Jump to content

Ironside

Members
  • Posts

    167
  • Joined

  • Last visited

Everything posted by Ironside

  1. Hi all, desperately hoping someone can help here. We have configuration profiles in Intune that use the Printer Provisioning configuration setting to apply printers to the PCs in our ICT suites. When you access the policy in Intune and go to the Report, where you can see the profile's applications and whether it Succeeded, Error or was in In Progress, we're getting a lot of cases where the printer is either listed as In Progress (when in reality, often it successfully installed the printer), or Error. This policy applies every time someone logs into the PC, and instead of either working every time, which is what we want, or never working (which means that there's something wrong with the config, and we can diagnose that and fix it), it's only working half the time. It's infuriating - we have no idea why it's not working. Event viewer has many errors pinging but doesn't seem to actually explain why things aren't working. The error code we're getting is "500", Error type "1". I cannot find any actual explanation for this error code in Intune documentation - the listed page for error codes contains a bunch of codes that start with -2016, and no code for 500. I'm at my wit's end, the documentation doesn't help, and I don't know what to do. We've tried different universal print connector software, different printers, reimaging the PC off of a USB to ensure it's fresh Windows 11 Enterprise, and can't find any consistency.
  2. Ok, my manager has made a lot of progress here and got the extension working, and things are going to the cloud filter now, properly, but a lot of ip addresses are being seen in the usernames rather than the username - is that standard when URLs are being accessed that aren't blocked or allowed by any categories?
  3. We've hammered out a issue with our ps1 script that was putting the wrong license and tenancy number as a reg key. We now have the correct cloud filter block page, but now the cloud filter is failing to group users properly. Even though we have our Azure AD directory set up and with groups to assign the user as Staff, but it's registering the user as Default User. In the Smoothwall Diagnostics, it's listing "Tenant" as "Unrecognised id (my_workplace's_actual_azure_tenancy)". Does the cloud filter pull the tenancy that the Azure AD user logged into on the PC, or is this caused by incorrect settings in the powershell script not being overwritten after we fixed the script? We originally thought the tenancy needed to be our Azure AD, not the Smoothwall tenancy. Is there a way to purge the registry keys and redo them with a powershell script?
  4. So some traffic is authenticating itself as the user without being prompted, but some traffic is remaining listed as an IP in the web filter logs. The cloud filter extension is reporting "Provisioning failed: No response from native client." but the configuration seems right on the script. The real concern is that authentication is inconsistent and sometimes resulting in teachers getting treat as staff, and student traffic getting listed on ip addresses rather than usernames. Is there meant to be a difference between on-prem block page and cloud filter block page? We haven't noticed a difference before so I'm guessing the on-prem is still in place. We're in a transition from all on-prem, MECM pxe booting and group policy managing our PCs towards autopilot and Intune managing our PCs. We just want to ensure that our Intune pcs still authenticate the users the same as our on-prem pcs.
  5. That's the browser extension, yes? The extension is being installed by intune, and we have a Smoothwall Unified Client that is supposed to install itself to the PC, and Intune reports it is installing, but I can't see any actual software running in the system tray, so I'm not sure what I'm supposed to be looking for?
  6. Hi all, We are steadily moving towards Intuning our PCs - however, some of our staff when trying to browse are getting treat as Students. Looking in the web filter logs, it says the username is the PC's ip address, which indicates that this PC isn't getting authenticated. Now, if they go to something that students can't access, they get prompted to sign in, and can sign in with their credentials (their username and password as stored on local AD, not email and password as per Intune/M365), which is a solution, but i'd rather try to understand how to get Intune logins to naturally authenticate as themselves. We have a directory setup for use with Azure AD, but also have our previous directory set up with Local AD - do we have to change the order of our directories so the Azure AD one is above the IDex directory or our Local AD directory?
