Jump to content

mrstrong

Members
  • Posts

    755
  • Joined

  • Last visited

Everything posted by mrstrong

  1. but if say moving everything to azure would increase "IT budget" by £10,000 you could sell it by saying you'll save you £15,000 on the leccy bill ! Also always a bit baffled why secondaries seem to have/need so may servers especially after reading a bit about azure AD / intune.
  2. ah ok so its the clients that get the NTLM response from smoothwall (HTTP Proxy-Authenticate response header) but they aren't "coded" to work with that type of authentication? As far as I'm aware everything is "working" (though maybe not optimal!) using NTLM auth (for domain PCs/ laptops) (plus ipads / chromebooks are on a transparent proxy (no auth: staff or students for unauth requests)) Will put idex on my (long) list of stuff to investigate
  3. interesting thread! I don't get massively involved in budgets but is power usage something you have to account for in your "budget requests" / overall strategy ? I guess it doesn't ultimately matter which pot it comes out of as it's still a cost to the school. When you're looking at "cloud" I guess you mean running your "servers" as VMs in azure for example ? Just started looking myself at azure / intune and would it not be possible to run a secondary school with a fully cloud intune solution (ie. no virtual servers and no hybrid / on-premises either)?
  4. We have a few of the samsung galaxy tabs. I tried to set up in gsuite (for free) with work profile but was soon in a world of pain. Ended up just configuring each one manually (also slow and painful!) and now just let staff manage themselves. (e.g. give them a google account for play store). Android were bought as they were "cheaper than an ipad" to save money but false economy in my opinion. Got to admit new ipads with DEP and MDM just work.
  5. Our LEA (who set up the smoothwall for us) recommended not to use iDex as it had a few "issues". To be fair this was a few years ago so maybe things have moved on. @ibpalle thanks for the 407 info, still a bit confused about the groups logged though e.g. Staff vs Unauthenticated IPs vs "nothing" ? Also is the first 407 coming straight back from the smoothwall and in it's http response it is telling e.g. chrome to provide authentication via NTLM, so then chrome sends the user as domain\user, smoothie looks them up in AD, assigns to staff group then makes request to web server, all ok 200 so returns page to chrome. But you say "...in your case, a lot of these 407s are due to the fact that the software cant respond to a NTLM request" by software do you mean the web server ? I thought the NTLM auth request was just for the smoothwall to know who was making the request, not actually used to get page from server ? (not doing any https inspection for staff in case that makes a difference)
  6. sorry if in an earlier post but can anyone clarify how you apply for this or will the DfE contact the school if we're eligible ? we're running mostly UniFi AP-Pro about 7 years old (running over older cabling (> 15 years) so some will only connect at 100FDX) Fairly reliable just rebooted an AP been up for over 200 days, a few go "disconnected" but unplugging the POE at patch panel fixes)
  7. kid came in today upset with a dropped chromebook with smashed screen. I was trying to be nice, " ... accidents do happen etc .." when he exclaimed "April Fool!" He had some kind of background that looks exactly like a smashed screen! Totally got me
  8. Hi, we are using NTLM authentication (terminal services compat mode) through a non-transparent proxy to smoothwall Seeing a lot of 407 returned e.g. even to our wsus server In web filter log get various combinations for Username Source-IP and Group e.g. (ip-adr denotes a 172... ip address) Username Source-IP Group ip-adr ip-adr Staff ip-adr ip-adr domain\user ip-adr Staff ip-adr ip-adr Unauthenticated IPs Could someone explain these four different "types" of log entry, e.g. the 3rd one, domain\user ip-adr Staff, is what I would expect to see (?) so what "causes" the other three types ? Most have return 200 so I guess its working ok, would just like to understand what's going on! There's also quite a lot of of 407s eg Username Source-IP Group Code URL Category ip-adr ip-adr 407 http://wsus-server-dns-name.local:8530/Rep... - ip-adr ip-adr 407 https://teach.classdojo.com ClassDojo App ip-adr ip-adr 407 https://oneclient.sfx.ms Microsoft Office 365 ip-adr ip-adr 407 https://www.googleapis.com Connect for Chromebooks None of them seem to have a Group. Whats the correct way to fix these ?
