Jump to content

itskdog

Members
  • Posts

    375
  • Joined

  • Last visited

Everything posted by itskdog

  1. Yeah, we ran into that with printing large numbers of photos from File Explorer - after lots of back and forth with PaperCut, the (so far only tested on my PC, going to test with others over the next couple of weeks before half term if I can) fix is to enable Protected Print Mode so it installs the printer using Windows inbox drivers rather than PaperCut's drivers or the OEM drivers. Currently everyone's working around by doing print-to-PDF then printing that PDF. I would expect that for most schools the UPN and username will match, only in staff who work across a MAT where they might have aliases at each school might they have a bit of difficulty, but Mobility Print should assign the job to the user who signs in to Print Deploy, so as long as the auto-signin works in the default browser, then it should connect fine. If the user has two unconnected accounts in the same tenant, then you could configure it to let each of those UPNs release print jobs from the other UPNs that belong to that user and have a shared account as their personal quota rather than the user's normal quota.
  2. If printing is the only service that doesn't have a SaaS equivalent, look into if your MFDs support PaperCut Hive (and that the current features are enough for your needs - individual user quotas have been added, but shared accounts aren't available yet). If you still need NG/MF, then it can integrate with Entra without having the server be Entra joined, you just create a custom application in Entra to sync users, and configure the PaperCut web UI to run on HTTPS to that they can log in to check their balance. Docs: Synchronize user and group details with standard Entra ID | PaperCut The built-in Print Deploy client lets you push out the printers to the users via Mobility Print, they just have a single click "Sign in with Microsoft" on login to install the printers to their PC as long as Edge SSO is enabled. (No idea why it doesn't just use Entra's SSO for zero-touch login like Cloud Drive Mapper does, 🤷‍♂️)
  3. That's where find-me queues and secure print release come in. They can enter their username & password at the MFD (or if you're on NG, on a Release Station you put next to the printer) and collect their job, and it could be collected at any printer on the network, not just a single printer (useful if one breaks down for any reason)
  4. Google Cloud Directory is available as a secondary sync source into PaperCut, so perhaps the student Google accounts could be added that way? Not a Google school so don't have much experience there myself, though.
  5. We just redeployed in the summer as part of a move to Intune from AD (hopefully retiring our on-site server either in the summer hols or at the end of the year when our Impero support ends and we see if Senso Network Cloud has improved by then to add onto our free Safeguard Cloud through LGfL, as I've always been nervous of the complaints here around reliability), initially just using USB sticks with vanilla Windows + Drivers per RM's standard practices (they managed the project for us and configured baseline policies), but I'm looking into OSDCloud for future deployments to clear out HP's bloat without paying the extra fees to get Corporate-Ready images. I think devices (especially business-grade ones) will be coming with both the old and new certs for a little bit yet, and it would probably just need an ADK/WinPE update to get the new bootmgr once that changes.
  6. This is expected - the Default DB in the UEFI is, as the name suggests, a default for when you factory reset the secure boot or UEFI settings in the UEFI setup, or the CMOS is cleared. The UEFI updates are still important, as they may fix issues that prevent Windows from installing the updates to the Active DB. Only Microsoft have the authority to update the Active DB, which is where these updates come in. Currently, I have enabled the Microsoft Managed Opt-in policy, to get behaviour similar to personal devices through Microsoft's Controlled Feature Rollout, to have a slow rollout across our estate, but depending on how many devices end up completing the update (I have some detection scripts in Intune to tide me over until the report is released to show the device status) I may finish by enabling the policy that pushes out the certs to the UEFI immediately to ensure devices remain secure.
  7. Just a reminder that Meraki MDM is being retired in a few years, ICYMI. FAQ: Meraki Systems Manager (SM) End-of-Sale - Cisco Meraki Documentation
  8. Google are missing a trick with Premium being restricted to personal accounts only, and not offering it as a Workspace addon. Not sure whether the Ad Blocking category in SchoolProtect/Netsweeper would block it, but given YouTube have anti-adblock warnings now, it's a little iffy (though given they use the same EasyList filter that all the browser extensions use as the basis for that category, that at least should be updated frequently, though whether it's frequently enough is another question).
  9. When I came in, our MSP (who still does our annual asset audit and serves as 2nd-line IT support on a remote-only contract) was already using Parago (now Civica EdOps) before we had in-house IT, and we still use it today. Their public roadmap on their ideas portal shows that they're doing an overhaul of the UI soon to match other Civica products, followed by a refresh of the Helpdesk feature to fix the various issues reported by users. My only complaint is that they recently redid the mobile app, and it's now really slow to load anything - it used to be a native app that cached everything locally for you to upload later (so you're not relying on signal everywhere in the building), now it feels like it's web-based and the asset list either doesn't load or takes an age to do so. EdOps also serves as a full premises management system, so can also be used by the site team for tracking contracts and compliance checks, and assets can have attachments on them, so I've started uploading scans of loan agreements in case the paper copy ever gets lost.
  10. If you've used Apple devices e.g. iPads, you may be familiar with Apple School Manager, which automatically enrols the device into your MDM solution during first-time setup. Autopilot is the Windows equivalent, it ensures the device is registered as a Corporate device rather than a Personal one, and then it just enrols to Intune and configures everything automagically with minimal interaction from the technician or user, plus if (for example) an enterprising child were to figure out a way to reset their 1:1 device to try and dodge the filtering and monitoring solution you've installed, it just comes back on its own into your control. With self-deploying mode, you can even make it as simple as "Connect to the network and leave it alone to set everything up", too.
