeek.net/blogs/entry/626-building-school-networks-for-the-future-with-system-centre-and-hyperv/</link><description><![CDATA[<p>This article was originally posted on the Microsoft Schools blog on 20th Jan 2012</p><p>
<a href="http://blogs.msdn.com/b/ukschools/archive/2012/01/19/building-school-networks-for-the-future-with-system-centre-and-hyper-v.aspx" rel="external nofollow">http://blogs.msdn.com/b/ukschools/archive/2012/01/19/building-school-networks-for-the-future-with-system-centre-and-hyper-v.aspx</a></p><p> </p><p>
<strong>Building School Networks for the Future - with System Centre and HyperV</strong></p><p>
One of our (many) friends over at EduGeek has recently done some work with Marine Academy Plymouth  taking over their systems in May 2011. We have now a series which charts the process of systems modernisation from analysis, to planning, then implementation before finally evaluation.  This first article will deal with a summary of that analysis; and the ones which follow will cover Stuart Wilkie’s (IT Manager) decisions and how he put them into practice.</p><p> </p><p>
Marine Academy Plymouth is the UK’s first Marine Academy.  It’s a state-funded specialist secondary school with three sponsors  - University of Plymouth , Cornwall College  and Plymouth City Council.</p><p> </p><p>
The Marine theme is not just about Marine Science. One of the common questions (and EduGeek had a few at a recent open evening), is why “Marine Academy”?  You immediately think, do I need to grow fins, have a boat, swim even…? Well actually it’s none of those things.  All the careers that we currently pursue from a land-based concept can feasibly be accessed in association with the sea and marine. Careers in areas such as engineering, tourism, medicine, catering, building and agriculture – just to start with!</p><p> </p><p>
Marine Academy Plymouth’s focus is to help to prepare and develop the students’ career opportunities, for today’s traditional jobs and for those that we don’t yet know about, we will achieve this through a commitment to high standards and to sustainability.</p><p> </p><p>
<em>“A modern, reliable, environmentally friendly computer system is key to the Academy in so many ways. Everything we do here has to embody our ethos and beliefs and ultimately empower the learners of tomorrow.”</em></p><p> </p><p>
Standardisation and a stable platform are the key to the success and development of any system – at least that’s what the experience of time tells me. </p><p>
The systems at Marine Academy were a bit of a mix at the start with a wide variety of hardware manufacturers as well as specification. Dealing with the inequality of accessibility would be key to ensuring the consistency of the learning experience. </p><p> </p><p>
The system itself consisted of surprising few servers for the scale of the clients – all 600+ of them! The server platform was powered by two DCs, Exchange, Capita SIMS (Student Management System) and ISA all of which relatively new. There were also a selection of older servers performing legacy file sharing and testing roles such as WSUS (Windows Server Update Services) and the free imaging and management platform “FOG”. The problem was the DCs were also the DFS, directly connected to the SAN , contained all the User Data (everything from Home folders to Profiles and the traditional Staff and Student shared folders) and the legacy servers were exactly that – legacy. There was no redundancy within the system, and the ability to perform any maintenance, or failure, would render parts of the network inoperable.</p><p> </p><p>
The majority of the teaching staff had been issued with laptops, a throwback to the Government “Laptop for Teachers” scheme. There was a wide variety of sizes and specifications. A quick glance at these, and their age/condition presented an issue. Consistency of delivery for one, and secondly, Devon and Plymouth as Local Authorities were insisting on implementation of encryption of all mobile devices which left school and college sites. </p><p> </p><p>
Largely, the desktop fleet was in a good way. Marine Academy has 6 main <abbr title="Information and Communications Technology">ICT</abbr> Suites plus clusters for Technology, Science and Arts. <abbr title="Information and Communications Technology">ICT</abbr> Suites had largely been refreshed the previous year with high not being realised due to downgrading to the older Windows XP Operating System. The administrative and support workstations had also received the same refresh which was slight overkill based on their use. The remainder of the machines comprised of large fleets of either “custom build” dual core machines, older Celeron small form IBMs or RM All in Ones. The majority of classrooms had a single workstation installed to be used with the Interactive Whiteboard and AV facilities available which fell into one of the latter two ranges.</p><p> </p><p>
Returning to the headline intentions, consistency of learning experience, reliability, stability and core to the Academy ethos, sustainability, the question lies, how could it be done?</p><p> </p><p>
Key development intentions:</p><p>
• More power was required to bolster the Server Platform to give the failover and resilience, as well as the flexibility to develop.</p><p>
• Security of Laptop Fleet for Curriculum Planning and Delivery, and a decision on the future of laptops or workstations for the “teacher point” in classrooms</p><p>
• Workstation modernisation, in those areas which had been “left behind”</p><p>
• Consistency of learning/delivery experience, by ensuring that no matter where learners were working – their settings and files followed them, and the environment they were working in was always the same.</p><p> </p><p>
Coming up in the second article in the series, there will be details of how we designed the new server system, what choices we made and why plus the start of the implementation process… so stay tuned!</p><p> </p><p>
