-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
After the 30 second delay, it does automatically log the user in without any further prompts (aside from the necessary Apple privacy disclaimer that just needs dismissing). I can confirm this in the diagnostics page where it shows the user's UPN. I have another app configuration for managed devices deployed, specifically targeting Microsoft Authenticator that has the following configuration: Configuration key: sharedDeviceMode Value type: Boolean Configuration value: true I don't know what would happen if I remove that, since I'm not actually using Shared Device Mode, but Shared iPad instead. However it appears to be working correctly, so I think I'll leave it alone for the moment.
-
Intune > Apps > App Configuration Policies > Create a new managed device policy and target it against the Smoothwall app > Enter XML data SmoothwallSerialNumber REPLACE WITH YOUR SERIAL NUMBER SmoothwallLegacyOrgID REPLACE WITH YOUR ORG ID UserID {{devicename}} UniqueDeviceID {{devicename}} HomePageURL https://www.{schoolname.council.sch.uk} SSOProvider Microsoft UsersIDsAllowedToSSOSignIn @REPLACE WITH YOUR EMAIL DOMAIN - E.G: @schoolname.council.sch.uk - Include the @ sign CanStoreSSOUserIDInCloud Deploy that configuration the the device group that contains your iPad(s). I've found that once the user logs in and is on the home screen, the Smoothwall browser will take approximately 30 seconds to work with SSO. If the user tries to use it before that, you will see the SSO login screen. It's been a bit of a nightmare getting the iPads to the stage that they're at at the moment.
-
We've disabled Safari and only deploy Smoothwall Browser to the iPads (so it's the only browser option), as we are subscribed to Smoothwall Cloud Filter and Smoothwall Monitor and it allows us to monitor and log usage. The app configuration was a bit of a nightmare with a lot of back and forth between their support departments. I can provide the PLIST of my Smoothwall app configuration, though it's only worthwhile if you're subscribed to either Smoothwall Cloud Filter or Monitor. Company Portal doesn't work in a shared environment from what I can gather, it's only really useful for one-to-one devices, such as an iPad assigned to a specific individual and they self-enroll the device. I have only deployed the Microsoft apps (including Authenticator), Smoothwall Browser and some other education apps, such as PiXL.
-
I am in the testing phase of shared iPads and I have found the same behaviour. We are deploying the Smoothwall Browser to replace Safari and that does pick up the SSO and is signed in automatically (bar a 30 second delay after sign-in is complete), however the Microsoft apps will not use SSO from the device sign-in. However, if you sign into one Microsoft app, it signs you into them all via the Authenticator app. My Intune configuration appears to be the same as yours, though my SSO sign-on app extension has a few apps defined:
-
Software Requests and renewal how do you handle this?
CHiLL replied to AlteredAdmin's topic in Licensing Questions
We didn't have a "process" until fairly recently (I say process, but it's really just a spreadsheet). Our finance officer got fed up with being sent invoices for software renewals that they didn't know about/no order raised and along with our network manager, they created a Microsoft List that contains the product, vendor, reason for the contract, renewal date, last renewal price, who is responsible for it (person or department), budget that it's assigned to, order number, cancellation period, data sync with MIS, etc. This list includes everything from Microsoft licensing, MIS, safeguarding, library system, subject subscriptions (Maths Watch, GCSEPod, etc), printer leasing, web filtering, etc. While it doesn't help for the actual procedures for decision making/procurement, it has definitely been useful for tracking random invoices or other surprises. -
I've been meaning to look into Autopilot v2 but haven't got round to it yet. You don't need to deal with the hardware hash, however they will be enrolled as personal devices and you need to register them using their make, model and serial number to turn them into corporate devices.
-
We found that a lot of limitations were being caused by inferior HDMI cables and especially HDMI adapters in trunking. We now run HDMI 2.0b cables (4K60Hz) between the TV and the dock, as the installer installed a Vision TC3 HDMI module, which was limited to 4K30Hz and causing a lot of signal issues between the laptop and TV. The 4K60Hz version of this is eye wateringly expensive, which is why we decided to do direct runs.
-
A car vs money scenario... Please help me make up my mind!
CHiLL replied to AB_IT's topic in General Chat
I have a 15 year old Mazda 2 and it's been rock solid. I do want to replace it with a Mazda 3 Gen3, but purchasing a house is the financial priority for me at the moment. The CX-30 is effectively a taller Mazda 3 and both appear to have very good owner reviews. -
"ai.exe - bad image" also affected Impero and they said it was because it hooks into every running DLL, which caused issues with this updated executable with Microsoft. Their temporary solution was to add "ai.exe" into their injection exclusion list within the Impero server and that stopped the issue straight away. I don't know if this is how Senso works or if they have a similar solution.
-
It's all come down to safeguarding and the inability to track student usage of websites visited on iOS, such as a student searching for self harm for example. We've previously used signing sheets that teachers filled out before handing the iPads out, but that lead to a lot of incomplete forms that were useless for tracking usage. We already subscribe to Smoothwall Monitor and will be purchasing Smoothwall Cloud Filter for deployment with DFE laptops at home (both of which include the use of iOS devices in their licenses). However, to use it with iOS, the iPad should be in shared mode to enforce users to log in with their Apple ID/federated Entra credentials, where the Smoothwall Browser app will use SSO to determine who they are, log what they are doing in the browser and send to Monitor if necessary. We only have 32GB iPads and I've only been using it on the spare iPad I have access to, though I am almost ready to push to a single class set for further testing. I have configured the policy that will delete the oldest profile from the iPad when the next student logs in, so I'm assuming this will alleviate the storage limitations that are required?
