Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

sraper

Members
  • Posts

    73
  • Joined

  • Last visited

Everything posted by sraper

  1. I did wonder that but the staff would like the "app" gone if possible. Do the above just blocks their ability to send/recieve emails - may have to go this route if needed though
  2. I thought I could only assign the main "Office 365 A1 for students" license by groups. All children need that license - its just the "Exchange Online (Plan 1)" sub-license that I want to remove.
  3. Is there a "simple" way to remove Outlook and any ability to send recieve emails for ALL pupils in a primary school Need to remove the Outook icons from here Copilot | Microsoft 365 Copilot if possible - if not then at least they get an error when click on it! I would love a simple way to apply this to all pupils and to newly created pupil accounts automatically. I have read about removing the Exchange license - but that would mean poweshell scripting as need to do this for close to 600 pupils and wont stop it on new accounts Also read that can remove MAPI from their mailbox in Exchange online - but again messy powershell scripts etc. What would be really nice would be some policy similar to all of the "teams" policies that could do this and then assign the policy to a group! regards
  4. Hope this is the right forum for this question I have a primary school that don't like the new homepage https://m365.cloud.microsoft/ They want "rid" of all of the CoPilot malarky they just want the clean simple old homepage back where it has the apps you can access - this one!!!
  5. Okay I believe in out sceranrio we have AD joined pc's User signs in to PC using ther AD username and password UniFlow is confgured on MS 365! School uses LGfL Staff Mail (so Exchange Server)! Member of staff goes to a computer signs in, nothing prints so they do whatever is that they are supposed to do to sign in to Secure Print. It claims to have sent them an email. The email NEVER arrives so they cant sign in. What we usaully end up having to do is Remove and re-install the "app" on ther account in Unflow remove the entry for that PC it then works We get 3 or 5 of these a day Monday after the 1/2 term most have recieved 20 of these from a 3 form entry primary school - so bascially one request for every teacher!!! P.S. we did not set this up and we specifically said not to go this route as the school DONT use 365 - not for authentication or emails - it was the "canon" who insisted
  6. From what i hear from the staff on the IT technician who supports the school. It basically staff member is using a computer ok. They go and use another computer and then come back to the first one. They try to print but nothing comes out. they click on the the Uniflow icon and choose "re-register" which says it will send them an email - the email never arrives I maybe misunderstanding what I am being told by co-workers and on site staff
  7. Odd we have issues maybe 2 or 3 times or week or even more where a user is not receiving the registration email. Even though they had been signed into same computer the day before and it had printed
  8. Would be good to know the current status of "cloud" printing. We had one school go with Papercut Hive about 18 months ago and they had to ditch it with 3 months as it couldnt seem to handle "shared" devices. So computers that were logged into by multiple staff were exceedingly unreliable. We have another school using Canon UniFlow (Cloud) and we hate it again the issue is with users moving to another PCs PCs used by multiple users both of these seem to mean that the user has to "sign in" again and then wait for the email - which often never arrives! Needs to work well in primary schools with the above caveat of "mobile users" contsantly swapping PCs - so dont want something that triggers the re-authentication process too often For example we have one school that is using PaperCut MF with 4 devices (3 Sharp and 1 Riso from memory) and they are planning on going fully cloud based (Micorosft 365/Intune/Entra) over the summer what is the most reliable and cost effective solution
  9. Well its worth a try a guess!
  10. This is the calling policy that is applied (and has been for months!) and yet they can still make calls!
  11. Ok this is doing my head in. School dont want kids calling each other in Teams. How do I remove either the "calling" app or if the app cant be removed then make it not usable I though this was through the "app setup policy" which literally has just this set! So this should "just have" teams and nothing more. Not the calendar, not OneDrive and NOT the calling app - and yet they are still there! Policies assigned to the user are these