Stuart’s “alter-ego” is TheScarfedOne and as well as being the IT Manager at Marine Academy Plymouth, he fits in being part of the staff team at Edugeek.net, with whom Microsoft have a close relationship. Edugeek.net is the community for <abbr title="Information and Communications Technology">ICT</abbr> Support and Development in Schools, with a worldwide following.</p>]]></description><guid isPermaLink="false">626</guid><pubDate>Fri, 02 Mar 2012 14:28:57 +0000</pubDate></item><item><title>Exchange 2010 - Granting write permission for calendar sharing with OWA 2010</title><link>https://www.edugeek.net/blogs/entry/622-exchange-2010-granting-write-permission-for-calendar-sharing-with-owa-2010/</link><description><![CDATA[<p>Ok - so from Outlook, you've been able to share your calendar with another user for ages. The problem is there haven't really been many options around automating this. Well - enter some handy new features in Exchange 2010.</p><p> </p><p>
The calendar sharing feature introduced in Outlook Web App 2010 (OWA) allows a user to grant access to their calendar to another user. To access the option, click on the Share option when in the Calendar and then on Share This Calendar. You’ll then be able to select the user(s) that you want to share your calendar with and define the level of information you want the recipient to be able to see in your calendar. Now, this is all well and good - because as an admin, you can open their mailbox through OWA logged on as you (you do give admins permissions to other users mailboxes right through delegation?) - and do this for them.</p><p> </p><p>
The recipients are then sent an email message with a link in it which enables them to create the "OWA" or "Outlook" shortcuts to the calendar. All they have to do is simply click on the Add This Calendar link. OWA will then add the calendar to the list of available calendars and the user can then access your calendar whenever they want by simply clicking on the calendar’s entry to instruct OWA to open it. It breaks it down as My Calendar, and Other Users Calendars.</p><p> </p><p>
So far so good right? The user will be able to see the calendar, but they won’t be able to add anything to it or make a change to an existing appointment. In short, they are restricted to “Reviewer” access. You can confirm this by clicking on the Change Sharing Permissions option in the Share menu, when you’ll see something like the screen shot shown below. In this case, just one other user has access to the calendar and all they have is Reviewer access, so it shouldn’t come as a surprise that they won’t be able to add or edit items in the calendar. Now, you will be thinking that you can then click on the "Change Permissions" option and increase those permissions to "Editor" right?</p><p> </p><p>
Sadly - wrong! The Exchange team left this out annoyingly - in the same way the pre SP1 version of OWA 2010 didn't have an option for printing the calendar. So...in short - Im hopeful they will get round to this.</p><p> </p><p>
In the mean time, you need to get down and dirty with a bit of Powershell to sort this one out. Actually, when you think about it, this is a good thing, as you could Powershell it from the start. There is one gotcha here tho - you can't give a user "Editor" on a calendar without them already having "Reviewer" - which is another annoyance!</p><p> </p><p>
What do you need to do then.... well, here we go!</p><p> </p><p>
We need the the Set-MailboxFolderPermission cmdlet, which is the underlying command that manipulates folder permissions. The command that we need to run is:</p><p> </p><p>
Set-MailboxFolderPermission -Identity alias:\Calendar -User UsertoGetRights -AccessRights Editor</p><p> </p><p>
Now, remember I said that you can’t run the Set-MailboxFolderPermission cmdlet to alter a permission on a folder unless a permission has already been granted to the folder for the user. If you want to add Reviewer permission for someone who doesn’t already have access to a calendar, you have to run the Add-MailboxFolderPermission cmdlet with a command like this:</p><p> </p><p>
Add-MailboxFolderPermission -Identity alias\Calendar -User UsertoGetRights -AccessRights Editor</p><p> </p><p>
To confirm that everything has gone to plan, we can use the Get-MailboxFolderPermission cmdlet to validate the permissions on the folder. This lists out the users who have the various levels of permissions.</p><p> </p><p>
Oh, and just for fun - and to prove where the Exchange Team need to do some more work - go back into OWA and take a look at the shared calendar permissions now. You will notice it says "Editor" but it is also all greyed out, and the button to change is also dead. The code to support dealing with this permission level isn't finished - but at least OWA knows about it rather than throwing a complete wobble at it!</p>]]></description><guid isPermaLink="false">622</guid><pubDate>Sat, 25 Feb 2012 22:34:24 +0000</pubDate></item><item><title>How to - System Centre Configuration Manager - Part 4b (OS Images - Build/Capture)</title><link>https://www.edugeek.net/blogs/entry/621-how-to-system-centre-configuration-manager-part-4b-os-images-buildcapture/</link><description><![CDATA[<p>Welcome to Part 4b of my System Centre Configuration Manager (SCCM) series! So - on with Part b of getting SCCM ready for building your first Windows 7 image - how to deploy that (with a load of extra options and fancy stuff!) to your estate. In the mean time, if there is something specific you need, or that you think Ive missed, please comment or send me a PM. Alternatively, you can find me on Twitter <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/2292-thescarfedone/" data-mentionid="2292" data-ipshover-target="https://www.edugeek.net/profile/2292-thescarfedone/?do=hovercard" data-ipshover="">@TheScarfedOne</a>.</p><p> </p><p>
<strong>Add New operating system image</strong></p><p>
Remember Ive been saying you are going to need you Windows 7 DVD? Well – now get it ready! You need to copy the contents of it to a folder shared that folder on the network. For this – I created a share called SCCM-SOURCES on my local server E$. C Drive is the OS obviously, D is where SCCM is installed, and E is a third partition. Im going to reuse this later on - so, SCCM-SOURCES needs sensible permissions, I gave Everyone Read, and Domain Admins Full. Remember, I said reuse. Inside it – I created an OS folder, and and APPS folder. APPS we will come back to in Part 5 of this blog series.</p><p> </p><p>
Now weve got that done – guess where we are going?! That’s right, our trusty SCCM ConfigMgr, Console. In there, select Operating System Images from within Operating System Deployment and right click it. On the menu, choose Add Operating System Image. I don’t think we need to be screen grabbing here again now – you get the idea of the way these SCCM wizards work.</p><p> </p><p>
