LinkZ
Members-
Posts
91 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by LinkZ
-
Prevent saving to C: for controlled assessments
LinkZ replied to LinkZ's topic in How do you do....it?
I hadn't done this but i've added that to the group policy now and it unfortunately hasn't stopped it. We're using Windows 10 Education and I have seen the exam mode however from what I can gather this is mostly to enable you to launch an individual web page. The issue with controlled assessments is the students need to be able to use multiple products from the office suite (so for example the controlled assessment we have coming up soon uses both Word and Access) and the students will need to save this work to a network drive so I can't just run the machine in a sort of kiosk mode as the issue is in the save menu from these and other applications. -
I am trying to get our machines ready for running controlled assessments, part of my plan involves having separate user accounts for the controlled assessment users with a home drive mapped to a network location where students save their work to and we will be disabling the user accounts out of exams hours, however I am currently struggling with the issue of preventing the students from saving to the C: drive. I am using the usual group policies to prevent windows explorer access to C: (User Configuration > Policies > Administrative Templates > Windows Components > File Explorer > Hide these specified drives in My Computer & Prevent access to drives from My Computer) however this does not stop students from typing in a path manually in Word or Notepad, such as in the save as dialog typing c:\windows\temp\mywork.docx My concern with this is students entering the classroom for their first controlled assessment session and completing their work, then in-between sessions having access to the computer and making modifications to their work on the local disk and copying it onto their network drive during their next controlled assessment session. Due to the large number of potential folders and the impact it would have on Windows I can't modify the access rights to the folders in Windows, I am also unable to re-image the machines at the end of the exam session due to the rooms being general teaching rooms and the imaging process potentially taking 3 hours. How are you setting computers up for controlled assessments or has it just been deemed an acceptable risk due to the low number of students who would exploit this?
-
Hi, I have a HP SE326M1 server from @ICTDirect_Dave which uses a HP P410 controller, i'm having issues with some hard drives that i've purchased causing the fans in the server to spin up to 90% rather than the 45% it normally sits at. The server currently has 12 Toshiba 1TB 2.5" drives (Model no: MQ01ABD1) installed which all work fine, however I needed to get some additional space so I purchased 3 HGST 1TB 2.5" drives (Model no: HTS541010A9E680). When I install these the server will boot and the P410 controller will report an overheating issue with the HGST drives. Once in windows I can check in the HP smart storage admin and it will see the drives and report their temperature as 25-27C (which is within the accepted range) but while windows has booted the fans will ramp up to running at 90% which for this server is very noisy! I have run the HP Service Pack for ProLiant to ensure that all drivers are up to date. Unfortunately I am unable to update the BIOS or ILO version as it seems these model servers were custom made servers for Microsoft data centres so HP do not publish specific updates for these to the public. I have updated the P410 to the latest firmware (6.64). After speaking with Dave he has advised that other customers have purchased similar drives for the same server and not experienced this issue so i'm out of ideas as to what would cause this for me.
-
I don't see a UAC prompt due to the GPO settings I use, however if I disable UAC by changing the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\system\EnableLUA regkey to 0 the update will run fine. My GPO UAC settings are With debug mode on I get the following error when attempting to run the software update (SoftwareUpdater being the account with local administrator privileges that I have told 4Matrix to run all updates as) Logging in as the SoftwareUpdater account on the computer and running 4Matrix results in the update running successfully.
-
I'm getting the exact same problem as you Garacesh, I thought I was going mad so i'm kind of glad it's not just me having this issue! If I turn off UAC then the update will run perfectly fine but with UAC on and a local admin user account set to run the updates in the settings file I can't make it go through as a normal user. Very interested to find out the answer to this one.
-
We have a few students here that require translation software for their lessons, specifically Albanian <-> English, however we do not have internet access across the site. Can anyone recommend some software for offline translation that runs on Windows?
