Jump to content

_techie_

Members
  • Posts

    434
  • Joined

  • Last visited

Everything posted by _techie_

  1. Interesting you mention a 30 second delay - we had this with the latest version of the extension on Windows. They did give us a workaround however, which seems to work. With the SSO, are you expecting the Smoothwall browser app to just sign in without prompts - and identifying the user correctly? We are getting a prompt when launching Smoothwall browser, to open authenticator app which prompts to sign into entra (not proper SSO IMHO). Whilst not terrible - it doesn't really perform as proper SSO - like the extension in Edge on Windows. I guess I am just impatient perhaps. Your plist file is close to my working version so thats good news.
  2. SAND Academies Trust - https://www.sandmat.uk/ Closing Date 11:59pm, 26th Mar 2025 The Role The role will involve on-site visits to provide support to end users where required, and for planned maintenance and improvements to infrastructure. End user support will be provided via the Service Desk using a ticketing system, utilising remote assistance tools where possible. Further details are available in the job description. As a shared IT Service covering multiple sites, you will be expected to hold a full driving licence and have access to a vehicle. We offer a hybrid working pattern, with four days per week on-site, and one day remote, although you must live within a commutable distance of the schools. The Trust We are passionate that every child deserves the very best education. As a partnership we will: improve outcomes, opportunities and life chances for children and young people, offer more / wider support for their families and share and develop staff expertise. https://mynewterm.com/jobs/17239/EDV-2025-SAT-32329
  3. Yes please! I will try your version of the Smoothwall Browser config if you can provide it!
  4. Do you mean that Safari picks up the SSO, or Smoothwall browser? What is your App Config looking like on the Smoothwall browser end? Are you installing the company portal on Shared devices? The company portal doesn't seem to work as when prompted to install a management profile, it fails. Is this even necessary? Since we had enrolled them as supervised, why the additional layer of management? Thanks
  5. I found doing any TLS inspection on traffic destined for Senso's servers caused issues. Specifying URL's and ports in your firewall, and setting them to be not TLS inspected helped massively. If you have a firewall that can do traffic priority, setting it to live/video/realtime helps speed up the initial connection massively. There are still some issues with the product, don't get me wrong, but the above really helps. Thanks Mark
  6. Hi. Does SSO on Intune managed shared iPads ever work? I am trying to improve experience with SSO on Apple's version of Shared iPads: The iPads are setup using an enrollment profile that is declared as shared with: 1) No User Affinity 2) Users must login to the device using a UPN/email address and password for the first time, then can setup a 6 digit iPad pass code thats tied to their school apple ID. 3) Our Apple School Tenant is federated against our M365 Tenant. Apparently according to Microsoft's documentation, just the Microsoft Authenticator App is required to achieve SSO, and their M365 Apps such as Outlook, Powerpoint, OneDrive and Teams etc (VPP versions) should just work, due to them being MSAL apps. So far, this doesn't seem to work! Users are prompted again, to enter their email address when opening any of the above apps. I have also enabled the attached policy, following the Microsoft documentation, but even with or without this, it doesn't seem to work. Any ideas? Thanks
  7. What setting do I need in Intune to lock iOS Devices to one WiFi network? Cheers
  8. Hi. Not getting that far sadly, the drive fills up. Might try on a smaller sub-section. I'm thinking that StorageSense isn't kicking in properly to manage the storage yet. I'll re-test and come back to you. Thanks
  9. Hi. We have a newly onboarded school as part of our MAT, which we have setup a Team for. We have private channels with members assigned to them. When syncing a larger number of files, we are experiencing local storage filling up on the client computers to the point that the device becomes unusable. For the time being we have advised no Teams syncing at present. However in testing I am still getting the same issue. There seems to be a disconnect in the OneDrive client, and the users profile size.. Profile shows 2.0GB for example, whilst 500GB drive is full, all under SANDMAT. It initially takes a while to do the processing on 100,000+ files. We have files on demand enabled, I'm not sure why its caching such a large number of files, and filling the local storage. Once the drive fills up, the OneDrive client refuses to continue processing any files (well obvs!). Any ideas? Am I missing something on Intune/Team setup for the channels? The general channel with a few files in worked fine... Thanks
  10. I am trying to use the online method of Get-WindowsAutoPilotInfo (using the -Online) switch, but current policy dictates that all global admin users have security key only as the only method for 2FA, which I would agree is good security practice. However 2FA prompts initiated by powershell commands currently don't always support FIDO2 MFA support. We are using AutoPilotOOBE module at Windows OOBE/Setup, however I have tried running Get-WindowsAutoPilotInfo.ps1 -Online within a running version of Windows 10 to get the Sign in Prompt, but get stuck at the 2FA part of the process with a window that continually loops at "Working". Is anyone else in the same situation, and how have you implemented a work-around? I can only think of having a single named location (the office at work) to possibly allow a second method for 2FA (such as Authenticator App) for directory admins only for Intune/Autopilot App. Looking for some guidance here, as using the CSV method is a little slow... Cheers
