Jump to content

mjhardisty

Members
  • Posts

    150
  • Joined

  • Last visited

Everything posted by mjhardisty

  1. What about Automatic Enrolment in Intune over Autopilot? This will at least enable you to get devices onto MDM - it doesn't give the full capability of autopiloted devices, but means they can be used and managed? https://learn.microsoft.com/en-us/mem/intune/enrollment/quickstart-setup-auto-enrollment
  2. First sign-ins will usually take some time to build a local profile. I think the GPO you need is https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.WindowsLogon::EnableFirstLogonAnimation
  3. Educators and students can only use the multiplayer feature within their O365 EDU tenant, which means students can only collaborate with other students from the same tenant. https://edusupport.minecraft.net/hc/en-us/articles/360047117692-FAQ-Game-Features#:~:text=Can%20I%20play%20multiplayer%20with%20users%20on%20other%20Office%20365,students%20from%20the%20same%20tenant.
  4. Not sure whether Visual Studio Code for Education enabled Java - but worth a look: https://visualstudio.microsoft.com/vscode-edu/
  5. I would presume the User policies would apply to all devices by default, so maybe adding this exclusion might work. Worth a try to understand the behaviour.
  6. https://www.tbone.se/2023/01/27/filter-out-devices-based-on-join-type-in-intune/ Would that work to exclude devices in policies that are Hybrid Joined?
  7. Because of the synchronisation delay I've chosen to have policies based upon devices rather than users.
  8. Are the on-site devices appearing in Intune too?
  9. Fair play to Microsoft. Gives schools some wiggle room I suppose. Even the last non-Windows 11 compliant device will be 8 years old by the end of the ESU period so they should be replaced.
  10. Feature update should be the Intune policy to use to force OSes to specific versions: https://learn.microsoft.com/en-us/mem/intune/protect/windows-10-feature-updates Whether this deploys quickly enough though is another matter ...
  11. Still listed in the support doc: https://support.microsoft.com/en-us/office/meeting-options-in-microsoft-teams-53261366-dbd5-45f9-aae9-a70e6354f88e
  12. Admin > Teams > Messaging > Messaging Policies ? Unless in an actual Teams meeting/class - then it should be supervised chats? https://learn.microsoft.com/en-us/microsoftteams/supervise-chats-edu
  13. Could it potentially be a display driver issue? If you log onto the PC in question can you change the theme and have it apply correctly?
  14. Whether this is accurate: https://cefm.co.uk/licensing/school/#:~:text=A%20PRS%20for%20Music%20Licence,music%20composers%2C%20songwriters%20and%20publishers.
  15. Good evening! As suggested I would investigate URL rewriting to exclude YouTube and other videos from search results with the -site option. Alternative is to force the users to access another search engine without video results.
  16. What about Sumo Digital's Academy:https://www.sumo-academy.com/ Or a Playstation development lab: https://www.prolificnorth.co.uk/news/sheffield-hallam-opens-worlds-largest-playstation-teaching-lab/ Or Maker Space: https://www.salford.ac.uk/our-facilities/maker-space
  17. I would evaluate as @MYK-IT has recommended what elements of the A5 you need. The cost is quite considerable for features that will never be used. Options are Defender for Office 365 https://m365maps.com/files/Microsoft-Defender-for-Office-365.htm - that gives security elements outside of the A5 security package. These could be purchased for staff that need the protection and do come with student-use benefit. To move to InTune you can add EMS.
  18. I would stick to Microsoft's recommendation of running Windows 10 22H2 until you can replace with Windows 11 compliant hardware.
  19. Don't think I've ever found a way to speed up the first login time problem where Windows builds the user's local profile, AppX's, registry, etc. I don't think it's a problem if staff appreciate that, and subsequent logins on the same machine are acceptable. I agree with @Chris_Cook to investigate why profiles are growing that machines are filling and profiles need deleting. Implement a policy to delete inactive profiles, but with 120-240gb drives there should be enough space for a lot of users depending on your app deployments, use of OneDrive Files-on-Demand, etc.
  20. Magnus Church of England Academy, an Academy within the Diocese of Southwell and Nottingham Multi Academy Trust, is seeking to appoint a Junior IT Engineer. https://www.tes.com/jobs/vacancy/junior-it-engineer-nottinghamshire-1898008
  21. It would be worth evaluating whether additional defender protection is required for students, given the device restrictions. You could look at Enterprise and Mobility which might give better value for money than a full A3. EMS gives the required InTune licencing: https://m365maps.com/files/EMS-E3.htm I think student-use benefit is 1:15 for these. You'll need to retain EES for your on-prem server/user CALS for your hybrid environment.
  22. A good debate here. Obviously there are many ways to skin a cat - the quickest way as mentioned is to have new machines pre-registered by the OEM (Dell, etc) with your Intune config and set with a specific Group Tag so they are automatically assigned policies. Use the Group Tag to have dynamic Azure AD device groups that are then ready to go. Switch them on and away you go. For ad-hoc machines, then either export to CSV ... or just use the USB at OOBE to capture the information. I think it's as quick as PXE-ing a machine in SCCM! Once a machine is into Intune the management should be easier. The last post about Fresh Start, etc, should give huge advantages on summer re-imaging work - just hit the button and the machine *should* rebuild itself from new.
  23. Whats the justification for moving to A3? Are you a fully-cloud school? If not then you'll need to consider hybrid licencing for your on-prem services too. https://m365maps.com/ gives you a breakdown of everything in A3 - EndPoint is included in the licence.
  24. I've experienced user sign-in errors with local profiles primarily when the machine has run out of disk space. Obviously the size of local profiles varies depending on what you enable. Big killers of space I've noticed are OneDrive caching and Adobe CC too. Machines with 128GB will fill up quickly. Nothing needs to be done to be configured, just leave profile path blank in AD and the machine should use local %appdata% usually in c:\users.
×
×
  • Create New...