Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. That's what's seriously lacking with W10, a decent set of policies! There's naff all for Edge and loads of areas that seem to be missed. I guess home users don't need policies so MS won't invest too much time creating them.
  2. TBH I'm sure that policy setting was there with Windows 7? I seem to remember setting it a long time ago!
  3. Hmm I already have this policy enabled so therefore GPO optimisation is already disabled on my w10 pcs
  4. Cheers folks, looks like the regex route is the way to go! I'll have a go at this and see how it goes.
  5. Not many about a dozen in all - for example we have a group for every student year group 7-13. So naturally we want Staff to be able to email all of those groups. But we don't want students in any of the year groups to be able to any of the year groups, only individuals within them. Its been requested as its been abused a few times, or when someone uses someone elses account!
  6. I think I'm too chicken as well - I might see what Mr Google has to say about it first!
  7. Yeah its a bit difficult to add permissions to google groups, I can't see a way to fully do what I want. Its possible to block the Staff group from students as I can set the Staff group to only allow Members to Send/Receive email - but if I then say I want the group Year7 to be accessible from Staff only, it falls apart, as the above method would stop anyone other than members of Year7 emailing their own group!
  8. I had a look at that, but I can't see a way to allow all members of a group to email another group (i.e just allow all of Staff to email all of students) I didn't want to add individual permissions for every staff member if I could avoid it!
  9. Is there any way to restrict the users who can email a group in G Suite? For example if I have a group called 'Students' and only want to allow the members of 'Staff' group to email the whole group? Obviously I would still want to allow individuals to email each other, but we've been asked to look into this. I used to do this fine with Exchange but can't seem to find a way with G Suite as the restrictions are quite basic (i.e Public, All Members of this Group, Whole Organisation etc)
  10. Everything is heading towards 1:1 - the mass panic to buy ipads for schools showed that they don't work very well unless they're 1:1 (G Suite Apps aren't multi user on these sort of things) I agree we need to adopt new ways and we are doing that, but the old ways are still in use in massive amounts of examples. I may be old school, but when it comes to any prolonged amount of typing/browsing I still always revert to laptop/desktop. Again its an example where MS could have offered W10 Home/Tablet Edition and W10 Business Edition, they are distinct areas of use and W10 could have worked well if adjusted to suit the environment.
  11. We're not that far ahead with our W10 rollout so its only in 2 areas at the moment, I aborted our W10 rollout months ago when I realised the core aspects were unreliable (start menu, printers gpo's applying, IE working, admx templates incomplete for Edge, applocker very flakey etc etc the list goes on) It seems like MS have given up trying with W10 as far as the workplace operating system.
  12. We have actually moved one of them onto another switch and it made no difference. With this being SSD based PCs I reckon W10 is just all about show - i.e look like its booted in seconds when in reality its not ready. Again, W10 seems to be home use ready but not domain use ready. I'd rather a 2 minute boot time and the PC be ready, than a 10 second boot that isn't loading scripts etc.
  13. We've got hardened paths set to the RequireMutualAuthentication=0 and RequireIntegrity=0 for SYSVOL and NETLOGON. Slow link detection is disabled on our network. I ran the script to check our GPOs and that didn't find anything to report. Its odd, in a room of 10, 3 will regularly generate these errors, however the others will be fine for days then generate them. One thing I have noticed is that if you reboot on of these machines, whilst running a ping test, the PC will be at the login screen for a good while (30 seconds at least) until the ping actually starts to reply! And the IP address hasn't changed as the DHCP lease is still at 1 day. So it does suggest the PC has booted up but isn't network ready. So much of this points to the poor support of W10 on a domain.
  14. Yes, all of these PCs are running SSDs - some are very new, some are old upgraded PCs. Using scheduled tasks might address some issues, but we run a script to delete old profiles on boot - we would have to schedule this out of hours. Saying startup scripts are dead seems to be MS's way of saying 'we can't get W10 to work on a domain properly' We're at 2008 R2 functional level, probably will move up this summer but I can't see that fixing anything. It does seem likely that the PC is booted up before the NIC is fully ready so delaying the netlogon service is worth a try. This is very frustrating as I would have assumed that W10 could cope with SSD and GB NICs! Obviously designed for the home market to show a 'fast boot' when really half the services aren't ready. We've also had the password issue - if you create a new user and set their passwords to be changed on first logon, it doesn't work on any W10 machines as it says their password is invalid -they have to use a W7 machine for their first login!
