_techie_
Members-
Posts
434 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by _techie_
-
How do you do the delegate access on Pupil OneDrive folders for staff?
- 29 replies
-
- locker
- salamander
-
(and 1 more)
Tagged with:
-
Hi. I am re-installing the AccessIT App, and have come across an issue with BioStore fingerprint recognitition/identification inside AccessIT. I am familiar with the AccessIT install, but have come across an issue where I simply cannot get fingerprints to be recognised in AccessIT using IDStation after installing and licensing the software. I have a working fingerprint, and can test this in IDManager without issue. What magic sauce am I missing to make this work? Cheers _techie_ If anyone can help me whilst I am waiting for BioStore support to come back to me, it would be great :-)
-
Sadly with OneDrive auto backup on, (and desktop being a folder that gets automatically backed up) this whilst a great suggestion won't work.... Thank you though!
-
Hi. We are slowly completing our rollout of Intune devices, but we have some 'challenging' students: We have locked down several parts of the system over and above the normal UAC prompts to install things to system. However we have the following things that still need resolving: 1) Locking down the personalize part of the settings for lockscreen and desktop (yes unbelieveably). 2) Stopping "User installable apps" such as Discord/Browsers from installing to C:\Users\username\AppData\Local\... (currently working on an Applocker Policy for this to stop MSI and EXE running from C:\Users\*\AppData\Local\ etc 3) General Dicking about creating hundreds of desktop shortcuts etc (not sure we can solve this!). Any suggestions/recommendations for points 1 and 2 would be good or settings in Intune we can lock it down. Thanks
-
Google Domain Sign in Issue at google.com/co.uk
_techie_ replied to _techie_'s topic in Cloud Services
Hi. Sorry for the slow delay in replying. No, it was a Google Service that wasn't turned on. Google Search & Assistant IIRC. Once turned on, issue worked as expected. We do have another odd issue however where using Azure SSO to sign into Chromebooks, we are hitting a login loop, where once we are signing in, and the chromebook goes to a wifi connection screen, then loops back to the Azure SSO sign in screen. Have you experienced this issue and how did you resolve it? Thanks Mark -
You need to be using a transparent proxy for a network location. I would advise if possible a seperate VLAN for the Chromebooks, and set them to go through the filter unauthenticated as your lowest common denominator (e.g. Year 7 pupils). This way you can remove the SSL login and the proxy settings via Google admin console. Hope this helps.
-
Hi. We have a successful google Education Fundamentals tenant setup, but we aren't really utilising most of Google's services, as we will be using Office 365 via SSO, and O365 services via the browser in general use. We have setup the SSO Enterprise app on our Azure portal, and this is successfully working, but we are facing an odd issue, where I cannot sign into Google services via the chrome browser. Signing into the browser itself works, and also going to specific apps also works too, e.g. https://keep.google.com and admin.google.com. Interestingly, this domain did have to go through a reset process with Google Support, as previous employees had setup the domain, but hadn't logged down any domain credentials :-D This experience is on both our Intune setup, my own unmanaged and managed chromebooks. I can only assume we have done something to stop this working, as I have disabled a number of google services, such as Classroom, Gmail, Drive, Docs, Sheets, Slides etc, as we simply won't be using them. Has anyone else tried to do what I am doing and stumbled across any issues? I may try enabling the services again and see what gives! Cheers
-
We are a large secondary school with no Department TAs to do this kind of work...
-
In a normal domain environment I would have setup delprof to run at startup to keep things clean. Doing nice easy scripting seems to be a ton harder on Intune, for very little gain. Would you recommend 256Gb storage as minimum for ease of operation? Our Lenovo 100e units have 64Gb and once all apps etc are installed, we are looking at over 50Gb leaving little space for profiles.