  11. I'd heard vaguely about this, but only with mention of CBBC providing better quality children's content on the platform. Interesting that it says a TV licence won't be needed, as well as no ads. Interested to see how that will get funded.
  12. Microsoft have a built-in migration tool available from the SharePoint Admin Centre. As a bonus it can also migrate your file shares to SharePoint sites. Migrate file shares to SharePoint and OneDrive - Migrate to Microsoft 365 | Microsoft Learn
  13. When I made an OSDCloud USB stick and put it into one of those machines, it gave me some sort of error relating to the low amount of RAM. It's been a few months and I've wiped the stick since then, so I can't remember off of the top of my head now.
  14. When doing the initial transition over to Intune from AD, we used a USB stick with a copy of Windows 11 and a provisioning package from Windows Configuration Designer to enrol to Entra, which (through Automatic Enrolment) then automatically put the device into Intune - no need to collect hardware hashes (though you will just need to leave them connected to the network for a few hours to ensure all the policies and apps are picked up, there's no ESP with this method) You could probably do similar with MDT to deploy a clean image to OOBE as above and then once each one has had the initial deployment, just walk around the building with the USB and just put it in each PC one-by-one. You can use a dynamic security group in Entra to set policies based on the device name you picked during MDT, or have the PPKG change the device name during OOBE. (e.g. one naming scheme for student devices and another for staff devices)
  15. If you want something you can load onto a USB stick, I personally use this tool: https://github.com/rbalsleyMSFT/FFU You can build a custom, clean Windows image with the latest Cumulative Update and have Office/OneDrive/Teams up-to-date, plus other apps if you need them (I leave that to Autopilot/Intune, though). Drivers are injected by just loading them onto the USB after it's all set up by the script, and then you just pick which folder of drivers to inject after booting the USB, and the UI (currently in beta, but works fine in my experience) makes it easy to download apps from Winget & drivers from Microsoft/HP/Dell/Lenovo. As it's using an FFU rather than a WIM, it's much quicker to deploy to the machine than a vanilla Windows image.
  16. I use this tool to create a clean USB image with the drivers included. https://github.com/rbalsleyMSFT/FFU Have looked into OSDCloud, haven't had a chance to use it as it doesn't like machines with 4GB RAM, which are the main ones I'm rebuilding lately (DfE laptops from Covid)
  17. Not much of a gamer, but recently got back into the Rollercoaster Tycoon games with OpenRCT2 (a community mod/reimplementation that fixes some bugs and makes minor tweaks to the second game and can take bits from the first game if you also have that on your PC), and finally got around to getting Kirby and the Forgotten Land (somehow buying new at Argos was cheaper than getting it 2nd Hand at CeX!)
  18. This is one of the reasons we're considering moving away from Riso (large primary) ourselves, in a similar situation to you (currently using MF connected to Entra ID on our old AD server which we're trying to retire). They support Hive, but only for print release - it can't report copier usage to charge to the print accounts (and we use a lot of copying for test papers), so that's not suitable for us, and are pushing us to DirectPrint RED, also, which can track copying. Their support site is certainly lacking in detail compared to PaperCut's very comprehensive documentation (I like to read the product documentation before purchase to get screenshots and a feel for what the product can do). Will probably ask Riso for a demo/trial of DirectPrint as our lease ends this summer.
  19. We got staff to do it themselves as part of the "Healthy Working" e-learning course from Cardinus.
  20. Currently we only permit Copilot (as long as you're logged in with your M365 account for their basic Enterprise Data Protection) and TeachMate (who promise not to train on our data, but it's up to staff to have their own subscriptions, we're not paying for that from the school budget), and block everything else on the network filter, but can't block too easily if someone switches to a mobile hotspot or takes their laptop home. We've just moved from Integris to Arbor, and that has a built-in LLM to create student summaries for reports, emails home, etc. LGfL have the "AI Chat & Image Generators" category from base Netsweeper, but also have a custom "Bundle" you can use to allow a number of AI tools for staff that they might find useful, if you're using user-based filtering - that includes ChatGPT, Claude, Copilot, and Gemini, "plus a small selection of AI URLs commonly used in education" (e.g. TeachMate, The Key). The description of the bundle actually recommends not using it but instead manually allowing just the sites you approved in your AI policy.
  21. You need to get annual parental consent now if you're using Google Workspace accounts with Additional Services, see this help article Communicating with Parents and Guardians about Google Workspace for Education - Google Workspace Admin Help Specifically,
  22. In my experience, InVentry (V4) and Net2 interpret card numbers differently enough that they can't be converted from Net2 back to InVentry, but InVentry card numbers can be converted to Net2 (and IIRC the documentation suggests that can be automated if you have a Net2 door licence in InVentry, which we do not due to the cost when we got it quoted) InVentry takes the full card number as hexadecimal (base 16) and works with that as it is. Net2 takes the card number as a decimal (base 10), then only keeps the last 8 digits. I have an Excel spreadsheet I use to convert the card numbers (as the app I use on my phone to read the card number also spits out the card number as hexadecimal, conveniently). The formulae are as follows: Cell A1: <Input card number as Hexadecimal, no colon separators, case insensitive) Cell B1: =HEX2DEC(A1) This converts to decimal Cell C1: =RIGHT(B1,8) This cuts to the last 8 digits for Net2 to use
  23. Our WUfB settings are set to a 60 day Feature Update deferral for IT and 120 day for everyone else. I've had no issues since upgrading on my machine, and the benefits of the new ADMX policy to uninstall pre-installed apps like Solitaire and Xbox seem to have worked fine.
  24. There was a Zoom assembly this morning that got caught up in this, too. Was a fun start to the day.
  25. Pre-provisioning is designed for if you're going to get the device enrolled to Intune but the user will complete OOBE. If you're just going through OOBE in one go, I don't see any use of making yourself wait the 90 minutes between resealing the device and then unsealing it later. Just do it all in one go.
×
×
  • Create New...