-
We have for a long time had grab and go iPads and whenever they needed the camera enabling on them, we'd have to do it via Intune and remember to disable it again. To sync any photos taken, we use QFile to copy them to our QNAP (a script running continuously on our file server then copies the photos to the staff shared area) and the app is manually configured on each iPad, along with a passcode to prevent students from changing settings. We are now looking at moving to shared iPad mode and part of my testing has shown that the app configuration for QFile is saved in each user's profile. Does anyone know of a way that I can achieve automatic photo syncing to the QNAP via an iOS app, ideally one that supports an app configuration policy/XML that can be deployed via MDM. I'd rather not open the shared folder on the QNAP to allow anyone to copy data to it if I can help it.
-
We've had experience with Ricoh, Kyocera and Xerox over the past 10 years of managed print services. The Kyocera machines were the least reliable, followed by Xerox and Ricoh respectively (Ricoh weren't without their issues either). We are currently investigating SHARP, following a recommendation with a technician from another local secondary school. If I recall correctly, we are pushing about 2m copies per year, across 4 large MDFs, 3 medium MFDs and 20 smaller MDFs.
-
We also use HP ProBooks (specifically the 450 G8, 450 G9 and 44 G10 models). They've been fairly solid in the 12+ months we've had them, though we have found that replacing the keyboard if a key cap breaks is a nightmare (the whole unit needs disassembling entirely) and we've had one USB-C port and repaired under warranty. I think next time round, I'm going to look for models with more easily replicable keyboards and two USB-C PD/Thunderbolt ports for resiliency.
-
Why not leave the icon there but restrict access with AppLocker?
-
It's different people and we don't have a great solution for the actual initiation process but the powers at be don't seem bothered enough to revaluate it at present. In our main/public reception, there's a panic button. When that button it pressed, it triggers two flashing lights; one in the school/internal reception and one in our office. If that light is flashing, the office staff know to ring the bell in the specific lock down pattern and we know to push out the notification via NetSupport Notify. The obvious disadvantage of this is if either of the three offices are unmanned for any reason, a vital step could be missed.
-
We are also a Microsoft school with some of these 64GB laptops. The only solution we've come up with is to use the compact OS feature: https://www.elevenforum.com/t/enable-or-disable-compact-os-in-windows-10-and-windows-11.3556/. It may only save a handful of GB at most, which still renders the laptops useless as shared devices. However, they have been mostly manageable as one to one devices. We also only deploy the absolute bare minimum to these laptops, Windows, Office, security/management software and that's about it to keep size down. Windows updates tend to suck on them though, so we've kept storage sense enabled.
-
Digital Support Technician - Stroud, Gloucestershire - £26,899
CHiLL replied to newpersn's topic in Educational IT Jobs
Three job responsibilities for one salary? I'm sure people will jump at the chance... -
We are using the HP USB-C G5 Essential Dock for about a year now and they've been pretty reliable. Most issues we've encountered are issues with the connected laptop or external devices than the dock itself. We haven't locked ours or anything like that and haven't had any issues of them going for walks. If any do go for a walk, then we'll likely use the timetable to figure out when it was last there and start having chats with people and if it persists, then it'll be raised with management.
-
Thanks for discovering this, we've just encountered this after switching from A1 licenses to A3 licenses. Despite not using Bing as our search, it was the only way to get it working. By default, that setting is set to "School search" and "Primary/Secondary/K-12". The only option to get it working for us is "School search" and "Higher education", with any other combination resulting in "Coming soon".
-
WCAG 2.2AA Standard for school websites?
CHiLL replied to PotNoodleTech's topic in Internet Related/Filtering/Firewall
Is this literally just a statement on the website? On Juniper's own website, they list a portfolio of websites that they host, all of which have the accessibility statement link. 90% of them are just blank pages with no content, but a small handful have content. Can we just copy what other sites have done, amend the wording and that's it? Or is there other stuff (Juniper reference amending things in the CMS). -
WCAG 2.2AA Standard for school websites?
CHiLL replied to PotNoodleTech's topic in Internet Related/Filtering/Firewall
I was just about to create a separate thread about this until I saw this one. Why are we being forced to pay extra for them to do this, when they are the ones who created/designed the website and should ensure it meets the necessary requirements, especially given who they mostly have as customers? So the consensus seems to be that we can just create a new page for our accessibility statement and amend the template? Is there anything else we'd need to consider? -
Checking the SMSPXE.log file in "%ProgramFiles%\Microsoft Configuration Manager\Logs" would probably be your best bet. Have you also tried another NIC in the device, such as a USB device? You could also create a new boot image, duplicate the TS and edit the new TS to use the new boot image instead of modifying the existing and working boot image and TS, which could potentially break both.
-
Being asked to open all outbound ports
CHiLL replied to snagrat's topic in Internet Related/Filtering/Firewall
What @Oaktech said. ChatGPT outlines some security concerns for this request, with the key takeaway being: -
I don't remove AppX packages anymore, in fear it might break something else in the future if it's not there (like removing the Store did back in the day). Instead I have AppX restrictions in place preventing users from launching the applications. It does mean they still appear in the Start menu, but they're harmless there.
- 6 replies
-
- mdt
- office 2021
-
(and 2 more)
Tagged with:
-
SCCM & Intune Co-Management - Preventing Primary User
CHiLL replied to CHiLL's topic in Cloud Services
Unfortunately not. I raised a case with Microsoft's Intune support and they said the only solution would be to go through each device in Intune and manually remove the primary user, which I did and it was tedious. Research from Google and AI will lead you to believe you can do it via the Graph API, but you can't anymore it seems. Microsoft confirmed that it was possible via the now depreciated MsGraph but it cannot be done via the new MgGraph. Maybe that functionality has since been into MgGraph, but I'm not holding my breath.