-
In my 20 years of running IT in various schools, I have never had great success running laptop trolleys running Windows. Windows Updates, students not shutting them down properly, use of low end hardware that can barely run Windows, let alone an application are all issues. Even running Intune and setting profile removal after 60% of disk usage doesn't seem to be working due to student profiles being often 1.5-3GB in size. Is 1:1 devices the only solution? Certainly it feels like it, as my own laptop never suffers from these issues. We started by doing Chromebook trolleys at my last school, and they worked great, but my new workplace is entirely Windows based. Is anyone using Chromebooks in a Windows dominated environment? Thoughts please?
-
@robyholmes How are you dealing with Students in this scenario with Azure? Quite a few students don't have suitable devices for use with Microsoft Authenticator, and or we can't easily register them for SMS text auth. We also have conditional access in place to stop MFA being triggered when on-site at the school. In terms of AD, we have AD connect setup for pass-through authentication. A lot of the kit being used by students still has just keyboard entry, so we are stuck with using usernames and passwords, for the time being anyway. Just trying to minimise being swamped by masses of students with password resets anyway. Thanks for any pointers you can give. Regards
-
Thanks, this answered my question perfectly! We have Pupils, Teachers, SLG and Tech admins. All slightly different. Now how to replicate this in Azure AD.... Challenge number 2! Thanks Mark
-
Thanks for this, most helpful. Wasn't even aware you could do this. I'll do some digging tomorrow. Cheers
-
Hi. I am experiencing an odd password policy issue at the new school I am working at. Group Policy on the domain and domain controllers, shows that we currently have the following: I know, I know, this is on the Default Domain policy, which shouldn't be altered, but hey ho. On our O365 tentant we also have our password policy set to match with no expiring passwords. Looking up any user on the on-premise domain, using net user %user% /domain shows that there is no password expiry (Password Expires: Never), however I am getting reports that users cannot login to on-premise systems such as SIMS, and printers. Checking the above, I get the users password expiry, but this doesn't seem to be working correctly. On Azure AD, in the user sign in logs, I am seeing that Windows sign in is showing as interrupted. Looking deeper into the specifc log for the user who has reported the issue, it shows the password has expired. Any ideas? We are running a mixed environment of Intune/Azure AD joined machines and On-premise machines, until Easter, when we will complete the rest of the on-premise stuff over to InTune. I can only think that this is some kind of weird password policy issue on the endpoint from an on-premise legacy setting, as this doesn't seem to add up. Thanks
-
Hi Has anyone managed to install ChromeOS flex to these 100e Gen2 Intel devices? I'm struggling with my AMD CPU version, but ChromeOS supported devices does specifically mention Intel. Got a ton of these, and they would make ideal chromebook devices. Thanks Mark
-
Thanks mrbios, that's exactly what was happening. We did as the instant chat recommended, adding in a large number of O365 URLS into the whitelisting policy and SSL inspection policy. What made the difference was that the issues still continued to happen, until we added in the internal network IP range, and the OMADMCLIENT.exe as URL/IP and Application exceptions respectively. Since then, fresh image builds have worked much quicker, logons happen faster and there are far less glitches. Apps also install more reliably from the Microsoft store too, as well as things like Papercut client and print mapping. I think some of the issues were related to the Delivery Optimisation feature in Windows 10, since Senso 3rd line support identified internal client IP's using the DO firewall port. This then meant we added in the internal IP range to the IP whitelist. Any stuck PC's that I really don't want to re-image, we are simply stopping the senso cloud service, performing a sync, then starting again, then rebooting. Whilst its waiting the updated Senso settings come down. Much happier now I must say with Intune, its not perfect, but far less troublesome! Cheers Mark
-
