Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. CHiLL

    VLSC

    That's the same for me, VLSC was activated on my account before I split it out from being a domain admin. I now have a separate account for that, but VLSC is still tied to what is now my non-admin account, so I have to use that to access VLSC. I'm not sure I understand what you mean. The admin account and standard accounts should not really be mixed. You can either assign your VLSC permissions to your user's standard accounts or their admin accounts.
  2. CHiLL

    VLSC

    You should already have access to it in your M365 Admin Center, under Billing > Your Products and selecting the Volume Licensing tab.
  3. M365 Admin Centre > Entra > Protection > Authentication Methods. You can download the list of users and then remove those you don't need (such as students for example). You can use the "Methods registered" column to see who has registered a method and which type.
  4. Is there any promotional imagery of that sofa, or images that anyone's posted of it? Just wondering if you could steal some interior design ideas from them. Or look for similar colour/pattern sofas and see what design people are using for the rest of the room. Usually the seller will have a design team that will have put thought into the photo shoot or there's a tonne of inspiration on Pinterest, etc.
  5. The wim file has to be generated from a source ISO (or extracted from one). It sounds like you're referencing or using the English version as the reference that MDT is using. You will need to replace it with the English International version in order to change the settings that you want.
  6. You need to download the International version of the ISO from Microsoft and use that in MDT instead. That has the en-GB language packs included, whereas the English one only has en-US.
  7. I've decided I'll create some new policies from scratch and test them on a test group. Since Intune can now effectively manage devices the ADMX way using the Settings Catalogue...is there any need or requirement to use Templates any more? Or should I just configure via Settings?
  8. A firmware update was applied last week, though the backups worked up until last night, which is why it appears to be something that I triggered yesterday. The QNAP is stating it is listing 117 OUs, which is the same amount of OUs returned by this Powershell command: Get-ADOrganizationalUnit -Filter *).Count Then when I count the list of actually displayed OUs, it's 2x pages of 50 entries plus a third page of 17 entries, totalling 117 - yet none of those are the OUs I'm looking for. Interestingly, I have used this Powershell command to list all OUs and they're missing from the list too: Get-ADOrganizationalUnit -Filter * So maybe it isn't specifically a QNAP issue. Edit: I wonder if it's because it's a container and QNAP isn't showing containers - it doesn't appear to be showing any of them. That Powershell command wouldn't either, because it's searching for OUs. A Powershell command to show containers does return them.
  9. Our QNAP TVS-1272XU-RP (firmware QTS 5.1.5.2679) is joined to our Windows domain and has been for a number of years now. We've had no issues with it for all those years and the NAS is used primarily as a backup repository for our VEEAM backup server, which uses a managed service account for authentication and this has been working all that time. It is joined to our domain using "AD authentication (domain members). However, I have found that it is no longer able to see some OUs in our AD environment, specifically, some of the root OUs, such as "Users" and "Managed Service Accounts". The OUs simply don't show up in the list of returned OUs in Control Panel > Domain Security > Edit Redundant Domain Controllers > Edit Organizational Unit. All of our other OUs seemingly appear, including other root OUs, such as "Domain Controllers", "Microsoft Exchange Security Groups", etc. Users and groups of the already selected OUs do show in the list of domain users or domain groups sections. However, we have some service accounts that live in Managed Service Accounts OU, specifically our VEEAM backup service account, which we need to continue having access. I'd rather not move these accounts to another OU that the QNAP can see, because I don't know if it's going to break anything else that may reference the account in that location. This appears to have occurred since I made a change yesterday, where I selected another OU to allow some domain users to access a different share on the NAS. Though I can't seem to figure out why. I have also tried dropping the QNAP from the domain and re-adding, but it still does the same thing. I'm currently at a loss as to what is happening.