  7. Wait, do you want to ban students from typing messages in teams? You can set up policies for different user groups in Teams admin center.
  8. Hi All Windows 11 Pro 23H2, OS Build 22631.3880. When I print to Print to PDF printer through the Photos app or Snipping tool app, it won't work. Event viewer generates this error log: Faulting application name: SnippingTool.exe, version: 11.2502.18.0, time stamp: 0x67c605f3 Faulting module name: WINSPOOL.DRV, version: 10.0.22621.3810, time stamp: 0x56f7c354 Exception code: 0xc0000409 Fault offset: 0x0000000000026596 Faulting process id: 0x0xBEF4 Faulting application start time: 0x0x1DBB9E2C1FBB380 Faulting application path: C:\Program Files\WindowsApps\Microsoft.ScreenSketch_11.2502.18.0_x64__8wekyb3d8bbwe\SnippingTool\SnippingTool.exe Faulting module path: C:\Windows\SYSTEM32\WINSPOOL.DRV Report Id: 74a5eaef-3a37-47d7-ac33-c280d03efcb5 Faulting package full name: Microsoft.ScreenSketch_11.2502.18.0_x64__8wekyb3d8bbwe Faulting package-relative application ID: App I've tried a few different things: sfc /scannow net stop pooler > dism /Online /Disable-Feature /FeatureName:"Printing-PrintToPDFServices-Features" /NoRestart > dism /Online /Enable-Feature /FeatureName:"Printing-PrintToPDFServices-Features" /NoRestart > net start spooler Uninstall and reinstalled the windows feature that adds Microsoft Print to PDF. This is plaguing quite a few users at my work, so any advice appreciated!
  9. Sorry but I have to agree with someone up the thread - TES, the people responsible for making (not letting, making) parents see classcharts info for kids who A: aren't theirs and B: not even at the same kid, shouldn't be trusted with school data to the extent of an MIS. While I will back down on this if a more-informed or more GDPR savvy person comes in, I don't believe TES ever faced consequences for that breach that should've seen more serious consequences than it actually did if my mmeory serves. Thread link for those unfamiliar: ClassCharts GDPR security issue - MIS Systems - EduGeek.net
  10. This was fixed by reinstalling the software on affected PCs.
  11. Smash the motherboard with a hammer? Just a eMMC soldered on isn't it?
  12. I don't know what to do about it honestly. Hoping someone has a solution.
  13. So my windows settings have no proxy address set and that matches my Surpass proxy I've got all the WJEC and Surpass web addresses chunked into our Authentication exceptions category from Smoothwall. SQL Server Compact 4 is installed. Internet access is all good on the PC. I'm now getting the following error: "Invalid Keycode: Unknown error" Any idea? I am getting an "unhandled exception occurred in your application. If you click Continue, the application will ignore this error and attempt to continue. IF you click quit, the Application will close immediately." Any suggestions? - - - Updated - - - How has this become industry-standard?
  14. Hi all, I have a mock exam in about 2 and a bit hours and am getting this error: Invalid Keycode: OFFLINE - There was an error validating the keycode. Any ideas? Don't seem to have any access to FAQ or anything for this. WJEC Secure Client if that's relevant?
  15. Just want to say to anyone making last minute panicked setups for mock exams - WJEC Secure Client is NOT updating to 25.01, they canceled that and the current latest version is still 24.03.090.033.
  16. Update: As it turns out, there was a USB ban in place in Impero that was preventing kids from using USBs. If you're having a similar issue to me, check if Impero still has policies applied to user groups in the siderbar on the left.
  17. Hello all.Just a word of advice for anyone doing the Group Policy method who is inexperienced (read - me) - the reg keys are not intuitive in the original email. Here's what you need to do: Make a group policy In Group Policy Management Editor go to User Config, Preferences, Windows Settings, Registry. Right click > New > Registry Item. Leave action as Updat Using HKCU\Software\Microsoft\input\Settings\EnableHwkbTextPrediction For Hive, select HKEY_CURRENT_USER. This is what the email means by HKCU. Put in the Key Path as the provide reg key, minus the last section The Value name is the last bit, so EnableHwkbTextPrediction Set value type to REG_DWORD and Value Data to 0 (if set to hexadecimal you can either do 00000000 or swap the base to Decimal and put in 0) I fought with this little thing for a while before realising my mistake in including HKCU and \EnableHwkbTextPrediction in the keypath!
