Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. We haven't used an iPad for exams, but you could put the iPad in Kiosk mode (which Intune can do - but I haven't tried it). I think kiosk mode limits the iPad to only using the one specified app. If you need access to other apps, you could create a new group in Intune and remove access to the browsers...or restrict Internet access another way, such as changing the proxy or putting the iPad onto a SSID/VLAN that has no Internet access.
  2. I've seen what the other's have said and I've also seen (mainly in some Dell laptops) that you have to toggle a setting in the BIOS to switch the drives from RAID to AHCI or something similar...then it was detected in the Windows installer.
  3. We have a set of laptops used for exams and then a bunch of exam accounts numbered exam01, exam02, etc..with networked home folders and a read-only shared drive if any resources are required. The details are passed to our exams officer and we leave all the accounts disabled, except for the ones she allocates to students. The exams officer tells us where to put the laptop and they're left on that student's exam desk for the duration of the exam period. The exam accounts are locked down significantly and only have access to the apps we specify, such as Exam WritePad. Completed exams are saved in that account's home folder, which we can print out after the exam.
  4. Firstly, congrats! Secondly, SCCM is a big beast to learn and best doing it once you're settled and used to your new environment. I wonder if the quickest (not long term - that would be SCCM with WSUS integrated) method would be to download the latest LTSC ISO (assuming you'd stick with LTSC) and creating a bunch of bootable USB drives (or even copying the ISO to each machine's local C:\ drive) and running the setup on the machines individually, allowing them to perform the in-place upgrade. Though if you want to convert from LTSC to CB, I believe you'd need to run a command or something to convert the type from LTSC to CB.
  5. Tech related, I've known people to say Toebisha for Toshiba and Imperio for Impero. I guess more dialect related, but I will say "hur" for the words "hair", "her". Similar for "their", etc..."thur".
  6. We have a newly created Server 2022 21H2 for our updated Cunninghams cashless catering system. It's all up and running, though I've noticed some odd behaviour on the server. For example, I cannot RDP to the server and I get UAC prompts when logged in as a domain admin and run Powershell...despite both RDP being turned on and UAC being turned off by the servers GPO. The server is in the same OU as all other non-DC servers and has the same policies applied. I've performed an RSOP and I can see that the server has received and applied the necessary policies...however they just don't seem to be actually applied. I've also dropped the server from the domain, deleted the AD account and re-joined it...and it's still doing the same thing. Has anyone had this behaviour before?
  7. I had this issue when they patched a vulnerability a couple of months ago. However, my issue was related to no longer being able to log in as a non-domain admin. My main account is a standard user and I had to change the shortcut to run as an administrator, authenticate with my separate domain admin credentials and then I could use the Windows session authentication to log in.
  8. Our devices in trolleys are in per-department areas, so each department has a set of iPads or laptops in a trolley. The trolley stays in one place and the teacher sends a student to the classroom/office to collect however many they've booked (we use HAP+ for the booking system). To transport multiple devices around the classes, we usually use plasic boxes with handles.
  9. I did get it (Lyca Mobile) at 14.59 and I thought it seemed very American, almost like what you hear in the movies. Both the alert tone and also the female American voice over (which may just be a basic non-localised Android/Google Pixel default setting) just came across like I was watching The Day After Tomorrow or something.
  10. The only solution we can come up with at the moment is regarding how the home drive is mapped. We use the user's AD properties to specify the home drive location and drive letter, which doesn't reapply and all other mapped drives are handled by GPP. I don't want to mess around with the AD properties at the moment, so I've added an extra entry into our GPP to map the home drive (\\server\share$\%username%\Documents) with the box checked for "Reconnect". This will potentially conflict with the AD properties but I'm relying on the fact that GPP will silently fail. In an on-site scenario, the user will log in and get the H: drive by AD properties and that's it. However, this extra GPP item means that GPP will attempt to add the H: drive again...but it should silently fail because it already exists. In an off-site scenario, the user will log in and the H: drive by AD properties will fail. However, this extra GPP item will fail at first run/login (which presents the H: drive, but it's unusable with the same error listed for Documents in one of my earlier posts), but then the reconnect flag kicks in and reapplies the map...then the drive appears as a usable drive. From my initial testing, it appears to take a couple of minutes until the H: drive is visible and accessible...but at least it appears to work.
