Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. Well thanks Apple, got my family to update their apple devices to ios 18(ipads, phones and macs) and 24 hours later facetime is borked across every single one of them! None will sign in, none work. Either stuck 'verifying' or simple hang in the settings page. You'd think facetime would have been part of the testing process...
  2. I wonder if this latest update to ruin the start menu experience is also responsible for removing the 'Pin to start' option in the context menu - previously I could pin anything to the pinned list, now it only appears for seemingly random items! The original setup worked fine, I wish they'd stop messing around with it
  3. Yeah I think it just makes it clunky feeling, so I've bunged the logoff shortcut back onto the desktop, like I used to for Windows 7...
  4. Is it but we have this switched off for students
  5. I notice our Windows 11 (hybrid joined) PCs have change the sign out option so its now Click the user name, then the '...' and then Sign Out (and the 'Manage my account option has appeared as well) Is there any way to revert this back to the simple options, as people are already complaining, and in a way I agree its less obvious than before and an unnecessary extra step?
  6. I think a software solution might work best for us, as we're a couple of years away from a new build - so any investment in current infrastructure is highly unlikely (although we're trying to also move to cloud phones so that would be portable anyway!) Having said that - the new build keeps getting postponed and a change of government isn't going to help either!
  7. Sounds like the sds cleanup is a broken thing. I’ll try a script tomorrow but 2500 lines will take a bit of time!
  8. Powershell is a backup option, but I’d only need to include SDS created groups Do you have the powershell script available for me to have a look at?
  9. Slightly non tech question, but how do your teaching staff alert SLT/first aiders etc from a classroom in the event of an emergency/issue etc? Do you have classroom phones (which seem a bad idea to me!) or other methods? I've used SIMS emergency alert but that's only any good if you're signing into SIMS every period (and we used classcharts predominantly) I'm even thinking of knocking up a basic desktop app that when run sends a message to specific users 'i.e Medical issue in Classroom 1 - send first aider asap'? Email etc are too easy to miss and staff mobiles are hit and miss I've used a system in a past role, but that was the reverse as it sent an alert to all powered on desktops from a manager console and was used for important announcements/fire alarm false alarms etc - it was bought in for the event of a lockdown situation which fingers crossed never arose
  10. I needed to run our SDS Group Cleanup for our SDS/Salamander synch - I ran the report and checked everything in there was SDS generated and ran the group cleanup using the generated report. This ran for maybe 30 minutes and came back successful However all the groups still showed in Teams admin, so I ran the report again - and 8 hours later the report is still being created! Something not right there I think I take it this isn't a normal delay for group cleanup reports? I can't cancel or restart the report so I'm stuck and MS will take weeks to bumble through any support cases based on previous experience
  11. You nailed it! It was buried in one of the exception lists - I feel a bit dense for not finding it but admittedly I skimmed those lists too quickly initially
  12. Our smoothie is set to use Negotiate/Kerberos Authentication and generally seems to be working (I've not been at this school too long!) but I've noticed and issue when trying to allow a group of sites (i.e Remote access Teamviewer) for specific users At the very top of our policy list is an allow list for those sites, with users specified in the domain\username format. At the bottom of our policy list is a default block list which blocks those sites for everyone else However it blocks it for the allowed users, and when I check the logs the access to (for example) teamviewer.com are coming through as the IP Address in the user name and the code 200 and being picked up by the catch all rule at the end Am I being thick here as I can't see what I've done wrong? When I check the Domain settings (using the Diagnose option) it all shows OK with green ticks all the way
  13. I've seen that, but also seen posts saying that the drive is missing after a VM reboot, as it thinks its still on the previous datastore (presumably as it wasn't done the 'licensed' way) I think I'll try it out on a non important vm and see if that works!
  14. As the title says, I'm in the position where I could really do with moving one of a VM's drives to another datastore to release some space. The school only has 3 hosts and a SAN - with 3 stores setup. The license is only Essentials plus for Exsi 8 so doesn't come with the useful stuff! So is there a way to move a single drive (not all of the VM's drives - just one of the bigger ones) to another datastore using the basic tools? Can I just power it off and move the drive that way or does it have to be Migrated using the storage vmotion that they don't have? I've never had to do this for a single drive on a Essentials license before so I'm not sure whats the best way, or is the best way to get a trial license for 30 days!
  15. Anyone else having issues with InTouch? Connection test shows an error: [h=2]502 - Web server received an invalid response while acting as a gateway or proxy server.[/h] Not sure if this is related to this mornings global issues!
  16. Not yet - logged it with MS who don't seem to know either and keep referring me to the article that refers to the missing option!
