2097
Members-
Posts
1,077 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by 2097
-
Im looking to get this setup fully. Currently we have O365 Setup to our internal domain ( School.org) Exchange 2016 Local setup ( ExternalEmail.org) But as most know its a complete pain to get things working correctly ( especially Teams) without emails accounts being avaliable in O365 I am assuming i need to do the following Add ExternalEmail.org as an extra Domain Name in AD Setup the ADsync to sync this to O365 ( Also enable Hybrid in this ) Then setup Hybrid with Exchange local Once i do this, will this muck up peoples phones who have the outlook app pointed to our local Exchange ( Its still done via Autodiscover ) Im also assuming once i have done this , Staff members can then login to Exchange with their Email address instead of [email protected]
-
The whole thing of superiority when using a mac-book will always be in their minds. I doubt any Pc/laptop will come close and even when the PC is 100x better it will always be " What a load of rubbish, my 10 year old mac-book was much better". I wouldn't consult with them, just choose some good quality windows laptops and distribute as no matter what you get them, in their minds will be inferior.
-
Thanks for that , As i have the ESD file and windowsupdatebox.exe, i have just packaged it into an application for SCCM. Might be a lot easier to install that way
-
Also.. Have another problem . Im getting the message popup on each machine saying " Restart to install feature update" Unless you manually click restart on each one, it wont upgrade. Any way to automate this with a GPO setting ?
-
Yes i have already done that. Defiantly seems i need to add that file to the default user folder on each machine. Otherwise it seems to try and connect to the internet instead of WSUS to try and grab the file. Its my first feature update as we are already on 1909 and are new adapters to Windows 10
-
Hi , Did you have to do the above ? Or did it work ok for that update.
-
Has any one else tried updating to a feature update via WSUS ? I kept getting an install error , My network is setup so only outside access is via a firewall. Ultimately found the solution via https://social.technet.microsoft.com/Forums/en-US/3a8740cc-ccb0-4ebb-a209-25e08ccc6f61/update-win10-2004-is-not-installed-without-the-internet?forum=winserverwsus Seems a very backwards way of doing things.
-
[2004, 20h1] Windows 10 May 2020 Update is Now Available
2097 replied to Arthur's topic in Windows 10
Anyone been able to install this via WSUS ? Im getting errors -
[1909, ou] Forcing Change password at next logon - Breaking Start Menu XML
2097 replied to 2097's topic in Windows 10
I have office 2019 running currently , If you use any custom coded Access files be very careful with it. I had to go back a few revisions to get past various errors. Each update caused different issues. Also if you are using an in-house Exchange don't forget to add the custom registry setting to bypass it trying to connect to office365 first ! And if you use Eset Security like us , This needs updating to the latest client for 2004 to install -
[1909, ou] Forcing Change password at next logon - Breaking Start Menu XML
2097 replied to 2097's topic in Windows 10
Yep you are correct, 2004 seems fine with the password reset. Possibly the way to go. I have noticed though that my links to IE11 and File Explorer no longer work on 2004 which i assume is version specific. So the start menu tiles needs amending -
[1909, ou] Forcing Change password at next logon - Breaking Start Menu XML
2097 replied to 2097's topic in Windows 10
Very interesting ! i will update a machine and see what happens, as like you all my machines are on 1909. Thanks for trying. Seems we have the EXACT same problem.. So cant be a setup unique to us. -
[1909, ou] Forcing Change password at next logon - Breaking Start Menu XML
2097 replied to 2097's topic in Windows 10
Thanks for the reply eddy . Could you try the following for me please? Restart PC - Set roaming profile with password change - Login ( make sure it has a corrupt start menu).Dont logoff. Then goto another machine - And logon with the same user , let me know if that machine has a corrupt start menu. This will i hope show us its nothing to do inside the profile. Also what domain controllers are you running ? Server 2019 ? -
[1909, ou] Forcing Change password at next logon - Breaking Start Menu XML
2097 replied to 2097's topic in Windows 10
Hi Eddy , i hope you are still following this Do you experience this issue with Mandatory profiles also ? I dont . I also dont get it with roaming if the user does not have a profile yet . I think it could be something that stays in the Roaming profile's Registry. Have you managed to find out any more info ? -
[1909, ou] Forcing Change password at next logon - Breaking Start Menu XML
2097 replied to 2097's topic in Windows 10
Also.. Changing the password Via AD console also doesn't cause this issue. -
[1909, ou] Forcing Change password at next logon - Breaking Start Menu XML
2097 replied to 2097's topic in Windows 10
As i am in today i am picking this up again. Ok worked out the following Turn Machine on > Change password > Start Menu is Corrupt. Turn Machine on > Logon > Logoff > Change Password , Start Menu is fine. Then tried the following with 2 machines. Turn Machine 1 on > Change password > Start Menu is Corrupt. ( Didn't logoff so the profile didn't get updated) Turn Machine 2 on > Login as normal > Start Menu is Fine. So this doesn't look like its related to any files being stored in the profile. It seems more that the "Change Password" request is stopping something from loading correctly. Also to note . It is loading a corrupt variation of my Start menu , i can see a basic layout. Just all the tiles are missing apart from edge . Also all the start menu its self is missing lots. Also.. This isn't happening on "Mandatory Profiles" just seems to be roaming. -
Used it for the initial run to make sure all the staff get added ( im sure none have been there longer than 9999 days ) I then run it every 2 days (-2) to add new people who come into school ( i run these as a scheduled task to stop me having to do it manually )
-
Script 1 Import-Module ActiveDirectory $When = ((Get-Date).AddDays(-9999)).Date $Staff = 'C:\Scripts\Teams\CSV\Staff.csv' Get-ADGroupMember -Identity "Admin Staff" | Get-ADUser -Properties whenCreated | Select-Object UserPrincipalName| Export-Csv -Path $Staff –notypeinformation Script 2 Connect-MicrosoftTeams Import-Csv -Path "C:\Scripts\Teams\CSV\Staff.csv" | foreach{Add-TeamUser -GroupId GOUPIDNUMBER -user $_.UserPrincipalName} Change "Admin Staff" to AD group of your "Admin Staff" 2nd Script , Line 2 adds users exported from AD Admin staff into each Group you specify , add multiple lines for more groups ( you will need the group ID numbers )
-
I went from 2010 > 2013 > 2016 I had the choice of 2019, but 128gb is the same amount of memory as one of our VM HOSTS ! 2016 seems fine , will probably go cloud eventually.