  15. The scripts run ok when run manually - and the paths are always unc\shares. I know the paths are correct as they are working on 100's of W7 machines and haven't been changed. It seems to be a pattern of Netlogon not seeing a domain controller, then not applying GPOs, then the GPOs logging the error that the script path wasn't found. I.e First error: Then: Followed by an error for each GPO that has a startup script: Which in itself is contradictory - if it can't see a DC and can't apply GPOs, then how it is finding the GPOs with scripts to 'not find' the paths! Stupid W10
  16. On our W10 machines we have a handful of .bat and some .vbs scripts for startup/shutdown and login/logoff. However we've just noticed none of thes are working. As usual they work fine on the Win7 machines! The errors being logged are either: or (more commonly) Neither of which is actually true. The PCs can resolve the paths in the first instance, and we're not blocking anything with group policy. We do use Applocker but that isn't logging anything as blocked. I'm rather worried now that W10 is making a right balls up of applying GPOs, as the deeper I look the more issues I seem to find! Is anyone else running scripts in GPO's with W10? I'm not sure why it thinks .bat .vbs are blocked by GP when I haven't actually got a policy that does that. Looks like I might have bigger problems, each one is also logging this on boot: Everyone can still login though, and they're all 1Gb connections so I'm not sure why they can't pull down policies or scripts.
  17. This is where departments and schools can vary. When we replaced a load of netbooks trolleys we have the departments the option of iPads or surfaces. It was split roughly 60/40 in favour of the ipads. A year later the surfaces are used regularly. The ipads very little, and we have had next to no requests for apps to be installed (we use meraki so little or no inconvenience) In fact some of the departments are just using the ipads as personal devices now. The ons left over from loss or damage anyway!
  18. Yeah this is all prep and practice for me moving a load of physical hosts to vms in a HA cluster - I must have changed the lockdown mode myself but don't remember doing it!
  19. Ah -ha! Brilliant, thanks for that. It was set to Normal and Disabling has let me back on. Nice one, I wouldn't have found that for ages. I'm obviously planning on using vCenter fully when my hosts are all online, but in the meantime I like the client for quick results. Help yourself to a hobnob!
  20. I'm just lobbed a vCenter appliance on one our esxi6 hosts to have a proper look and have added the host to the vCenter. This works fine and I can see this host and all the VMs ok. Problem is I can no longer login to that host directly using the vSphere client, I used to use the root login directly, but neither that or the [email protected] account (from the vCenter appliance) work. I'm baffled as to what I've missed? I've added the localos\root login in the permissions tab to manage that host through the vCenter configuration but it says 'you do not have permission to login to the server'. Trying the [email protected] results in teh message 'Cannot complete login due to incorrect username or password' I'd still like to use the vSphere client whilst familiarising myself with the vCenter tools, but is this not possible once a host has been added to vCenter?
  21. Having just had a department 'lose' yet another ipad I'm even more keen on suites. At least they don't diminish from 20,19,18,17....15 during the course of the year!
  22. So now we're beginning the task of splitting our vle from our GSuite domain to simply use Google (and GADS) - and as we created quite a few additional groups I was trying to find a way of dumping all of the groups into a csv file or similar. I just want a list of the actual groups, not members (I've found the way to do that for single groups) but I can't seem to find a way, has anyone found a way?
  23. I pretty much came to the same conclusion. Since 8 the start menu is a broken mess, and I hate using third party tools to replace what should be a part of the default system but ms can't be bothered to fix it so it's either classic start menu or we stick with 7 until a working version comes out. So far classic start has been pretty reliable, more than I can say for other parts of 10!
  24. Hmm, I think I must be doing something wrong still. I've set up some basic policies for macs on PM, enrolled a single mac and the settings have applied correctly according to the PM activity console (basic settings include AD directory for authentication and change the login screen to show username and password boxes) However, on the mac all I get is the single user (the local admin account) waiting for a password - like I would have got with WGM before I joined it to OD and AD. The mac itself isn't bound to OD or AD locally - the AD details are only specified in the profile. Have I got that the right way around?
  25. Thanks for the ideas - I'm going to have a plod through these and see if it helps!
×
×
  • Create New...