-
Google Classroom vs Office 365 Teacher Dashboard
LinkZ replied to CamelMan's topic in Cloud Services
As an alternative to Teacher Dashboard, Onenote Class Notebook (included with Office365) may be something worth looking at. I've started testing it today after seeing it at BETT and it seems quite interesting. -
Is there a statututory requirement to have a VLE (primary)
LinkZ replied to grinch's topic in Virtual Learning Platforms
As far as I remember the requirement to have a VLE was an old BECTA thing which has now gone by the wayside. -
The problem was with our Active Directory LDAP settings. The MaxPageSize was set to 1000 so after this is stopped returning results for the group membership including this user. Increased it and Profile Manager now shows him in the group. See https://support.apple.com/en-us/HT203264 for more info.
-
Our mac server is running OD and profile manager in order to customize user settings when users login to our client macs, it is also connected to AD in order to use the users and groups from there in profile manager so I don't have to re-create groups. I have applied custom settings to the AD 'Students' group so all students will get the same settings on any mac. This has been working fine however yesterday I was informed that 1 user was no longer getting their settings. I have checked in profile manager and for some reason that student is no longer listed as a member of the 'Students' group however they are still a member in AD. They also show as a member of the 'Students' group when i check via directory editor on the mac server. I'm stuck for ideas on why this one specific user (that i'm aware of) is no longer showing as a member of the group through profile manager only? Mac Server - OSX 10.11.1 Mac Server - Server Version 5.0.15
-
Terrible Outlook connectivity to O365 & I've no idea why
LinkZ replied to sonofsanta's topic in Cloud Services
We had similar here and it turns out it didn't like being set to online only mode. I enabled caching (only around 200mb) and it got rid of all those issues.- 8 replies
-
- 1
-
-
- exchange
- exchange online
-
(and 2 more)
Tagged with:
-
It was staring me in the face the whole time I was too focused on the Failed auth for target NETWORK LS: message.
-
That was exactly it Ben, thanks! I have an applescript setup to mount the AD users home drive on login, the script was in the right place however there must have been some issues with it as I copied it back over from the mac server and logins work fine now. I don't suppose there is a log file anywhere that would have given me a hint towards this? All I really have is the ambiguous error message from the mac server, i'm assuming there must be a log file on the client that i'm not aware of that would have pointed me in the right direction.
-
I've checked our internet filter logs and it shows all internet requests were allowed (I wasn't aware that they received settings from apple rather than the server, but it shows the URL http://init-p01st.push.apple.com/ being used which was allowed) so I don't think this is the issue. When I register the device via the mydevices site it installs the remote management profile for the initial settings then it successfully installs the device settings configured in profile manager. It seems to just be the settings which have been applied to users that it struggles to deploy.
