mrwoberts
Members-
Posts
634 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by mrwoberts
-
Sysprep Generalize error for windows 10 1909
mrwoberts replied to bbishopMGC's topic in O/S Deployment
Could we just see what packages are provisioned, maybe there is something else. Get-AppXProvisionedPackage -Online | ft -AutoSize -
Sysprep Generalize error for windows 10 1909
mrwoberts replied to bbishopMGC's topic in O/S Deployment
Looks like the HPPrinterControl app is causing the issue, how about initially removing that and see if Sysprep then completes Get-AppXProvisionedPackage -Online | Where-Object {$_.PackageName -like "*HPPrinter*"} The following command will remove it... Get-AppXProvisionedPackage -Online | Where-Object {$_.PackageName -like "*HPPrinter*"} | Remove-AppxProvisionedPackage -Online -
Authenticated Users (Read) is the minimum every GPO needs, either in the Security Filtering section, or Delegation. There were problems with that a while back so maybe this GPO never got fixed, but well done for spotting it.
-
Been told by my SSU, who apparently have spoken to Capita, that this is a dodgy scam email, and not from Capita! The plot thickens. Either the SSU are misinformed, or Capita are trying to disown this one.
-
Just for a little more specifics, are the proxy settings actually in place when you go to Internet Options >> Connections >> LAN settings? If not, just double check the GP is definitely applying to a Users OU (and the GPO Users application is Enabled) I used to use registry entries to set mine, but I seem to remember I had to write a little login script to 'wake them up', so to speak. They were set, but if I didn't use IE, or didn't go into Internet Options at least once, the settings weren't being used. As soon as I went in to Internet Options and checked they were there, which they were, it then seemed to work.
-
Personally, I've had many conversations about this with various SL Teams, and the consensus seems to fall along these lines... "The children will be using Google outside of school, so lets teach them how to use Google safely." We do however enforce safesearch of Google and Youtube. If you are interested in an alternative, try these DuckduckGo duckduckgo.com Swiggle swiggle.org.uk Link to an article with some search engines.... https://www.educatorstechnology.com/2018/01/11-great-kids-safe-search-engines.html
-
Looks like I'm heading down the certificate (and captive portal) route. Thanks again for replies.
- 32 replies
-
- block page
- hsts
-
(and 1 more)
Tagged with:
-
Would folks just mind commenting whether other Filtering solutions behave in the following way, please... When SSL inspection is not enabled for a device, a blocked (https) page will present a browser error e.g. 'This connection is not Private' Untangle: Yes - this is the normal response. Sophos: ? Smoothwall: ? Lightspeed: ? Fortinet: ? iBoss: ? NetSweeper: ? RM SafetyNet: ? Exa: ? Any others: ?
- 32 replies
-
- block page
- hsts
-
(and 1 more)
Tagged with:
-
Okay, thanks for that. Although, in reality I'm not asking the filter to change the content, just not allow the browser to go to the blocked site and present them with a block page. But I'm guessing therein lies the difficulty, redirecting to the block page from a HTTPS address seems to be impossible without SSL inspection, even though I don't want to inspect the page, just the address the browser wants to go to - more like URL inspection/filtering. This little test has highlighted my misunderstanding of this protocol I guess.
- 32 replies
-
- block page
- hsts
-
(and 1 more)
Tagged with:
-
NxFilter does look interesting and I may well have a play at some point, but just wanted this paid-for solution to work properly. @nathan3388 With Fortinet, what happens to a device that doesn't have the appliance root CA cert and you disable inspection for that device. Do blocked HTTPS sites still display the Fortinet block page??
- 32 replies
-
- block page
- hsts
-
(and 1 more)
Tagged with:
-
Yes, I'm talking about blocked sites. Allowed sites all seem fine. Would anyone mind just doing a check on the David's suggestion please. Could you disable inspection for a particular device then head to a site that is blocked (one that starts with HTTPS....) I'd really like to know whether this is the case or not since I have assumed that the DNS lookup would trigger the block, but now I'm guessing what you're saying is that all modern browsers, Chrome/Edge/Firefox, will not permit a site to be 'redirected' from the filter?? So, if the browser asks for https://purplebricks.com, unless it receives a certificate from that site, or from the filter that is acting on behalf of that site, then you receive the CNP message?? So am I correct in saying that unless you bypass all your non-domain joined devices, those devices get the CNP message on blocked https sites??
- 32 replies
-
- block page
- hsts
-
(and 1 more)
Tagged with:
-
Would this then mean that all filtering providers that don't have SSL inspection enabled will present the C.N.Private page??
- 32 replies
-
- block page
- hsts
-
(and 1 more)
Tagged with:
-
Comments are much appreciated. If I disable the SSL inspection feature, it will block the page, as expected, but for a lot of pages it shows the 'This connection is not private' page. I'm guessing that as sites enforce HTTPS, or at least have a redirect, this is causing the issue. For interest, our product is Untangle. Is anyone else using Untangle that isn't having this issue. The support at Untangle say this is normal behaviour. @localzuk just to confirm, is the suggestion that HTTPS sites will always present the connection not private message if I don't 'inspect' the traffic?
- 32 replies
-
- block page
- hsts
-
(and 1 more)
Tagged with:
-
Came across an issue with our current filtering solution that has an undesirable workaround. They suggest all filtering providers are the same on this issue. The issue is that unless we install the Filter appliance SSL root certificate on every device, we're going to see the 'This connection is not private' error, typically in modern browsers (related to HSTS). Can any other filter show a block page for HTTPS sites without needing to install the SSL certificate?? Smoothwall?? Sophos??? Basically, I'd like to take some examples back to them and suggest they are not correct in saying that all filtering engines suffer the same problem - I'm sure I've seen a block page on my device when going joining a guest network and heading to a HTTPS site (without SSL certificate) Can't remember whether it was Smoothwall or Sophos. Much appreciated. EDIT: Apologies, I should have mentioned that I actually don't want to SSL inspect any traffic, but without the inspection this issue is compounded in the sense that most HTTPS sites then show the 'Connection not private' problem page.
