-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
Smoothwall Monitor usefulness?
CHiLL replied to petben's topic in Internet Related/Filtering/Firewall
We've been using it for a number of years now, even from when it used to be Policy Central (which Smoothwall purchased). Using the client installed on each device, it will monitor the usage and take screenshots of anything classified as inappropriate. That screenshot is then sent back to Smoothwall, where is is assessed by an automated process and graded. It it's graded below a certain level, it's viewable in the portal and not passed onto a human for manual assessment. If it's graded above a certain level, then it's passed onto a human for evaluation. If it's then assessed by the human to be the highest grade, they will call the school to inform the designated people (this is usually for something like self harm, extremism, etc). This really came into it's own for us with at-home devices, especially since the pandemic as where we cannot have Impero on them like we do on-site devices (as Impero is on-site only). However, we have had some instances where captures have been taken and graded incorrectly, which meant they weren't passed onto a human when they should have been. This is relatively uncommon though. -
We use SCCM to deploy out software to collections and have a collection for each IT suite, with software deployed to it. This allows me to easily see what software is being used by viewing the deployments tab of the collection. However, a computer can be a member of specific collections, so I can either view the deployments of each collection (such as "All Workstations", "All IT Suites" and "IT Suite 01"), or I can view a specific machine from an IT suite in SCCM and see what deployments are hitting just that machine. Not directly related to software in use in specific rooms, we have recently liaised with our finance department and created a Microsoft List that contains all IT-related/adjacent contracts, which they can edit too. Information that is in the list includes things such as supplier, contract end date, cost, who/which department it's for, who requested it, whether it's an auto-renew contract, cancellation period, which budget is used, etc. This came about after years of not being told that software or subscriptions that required MIS linking, etc had been purchased or losing track of who is responsible for software after staffing changes.
-
I am currently looking into this at the moment. The options are either disable Credential Guard via GPO for the devices or amend the Network Policy in NPS to use "Microsoft: Smart Card or other certificate" and select a certificate issued by your CA. I believe the latter requires you to have PKI set up in your environment, which we already do. Ideally, I don't want to disable Credential Guard if I don't have to. We split out our staff and student laptops into different VLANs via our network policies, based on security group membership. All devices are members of "Domain Computers". All student devices are also members of "Dot1xStudents" group. All staff devices are also members of both "Dot1xStudents" and "Dot1xStaff". The network policies run in processing order, so a staff device will be processed by the staff WIFI policy first and be placed into the staff laptop VLAN. Then student laptops do the same thing. I've duplicated my Wi-Fi network policy and set it to disabled for the time being. In this new policy, I've removed the PEAP authentication and added in smart card, selecting a certificate from our CA. I am yet to test this though, as I would need to set this as a precedent/disable the existing one in order to test. While that won't affect currently authenticated devices, if the policy doesn't work, any devices that attempt to authenticate will fail. So I'll have to be quick with my testing. Edit: According to this Microsoft article, EAP-TLS on Windows 11 uses TLS 1.3 and NPS does not currently support TLS 1.3. This would suggest the only viable option for using Windows 11 with a RADIUS server would be to disable Credential Guard.