-
Likewise enabled that The other week , Worked a treat
-
I tried for a while and couldnt get them to consistently work with mandatory & roaming. In the end i installed the "Classic calculator" and enabled the old photo viewer app via reg. Most UWP apps wont work correctly with unsupported profile types.
-
we had lots of problems with roaming profiles and printers on windows 10 in the end i used Printer Mapper - No hassle and reliable printer deployment across your organisation - 0x80070057 Parameter Incorrect Fixed Mapping works consistant on PC DNS names and User accounts Price is so cheap which saved me so much hassle. Was recommended on here ! so just passing on the info. FYI , i used both GP and kixtart with windows 7 and it worked flawlessly . Windows 10 was a no go with either !
- 7 replies
-
- group policy preferences
- papercut
-
(and 2 more)
Tagged with:
-
Turns out i could answer my own question. Heres some info for any one wanting to know. You cant remove people from search But ! you can remove certain attributes from syncing to the cloud which is ok for us. In the Synchronization Service i was able to remove some AD attributes such as Firstname and surname ( so only username is displayed ) also unchecked the email from showing as thats not needed atm But ! i did notice i couldn't do this with the current users , I had to remove all users , change attributes and re-add them again. Luckily i haven't allowed any one access yet so all is good
-
The problem being is we sync them with AD ( and we have them removed from exchange online) , As we have exchange onsite i think its picking up msexchhidefromaddresslists and populating the global address list. I have hidden a staff account using the msexchhidefromaddresslists set to true and it does in indeed disappear. Just wondering if i remove this attribute from the sync ( if possible ) will it remove them all from the global address list.
-
Did you manage to solve this ? I basically just want kids/staff to have access to Office and Onedrive . No online exchange. The kids when they login to office365 can see any user account using the search button. Pretty annoying !, Any way around this ?
-
Sure here are mine, decided against using Teams as i think im a little late to the game . We have a pretty sturdy setup with RDS and ShowMyHomework. First of all manually create 2 groups in office 365 , One for kids and one for staff. The following script checks for any new user accounts in the last 2 days and exports to CSV . I suggest changing the -2 to something like -5000 to import all your users in AD ( first run). Then set the script up in task scheduler to run every night ( Replace OU pathways to the pathways to your Kids and staff folders on the local AD). Import-Module ActiveDirectory $Kids = 'C:\Scripts\Teams\CSV\Kids.csv' $Staff = 'C:\Scripts\Teams\CSV\Staff.csv' $When = ((Get-Date).AddDays(-2)).Date Get-ADUser -Filter {whenCreated -ge $When} -SearchBase "OU PATHWAY" -Properties whenCreated | Select-Object UserPrincipalName| Export-Csv -Path $Kids –notypeinformation Get-ADUser -Filter {whenCreated -ge $When} -SearchBase "OU PATHWAY" -Properties whenCreated | Select-Object UserPrincipalName| Export-Csv -Path $Staff –notypeinformation Next script will import them into groups either kids or staff in Azure . Replace Admin name with AZURE admin credentials , Run the line commented below to encrypt a password. Also replace AZUREGROUPIDNUMBER with the groups you created in step 1 . You need to the GROUP ID NUMBER and not the name. #MS Teams Update By Luke 27.04.2020# # Run This line to Update MS Encrypted Password "Read-Host -Prompt "Enter your tenant password" -AsSecureString | ConvertFrom-SecureString | Out-File "C:\cred.txt""# Set-ExecutionPolicy Unrestricted -force $AdminName = "[email protected]" $Pass = Get-Content "C:\cred.txt" | ConvertTo-SecureString $Cred = new-object -typename System.Management.Automation.PSCredential -argumentlist $AdminName, $Pass Connect-MicrosoftTeams -Credential $cred Import-Csv -Path "C:\Scripts\Teams\CSV\kids.csv" | foreach{Add-TeamUser -GroupId AzureGROUPIDNUMBER -user $_.UserPrincipalName} Import-Csv -Path "C:\Scripts\Teams\CSV\staff.csv" | foreach{Add-TeamUser -GroupId AzureGROUPIDNUMBER -user $_.UserPrincipalName} I hope this helps you out