  9. would the LUN backup try and do the "whole LUN" though, I would only really want to create an offline backup of the latest windows server backup to a usb drive. The synology has no volumes listed in Storage manager and the option to create one is greyed out. There is one storage pool: capacity is all used for the iSCSI LUN is this a bit odd e.g. is it normal practice to create a volume (which I guess also creates a storage pool at that same time) Perhaps I can't create a volume now as the storage pool has all been used by the iSCSI LUN. Maybe if I deleted the iSCSI LUN, created a volume then re-created the iSCSI LUN I would be able to access individual backups on the synology and copy them off to a usb?
  10. yes lightspeed can be a bit frustrating at times, you could try a live support chat as you can send them the web url and they are able to see what you see
  11. thanks, yes I want a completely offline backup, think I will try adding a few usb drives to WSB e.g. via WBADMIN ENABLE BACKUP -addtarget .... and then rotate them. Hopefully should work with the exiting Synology NAS drive (the iscsi target)
  12. Hi, looking at options to simplify our offline backups (and make the process quicker and more robust) Current setup is: Windows Server Backup on the VM host to a Synology NAS (over iscsi ) To do offline backups I currently manually run a backup once to another NAS using a UNC path then copy files to usb from that! Originally I had hoped I could just copy the files from the synology to a USB drive but weirdly it seems to have been set up with no volumes only a storage pool, is this standard practice for NAS / iscsi ? Anyway with no volumes on the NAS it won't let me copy to USB. I guess I could reset up the NAS with volumes, then recreate the iscsi target and backup job in WSB ? Or as I have another NAS, could I just add that as a second iscsi target and then add that as a second destination in WSB ? Or maybe just add a few external USB as extra targets/disks in WSB and rotate ? Or perhaps it is finally time to investigate veam (would have to be the free version as no £ left!)
  13. yes worth getting mac to use a cache server. Sounds like you're nearly there, once you get them erased and assigned a profile in lightspeed with "Shared Device: false" it should all just work. Also somebody mentioned tags in jamf, lightspeed doesn't seem to use tags, rather groups which are worth planning in advance a bit like OUs in AD, can get confusing with inheritance etc. E.g. we have two groups Pupils and Staff, each group has their own apps, restrictions, wifi, web shortcuts etc. Sometimes an ipad has been put in Staff and Pupil groups so it gets "all" of the apps for example but then it also gets Pupil restrictions so e.g. can't erase etc! This has caught me out a few times. Not sure if lightspeed have any articles on best practice setup as I'm sure the way we've got it is not optimal (I inherited the setup)
  14. interesting thread, not read all in detail but we have lightspeed and ipads working "ok" (-ish ). If its any help this is how we used to do it: we used a mac to prepare the devices "manually" using apple configurator (i.e choose "do not enroll in mdm") then supervise and allow pair with computers (so you can plug in via usb to get photos off etc) (if existing ipads erase all content and settings first) in lightspeed download the bulk enroll profile to the mac from the group you want them in then connect ipad to wifi and add the bulk enroll profile in apple configurator no users or logins. For new devices you're best using DEP. We followed this guide https://help.lightspeedsystems.com/s/article/dep-how-to-setup-device-enrollment-program?language=en_US
  15. got KB5010351 on a few test devices seems ok so far
  16. well after faffing about with a winpe usb and trying to start the deployment manually via net use * \\deploymentshare (which worked ok but when I run litetouch.vbs get error "no such interface supported") I found another usb ethernet adapter that does pxe boot! The one that wouldn't pxe was a Startech. Although after booting from a winpe usb the Startech worked fine (just not picked up at F12 boot)
  17. Hi @CHiLL We're wanting to look into using auto pilot and intune and we too have an OVS licenses (3 year till end of 2023) Whats the license we need to add to enable intune and could we just add a handful to trial it ? We do have some Azure P1 and Office 365 A3 but under https://endpoint.microsoft.com/ Tenant admin | Tenant status it says "No Permission"
