-
Posts
592 -
Joined
-
Last visited
Reputation
2,386 ExcellentAbout Sephiroth

Personal Information
-
Occupation
Network Technician
-
Interests
Electronic engineering, Gaming, Coding
-
Location
The Comms room, with the cooling pipe...
Recent Profile Visitors
The recent visitors block is disabled and is not being shown to other users.
-
Personally recommend ICT-Direct. According to their Stock List they have 1000 HP Chromebook 11 G9 EE devices from £115, or below £100, you can get the G8s, which are supported until 2029. If you're happy with 'C' grade, it looks like you can get them for £30 each!
-
Without wanting to sound like an extreme conspiracy theorist, this kind of thing is one of a great many reasons I don't use Windows at home. Application installation security has always been a sore point there, this is just a company being caught using one of Microsoft's flaws for their own gain. It'll be interesting to see if this affects cyber security guidelines gooing forward.
-
Glad its working. Until MS kill off Group Policy in favour of Intune, at least. Can't wait for that one... 😒
-
Eveyone seems to hide the goodies away now. I know that a lot of stands were complaining that the children that were let loose just took handfulls of sweets that seemed to be abundant this year. @Rob_D the little ICT-Direct box is a screen cleaner spray with cloth Most of what I got this year was bags and sweets. The highlights were a Verkada Yeti mug, an ICT-Direct thermal mug, and a beautiful 43 piece precision toolkit. I neglected to get any photos, so if I remember, I'll get some when I get home tonight (of course it didn't get to the office, thats what the paperwork is for!).
-
It should only apply to objects that match the security filter. I assume your security filter on the 'Scope' setting has only the object that you want affected? The screenshots I listed are from a fully functional GPO in my domain, as that's how we primarily do device specific software installation. We used to have the same settings in production for users, but don't any more. What does Group Policy Results show for that GPO against your users, both that you're expecting it to apply to and not?
-
I've put some examples in here. This is from an object applied to computers for software installation depending on group membership, but the premise is the same.
-
The security filter should have the 'Authenticated Users' removed, but that also removes it from the security settings, meaning that Windows won't be able to read the policy to apply it. You need to add 'Authenticated Users' back into the security settings with read permissions for it to apply.
-
I've found myself gravitating to old favourites recently. Project Zombiod - Fantasticly realistic zombie apocalypse survival game that's brutally challenging. Factorio Space Age - Top down, complex factory builder. Dying Light - Zombie apocalypse FPS parkour. 7 Days to Die - Zombie apocolypse FPS survival crafting game. Ostranauts - Rogue-like top down ship breaking/building game. Most of those are multiplayer, but i mostly play alone. Factorio is great with friends, and thats how I started, but mostly I play singleplayer. 7D2D is another one that is great multiplayer and I've run a few servers for a small group of friends, but I've logged nearly 8k hours since ~2018
-
I'm looking at the way we do secure accounts for technicians/domain admins and have started to go full circle driving myself barmy! Would you be willing to share how you manage the security and group policy for techs in your domains so I can see how others do it? For reference we are a secondary with ~2000 users and 2 sites supported by 3 staff. As it stands we have LAPS set up and technicians have 3 accounts: test user; technician; and domain admin. The test user is exactly the same as a staff account. The Domain admin account is a named but standalone account, not restricted by group policy. The technician user is a standard staff account but with a few overrides in group policy; for example, to enable CMD, PowerShell, and MMC and to allow access to the local disk. We still have to escalate to the DA account if something needs administrator access. I suppose my slightly rambly question is: Is this secure/effective/efficient, or is there a better way to do it? Thanks!
-
How are people blocking software/apps in windows 11
Sephiroth replied to User3204's topic in Windows 11
The one that tripped me up when setting up AppLocker is getting the rules generated automatically adds the version currently installed on the device. For example, if I have Chrome version 138.0.7204.97, then it will pick that as the lowest version to allow. If that's the latest version then any machine that isn't bang up-to-date as of implementing the policy will have that application blocked. I got around this by removing the version (asterisk in the file version field, as pictured above) fixed most of the initial issues I was having. -
How frustrating. I was hoping to completely remove Read & Write this year in favor of EWP everywhere. We've been using EWP for the last 2 years on isolated exams laptops, having moved from Word/Wordpad + Read & Write. I would guess that it has come from a market share perspective; There's a competitor that is seeing a hefty chunk of sales, buy the product and slowly (or not-so-slowly in this case) bludgeon it to fit the marketing and costing of existing products.
-
I was at a small town middle school in the late 2000s and remember the death of this scheme. We had 600 students all come in with fistfulls of the wreched things and we'd count them up. We generally got a few keyboards and mice a year to replace dead or broken ones, so it wasn't all bad, but it would probably have been cheaper in staff time to just buy them new. With all the fervor that came with it, I can only assume that it did peak at some point earlier, where it was viable to get a few BBC Micros or something similar.
-
As above have commented, I would recommend looking to automate the installation and activation processes. If there's no SCCM server then MDT / WDS is quick to set up and very powerful for automation, especially if you utilise the database features in MDT. Does the school have a Microsoft 365 tennant? If so, InTune might be something to look at as an alternative to on-prem deployments. I can't recommend starting to look at it if it's not already at least half set up though. I also agree that you should get an MSP involved to assist. I would stress, however, that you ensure they are brought in to help you get things set up, rather than rely on them to sort it out. This will mean that you have the knowledge behind you and a second opinion if necessary, as well as a guiding hand specific to your situation. You may be able to rely on support on forums like this (and we will, of course, help you as much as we can), but sometimes it's impossible unless you get hands on. Does the school have Google Workspace access? If so, Google Chrome OS might be a viable alternative to windows on some hardware. Have you considered refurbished hardware from somewhere like ICT-Direct? This will enable you to get some hardware replaced for a decent price to meet Windows 11 hardware requirements. Windows 10 LTSC is technically not supported outside of specific use cases, so I wouldn't recommend going down that route. Similarly, I can't recommend installing the production OS on unsupported hardware, It's a ticking time-bomb for when Microsoft change something that kills it, either in a patch or update, or as part of it's processes. Another option is to look at desktop virtualisation with something like HiveIO. If you have the server capacity, this could smooth out some of the more problematic areas, buying you time to consider better options later on down the line. A single high power server is cheaper than 300 desktops, especially if you go down the refurb route. I know there's a lot to think about here, but hopefully this give you some options to go through. Welcome to the forums, good luck, and keep us posted!
-
Broadcom VMware cease or desist or be Audited
Sephiroth replied to loxford01's topic in Licensing Questions
Personally I think that Broadcom's policies have made VMWare a very hard sell and would recommend migrating away, especially with the current turbulence and sudden changes that are coming about. We moved to a Hyper-V Hyperconverged cluster 5 years ago which was the best move we've made, going from 3 hosts, a controller, and a SAN to 2 cluster nodes. Windows Server Datacenter is already in our licence so made financial sense. I would strongly recommend looking at Proxmox as an open source alternative though, especially if your Microsoft licencing isn't in your favour for Hyper-V. Out of interest, what is your current physical infrastructure setup? -
A friend was on Manjaro for a bit but stopped. It kind of worked but only in that they had so much stomach upset and pain that they couldn't possibly eat anything. The thing with these injections is that they are great to get you into the habit of smaller portions or less snacking, but if you don't change anything then the weight will just come straight back when you aren't taking it.