  18. A v. good suggestion but only for cases where the policy applies via Computer Configuration - we're blocking for users in certain OUs and the policy is a User Configuration setting, so this, while a valid solution for computer configuration, didn't quite fit my use case. Another good answer but it's not quite how I wanted to do it cause the USB block group policy applies to users not computers to allow certain users access. (Also I just really didn't want to re-jig the OUs or the policy if I could help it!) Yup, this did the trick! Cheers - this fills a major gap of my understanding of how group policy works!
  19. Hi all. We have a policy in place to block removable storage access - no USB pen drives for kids or staff. This policy is linked to various OUs containing users, and works via User Configuration. Unfortunately, PE-DESIGN comes with a physical license USB which reads as a storage device. We need to get one PC to override the USB Block policy. The problem is the USB Block works via User Configuration and is linked at the User OU. How exactly does this interact with a Group Policy that applies Computer Management policies? If you have "Removable Disks: Deny read access" enabled for the user configuration policy, but Disabled via a Computer Configuration, which takes priority/overwrites the other? How do I get my USB unblock to override a USB Block applied to User IYIt has to be on a specific PC - is there a method to do it with Security Filtering down to specific computers? I have tried using Computer Configuration > System > Removable Storage Access policies with the policy still linking to the User OU, but this didn't work because the USB access was not denied. I have tried using User Configuration policies in my USB Unblock policy which is linked to the Computer OU of the one PC I need to unblock USBs for, but the USB block policy still applied and overrode my Unblock - or the Unblock just didn't apply at all. Honestly, not sure. Anyone else had to work with something like this? (I know a technicalyl valid solution is to rewrite the USB Block policy to link to computers and apply Computer configuration, but this has been bugging me for so long that I want to know a better solution that lets me overwrite User Configuration policies on specific computers, rather than rework the block policy to not apply by User at all.
  20. "Unfortunately, the support team do not have a direct way of passing such items to product" lmao what
  21. If there's any truth to this it should be fought in the court of law on a case by case basis, not shouted on Edugeek in a mudslinging war. Weapons grade sour grapes.
  22. You should be able to do Teams Assignments with regular windows PCs and teams?
  23. Sorry mate I can't think of a way to do what you've asked, but this might be helpful in general. So I've only ever done this for a exam account and it's not going to be as easy as teachers just grabbing files, but if you have the time capacity to take over this from teaching staff, you can: Go to M365 Admin Center, then Sharepoint Admin Click More Features (sidebar, left) Go to User Profiles You're now in Old Sharepoint. Go to "Manage User Profiles" Type in the username of the profile you need to pull files from into the Find Profiles search box Click the listed user, then click "Manage Personal Site". You'll be brought to the user's Onedrive. There is a in theory easier way - go to M365 admin center, click More Features, go to Users, type in the users naem, then click that name, click OneDrive on the fly-in panel on the right and then create an access link to onedrive - but this never used to work for me.
  24. even if Qualcomm manages to put something together that can even get close to Apple Silicon, they still have to rely on Windows and Microsoft to A: Make windows on arm good, and B: make windows on ARM a ecosystem that works. Windows RT, and Windows Phone, and Windows UWP Apps, Windows Subsystem for Androids upcoming closure and Windows Store all indicate quite thoroughly that Microsoft are fundamentally incompetent at making third party app developers confident in their ecosystems. I expect Apple to maintain a hold over ARM pcs and in turn the PC/mobile device industry for a long time.
×
×
  • Create New...