Jump to content

Blue_Cookeh

Members
  • Posts

    1,485
  • Joined

  • Last visited

Everything posted by Blue_Cookeh

  1. If you're on an EES agreement I believe MBAM is now included with the OS licensing, which will cover your needs for USB and make management of your OS BitLocker encryption easier.
  2. We use Microsoft MBAM, part of the MDOP suite. Using MBAM we can centralise key escrow (it all goes back to an MS SQL database with a fancy web front-end) and set fine grained policies (GPOs) relating to operating system disk, external disk, and removable media encryption. We use it to enforce BitLocker on the operating system drive using a start up PIN across all staff laptops, and then use it to enforce password based encryption on USB sticks. This is pretty much perfect for us because if staff don't want to encrypt their home USB sticks, it will mount them in Windows as read-only, then if they try to copy any data to it in school it'll ask them to set up encryption first or deny it if they hit cancel. When this happens it will then send all recovery keys off to our MBAM server should they forget them. It also has a web-based reporting tool and can totally integrate with SCCM if you use it. I'd highly recommend it. Oh... and it also works on any standard USB stick, so no need to waste money on those fancier encrypted ones. Our policies state work is NOT to be done on home computers where a school laptop is provided. Obviously we can't police that but we've done all we can in the eyes of the law to protect our data, so at that point I believe it falls onto staff for breaking our policies.
  3. Disable lower data rates, lower wireless power so that APs aren't overlapping so much, try to use 5GHz where possible, and if your APs support features like airtime fairness enable those. Apple kit is notoriously chatty, which will affect things.
  4. Any chance you could let us know how much Redstor is costing you guys?
  5. This guy knows what's up +1 for SCEP
  6. 1. You will never get a response from a DA connected client unless you are pinging the IPv6 address from a "DirectAccess manage out" machine (Google it), so that's working as intended. 2. I'd argue there are probably some communication problem or a certificate template problem if your certificates aren't autorenewing over DA, our's do. 3. It will not push to DA clients unless you set your SCCM boundaries up (you need to add the DA IPv6 address space as a boundary) and set up a manage out address on the SCCM site servers. Fundamentally DirectAccess relies on IPv6 connectivity between the laptop and the DA server (even if they are 6in4 tunneling or whatever), the DirectAccess server will then do the translation between your IPv6 DA clients and the IPv4 on-premise servers/services. Also for 2,200 laptops I hope you a) have a redundant DA location server, b) multiple site entry points c) maybe even load balancing, otherwise you're not going to get a good DA experience.
  7. Ohhh yes - we'll definitely be looking at moving over to OneDrive now It'll likely be October time, if they follow last year's release cycle.
  8. This. Remember WiFi is a shared medium and unless you have some of the newest generation access points (with MIMO, beam forming etc) and client cards your devices are going to be fighting for air time on both receiving and transmission. This only gets worse with more clients. If you're going to be doing this sort of thing in future I'd look at deploying these files ahead of time in the background using SCCM or whatever your $configmanager of choice is. I dare say if you looked at the graphs for your AP's uplink, it isn't even hitting 10% utilization during these times because the bottleneck will be the wireless portion.
  9. An e-mail in the least, which to be fair, is what we got so I ain't complaining
  10. Are you setting the proxy for Gopher in your GPO? This seems to break it, set the proxy up for all protocols apart from Gopher and it starts to work.
  11. Are these servers running any other roles?
  12. Modern apps wont work with UAC disabled, for example (in Win10). Microsoft are going to make your life more and more difficult if you decide to turn it off. It's an extra layer of kernel level security in Windows. We force it ON via GPO in our environment and have actively refused to purchase software that require it be disabled. I'd argue the people turning it off nowadays don't really know what they're doing when it comes to a Windows deployment, harsh but meh.
  13. Am I the only one that goes out back with a hammer?! (BitLockered drives)... physical destruction isn't only the safest, but also the most satisfying method of data removal!