<em>A little off topic, but you will be pleased to hear under SCCM 2012 RC2 and RC3, the wizards are largely unchanged! Win! We will deal with what has changed in 2012, and how to upgrade at a much later date. Lets just get 2007 up and fully running for now…</em></p><p> </p><p>
Back to our wizard for adding the OS image. On the Data Source page browse to the sources folder of the DVD you copied above and select the install.wim file, and then on the general screen fill in the details.</p><p> </p><p>
The usual summary to next past, and then finish. Remember in Part 4a, we dealt with the concept of distribution points. Well – we need to do all that again for OS images. So go and find the image you just added in Operating System Images, click the arrow next to it, and right click on Distribution Points. </p><p> </p><p>
<em>Heres a reminder on that process then…</em></p><p><em>
Select New Distribution Points, when the wizard appears click next. Remember - we only select the normal distribution point from the list (and not the PXE one) as this is not a boot image. Summary time and done.</em></p><p> </p><p>
<strong>Add new Operating System Install Package</strong></p><p>
Next we will make an Operating System install package, this package will contain the files necessary to support the installation of the install image we created above. </p><p> </p><p>
You might have noticed when in the Operating System Deployment node, there is an Operating System Install Package option. That’s what we need here. The section title was a bit of a give away! Wizard time again!</p><p> </p><p>
Instead of picking the install.wim file from the source we used above, we must now point the Operating System Install Package wizard to the root of the DVD which we've already copied to the network, SCCM will then import all of the setup files that are required to support the installation of Windows. Why – well here is some TechNet info…</p><p> </p><p>
Quote</p><p> </p><p>
The Operating System Installation Package must contain all the files necessary to install the desired Windows operating system on a reference computer. For example, this package might contain all of the reference files found on a Microsoft Windows XP Professional installation CD (not just the files in the i386 folder) because the installation must be run unattended. You create this package as you would any other Configuration Manager 2007 package. This package does not require a program. The task sequence will reference the source files as needed.</p><p> </p><p>
Next up, enter some details to describe what you are importing – I think you might just be getting the hang of these SCCM wizards now. They are pretty good at walking you through what is neeted. Summary, confirm – job done…?</p><p> </p><p>
No… not quite – don’t forget to create that distribution point! And again – its not a boot image, so “Standard DP” only.</p><p> </p><p>
Next up – that’s all well and good – but weve not told SCCM what to do, or dealt with something that will really foul you up if you arent careful…. DRIVERS!</p><p> </p><p>
Coming soon ☺</p>]]></description><guid isPermaLink="false">621</guid><pubDate>Sat, 25 Feb 2012 00:20:15 +0000</pubDate></item><item><title>How to - System Centre Configuration Manager - Part 4a (OS Images - Get Started)</title><link>https://www.edugeek.net/blogs/entry/611-how-to-system-centre-configuration-manager-part-4a-os-images-get-started/</link><description><![CDATA[<p>Welcome to Part 4a of my System Centre Configuration Manager (SCCM) series! So - here is probably the most anticipated post - how to get started with OS Imaging! Im going to show you how to get SCCM ready for building your first Windows 7 image - and then in 4b, how to deploy that (with a load of extra options and fancy stuff!) to your estate. In the mean time, if there is something specific you need, or that you think Ive missed, please comment or send me a PM. Alternatively, you can find me on Twitter <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/2292-thescarfedone/" data-mentionid="2292" data-ipshover-target="https://www.edugeek.net/profile/2292-thescarfedone/?do=hovercard" data-ipshover="">@TheScarfedOne</a>.</p><p> </p><p>
So... introductions over with, lets get started! First things first, lets get into the SCCM Console. Im going to assume for the purposes of this guide that you have followed the rest of this guide (or have a basic functioning setup); and that you are Remote Desktop'd to the SCCM Server.</p><p> </p><p>
<strong>Add the PXE Service Point (PSP) role to SCCM</strong></p><p> </p><p>
So, before we can get started - we need to first activate the PXE role in SCCM. This will enable our machines to boot through SCCM. Want to know more - or see the best practice stuff - head over to Technet <a href="http://technet.microsoft.com/en-us/library/bb680753.aspx" rel="external nofollow">http://technet.microsoft.com/en-us/library/bb680753.aspx</a></p><p> </p><p>
You must be getting used to where we need to go in the Console by now - yes that's Site Database/Site Management/Site Code/Site Settings/Site Systems and highlight your server. Right click on it and choose New Roles, which will give us that nice wizard.</p><p> </p><p>
Get ready for a load of Next, Next, Next! On the "New Role" screen, highlight the PXE role and select it, click next. This will want you to confirm, so say yes.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM10.jpg.a3e50fefcde019457bf65697abc7d553.jpg" data-fileid="123" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM10.jpg.a3e50fefcde019457bf65697abc7d553.jpg" data-fileid="123" data-src="https://www.edugeek.net/uploads/monthly_2012_02/SCCM10.jpg.a3e50fefcde019457bf65697abc7d553.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Up next, the PXE - General options page. For your testing, I would suggest that you remove the password requirement  - but in production, you will want one of these. It stops little monkeys getting into your deployment system by mistake.</p><p> </p><p>
Now - if your server already has been used for WDS - and you are still using that actively whilst testing out SCCM - this bit is for you! By fiddling with the PXE server response settings - you can swap between which system you are using. For SCCM, this value should be less than the value listed in your Windows Deployment Services PXE delay, you can verify the WDS pxe delay by right clicking the WDS server and choose properties/PXE response Settings.</p><p> </p><p>
