Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. It seems to take 5 minutes compared to when we ran OS X 10.7.5 with ad/od and it took less than a minute (on the same hardware) On the test accounts we've noticed it's put Everyone with full access at the root of the share! That's on 2012 servers hosting the shares. I wouldn't mind switching to profile manager if it was as flexible as wgm!
  2. I've progressed a bit now - only have the AD in the profile for authentication which seems to work. However profile manager doesn't allow us to define the layout of the dock for locally installed apps - unless they'e vpp ones. With WGM you could drag apps to the dock setup so now if the app isn't in the profile manager list then you can't add it to the dock. Looks like we'll be sticking with WGM for a little longer! I've also noticed it takes a stupidly long time for an AD account to login, not to mention the SMB share permissions on the Windows server get screwed up - it seems OSX 10 is not destined to play happy with Windows anymore.
  3. We use GAFE and I've noticed students using Drive to browse the SYSVOL and NETLOGON folder, and even uploading the files to their drive. Theres nothing secretive in there but I would like to remove this temptation! We have Chrome policy that blocks file://*/sysvol but this still allows them to browse the folder using chrome so that doesn't appear to work. How does anyone else deal with this? Chrome ignores any policies that block browsing for file:// paths so they can see anything that way.
  4. I'm just starting to look to upgrade our old 10.8 Macs to 10.12 and move from using WGM to profile Manager. I've setup up PM on the server and created some policies for users and devices, and added one device placeholder (a Mac by using serial number) into this to test - we don't have many macs so manually adding them is the easiest option. However, this test mac is still pulling through the WGM settings, rather than the newer PM settings. How do I force a device to use PM instead of WGM? The devices are all added to the OD server and AD server for authentication (OD for devices, AD for users) as previously working with 10.8 but I want to make sure the PM settings work on the test mac before updating all the others.
  5. I get the same result when trying on non IE browsers, it opens the Rdp and then requires a second login. This is a really basic single server setup for testing rds for certain apps. Everything is on one server and no HA setup or anything complicated as it is unlikely to be a live server.
  6. Yes, same wildcard domain cert on all. Oddly it works internally but externally is where this falls over suggesting I've missed something
  7. This is from rdweb, clicking one of the apps once logged in.
  8. This is the second dialogue box we see (on a windows 10 pc) but I notice the domain is blank - which suggests I've not configured something right? Even when I enter the domain\user and password it still fails saying 'The Login attempt failed'
  9. Our gateway is set the same as that, apart from the HA settings. It really is a basic test config so I'm wondering what I've missed here!
  10. Yup thats what we've got set - through the RDS settings in Server Manager. We have a valid SSL (wildcard) for the gateway and web access components as well.
  11. I've setup a test RDS server to see how well it will replace our aging citrix system and for the sake of the test everything is on the same 2012 R2 box - with only the basic wordpad/paint apps ready. Testing it internally works fine, but externally users get a second dialogue box (with the correct domain details) - but entering their details still doesn't work. I've had a look around and a few places mention policy settings but I've done these and it makes no difference. So i'm not quite sure a) why the dialogue appears and b) why, when a user enters valid credentials it still won't proceed past the second login dialogue? I'm just experimenting with RDS (like I say I've been using citrix for years) so a bit stumped?
  12. We've got lots of suites in our secondary and I've tried a few times to offer 'mobile' alternatives but generally the teaching staff seem to prefer the 'easy' option. I guess from a teachers point of view, would you rather take your 30 kids into a room where the 30 computers are pretty much guaranteed to work (and quickly) and be able to walk away again at the end of the lesson, or have to unplug a load of ipads/laptops fire them up, realise half aren't charged, wonder why a couple suddenly won't connect etc and then have to stash them all away again at the end of the lesson! Don't get me wrong I think mobile solutions have their uses, but in addition to ict suites. We've got a few notebook trolleys for blocks where a fixed ict suite is not possible and some trolleys of ipads for use in specific departments where they have a few apps they want to use. Our primaries all still have one suite with mobile devices used as well - which seems to be a happy balance.
  13. Yeah it uses its own grubby little protocol. The only way around is I'll allow traffic from the individual PC through the firewall when the Skype session is on. Smoothwall I think are of the same attitude that it needs unsafe rules opening for temporary use.
  14. Yeah its a pretty odd little program, even when specifying a proxy it heads off to the firewall, as well as the proxy.
  15. What a nasty little program skype is, it just scatters requests across http/s/ips all over the place. I don't think there is a realistic way I can get smoothwall to allow it through, without basically removing filtering and https inspection!
  16. Its only for a handful of users so not a big problem. Still can't get it to connect though, even logged in as an admin. Oddly though it seems to work on a couple of W10 machines, but not W7!
  17. Never seen that guide before, thanks! Can I ask what reg key you set, to make sure I'm doing the same thing?
  18. I know its an old problem, but I haven't found any recent solutions to this. Is there any way to allow the skype windows based program through smoothwall? I'vw whitelisted the skype sites, but I see a load of 407 and 503 errors going to a raft of https ip addresses. Even if I allow the category of https sites with ip addresses I get the same. Ideally I'd want staff to be be able to use skype but it looks like a mess to try and sort out. Looking at the firewall logs the pc we're testing on is hammering it on 80/443/37957 and lots of high ports so does it even work with a proxy properly?
  19. You're welcome, it was a complete pain to get working I admit!
  20. Ahh I've just double checked, I didn't just copy the file over, I used a batch file on machine startup to import the settings using DISM: dism /online /import-defaultappassociations:\\server\share\defaultassociations.xml Then I used the machine policy to point to c:\windows\system32\defaultassociations.xml for the "Set a default associations configuration file" setting. I tried so many things that I'd forgotten how I got this to work!
  21. Yes - but its a bit of a cludge like most Windows 10 things. We had to copy the default file associations xml file to the local pc using a script, then set the "Set a default associations configuration file" policy to point to the local file. If you try to point to a share or mapped drive for the xml it doesn't work, which is exactly how the start tile seems to handle it.
  22. This is the only way I found that worked - in conjunction with disabling the Action centre. Do you still get the annoying prompt even with those preferences pushed out?
  23. Just watches Nativity 3 with my daughter. Dear god what a terrible film on every level. Had to watch several episodes of walking dead just to clear my mind.
  24. Got it sorted, it was a mixture of problems relating to IMAP and also because of SSO from our VLE. Have to say Google support were very good on this one and slogged through it! Basically a user account became orphaned in Gmail when deleted from the vle - so we had to recreate the old account to allow gmail to migrate the mail to a new account.
  25. Well if anyone else is thinking of trying this with Netgear switches - don't bother. Its a bug in their firmware which isn't resolved. The only way I can resolve this is to ditch a load of their switches and replace them with HP or similar. Not a happy bunny as these are only 2 years old. Ironically some of the older crappier switches work fine, but the new 'Smart' ones are useless.
×
×
  • Create New...