-
MSGraph - Error AADSTS700016: Application with identifier
CHiLL replied to CHiLL's topic in Cloud Services
Thanks to information from @robk and this site: https://chanmingman.wordpress.com/2022/04/22/aadsts50011-the-redirect-uri-urnietfwgoauth2-0oob-specified-in-the-request-does-not-match-the-redirect-uris-configured-for-the-application/, I've managed to fix it by creating a new app registration in Entra admin > Applications > App registrations. Once created, I added API permissions for "DeviceManagementConfiguration.ReadWrite.All", "DeviceManagementManagedDevices.ReadWrite.All", "DeviceManagementServiceConfig.ReadWrite.All" and "User.Read", plus granted admin consent for our tenant. Then in Authentication, I added an authenication method for "Mobile and desktop applications Redirect URIs" and added an extra URI for "urn: ietf: wg: oauth: 2.0: oob" (spaces added because it created emojis), as that was specified in the new error message I was receiving. I also checked the box for "https://login.microsoftonline.com/common/oauth2/nativeclient", as that was also selected in the screenshot from Chanmingman's Blog. I then ran the command @robk mentioned "Update-MSGraphEnvironment -AppId . Once all that was done, I was able to successfully authenticate via the Connect-MSGraph command and run some Intune commands. -
Oh man, I remember that being a problem with the roll out of Windows 7, but I can't for the life of me remember what it was. Regarding folder redirection, we have it configured as follows: User Configuration > Policies > Windows Settings > Folder Redirection Setting: Basic - Redirect everyone's folder to the same location Target folder location: Create a folder for each user under the root path Root path: \\server.local\share$\2023 This will create a folder with each username in the root of the 2023 folder and create a Documents folder within that folder. For example, 23JSmith would have a Documents folder located in \\server.local\share$\2023\23JSmith\Documents. I had an issue many years ago with the Downloads folder location and successfully used the "Move the contents of Documents to the new location" check box, which did move the files without issue. Though I would recommend testing it first.
-
MSGraph - Error AADSTS700016: Application with identifier
CHiLL replied to CHiLL's topic in Cloud Services
That is the application ID! I wasn't sure if that was unique, hence why I excluded it. Searching for "Intune PowerShell" shows me the application with that application ID, so I don't know why it wouldn't appear when I searched for it via the ID alone. I have confirmed that the account I am using has permissions to access the app, but I'm still getting the same error. I don't know why it can't locate the app within our tenant when I can view and edit it in the portal. -
We have started encountering issues when attempting to authenticate with our MSGraph command. Whenever we issue the "Connect-MSGraph" command, we are prompted to enter our credentials (I'm using my M365 global admin account) and once I enter my MFA code, I am greeted with the following error:
-
Not just me then! Do you have a source for this information or know which route I need to take regarding this warranty claim?
-
They attempted to close the ticket without responding to my follow up issues.
-
I updated the ticket quite a while ago stating that while the work around make the feature appear in the settings - I cannot enable it because it requires a license and the option is greyed out, despite I was told we are fully licensed.
-
Yeah. Annoyingly, I do update the ticket and ask for an update, but I don't get a reply back until I get fed up and post here.
-
Hi Darren. It's been a further two weeks since you last chased them for me and there's again been no update from that. I shouldn't have to resort to replying publicly to you in order to get an update.
-
[ms office - o365] PowerPoint Bug Test - I need your help!
CHiLL replied to robyholmes's topic in Office Software
I have the bug too: Windows 11 Education 23H2 22631.3447 M365 Apps; Microsoft® PowerPoint® for Microsoft 365 MSO (Version 2310 Build 16.0.16924.20054) 64-bit Edit: Running the slideshow again and performing your instructions straight not only replicates the bug, but also makes it occur immediately. -
Is this a nationwide outage or just affecting server clusters? Just wondering since they seem to describe it as a 'minor' incident.
-
Yeah, we're unable to load it at all here. Can't even log in to see what server we're connected to. Update: They've just posted about it on their community forum: https://community.bromcomcloud.com/bromcom-announcements/post/known-issue---bromcom-mis-speed-20-05-2024-RmNzm85hTpT61lO
-
We have Windows 10 Education 22H2 deployed across our site and it's using the English (en-US ) ISO. I am looking for perform an in place upgrade via SCCM on some devices to Windows 11 Education 23H2, but using the English International (en-GB) ISO. Would the ISO language difference be enough to cause my in place upgrade to fail with error "0xC1900204 (decimal 3247440388"), which translates to "MigChoice: Selected install choice is not available".
-
We haven't had a request for a while, but we are usually instructed to buy a laptop, bag and the Office suite. We leave everything sealed and hand it to the student, who is directly informed (and their parents) that this is not property of the school and there is no support available for them. Many years ago, we had a pupil who abused their LAC budget to their advantage and managed to wangle a gaming laptop. The SENDCO at the time simply took the stance "it's not our money, it's from the council and it'll be sent back if not used". Lucky kid.
-
WMware problems since Broadcom took over?
