Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. I remember having issues when I was trying to run it from a UNC path, where it would just error with a generic message. Instead, I had to copy the folder with setup.exe and the XML files to my local machine and run it from there. Once it downloaded, I copied the files back to the UNC folder for deployment. Do you have SCCM? Because it can sort out a lot of that for you.
  2. I have mine activated via KMS, which I obtained the key for from our VLSC. Install the key on your KMS server/AD activation method and use the standard KMS client key on all your clients (same key for everyone, specified in the config XML). I don't use MAK keys. Using AUTOACTIVATE will tell Office to go look for a valid license, usually via KMS. Once KMS grants it, Office is automatically activated. Note: KMS activations only last 180 days, then they request a new activation. So if a device is off the network for more than 6 months (staff laptop without a VPN for example), then it will limit Office's functionaliity until it's activated again. Usually it's automatic once the device re-joins the network (and may Word or something is opened).
  3. I don't think you need to worry about shared licensing in regards to DBL for Office 2019. I had mine deployed since 2019 and looking at my config XML in config.office.com, it only has User Based selected. However, if I check my actual deployed XML file, I have added: I think Device Based Licensing only applies to Microsoft 365 (formerly Office 365) apps.
  4. Yeah, starting with Office 2019, Microsoft did away with the old MSI deployments and it all went purely C2R.
  5. That configused me at first, but you don't download anything from VLSC for Office 365. You need to download the Office 365 Deployment Tool: https://www.microsoft.com/en-us/download/details.aspx?id=49117. Run/extract the contents, which will contain setup.exe and some sample XML. You can go to https://config.office.com/ to create a cutsom XML file with your requirements of how Office is configured and download it. Once you have your customised XML file, you can download Office by running the following command (which will download Office 365 into a sub folder of that folder structure): \\server\share$\O365\setup.exe /download \\server\share$\O365\config.xml To then deploy Office, run the following command: \\server\share$\O365\setup.exe /configure \\server\share$\O365\config.xml
  6. I think 1 VUL license covers 5 workloads (5 VMs, or 4 VMs and a physical server, etc). So if you have 17 VMs, you need to buy 4 VUL licenses. I didn't know the rest of that, which is more reason to buy a perpetual license while you can.
  7. We originally bought a perpetual license with maintenance support in 2015 and had it until 2018, where we didn't renew the maintenance. With the vulnerabilities discovered in VEEAM earlier this year, we decided to try and renew the maintenance agreement, so we can update to v11 (was on 9.5). We had three options; the new VUL subscription model, renew our old traditional perpetual license, or purchase a new traditional perpetual license. While the VUL was cheaper, we decided to to go down the perpetual route again, with the the plan of not renewing the maintenance after next year and keeping it on v11 for the next few years. Our main issue with the VUL was that VEEAM is completely unusable if you don't renew the VUL, whereas the perpetual is. With the perpetual license, it was actually cheaper to buy a new perpetual license than the renew the existing license, because they were trying to backdate support during the years we didn't have an active maintenance agreement, on top of the cost of the renewed license.
  8. We're generally up to 30, but have had an instance before of 60 (two class sets), so I just created 100 exam accounts, which I keep disabled. I only enable the accounts that our exams officer wants to use during that time and disable them afterwards. I also have a script to copy the contents of the exam account home folders to an archive, then delete the contents of the home folder, so they can be re-used without anything left over.
  9. I'd imagine that could cause other issues. The main one I can forsee is if the app or device crashes and they need to re-open their existing document. Unless I'm wrong, as far as EWP would be concerned it can open all files in that home folder because it's all authored by the same user. My solution for that was to create a bunch of exam accounts, Exam01, Exam02, etc. Our exam's officer knows these and assigns them to individual students, with printed out instructions for them to follow. These accounts are all locked down by one GPO, so they can't do anything outside of what we want. Another problem of using just one network account is when you need to enable spell check for only certain students and have it disabled for everyone else. EWP lets your specify an AD security group of specific accounts that have spell check enabled. Just add the exam accounts you wish into that group and they'll have spell check, while disabled for everyone else.
  10. I still have Private Internet Access, though I haven't used it abroad or attempted to watch things like Netflix. I am considering switching to ExpressVPN, which seems to be a very popular sponsor in the YouTube and Spotify ad-spots space.
  11. I started using a dehumidifier when drying my washing inside a couple of years ago and it makes such a difference, and drastically reduces the amount of time it takes them to dry. Especially if you shut your washing and dehumidifier in a small room, with less air for it to process.