  11. That appears to be the case. Our staff share mapped drive will have a red x through it because it maps the drive before the VPN has established it's connection, though users can still click through it to access it and the red x disappears. Edit: The staff home folders and staff share are both on the same drive of the same server.
  12. 1) I've just tried it and it's a combination of yes and no. I cannot use the same drive letter because it says it's already in use. Using a different drive letter, whether using the FQDN or IP address I get two outcomes; either it maps fine or it says that the user doesn't have permissions to access the folder (which isn't correct because all users have full control over their home folder and it will work when on the internal network with the same path). 2) Yeah, we're using FQDN's (drives are mapped via GPP using the Update option). 3) Restarting File Explorer in the user's context made no difference The error using the Documents folder is as follows: \\server.fqdn\share$\\Documents is unavailable. If the location is on this PC, make sure that the device or drive is connected or the disc is inserted, then try again. If the locaiton is on a network, make sure that you're connected to the network or Internet, then try again. If the location still can't be found, it might have been moved or deleted. I have just tried it again on a user's laptop and as I logged on, I got the above message. When manually trying to browse to the path via Run, it says the following: \\server.fqdn\share$\\Documents. The specified path does not exist. Check the path, then try again. This is despite I can browse to the same path from my machine and access the user's home folder. However, I noticed that leaving the laptop idle for a couple of minutes without it logging out/locking...the Documents folder then worked as expected. It appears that the network path only works after some time of being logged in/VPN being established, I'm not sure why. I've also noticed that this Sophos VPN has the same Home Folder issue that our older Microsoft Always-On VPN had where it doesn't map the H:\ drive for the home folder. I'm trying to figure out how to get it to re-apply.
  13. I don't think this issue is specifically related to our VPN itself, hence why I've started the thread here than in another section. We use Sophos IPsec VPN for external access, however we are finding that an increasing number of users are reporting that their mapped drives aren't working. This mainly occurs when they are connected to the VPN, however I have also seen it when they're connected to the internal network, not via Sophos. I am struggling to replicate the issue when connecting the device via my phone's hotspot. I can see in the event logs that the folder redirection was sucessfully applied The mapped drives end up having red x through them and when you try to access them, it says something along the drives of "Could not reconnect the drive. The network name is already in use". The Documents folder also won't work, because Documents redirects into their networked home folder. Although I can see in the event logs that folder redirection applied correctly.
  14. Is there a file in a folder in a folder in a folder in a folder (etc etc)? I've seen similar issues when the file path is longer than what Windows can support. If so, try deleting via this method: https://www.howtogeek.com/283877/how-to-delete-files-windows-claims-are-too-long/
  15. We have a Sophos XG provided and supported by Wave9. Their support has been excellent during the time we've had them.
  16. I do get the "Start PXE over IPv4" message, though it times out and takes me to a default Windows cannot load an OS menu. It seems similar bhaviour to a device not getting an IP address. Actually, looking at the Networking tab, no IP address has been assigned and I'm getting the same behaviour on both the Default Switch and the External Switch I created. Edit: I deleted and new external vSwitch and created it again. Now it's working, no idea why!
  17. My Google-Fu and fixes have let me down. I've just built a more powerful machine for my workstation, with the aim that I can use virtualisation on it for testing with VMs. I've installed Hyper-V and created a VM template...however, I cannot get it to PXE boot from our SCCM server. I get the "Start PXE over IPv4" message, though it times out and takes me to a page that says: The main causes for this that I've found are: Make sure network is the first boot order - it is SCCM/WDS isn't configured for UEFI - it is, as we can PXE boot other UEFI secure boot devices Create an external vSwitch and use "Allow management operating system to share this network adapter" - I have and it did the same thing Gen2 only supports x64 - We are only using x64 Use Gen1 instead - I'd rather use Gen2 if possible! My knowledge of Hyper-V is quite limited, as most of my experience is with VMware. Any assistance would be appreciated!