What we want to happen here is that SCCM answers the first PXE boot request(s) from a client and if they are not associated with a Task Sequence then let WDS take over with the PXE boot routine.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM11.jpg.b99a11f9774c89b7b35167e3ca3d31af.jpg" data-fileid="124" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM11.jpg.b99a11f9774c89b7b35167e3ca3d31af.jpg" data-fileid="124" data-src="https://www.edugeek.net/uploads/monthly_2012_02/SCCM11.jpg.b99a11f9774c89b7b35167e3ca3d31af.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
<em>Now - sometimes SCCM and WDS can get themselves in a tangle. If you find things arent happening in the right order, then this is what you need....</em></p><p> </p><p>
<em>Installing the PXE Service point adds a service to the machine and a registry entry for WDS so WDS knows what to do with a boot request.</em></p><p><em> </em></p><p><em>
If you open regedit and browse to HKLM\System\CurrentControlSet\WDSServer\Providers\WDSPXE there is a "ProvidersOrder" key with some values in it. These values represent the boot order of WDS.</em></p><p><em> </em></p><p><em>
- SMS.PXE.Filter - The PXE filter script added by MDT.</em></p><p><em> </em></p><p><em>
- SMSPXE - Configuration manager PXE service point.</em></p><p><em> </em></p><p><em>
- BINLSVC - WDS and RIS legacy menus.</em></p><p><em> </em></p><p><em>
If you change the order of the ProvidersOrder key you should be able to switch between which device answers the PXE call first..</em></p><p> </p><p>
The above is rare though - but hey - its a useful insight into what is going on behind the scenes! Now, where were we? Ah yes, SCCM's PXE role - lets finish it off. Unless you can think of any real reason (I cant), then you will want to accept the PXE-database settings and click next. When dealing with the Certificate used for PXE, set the expiry to a long long long time into the future. The last thing you need is in a year is to have to renew it. Chances are, you will have forgotten about this setting by then - and will be head scratching why PXE booting isnt working! Save yourself the hassle then!!</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM12.jpg.abcb3d9c668342c8e72ad8af0e703e62.jpg" data-fileid="125" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM12.jpg.abcb3d9c668342c8e72ad8af0e703e62.jpg" data-fileid="125" data-src="https://www.edugeek.net/uploads/monthly_2012_02/SCCM12.jpg.abcb3d9c668342c8e72ad8af0e703e62.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Last up, that summary screen, so click next and then click close to finish. Ta da! Done! Next up - configuration time: thats boot images, operating system setup files and other lovely stuff! You will need your Window 7 Enterprise / Professional DVD to hand...</p><p> </p><p>
<strong>Create the SCCM Client Deployment Application</strong></p><p> </p><p>
Now we are going to get to know a new bit of the console! It will be the bit you will actually get to know pretty well, as everything you do in the future in SCCM will be done here, rather than in the Settings bit we have been in so far! So... in the console, go to Computer Management and select the Software Distributions node. You then want to right click on packages and choose New Package from Definition. We need to give SCCM a copy of the client, which it uses to manage systems; and it helps out in our build and capture also! You use the Definition option where you have a pre-build package - like MSIs. You dont have to, but SCCM creates all the install and uninstall options for you which makes life a bit easier.</p><p> </p><p>
You will get another wizard, aptly called the Create package from Definition wizard! Click next, and since SCCM is relatively clever, it already knows about its client. Select the package called Configuration Manager Client Upgrade, click next and choose the second option "Always obtain files from a source directory".</p><p> </p><p>
You will then need to choose the Network Path (UNC name) as the type and click on browse - choosing your sites SMS directory (SMS_xxx where xxx=the SMS site code) eg: \\SERVERNAME\sms_xxx\Client</p><p> </p><p>
Time for the usual Summary screen, and click Finish.</p><p> </p><p>
Right-click on the new package you've just created and review it's properties - just to make sure it matches what we have done, and while you are at it rename it from Upgrade to Installation. I have no idea why the package is called Upgrade and not Install!</p><p> </p><p> </p><p>
<strong>Create and Update Distribution Points</strong></p><p> </p><p>
Now you have created a package - here is a concept to get used to. Once you make one, you have to distribute it. No - that doesnt mean install it - it means make the setup files for it available. Until you do this, you will get an error "Source files not available on any distribution point" error. Not good!</p><p> </p><p>
So, we need to select the Package we have just created (Configuration Manager Client Installation) and expand it. Right-Click on Distribution Points and choose new distribution points - select the standard distribution point only and click next (I will go into the difference between the two later on in the Boot Images section).</p><p> </p><p>
Now that you have created the distribution point, right click on Distribution points again, and choose Update Distribution points, answer Yes when prompted. What you have done is create a reference point on the server for your installation files (step 1), and then populated it (step 2).</p><p> </p><p>
<strong>Windows Boot Files, getting your SCCM PXE to Boot</strong></p><p> </p><p>
In your basic installation, there will already be x86 and x64 bit boot.wim images, however we want to create our own and then distribute them to both the standard share and the PXE share. This is generally better, because then at least you arent faffing with the default ones!</p><p> </p><p>
In that trusty console, select Operating System Deployment under Computer Management, and expand the boot images node. Then right click, and choose Add Boot Image.</p><p> </p><p>
Browse to the network share where SCCM stores it's boot.wim files, first off for the 32 bit one (then repeat for the 64 bit one later) eg \\SERVERNAME\SMS_xxx\OSD\boot\i386\boot.wim</p><p> </p><p>