  18. I think Oaktec is correct, there appears to be no pxe boot option (at least for the model we have: 81M9) So as i understand it I have two options, either do an MDT offline install completely from a usb, or boot into windows PE, plug in a usb ethernet adapter then manually start the deployment somehow ? edit: maybe if i copy boot image from wds onto a usb and make that bootable it would work ?
  19. grrr now my usb stick is not recognized by windows. @Oaktech How do you create your bootable usb's ? If I understand correctly, you are not using "offline media" but booting into windows pe then plugging in a usb ethernet adapter and then manually starting the deployment task sequence, e.g. run a script from deployment server (which one) from cmd prompt ?
  20. thanks for that, one step closer, trying to generate offline media in mdt (https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/deploy-a-windows-10-image-using-mdt#use-offline-media-to-deploy-windows10) generated an iso and burnt to usb with rufus, it now boots but fails at first hurdle asking "specify which deployment share to use" doesn't like X:\deploy and in here is only Scripts and tools, e.g. no control etc maybe rufus has messed things up, will try manually copying files and split wim diskpart active etc like it says in above link
  21. Has anyone managed to PXE boot these laptops from DFE: Lenovo 300e 2nd Gen Notebook - Type 81M9 can't see anything in bios, boot mode is uefi only (no legacy option) tried switching secure boot off / plugging in usb ethernet adapter If no PXE how do you image them ?
  22. Yes KB5007206 is the November 9 CU, it's the last one I deployed site wide. (after testing it didn't break printing ) Now you mention it I did run the Aj tek wsus script, so maybe that's removed KB5007206 ? I see your point re KB5008602. I'm currently testing 2022-01-11 17763.2452 KB5009557 (this is the last one that appears in my wsus) but given all the MS / update issues of late just wanting to err on side of caution. I've now got a few laptops come back onsite that are on an old build version (<2300) and printing doesn't work on them. They are reporting "You're up to date" on the laptops. I might try and add it (KB5007206 ) back. Currently stopped doing updates to the servers as I can't see how to really test those updates before rolling out, open to any ideas!
  23. was checking updates on wsus using the search box under actions searching for KB's for win 10 1809 ltsc as listed here https://docs.microsoft.com/en-us/windows/release-health/release-information For some of them search returns nothing e.g. a search for KB5007206 but I know that update was pushed out via wsus last year as I have a lot on build 17763.2300 ! Also if I search for next one KB5008602 still get nothing, but for this one (later still) KB5009557 I do get 3 returned (x86, x64 and ARM64) any ideas whats going on? I need to get some up to build 2300 i.e. apply KB5007206 Maybe I could get from Microsoft Update Catalog and re-add to wsus?
  24. Just went to get my morning coffee and overheard some bad news I think I need to share: Apparently the vaccines contain metal which reacts to 5G. This, from a respected member of the teaching staff so it must be true. Ruined my morning to be honest until I found these: https://www.amazon.co.uk/SYB-Briefs-Anti-Radiation-Protection-Silver/dp/B07QY8D193/ Get your orders in quick!
  25. mrstrong

    new mac setup

    so, slightly odd one: I used our appledid (from ASM, originally from the volume purchase program) to sign in to app store ok but won't let me click Get to download apps like Apple configurator, I can see the Get button but clicking it does nothing So created another appleid and signed in to app store with that, sure enough I can download new apps like apple configurator but it's also telling me I have updates (garage band, imovie, numbers, pages, keynote) When i try to update with the this new appleid it prompts me to "sign in to itunes store" (with the original ASM appleid). If I use the new appleid and click download it just pops up another download box saying "sign in to itunes store" and nothing happens. I tried the old ASM appleid to update garage band and it works! So am I stuck having to use two appleids going forward ? Note credit card credentials on ASM appleid have expired and the new appleid also doesn't have any payment / credit card setup on it. [edit: just thought maybe I need to get apps by logging into ASM rather than using app store on mac ?]
×
×
  • Create New...