_techie_
Members-
Posts
434 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by _techie_
-
Is it worth using Edu 21H1 with feature updates coming in via WSUS? We have used LTSB/C since our rollout back in 2018, so no feature updates, security and critical updates only. Operating in this method, has seen excellent stability for the past few years, so I'm loathed to move to rolling out feature updates, as reading on here, the feature updates seem to give lots of issues. We seem to be moving towards becoming a Google infrastructure school utilising Google classroom, meet, drive, chat etc. I don't think Chromebooks are quite ready for teachers to use just yet, plus we still need to host legacy software whilst we assist teachers with the transition. What does everyone think? Cheers Mark
-
Hi. My network manager came into the office this afternoon, to deliver some good news that we will be getting some funds for replacment PC's for teacing staff. We had recently looked at Chromebooks for staff to use, along with our Citrix system to access SIMS.Net and files whilst we transition to a cloud ready future, but a recent trial didn't work out quite as planned, and we now need time to move away from SIMS.Net to another MIS. With this in mind, we initially went down the route of doing a direct replacement of existing kit. We currently run Chromebooks for students across the site (we are a Google Classroom school you see). Driving home, I was thinking that signifiicant savings could be made on replacement kit, by just going down the Azure managed device route for Staff and reducing the endpoint count down. I recently did a trial of this myself using a Windows 10 Azure managed device setup using autopilot, but the experience left a little to be desired, as well as significant delay between the device checking in with Azure... I also didn't really get round to use Sharepoint, or OneDrive as I was the only one using it. I also experienced quite a few bitlocker startup issues, which caused some grief... We currently run fixed desktop PC's on an on-premise domain, but this does increase the PC count and thus cost as well, however we do have good reliability. We also need to provide some breathing room for the next 3-5 years whilst we undertake some other projects, like moving Staff mailboxes to Exchange Online, putting in some new servers and replace SIMS.Net (some big ones here!). We are also only running O365 A1 for faculty, which means staff don't actually have full Office M365 that can be installed on your their individual PC's so some additional costs there to do this. I'm also not a massive fan of OneDrive having experienced significant issues with file length path issues having assisted some friends in the past with this. Has anyone transitioned from the more old-fashioned Windows network, to a new cloud ready MS future for Staff using Azure/Endpoint Manager? What benefits did you experience and what drawbacks/issues did you have to overcome. Thanks _techie_
-
[ms office - 2019] Office 2019 Updates Location
_techie_ replied to _techie_'s topic in Office Software
Hmm I'll keep going then trying to get this to work. Would rather use the CDN as you say. How do you identify out of date machines, or troubleshoot them, since you can no longer deploy Office updates via WSUS? I can probably run a scan on the office version using PDQ Inventory at a guess? Cheers Mark -
Hi. I'm currently doing our Office 2019 Update for this summer from Office 2016. We are mainly Windows 10 LTSC 2019, and Server 2019 for RDS/RAS How do you deal with updates? I have currently set my install config.xml file to get the updates from a network share. How do you populate this UNC path location with updates? On this page: https://docs.microsoft.com/en-us/dep...ice2019/update It seems you still need a device which has access to the CDN, which is fine, but where are the updates located? How do I populate the updates UNC path. All very unclear! I would ideally like to just use the CDN, but this seems unlikely at present, as we are using Smoothwall with proxy for users, on Windows 10. Some pointers would be appreciated! Regards Mark
-
Hi. I'm currently doing our Office 2019 Update for this summer from Office 2016. We are mainly Windows 10 LTSC 2019, and Server 2019 for RDS/RAS I am trying to understand the activation (we have a KMS host setup for Office 2019) process around RDS, and whether I need to use User based activation, Device or Shared, as this seems unclear. Also how do you deal with updates? I have currently set my install config.xml file to get the updates from a network share. How do you populate this area with updates? On this page, it seems you still need a computer able to access the CDN to obtain the updates, which is fine. However where are the updates stored? On this page: https://docs.microsoft.com/en-us/deployoffice/office2019/update It seems you still need a device which has access to the CDN, which is fine, but where are the updates located? How do I populate the updates UNC path. All very unclear! I would ideally like to just use the CDN, but this seems unlikely at present, as we are using Smoothwall with proxy for users, on Windows 10. Some pointers would be appreciated! Regards Mark
-