  12. If you mean this "In the chrome GPO for "set the roaming profile directory" it is set to ${documents}\Chrome" then that ${documents} maps to the user's "my documents" which in this case is redirected to a folder on the sever. this is working "correctly" in that within their "my documents" there is a Chrome folder which is uptodate and has various settings/config files and folders in it. The point is that that is working correctly IMO and very user has their own copy in their own my documents on the server. and yet something somewhere is being "shared" locally on the C drive amongst all users - so it would seem
  13. On the PC that had the main issues I have just noticed that there is a c:\Chrome\Default\profile.pb" ! However that is owned by "Administrators" and nothing I can see should allow Chrome to create or modify that!
  14. Profiles are redirected to a share on the server In the chrome GPO for "set the roaming profile directory" it is set to ${documents}\Chrome so that redirects their Chrome "profile" in to a folder called Chrome in "My Documents" eg \\server\StaffData$\Teacher\username\Documents\Chrome which is what makes this even more confusing as nothing chrome releated should be on the local PC - let alone shared amongst all users!!! I think we may also have UE-v settings as well - could they be overriding the above and causing the issue???
  15. That was my assumption but I have checked that machine carefully and we have scripts that run at logon and logoff to write these events into a custom log file, Person A in question definately logged off and did not log back in untill 3 days later. The only login/logoff events during these 3 days were for two other users!
  16. It would appear so - but I have checked through all the chrome settings in GPO and the closest relevant one is "Set the roaming profile directory" They can happily sign onto multiple computers to use Chrome - but only ONE user per PC
  17. Good Morning Really not sure where to post this one none of the existing forums seemed appropriate. Have two issues with Google Chrome on Windows 10 (and I presume Windows 11 but not tested). The first one has been ongoing for possibly years but did not think much of it - other than an minor annoyance but I think now maybe related to the second issue which has just been spotted. So we run a "typical" setup for a primary school so Windows server with AD, GP, DHCP, DNS etc all on the one physical server. All PCs on the domain .... 1st issue Person A signs onto any windows 10 client and then goes and starts Google chrome. They get busy distracted and walk away from the computer for the rest of the day! Computer locks after a suitable time period Person B comes along and sees a "spare/unused" PC and decides to use it. Person B signs in and tries to open Google Chrome - it "NEVER" opens. No matter what they do it wont open. So reboot PC and signs in Chrome opens fine It seems that person A still being signed in and with chrome "open" is blocking a second user from using chrome this has been happening for years but never thought much of it 2nd - more serious issue On a teachers classroom PC - been signing into same PC for months. One day they sign off at the end of the day Next day they call in sick and are off for 3 days. In those 3 days two other staff cover the lessons and sign in using their credentials. They use Chrome and sign into various websites. From the logs I can see that they both signed out correctly when they finished On 4th day Person A comes back and signs in. When they use Chrome they can see the other users Autofill data etc:mad:
  18. Yes but trying searching for a supplier of these devices !!!
  19. Obvious that mess up are StartMenu Layout and that area. but apart from that. Pretty much everything that works for 10 will work in 11
  20. I know what your saying. Just there's a few apps on the start menu when you install Office365 (OneNote, Access, Outlook etc), Cloud Drive Mapper, Inkscape (who uses Inkview!) just wanted to tidy things up! But I just may bow the Inevitable (thanks Microsoft) and given in.
  21. So what is the consenus for managing the StartMenu Layout as of latest builds of Windows 11 23H2 (and newer). Is the "registry hack" definitely no longer working? Is the only option copy a customised start.bin file
  22. Can you even buy them now? One of the schools I work for tried to buy 200 in June and then at the very last minute were told in July - Sorry no longer available!!!
