Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. Thanks for the replies. The logs for my UPS (APC Smart-UPS RT 6000 RM XL) don't yield much info and the logs only go back to 21/07/2022 - which is coincidently the first day it failed. The logs it does have show some things of note: 05.08.2022 22:43:11 Device UPS: The battery is now installed. 0x0130 05.08.2022 22:43:09 Device UPS: The battery is not installed properly. 0x012F Research shows that when it reports not installed properly, it's indicitive of a fault or complete failure of the battery. The log also includes a bunch of SMTP errors (due to incorrect configuration) The times are all over the place, because desipte the NTP settings being correct and pulling from our DC, which has the correct time, it currently thinks it's 10 minutes behind (timezone is set to London and DST is disabled). However, on the days that we had outages, there is nothing significant. We had our last outage on 29/07/2022 and these are the only three logs for that day and each day either side: 30.07.2022 19:22:36 System NTP update successful. 0x004A 30.07.2022 19:22:36 System Configuration change. 0x0033 30.07.2022 06:11:09 System NTP update successful. 0x004A 30.07.2022 06:11:09 System Configuration change. 0x0033 29.07.2022 17:02:33 System NTP update successful. 0x004A 29.07.2022 03:55:06 System NTP update successful. 0x004A 29.07.2022 03:55:06 System Configuration change. 0x0033 28.07.2022 14:42:37 System NTP update successful. 0x004A 28.07.2022 14:42:37 System Configuration change. 0x0033 28.07.2022 02:18:09 System Web user 'apc' logged out from 10.22.100.70. 0x001F 28.07.2022 02:17:19 apc Web user 'apc' logged in from 10.22.100.70. 0x0015 28.07.2022 02:16:15 System Web user 'apc' logged out from 10.22.100.70. 0x001F 28.07.2022 02:15:26 apc Web user 'apc' logged in from 10.22.100.70. 0x0015 28.07.2022 01:27:04 System NTP update successful. 0x004A We are going to replace the battery as a first port of call and also get secondary power sockets installed from another ring (will also ask for surge protection to be included, thanks @Chris_Cook. It's the cheapest option at present and also the quickest, with no lead time on batteries and a multi-week lead on a replacement UPS. While a dual UPS solution with two power sources is my ideal solution, it's very expensive. If the replacement batteries don't resolve the issue, then we'll replace the UPS and also have the power split between UPS and wall sockets. Maybe down the road, we can buy a secondary UPS and replace the wall sockets with a commando socket. At least the power won't be as expensive then, as it's already been run to the room, it just needs sockets converting. While our UPS is 7 years old, I'm hoping that the UPS itself is designed to work for much longer, assuming battery replacements are made and not accounting for actual hardware failure.
  2. Devices using the legacy MBAM have the KeyRecoveryServiceEndPoint entry and configured in the registry, pointing to the legacy MBAM server. Though on my test device, I've removed all MBAM GPOs and pushed the (correct as far as I can tell) BitLocker configuration baselines to the device. I can see that CM takes over, as the baseline shows and is evaluated as compliant, but the KeyRecoveryServiceEndPoint registry entry is missing. The recovery key is not written to the CM database and there are no entries in MBAM section of Event Viewer that say the key has been escrowed. I've been following Naill Brady's "BitLocker management – Part 8 Migration" video, which clearly shows the KeyRecoveryServiceEndPoint exists and points to the CM server. I'm kind of stuck at the moment.
  3. We've had our UPS fail a couple of times in as many months recently, so we are looking at replacing it. While the battery is well past it's EOL, the UPS put itself in battery mode, even when the power was still on. Eventually the batteries drained it everything went off. To me, this sounds more like an issue with the UPS than the battery - as it did operate (incorrectly) via the battery until it ran out. We've already got quotes in and we have secured the funding, I just have some queries before I make any commitments. Dual power sources We currently only have one power source into the server room, with all devices (incl secondary PSUs) plugged into it. We will be getting a secondary power source fitted into the room, from another distribution board. My query is regarding physical connections: A) Should we have the power terminate in DSSO sockets and have the secondary PSUs plug into those? B) Since we are purchasing another UPS, should we utilise our old UPS with a new battery and have the power terminate in a commando socket, which is then attached to the secondary UPS? I think option A) is the simplest and most common solution with B) being overkill. I was just after some thoughts on it. PSUs via two inputs Since most critical devices have dual PSUs - how does the device know which PSU to draw power from? If I choose option A) above, ideally I'd like the UPS as the primary power deliverer for the device, protecting against brown outs/spikes, etc. I'm guessing the devices aren't smart enough to choose inputs - as they won't know where it's come from, it's just power. It just got me wondering.