  12. We deploy our Start Menu Layouts (as in the pinned icons) via GPO and target specific user OUs. For ease, we only have two defined Start Menu layout configurations - one for staff and one for students. The XML files are stored on our NETLOGON folder for easy access and editing. However, we do have some staff (mainly office staff) who are allowed to have custom desktops and Start Menus (by not applying the GPO to their OU or using block inheritence). For the actual Start Menu application list, we use redirected Start Menus (also configured in GPO), and just like the layout, we have one for staff and one for students, with some staff being allowed their own. For department specific applications, like Scratch for IT, I have an icon in the redirected Start Menu. If someone logs onto a PC without the software installed, they just see a white icon indicating it's not installed. For those that have it on, the icon is populated. We have sub-folders for subjects in the Start Menu, so it's less obvious that a bunch of applications aren't installed. The folder redirection lives on shared folders on the staff and student servers respectively. As for the image, I have the same image (via SCCM) that is pushed to all devices across the school. SCCM manages what drivers, apps, etc are then installed onto that machine. It just means I only need to change/update one OS/Task Sequence instead of multiple.
  13. That's interesting, I'm seeing the same thing. Presumably 1909 is the most up to date of the two (despite the update dates), since it's made from a newer build. It's probably just that they've recompiled the ISO for 1809 to include more updates out of the box. I think the Server editions that specify a year, 2016, 2019, 2022, etc are the LTSC versions. With the editions named just "Windows Server Standard" and "Windows Server Datacenter" being the SAC versions.
  14. I use the LTSC versions, as it's effectively like the older releases of Server XXXX every few years, with only security and critical updates to worry about and extra support lifetime. I'm not sure I like the idea of a production server adding extra features every few months by itself or upgrading it more frequently.
  15. We're with AltoDigital (now Xerox) and are consistently having issues getting parts, consumables and even engineer service for our Xerox printers. The most annoying thing is that we aren't being told about shortages until we have to enquire. They have monitoring/order triggering software installed on the print server to automatically order toners when they get low. But since they have no stock, we aren't receiving anyting and have to chase them when it eventually runs out and stops working. I just wish they'd send an email or something when it's triggered that they have no stock and what their ETA is.
  16. DM sent!
  17. My Always-On VPN has been working for a couple of years now and we're currently using Sophos XG. Here is my config: XML: domain.local true external.fqdn.sch.uk IKEv2 Eap 2500025trueCA.domain.local25 1a 81 b5 d6 7f c7 1b 94 cd 80 a1 52 c1 be 9f 7e ed e5 8c truefalse13truetrueCA.domain.local25 1a 81 b5 d6 7f c7 1b 94 cd 80 a1 52 c1 be 9f 7e ed e5 8c falsetruetruefalsefalsetruetrue SplitTunnel true true domain.local .domain.local 10.22.11.11,10.22.11.12 Powershell script to deploy VPN and XML: $ProfileName = Always-On VPN' $ProfileNameEscaped = $ProfileName -replace ' ', '%20' $ProfileXML = ' domain.local true external.fqdn.sch.uk IKEv2 Eap 2500025trueCA.domain.local25 1a 81 b5 d6 7f c7 1b 94 cd 80 a1 52 c1 be 9f 7e ed e5 8c truefalse13truetrueCA.domain.local25 1a 81 b5 d6 7f c7 1b 94 cd 80 a1 52 c1 be 9f 7e ed e5 8c falsetruetruefalsefalsetruetrue SplitTunnel true true domain.local .domain.local 10.22.11.11,10.22.11.12 ' $ProfileXML = $ProfileXML -replace '<', '<' $ProfileXML = $ProfileXML -replace '>', '>' $ProfileXML = $ProfileXML -replace '"', '"' $nodeCSPURI = "./Vendor/MSFT/VPNv2" $namespaceName = "root\cimv2\mdm\dmmap" $className = "MDM_VPNv2_01" try { $username = Gwmi -Class Win32_ComputerSystem | select username $objuser = New-Object System.Security.Principal.NTAccount($username.username) $sid = $objuser.Translate([system.Security.Principal.SecurityIdentifier]) $SidValue = $sid.Value $Message = "User SID is $SidValue." Write-Host "$Message" } catch [Exception] { $Message = "Unable to get user SID. User may be logged on over Remote Desktop: $_" Write-Host "$Message" exit } $session = New-CimSession $options = New-Object Microsoft.Management.Infrastructure.Options.CimOperationOptions $options.SetCustomOption("PolicyPlatformContext_PrincipalContext_Type", "PolicyPlatform_UserContext", $false) $options.SetCustomOption("PolicyPlatformContext_PrincipalContext_Id", "$SidValue", $false) try { $deleteInstances = $session.EnumerateInstances($namespaceName, $className, $options) foreach ($deleteInstance in $deleteInstances) { $InstanceId = $deleteInstance.InstanceID if ("$InstanceId" -eq "$ProfileNameEscaped") { $session.DeleteInstance($namespaceName, $deleteInstance, $options) $Message = "Removed $ProfileName profile $InstanceId" Write-Host "$Message" } else { $Message = "Ignoring existing VPN profile $InstanceId" Write-Host "$Message" } } } catch [Exception] { $Message = "Unable to remove existing outdated instance(s) of $ProfileName profile: $_" Write-Host "$Message" exit } try { $newInstance = New-Object Microsoft.Management.Infrastructure.CimInstance $className, $namespaceName $property = [Microsoft.Management.Infrastructure.CimProperty]::Create("ParentID", "$nodeCSPURI", "String", "Key") $newInstance.CimInstanceProperties.Add($property) $property = [Microsoft.Management.Infrastructure.CimProperty]::Create("InstanceID", "$ProfileNameEscaped", "String", "Key") $newInstance.CimInstanceProperties.Add($property) $property = [Microsoft.Management.Infrastructure.CimProperty]::Create("ProfileXML", "$ProfileXML", "String", "Property") $newInstance.CimInstanceProperties.Add($property) $session.CreateInstance($namespaceName, $newInstance, $options) $Message = "Created $ProfileName profile." Write-Host "$Message" } catch [Exception] { $Message = "Unable to create $ProfileName profile: $_" Write-Host "$Message" exit } $Message = "Script Complete" Write-Host "$Message" This is deployed via SCCM to a machine collection not user collection. I don't know why it works this way, but I couldn't get it working deployed to the user. The only caveat is that the first user to sign into a device with this deployment assigned (including your domain admin account used to prep the device) will get it installed automatically. The next time a user logs on, it doesn't re-apply. So when I issue out laptops, I get the user to log on before they take it, then manually press the install button in Software Center to force install the VPN. (May require the "Allow end users to attempt to repair this application" in the deployment settings). Another bug that I've found is that the VPN will randomly remove itself from the user's account, for reasons I've never figured out. To fix this, you need the user to bring the device in, log on as that user and repair the VPN installation from Software Center. Another thing we had to configure on our side was making sure that all paths, be it shortcuts, GPO policies, SIMS, etc referenced the FQDN path instead of the NetBIOS name for network devices. Due to it being split tunnel, it was trying to find NetBIOS paths on the user's home network instead of tunnelling it to the domain.
  18. Production SAN Total Capacity: 17TB Used Capacity: 10TB Backup NAS Total Capacity: 58TB Used Capacity: 37TB Small Backup NAS 1: Total Capacity: 12TB Used Capacity: 12TB Small Backup NAS 2: Total Capacity: 12TB Used Capacity: 12TB
  19. I have the students machines set to 14 days and staff to 60 days (to account for the summer holidays+buffer). GPO works well and I no longer use DelProf2.
  20. We use a ticketing system, but I tend to make a distinction between IT support requests/resolutions and IT documentation. The ticketing system is great for going back to look how to resolve an issue, but not good for documenting procedures for configuring system services like Core AD services, VMware, SCCM, VEEAM, etc. For that we use OneNote as much as we can, though I tend to only document big projects or the repair of something that's failed and needs reconfiguring, should it happen again. I tend to find that I'll not make many notes if I'm noodling around on a side project to see if I can get something working or if it'll be useful. Then it ends up working and actually useful, so it becomes a live production service, with little documentation aside from stuff I happen to remember.
  21. If you have other services available to you, I'd consider reaching out to other companies, like Wave9 for example. We are currently with Virgin Media Business directly and in the process of switching to a 1Gb link from Wave9 and both are significantly cheaper than anything our LEA could quote. Plus no stupidly long contract length. My my experience with a notoriously bad council, I wouldn't put much faith in their promise to upgrade their infrastructure if they offered me that deal.
  22. From what I can gather, dark fibre can also refer to unused fibre runs owned by companies like BT, Virgin, etc and can be leased out to companies. Even if this dark fibre is being used by a leasee, which would send light down the cable, it's still classed as dark because the owner of the cable isn't operating it. So your LEA are saying that the installation cost of that cable would be £30,000 and want you to pay over a 25-year period. You'd then have to source your own actual Internet service on top of that? Assuming my understanding of dark fibre is right, I'd be noping out of that deal unless it was a last resort.
  23. Can you configure a RADIUS server on NetSweeper? It's been a while since I've looked at our configuration, but we have used our Ruckus's built-in captive portal in the past (we now use Sophos XG's built-in captive portal). If you can configure (or already have) a RADIUS server, then you could configure both Ruckus and NetSweeper to contact the RADIUS server to query AD. As it is querying AD, you could use security group membership to define filtering levels, so anyone in the "All Students" security group gets student level filtering and anyone in the "All Staff" group gets staff level filtering, etc. For domain joined devices, it may also eliminate the requirement for having an applicaiton installed on them, with NetSweeper querying AD for user authentication. Obviously this is all dependant on NetSweeper's functionality, which I don't know at all. Maybe someone who has a NetSweeper can confirm/deny or expand on the above. I know our old Smoothwall was able to do this all on-box without any extra software, however our current Sophos XG has a client installed on our DCs to connect into AD and query users/groups. Edit: It's worth noting that if you have an open network that anyone can connect devices to, a lot of VPN clients on phones simply bypass the filtering. It happened on both our Smoothwall and now our Sophos XG (though to a lesser extent). If a student connects their phone and turns on their VPN, they don't need to go through the captive portal and have full, unfiltered internet.
  24. Aside from Anoop C Nair, other good SCCM gudie sources are: Prajwal Desai and System Center Dudes. I think you may need to upgrade 2012 R2 to an older baseline version (such as 1606), then upgrade to CB from there.
×
×
  • Create New...