Jump to content

mdrabble

Members
  • Posts

    2,704
  • Joined

  • Last visited

Everything posted by mdrabble

  1. Did an inplace upgrade from 2012r2 to 2019 on all 3 of my domain controllers back in January and thought all was well until last week when I was starting to see some GPO errors when running gpupdate on some computers. Turns out DC-01 which also holds FMSO roles and Certificate Authority stopped replicating and no matter how much troubleshoot I cannot get it to replicate again! So I am thinking, move FMSO roles to roles to another DC (which is easy enough) - but what about moving the CA? Never done this, so no idea how easy/difficult it is. Once moved all roles, I will demote the server and then spin up a new VM to take its place. Anyone moved their CA to a different server? Any gotchas i need to worry about? Cheers
  2. That’s exactly what I was after - cheers :-)
  3. Currently have papercut setup with Sharp MFDs where staff select chargeable department via the papercut windows popup. I know I can change it so account selection takes place at the MFD but for the life of me I cannot find the settings. Anyone able to point me in the general direction? Cheers
  4. Thanks for the replies - I think I got sucked into pushing all things cloud - when sometimes the old tried and tested methods work just as well. Think will go Domain joined and AOVPN using device tunnels - that way I can simply use an existing SCCM TS to image laptops and add on the AOVPN - will definitely be less work and less stress for me so Ian get some time to re-evaluate things.
  5. I've done similar post on this before but I've become indecisive on how to approach this. approx 3 1/2 months ago, I started looking at all this with the idea to deploy staff laptops via intune and AzureAD joined only. I presented/email the proposal to the Head/SLT and was told it would be looked at - approx 3 1/2 months later not a word, so I scrapped the idea and the project. I now have to start over and have a working setup buy next tuesday as SLT now want a meeting about it. So.... after much thought and over thinking things I have no idea which would be the best method/way to go. Do I go Intune, Azure AD Joined, (can I still always on VPN), Do I go Intune, Hybrid Joined so I can do Always On VPN for SIMS.net access - possible network drive access from home? Do I go Domain Joined, SCCM Managed and Always on VPN so full network access from home? Part of the ideal scenario is to remove RDS altogether and rely on AOVPN for network access/SIMS.net etc. Realistically I cannot see the school going cloud/server free in the next 5 years - some staff go into meltdown at the words OneDrive/SharePoint/Cloud Storage including turning a computer on! Hoping fellow edugeekers who have been on this journey can share their insights and talk come sense into me! Thank you all
  6. Any reason why I shouldn't run a Dedup Garbage collection manually in the day whilst users are using the system? Cheers
  7. Was off Thursday and Friday when my box arrived - come in this morning to find it had been ransacked by my techie and the finance manager Still I cannot complain as I am more than happy with what I was left with Thanks for the goodies @VeryPC
  8. I warned all staff a number of times and listed the software used in school which used flash - including 10 year old boardworks used in science. Had a couple of science staff come and complain that boardworks stopped working when i did updates very recently. I pointed out the warnings I emailed and how flash was a security concern and they should look at purchasing up to date software.
  9. I currently have 2 start menu layouts - 1 for staff and 1 for students and ideally I would like to reduce this to just the one. The student shortcuts contain all shortcuts for all programs regardless if the software is installed and the layout only shows the shortcuts. The staff shortcuts are generated by GPO by checking if software is installed. The staff layout allows them to see normal windows apps plug the generated shortcuts. How do other people do shortcuts and start menu layouts? Cheers
  10. I did a proposal which went though various things including comparing running costs over 5 years. I wanted to do all teaching rooms but head only wanted to do half as she was worried about lack is usage - which annoyed me slightly as 3 years later some rooms which were left now have failing projectors which I predicted. Depending on size of the room, if possible I would go bigger if possible. I did get various makes/models in for eval and asked staff to use them and they opted for Sharp due to having buttons on the front such as freeze and source buttons. Also after 3 years some staff complained about speaker quality - but my view is that is clear and loud enough to be heard at the back of the classroom it does the job.
  11. Thankfully my Exchange box had been powered down since Jan as I was moving VMs around and running updates and forgot to power it back up. Since all this faff with patching etc, though better restrict Exchange to MS Addresses only. Still in two minds if I should keep it off until I actually need to use it.
  12. I just looked at at this got quotes as SLT were interested at going forward and then everything ground to a halt as they wanted to discuss this with head of department??? I looked at Startech USB-C dock (MST30C2DPPD) had NIC, HDMI, Display Port and USB ports.
  13. I had the one from MS - was wondering if there was a quicker way of add the IP Addresses in bulk without adding them one at a time.
  14. Does Smoothwall have the Office 365 address ranges available to create firewall rules to only allow traffic between MS and On Premise Exchange Boxes that are configured in a Hybrid mode? I can create a new address object group but means having to enter each address one at a time - unless someone can tell me a quicker way. Thankfully my on premise box has been offline for over a month while I have been doing some moving of VMs and was to secure communication for when I turn it back on. Cheers
  15. What size labels do you use? Are they laminated or paper? Cheers
  16. For those who are using Parago - what kind of Barcode labels are you using? Do you print your own or purchase preprinted ones? If you print your own, what printer do you use? Cheers/
  17. Had a reply from Christie support with a few suggestions to the cause - one was the filter (it is a Cassette type which rotates a roll). They suggested reseating the filter - I laughed at the idea but tried anyway and don’t I feel stupid!! Reseating the filter worked!! Who knew that would have caused that particular issue.
  18. Anyone in the Manchester area know or recommend any companies that repair/service projectors? I have an out of warranty projector which I need a cost for possible repair. Cheers
  19. Can you talk me through your process as I must be missing something - this time round I’m struggling to save it once ive edited the dll file. Once edited I put the file back in the image. Cheers
  20. Anyone got this working on 20H2? Had this working on up to 1909 - tried on 20H2 and no luck (probably me being an idiot) so thought would check with other peeps. Cheers
  21. Have scrapped what I’ve done for certificates and SCEP and started again but this time looking at hybrid joined devices. Just gone through and done the config work just need to test it now.
  22. Ran the validation tests and all come back as fine - showing success on all areas. Will agree looks like a Certificate issue somewhere - will have to do some more digging and googleing....
  23. Talk about frustration! Setup NDES, Proxy App and all reportedly works. Export CA Cert and deploy via intune as trusted Cert. Next, create config profile for SCEP Cert - deploy out to my test laptop and the cert fails to enroll 1st Error in event viewer talks about SCEPInstallCertificateWithSCEPHelper failed to initalise SCPE enrollment with NDES Server - URL...... followed by CA Thumbprint. 2nd Error in event viewer gives this info - SCEP: Certificate enroll failed (The Signature of the certificate could not be verified) Checked on Laptop and Root CA installed - checked the thumbprint against and it is correct Anyone any ideas?
  24. Currently have Intune running with devices as AzureAD Joined only. Ideally I would like to have devices using a device tunnel so I can manage/update SIMS.net without user intervention - but this required devices to be AD Joined/Hybrid Joined - which will involve some more work on my part. Don't want to use User Tunnels as users need to authenticate before I can manage/update SIMS.net My other thought is to publish the SIMS.net Apps as a RDS App and place a shortcut on users Desktops - again not ideal, as means having to keep RDS in place when I am trying to move towards having less on-premise kit etc. So, fellow edugeekers..... what are your thoughts and opinions? Which method would you opt for and why? Cheers
×
×
  • Create New...