Hi. I have just moved schools to a new job, and have inherited Smoothwall, Windows 10 Intune devices and Senso. The Intune devices are running the Smoothwall cloud filter and are successfully performing the Secret Knock (I can see this from the Smoothwall Diagnostics for the browser extension). We seem to have some odd issues where Senso is blocking Intune devices from syncing correctly, once the devices have been renamed, and get auto-assigned to a group. I am thinking that this is some kind of policy in place here, but having gone through there support twice now, I can still see the same issue. They have advised that we add a number of exceptions into the mix, and on the second time, added another. These exceptions are added to a web filter policy in Senso. Tbh, I would rather turn off the Senso web filtering completely, as it just seems to be causing issues, but what problems could this give me? We also have sufficient filtering in place with Smoothwall, both on-premise and in the cloud. Diagnosis as follows: Syncing is fine, until devices are renamed, and get auto-assigned in Senso, then we get a dreaded sync could not be initiated error (the error always ends in 194, so I know its Senso). Stopping the Senso service, performing a O365 sync (under Settings, Accounts, Access Work or School) then successfully completes. Subsequent syncs then work fine, even when the Senso service is running however. You can see there are issues occurring, as some apps are not reporting as being installed in O365, even when they are installed correctly. A few days later, the issue seems to return on devices we have had successful Device syncing on, then return the same error. Anyone experiencing the same issue? We are on version 2021.11.15.0 of the Senso client. Thanks
-
Windows 10 Intune Devices, Smoothwall and Policies Applying Inconsistently
_techie_ replied to _techie_'s topic in Windows 10
Thanks both. We've had a smoothwall checkup, and a bit of tidying up has been done. The overall experience is generally working. We are still having "sync could not be initiated" errors on shared devices, that are not assigned to users. Some devices are consistently working whilst syncing, whilst others of the same model are giving us sync could not be initiated. All devices are checking out via smoothwall aside from a few 404 errors to Microsoft sites in the event log which also show up in the smoothwall web filter live reports. These are the same 404 errors between working syncing and non syncing devices The only thing of interest is that whilst the devices support TPM 2.0 in the bios, (Dell 7050 units) my manager had to use the user driven autopilot configuration, even though no user has been assigned in the Autopilot console. Surely we should be using the self deploying profile if the devices support TPM 2.0? Bit of an Azure n00b here, but I'm quickly learning. The machines that are successfully syncing are working great. -
Hi. I have recently moved jobs to a new school, and have inherited a domain that is slowly being moved over to InTune. We seem to be having some odd issues with Smoothwall (which I am very familiar with) and newly imaged InTune devices not picking up certain policies, and giving us issues with the sync not working correctly - often we get Sync could not be initiated when running manually from the settings panel. Is there anything I need to look out for with regards to setting up Smoothwall to allow InTune to work in its most optimal way? Thanks
-
The user has the licences enabled, but they are greyed out ticks. I can't undo this, or revoke licences. The seem to be 'stuck' like this. Feels like a bug this. I can't yet delete the account either, since it's being used as part of a transition to a new SENDCO.
-
Hi. I have just joined a new school. The school are using Azure AD Connect. AD groups are mapped to O365 matching groups. We have O365 licensing mapped to licenses based on user groups. I have a user who has left, and their account has been removed from the AD Groups. I can see the change is reflected in Azure, as said user is also not part of the groups in either location. I am trying to free up some licenses, but I am unable to remove licensing from said user, even though they don't exist in the groups. What am I missing? Thanks Mark
-
I don’t see the point of this… if your using office in the browser, you might as well use Google Docs. Only way I would achieve this if your using the chromebooks as RD/WaaS thin clients, something I can understand. I’m using standard ADFS on prem as the sign in page for our chromebooks in native mode, and it works well. Let me know if you need any IdP/SdP help.
-
In the office config generator, are you enabling the setting: “Allow the token to roam” or not, and where are you placing the tokens in the UNC/http path? Regards Mark
-
How are you dealing with shared versions of office 365 in terms of licensing. I’ve been pretty happy with the std versions and licensing via KMS. I know you can deploy in shared mode, but how well does this work in practice if staff are moving around site, covering lessons and just going about their normal business… logging into multiple machines (this happens at our place, a lot).
-
Secondary… we are looking at some new desktop PCs for teaching staff unfortunately the next 5 years to ease the transition. Also trying to get staff to appreciate the benefits of Google docs and drive…
