-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
Red motherboards: [ATTACH=CONFIG]71863[/ATTACH]
-
This is exactly why we would never consider purchasing this sort of device.
-
Impero iOS Browser - Issues with M365
CHiLL replied to CHiLL's topic in Network and Classroom Management
Ah you are right, it wasn't working for me because the site ID field is specifically two characters and I'd mashed a few. I did manage to get in and test the M365 Portal Home and it loads as it does on the other browsers, so it definitely appears to be an Impero app issue. It's a shame we aren't licensed with NetSupport (2.5 years left on our Impero contract I believe), as we want to be able to enforce users to log into the browser with their AD credentials. -
Impero iOS Browser - Issues with M365
CHiLL replied to CHiLL's topic in Network and Classroom Management
It's asking me to enter the site ID, account ID and Region in order to enrol, so I suspect it's not going to work. I will say though that NetSupport's app appears to be significantly more advanced than Impero's...like by more than a decade. -
Impero iOS Browser - Issues with M365
CHiLL replied to CHiLL's topic in Network and Classroom Management
I've tried it with an iPad that has no restrictions, only the enrollment profile settings, a specified WiFi profile and a filtering SSL certificate. I've also tried on a WiFi that I've turned off all filtering and ensured all specified Impero firewall rules are in place. The iPads are Gen9, running iOS 17.1. The fact that the site loads perfectly on Safari, Chrome and Edge on the same test iPads, even ones with all the restrictions in place, suggests it's an issue with either the Impero iOS app or the Impero server. -
Impero iOS Browser - Issues with M365
CHiLL replied to CHiLL's topic in Network and Classroom Management
Unfortunately I can't use Classroom.cloud as we don't have a contract with NetSupport and you need to log in in order to use their app. -
PC gaming cases with an oversized case fan. [ATTACH=CONFIG]71846[/ATTACH]
-
Conditional access policies for country blocking
CHiLL replied to Sheridan's topic in Cloud Services
This is basically what I was going to suggest, have your location exclusions in one policy. For example, in your "Deny logins from outside UK" policy, check the "Network" section and under "Include", select "Any network or location". On the "Exclude" tab, select the UK and other locations you want to allow logins from. -
New Laptops - Physical security and accountability
CHiLL replied to AndrewPowell's topic in Hardware
When it comes to repeat offenders, charging the departments for repairs and replacements of their IT resources has generally been quite effective in our school, as departmental budgets are already small enough as it is. In regards to tampering deterrents, etc...is it staff or students doing this and are the devices being stolen/taken away from school? If it's students, I've found deterrents make little difference unless the classroom teacher is on it or there is good disciplinary procedures. -
We are using the "HP USB-C Essential Dock G5" (which is a different product to the non-essential one) with HP ProBook 450 G8/G9s and ProBook 440 G10s. They've proven to be very good from our experience and little in the way of issues, with the only real one being HDMI to VGA adapter compatibility...but that's more an issue with the cheap adapters than the docks. The USB C cable is long enough to reach either side of a laptop, which is an issue with other docks that have short cables. My only complaint was that I thought the USB C cable was moulded and non-replaceable until I read @chazzy2501's post, so that's not an issue any more!
-
I think 64-bit has been Microsoft's default for the Click-to-Run version for a while now. We've been using the 64-bit version since at least before the pandemic, possibly since Office 2019. We now push the Current Branch of M365 Apps via SCCM or Intune, depending on the type of device and whichever is managing it. We haven't experienced any issues relating to 32/64 bit.
-
I have a case open with Impero regarding the page https://www.microsoft365.com/?from=PortalHome loading as a blank white page when accessing it via the Impero iOS browser app. If I access it on any of the other browsers installed on the iPad (Safari, Chrome and Edge), it loads as expected. Impero are unable to replicate the issue on their end, even using our test account that I changed and provided credentials for. If I go to https://outlook.office.com, it loads the emails as expected...it's just the portal landing page that I appear to be having issues with. I have confirmed that we have all the URLs and ports unblocked/allowed as necessary and I've even tried it with an unfiltered Wi-Fi, which also produces the same result. They have asked me to remove an iPad from our MDM (Intune), but I'm reluctant to do that as it would be added back in automatically by Apple School Manager. I don't want to delete it from there, as it warns me that removing a device from ASM is irreversible. I do have a staff allocated school iPad that is linked to Intune, but not restricted like the student ones, meaning I can log in with my own Apple ID and install my own apps. I will have to bring it in on Monday and have a test with it. Has anyone who uses the Impero iOS app encountered similar issues? If so, did you manage to resolve it and how?
