psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
128Gb for a 1:1 teacher (windows or mac) device is too small. It might *just* be enough for a student not doing any creative "multi-media" work. 256 is fine for a 1:1 teacher device in almost all cases. Photography and Media Teachers need more. Shared Devices, 256 is fine with intune shared user with local onedrive policy. If these shared devices are ever used by media heavy classes, then 512Gb is essential. Shared Devices with 128Gb is fine *if* you have no locally installed apps, and the intune shared users policy (the one that disables one drive and encourages apps to prefer cloud storage). This is a "Chromebook-like" device set up, and nothing like a traditional PC Lab, so make sure to manage users expectations.
-
not ideal, but maybe the only "free" solution? ...if you use it for *only* deploying software, get all the collections set up for them, and a write a little "how to deploy software" guide then it will be fine for probably at least 18 months which is plenty of time for them to find their feet, break it and take ownership of the sccm replacement project.
-
Store Apps are they key I think. Microsoft bet Windows' future on metro/modern/appx and intune was built for that. IOS and Android *only* had those style of apps. Microsoft's bet didn't pan out, and Intune has struggled every since.
-
Unless you can figure out the correct blood sacrifice and incantations, you are probably going to need a 3rd party product to meet your "all apps installed perfectly in a predictable, compliant timeframe" requirement. Here's a deep dive on the timings of various Intune managed processes: Intune Timing Demystified: The Truth About Intune Sync Intervals But more importantly, will you be updating your handle to be localzpl ?
-
There's a reason Configuration Manager is included with Intune. 😂
-
The Ryzen AI 5 330 has 1 performance core and three efficiency cores, and can be tuned down to 15w by the OEM. A performance CPU it is not. Probably fine for most tasks in schools/offices though.
-
WDAC and Manually Installed Software Failures
psydii replied to petben's topic in Enterprise Software
In my opinion WDAC is not a fit replacement for Applocker. Indeed several modern features of Intune delivered security profiles now use applocker instead of WDAC. Furthermore, just because an app comes from the app store, it is not necessarily a "modern app" in the sense WDAC (or applocker) is expecting, these days they can be used as a distribution tool rather than philosophical statement, hence the unpacked .exe in temp folders during install. When I was looking at WDAC, (back when and appx/Metro was the future), I got the impression that it was designed to restrict apps to only those specifically approved by IT, on a per machine basis with no regard to the end user. -
Get the Finance Director to write a letter to Head of Customer Services advising them of their breach of contract, and requesting immediate remedy. Send it recorded delivery.
-
Probrand seem to have a very good relationship with Lenovo, and seem (to me) very good at matching Lenovo's portfolio to our requirements.
-
If you've got an HP print fleet, their recycling programme still seems to be 'free', its part of the 'value proposition' of the brand. HP Ink & Toner Cartridge Recycling | HP® United Kingdom Similar with Sharp Toner Recycling Scheme | Sharp And Oki OKI Consumables Free Recycling Services | Support | OKI Europe Ltd | Printers and Solutions and Kyocera Toner Take-Back Service | Support | Kyocera and Konica Minolta Recycle Your Toner Cartridges | KONICA MINOLTA Canon claim to too, but their language is a little less decisive, so YMMV How to recycle printer ink cartridges and toners — Canon UK Store
-
I was recently told they are no longer free Year 1 is now a whole £1.
-
...while this is probably a config error (because keeping tabs on where and how all the settings interact seems to be a Sisyphean task).... I have a ( paranoid? unfounded? cynical?) suspicion that Microsoft might be ignoring some "don't restart in business hours/without user consent" settings in order to get machines up to date before the secure boot certificate expirey next month. This May, we've seen 50% more devices come completely up to date than is usual by this time in the month, even some previously extremely recalcitrant devices have cleared update errors and made it up to 8457 / 7079 / 7291
-
Check here: Windows Autopilot devices - Microsoft Intune admin center You might also be able to check in on the machine itself: Interpreting the Windows Autopilot profile – Out of Office Hours It's also possible something else other than autopilot is causing that screen to appear, but I've only ever seen that during autopilot, or when explicitly enrolling during a non-automated windows install.