  17. Thanks all, I think this needs a tidy up - basically theres a rule to block access from outside the UK applied to all staff/students. Then there are multiple rules to allow specific staff access from various countries, so obviously this has been added piecemeal over time. So one rule allows access to 3 staff from the USA, another allows access to 2 staff from Portugal and so on, so this probably hasn't ever worked with the Outside the UK block being more restrictive! I think my best option is to have a single rule, block access outside the UK (with GA accounts/admin accounts as exceptions!) and then put users into an exception group as well - keeps it simpler
  18. Anyone else using Viva Engage? We have a few staff using it, but the issue we have is the default community called All Company (shows its not intended for Edu!) allows anyone to post, which as you can imagine the students are messing around with! So the MS answer is officially to go to the Options in that community, pick the Settings and chose the option to allow only Admins to start a post/conversation. But there is no Settings available for All Company, even as a GA - its there for all other communities but not this one, which I believe is a default/system one we can't delete Just wondered if anyone had this issue as well, and if there is a workaround?
  19. Yes, its a blank CA policy to deny, then separate policies for each country to Allow - but they seem to be overlooked so I'll have to just add the users into the Excluded part of the main rule
  20. I've inherited an Azure tenant, and one thing I've just noticed is is has conditional access policies to block access outside the UK, and then specific Allow policies to allow some Staff access from various European countries (school trips etc) But it appears this isn't working - I can see in the Sign in logs MFA is satisfied, then the rule to block access outside the UK is a result of 'Failure' and the rule to allow access from Italy/France is simply not applied - even though the log shows access is attempted from that country! The user sees a message saying access is blocked. When I run the diagnostics it shows the 'Outside UK' rule has been applied, and suggests adding an allow rule for that country, which is already in place So do these location rules actually work? It seems like they're just ignored during sign in
  21. Well my latest testing of this terrible system have got me no further - in the logs it appears to copy the files across (which appear on the client) and thats it 2024-06-26 12:44:23.8252|Info|Attempting to log on as specified user. 2024-06-26 12:44:23.8409|Info|Attempting to impersonate specified user. 2024-06-26 12:44:23.8409|Info|Target directory is: \\pc-01.domain.local\C$\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp 2024-06-26 12:44:23.8409|Info|Checking target directory exists: \\pc-01.domain.local\C$\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp 2024-06-26 12:44:23.8881|Info|Copy complete. 2024-06-26 12:44:23.9039|Debug|pc-01.domain.local Checking queue availability. 2024-06-26 12:44:23.9039|Info|pc-01.domain.local - installing the agent 2024-06-26 12:44:23.9039|Debug|pc-off-01.domain.local Sleeping. 2024-06-26 12:44:23.9197|Info|pc-01.domain.local Attempting to start remote process: msiexec.exe /lv* "C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\pc-01.domain.local_agent_install_log.txt" /i "C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\SOLUS3AgentInstaller_x64.msi" /qn AGENTSERVICEADDRESS="net.tcp://pc-01.domain.local:52966" DEPLOYMENTSERVERADDRESS="net.tcp://sims-server:52965" AGENTID="" RSAKEYPATH="C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp" 2024-06-26 12:44:23.9197|Info|pc-01.domain.local Started 2024-06-26 12:44:23.9197|Info|Attempting to create ConnectionOptions with username='domain.local\user' 2024-06-26 12:44:24.1251|Info|pc-01.domain.local Installation worker completed. So it copies the files, tries to run the installer. Then thats the lot, no errors logged either on the server or client. I'm thinking about reinstalling the whole lot again but it seems to be 99% of the way there! I did wonder whether AppLocker was an issue but nothing is logged by applocker at all
  22. Well I found a workaround, run the downloaded installer (so Solus is lying about not being able to contact the PC!) in C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp and set the server and key path manually and it installs. And if its a target in Solus it then pulls down SIMS. Solus3 - I give up trying to get you working.
  23. I've also checked that the client can connect to the server on port 52965 (I believe the server connects to the client on 52966 - which doesn't work as the solus client isn't installed!)
  24. I deployed it to a W11 machine a week or so ago, so I would have thought it was OK - although I had to do a manual install (mainly due to a rename of the machine causing solus to get confused because of cached DNS entries, and I was in a hurry!)
  25. I know this is a common issue, but I've now got a couple of newly deployed W11 desktops that simply will not install Solus/SIMS and always return 'the remote machine cannot be contacted' The machines get the same GPO as the others which set the firewall ports, and from the Solus/SIMS server I can browse the PC's drives, and rdp to them so not a DNS issue I'm stumped so I copied the client install files to them to try an manually install it - and this is where something new happened - when I run the 'Solus3AgentInstaller.bat' file - it opens in a command window and just sits there - nothing else happens! I've run this on other W11 machines, so I don't think its the OS - but I've run through the usual solutions and nothing seems to be working this time?
×
×
  • Create New...