Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. We use SCCM for it. When an OS is deployed, one of the steps in the Task Sequence is to look for and install all available updates at that time. I have an update rule that runs every second Wednesday (day after patch Tuesday) to look for and download available updates. That is then deployed to a defined collection of computers. SCCM also has another feature called 'Scheduled Updates', which allows you to effectively inject the available updates into your WIM. That way there's less work for the machine to do during the OSD.
  2. I don't know about the version of Office, but if I remember correctly, Surface Go tablets can only take Store apps, so you'd need to deploy Office via your MDM.
  3. I never got mapped drives to reliably appear as Start Menu tiles, so I stopped trying and put a link to File Explorer instead (I didn't use This PC because I couldn't relaibly get that to appear either).
  4. CHiLL

    IT Room upgrade

    I wouldn't consider AIO or laptop devices for a suite. I think AIOs have too many points of failure to take out the whole device and laptops are an absolute bugger to get staff to plug them back into the trolley. We have some Windows tablets that are barely used. Not only because they're now extremely slow, but also because they were never charged. We did a mass upgrade 4 years ago and went for some HP ProDesk 400 G1 units. They're small, powerful and can mount on the back of monitors. They were great at first, however we wouldn't be replacing them with a similar form factor (monitor mounted). We've found that accessing the USB ports is an issue, as the whole screen needs to be turned and causes cables to come loose/disconnect. They only have 6 USB ports (4 rear USB 2.0 and 2 front USB 3.0), of which all 4 rear ports are taken by the keyboard, mouse, DVD drive and SMART board...leaving the front two USB ports to take all the constant use (and eventually fail). They only have one audio jack, which tends to fail after a short while of use by different users. Performance wise, they've been fine for the most part. We'll probably go down the SFF route in the future. Slim towers that offer more connectivity.
  5. I've just started watching The Umbrella Academy. Took a bit of getting into, but I'll start episode 7 later this evening. I've really gotten into it!
  6. Thanks for the response. The exclusion list on the VMs tab is empty. The Disks tab lists the VM and under 'Disks to process' states 'All disks'. The Templates tab is set to backup templates and exclude them from incremental backups.
  7. For some reason, our staff file server VM started to fail backing up on Wednesday last week. Previous job reports had been showing warnings on disk space (less than 10% remaining), which was rectified on Friday, but the job still completed sucessfully. However on Thursday, the backup completed but the verification failed with the error: Then the job failed it's rety with the following similar error: Then the job finished with a warning on Friday with the following: When I select the job in VEEAM, the VM doesn't appear in the VM list at the bottom (next to where the job log appears). However if I go into the properties of the job and go to select the VM - it is there in the list, with a size listed. If I press recalculate, the size refreshes. When I press Finish, the VM still doesn't appear in the VM list. No changes have been made to that job this calendar year and the backup files (we use reverse incremental, .vbm, .vbk and .vrb files) do appear in the backup directory. I've performed a rescan of our infrastructure, but that's not made a difference. I'm going to restart the server in a couple of hours, once a file copy completes, to see if that helps. Otherwise I'm at a loss. I could remove the VM from the job and re-add it in, but that'd create another chain. Not the end of the world, but for space reasons, I'd like to avoid that if I can. We are using VEEAM 9.5.4.2753, with no active support contract at present.
  8. We are a small secondary school of about ~650 students, with ~300 desktops and ~200 laptops/tablets. I can't recommend SCCM enough. It makes life so much easier to not only deploy Windows and manage Windows Updates, but it also manages our application deployments and endpoint protection (which requires extra licensing on top of the SCCM ones). SCCM can do much more than those that I've listed, but they're what I use it for most of the time. It will take you time to get to grips how SCCM works once it's all installed and had it's initial configuration. The things that took me the longest to understand were; Task Sequences to deploy and customise operating systems, collections to group/organise computers (especially the WQL queries) to deploy applications/updates/settings to, creating/deploying applications that don't use MSI (and having to specify the switches and defining a custom detection method), Endpoint Protection (SCEP...which requires additional licensing on top of SCCM) and Software Updates (which takes over the WSUS role) to manage and deploy updates for Windows, Office and endpoint protection. I've not been on any training for it, just learnt as I go and have been using it for over 4 years now.