  4. It's not installed though is it? Isn't it just an application that's executed?
  5. For Birmingham City Council schools who have initiated the break clause - it's worth checking that the payment has gone through. With all the council's still ongoing payment issues, we had an email from ESS saying that payment is required for the break clause to be valid. It turns out that we had actually paid, just ESS hadn't actually confirmed, but it's worth those who are under BCC to check.
  6. Our IIS certificate had expired on the MEMCM server, stopping clients communicating (only found out as we saw baselines were not being received on machines and machines were appearing offline in the console, despite the client communicating with the server). I have followed my previous instructions to renew and apply the new certificate, which went smoothly. Clients are now appearing online in the console and baselines are being received. However, when I attempt to access https://fqdn.server/sms_mp/.sms_aut?mplist, I'm getting "Hmmm... can't reach this page" and "The connection was reset". It appears to be the same for all sms_mp sites. Although, the CM MBAM site (https://FQDN.server/HelpDesk/), also on the same IIS instance is working correctly. The MP and DP are configured to connect via HTTPS and the PKI is specified/correct as far as I can tell. IIS also appears to be configured correctly. If I attempt to connect via HTTP, I get error "403 - Forbidden: Access is denied.", which I think I expect, as it's supposed to use HTTPS. Site Status and Component Status are all reporting healthy. I'd like to try and resolve this, as I don't know what other knock on effects it may have to MEMCM. I've exhausted my knowledge and tried the things I can find online. I have noticed that the IIS site lives in E:\Program Files\SMS_CCM\SMS_MP, but the folder is empty. Can anyone check their folder and see if it has contents?
  7. We've had MBAM set up for years now, with the database hosted on our SIMS server. We're moving to Bromcom this summer and will be retiring the SIMS server, so I need to relocate the database. We also have MECM, with BitLocker/MBAM integration. When I originally set up MBAM, I tried hosting the database on the MECM server, but the SPN was conflicting between the two, though this was before MECM had improved it's MBAM integration. I can't seem to find any decent guides to do a migration from an existing MBAM configuration to MECM, they're mostly guides to seting up a new instance. Has anyone done this before?
  8. The lack of public acknowledgement or willingness to engage in a public forum is concerning.
  9. From what I can gather, if there are strikes planned for the dates you go away when you take out the travel insurance policy, then it would not be covered. But if you get the insurance today and the airport announce strikes tomorrow for the dates you fly...you would be covered. Is your holiday also ATOL protected? I've used the Post Office and Avivia travel insurance before, though never actually had to call on them.
  10. We only have one unit, which failed the other week. We had it repaired and now have quotes for a second unit for redundancy/reduced load. Good job it didn't fail today and I hope it lasts until at least the end of tomorrow!
  11. I don't think I've ever drank as much water in one day as I have today.
  12. Server room is air conditioned, but the condensor is on the wall which is receiving direct sunlight, so it'll be working overdrive. The edge switches in cabs are very hot to touch. I have no way of checking their temps by the looks of it.
  13. I believe the store apps are all the same across Windows builds (incl workstation and server), you should be able to create a basic template from a machine that has all the store apps installed. This is done in the AppLocker section in GP and you can then modify the apps on an individual basis. I believe it will default to blocking the specific version number that was on the template machine, but you can modify it to have a wildcard for the version number, etc. So it should then block all instances of that app, regardless of the version number.
