-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
While it sounds like a good idea, I'm somewhat skeptical. Student laptops, especially 1-1 devices where a student carrys it round all the time, it's likely they'll have the QR code in their bag with their laptop. If they leave it on the bus, or it's lost/stolen...isn't it just like leaving a post-it note on the laptop with your username and password, where whoever has it has free access to the laptop?
-
XMA or Jigsaw are usually our go-to suppliers for sourcing iPads. They regularly have better pricing than our other suppliers.
-
It will do the main stuff, like scheduled backups (including incremental/reverse incremental), backup to target local repositories, deduplication, etc. Backing up to cloud repositories does require licenses.
-
Veeam is likely to be the most commonly recommended, I've been using them for many years now. I've also heard good things about Altaro, though never used them.
-
This has been a renowned issue since Microsoft made changes to printing back in Windows 8 or 8.1 and made worse by PrintNightmare related patches too. We're using GPP to deploy printers and here's what we've found/do: The user's first log on to a computer (where it generates a local profile for them) - printers will not map 99% of the time If the user logs out and back onto the machine, printers will map 99% of the time We're using the FQDN of the print server in the GPP mappings We're using Point and Print settings in GP, specifying the print server by FQDN We also have all the PrintNightmare patches in place, including the bypass to allow non-adminstrators to install drivers (un-does some of the PrintNightmare mitigations - but Point and Print should at least limit drivers being pulled from a specific target) We have set the GPO "Allow non-administrators to install drivers for these setup classes" to "Enabled" and specified these GUIDs: {0ecef634-6ef0-472a-8085-5ad023ecbccd}, {4658ee7e-f050-11d1-b6bd-00c04fa372a7}, {4d36e979-e325-11ce-bfc1-08002be10318} Printing has been an absolute mess for us since about 2015, when we made the transition from Windows 7 to Windows 8.1. We ended up listing the classroom and staff room printers in Active Directory, so those users who don't have a printer can browse the directory for it. Luckily, we use follow-me-printing for staff with restrictions on the printers, so students can't print to it. For office printers, it's less of an issue as office users are less likely to have their profile wiped or we can deal with it on a as and when basis. Any students caught printing to other room's printers (evidenced by Papercut logs) are issued detentions and whatnot.
-
I'll be going for a day visit (not too difficult from Brum, so it can be done in a day). From what I understand, Connect@Bett is a way to organise meetings with specific people/suppliers, so you actually get to see them, rather than hang around their booth and hope they're free. I believe you are still able to wander round the stands as normal and speak with people if you find someone free though, like the old times.
-
Is there any MIS for secondary schools that comes close to SIMS
CHiLL replied to JamesParker's topic in MIS Systems
We moved from SIMS to Bromcom last summer. Our procedure was that Bromcom took a snapshot of the SIMS data at the start of the move, meaning we had two active MIS systems. However, we were told to keep updating data in SIMS, rather than Bromcom. Since this happened over a period of June-September, any new year 7s, exam results, etc were entered into SIMS and then a final export was done from SIMS into Bromcom at the end of summer. Once that was completed and verified, we fully switch to Bromcom as our sole MIS. Your Bromcom migration/support team will be able to clarify what you should do. Moving MIS is a multi-week process, so if you're only starting the process in February half term, it might be near Easter before it's complete. -
Thanks. I didn't know about that and have now implemented it. However, it hasn't resolved the issue for us. I have an SLT laptop that this is happening to and I've also upgraded it to Windows 10 22H2, along with the IKEv2 fragmentation enabled on the server. I have it connected via hotspot from my phone. I've just witnessed the connection terminate in person for the first time, about 10 minutes into the session. I have the Remote Access Management Console open on the server and can see the current connections. I suddently saw the connection disappear from the connected clients list. However, checking the laptop shows the VPN says it's still connected. Checking the event logs of the client laptop, there are absolutely no logs at the time I witnessed the client disconnect (11:48 in the instance as I write this post). There are also no event logs on the VPN server or NPS server for that time either.
-
I've had multiple reports from different users that our Microsoft Always-On VPN keeps disconnecting when they're working remotely, which had been running fine (for the most part) since we deployed it in 2019. The time ranges that have been reported range from every few minutes, to every 15 minutes or so. I've checked the Application Event Log for an affected laptop and noticed this entry (which also appears on other affected user's devices): CoId={3D750570-366A-0001-B505-753D6A36D901}: The user \ dialed a connection named SJW Always-On VPN which has terminated. The reason code returned on termination is 631. From what I can tell, this affects remote users more than it affects internal users. By that, I mean if I manually connect the VPN when the device is on-site, then it seems to remain connected for long periods of time. This is only a more recent issue and I'm not sure what's causing it. Our setup: Clients: Windows 10 21H2 (19044.2486) VPN Server: Windows Server 2022 21H2 (20348.1487) Firewall: Sophos XG managed by Wave9 VPN Configuration: Device tunnel, certificate based (PEAP), Ikev2
-
Cost of living crisis 2022 - what have you cut back on?