  10. We have very recently transitioned to 1-1 laptops for teaching/classroom staff. We have had quite a lot of push-back and some issues to resolve, but it's mostly working well. For the hardware, we have always been a HP house here. We specifically bought HP ProBook 450 G9 laptops, as they have USB C that supports power delivery and Display Port Alt Mode. We have also bought HP USB-C Essential Dock G5 for every classroom, so one sits on every teacher desk. All the cabling, such as network, projector/TV display, USB for board/TV touch, sound, etc are plugged in the dock, which allows staff just to plug their laptop into the dock by the dock's built-in USB-C cable and it all switches over. We had tried other docks, such as a flat Belkin model, specifically because it had built-in VGA for our projectors, but we had issues with it not allowing the projectors to work at 1080p (despite they very much can and have been over VGA). The most common issues we've experienced with this are: Windows sound output set to the wrong device - needs to be set to the USB-C dock Teams sound output set to the wrong device - As above, sometimes Teams needs to be told specifically to use the dock Projector resolution issues when using converters to convert the projector cabling from VGA to HDMI/Display Port (Windows will show it as 1024x768 as default (Recommended), but allow it to be manually set to 1920x1080) - This could be resolved by slowly changing the cabling over from VGA to HDMI, though that's a big job and we might just wait for the projector or interactive board to die first, then replace them and the cabling with an interactive TV. Temporary/One off network dropout as the laptop switches from Wi-Fi to Ethernet via the dock and vice-versa (This could be avoided with a good enough Wi-Fi solution that you no-longer need Ethernet for these devices) Issues with broadcasting Impero to the student PC's - we currently have an open case with Impero for this For the software/management of the laptops remotely, we use SCCM to image and manage devices and deploy an IPsec VPN from our Sophos firewall. When the laptop is connected remotely through the VPN, SCCM works as normal (albeit slower) and we can still deploy apps/updates, etc. We allow cached logons and make the user log on in school first, then the VPN can be configured, so when they get home, they join their Wi-Fi, log in with their cached credentials and the VPN auto-connects when it detects they're not connected to our network.
  11. We use Smoothwall Monitor, which is always running on the device and sends the captures directly to Smoothwall, instead of to a local/on-site server. We also use our Sophos IPsec VPN, which routes web traffic through or firewall, including it's filtering. With the VPN connected, Impero is also able to establish a connection to our on-site server and monitor/capture devices.
  12. You shouldn't even need to hide the fact that you're monitoring all devices including staff. If anything, it would come under computer misuse, as they are work property and not personal devices. Our staff are aware that we have filtering and monitoring on the devices, even when they're used at home and they're to be used for work or education purposes only. Our monitoring is done by Smoothwall Monitor and graded by humans, not auto-graded. Severe and/or inappropriate captures are send to our network manager and DSL, regardless of who the user is. W also used Impero for remote control and monitoring/logs, but it's not managed or as accurate as Smoothwall Monitor. If we are requested to bring up logs for a specific users, we will provide that information.
  13. We have all of our student DFE laptops on Intune and since it was during the pandemic, it was all done in a rush and a that'll do approach, especially since we hadn't used the Windows management side of Intune before. I'm now looking back over our configuration and trying to decide how best to manage all our policies. Specifically that we have a group that contains all our DFE devices and all our machine and user policies are directed towards that. This has the knock on effect that machine policies are affecting all users that use the machine, including admins (such as disallowing the C: drive, USB drives, etc). In a traditional AD environment, your machine settings were targeted towards the machine OU and the user settings were targeted towards the user OU. While I can do this in Intune, I want to clarify a couple of things: Our on-site devices are co-managed, with SCCM being the specified/preferred MDM in the co-management settings. I want to be sure that for example, if I apply a user setting to our "All students" group in Intune, that will only affect the users on the DFE laptops and not the on-site machines. It's my understanding that this is the case, since SCCM shouldn't allow Intune policies to apply, but it's not something I'm entirely sure about. Has anyone attempted to import their existing on-site group policy settings into Intune and did it work? I'd rather not reinvent the wheel, since we already have known working settings and restrictions on-site.