Now you can fill in some details for the boot.wim and call it something sensible - like x86 Windows PE boot environment for SCCM</p><p> </p><p>
Summary time, just check it - then click next to apply the changes.</p><p> </p><p>
Now that you have done the 32 bit boot.wim, I hinted at it a min a go - you know whats coming next! Repeat the above actions for the 64 bit (X64) boot.wim file by using the 64 bit path (\\SERVERNAME\SMS_xxx\OSD\boot\x64\boot.wim).</p><p> </p><p>
You should now have two new boot.wim files listed in the Boot Images section.</p><p> </p><p>
Now - when you boot SCCM normally - you would get the default Microsoft corporate background. Looks fine, yes - but why not look like a pro where you are, and put your own background in... its so simple. In explorer, browse to \\SERVERNAME\sms_xxx\OSD\bin\i386 and locate a file called WINPE.BMP, open it in Microsoft Paint and paste in your own company Logo, save the file (after backing up the original) and repeat this action for the WINPE.BMP file stored in the x64 path, this background will appear during the Deployment of Windows Vista, 7 or Windows Server 2008.</p><p> </p><p>
Once done, right click your chosen Boot.wim file in the console and choose properties and then the Windows PE tab, select the Specify the customer background bitmap (UNC Path) and browse to your newly created WINPE.BMP file, apply the changes and answer NO to the Distribution points update reminder as we'll be doing that shortly.</p><p> </p><p>
Remember what we did for the SCCM client installer - the whole distribution points jazz. Well, it applies here too - actually, it applies to all installs - client, OS, setup.... everything! So, we need to select the x86 Windows PE boot environment for SCCM boot image and expand that node, right click on distribution points and select New Distribution Points - which will give us that wizard.</p><p> </p><p>
Now, heres where things are a bit different. When the Copy Package screen comes up, make sure to select BOTH of the distribution points listed, one being the normal one and the other is the PXE distribution point, both are required for this to work properly. As at this point, we are in PXE mode for the boot - the files need to be on the PXE point too. You need to repeat this for the x64 as well.</p><p> </p><p>
Now you need to Update the distribution point, so right click on Distribution Points and choose Update....</p><p> </p><p>
Next up - its Operating System setup time. So... really, last warning for those DVDs!</p>]]></description><guid isPermaLink="false">611</guid><pubDate>Sat, 18 Feb 2012 13:04:32 +0000</pubDate></item><item><title>How to - System Centre Configuration Manager - Part 3 (Initial Configuration)</title><link>https://www.edugeek.net/blogs/entry/608-how-to-system-centre-configuration-manager-part-3-initial-configuration/</link><description><![CDATA[<p>Welcome to Part 3 of my System Centre Configuration Manager (SCCM) series! I know its taken me a bit longer to get this lot sorted, and I hope that Im covering the mailbag of questions Ive had - but if there is something specific you need, please comment or send me a PM. Alternatively, you can find me on Twitter <a contenteditable="false" rel="" href="https://www.edugeek.net/profile/2292-thescarfedone/" data-mentionid="2292" data-ipshover-target="https://www.edugeek.net/profile/2292-thescarfedone/?do=hovercard" data-ipshover="">@TheScarfedOne</a>.</p><p> </p><p>
Part 3 is going to deal with your initial configuration. Im going to take you on a whistle-stop tour to get your basic SCCM system ready to do a Build and Capture in Part 4 (which will be a 3 parter itself I think - 4a: Build and Capture, 4b: Deployment and 4c: Advanced Deployment Options [already published based on questions]).</p><p> </p><p>
So... introductions over with, lets get started! First things first, lets get into the SCCM Console. Im going to assume for the purposes of this guide that you have followed parts 1 and 2 of the guide; and that you are Remote Desktop'd to the SCCM Server.</p><p> </p><p> </p><p>
<strong>Boundaries</strong></p><p>
Clients are assigned to SCCM sites based on the boundaries defined for the site. Even though you are likely to only have one Site in a School Environment - you still need to set this up.</p><p> </p><p>
SCCM boundaries are used to identify a roaming client's position in the hierarchy, which in turn facilitates locating the nearest distribution points that host the content requested by clients. When a change in network location results in a client being outside its assigned site's boundaries, it relies on roaming behavior to locate content. More information about Boundaries can be found on technet - <a href="http://technet.microsoft.com/en-us/library/bb632910.aspx." rel="external nofollow">http://technet.microsoft.com/en-us/library/bb632910.aspx.</a></p><p> </p><p>
Boundaries can be defined by IP subnets, Active Directory site names, IPv6 prefixes, IP ranges or a combination of these. We need to configure the Site Boundaries in order for auto-site assignment to succeed (the clients network location must fall within one of the configured boundaries for site assignment to succeed).</p><p> </p><p>
To set our Boundary, click on the + beside Site Management. Then, click on your SCCM Site Server name, and underneath that we have the Sites Settings node. </p><p> </p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM1.jpg.4a113947538beb019a61c33416e962e8.jpg" data-fileid="116" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM1.jpg.4a113947538beb019a61c33416e962e8.jpg" data-fileid="116" data-src="https://www.edugeek.net/uploads/monthly_2012_02/SCCM1.jpg.4a113947538beb019a61c33416e962e8.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a> <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM2.jpg.4a7587f0be711fcb84ac161b0ccbdae2.jpg" data-fileid="117" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM2.jpg.4a7587f0be711fcb84ac161b0ccbdae2.jpg" data-fileid="117" data-src="https://www.edugeek.net/uploads/monthly_2012_02/SCCM2.jpg.4a7587f0be711fcb84ac161b0ccbdae2.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Next, click on the Boundaries node, right click the node and select New Boundary from the context menu. We need to change the type to Active Directory Site - which you can select from the drop down list. AD Site is by far the easiest to use here. Click on the Browse option, and select your AD site name. In most cases, this will be Default-First-Site-Name, but you can check this from your Domain Controller (or your machine if it has the Windows Server Administration Toolkit installed) - using the AD Sites and Services tool.</p><p> </p><p>