  14. If you want command line access I'd spin up a cheapo VM with DigitalOcean or Vultr and go nuts. Otherwise, http://www.SimplexWebs.com. The guys behind this site are fantastic and I can say (having worked with them in the past) they tell the truth when they say they never oversell and run decent servers.
  15. Are people actively using these devices? I've never heard of them but they seem to be trying to solve a non-existent problem?
  16. Had BT Infinity since I moved in to my current place (employee broadband originally... those were the days :'() and it's been rock solid, I get a consistent 80 down, 20 up. We were using the HomeHub 5 for a long time but eventually I bit the bullet and swapped it out. Bought a cheapo BT Openreach modem from eBay for a tenner and put in an AC router I had lying around with DD-WRT on it. That thing has been solid as a rock! I think it's uptime is into 100 odd days now without losing a connection. The BTWiFi-X stuff is indeed used for certificate authentication to the public, but it's also used for corporate customers too. BT sold a software product to public and private sector called MobileXpress which made heavy use of the BTWiFi-X SSID to provide connectivity.
  17. DirectAccess works *entirely* on DNS and IPv4 in 6 tunnelling, which unfortunately means you're going to have to add a DNS record for the private IPs your vendor is using, and then make sure the software is using DNS names rather than IP addresses. If you do this make sure your DirectAccess server knows how to get to the IP addresses internally, you may need to add a static route in Windows. Otherwise yup! Full blown VPN solution or make the software accessible via the Internet if appropriate.
  18. Can you post the batch script you were using? If it's an MSI file by default there's nothing SCCM would do to stop /qn working, that would be down to whoever packaged the MSI breaking it EDIT: I also take it you read this? It looks like you need a little more to get it to silently install: http://www.wordsharksupport.co.uk/docs/si.pdf
  19. I'd say that SCCM is fantastic at what it does, but as others have said when something goes wrong, it generally really goes wrong. I think one thing to bare in mind is that businesses that use SCCM generally have teams of people dedicated to just SCCM, for example MDM admins, application packagers, OS deployment specialists etc. That said, for the Edu pricing on it I can't recommend it to schools enough. A teacher recently asked me to install Scratch on all our netbooks, spent half an hour packaging and deploying it as ASAP and our machines had all picked it up within 30 mins of being turned on. It also allows me to deploy Win10 and all our apps (two of them are 20 and 30GB each...) to 45 netbooks in roughly 2 and a half hours. It's an entirely zero touch deployment (apart from new machines which prompt for a computer name and staff/pupil role) and a clean WIM that has all our applications and tweaks installed as part of the task sequence. This makes any new OS upgrades dead easy since I can just swap the WIM out. If you're doing deployments to IT suites etc I would highly recommend taking the time to setup Multicast deployment in SCCM and on your switches since that speeds it up loads too.
  20. I know BT WiFi are primarily concerned about unique foot traffic. Places like Starbucks and McDonald's will attract enough of their existing customers, or people who are willing to pay, to make it worth their while. Not so sure a school would offer that. They end up doing surveys and all sorts before even thinking about putting a solution in.
  21. I'd suggest taking another look at it when you next do a roll out or something, all of these are solvable with group policies etc Once it's setup your administration will be tons easier!
  22. Loving Windows Defender here. We originally had McAfee 3 or so years ago but ditched it when we bought SCCM licenses... back then it was mainly financial reasons rather than technical but honestly I haven't looked back. I probably wouldn't use it on it's own, but with SCCM the reporting is there and SCCM pushes silent definition updates out to clients every 2 hours (if there's a new one available). As soon as anyone in school gets something bad on their machine and it pops up in SCCM it e-mails IT about it so we can be a little quicker on the mark
  23. What's your scaling set to in the display settings? I'm using Win10 Enterprise CBB on a Surface Pro 4 right now and don't see any of these issues in Office 2016. My display scaling is set to 200%.
  24. That sounds really janky but also why local accounts? Domain accounts work just fine at home
×
×
  • Create New...