Yanover Posted December 22, 2020 Posted December 22, 2020 (edited) Hey guys, We have multiple classes that are affected to Impero class groups through AD user groups (BYOD Laptops). For a reason that I cannot explain, some of the computers entities into the impero console don't have any groups into the property tab, it seems that the AD group of the user is not transferred to the impero server when the user logon. Some of the students that are affected to the same AD groups are well placed into those groups and the Impero client version between the non working computers and the working ones are the same. I looked at the server and client logs, but didn't find anything in relation with this problem .. If anyone has an idea, it would be very appreciated. Thank you ! Edited December 22, 2020 by Yanover
Steve21 Posted December 22, 2020 Posted December 22, 2020 To clarify, when you say BYOD laptops do you mean like a shared bank? Or are these their own devices? Just thinking in terms of how the client is being deployed out/run on said devices Steve
Yanover Posted December 22, 2020 Author Posted December 22, 2020 It means that those devices belong to the students. Nothing special about the deployment, they use W10(1909) and are member of the domain. They all belong to the same Organization Unit. Impero client is deployed manually from the server console. (MSI deployment) and the client version is 8.4.83. Hope it helps .
mavhc Posted December 23, 2020 Posted December 23, 2020 did they log in after the laptop was turned on that day?
Yanover Posted December 23, 2020 Author Posted December 23, 2020 Yes of course !And I can see these computers in the Impero console, under the "all network" section. The group attribution is based on the AD Group and as I said I my precedent post, the AD group is not showing up in the computer's properties.
mavhc Posted December 26, 2020 Posted December 26, 2020 When staff open their laptop in the morning after it's been sleeping, and unlock it, they often don't appear in my staff group. My theory is it's not getting the AD groups in that scenario
Yanover Posted January 11, 2021 Author Posted January 11, 2021 (edited) I tried from different computers, which were shutdown before I opened the Impero console. The problem is probably on the client side .. Will probably try to reinstall the imper client on the student computer .. Edited January 11, 2021 by Yanover
Yanover Posted January 18, 2021 Author Posted January 18, 2021 hello, We noticed that when a student with an Active Directory account is not on the right wifi when he connects to his session, even if he changes wifi afterwards, the AD groups are not traced back to the server. As we work with the name of the student's AD group for group assignment in the Impero console, the student's computer is not categorized as it should be. To overcome this problem, it is necessary to disconnect the session and reconnect it making sure that the correct wifi is selected. We have posted an issu to the official Impero customer's platform to inform them about this problem.
Yanover Posted January 18, 2021 Author Posted January 18, 2021 No it does not, the session needs to be restart. Otherwise, the service doesn't forward the AD group of the user. So if the session was open with the wrong wifi, the student need to close the session, change the wifi by selecting the correct one and re-open the session.
Yanover Posted January 18, 2021 Author Posted January 18, 2021 Yes, if you restart the service, it works.
mavhc Posted January 19, 2021 Posted January 19, 2021 https://github.com/mavhc/powershell/blob/master/imperofix.ps1 has my quick hack to restart impero service on an OU's worth of computers
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now