  11. Remote desktop with HTML5 gateway to a RDS Farm - We use Parallels for Remote access for staff anyway, so just bolt onto this...
  12. The Templates settings then administrative templates seem to work way more reliably for me too, I've been designing an updated set of configurations using them and it seems way more reliable....
  13. Yes, disabling the Senso service improves matters instantly! I will try the fix on one machine EDIT - their powershell command seems to fix it. We are waiting however - Senso need to fix their stuff
  14. Hi. We have had several (but not everyone) reporting that outlook is performing slowly. This seems to be affecting users more with outlook in non-cached mode, but I have had users on the same laptop/workstation on InTune reporting the same issue. I experienced the same issue myself approx 45 mins ago, but had to close Access down in order to delete my OST file.... Once done, and re-created my profile, everything is now working as expected. We are a smoothwall school btw, and apparently not the only one having problems! Anyone else?
  15. My colleague started work on it before I started. It's been disappointing I must say comparative to things like Mosyle.
  16. From a sysadmins point of view I have the following issues with Intune: 1) not designed for shared devices environments (often occurs in schools) 2) Unresponsive compared to on-prem technologies (important for exams) 3) restrictions taking time to apply after login, therefore making any cyber security policies broken and students taking advantage of this (not just messing about but being able to run scripts/bad processes 4) You cannot easily see what is inside any existing scripts to refer back to for troubleshooting... 5) waiting for devices to check back in to follow up 6) unhelpful error messages when installing software. Win11 23H2 seems particularly bad when using IntunePckgr apps... 7) costs and additional costs for tiering and add-ons. 8) Deploying printers... Still hell even using Paper cut Print Deploy client. I have had reasonable success with Win10 but Win11 is giving me serious issues with reliability. Thanks
  17. I will take a look at these two thanks. I have managed to improve things by using a combination of both Senso's Allow Only whitelisting, and Smoothwall. Seem to have something - next steps are removing the PC's in there entirely.
  18. Hi. I have been tasked with setting up a whitelist for our exclusion room. I have been getting it to work, bar one thing - blocking google.com which comes under the inbuilt Chromebook category. Students can still get to Google and search which is what we want to block. This is on smoothwall, and we are using the cloud filter on ChromeOS. Any suggestions welcome. Thanks Mark
  19. I would say there is something fundamentally wrong with your system if users cannot read from %PROGRAMFILES%..... That is all that should be required. Where are you installing ExamWritePad to?
  20. On the new Teams app, the files app has been removed and can't be re-added. Is there a way around this?
  21. Hi. We use Teams cloud PBX, and are having issues with iPhone users calling the Auto Attendant. It connects but no audio works. Android phones are not affected. Anyone else with this issue? We have a ticket open with Microsoft but no joy at present.
  22. Yes that sounds right from memory - we had to add https inspection exceptions for google domains. Luckily, I think Smoothwall as a Chromebook category, which includes what is necessary for this to work! Glad you got it sorted.
  23. Hi, We have an odd issue or two, both with the same symptoms: 1) Intune managed devices - users who hotdesk (both students and staff) end up with multiple desktop shortcuts for Teams, the suffix ending in the PC hostname that was logged into! 2) Both intune and on-domain hybrid azure joined (not intune) have the same problem with Microsoft Edge for Business shortcuts that keep duplicating - again with the hostname of the PC that is appended to the shortcut name... This isn't terribly taxing, but it is annoying and staff keep asking me if they can delete them (they can, as they exist on the users OneDrive desktop folder). Is there a GPO/Intune setting to stop this? Thanks
  24. I use the powershell module AutoPilotOOBE. Works fine and does group tags, hostname and sysprep too!
  25. I use my OSDCloud ISO on a fresh laptop that I install Win10/11 over the internet including the corresponding driver pack. Then once that's done, shift+F10 and install all windows updates, rename computer to serial number then reboot. I then use the powershell module AutoPilotOOBE to do the autopilot enrollment which is online and you can name the device here too and Group tag. You can even specify sysprep reboot/shutdown and wait for the tag be be assigned before sysprep. I then am doing the autopilot pre-provisioning which means when I'm handing it over to the staff member who I've assigned it to in the autopilot device console. It's far from quick, but I'm only doing this on staff 1:1 devices (laptops) at present... We also tried this (Intune) with shared laptop trolleys and it was far from perfect IMHO. Ive achieved better results with GPO for shared hot desking computer suites at present. The settings are enforced from the point of logon in the in the case of computer suites with GPO.
×
×
  • Create New...