Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. We were in the same position, but IT hardware is our responsibility. We simply provided our site team with a an older desktop with our standard Windows 10 1709 image (which we were deploying at the time). Since then, we've upgraded our site to 1903 and chose to leave that machine alone. It is a domain joined machine and uses a local account for the site team to log in and use the software. If hardware fails, we'll repair/replace as necessary and we will ask the heating company to reinstall and reconfigure the software if required.
  2. Office 2019 is basically Office 365 1808. So anything implemented in Office 365 since 1808 is missing in 2019. You are entitled to install/use Office 365 as part of OVS-ES and it works great for staff/students to use personally or on one-to-one devices. However when you deploy it in a shared environment, such as an IT suite, you'll encounter all sorts of licensing issues.
  3. If I remember correctly when I was doing this testing - Office 365 worked with SSO (from Windows) for about the first 5 times. After that it prompted the user to sign in. Some users could sign in, some got errors. Even those who were able to sign in had activation issues in Office and it was unusable. This was also the case when Microsoft introduced DBA (predecessor to DBS) and we found out that a A1 license was required, which was extremely difficult to obtain outside the US. The DBA method required a hybrid Azure AD domain and registering the devices, which apparently worked. I received an A1 license just after Microsoft ditched DBA for DBS, which was extremely annoying. Honestly, without EES and DBS, I don't think you can get it working correctly. We just pushed Office 2019 instead.
  4. In that case, when you renew your license, your supplier should put you on EES anyway due to how the model works.
  5. Unfortunately it's tied to how many users you have, so if you don't have 1000 or more students, you're stuck on OVS-ES.
  6. Basically, if you have 1000+ users, you should be on the EES licensing model. If that's the case, you can make use of Office 365's DBS licenses. However if like my school you have 999 or less users, you're on the OVS-ES licesensing model, meaning that you're not eligable for Office 365 DBS licenses. This basically rules out being able to use Office 365 because without DBS, Office 365 becomes unusable ina shared environment.
  7. We moved from Link2ICT's Zimbra service to Office 365 back in 2015 and it was one of the best decisions we made. Sure, Office 365 isn't perfect...but it integrates with AD and makes life much easier. Can I make one recommendation before going any further? Look at purchasing SalamanderAD. It's an automatic provisioning tool for AD and Office 365 that will create/disable/manage users in AD by reading from your MIS (SIMS in our case). When a new pupil is added into SIMS, SalamanderAD automatically creates the account and puts them in the right OU and group membership based on their intake year, specified in SIMS. For staff it does the same based on the employment start/end date and whether the 'Is teacher' checkbox is selected. Is will also disable and archive users when they are marked in SIMS as no longer being in school. It will also automatically provision their Office 365 account, assigning your specified Office 365 licenses (because you don't necessarily need the Yammer, Teams, etc licenses enabled for your users). We generally just have Office 365 (mailbox and OneDrive) and Office 365 ProPlus (the Office suite). However Salamander isn't really configurable by yourself, it's basically just a bunch of Powershell scripts. Just call them up or email them and they'll make any changes you need. Their support has been spot on for us over the years. They have a stand at BETT again this year, if you're going. I presume you have a non-AD integrated email service at the moment and it uses a different email format than your AD usernames? So your emails may be something like [email protected] and your AD accounts are JSmith (without the full stop), meaning your new email addresses would be [email protected]. Yes, this will be a learning curve for your staff, however it can be made smoother whilst in school by having a single sign on method. So when they're logged in to the computers, they don't need to authenticate through Office 365, because they're already logged in. Microsoft offer a couple of ways to do this. We're using AD FS, which I believe is an older way of doing it and it was superseded by Seemless SSO? I've also seen other schools have some form of portal that acts as a SSO method. So they log into a portal with their AD credentials (including from outside school/home) and there's a link from there to Office 365, meaning they've already authenticated so they don't have to again. You'll need to ensure that all users have their email address entered in the email section of their AD account properties. You can also use the SMTP Proxy field to add alias addresses and specify the default. For example, when we transitioned from [email protected] to [email protected], we utilised the SMTP Proxy field to include the following; SMTP:[email protected] smtp:[email protected] Note the difference in capitalised and non capitalised SMTP. The capitalised one denotes that that is the primary email address. The lowercase smtp is an alias address (which in your case would be your users old email format). Any emails sent to the address specified in the lowercase smtp would still arrive in the primary mailbox for that user. However this only applies if you're keeping the same domain name. Another important implementation we made was a GAL (Global Address List). We were able to split the mailboxes into two sections, staff and students. The reason for this is because we want the staff to be able to search the directory for everyone, including students. However when students search the directory for recipients, we only want them to see other students. If they need to email staff, they can either reply to an email first sent by the member of staff to them or the member of staff provides them with their email address directly. This GAL separation was a management decision. I can't think of anything else at the moment, but I'll update you if I remember more.
  8. I wouldn't, that will most likely break a lot of other sites. For example, we blocked the .io TLD and it broke a few educational sites we're subscribed to because those sites have some content hosted on a .io domain.
  9. We use OneNote for that, our documentation and a whole range of other stuff.
  10. It still happens for us on Windows 10 1909. We've given up on it now and have the printers listed in AD and provide shortcuts to printers on both staff and student's desktops.
  11. Once you ran DelProf, did you then install SIMS or any other applications, or copy other files to it? Data recovery for something like this has been hit or miss for me. I'd mount the HDD to your machine using a SATA>USB caddy and use a program like Recuva to see what it can recover. I would prep the user for the worst and anything you get back is a bonus. I did once use EaseUS but it's a paid application. It does have a free trial, but I can't remember what form the restrictions took, such as a 30-day free trial or recoverable data was limited to 1GB or something. Regardless - take the HDD or the whle machine and provide a temporary one - you need to make sure they don't write more data to it because that'll permenantly overwrite 'deleted' data.