-
I am having issues trying to push settings to some of our macs. We have 15 client macs in total running OS X 10.10.5 and a Mac server running OS X 10.11.1, 13 of the client macs work just fine however 2 of them will fail whenever profile manager tries to push settings to them even after removing the devices from profile manager and re-enrolling them. The only error I can find in the log files on the server is in the php.log file: 1:: [68478] [2015/11/06 08:57:43.245] <> Time since script start: 102675us [https:///devicemanagement/api/device/mdm_checkin] 1:: [68478] [2015/11/06 08:57:43.245] <> >>> Processing PUT mdm_checkin 0:: [68478] [2015/11/06 08:57:43.248] <> checkin: "UserAuthenticate" 0:: [68478] [2015/11/06 08:57:43.317] <> LabSession_for_incoming_request: LabSession for UserID 567574ED-776D-4DDA-B2FB-65F3D06AE896, UDID ef75817a037f517f9209731bca5657b3: NETWORK LS: 1:: [68478] [2015/11/06 08:57:43.317] <> Found target NETWORK LS: 0:: [68478] [2015/11/06 08:57:43.317] <> Failed auth for target NETWORK LS: , incoming_request={ 'MessageType'=>'UserAuthenticate', 'UDID'=>'ef75817a037f517f9209731bca5657b3', 'UserID'=>'567574ED-776D-4DDA-B2FB-65F3D06AE896' } 1:: [68478] [2015/11/06 08:57:43.391] <> <<< Sent Final Output (555 bytes) - PUT mdm_checkin 0:: [68478] [2015/11/06 08:57:43.392] <> Completed in 249ms | 200 OK [https:///devicemanagement/api/device/mdm_checkin] 1:: [68477] [2015/11/06 08:57:43.434] <> Time since script start: 39701us [https:///devicemanagement/api/device/mdm_checkin] 1:: [68477] [2015/11/06 08:57:43.435] <> >>> Processing PUT mdm_checkin 0:: [68477] [2015/11/06 08:57:43.438] <> checkin: "UserAuthenticate" 0:: [68477] [2015/11/06 08:57:43.452] <> LabSession_for_incoming_request: LabSession for UserID 567574ED-776D-4DDA-B2FB-65F3D06AE896, UDID ef75817a037f517f9209731bca5657b3: NETWORK LS: 1:: [68477] [2015/11/06 08:57:43.452] <> Found target NETWORK LS: 0:: [68477] [2015/11/06 08:57:43.453] <> Failed auth for target NETWORK LS: , incoming_request={ 'DigestResponse'=>'Digest username="",realm="",nonce="qu17qK4Lfm/Q52zXWIaoHG+LNAaYQzrNS9EiEAyAK6Ub07py",nc="00000001",cnonce="hv+5H9P3/KTjKTKlQUW5IidtJXmHf35bSc38oDwl39avav3R",qop="auth",uri="/",response="37803f338fee398a9508b0eede75148d"', 'MessageType'=>'UserAuthenticate', 'UDID'=>'ef75817a037f517f9209731bca5657b3', 'UserID'=>'567574ED-776D-4DDA-B2FB-65F3D06AE896' } 1:: [68477] [2015/11/06 08:57:44.254] <> <<< Sent Final Output (277 bytes) - PUT mdm_checkin 0:: [68477] [2015/11/06 08:57:44.254] <> Completed in 858ms | 200 OK [https:///devicemanagement/api/device/mdm_checkin] 1:: [36130] [2015/11/06 08:57:52.041] <> Time since script start: 27362us [https:///devicemanagement/api/device/mdm_connect] 1:: [36130] [2015/11/06 08:57:52.041] <> >>> Processing PUT mdm_connect 0:: [36130] [2015/11/06 08:57:52.051] <> LabSession_for_incoming_request: LabSession for UserID 567574ED-776D-4DDA-B2FB-65F3D06AE896, UDID ef75817a037f517f9209731bca5657b3: NETWORK LS: 1:: [36130] [2015/11/06 08:57:52.051] <> Found target NETWORK LS: 0:: [36130] [2015/11/06 08:57:52.051] <> Status="Idle" 0:: [36130] [2015/11/06 08:57:52.076] <> EXCEPTION: 500 Internal Server Error - ExecuteSQLFunction: attempt to call function 'dm_auto_update_all_profiles_for_mdm_target' without