Hi. I have one user who has a number of shared mailboxes setup. They are using Outlook 2016 on Windows 10 - Cached Mode is on, in Outlook 2016. When sending email on behalf of the shared mailbox, the user also gets a copy in their personal sent items mailbox, which they would like to not happen. I have enabled in powershell: MessageCopyForSentAsEnabled = True MessageCopyForSendOnBehalfEnabled = True These are giving the desired effect of keeping a copy of the sent item in the shared mailbox, however a copy is always sent to the users personal mailbox too, which I would like to avoid. Any way to do this? Cheers Mark
-
For anyones reference, I sorted this by using the following: --disable-toast-notifications on the login script, whilst removing --disable-balloon-tips This allowed basic pop ups in the systray area, without needing access to the notifications pane. Cheers Mark
- 1 reply
-
- 1
-
-
Hi. We recently did an in place update through our print support vendor, to PC v20. It was reported recently that students weren't getting notifications from PC for hold release queue jobs. We are running the following: Server 2016 Print Server Win10 LTSC 2019 Clients Zero Papercut client deployment from PCClient share. I can replicate this and originally put this down to me blocking the notification area for students. However re-enabling still shows no notifications for PC. If I send a manual notification from PC admin console, that doesn't make any difference either. Running as a domain admin with no user GPOs applying allows some notifications to work, but I don't get the papercut logo, or the actual message, just a pc-toast notify notification to show in the notification area. Sending a manual notification from PC admin results in the same pc toast notification with no message. Doing the same on a workstation with no Computer GPOs applying results in the same. The The solution ATM is to run the local cache version but trying to deploy this using the same gpo method (system...logon...run these programs at login) caused logon to slow to around 2, 2.5 mins from a normal 20 seconds. How are people deploying the local cache version? Any suggestions welcome, bit odd this one. Cheers Mark
-
2nd for Mosyle. It's fine so long as you get your MDM APNS through your firewall. It works for about £3 a device.
-
Blue Screen Day - Office 2016 and Printing related
_techie_ replied to _techie_'s topic in Windows 10
It was kb5000822 for us. Removing via script seems to have killed most of it, let's hope tomorrow is more stable. -
Blue Screen Day - Office 2016 and Printing related
_techie_ replied to _techie_'s topic in Windows 10
Hi. Thats interesting, as I don't have those updates installed, but we are using Kyocera printers! I'll update as I know more. Cheers -
Blue Screen Day - Office 2016 and Printing related Anyone else experiencing freezing surrounding printing and office 2016 today? Mine is occuring at random but the tie in seems to be surrounding printing and office! Hope I'm not alone. Thanks Mark
-
LTSB/LTSC support lifecycle cut to 5yrs for 21H2 release & later
_techie_ replied to computer_expert's topic in Windows 10
I'm with Michael on this one. It was a tough decision at the time, but a few things put me off the SAC rollout - September being the main one, as its when I'm at my most busiest! Having a feature update in the first 6 weeks that causes chaos is not going to go down well with SLT! I know you can defer updates, but I want stability, not features! Its an OS for god sake, features come in apps. I've been using LTSB and LTSC since we rolled out Windows 10 around 4 years ago with excellent stability and familiarity for users. Our users have asked for a Metro/Windows Store App once, and I pointed them in the direction of Google Keep (as we are a G-Suite School). Since we are also using XenApp on Server 2019, the alignment between LTSC 2019 (1809) and Server 2019 seemed to make perfect sense to me. We are a highly shared PC school, so making use of Office 365 is just not happening (even with their shared PC rollout). I'm also using Visual Studio without issue on LTSC. Education 2004 and 20H2 seem to have removed a lot of the crap that came with the earlier versions (as I'm typing this on a Win10 Edu 20H2) laptop, so its looking better and better. However I feel the direction of the industry is push a 1:1 device setup, and with this in mind, Chromebooks do seem to fulfil a large number of departments (apart from Computing and Design Technology). The only issue I have had is with Zoom on a specific model of PC (very old - 10 years old) and on LTSB. Luckily this only affected one user, so the time came to update their PC! I am looking forward to see how LTSC 2021 and Office 2022 shape up, but 5 years does seem fine for a longer term channel OS. I am probably looking at updating our last few 1607 PC's this year, as those users will probably have updated hardware at the same time. :-) -
Interesting reading this thread, as I'm contemplating how shared computer suites would work on InTune! InTune from my point of view is really made for 1:1 rollouts. GPO and shared computer suites go hand in hand at the moment, especially if they are desktops! Be interested to hear people's thoughts on this
-
Hi. Odd issue here with using ADFS 3.0 and students using their own Windows laptops. We have Forms Authentication only for Extranet Sites, and WIA and Forms for internal use, yet the ADFS Site seems to think that students on Windows devices outside the domain are trying to use WIA? If I disable WIA for internal use this fixes the issue externally, but then my SSO breaks on internal Domain PC's! Whilst I can advise students/staff to enter the full email address, in the WIA prompt, its odd this is happening. What am I missing? Cheers
-
got a link to it?