-
There is a suggestion by someone on Bromcom's idea portal to incorporate OAuth: https://ideas.bromcomcloud.com/ideas/BRCM-I-5328. More votes the better!
-
Yeah, that's what we're trying to avoid - unnecessarily giving users who aren't technically employees access. There can be some exceptions, like a HoD or SLT who wants to get a head start during the summer holidays or something. We also want to achieve this in the least disruptive way for HR as possible, so they don't have to do a job twice if it isn't necessary. We are investigating with Salamander whether they can read the "The user can log into system" checkbox in "System Users". If they can, then we can see if they can change the password to something random is that box isn't checked and if it is checked, change the password to the default new starter password. This would require HR to have access to the System Users section, but I don't see that being an issue (though by default, that's only available to Administrators, so I'd probably have to create a custom role). Sure, it means they'd have to revisit Bromcom and change that flag, but at least it's less steps than creating a new contract. One downside is that Salamander doesn't automatically run until the following night, so either HR have to check that box BEFORE the start date (which could be a problem during holidays), or we'll have to manually run the Salamander script to force the sync.
-
We are trying to streamline our onboarding process and want to figure out how we can add new staff into Bromcom, which would allow Salamander to create their AD/M365 accounts and allow them to log in for an induction. A contracted member of staff would have their contract and start date added, however we are conducting inductions sometimes several weeks before their official start date. I have read that some people are adding users in as volunteers in Bromcom, as well as their contract, meaning that they can overlap. However, I cannot figure out how to do that. Ideally, we would like to have it as follows: Person's details entered in Bromcom, including volunteer date for induction (for example 01/07/2024 - 05/07/2024 or overlapping with their contact start date, such as 01/07/2024 - 01/09/2024) and their actual contract start date (for example 01/09/2024) Salamander creates their account Person has their induction Salamander disables their account as per volunteer end date Salamander reactivates their account as per contract start date Person then starts their employment on their actual start date Bromcom support is either not understanding what we're trying to achieve or being cagey about it. Does anyone have any advice on how to achieve this?
-
I managed to get this working using your command, but as an Application. I used the registry key "HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Creative Cloud\DisplayVersion" defined as "Greater than or equal to 5.10.0.573" (which is the packaged version we downloaded last year and it should auto update.
-
We have tried two units, one from HiHo and one from Verkada and both appeared to have the same detection issues when it came to open plan toilets, specifically with near floor-ceiling cubicle walls/doors. During our testing, neither device was able to reliably detect a various vapes and we determined that the issue was two fold; you'd need multiple detectors in each toilet area to target multiple cubicles and because each toilet must have a vent by law, we think it was drawing the vape away from the detector. We even put the detector in front of the vent, but we still have detection issues with both units. We have been left disillusioned with vape detectors and the costs, especially given our funding situation (or lack thereof).
-
+1 for Enviroelectronics. They provided us with a bin that we fill up and call them when it's full. They arrange collection and provide a replacement empty bin. We receive the serials and WEEE certificate, so I can't complain about anything!
-
The 250 G7 I have in front of me, which has the most up to date BIOS from HP (F.48 dated 07/05/2024) shows "Is Capable for Attestation: False", which suggests that it's a flat no go for device enrollment, if that's a requirement. I'm not sure I want to have to go through a whole rigmarole of running a bunch of different things on each laptop, when it appears that every laptop is affected. I'd rather go back to user-driven enrollment and remove the primary user in Intune, which will turn it into a shared device.