  9. I believe that the script only needs to be installed once per client and must be ran in the SYSTEM context. My script is deployed out by SCCM, but I don't see why I couldn't deploy it out as a startup script via GP. Have you considered that?
  10. You can get it unlocked via Apple, as long as you have the proof of purchase. Apparently any invoice of an iPad of the same generation will do, as invoices don't contain the serial number of a specific device, only the model number. That's how we managed to unlock an iPad that we weren't able to unlock.
  11. We have the follwing GPO set for students, which disables their access to C:\ User Configuration > Policies > Administrative Templates > Windows Components > File Explorer > Hide these specified drives in My Computer: Enabled > Restrict A, B and C drives only User Configuration > Policies > Administrative Templates > Windows Components > File Explorer > Prevent access to drives from My Computer: Enabled > Restrict A, B and C drives only On our 1903 deployment as a student - if they type C:\ into the Start search bar, it loads File Explorer and displays a dialogue box stating that "This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator.". If I try and access a UNC path via the address bar in File Explorer, it displays another dialogue box stating "Accessing the resource "\\server" has been disallowed.".
  12. I don't actually know that much about the early years of Microsoft or the evil days, but I haven't come across much about that in the programme. It seems to generally besympathetic towards him. I'd be interested to watch a documentary about the other side of Gates.
  13. Does the ProPlus license cover that? That article you linked doesn't mention the A3 license. We have both "Office 365 A1 for Students/Faculty" and "Office 365 ProPlus for Students/Faculty" assigned to our users.
  14. I've had a response from SMART: I've asked if there's a way to deploy this fix via GPO or registry fix and waiting for a response.
  15. So I've been banging my head against a brick wall for months now, trying to resolve an issue with Shared Activation when using Office 365. The issue is that unless you're using Device Based Activation, Office 365 will run into licensing issues and become unusable as soon as more than a few people log onto a computer and use an Office application. This is regardless of whether you've specified Shared Computer Activation during the setup or not and you have Office 365 A1 for faculty/students, or Office 365 ProPlus for faculty/students assigned to the account. As soon as say 5 different users with the correct licensing and configuation log on, they will encounter licensing issues and become unusable. So the solution is that you need to use Device Based Activation to get this sorted. However in order to use DBA, you need to be able to assigned A1 Plus licenses, which aren't provided under the usual licensing agreements - you have to contact Microsoft to get it. Here's the kicker - it's only officially supported in the US at the moment. Other's on here have said that they've managed to contact Microsoft and get the A1 plus license assigned and can use DBA without issues. So I contacted Microsoft and...I think I'd prefer eating glass. So Microsoft started the process and had issues getting the A1 Plus license to appear. After a while, they pointed me to this link and told me to use the Education link and sign in using an on-site AD account that's been synchronised to Azure but hasn't had any licenses assigned to it. So I did that and no luck - A1 Plus still isn't appearing in my available licenses. they asked me to try logging in via that link several times as it may take a few goes - no luck. They asked to me to try another account - nope. Another account - nope. Now they're asking for proof of ownership of our domain in the way of an invoice - I'm sorry, what?! We use a school.bham.sch.uk domain and those domains were provided for free by the UK government to schools. We have full control of our DNS and can create A records as we please, but that isn't sufficient enough. I've contacted Link2ICT (our LEA's IT services) and they said that they can't provide proof and linked me to this document, which clearly states how we got our domain. I just want to deploy Office 365 across the site and for it to work without issues. How hard can it be? Sorry for the rant.
  16. Item-level targetting for this. I believe (but may be wrong) that security filtering would allow/deny the user from actually processing the item. Whereas item-level targetting is processed and then decides whether to apply the configuration or not from the result of the item-level parameter. We initially had one drive mapping policy that applied to all users and we used item-level targetting to specify who got what. However management of that policy got a bit iffy with all the different drives and it had the potential to slow down everyone's log in. Now I hav three policies, one for staff, one for students and one for admin. I still use item-level targetting to determine who gets what, but the students are no longer needlessly processing the admin/staff mapped drives entries.
