-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
We have Sophos as our filtering, with YouTube set as blocked by default for students - except if they use a bypass code. With the bypass option enabled, when a student accesses YouTube, they get the block page and also an extra field where they can enter the bypass code to temporarily access YouTube. We have generated codes for each department and the staff must fill the code in themselves and not let the students know what it is (which isn't always the case). However, we have noticed that the browsers (Chrome and Edge, both latest versions) will remember that code after it's been entered. This means that the next time that student logs onto that same computer (or in the case of Edge and synced Microsoft settings, everywhere)...when they get to the YouTube block page and click the bypass field, both browsers will show the code as an autofill field. This is despite we have specifically disabled all autofill, password remembering, etc features in both browsers via GPO. Does anyone know which setting (if there is one) that I can configure to prevent this from happening?
-
I know others have mentioned using a virtual appliance for this sort of thing, but we were put off using our Smoothwall virtual appliance several years ago and we swapped it for their hardware appliance instead, specifically so it was in-line filtering. We found that if a client/user didn't apply it's proxy settings for whatever reason, the traffic would flow via the network route, which was typically client > edge switch > core switch > router > Internet. This meant that the traffic wasn't being diverted via the proxy settings to the virtual appliance and therefore was unfiltered. Having a hardware appliance that sat in-between the core switch and firewall meant that the traffic had no choice but to go through the filter. We currently have a Sophos XGS that does both filtering and firewall duties, but prior to that we had a hardware Smoothwall filtering device and a Cisco ASA firewall. Only the Smoothwall was performing HTTPS decryption, so only the Smoothwall certificate needed deploying to domain clients via GPO or manually to BYOD devices. The Cisco ASA was purely performing firewall and NAT duties, so it had no reason to have certificates on clients. Even with our Sophos XGS, we still deploy certificates to clients to perform HTTPS decryption. Though our Guest/BYOD networks don't have HTTPS decryption enabled, so purely rely on URL lists for filtering - which since they're either password protected networks that students can't access or access controlled, it doesn't concern us too much.
-
Sent you a PM.
-
I've had an update from a member of the escalation team, who have been referred the ticket before it is passed to the developers. They have admitted that [bromcom] "have not been able to look into this issue" and advised me to "please keep an eye out for a change in the tickets status". I understand that this has been marked as a low priority ticket, but over two months seems an excessive amount of time for this ticket to be open and not even investigated further than basic helpdesk responses. I have just responded to the escalation team member, though I don't know how long it'll take to get a response. Pprevious replies appear to be weekly, though only following my prompts to you in this thread and sometimes as long as a month.
-
If you use GPO to manage Chrome, you could take a look at the GPO setting: Computer Configuration > Administrative Templates > Google > Google Update > Preferences > Time period in each day to suppress auto-update check. If you enable that policy and set a start time of 9am and duration of 6 hours, that'll prevent clients from downloading Chrome updates during the core school hours.
-
Is there any way you can specify via Group Policy or your MDM to update at specific times?
-
It's more likely to be a Group Policy or other similar managed browser rule that is enforcing safe mode for YouTube.
-
We once looked at the possibility of exiting our print contract and we do have access to legal advice. We would have had to evidence every instance where service has been unacceptable or a breach of contract. We would have had to collect that for a prolonged period of time and pass it onto the legal firm, who would then write to the print provider.
-
The only network connectivity I want in my laptop trolley is something like a basic wireless controller, so I can configure/control the charging schedule of the devices in the trolley via a web portal instead of the always fiddly physical controls.
-
We were previously using Microsoft BitLocker Administration and Monitoring (MBAM) from the Microsoft Desktop Optimization Pack, though I understand that extended support will end for that in April 2026. We currently still deploy the MBAM client to initiate and enforce the BitLocker process, but we migrated away from using the MBAM database and moved it into SCCM for more central management. The BitLocker configurations are specified in SCCM under "Assets and Compliance > Overview > Endpoint Protection > BitLocker Management". I don't actually know if we still need the MBAM client deploying to clients or not though, or whether this SCCM configuration will enforce it without the client...but it works as it is atm with SCCM and the MBAM client, so that's how I've left it.
-
Hi Darren. I did eventually get a response, but I had to reply back as it's not fully resolved the issue. That reply was 5 days ago and I've not had a reply back. I have noticed that to/from on the reply says my name > my name, instead of my name > support agent, so it seems like I'm replying back to myself without a notification to the agent. I don't know if this is what is happening, or if it's by design or a bug.
-
Most of that is done via Group Policy to be honest. Our devices are managed only by SCCM too and the Task Sequence doesn't do that much that isn't pre-configuring (our TS was built using MDT). Most changes include auto-joining the domain, setting language and timezone, installing drivers, installing key applications (such as Office, Smoothwall Monitor, Impero, etc) and a couple of other customisations including disabling WinRE and resetting mouse suppression (there was a bug at some point where the mouse cursor wouldn't show during the OSD, so if it errored out, you couldn't use the mouse).
-
That's a good point. All of our staff workstations have the NSN client on them, so I'll make sure that our procedure includes something along the lines of "if you didn't get the popup on your screen, assume it hasn't worked and perform steps xyz". Thaks for that. I think I'm very close to completing a Powershell version of that. The main restriction is that is has to be run as a 32-bit Powershell command to access the COM object and I'm specifically having an issue getting it to accept the gateway key. The key contains special characters, including (but not limited to) brackets: "<", ">". It appears that it won't accept these as a string and throws an error: "Value does not fall within the expected range." I'm now stuck and so is ChatGPT and Gemini it appears, with both now suggesting I contact the developer of the COM object (NetSupport).