a schema defined. at #0 /Applications/Server.app/Contents/ServerRoot/usr/share/devicemgr/backend/php/db.php(227): DieInternalError('ExecuteSQLFunct...') #1 /Applications/Server.app/Contents/ServerRoot/usr/share/devicemgr/backend/php/mdm_connect.php(88): ExecuteSQLFunction('dm_auto_update_...', Array) #2 /Applications/Server.app/Contents/ServerRoot/usr/share/devicemgr/backend/php/db.php(396): _connect_transaction_1(Array) #3 /Applications/Server.app/Contents/ServerRoot/usr/share/devicemgr/backend/php/mdm_connect.php(128): PerformInTransaction('_connect_transa...', Array) #4 {main} 1:: [36130] [2015/11/06 08:57:52.077] <> <<< Sent Final Output (26 bytes) - PUT mdm_connect 0:: [36130] [2015/11/06 08:57:52.078] <> Completed in 63ms | 500 Internal Server Error [https:///devicemanagement/api/device/mdm_connect] 1:: [70030] [2015/11/06 08:57:52.309] <> Time since script start: 6211us [https:///devicemanagement/api/device/mdm_checkin] 1:: [70030] [2015/11/06 08:57:52.310] <> >>> Processing PUT mdm_checkin 0:: [70030] [2015/11/06 08:57:52.312] [FILTERED] 0:: [70030] [2015/11/06 08:57:52.320] <> LabSession_for_incoming_request: LabSession for UserID 567574ED-776D-4DDA-B2FB-65F3D06AE896, UDID ef75817a037f517f9209731bca5657b3: NETWORK LS: 1:: [70030] [2015/11/06 08:57:52.321] <> Found target NETWORK LS: 1:: [70030] [2015/11/06 08:57:52.388] <> <<< Sent Final Output (0 bytes) - PUT mdm_checkin 0:: [70030] [2015/11/06 08:57:52.388] <> Completed in 84ms | 200 OK [https:///devicemanagement/api/device/mdm_checkin] 1:: [68478] [2015/11/06 08:57:52.638] <> Time since script start: 6456us [https:///devicemanagement/api/device/mdm_connect] 1:: [68478] [2015/11/06 08:57:52.639] <> >>> Processing PUT mdm_connect 0:: [68478] [2015/11/06 08:57:52.647] <> LabSession_for_incoming_request: LabSession for UserID 567574ED-776D-4DDA-B2FB-65F3D06AE896, UDID ef75817a037f517f9209731bca5657b3: NETWORK LS: 1:: [68478] [2015/11/06 08:57:52.648] <> Found target NETWORK LS: 0:: [68478] [2015/11/06 08:57:52.648] <> Status="Idle" 0:: [68478] [2015/11/06 08:57:52.717] <> Sending request "InstallProfile" as CommandUUID=858C8E8E-D58B-4CDF-93D0-1981C131BA45 1:: [68478] [2015/11/06 08:57:52.722] <> <<< Sent Final Output (25572 bytes) - PUT mdm_connect 0:: [68478] [2015/11/06 08:57:52.722] <> Completed in 90ms | 200 OK [https:///devicemanagement/api/device/mdm_connect] 1:: [68477] [2015/11/06 08:57:55.732] <> Time since script start: 9443us [https:///devicemanagement/api/device/mdm_connect] 1:: [68477] [2015/11/06 08:57:55.732] <> >>> Processing PUT mdm_connect 0:: [68477] [2015/11/06 08:57:55.742] <> LabSession_for_incoming_request: LabSession for UserID 567574ED-776D-4DDA-B2FB-65F3D06AE896, UDID ef75817a037f517f9209731bca5657b3: NETWORK LS: 1:: [68477] [2015/11/06 08:57:55.742] <> Found target NETWORK LS: 0:: [68477] [2015/11/06 08:57:55.742] <> Status="Error" CommandUUID=858C8E8E-D58B-4CDF-93D0-1981C131BA45 0:: [68477] [2015/11/06 08:57:55.742] <> ErrorChain: [ { 'ErrorCode'=>-319, 'ErrorDomain'=>'ConfigProfilePluginDomain', 'LocalizedDescription'=>'The 'Loginwindow Preferences' payload could not be installed. One or more login items could not be installed.' } ]
-
Yep, in SIMS go to Tools > Setups > Behaviour Management > Behaviour Type / Achievement Type and in each type untick the 'Include in Register' box.