  12. We received this from Link2ICT about half an hour before Capita's official statement: I guess they hadn't had the update from Capita yet!
  13. When I click the button it takes me to a Capita software services login page, powered by ServiceNow.
  14. I got one to that was addressed to ~100 recipients My boss got one that was addressed to ~100 different recipients Our public enquiry mailbox got one that was addressed to ~100 different recipients again Someone did an oops.
  15. It shouldn't need to be applied to the computer. The only Chrome based policy I have configured on the computer side is to disable Chrome's automatic updates. Everything else is controlled by the user policies.
  16. I never did deploy Microsoft Whiteboard site-wide because staff had no use for it, since they have SMART Notebook. However during testing, I deployed it as a store app via SCCM....but I still had Do not connect to any Windows Update Internet Locations configured. I believe you can get the AppX package and deploy it via a Powershell script, however that isn't the route I took and don't know where those files can be located. Edit: Looking back at my SCCM deployment, I can see AppX packages in my Sources folder (specifically for version 18.1009.2209.0); Microsoft.NET.Native.Framework.1.7_1.7.25531.0_x64__8wekyb3d8bbwe.Appx Microsoft.NET.Native.Framework.1.7_1.7.25531.0_x86__8wekyb3d8bbwe.Appx Microsoft.NET.Native.Runtime.1.7_1.7.25531.0_x64__8wekyb3d8bbwe.Appx Microsoft.NET.Native.Runtime.1.7_1.7.25531.0_x86__8wekyb3d8bbwe.Appx Microsoft.VCLibs.140.00_14.0.26706.0_x64__8wekyb3d8bbwe.Appx Microsoft.VCLibs.140.00_14.0.26706.0_x86__8wekyb3d8bbwe.Appx Microsoft.Whiteboard_18.11009.2209.0_x64__8wekyb3d8bbwe.Appx Microsoft.Whiteboard_18.11009.2209.0_x86__8wekyb3d8bbwe.Appx If I remember correctly, you needed all of the above files for it to deploy, or at least all the 32-bit files for a 32-bit deployment and all the 64-bit files for a 64-bit deployment. I just had them all in the same location and two Deployment Types in my Application within SCCM. SCCM treats this application as a Windows app package deployment, rather than a MSI/Script deployment.
  17. We have Do not connect to any Windows Update Internet Locations enabled and that setting has been enabled for many years. When I was testing Microsoft Whiteboard a couple of years ago, I'm pretty sure that it worked without having to change that setting. How are you deploying Microsoft Whiteboard? Is it built into your version of Windows 10 or are you deploying the AppX package? When I was testing, it wasn't in the OS, it was a AppX package.
  18. Bombshell - 7/10 Saw this last night and liked the film. Based on true events of sexual harrasment at Fox News from only a few years ago, most of which appears to have either passed me by or I've forgotten about. I thought that Charlize Theron's performance was very good.
  19. I was just reading your previous post about GAME stores closing and the article mentioned that Intu are one of the companies GAME are unhappy with regarding rent costs and want them to reduce the rates - Intu are less likely to reduce the rate with a debt of £5bn!
  20. CHiLL

    Exams

    Most of the time we don't log the devices in ourselves, we have instructions for the pupils to follow before the exam officially starts. We have 99 exam accounts in AD and our exams officer allocates those accounts to a specific pupil for the duration of the examination period. The computer or laptop that is being used has a copy of those instructions. So our procedure is: 1) Copy the paper and other materials to the shared drive 2) Exams invigilator sets up the rooms and places instructions 3) Students log on with their instructions 4) Students copy the open their exam software (ExamWritePad for us) and save it to their Documents 5) Students start and finish the exam 6) At the end of the exam, before the student leaves, completed papers are then printed by ourselves and co-signed by the student. 7) We then archive off and wipe the Exam home folder areas. We generally don't use lots of rooms at the same time because we'd need an invigilator per room and we don't have enough (or simply won't employ more) exam invigilators. We always ensure there are spare computers or laptops available. The only time this is different is when we do Pearson online tests because they all log in to the computers as the same basic account and use the Pearson software, with specific Pearson login details. (Pearson software has restrictions built-in to prevent using other software at the same time - it's full screen and locks out if it detects 'loss of focus'.
  21. I haven't tested it, but we use Claro Read Pro and I believe it would read back a selection made from EWP.
  22. In your second screenshot, I do not have Move contents of Deskop to the new location checked. My Policy Removal section is also set as Leave the folder in the new location when policy is removed. My share permissions are: Everyone: Read. Domain Admins: Full Control. My folder permissions are: Users: Read & Execute. Administrators, Domain Admins, SYSTEM are all inherited Full Control.
  23. AppLocker should present a blue modern/metro style access denied message when you try and run an app that's blocked by AppLocker. I would try isolating the specific GPO that is causing it to stop running by creating a new OU with blocked inheritance and adding each individual GPO individually until you find the culprit. Then go from there. I've stumbled into that hole a few times, absolutely sure it was a specific GPO causing issues when it wasn't.
  24. The majority of our printers are leased and the lease company provide software called FMAudit. FMAudit scans the network for all printers and detects levels and other printer stats. Our lease provider uses this information to automatically trigger a toner order once one of their supplied printers gets below a certain level of toner. For the most part, it's worked pretty well.
  25. Entry submitted.
×
×
  • Create New...