  23. I am using this <# Based on code from https://www.burgerhout.org/remove-bloatware-on-windows-10/ #> #List of 'apps' to remove $UninstallPackages = @( 'Microsoft.BingNews' 'Microsoft.BingWeather' 'Microsoft.GamingApp' 'Microsoft.GetHelp' 'Microsoft.Getstarted' 'Microsoft.MicrosoftSolitaireCollection' 'Microsoft.MixedReality.Portal' 'Microsoft.People' 'Microsoft.PowerAutomateDesktop' 'Microsoft.Skype' 'Microsoft.Windows.DevHome' 'microsoft.windowscommunicationsapps' 'Microsoft.WindowsFeedbackHub' 'Microsoft.Xbox.TCUI' 'Microsoft.XboxGameOverlay' 'Microsoft.XboxGamingOverlay' 'Microsoft.XboxIdentityProvider' 'Microsoft.XboxSpeechToTextOverlay' 'Microsoft.YourPhone' 'Microsoft.ZuneMusic' 'Microsoft.ZuneVideo' ) # List of programs to uninstall $UninstallPrograms = @( ) # Create a tag file just so Intune knows this was installed if (-not (Test-Path "$($env:ProgramData)\Microsoft\RemoveWindowsBloatware")) { Mkdir "$($env:ProgramData)\Microsoft\RemoveWindowsBloatware" } Set-Content -Path "$($env:ProgramData)\Microsoft\RemoveWindowsBloatware\RemoveWindowsBloatware-1-0.ps1.tag" -Value "Installed" # Start logging Start-Transcript "$($env:ProgramData)\Microsoft\RemoveWindowsBloatware\RemoveWindowsBloatware-1-0.log" # get all provisioned packages $AppList = Get-AppXProvisionedPackage -Online | Where {($removeList -contains $_.PackageName)} #and other apps $InstalledAppList = Get-AppxPackage -AllUsers | Where {($removeList -contains $_.PackageFullName)} $InstalledPrograms = Get-Package | Where {$UninstallPrograms -contains $_.Name} $InstalledPackages = Get-AppxPackage -AllUsers | Where {($UninstallPackages -contains $_.Name)} $ProvisionedPackages = Get-AppxProvisionedPackage -Online | Where {($UninstallPackages -contains $_.DisplayName)} $InstalledPrograms = Get-Package | Where {$UninstallPrograms -contains $_.Name} # Remove provisioned packages first ForEach ($ProvPackage in $ProvisionedPackages) { Write-Host -Object "Attempting to remove provisioned package: [$($ProvPackage.DisplayName)]..." Try { $Null = Remove-AppxProvisionedPackage -PackageName $ProvPackage.PackageName -Online -ErrorAction Stop Write-Host -Object "Successfully removed provisioned package: [$($ProvPackage.DisplayName)]" } Catch {Write-Warning -Message "Failed to remove provisioned package: [$($ProvPackage.DisplayName)]"} } # Remove appx packages ForEach ($AppxPackage in $InstalledPackages) { Write-Host -Object "Attempting to remove Appx package: [$($AppxPackage.Name)]..." Try { $Null = Remove-AppxPackage -Package $AppxPackage.PackageFullName -AllUsers -ErrorAction Stop Write-Host -Object "Successfully removed Appx package: [$($AppxPackage.Name)]" } Catch {Write-Warning -Message "Failed to remove Appx package: [$($AppxPackage.Name)]"} } # Remove installed programs $InstalledPrograms | ForEach { Write-Host -Object "Attempting to uninstall: [$($_.Name)]..." Try { $Null = $_ | Uninstall-Package -AllVersions -Force -ErrorAction Stop Write-Host -Object "Successfully uninstalled: [$($_.Name)]" } Catch {Write-Warning -Message "Failed to uninstall: [$($_.Name)]"} } Stop-Transcript
  24. In the good 'ole days we used to redirect all pupils StartMenu Folder to a single location. Making it easy to a) lock down the Start Menu and b) only show the applications we wanted them to use and hide all the "rubbish". now that we are moving to purely an Entra/AzureAD solution it seems that there is no way in Intune to do folder redirection (which make sense for Document, Pictures et al - as they just redirect into OneDrive) but for the StartMenu still need a way to have only a simplefied list showing under "all apps". Have the pinned list working ok just when you click on "all app" there is soo much crap in there - I know there is no way to stop UWA/Modern apps from appearing but the traditional apps like Outlook, Cloud Drive Mapper ... At the moment all I can think of doing is writing a "user" logon script that "resets" their start menu in "%appdata%\Microsoft\Windows\Start Menu\Programs" either by a simple ROBOCOPY from somewhere accessible or a fancy script that just deletes everything and then copies specific files from the "%allusersprofile%\Microsoft\Windows\Start Menu\Programs" Surely there is a better way to do this?
  25. I am trying to configure and deploy a taskbar layout at two different sites. Something as simple as this: xmlns="http://schemas.microsoft.com/Start/2014/LayoutModification" xmlns:defaultlayout="http://schemas.microsoft.com/Start/2014/FullDefaultLayout" xmlns:start="http://schemas.microsoft.com/Start/2014/StartLayout" xmlns:taskbar="http://schemas.microsoft.com/Start/2014/TaskbarLayout" Version="1"> Using GPO on one site I can now get this to work. At the site using Intune pretty sure its not even getting that far. I have a configuration policy that has the following The "Configure Start Pins (User)" is working fine. However not convinced about the "Start Layout (User)" not so sure about - the official MS documentation heavily implies that this should be a reference to an actual file residing somewhere - which would be a paim! However I have seen example where people appear to have just copied the contents of the file into the entry as I have chosen to do. Does this method actually work? Or will I need to make this available somewhere in Sharepoint? If so whats the best way to create a read-only area where I can dump this file and others?
×
×
  • Create New...