- 32 replies
-
- block page
- hsts
-
(and 1 more)
Tagged with:
-
Yes, I've experienced issues to. In the end I resorted to a page optimiser (creates static HTML from a WordPress page) Furthermore, it appears that one of their IP addresses that my domain uses to send my mail through has been blacklisted. I contacted them about this and they were suggesting that I'd been spoofed, but didn't have an answer when I said that it was primarily their IP address that has been blacklisted, not my email address. They created a SPF record for my domain (good practise anyway) but it hasn't changed anything. Thinking of moving away from them.
-
Fairly decent spec. My main query would be the RAM. Was that your choice, based on current VM usage? If it doesn't add a huge amount I'd go for 128 HV-Host 8 GB DC1 6 GB DC2 6 GB APPSVR 8 GB FILEPRNSVR 16 GB SQLSVR 16 GB RDS 16 GB SCCM 8 GB ----------------- 84 GB Some folks would give the SQLSVR more than 16GB, but it depends on your usage.
-
Could be a number of things, but here are a few things to tick off the list... Do your host names resolve using ping -a ipaddress or nslookup? (if not, likely a DNS issue) Have you configured these GPO items to allow remote management... Computer / Policies Windows Settings / Security Settings / Windows Firewall with Advanced Security Inbound Rules - Windows Remote Management (HTTP-In) Administrative Templates Network / Network Connections / Windows Defender Firewall / Domain Profile - Allow ICMP exceptions Enabled - Allow outbound source quench Enabled - Allow inbound echo request Enabled - Allow inbound file and printer sharing exception (your local subnet) - Allow inbound remote administration exception (your local subnet) - Allow inbound Remote Desktop exceptions (your local subnet) Windows Components / Windows Remote Management (WinRM) / WinRM Service - Allow remote server management through WinRM (*) Computer / Preferences Control Panel Settings / Services Service (Name: WinRM) STARTED Service (Name: RemoteRegistry) STARTED You'll have to run a GPUPDATE once you've made sure these apply to your test computer in a specific OU. EDIT: And a reboot for good measure :-)
- 1 reply
-
- 1
-
-
Schools Broadband In-line Filter down?
mrwoberts replied to snagrat's topic in Internet Related/Filtering/Firewall
@SchoolsBroadband We are scheduled to migrate to the Netsweeper service on Friday, however, since we're ending our contract with you (ends in Jan), do we really have to migrate over for this short period? -
Office Documents become READ ONLY after resume from sleep
mrwoberts replied to mrwoberts's topic in Windows 10
Here's an interesting thing... I just reproduced this issue at a different school, simply by opening a document on the server through a UNC path, made a simply edit, then put the PC to sleep. The moment I unlock after waking up, it gives me with the error message. -
Office Documents become READ ONLY after resume from sleep
mrwoberts replied to mrwoberts's topic in Windows 10
Thank you for those suggestions, I'll add them to the list. At least I know others have experienced. -
Office Documents become READ ONLY after resume from sleep
mrwoberts replied to mrwoberts's topic in Windows 10
Yes, I was thinking the same. That's definitely on my 'try this' list. Thank you. -
It seems the internet has plenty of results on this issue, mostly relating to older versions of office (pre 2016), but I'm struggling to find a working solution. Office 2016 and Windows 10 1809 Server 2016 This doesn't appear to be affecting every user, possibly because the teachers are quite good at closing their documents, whereas the support staff have been experiencing this problem for a while (~3 months). They're now sick of 'Saving As' and I need to find a solution ASAP. Basically, if they are editing a Word document then leave their PC (locked) for a period of time, when they return and unlock (possibly wake up - still testing that theory), the Word document has become READ ONLY. One PC this morning gave the following error message... The things I've tested are... - Nobody else has opened this document - Office has August 2019 updates installed (will potentially release latest updates through WSUS if need be) - Prevented one computer from sleeping, but it still happened when the PC was unlocked I'm at the school tomorrow and will have a more thorough look at it, but just wondered if anyone else has come across this. Here's another Edugeek post with same error message.. http://www.edugeek.net/forums/windows-7/149522-read-only-office-documents-after-suspend.html
-
Passmark results for these CPUs : link Intel Pentium Gold G5400 (2cores/4threads): 5200 (Based on 115 samples) Intel Pentium Gold G5500 (2cores/4threads): 5195 (Based on 19 samples) Intel Pentium Gold G5600 (2cores/4threads): 5660 (Based on 27 samples) Intel i3 8100 (4cores/4threads): 8033 (Based on 1446 samples) Intel i3 9100 (4cores/4threads): 9043 (Based on 3 samples) Pricing (inc. vat) Intel Pentium Gold G5400 : £ 80 Intel Pentium Gold G5500 : £ 90 Intel Pentium Gold G5600 : £ 100 Intel i3 8100 : £ 120 (not readily available) Intel i3 9100 : £ 125 I'd say the Pentium Gold processors are fairly competent cpus for student devices. My minimum when buying equipment is a passmark of 2,000, so this is not bad at all.
-
https://www.microsoft.com/en-us/download/details.aspx?id=58495 Plus the link to the security baselines (toolkit) for 1903 https://www.microsoft.com/en-us/download/details.aspx?id=55319
-
- 4
-