CHiLL replied to Ditto's topic in General Chat
After coming off a (very) good energy deal (March 2021 prices) that Octopus accidentally extended my contract with, onto the current pricing...it's been eye-opening. I've gone from spending £1.50-£2 on the average day to about £5 for a two bed maisonette. Lucily I already have some cost saving measures in place, like a door curtain for the top of my stairs keeping the curtains drawn all day while I'm at work to keep the heat in, etc. Unfortunately, I don't have a termostat, just a time controlled boiler, so I've amended the timings to 10 minutes in the morning, 15 mins just before I get home and another 20 mins at about 7pm. -
[bromcom] You guys getting SMTP exceeded notifications since just before xmas?
CHiLL replied to Jaan's topic in MIS Systems
Microsoft have are disabling basic authentication for all tenants in Office 365 and as such, Bromcom have disabled their Microsoft SMTP relay (https://community.bromcomcloud.com/setup-29wgkogd/post/office-365-smtp-no-longer-supported-by-bromcom-TkbxxVPiUlTKkCH). It is annoying, because that only leaves us with Bromcom's own SMTP service, which is only free us you use 3000 or less emails per month. -
It may not be related, but I had issues with SIMS/FMS over the VPN because all our paths were using the NetBIOS names, rather than FQDN. Once we changed those in GPOs and VPN configurations, SIMS and FMS started working fine.
-
[MECM 2211] Software Updates stuck on Waiting to install
CHiLL replied to CHiLL's topic in Enterprise Software
So the server with three pending updates (including the September .NET update) has these updates and run times: KB5017501 has a maximum run time of 60 minutes (reported 96% comliance) KB5021095 has a maximum run time of 60 minutes (reported 85% compliance) KB5021249 has a maximum run time of 60 minutes (reported 85% compliance) What's the best practise for maintenance windows and least disruption? Possibly a full 24 hour windows on Saturday? Edit: The SUP is configured for: Windows Windows feature updates: 120 minutes Office 365 updates and non-feature updates for Windows: 60 All other software updates outside these categories: 10 -
[MECM 2211] Software Updates stuck on Waiting to install
CHiLL replied to CHiLL's topic in Enterprise Software
Thanks for your reply. I've amended the rule to run for 12 hours (8pm - 8am) over weekends, so I'll see how that goes. I can't seem to see any options regarding timeouts, like I usually see on app deployments. As for the software availablity and deadline, they're set to asap/7 days respectively. -
[MECM 2211] Software Updates stuck on Waiting to install
CHiLL posted a topic in Enterprise Software
For a long time now and across multiple versions of MECM/SCCM, I've noticed that our servers and desktops will often get stuck trying to install software updates, specifically on the "Waiting to install" phase. For example, I have a Server 2019 server which is stuck trying to install the 2022-12 Cumulative update for .NET and also the 2022-12 Cumulative update for Server 2019. I have another server (Server 2022) that is currently stuck on "Waiting to install" the 2022-09 .NET update, as well as the 2022-12 updates for .NET and Server 21H2. I have my SUP configured to check for updates monthly, every Wednesday after Patch Tuesday and the ADR is deployed to my server group. I also have a collection that contains all my server, with a maintenance window configured for Friday, Saturday and Sunday nights between 10pm and 7am. This issue doesn't appear to be affecting desktops, though I'd need to confirm that. I can't see any configuration differences, aside from maintenance window time slots between the two configurations. Does anyone know how to resolve this, or has anyone come across this before? -
I guess the problem with constant equipment is that you're not likely to see any gains. If you run the servers off the UPS and it consumes charged battery, it's just going to pull more power when it's reconnected to charge up what it lost. If you turn off the aircon, the room will heat up a little more and the aircon will work harder to cool it back to your target temperature when it's back on. I suspect the only real gains you're going to have from an IT perspective is ensuring you schedule a machine power down in the evening (if you already have one, maybe bring it to 7pm if it's set at 9pm currently - though be aware of parent's evening requirements, etc). Possibly increasing the target temperature of your server room into the 20s instead of 18/19/20, etc. Turn on powersaving/eco modes in Windows on your laptops, set time-outs on your projectors and turn the brightness down on monitors to reduce power draw. All that being said, I doubt any of that would touch the sides when it comes to whole school power consumption. What's the point when the school props the external doors open during break/lunch or classroom transitions for example, letting all the heat out and a nice winter draught in?
-
Yeah, I can confirm that the machine I'm testing on has the regsitry keys via GPO and it has also been rebooted recently.
-
Update, it worked that once and hasn't worked again since!
