-
Posts
592 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Sephiroth
-
Personally recommend ICT-Direct. According to their Stock List they have 1000 HP Chromebook 11 G9 EE devices from £115, or below £100, you can get the G8s, which are supported until 2029. If you're happy with 'C' grade, it looks like you can get them for £30 each!
-
Without wanting to sound like an extreme conspiracy theorist, this kind of thing is one of a great many reasons I don't use Windows at home. Application installation security has always been a sore point there, this is just a company being caught using one of Microsoft's flaws for their own gain. It'll be interesting to see if this affects cyber security guidelines gooing forward.
-
Glad its working. Until MS kill off Group Policy in favour of Intune, at least. Can't wait for that one... 😒
-
Eveyone seems to hide the goodies away now. I know that a lot of stands were complaining that the children that were let loose just took handfulls of sweets that seemed to be abundant this year. @Rob_D the little ICT-Direct box is a screen cleaner spray with cloth Most of what I got this year was bags and sweets. The highlights were a Verkada Yeti mug, an ICT-Direct thermal mug, and a beautiful 43 piece precision toolkit. I neglected to get any photos, so if I remember, I'll get some when I get home tonight (of course it didn't get to the office, thats what the paperwork is for!).
-
It should only apply to objects that match the security filter. I assume your security filter on the 'Scope' setting has only the object that you want affected? The screenshots I listed are from a fully functional GPO in my domain, as that's how we primarily do device specific software installation. We used to have the same settings in production for users, but don't any more. What does Group Policy Results show for that GPO against your users, both that you're expecting it to apply to and not?
-
I've put some examples in here. This is from an object applied to computers for software installation depending on group membership, but the premise is the same.
-
The security filter should have the 'Authenticated Users' removed, but that also removes it from the security settings, meaning that Windows won't be able to read the policy to apply it. You need to add 'Authenticated Users' back into the security settings with read permissions for it to apply.
-
I've found myself gravitating to old favourites recently. Project Zombiod - Fantasticly realistic zombie apocalypse survival game that's brutally challenging. Factorio Space Age - Top down, complex factory builder. Dying Light - Zombie apocalypse FPS parkour. 7 Days to Die - Zombie apocolypse FPS survival crafting game. Ostranauts - Rogue-like top down ship breaking/building game. Most of those are multiplayer, but i mostly play alone. Factorio is great with friends, and thats how I started, but mostly I play singleplayer. 7D2D is another one that is great multiplayer and I've run a few servers for a small group of friends, but I've logged nearly 8k hours since ~2018
-
I'm looking at the way we do secure accounts for technicians/domain admins and have started to go full circle driving myself barmy! Would you be willing to share how you manage the security and group policy for techs in your domains so I can see how others do it? For reference we are a secondary with ~2000 users and 2 sites supported by 3 staff. As it stands we have LAPS set up and technicians have 3 accounts: test user; technician; and domain admin. The test user is exactly the same as a staff account. The Domain admin account is a named but standalone account, not restricted by group policy. The technician user is a standard staff account but with a few overrides in group policy; for example, to enable CMD, PowerShell, and MMC and to allow access to the local disk. We still have to escalate to the DA account if something needs administrator access. I suppose my slightly rambly question is: Is this secure/effective/efficient, or is there a better way to do it? Thanks!
-
How are people blocking software/apps in windows 11
Sephiroth replied to User3204's topic in Windows 11
The one that tripped me up when setting up AppLocker is getting the rules generated automatically adds the version currently installed on the device. For example, if I have Chrome version 138.0.7204.97, then it will pick that as the lowest version to allow. If that's the latest version then any machine that isn't bang up-to-date as of implementing the policy will have that application blocked. I got around this by removing the version (asterisk in the file version field, as pictured above) fixed most of the initial issues I was having. -
How frustrating. I was hoping to completely remove Read & Write this year in favor of EWP everywhere. We've been using EWP for the last 2 years on isolated exams laptops, having moved from Word/Wordpad + Read & Write. I would guess that it has come from a market share perspective; There's a competitor that is seeing a hefty chunk of sales, buy the product and slowly (or not-so-slowly in this case) bludgeon it to fit the marketing and costing of existing products.
-
I was at a small town middle school in the late 2000s and remember the death of this scheme. We had 600 students all come in with fistfulls of the wreched things and we'd count them up. We generally got a few keyboards and mice a year to replace dead or broken ones, so it wasn't all bad, but it would probably have been cheaper in staff time to just buy them new. With all the fervor that came with it, I can only assume that it did peak at some point earlier, where it was viable to get a few BBC Micros or something similar.