  14. I believe so, though my knowledge on the subject is pretty limited, though I believe distance from the exchange (or even cab) doesn't matter anywhere near as much with FTTP as traditional copper (or FTTC). Also yes, the cab would need to be fibre ready, then at least FTTC can be used. You'd need to confirm with the ISP whether your building can receive FTTP. Are you able to look at other ISPs? Such as Virgin or even Dark Fibre (effetively a company using a leased line, kind of like Sky using BT/Open Reach's infrastructure).
  15. FTTP (fibre to the premesis - often also called FTTH, fibre to the home) is a direct fibre run from the cab to the building/premesis. For fibre connections to the cab only this is referenced as FTTC (fibre to the cab), which will be then a copper cable run from the cab to the premesis/home. So to answer your question, if the school have a FTTP connection, they have a specific fibre line ran from the cab to the school, only to be used by them.
  16. The Asda near me has been hovering around the 186.9 mark now for a few weeks and it was still that this morning when I filled up. I should be thankful that I only have a 43L tank, so it doesn't cost a small fortune to fill.
  17. We don't use Paxton and our Inventry isn't tied to our door system (so this may not be entirely relevant), but we don't have to faff around with entering card numbers on Inventry. We just have "autocode" enabled on a new user's account when they're created in Inventry (users are synced from our MIS). Then a user can just associate their card manually by selecting their name and scanning their card when prompted (like Papercut card association). It doesn't use the same code, it creates an Inventry specific number, but we don't have to do anything else.
  18. Just let them get on with it. They just register themselves using their school email address. I believe it also has M365 SSO too, though I'm not on site atm, so can't confirm.
  19. We're on v21 and while it is free, it requires staff need to log in/create an account with SMART in order to use the features.
  20. We used to have it set up with 5 iPads per AppleID, but were informed by our supplier that it isn't necessary any more and Apple had relaxed the rule. We just took their word for it.
  21. Take a look at this article, which suggests you need to associate your DP with your boundary group: https://www.prajwaldesai.com/application-installation-error-0x87d00607/. That site is one of the best when it comes to SCCM related guides and help.
  22. I'd be interested in the replies to this, because this is an issue that plagues our iPads. We have flattened them before, but they are asking for credentials again. One thing we do know, is that it will ask for credentials if you deploy an iOS Store App, instead of a VPP Store app. Despite not deploying any iOS store apps, we are still getting the popup. If you want to make life a bit easier, you can use one Apple ID across all iPads. That also reduces the amount of times you need to purchase an app. Syncing photos can be done if you have a QNAP or Synology NAS, as they have a file sync app that can be installed on them. There's also a corresponding iOS app, which you can configure to the iPads to point to the NAS and sync photos to that. Then all the photos are in one place and can be copied somewhere else via a script, somewhere like your staff shared area. The only downside to this, is it's difficult to identify which photo was taken on which iPad, because all the photos end up in the same place. Our script will move the photos into a new folder with today's date (such as 2022 > 07 > 08 for photos taken today). While that will still dump all photos from all iPads taken today into the one folder, it is relatively easy for the member of staff to look through and find the photos that they took.
  23. Laptop management has become less of an issue since we implemented Microsoft's Always-On VPN. Staff can just use it as if they are in school, with access to their documents, shared drives, etc, and the device still gets the GPOs and connects to MECM via the VPN. We do still manually create local accounts on the laptops, just in case the VPN doesn't work, so they could log on with .\. We used to just use the same account called "Home", but for accountability/ease of viewing logs/captures, we've decided to create the local account with the same name as their AD account. You used to be able to create local accounts via a GPP and you could target a specific local account on a specific laptop. However, due to password vulnerabilities, Microsoft removed the ability to set passwords on these local accounts a few years ago.
  24. I don't bother removing any apps now, just use AppLocker to block access to them. The main snag is that they are still visible in the Start Menu, though the user is shown a block message if they try and open the app.
  25. It's recommended to keep the store in Windows, as it's quite integral to some built-in apps, plus as others said, it's required to keep the store apps up to date. It's also required if you need to push out any future store apps, like the Minecraft Education, etc. You can use AppLocker to prevent users from then accessing the store itself.
×
×
  • Create New...