Jump to content

Sheridan

Members
  • Posts

    4,144
  • Joined

  • Last visited

Everything posted by Sheridan

  1. We've just installed some new wireless kit to replace some old stuff, we're using the same NPS server for Radius and deploying our root CA via group policy. The NPS Server has a certificated from our CA which is valid and in date. However, our wireless Windows 7 clients won't connect anymore - they come up with the error: "The server presented a valid certificate issued by , but is not configured as a valid trust anchor for this profile." If you load up the certificates on the clients, you can see our CA is a Trusted Root CA in the list, so I'm a bit stumped as what its complaining about?
  2. These are machine deployed printers - using the \\server\printer name. It worked fine in W7 and was working ok in W10 until recently. And now it seems to be working again since I restarted the print service on the print server! I'll have to reboot a few of the clients to see if it starts playing up again.
  3. We haven't got any point and print restrictions set on our Win10 GPO's - we've deliberately cut the policies back to the minimum for a fresh start so they're all set to Not Configured.
  4. In our test room we've noticed that since updating to build 1511 none of the GPO deployed printers are working anymore. Each PC simply logs the error "Group Policy was unable to add per computer connection \\server\printer. Error code 0x57" The same GPO's are working on the Windows 7 machines so its not like the names or drivers are missing. The error code just seems to be a generic failure one as well. It does seem to work if you're logged in as an admin though. One thing this test room has proved is that W10 is a complete pain!
  5. We're about to upgrade our staff laptop to Windows 10 and ssd drives (if not already) and use bitlocker instead of true crypt. I must be mad.
  6. We use vpp for deployed apps and they use their own for free apps. It's so they can try free ones and paid ones under the vpp are under our control. We did initially just use the vpp account and install ones on request but they weren't happy with that!
  7. I can't be bothered with Apple if they're doing this. The affected user is just going to create a new Apple ID!
  8. How timely, our first batch of Staff ipads (where staff can use their own Apple id to buy free apps) and Apple have disabled their Apple ID! Not for security reasons, just buying a free book/app results in 'Your Apple ID has been disabled' No help available from Apple, and they can still login and view their Apple ID, so what are they supposed to do now! This is the downside of being at Apple/Google/etc mercy - their support is non existent.
  9. Off topic, but Uni and schools differ quite a lot. A secondary school student who wants to break a pc/tablet etc will do it, a uni student won't (in general) break a device that is helping them! My students have to be here, uni students are there by choice - worlds apart!
  10. I guess it would be older apps that would be the problem, even then I would opt for 'Run As' and pick an elevated user account to work around it.
  11. I work in a secondary school - some students will try to break things.That's the way it is. I have to make sure all IT suite and classroom computers are available as much as possible - that means preventing rubbish being installed and settings being changed that don't need to be. In all my years here I've never found an application that required admin rights (permission changes yes, but not specifically admin rights)
  12. We don't want to use Docs etc as these are multi user student devices. One the 1:1 staff devices we do use Gmail/Docs/Sheets Apps and they're fine
  13. We use https inspection on our smoothwall and our vle is based on GAFE - works fine everywhere. However the students shared ipads have never worked as a) Safari doesn't work with google drive/docs to allow editing and b) Chrome on ios just does not work with https inspection at all, despite the certificate being installed on the ipads. Is anyone else out there using GAFE on iOS along with https inspection? It seems like a non starter unless I remove the inspection.
  14. Thanks for that, but that still causes the network drives to disappear as its running it as an admin. However I did manage to find this and after a reboot it now seems to work!
  15. We've got an old Macromedia application that appears to still work ok in Windows 10, except that Windows 10 has decided it has to be run as administrator (the executable has the shield icon on it) It doesn't matter whether you have UAC on or off, it still will only run as administrator - which causes a problem as it doesn't recognise your mapped drives when it does run! Is there any way to find out why W10 thinks it needs to run this as an administrator, or force it to run it as a normal user?
  16. The reason I went back to edu with the classic start was really to hedge my bets in case LTSB turns out to be a dead end. Yes it does appear to be the Windows 10 we all need, but without the recent updates it had as many issues and bugs as Windows 8.
  17. I don't disagree with that, it was more of an observation. However many ipads anyone deploys they way they are managed will have to be quite different to the desktop/laptop stock.
  18. I think the problem we're seeing with ipads is that staff are constantly being told about a 'new app' which is this weeks 'best thing ever for ' so they want to try it right now! Next week the next best thing rolls along again etc....In the couple of years we've been supporting ipads the life expectancy of an app (free or paid) is very short apart from the core ones like Youtube etc.
  19. Been there! And gave up and went with Classic Shell - which makes using Edu/Ent a lot easier than ltsb. The Start Menu/tiles in 8/10 is a mess that MS don't seem to want to resolve.
  20. Some of our SLT have ipads that have their gmail and google drive on them, we simply enforced a password/pin lock on them to secure them - in the same way we insist laptops are encrypted or use bitlocker.
  21. We delegated Staff control on students account and give them this tool And we still get at least one a day coming to see us - I think they just like the chance to get out of a lesson!
  22. We moved away from the staff laptops a while ago (apart from some SLT and HODs) and every classroom has a decent PC in it (all SSD based). Staff are expected to use their own laptop/home pc as they all have one and can remote in to the school via Citrix or simply access the VLE for resource whilst at home. Keeps it simple and reliable for us - PCs are always online and ready for use, no cables to move around. In contrast in our primaries they all had laptops each and they were a nightmare, always missing power supplies, bent cables and broken ports from the constant movement. Most now have a PC in the classroom and they took the old laptops home! I should mention those who do have laptops do not have local admin rights, they have an 'offline' login which has more relaxed restrictions but they still can't install whatever they want.
  23. We blank the HDD and put back on the default OS (no matter how old!) and fill in a disclaimer type of sheet. This show the serial number and device types that have been donated. It basically says that we are not responsible for any repairs/damages caused etc by using the donated equipment. Once they sign it they can have the goods and everyone is happy! We've donated a lot of stuff this way and never had any complaints, most of the recipients never even seem to want a copy of the disclaimer.
  24. This looks like a good compromise. I think we'll have to let the staff have the freedom of trying apps (like its been said we don't have the time or background to pick apps) but also have a layer of control over the device. If I keep managing them with Meraki but allow the app store then presumably pushing apps from the MDM will work in conjunction with apps 'bought' under a personal Apple ID. There are some slighty iffy apps out there - wifi scanners and the like but nothing too horrendous (yet) unlike the play store which seems to have all sorts of garbage! Having said that, we notice a lot of staff in our school and primaries assume an ipad is the default thing to buy, then wonder to what to do with it when facebook isn't available.
  25. I think this may be where we are heading - getting a handful of staff to establish that an app is useful and then we deploy it. Students devices will get a similar treatment.
×
×
  • Create New...