-
As above have commented, I would recommend looking to automate the installation and activation processes. If there's no SCCM server then MDT / WDS is quick to set up and very powerful for automation, especially if you utilise the database features in MDT. Does the school have a Microsoft 365 tennant? If so, InTune might be something to look at as an alternative to on-prem deployments. I can't recommend starting to look at it if it's not already at least half set up though. I also agree that you should get an MSP involved to assist. I would stress, however, that you ensure they are brought in to help you get things set up, rather than rely on them to sort it out. This will mean that you have the knowledge behind you and a second opinion if necessary, as well as a guiding hand specific to your situation. You may be able to rely on support on forums like this (and we will, of course, help you as much as we can), but sometimes it's impossible unless you get hands on. Does the school have Google Workspace access? If so, Google Chrome OS might be a viable alternative to windows on some hardware. Have you considered refurbished hardware from somewhere like ICT-Direct? This will enable you to get some hardware replaced for a decent price to meet Windows 11 hardware requirements. Windows 10 LTSC is technically not supported outside of specific use cases, so I wouldn't recommend going down that route. Similarly, I can't recommend installing the production OS on unsupported hardware, It's a ticking time-bomb for when Microsoft change something that kills it, either in a patch or update, or as part of it's processes. Another option is to look at desktop virtualisation with something like HiveIO. If you have the server capacity, this could smooth out some of the more problematic areas, buying you time to consider better options later on down the line. A single high power server is cheaper than 300 desktops, especially if you go down the refurb route. I know there's a lot to think about here, but hopefully this give you some options to go through. Welcome to the forums, good luck, and keep us posted!
-
Broadcom VMware cease or desist or be Audited
Sephiroth replied to loxford01's topic in Licensing Questions
Personally I think that Broadcom's policies have made VMWare a very hard sell and would recommend migrating away, especially with the current turbulence and sudden changes that are coming about. We moved to a Hyper-V Hyperconverged cluster 5 years ago which was the best move we've made, going from 3 hosts, a controller, and a SAN to 2 cluster nodes. Windows Server Datacenter is already in our licence so made financial sense. I would strongly recommend looking at Proxmox as an open source alternative though, especially if your Microsoft licencing isn't in your favour for Hyper-V. Out of interest, what is your current physical infrastructure setup? -
A friend was on Manjaro for a bit but stopped. It kind of worked but only in that they had so much stomach upset and pain that they couldn't possibly eat anything. The thing with these injections is that they are great to get you into the habit of smaller portions or less snacking, but if you don't change anything then the weight will just come straight back when you aren't taking it.
-
I've used variations of the same password system for as long as I've been using computers. I get around the complexity requirements by putting numbers and special characters between words. The only time I change mine (outside of nonsensical forced changes) is when they get compromised, which I check for regularly. Our password policy at school is linked to the policies of other systems like Go4Schools, making it easier to tell younger children what the requirements are. I'd love to just set it to length>16 though. Back on topic... Password manager depends on use case. We are a Google school so promote the use of Google's password manager in Chrome, but others exist. We use Zoho Vault in IT Services to share passwords and it's a powerful system with plugins for most modern browsers. The fix is exactly this is you are on a Windows exclusive platform:
-
Group Policy Objects Link Order - this has got me stumped
Sephiroth replied to kennysarmy's topic in Windows
If you can parse the licence key as a variable to MSIEXEC, them you should be able to create a transform for it, which can then be deployed by GPO or SCCM. If that's the only setting in the transform, you should be able to use it for all subsequent versions as well. -
Block specific HTML file (Eaglercraft)
Sephiroth replied to Undertoad's topic in How do you do....it?
We've just had this rear it's head here and I'm struggling to find a way of reliably stopping it without blocking file URLs, which is a last resort. How did you do this? Hopefully I can get this to work in both Edge and Chrome. -
As long as it's not between 2025-08-27 and 2025-09-05, I'm happy. I'll be on holiday then!
-
Can't read from behind the paywall... any chance of an excerpt?
-
This is also true of most positions that people think that AI will take over! Humans are great at interpreting human stupidity. AI is a bit more literal, assuming that humans know what they're asking for.
-
I've said June/July as this would be better than the start of the academic year, but I am open to either. My driving force there is primarily that we are migrating to Windows 11 over the summer holidays and I anticipate needing all the time I can get once users start breaking things properly in September. I suspect there will be a few others in the same position.
-
Should the school I work for get Senso Enterprise - Advice needed
Sephiroth replied to EduDISC's topic in Cloud Services
Our experience is similar to that above. We've used it now for several years and will likely be replacing it when the contact is up. We use Lightspeed for filtering, so don't use that element of Senso though. For what it's worth, we've had reported issues for about 2 years now, which were written off as networking faults on our end. The last update for the clients (for us, at least) was December 2023. I'm curious as to what has happened in the last year and a half. One thing I will add; the internet blocking through classroom management only works on Edge, so it wouldn't surprise me if the filtering either doesn't work or is severely limited on Google Chrome. -
What is your preferred operating system? (PC)
Sephiroth replied to YeetJeepo's topic in General Chat
Update on my last post; I've moved to Ubuntu on my home PC, having looked at support for games these days. Been running it now for a few days and just wish I'd made this move sooner! -
Adobe Reader MSI - Why is it so difficult? How do you do it?
Sephiroth replied to Warwick_Tech's topic in Enterprise Software
This was one of the big reasons I looked seriously at Chocolatey. I've got it now so that the latest version is installed whenever it's run without having to worry about what versions there are.