<strong>Management and Distribution Points</strong>  </p><p>
Technet: How to Configure the Default Management Point for a Site (<a href="http://technet.microsoft.com/en-us/library/bb632897.aspx" rel="external nofollow">http://technet.microsoft.com/en-us/library/bb632897.aspx</a>)</p><p> </p><p>
Next up, time to configure the Distribution and Management Points. Hopefully – you’ve still got the console open! Highlight your SCCM server, which should be listed under Site Systems, under Site Settings. In the right pane we'll see the roles we've already installed – as part of the setup.</p><p> </p><p>
Now, double click on ConfigMgr distribution point and place a checkmark in Allow clients to transfer content from this distribution point using BITS. That will help speed up your installs, as it enables the “trickle-feed” option; like Windows Update uses. You can leave the rest alone.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM3.jpg.78817a3bab241760f6b54734ebb1f26d.jpg" data-fileid="118" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM3.thumb.jpg.1ec7e2d21436ab3fce1fdd57a2261670.jpg" data-fileid="118" data-src="https://www.edugeek.net/uploads/monthly_2025_03/SCCM3.thumb.jpg.1ec7e2d21436ab3fce1fdd57a2261670.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a>  <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM4.jpg.61f458a6d5c1c65f89a3caef9976e904.jpg" data-fileid="119" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM4.jpg.61f458a6d5c1c65f89a3caef9976e904.jpg" data-fileid="119" data-src="https://www.edugeek.net/uploads/monthly_2012_02/SCCM4.jpg.61f458a6d5c1c65f89a3caef9976e904.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a>  <a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM5.jpg.829c32c254bbc7fe23e929f5c9d39ff7.jpg" data-fileid="120" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM5.jpg.829c32c254bbc7fe23e929f5c9d39ff7.jpg" data-fileid="120" data-src="https://www.edugeek.net/uploads/monthly_2012_02/SCCM5.jpg.829c32c254bbc7fe23e929f5c9d39ff7.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
Click on Configmgr Management Point to bring up its' properties. If you are planning on managing mobile devices (phones) put a checkmark in Allow devices to use this management point and click Apply. </p><p> </p><p>
<strong>Client Agents</strong></p><p> </p><p>
This basically does what it says on the tin. It will control the way in which the various components of the SCCM Client work. Select the Client Agents option, under Site Settings. </p><p> </p><p> </p><p> </p><p>
Lets start with the Hardware Inventory Client Agent – choose it from the list on the right side and verify that it is enabled. Set the inventory schedule to 7 days – unless you really need to gather your hardware specs more often. The more regularly you do this, the more beating you do of your SQL DB and your network. Click ok to close.</p><p> </p><p>
Next up is the Software Inventory Agent, again, a schedule set to 7 days will do fine. Theres a few more options here though - click on the inventory collection tab, and delete the default scan listed. It’s a bit OTT going through every HDD looking for exe’s! We are going to create one to just look in Program Files – as that’s where you install your Applications….right?!</p><p> </p><p>
Click on the yellow star and add files of type *.exe, then click on Set beside location, select Variable or Path name and enter %ProgramFiles%\ as the program path; and make sure you remove the tick from the windows directory as well. </p><p>
Next you can enable the Advertised programs client agent. This is the one you will want to use to allow users to do “self-installs” of registered safe software – and you also use it to do push installs as well. Enabling it is simple – open up the General tab and check the box for Enable software distribution to clients. Getting the hang of how easy it can be? One other setting you may want to do is change the New Program notification icon opens Add or Remove Programs option. If you are planning to use AppV, then also enable Allow virtual application package advertisement.</p><p> </p><p>
From the notification tab – you can choose whether to tell your users about new software. I tend to turn this off or your get popups every time and you generally don’t want this. You will have other ways of letting users know you’ve put new software out – like bulletins?</p><p> </p><p>
Next we will configure the Computer Client Agent properties. Health warning here - Failure to configure this correctly or failure to configure it will lead to a failure in Operating system deployment.</p><p> </p><p>
Under Network Access Account we need to enter an account to be used by Configuration Manager 2007 client computers to communicate with network resources. You should be careful about what account you use as the Network Access Account - it only really needs enough to connect to your distribution point shares. It should never have domain admin rights. </p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_02/SCCM-CA.jpg.81f63aec72d2cd3ca616bf15e379980a.jpg" data-fileid="113" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="SCCM-CA.jpg.81f63aec72d2cd3ca616bf15e379980a.jpg" data-fileid="113" data-src="https://www.edugeek.net/uploads/monthly_2012_02/SCCM-CA.jpg.81f63aec72d2cd3ca616bf15e379980a.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
You can then also change the text on screens shown to the user, via the Customization tab. On the BITS Settings screen, make sure that it is set to All Clients, and unless you want to get clever with throttling settings and time windows – you can leave the rest alone. Click apply and ok.</p><p> </p><p>
For Remote Tools, set your Remote Assistance settings to Full control for both solicited and unsolicited remote assistance and add Domain Admins to the Security page.</p><p> </p><p>
<strong>Client Installation Methods</strong></p><p> </p><p>
From the menu list to the left select Client installation methods. Unless you really need to – don’t enable Push Installations. The best way is to build your machines and include the client there. If your don’t have that luxury, then enable it by double clicking it in the right pane – and  selecting Enable Client Push Installation to assigned resources. You will get a warning message. Click OK, and then check the options for Workstations and Enable to Site Systems.</p><p> </p><p>