-
We haven't had DVD drives on machines for a while now and use Emby on one of our NAS devices. Any DVDs that staff want to use as educational resources, we'll rip the disc and upload it to Emby (based on the idea that we've already purchased it, just playing it another way). We set up departmental user accounts in Emby and can set libraries to only show to specific users/departments. It looks like it only applies to "maintained state schools". Do academies still fall under that category if they're not LEA maintained...or are they still classed as maintained since most of the money still comes from the government?
-
Papercut Budget Box - Not Appearing for Office Online
CHiLL replied to CHiLL's topic in Enterprise Software
Surely if that was the case, the device would not print at all? However, it can print from the Office Apps, as well as other apps like Notepad and even other websites and PDFs opened in the browser. It seems to specifically be when printing from the online/web version of Office apps. -
Papercut Budget Box - Not Appearing for Office Online
CHiLL replied to CHiLL's topic in Enterprise Software
Sorry, I did misunderstand you. We do not have any scripts in Papercut against the print queues. -
We have the HP ProBook 450 G8 and G9 models, as well as some ProBook 440 G10 models (14" version). We're finding that they're fairly good for us, though the only downside is the keyboard quality and replacement cost/procedure. We've had these <1 year and already had a key come off the keyboard on two laptops and we can't fit them back on. A replacement keyboard is the whole top keyboard panel, which costs ~£100 to replace and is literally an entire laptop teardown to replace it. Despite that, we also have HP USB C docks and deciding to keep ourselves a mostly HP house. We do have 15 Dell Latitude 3520 (not the same I know) laptops as student devices in one department. A school I worked at previously had replaced all their staff laptops with 3520's a couple of years ago and first impressions were pretty decent, though I haven't had enough exposure with them to suggest anything else. I think that school may have also bought some Stonebooks and liked them, but I can't remember, though I don't have any experience with the Stone's myself.
-
Newer iOS/iPadOS and Android devices have private MAC addresses enabled by default, which are temporary and randomised MAC addresses. This means it can be extremely difficult to identify a device from it's MAC address. If you aren't using an MDM and can't do the method @hallb15 is suggesting, I'd try and find out why your devices aren't appearing in DNS. I'd get hold of one of the devices and try and find out. I previously didn't have devices showing in DNS, because they were on a /21 subnet, which spans 4 "subnets", but only the first subnet was defined as a DNS scope. For example, for the subnet 10.1.20/29 - only 10.1.20.0 was showing as a scope in DNS. I had to manually add the extra three scopes (10.1.21.0, 10.1.22.0 and 10.1.23.0) and configure replication/failover for IP addresses to start showing those too.
-
Papercut Budget Box - Not Appearing for Office Online
CHiLL replied to CHiLL's topic in Enterprise Software
No, there's a logon script to launch the Papercut application for users at logon and printers are mapped by GPP, with printing in all other scenarios working, except for the case I outlined in my original post. -
I didn't know about this and now we're wondering why it's free. They say they're GDPR compliant but we're wondering if they're only now offering it because they can use the files to train their AI models. That poses the question of converting say a child's medical history that's stored as a PDF and needs amending.
-
Papercut Budget Box - Not Appearing for Office Online
CHiLL replied to CHiLL's topic in Enterprise Software
Sadly we have not found a resolution, just the workaround of opening it in the app or saving it as a PDF and printing from there. -
Weird Intune behaviour with logins and policy application
CHiLL replied to CHiLL's topic in Cloud Services
This is definitely an account problem. If I log into the Intune laptop as "myadminaccount", I get sync failures with Company Portal. If I log into the same laptop as "[email protected]", the sync completes. When checking the Intune logs on the laptop, both are using the same GUID, which corresponds with the GUID in Entra. From my research, it appears to be a TLS authentication issue, which fails when using the first login type but succeeds with the second. I may have to raise this with Microsoft. -
That sounds like a good idea, would you be able to share the script you're using to trigger the message?
-
While it's probably not related, I experienced something similar earlier this week, the client wasn't being installed. In our MDT based TS, along with deploying driver packages in the step before "Setup Windows and ConfigMgr", we also deploy drivers as Applications using silent switches (because sometimes the drivers packages don't always install all the drivers), which is right after the "Setup Windows and ConfigMgr" step. For these driver applications, we use WQL queries to limit them to running on machines of a certain model. As it turns out, I had made a typo on one newly created WQL query and it was causing the TS to fail without failing. No error message would be displayed and Windows would restart on the next step "State Restore - Restart Computer". Since the OS had already installed and the Windows and Network configuration steps had already completed by this point, Windows would just assume it's working fine and boot. Once I fixed the typo, it worked immediately.
-
I have been troubleshooting some issues with our Intune policies and app deployment, using one of our admin accounts. Traditionally our Intune devices had their domain set as the default school.onmicrosoft.com, so users had to use their full school email addresses were signing in and I've now changed that to our school domain (school.bham.sh.uk), which works and users can just sign in with username instead of their email address. However, while I was logged in as my admin account, apps being deployed were showing in Company Portal, but not downloading because it said it was waiting for the device to sync. The sync button in CP settings showed sync failed for reasons I couldn't deduce from the logs and the user was showing as "Domain\myadminaccount". I was battling this for days without any issue. Yesterday, I logged on with the full email address if the admin account ([email protected]) and it kicked into life, downloaded the apps and synced. Though the user in the log was still showing as "Domain\myadminaccount". Since the domain under the login box shows school.bham.sch.uk - why am I seeing different behaviours when I log in as myadminaccount and [email protected]?
