Jump to content

Blue_Cookeh

Members
  • Posts

    1,485
  • Joined

  • Last visited

Everything posted by Blue_Cookeh

  1. The notion of a physical domain controller is out the window nowadays, just ensure you sync one of the the two VMs to an external NTP source and turn off time synchronization for that VM in Hyper-V. Looks good to me, if you have enough storage on both hosts I'd configure replication as a secondary measure if one of them fails. Also 1TB seems like a waste of storage space just for the OS, I'd probably stick an SSD or two in there if possible and give that extra 1TB back to the VMs. I usually only allocate 60GB to host storage.
  2. You're probably going to have to script this as part of your deployment process: https://technet.microsoft.com/en-us/library/ee617165(v=ws.10).aspx How to enable Wake on LAN on Network Interface Cards using SCCM 2012 Compliance, by Ben Fisher | myITforum.com etc
  3. We've had 0 problems with BitLocker, but I wouldn't do it on a large scale without MBAM to manage it. Plus I can begin the encryption process before we even deploy our image with BitLocker pre-provisioning, so no waiting for hours Bear in mind, a lot of encryption solutions (Sophos etc) are actually just frontends for BitLocker now.
  4. You need an Apple Education contact, press your Apple reseller for some support if they're Authorized Apple partners.
  5. For those small remote classrooms I'd probably do a site to site VPN from the remote router to your local one if possible. Other than that, we deployed DirectAccess on 2012R2 for our 8.1 and 10 clients with no issues. The only gotcha we came across was super slow folder redirection, so make sure you configure slow link detection policies properly.
  6. All our staff have laptops, all on Windows 8.1 or 10 depending on when I last physically got my mits on it! They all used their cached domain profile with folder redirection (so offline files takes care of sync issues), none of them have local admin rights, and they all have DirectAccess enabled so we can still update their machines etc over the summer period. I would seriously look at deploying MDOP MBAM to forcefully manage BitLocker drive encryption though. We use MBAM so we can enforce BitLocker encryption on the OS drive with TPM and preboot PIN. This also makes key escrow easier on my end.
  7. Windows 10 Anniversary Edition will update roaming profiles to a .v6 extension, confirmed by MS. Joy of joys.
  8. We just buy them premade from Insight, sort low to high, pick the cheapest cable of the length/colour we want. Insight
  9. If you need to pass all VLANs back to the router then yes, you want to put the port into Trunk mode and explicitly define which VLANs you want on there with the allow command.
  10. iPhone. It just works™ But seriously, I went through about 5 generations of Android phones before switching to iPhone and never looked back. I loved being able to root devices and mess with them, but eventually I just wanted something that works and didn't slow down after 6 months.
  11. iPads are encrypted by default, so I see no problem with accessing school data on them so long as you lock various settings down. We're a firm believer that school provided equipment should meet the needs of the school first and that home use is an added bonus. This means that we get staff to ask us to install Apps via Meraki and VPP (we haven't ever declined an app, so they're OK with this, particularly as it means we'll often pay for the apps out of our budget) and that we lock down various account settings so that they can't be sending school data all over the place.
  12. Are the iPads supervised using Apple Configurator? AFAIK for silent VPP device deployment they have to be supervised AND enrolled in Meraki.
  13. Office 2013/2016 and Windows 8.1/Windows 10 all have brilliant integration with Office365, so much more so than any of the crap Google put out. I very nearly took our school onto GAfE, and switched to Office365 at the last moment, Google's customer support is shockingly bad whereas with Microsoft I usually get someone calling me back within 20 minutes of submitting a help ticket. Google Apps was nice at home, not so much at school (unless you're using Chromebooks everywhere, in which case it's a whole other story...)
  14. Turnitin - Home seems to be what all the Universities use.
  15. I'd put off any Hyper-V projects for now, Server 2016 introduces a whole bunch of really great features around Hyper-V clustering and storage using local disks to provide redundancy. This could well be a game changer IMO. https://technet.microsoft.com/en-GB/library/dn765471.aspx What’s new in Windows Server 2016 Hyper-V | Thomas Maurer especially https://technet.microsoft.com/en-GB/library/mt126109.aspx
  16. Out of interest, why are you deploying Meraki to Windows machines if you have SCCM? You should be able to get way more data out of SCCM than you ever could out of Meraki.
  17. We don't run anything particularly heavy in our school anymore so I couldn't tell you I'm afraid (all our heavy stuff is web-based now, like Integris instead of SIMS), but they seem to run all the various programs our classrooms need without a hiccup (Office 2016, Kar2ouche, Photoshop, other bits and bobs for programming). Time from pressing the on button to being on the Desktop is well under 30 seconds in Win10. You could easily spec them up better than the ones we went for, I'd definitely give @VeryPC; a call about them though.
  18. Every time we've ordered/renewed EES it all comes in at one go on the day a) the order went through or b) the old contract finished, and we've never had any e-mails with minus amounts on. Sounds like someone dun goofed somewhere to me!
  19. Go through and selectively apply properties from STIGs (published by the US Gov) that would be relevant to your environment, found here: http://iase.disa.mil/stigs/os/Pages/index.aspx
  20. I cant remember which one (really sorry!!) but one of these worked when we had a brand new NMC to install in an APC UPS. administrator / administrator administrator / apc admin / apc
  21. Ubiquiti can do 802.1x against RADIUS, but it cannot do it using a captive portal. You would probably have to invest time and effort into creating your own Ubiquiti compatible portal and authentication mechanism. Arguably, you shouldn't be using a captive portal without a certificate if you're passing AD credentials across it, in which case you might as well have used 802.1x anyway. Saying that, I've had success using PacketFence/Ubiquiti/Cisco switches to get users to authenticate using a captive portal in an 'unsafe' VLAN and then moving them across to a 'safe' VLAN automatically if that's any better for you.
  22. Ripped all our Netgear kit out. APs were dropping like flies and the management interfaces on the switches left a lot to be desired. Everything we have now is HP/Cisco/UniFi.
  23. Another vote for UniFi, we've had it in for threeish years now and we keep expanding it. Great hardware at a good price. Bear in mind Meraki is licensed yearly, if you don't pay the license the AP becomes a brick. Whichever eejit thought subscription/cloud based infrastructure was a good idea should be hung. Although, must keep the vendor in business good and proper!
  24. I'd look at the UniFi EDU APs for this purpose nowadays. https://www.ubnt.com/unifi/unifi-ap-ac-edu/
×
×
  • Create New...