-
Thank you! Implementing this on one machine resolved it immediately after a reboot. I will test it a little more before rolling it out, but it looks like this was the cause of the issue and the resolution to fix it.
-
Bump, this is still an issue for us unfortunately. Has anyone encountered this before?
-
No problem! Just be mindful that when you chain backup jobs like that, if one job gets stuck and doesn't error out, then the other jobs chained after it won't start until it's resolved or ended.
-
The other stuff that Veeam installs, I just left installed. It wasn't taking up that much space and who knows if I may need the utilise them in the future and then can't because I've removed the features. I believe you need a specific license to allow you back up both physical and virtual machines. Our perpetual license only entitles us to virtuals, so we use the free community edition on another server for our physical DC and both our technician workstations. I don't know how this works via VEEAM's new VUL though. Our VEEAM server is installed on a VM (VMware), which has 2x disks; 100GB OS disk and 100GB data disk. Veeam is installed onto the OS disk, with the default repository pointing to the data disk. I have another repository on our QNAP NAS that is used as our main backup repository. Back in the day, I used to like doing reverse incremental backups, as it means I always had the latest full backup file every night, which could be easily copied off for off-site backup. However, with ever-increasing file storage requirements, we were finding that our backups were running through the night and into the working hours of the morning too, impacting user performance accessing files, server speeds, etc. Instead, we now use forward incremental, but with weekly synethetic backups for each job (I've spread the synthetic backups on different days throughout the week to reduce workload/them all running on the same day). The benefit of having a synthetic backup means that I always have a full backup file dated within the past 7 days. We can just copy off these .vbm and .vbk files to our external storage (sure it's not of the day before, but it's only for disaster recovery and I think losing up to a week's data is less of an issue than recovering from a whole-site disaster!) For the jobs themselves, we have all VMs as separate jobs instead of jobs that contain multiple servers, as this creates a seperate backup files per server instead of one large backup file per server. Our rationale for this, is should we need to recover data from our off-site backup, we only have to download the server we need, instead of a massive file containing all servers. It also increases the speed of a disaster recovery, as you can prioritise the servers you download, such as the DCs, instead of downloading all server, including non-vital ones, such as web servers for booking systems, management servers, remote access, etc. For scheduling, we have all jobs set to start at 10pm, though limited the amount of concurrent jobs allowed to run to 4, so they all aren't running at once. Instead, once one of the 4 concurrents finished, Veeam automatically starts the next job and so on. This, combined with incremental backups has massively improved our performance and backup completion times, so they're well finished before the school is opened the next morning. Email notifications I have set to warning/errors only, as I don't want to de-sensitise myself if a job has a warning but it's lost with all the other sucessful email notifications. I know there's a fair amount in this post, not all is what you asked...but I hope it helps further inform the way Veeam can work!
-
[ms office - o365] M365 Shared Computer License & Token Roaming
CHiLL posted a topic in Office Software
I'm revisiting shared activation on M365 Apps and looking into a roaming token. Microsoft's documentation uses the user's profile location as an example path to store the activation token. Does this matter if the user doesn't have a roaming profile? So if the user goes onto another computer, would it then download a new roaming token to their profile on that machine instead? Or would it be better to point it to the user's home folder instead, such as "%homedrive\Microsoft\Office\Licensing"? If it is pointing to the user's home folder and they then log onto another machine - would Office use that existing token, or create a new one for this new machine? -
Impero Reinstall - Cannot start ImperoClientSVC
CHiLL replied to CHiLL's topic in Network and Classroom Management
My machine is running Win10 21H2 and .NET 4.8.09037. I do have KB5011048 installed. Uninstalling KB5011048 and restarting allowed Impero to install and work. Looks like I'll have to figure out how to uninstall that update site wide and and exclude it from SCCM deployment. Thanks for the replies! -
I'm trying to reinstall Impero (8.5.17) onto my workstation because it stopped working, but the installer is failing because it can't start the service. The MSI fails with the error: Service 'ImperoClientSVC' (ImperoClientSVC) failed to start. Verify that you have sufficient privileges to start system services. I have ran this as my domain admin account and local admin account (including logging on as a domain admin/local admin, instead of just running as), to no avail. 1) I can install other software that also installs a service (Sophos Connect) and that installs fine, with the service starting no problem. 2) I can install the Impero MSI on other workstations without issue 3) I have manually purged all files with the word Impero from my system and also purged all Impero related entries from the registry manually 4) I have added my admin user and the Administrators group in the Log On As A Service gpedit.msc policy 5) I have ran "MSIEXEC /UNREGISTER" and "MSIEXEC /REGSERVER" 6) I have also tried older versions of Impero This appears to be a specific Impero related issue on my specific machine. We do not have a current support contract with Impero, so I can't contact them about it. I think something is being stored somewhere regarding the ImperoClientSVC and preventing it from being replaced, whether that's borked permissions or whatever...I'm just not sure!