  18. Sad that Amazon are just closing it, rather than trying to sell it off or whatever. Two of the DPReview guys were on as guests on the Linus Tech Tips podcast The WAN Show the other week discussing it:
  19. For a long time, we have had WLAN disabled on desktops that are connected via Ethernet, with the origins being DNS related issues (I think with SOLUS3). Since we no longer use SIMS/SOLUS3, I'm wondering if this policy to disable WLAN on desktops is still necessary, especially since we use dot1x and security groups to specify different VLANs for desktop/laptops and staff/student devices? The only things I can think of that would cause issues are: I'd be harder to tell if the Ethernet cable has been unplugged, as it'll default to Wi-Fi (while a good failover, we'll likely not know that network performance is degraded on that machine) Hotspotting - Since Windows now has the ability to hotspot it's wireless, I'd want to disable this. I'm sure there's a GPO for it, I just haven't looked into it yet Is there anything else that I may need to consider?
  20. We enquired about Avigilon, though we were told by two suppliers that you're looking at 2-3 times the cost of a HikVision/Dahua equipment, which pretty much rules it out as a replacement.
  21. I did this recently on our DL360 Gen9 hosts and MSA2040 SAN. I downloaded the HP VMware 7.0U3 image from HP's website and uploaded it directly to our ISO folder on the 2040. I was able then to add that ISO into our vSphere environment and created an update baseline for it. After that, I updated vCenter using it's built in updater, which put it on the latest version. Once vCenter was back, I migrated all the VMs from the first host to the second host (so they were still running - they're compute only, since the actual VM files live on the MSA and not the host) and put the first host into maintenance mode. Once in maintenance mode, I was able to apply the update baseline that I created with 7.0U3. Once the update completed and the server had rebooted, I verified that the server was as expected, took it out of maintenance mode and migrated the VMs back. Once I was happy with the situation, I repeated the process with the second host.
  22. I think mine would be in the mid-90s playing Desert Strike on my Sega Megadrive. It was the first time I was allowed a TV/console in my bedroom and it was also the first time I accidentally swore in earshot of my mum, out of frustration to the game. Needless to say the TV and console weren't in my room for a while after that.
  23. We have deployed Sophos Connect as our VPN solution to all our staff laptops and it's been working fine for the most part. However, I have recently had reports that Sophos Connect has disappeared from multiple laptops. I actually saw this happen on my partner's laptop at home last night, she was connected to Sophos, then she was disconnected and it was missing from the Task Bar and the shortcut didn't work. I have another member of staff's laptop with me at the moment who had the same issue. Looking at the Application log in Event Viewer, I can see that on 20/03/2023 at 17:08:36, the uninstall of Sophos Connect was initiated by msiexec. Looking at AppEnforce.log for the same time period, I see this: +++ Starting Uninstall enforcement for App DT "Sophos Connect 2.2.75" ApplicationDeliveryType - ScopeId_52DA5FC5-B299-4EB5-9230-3EAD92748ACD/DeploymentType_dadd89c3-0032-4708-b4a7-27f688587795, Revision - 2, ContentPath - C:\WINDOWS\ccmcache\37, Execution Context - System Performing detection of app deployment type Sophos Connect 2.2.75(ScopeId_52DA5FC5-B299-4EB5-9230-3EAD92748ACD/DeploymentType_dadd89c3-0032-4708-b4a7-27f688587795, revision 2) for system. +++ Discovered application [AppDT Id: ScopeId_52DA5FC5-B299-4EB5-9230-3EAD92748ACD/DeploymentType_dadd89c3-0032-4708-b4a7-27f688587795, Revision: 2] App enforcement environment: Context: Machine Command line: msiexec /x {47055399-87A8-47D5-8E6D-E916B3FEADC4} /q /norestart Allow user interaction: No UI mode: 0 User token: null Session Id: 4294967295 Content path: C:\WINDOWS\ccmcache\37 Working directory: Prepared working directory: C:\WINDOWS\ccmcache\37 Found executable file msiexec with complete path C:\WINDOWS\system32\msiexec.exe Prepared command line: "C:\WINDOWS\system32\msiexec.exe" /x {47055399-87A8-47D5-8E6D-E916B3FEADC4} /q /norestart /qn Executing Command line: "C:\WINDOWS\system32\msiexec.exe" /x {47055399-87A8-47D5-8E6D-E916B3FEADC4} /q /norestart /qn with system context Working directory C:\WINDOWS\ccmcache\37 Post install behavior is BasedOnExitCode Waiting for process 18616 to finish. Timeout = 30 minutes. Process 18616 terminated with exitcode: 0 Looking for exit code 0 in exit codes table... Matched exit code 0 to a Success entry in exit codes table. Performing detection of app deployment type Sophos Connect 2.2.75(ScopeId_52DA5FC5-B299-4EB5-9230-3EAD92748ACD/DeploymentType_dadd89c3-0032-4708-b4a7-27f688587795, revision 2) for system. +++ Application not discovered. [AppDT Id: ScopeId_52DA5FC5-B299-4EB5-9230-3EAD92748ACD/DeploymentType_dadd89c3-0032-4708-b4a7-27f688587795, Revision: 2] ++++++ App enforcement completed (11 seconds) for App DT "Sophos Connect 2.2.75" [scopeId_52DA5FC5-B299-4EB5-9230-3EAD92748ACD/DeploymentType_dadd89c3-0032-4708-b4a7-27f688587795], Revision: 2, User SID: ] ++++++ So I have checked the application in SCCM and I have confirmed that there is no uninstall or supersedence applying to this application. Just an install deployment that is pushed to all staff laptops. I have also clarifyed that the option in Deployment Settings "When a resource is no longer a member of the collection, uninstall this application" is NOT checked. What is also concerning is the actual uninstall command that was used: msiexec.exe /x {47055399-87A8-47D5-8E6D-E916B3FEADC4} /q /norestart /qn As the uninstall command specified in SCCM doesn't include the /qn at the end and is just: msiexec /x {47055399-87A8-47D5-8E6D-E916B3FEADC4} /q /norestart I've also noticed that Sophos Connect doesn't appear in the list of applications in Software Center on a client device, despite double and triple checking that the device is in the collection Sophos is deployed to in SCCM and reporting as active/online. Can anyone help shed some light on why SCCM is uninstalling this application? I'm getting hounded by staff who can't work at home.
  24. Our March updates came through last week, as we have ours configured to sync on the second Wednesday of the month.
  25. Ah ok, though I'll give info for you anyone who may want info at a later point. We use the HBS 3 Hybrid Backup Sync app from the QNAP app store (which is a free first party app). With the USB drive connected to the QNAP, I created a job and configured the source and destination. Schedule set to run automatically when the drive is connected and eject when the job completes (this is annoying if the job fails, as it still ejects the drive) Job rules set to include filters, specified with the following parameters: Include files dated within the last 7 days and only *.vbm and *.vbk files. Exclude *.vib files (reason being that we do incremental backups with synthetic full backups created on a weekly basis - with different servers scheduled on different days as to not overload the CPU in the QNAP. Therefore all servers have a .vbk file created dated within the last week - a full backup file that can be used for a server restore). Since the drive and USB port on the QNAP are both USB 3.0, the job that ran earlier this week reported an average file transfer speed of 137.88MB/s and took a 7 hours, 19 minutes and 11 seconds to transfer a total of 3.46TB (we are a relatively small secondary school and our data volume isn't massive). I hope that helps.
×
×
  • Create New...