-
Credential Guard does break PEAP/MSCHAPv2 machine authentication. If you want to use machine authentication, your only two options are disable Credential Guard via GPO or create a new RADIUS policy that uses EAP-TLS instead. Check out this thread: /forums/windows-11/238344-windows-11-wifi-nps-radius.html
-
I have just encountered into this issue with 3x HP 250 G7 laptops and 1x Dell 3190, with the same error code reported. All laptops are running Windows 10 21H2, TPM 2.0 and all report that "TPM Has Vulnerable Firmware" is "False". I have also updated them all to the latest BIOS/firmware version, but I'm still encountering the issue. I am wondering if it's configuration related, because we recently changed our Autopilot from User-driven to Device-driven.
-
Sky TV via satellite + Broadband through (copper) phone line. Possible?
CHiLL replied to Koldov's topic in General Chat
Basically any provider that uses Openreach's network (such as Sky, BT, TalkTalk, Plusnet, Vodafone, etc should be able to provide Internet over the telephone line. Though they'll all offer roughly the same speeds, as they're all using the same cabling. You should get pricing for the Sky TV package on it's own, Sky TV and Broadband combined and also pricing from other Internet providers. Then you can then choose the cheapest combination, whether that's having the services combined with Sky or having TV from Sky and Internet from someone else. Sky TV via Q box and satellite dish only uses the Internet when streaming via built-in apps such as Netflix and downloading updates overnight, all TV content is sent via the satellite dish. -
Sky TV via satellite + Broadband through (copper) phone line. Possible?
CHiLL replied to Koldov's topic in General Chat
Assuming you have a functioning copper telephone line entering your property, Sky still do offer FTTC and Broadband Internet (though the latter may not be advertised well/at all). Is there a reason you're limited to just Sky for your Internet? If one company can supply telephone line based Internet, pretty much every provider can. Those customers are referred to as "locked in customers", as they're unlikely to want to unpackage each product. -
Smoothwall Monitor usefulness?
CHiLL replied to petben's topic in Internet Related/Filtering/Firewall
Smoothwall Monitor doesn't have any form of on-site server and transmits it's data over the Internet to their servers. Therefore the supported device just need an Internet connection and Monitor will be able to communicate. -
It appears I've had success following this YouTube guide: https://www.youtube.com/watch?v=SgAjEuCAFzE. I already had most of the configuration in place, but for our testing I created a security group called "Win11-Testing" and I'm manually adding the Windows 11 machines into the group for the time being. Since we already have a GPO that contains our wireless settings with PEAP authentication, I duplicated the policy and amended a few settings. The main ones I've edited are: "Computer Configuration > Policies > Security Settings > Wireless Network (802.11) Policies" configured. We already have an existing policy defined here that uses PEAP authentication, though this new GPO is defined using "Smartcard or certificate" authentication. "Computer Configuration > Policies > Security Settings > Public Key Policies > Certificate Services Client - Auto-Enrollment Settings" set to "Automatic enrollment" "Computer Configuration > Policies > Security Settings > Public Key Policies > Public Key Policies > Automatic Certificate Request Settings" set to "Automatic Certificate Request: Computer" "Computer Configuration > Policies > Security Settings > Public Key Policies > Public Key Policies > Public Key Policies > Trusted Root Certification Authorities" set with our imported CA certificate "Computer Configuration > Policies > Security Settings > Public Key Policies > Public Key Policies > Public Key Policies > Intermediate Certification Authorities" set with our imported CA certificate "Computer Configuration > Administrative Templates > System > Device Guard" set with credential guard enabled The GPO was also configured with a WMI filter for only Windows 11 devices and the old/existing policy configured with a WMI filter for Windows 10. I also created a new NPS Network Policy, following the YouTube guide, added an extra condition for "Machine Groups = Domain\Win11-Testing" and made sure it was above/higher processing order than the existing NPS policy. This means that only machines in the security group I specified will be processed by it. I have successfully tested the Windows 11 GPO and NPS policy on Windows 10 by removing the OU GPO link, removing the Windows 11 GPO WMI filter and removing the machine group condition in NPS - and it did work...but only after a gpupdate/restart with an existing network connection. For the duration of my testing, I'm leaving it so that I'll have to manually add machines into the machine security group. Once I'm happy with Windows 11 and push it to all machines, I can then remove those restrictions.