-
Typically proxies/firewalls are configured to allow devices to bypass filtering/proxies for enrolment/management. Unless you built it yourself, or explicitly chose to change what it offered as useful defaults, your devices are probably able to phone home to check for MDM enrolments. Windows (like MacOS and iOS) phones home during setup and checks to see if it is owned by an org. If Apple/Microsoft have a record for that device, the device is then passed off into the org's preferred MDM to apply org settings etc. This device appears to have received info from Intune/Autopilot that *somebody* owns it and it needs to fully enrol in their management platform and apply the various settings. It's for some reason failing at this stage. This could be because your filtering platform is getting in the way , or because stale records exist and the device needs to be "unlocked" in Autopilot. Of course, from your point of view, it does not need to be unlocked because its not supposed to be enrolling in the first place! To resolve this you can go to autopilot devices and remove it. You will likely have to search for the device there based on its serial number (hostnames don't really exist/are completely arbitrary within the autopilot phase). If the device is not there, then its possible that the device/motherboard has previously been registered in someone else's tenant. I'm not sure the flow to resolve that. More info about troubleshooting Autopilot phase here:Windows Autopilot troubleshooting FAQ | Microsoft Learn
-
Just to re-iterate Matt's suggestion, use the chrome/edge developer tools to see what elements of the website/pages are taking a long time to load, since that might help you track down what is going on as that specific traffic tries to traverse the smoothwall and then your isp. The Chrome DevTools Network Tab: Debug Page Speed | DebugBear
-
Subject Access Request Emails
psydii replied to Bankesy's topic in Data Protection & Information Handling
Or.. y'know, the automated redaction tools built into Acrobat for decades. I missed the "its faster than acrobat's tools" bit -
Is that during OOBE or first login? To me that looks like autopilot (which fires during oobe ). Which suggests that the device’s hardware hash is registered in intune/autopilot. If so, that failure is pretty normal if you didn’t do something in the intune->enrollment portal to (re) enable that specific device to re-enroll.
-
1) gives you five or six years of support since they'll eol these soon, since its replacement was launched about 12 months ago. 2/3 are for when you've got a £40K core out of warranty and no money to replace it, so you have to keep it going by hook or by crook. But this is just daft now you've got the green light from governors. Replace with new! 4) yup. hate the idea of replacing a chasis with a stack, but its hard to dismiss it when the equivalent chasis solution is 5x the price. 5) warranty and support - if you need things with warranty and support coverage, you'll be replacing these every few years (compared to the venerable procurve you currently have). This might not actually be a bad thing.
-
Subject Access Request Emails
psydii replied to Bankesy's topic in Data Protection & Information Handling
Yes 100% as per @dmj and @msi_school; if id validation is needed, ask them to come in with it, and also alert the office staff to expect them. The front-line staff should be trained to check and cross check against data held in the MIS, and then email confirmation (rather than the actual documents) to the DPO/responsible officer. FWIW E5 (and probably e3) Purview can spot passport id's etc being emailed, though its a bit noisy if you have granularity set to detect single instances of that sort of thing. Also the person who would be receiving the unwisely scanned documents is usually the DPO or equivalent, so ideally placed to ensure they are deleted from the system post-haste. -
For the business range of the ecotank's the print head(s) are fixed and span the entire width of the page. They don't move so speeds are closer to those of lasers. Epson have a different pricing model than HP. HP priced theirs like they did the lasers, and the device was basically a loss leader. Epson charge about three times what HP did for comparable devices. HP shut their Pagewide line because it never became profitable (most devices never printed volumes that allowed purchased ink to turn the initial sale into profit.
-
EcoTank seems quite similar to HP's old PageWide series. I would say that domestic to small office/low-end professional epson printers notoriously clog their print heads, and while better at being recovered than they were, can be a right pain. The larger low-end commercial epson we have has never been a problem. Pagewides also suffered from this. Pagewides were phenomenally good value for money, at the time you'd need to be pushing 1m+ pages on a Riso for the TCO of the Riso to be actually be lower than the four or five PageWides (per year) you'd need to handle that volume. (it would however be insanity to actually do that). Last time I checked, as long as they get regular use and are printing *at least* 20-40K per year, they are excellent value compared to laser printers doing the same volumes.
-
Not looked into it for a while, so I'm not sure what the logs would look like if it had paused for the user to consent or manually restart, but that does read to me as though any consent for the reboot had already been given before the update started, (or "please delay reboot" wasn't clicked if/when prompted) Whether this happened via policy, or user interaction I don't know.
-
I think "allow users to receive prompts" might been the route taken for this incident. The user may have been prompted, and they clicked without considering the implications. It's not an automatic reboot (which you have disabled) if the user opted into it. When we used GPO for managing this, I think we set the equivalent of don't automatically, install and don't prompt on devices within the exam set, for the duration of the exam period. These days we keep exam devices off the network, in part, to reduce this risk. If one does need to be connected, our SOP is to keep it out of circulation until we have manually triggered a windows update scan and install so we're sure there's nothing lurking.