-
Ok a bit of follow up. I found a post https://social.technet.microsoft.com/Forums/windows/en-US/72b9fc06-d550-4621-a763-ddb96eb5441a/printer-mapping-using-gpp that says try turning on CSE logging in group policy to get some verbose logging for printer deployments. When I turn this on the printers connect just fine (which really confuses me)...the problem is i'm going to have tons of logs files littering the computers every time someone logs on so i'm reluctant to leave this turned on.
-
I've been pulling my hair out for a few days trying to solve this and i'm running out of ideas. I am having problems with users printers either a) not being mapped on login b) being removed while logged in c) getting printers mapped for each computer they login in to and having these printers stay on their account rather than being removed on login and only show the rooms printer. I have a group policy setup which contains all the printers in User Config > Preferences > Control Panel Settings > Printers which contains all the printers (with the action set to update) and item level targeting so only the computers in a specific OU get given the printer (these OU's are based on the machines location so we have a separate OU for each classroom). I have a printer set to order number 1 which has the 'Delete all shared printer connections' option set to try and counter the issue of accounts picking up every printer they get connected to. The group policy also has Computer Config > Policies > Administrative Templates > System > Group Policy > Configure printers preferences extension policy processing set to not apply during periodic background processing. This group policy has been set at the top of the domain so it applied to all computers and users. The printers not being mapped on login seems to be contained on a user basis as I have 2 test accounts, 1 where the printers do not get mapped at all and I can't find anything in the event log for it, and another test account which gets the correct printers on several different computers. I can't find anything in the event log that says why the printers weren't connected so i'm a bit stumped. We're using roaming profiles for our staff accounts which are the accounts being effected.
-
I use logon/logoff scripts to copy the bookmark files from the local appdata to the users home folder and back again. http://www.edugeek.net/forums/internet-related-filtering-firewall/109216-chrome-bookmarks.html#post1015582
-
Run the following from the command line on your KMS host server slmgr /dli all That will show you what codes you have activated and how many clients have activated. I believe office 2013 clients only properly activate when at least 5 clients have attempted to register with your KMS host.
-
An easier way to install this without manually editing a config.xml is to run the setup.exe file with /admin on the end from the command line, that will open up the office customization toolkit. Run through that to set any custom settings you want and it will generate an MSP file. Put that in to \x86\updates then whenever the setup.exe is run on any machine it will automatically pick up the settings you put into that MSP file. To install it via group policy create a batch file with the following (adjust the paths as necessary) and run it as a shutdown script setlocal REM ********************************************************************* REM Environment customization begins here. Modify variables below. REM ********************************************************************* REM Get ProductName from the Office product's core Setup.xml file, and then add "office15." as a prefix. set ProductName=Office15.PROPLUS REM Set DeployServer to a network-accessible location containing the Office source files. set DeployServerx86="\\Shares\software$\default\Office2013\x86\setup.exe" REM ********************************************************************* REM Deployment code begins here. Do not modify anything below this line. REM ********************************************************************* REM Check for 32 and 64 bit versions of Office 2013 in regular uninstall key.(Office 64bit would also appear here on a 64bit OS) :ARP86 reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\%ProductName% if %errorlevel%==1 (goto Officex86) else (goto End) :Officex86 %DeployServerx86% REM If 0 or other was returned, the product was found or another error occurred. Do nothing. :End Endlocal
-
Article: Happy SysAdmin Day 2015 - Now here is a prize
LinkZ replied to ZeroHour's topic in Legacy CMS Comments
Happy sysadmin day! And it's made all the better by there being no students or teachers in the school! -
DirSync is free and works really well Synchronizing your directory with Office 365 is easy - Office Blogs
- 5 replies
-
- active directory
- help
-
(and 1 more)
Tagged with:
-
Nice, there's some motivation for me to carry on reading my powershell book!
-
Try the CSV version I edited in instead, also paste this into the powershell ISE rather than a console and run it from there. In your output it seems you haven't changed the location for the CSV, have you created this folder structure on your machine and pasted yours there? Otherwise edit the location in the script.