CHiLL replied to dan00204's topic in Thin Client and Virtual Machines
I presume you mean the account management portal online and not something like vSphere/ESXi? I would expect outrage is Broadcom started locking customers out of their environments! I can log into Broadcom fine, though I tried to open a new case and was met with "Inactive User or UserName not found." when I was redirected to "wolkenservicedesk.com". Though that could be related to the fact that we don't have an active support agreement in place. -
I don't have the issue you're describing on either our Windows 10 22H2 CB builds or my own workstation's Windows 11 23H2 build. However, the issue may not be related to that and be something else entirely. Honestly, we don't even remove bloat anymore. I just leave it all in (icons in the start menu included) and use AppLocker to restrict access to the apps.
-
While I can't answer your question, I would ask why you've decided to use LTSC? Unless you have hardware that absolutely cannot change, Current Branch is the recommended deployment for Windows with monthly updates. As I understand it, it isn't like CB of M365 Apps, where monthly updates add extra features and some old features may be depreciated. Instead, you deploy say 23H2 and it'll stay at 23H2, even when 24H2 comes out...unless you push a feature upgrade to specifically upgrade/unlock that version. Windows 10 is stuck on 22H2 and since then it's only been security/critical updates pushed, so wouldn't that effectively act like an LTSC for you (though support/updates for CB ends October 2025).
-
We are looking at the possibility of migrated our staff shared area to SharePoint but want to evaluate a sort of best practice. We already utilise CloudDesignBox to manage our SharePoint sites and want to avoid just copying and pasting the shared area as is into SharePoint and but look at more department/site based. Since every department already has their own site (even if they aren't using it, though some already are) thanks to CloudDesignBox. My colleague has read previously that people have posted online that just dumping the existing structure into SharePoint isn't best practise and can slow it down (not sure how). We'd rather do it right first time than manage a mess in the future if possible. Examples of folders in the main structure includes: Department Folders (sub-folders for each department with ACLs) Cover work Catholic Life CPD Exams Pastoral Learning Support School Information Teaching and Learning Department Folders can just be moved into the staff only section within each department's SharePoint, which is already managed with ACLs Cover work, Catholic Life, CPD, Learning Support, School Information and Teaching and Learning can go into a new site, such as admin/office. Pastoral can have a site to themselves due to the nature of it's contents Exams can have a site to themselves, also do to the nature of it's contents One thing we are unsure of is what would be the best way to manage multiple subjects/areas for SLT for example, who may need to access resources from multiple departments? The request we've had is that it wouldn't be ideal if SLT had to jump though multiple sites to access things they need and they'd prefer it to be like it is now, one folder structure that contains multiple departments - but we'd like to avoid this and utilise what we already have. Is there some form of compromise? What would be the best way to manage new academic years with rollover/archive/revisions of data without removing or duplicating required files?
-
Chrome & Edge - Stop remembering fields
CHiLL replied to CHiLL's topic in Internet Related/Filtering/Firewall
Oh I see, I didn't understand that's what you meant in your original post. I'll raise that with Wave9 and see if they can raise it as a bug request with Sophos. -
Chrome & Edge - Stop remembering fields
CHiLL replied to CHiLL's topic in Internet Related/Filtering/Firewall
Looks like this bug report dates back to 2015, so it may not be possible if the "off" flag isn't respected. I'm not finding a way to specify autocomplete="new-password", it certainly can't be done via the ADMX policies. Looking at chrome://flags and edge://flags, "autocomplete" isn't a valid flag that an be amended. In Firefox, it looks like you need to go into about:config, find the setting, change it from "Boolean" to "String" and then specify "new-password" as the value. -
Chrome & Edge - Stop remembering fields
CHiLL replied to CHiLL's topic in Internet Related/Filtering/Firewall
Thanks for that, though that article seems to say that browsers ignore autocomplete="off" and may adhere to autocomplete="new-password", though it's not a standard that browsers must adhere to, so may not work. Since that's an article for Firefox, I need to figure out where or if I can specify that for Chrome and Edge, as it appears that the only options I have are "Not configured", "Enabled" and "Disabled".