-
Agreed! Have to say, Im impressed so far with the bang for your buck with the Unifi/Ubiquiti system. My only gripe is that the update process for the controller is a bit rubbish, as it installs by default, into the user profile. Is there a way around this using command line/powershell? Cheers.
-
hi. I'm using unifi with smoothwall captive portal on an open SSID. I've heard mixed things from some of 6th form students on the grapevine that it doesn't work even though I can't replicate any issues with my Pixel 3a phone on A11. I've seen that on certain phones it can take a reboot of the phone for the captive portal to come up even though the phone has received a correct IP address. Smoothwall reports logs of 0 in the web filter, and diagnosis of the device shows HTTPS sites not being displayed, only cert errors. This ties in with the fact the user hasn't had yet to authenticate, due to the captive portal not appearing in normal process. I'm not pushing the HTTPS inspection cert, and have a transparent auth policy setup for the subnet on smoothwall. Am I missing something? Do I need to tweak a setting? Laptops seem way more flakey with the captive portal appearing (Chromebooks esp) but it's not really being used in lessons, just for 6th form BYOD devices for free study use. I'm trying to decide whether to ditch the captive portal altogether, and provide Radius access via MSCHAPv2, which isn't particularly secure if there certificates aren't up to date. Suggestions please?
-
Tempt me to move to MS Config Endpoint Manager
_techie_ replied to _techie_'s topic in Enterprise Software
Right now and even in the next 5 years, I just can't see us moving to O365 fully with Intune. The only reason we have a domain right now is due to SIMS.Net, and I've been in impromptu meeting where a possible replacement is being discussed, most likely web based. This really does put the onus on what devices could be used on teachers desks. Student devices will most likely be Chromebooks, as we are using Google classroom, plus a load of other web based learning platforms such as Kerboodle, mathswatch, GCSEPod, etc. The use of windows computers will seriously decline to specialist STEM subjects like Computing DT etc. A level students may also be in a position where they will be using their own devices as the variety of the work and small class sizes, will not require full-size computer suites. Even science only use basic apps, such as excel, which could be replaced with similar tools. The science block currently have Chromebooks setup as Citrix thin clients. I'm not currently utilising MDT, just plain old WDS. GPO for settings and PDQ for app deployment and inventory. Hands down it just works simply, and with PDQ D and I at £700 a year for the Enterprise license for package library, it's a real time saver. I guess I'm possibly trying to fix something that's not broken.... -
Tempt me to move to MS Config Endpoint Manager
_techie_ replied to _techie_'s topic in Enterprise Software
Hmmm don't think I'll bother to be honest. Stick to my KISS model. -
Tempt me to move to MS Config Endpoint Manager
_techie_ replied to _techie_'s topic in Enterprise Software
There are a few things: Rolling out latest drivers as part of a step by step process rather than having drivers in an image go out of date and having to recapture an entire image just to update drivers. Just had our MS Licensing model reviewed and I'm trying to get the number of VMs down. By integrating 2 VMs together (WSUS and WDS) and introducing MCEM I was possibly looking at going down the Win10 Edu route rather than LTSC so wanted better overall visibility of machines being on a specific version. Apparently MCEM can also do reporting on client application usage, something that would be a great benefit going forward. Is this possible/feasible? Also seems a way to keep an eye on InTune managed devices as well as on-prem. Something I learned in a Microsoft training demo this week. PDQ Deploy/Inventory still and amazing product set IMO. Would be hard pushed to go to something else even if you can do this on MCEM. Thoughts feedback on please? -
Tempt me to move to MS Config Endpoint Manager
_techie_ replied to _techie_'s topic in Enterprise Software
Can I ask what/how your backing up Exchange mailboxes? Veeam o365 V2 was a bit painful with some difficult power shell commands, but it's on v5 now so might take another look. -
Have a look at NtLite can make a custom image including drivers, apps and whatever else you want from a wim, then turn into an ISO. Use RUFUS to make bootable ISO on pen drive and go rouND each machine. Job done.
-
Oh and standard edition on 2016 supports IP ranges, I have this confirmed and working.