You then need to specify an account to install the client under. To successfully install the Configuration Manager 2007 client, the Windows user account used must have Local Administrative rights on the destination computer. If the install fails with all accounts in the list then the installation will be attempted using the computer account from the Configuration Manager 2007 site server. If the user account does not have Local Administrative permissions on the destination computer then the Client will not install.</p><p> </p><p>
Next click on the Advanced client tab and set your Installation Properties string to something like this “SMSSITECODE=SITECODEHERE SMSCACHESIZE=8000”</p><p> </p><p>
<strong>Configure Discovery methods</strong></p><p> </p><p>
Now we need to set up how SCCM will find your machines! This can be in terms of finding agents that are out there; or new "unmanaged" machines which then our Client Push will deal with. So, a bit about it first... taken from Technet (<a href="http://technet.microsoft.com/en-us/library/bb633276.aspx" rel="external nofollow">http://technet.microsoft.com/en-us/library/bb633276.aspx</a>)</p><p> </p><p>
Active Directory System Discovery – Discovers computers from the specified locations in Active Directory Domain Services.</p><p> </p><p>
Active Directory User Discovery - Discovers user accounts from the specified locations in Active Directory Domain Services.</p><p> </p><p>
Active Directory Security Group Discovery - Discovers security groups, including local, global, and universal groups from the specified locations in Active Directory Domain Services.</p><p> </p><p>
Active Directory System Group Discovery – Discovers additional information about previously discovered computers from the specified locations in Active Directory Domain Services. This information includes the OU and group membership of the computer. Active Directory System Group Discovery does not discover information about new resources that did not previously exist in the Configuration Manager site database.</p><p> </p><p>
Heartbeat Discovery – Used by active Configuration Manager clients to update their discovery records in the database. Because it is initiated by an active client, Heartbeat Discovery does not discover new resources.</p><p> </p><p>
Network Discovery – Searches your network infrastructure for network devices that have an IP address. This allows you to discover devices that might not be found by other discovery methods, including printers, routers, and bridges.</p><p> </p><p>
In the Discovery Methods section, select Heartbeat Discovery, and set the discovery to something like an an hour or 2 hours to start with. This will help ensure all clients get connected quickly. Once you are all up and running – you can then set these to be a bit longer. I usually use 4 hours. </p><p> </p><p>
You can use the same setting for the other discovery methods - Active Directory System Discovery, Active Directory User Discovery, Active Directory Security Group Discovery and Active Directory System Group Discovery. I tend not to enable Network Discovery. To give things a kick start - you should also check the Run discovery as soon as possible is ticked for all of the above.</p><p> </p><p>
For all the “AD” related discoveries – you can target where abouts in your OU structure you want to look. To do this, open the properties and click on the Yellow star to add an Active Directory container. You can use the Domain, or a custom query if you want to tie down to an OU (or multiple OUs).</p><p> </p><p>
That's it you are done. The basic configuration is ready – and if you have enabled Push Client Install, you will start to see your machines “check-in”. </p><p> </p><p>
<strong>Add the PXE Service Point (PSP) role to SCCM</strong></p><p>
More Technet Bedtime reading....Planning for PXE Initiated Operating System Deployments (<a href="http://technet.microsoft.com/en-us/library/bb680753.aspx" rel="external nofollow">http://technet.microsoft.com/en-us/library/bb680753.aspx</a>) - no seriously, read this one. It will save you a whole world of trouble later.</p><p> </p><p>
Ok – so Im guessing one of the real reasons you want SCCM is for the uber OS deployment handling that it does. This section will walk you through that – from installing the role down to getting your basic OS Build and Capture image made ready to deploy.</p><p> </p><p>
So, first things first – what you need. You need to have the Windows 7 DVD ready, and also Remote Desktop access to your SCCM Server. Open the Console, and go down to Site Database &gt; Site Management &gt; Site Code &gt; Site Settings &gt; Site Systems and highlight your server. You need to then right click on it and choose New Roles.</p><p> </p><p>
When the New Site Role Wizard appears, click Next – and then highlight the PXE role and select it. You will be prompted about “incoming PXE requests” which you can accept.</p><p> </p><p>
Next up is the PXE - General options page. For texting you might want to remove the password requirement – but in production, definitely set one! Choose a delay for your SCCM to wait before answering a PXE Request. This is useful if you currently have another deployment method in use – such as FOG or another WDS/RIS server. </p><p> </p><p>
Now let's continue with configuring SCCM's PXE role – and you will need to accept the PXE-database settings. You will also be setting up a Certificate for the PXE server. Make sure you create this with an expiry way into the future. You don’t want to go around having to redo that in a years time! The usual summary screen will be show, then that’s that done.</p><p> </p><p>
If you have any problems with getting WDS to start once the PSP role is installed then please take a look at <a href="http://blogs.technet.com/b/configurationmgr/archive/2011/01/05/troubleshooting-the-pxe-service-point-and-wds-in-configuration-manager-2007.aspx." rel="external nofollow">http://blogs.technet.com/b/configurationmgr/archive/2011/01/05/troubleshooting-the-pxe-service-point-and-wds-in-configuration-manager-2007.aspx.</a> </p><p> </p><p> </p><p>