  17. That GPO setting will only prevent the Store from launching, AppX packages are dealt with separately. My GPO for the store is configured as: Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Disable all apps from the Microsoft Store: Enabled Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Turn off the offer to update to the latest version of Windows: Enabled Computer Configuration > Policies > Administrative Templates > Windows Components > Store > Turn off the Store application: Enabled For disabling AppX packages, I've disabled all but the essential ones. I can allow specific ones if necessary in the future. I automatically generated a list of AppX packages from my test workstation that had the same version of Windows that these restrictions will be enforced against (because different versions of Windows have more/less/different versions of the AppX packages). To do this; 1) Create a GPO and naviagte to: Computer Configuration > Policies > Windows Settings > Security Settings > Application Control Policies > AppLocker > Packaged app Rules 2) Right click Packaged app Rules and select 'Automatically Generate Rules...' 3) Complete the wizard, using the user or security group you wish to deny access to and select Deny as the action (you can select all or specific packages from the list) 4) Once the rules appear in the list, they should all be marked as Deny against your selected user/group 5) Important #1 - Ensure the Start Menu works: You change the encry for Microsoft.Windows.Cortana to Allow, otherwise the Start Menu won't work. 6) Important #2 - Allow others to use AppX Packages: I found that I needed to create a new custom rule to allow everyone to run AppX packages, otherwise it would block it for staff and admins, despite it only being targetted to your specified user/goup. (Action: Allow, User: Everyone, Name: *) When a user in the Deny group attempts to launch a Denied AppX package, they're presented with a blue diaglogue box stating that they cannot run as it has been prevented by the administrator. Note: I've noticed that our students will be automatically presented with the dialogue box, even though they haven't done anything to trigger it. It appears that the Xbox Gaming Overlay (Microsoft.XboxGamingOverlay) is the culprit and has some form of auto-trigger that I can't find. I'm still working on that.
  18. Did you find out what registry value changed for that, because I'd have to do that change en-mass.
  19. Good to hear. How did you remove the plugin? I was thinking of a GPP delete file item.
  20. We recently upgraded our version of SMART Notebook from our licensed 11.4 to the free 19.0 version. However we've noticed that since then, PDFs have been incredibly slow to open, taking approximately 60 seconds. If Adobe Reader is opened from the Start Menu, it opens instantly. However loading PDFs directly from Explorer is slow. I initially thought it was our version of Adobe Reader causing the issue, so I upgraded to 2019.012.20036 (from 2019.010.20098) but the problem still existed. After some Googling I found a thread on the Adobe support forum from May 2019. Someone posted in their that they found that their slowness was caused by a plugin that's installed by SMART called SMARTPlugin.api (located in C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins). Removing this plugin from the directory instantly improves Adobe Reader to it's snappy opening. The poster on the Adobe forum said that removing the plugin broke some functionality, though I don't know what functionality and I haven't tested that yet. I've raised a case with SMART regarding this and will post updates accordingly, but I wanted to share it on here in case anyone else comes across this issue.
  21. Yes! I completely forgot to mention that I'd watched that, how daft of me! I really enjoyed this programme, I could watch him all day. I've only really come to appreciate him in recent years, but his trip shows are just a lovely watch.
  22. I finished episode 2 last night, but I think it's only a three-parter. Kind of wish there were more because it's fascinating!
  23. Yeah. .
  24. Inside Bill's Brain A documentary about Bill Gates, mainly focusing on the Bill and Melinda Gates foundation and Microsoft formed. I've found it facsinating and I don't think he gets as much credit as he deserves in the public eye for his work in third world coutries.
  25. Yeah. I have a Cineworld Unlimited card, so at least I didn't pay for a full price ticket. I don't regret seeing it, but I was just dissapointed.
×
×
  • Create New...