  14. We have noticed that our users are not getting the print budget dialogue box appear when they print documents from the likes of Word Online, Excel Online, etc. However, if they open the document in the desktop app and then print, the budget box will appear. We have witnessed this both in Edge (including the latest version, 122.0.2365.52) and Chrome (including the latest version 122.0.6261.70). This doesn't appear to be an issue in Outlook OWA/web, where an attached Word document opens in the browser and then when printed, opens as a PDF in a new tab. Printing PDFs in the browser also seem unaffected, where they present the dialogue box. We are running Papercut MF 22.1.2. We utilise the locally cached version of the Papercut client, which auto-updates. The client on the machine I'm testing with is v109.28.0.6575. Just wondered if anyone else has encountered this?
  15. We assign our P1 license to a specific account: M365 Admin Center > Users > Active Users > User you wish to assign the license to > Licenses and apps: Check "Azure Active Directory Premium P1" > Save Changes
  16. The new Nvidia app will replace both GeForce Experience and the Nvidia Control Panel, combining everything into one modern app (that doesn't require you to log in to get automated driver updates and game preferences, wahoo!). It looks like it will also incorporate things like Nvidia Broadcast, so that won't also need a separate app.
  17. And an app that doesn't look like it was made in 2006 (because it was).
  18. We're only using the one form of MFA, specifically the Microsoft Authenticator app.
  19. Haven't Microsoft now depreciated SMS MFA entirely?
  20. We have our teaching staff (and I actually think all our staff) set to 10 minutes of inactivity and I think this is ignored by default if videos or slideshows are running. We had many instances of computers being left unlocked with SIMS left logged in, so we had to enforce it.
  21. Thanks for your quick reply! I am trying to get to the bottom of where our actual problems lie. I've posted in an old thread that matches the behaviour we are seeing: /forums/wireless-networks/217148-dell-latitude-3380-radius-wi-fi-connectivity-issue.html#post2027835. I'm hoping the OP is still active and remembers, though that's a stretch from a few years ago!
  22. Sorry to necro this thread, but did you ever get to the bottom of this? I know it's a lot to ask after 3.5 years. We are encountering this behaviour with our Ruckus ZD1200 & R500 APs, on our HP ProBook 450 G9 laptops. Continuous pings will work, but we will see frequent drops, from one packet to multiple packets in a row dropped. The laptops are running Windows 10 22H2 and I've installed the latest WLAN drivers (v22.250.1.2) available from HPs website and also tried even newer drivers directly from Intel (v23.20.0). Power management is disabled (so the laptop can't turn it off). We have two identical laptops, with the same WiFi module and driver version - but according to ZD, one is authenticated with EAP and the other with CPMK. The EAP authenticated device is the one dropping out. We have a RADIUS server that adds devices that are members of our Dot1x authentication group into the relevant VLAN and that appears to be working as expected.
  23. After speaking with Net-Ctrl at BETT and explaining how we're having issues with clients hanging onto weak signals from APs as they move around the building, the guy I spoke to mentioned that one way to tackle this is to turn down the TX power output of the APs. That way, the AP isn't broadcasting as far and clients would be forced to connect the next one. I have found the setting in our ZD, though I don't really have an understanding on the dB levels and what to set them do. I have the following options: Full -1dB -2dB -3dB(1/2) -4dB -5dB -6dB(1/4) -7dB -8dB -9dB(1/8) -10 dB Min Auto They are all currently set to auto and have been since they were implemented in 2015. I assume that -3dB is 50% power, -9dB is 12.5% power. I am just not sure how much power to reduce the AP by, presumably not be a lot otherwise I'd be creating a lot of dead zones.
  24. Sorry, I initially missed this thread update. Unfortunately, I cannot remember that far back, though I do know around that time or sometime after, we migrated away from Microsoft's Always-On VPN to utilise the Sophos IPsec VPN that comes as part of our firewall package. It has been much more reliable than Microsoft's VPN solution.
  25. IIRC, you don't have a choice to which agreement you're on regarding OVS-ES or EES, as it's based on your number of users. If you have <1000 users, you'll be on OVS-ES. If you have >=1000 users, you'll be on EES. Maybe that's changed, but we had a nightmare with O365 shared licensing/computers a few years back, as that aspect was only available to EES customers. Since we had <900 users, we were told by multiple suppliers and Microsoft directly that we weren't eligible for the EES model and had to use OVS-ES.
×
×
  • Create New...