Next up in Part 4A (yes, its got to be that big an uber topic that Im now breaking it down a bit more) - we finish off with our boot images, set up the actual Config Manager client installer; and then lastly our OS install. Then, we will build a task sequence - and watch as SCCM sets up Windows, then captures that for us ready to use.</p>]]></description><guid isPermaLink="false">608</guid><pubDate>Tue, 07 Feb 2012 10:39:43 +0000</pubDate></item><item><title>How to - System Centre Configuration Manager - Part 2 (Installation)</title><link>https://www.edugeek.net/blogs/entry/603-how-to-system-centre-configuration-manager-part-2-installation/</link><description><![CDATA[<p>Welcome to Part 2 of my System Centre Configuration Manager (SCCM) series – desigined to show you how to get a basic setup up and running in a day not a week!</p><p> </p><p>
So, Im guessing you’ve gone through Part 1 – and are now ready to get on with the actual install. </p><p> </p><p>
You will be needing those two AD accounts - SCCMAdmin and SCCMClient – so make sure you have them ready. </p><p> </p><p>
<strong>Starting the Install</strong></p><p> </p><p>
STOP – SCCM needs to extend the AD Schema. If you have not installed SCCM before, you will need to do this. Checklist….</p><p> </p><p>
1.	Where is your Schema Master role (it will be one of your Domain Controllers)</p><p>
2.	You can only update the Schema if you are a Schema Admin. Give the user account membership of that group via AD Users and Computers</p><p>
3.	Remote Desktop to that server, and access the SCCM Install CD from that server (you need to share it – then you can use \\SERVERNAME\DRIVE)</p><p>
4.	Open an elevated Command Prompt, and run extADSch.exe method and located it on the SCCM 2007 DVD (..\SMSSETUP\BIN\I386)</p><p> </p><p>
<strong>Install "Take 2"</strong></p><p> </p><p>
Back to our install….</p><p> </p><p>
On your SCCM server, run the Setup file, and then on the splash screen, select Install. Now, lets walk through the setup and its options…</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_01/post-1-1219731375.jpg.5828410b5f6fbdf0bbbaa9115c51f4d0.jpg" data-fileid="109" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="post-1-1219731375.jpg.5828410b5f6fbdf0bbbaa9115c51f4d0.jpg" data-fileid="109" data-src="https://www.edugeek.net/uploads/monthly_2012_01/post-1-1219731375.jpg.5828410b5f6fbdf0bbbaa9115c51f4d0.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
First we will get the usual “Welcome screen”, which you can click through. Next up – what to do! Choose the first option, Install a Configuration Manager site server.</p><p> </p><p>
Now time to review the licence – go on, read it if you must! Of course, we always do. Next we get to choose the type of installation, choose Custom, so that it is set up as we want.</p><p> </p><p>
Next up – choosing a site type. As you are reading this article – im guessing you are new to SCCM – so it will always be “Primary site”. You would use “Secondary” in branch scenarios, or in some upgrades.</p><p> </p><p>
Time to choose whether you want to be in the improvement programme; enter your license key, and then an install directory. </p><p> </p><p>
<em>Lets get more serious</em></p><p> </p><p>
The “Site Code” section is where things start to get interesting. Choose something sensible – like a short version of your domain name etc; and give a description. You then need to choose a mode. Everyone will tell you to use “Native mode” – and yes, this is more secure – but it will also take you longer to set up. Ive run both, and have always found “Mixed mode” to be more stable. So – choose “Mixed”.</p><p> </p><p>
The next screen asks about the agents you want to use – this is why we chose “Custom” setup. </p><p> </p><p>
Add Hardware Inventory, Software Inventory, Advertised Programs, Remote Tools. You can add others if you want, but these are the ones we are going to deal with.</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_01/post-1-1219733088.jpg.46a69325f74abc35bd573a42309ad1f3.jpg" data-fileid="110" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="post-1-1219733088.jpg.46a69325f74abc35bd573a42309ad1f3.jpg" data-fileid="110" data-src="https://www.edugeek.net/uploads/monthly_2012_01/post-1-1219733088.jpg.46a69325f74abc35bd573a42309ad1f3.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
We are nearly there now – most important step, where is your database. Yes, you can use clustered SQL here too. Point the setup at your SQL instance. You can also choose your DB Name. Next you need the specify the “Provider” – and as the dialog says, on clustered SQL, this cannot be on the SQL. I tend to use the SCCM box itself.</p><p> </p><p>
The SMS Provider is used by the Configuration Manager console, Resource Explorer, tools and custom scripts used by Configuration Manager Admins to access site information stored in the site database.</p><p> </p><p>
The Management Point is your next choice – again, I tend to use the full name (dotted domain – ie FQDN) of the SCCM Server. TCPIP Ports are up next, don’t mess with this unless you need to. There’s just no need! </p><p> </p><p>
You are then going to do a quick net connection to grab the latest SCCM components. You can download these in advance if you want to though.</p><p> </p><p>
A pre-requisite check will then be done – all should be good to go. So sit back, whilst it installs – and it can take quite a while!</p><p> </p><p>
<a class="ipsAttachLink ipsAttachLink_image" href="https://www.edugeek.net/uploads/monthly_2012_01/post-1-1219735234.jpg.db0f71fb86dae891fdb72cacb5adec46.jpg" data-fileid="111" data-fileext="jpg" rel=""><img class="ipsImage ipsImage_thumbnailed" alt="post-1-1219735234.jpg.db0f71fb86dae891fdb72cacb5adec46.jpg" data-fileid="111" data-src="https://www.edugeek.net/uploads/monthly_2012_01/post-1-1219735234.jpg.db0f71fb86dae891fdb72cacb5adec46.jpg" src="https://www.edugeek.net/applications/core/interface/js/spacer.png" /></a></p><p> </p><p>
<em>Coming next</em></p><p> </p><p>
Now – Ive changed my mind a bit on how to complete this blog series. Part 3 is going to deal with your initial configuration, and Part 4 will deal with doing a build and capture of and OS – and push it out. Part 5 will deal with what to do with Applications. Part 6 will bring Part 4 and Part 5 together and show you how I run SCCM live now, to build any machine and do automatic software deployments based on AD groups.</p><p> </p><p>
Stay tuned!</p>]]></description><guid isPermaLink="false">603</guid><pubDate>Thu, 26 Jan 2012 22:16:11 +0000</pubDate></item></channel></rss>
