-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
Office 365 A1 Plus for faculty licences missing!
CHiLL replied to CommodoreS's topic in Cloud Services
I've had a ticket open with O365 suport via the admin centre since 03/07/2019. The only response (other than the odd automated "we're investigated and will contact you with more information"), I've had a response asking for the following: The only document we've received is our "Open Value Welcome Letter" when we started our latest OVS-ES agreement. I've sent that to them and not heard anything back yet. -
I believe all of our devices are now UEFI, as they all have the options for Secure Boot, which I don't think BIOS can support? On our off-site devices like laptops, secure boot is enabled along with BitLocker, though on on-site devices, Secure Boot is disabled and we're using Legacy Boot (though I'm planning to switch them to Secure Boot at some point).
-
We have 12 VLANS at the moment, each one has it's own DHCP range, so 10.22.10.2 to 10.22.10.254, or 10.22.100.2 to 10.22.103.254. This allows us to segregate our network. We do have a VLAN specifically for BYOD, so clients connecting to the BYOD SSID only receive an IP address from the BYOD DHCP/VLAN.
-
Would separate VLANs do what you need?
-
Does anyone use both SMART Notebook 11.4/18.0/19.0 and Visigo? I'm having issues where if Visigo is already installed on the machine and I install SMART Notebook - the SMART installer will ask for a restart during the installation (specifically during the SMART Product Drivers installation). This causes issues where during automated installations, the restart prompt is hidden and will eventually time out. Even /q and /norestart commands to not suppress the reboot message. This ONLY occurs if Visigo is installed on the machine. If Visigo is removed, SMART installs without a restart prompt. If Visigo is put back on, the SMART installer is prompted for a restart. If anyone uses both - can you please test this for me? 1) Install Visigo on a machine 2) Install SMART Notebook on the machine and 1) Remove Visigo from the machine 2) Remove SMART from the machine 3) Reboot 4) Install SMART I'd really appreciate any help, because I need to gather evidence to provide to Smoothwall. Edit: The issue is easily replilated if you already have SMART Notebook installed, by running the following elevated command: For SMART Notebook 11.4: "%programfiles(x86)%\SMART Technologies\Education Software\Drivers\x64\DriverInstaller64.exe" -i" For SMART Notebook 19.0: "%programfiles(x86)%\SMART Technologies\SMART Product Drivers\Drivers\x64\DriverInstaller64.exe" -i
-
Our core hours are 8:50 to 3:10 (start of registration to end of last period). We are a fairly small school and there are only two of us, with us both working 8:00 to 16:00 Monday to Friday. At one point, we had been asked to provide cover until 17:00, so we used a shift pattern (one would work 8:00 to 16:00 and the other would work 09:00 to 17:00). This didn't really work too well because there was barely anyone in after 16:00 (this was brought in because someone high up stayed 'till 17:00 and needed support one time after 16:00. Because we weren't in, they kicked up a fuss and thus the new time pattern). The knock on effect to this was that we tend to find that 08:00 to 09:00 are much busier than 16:00 to 17:00 due to staff preparing for the day, and there only being one person available at that time (even worse if something does go awry overnight). We documented the lack of work after 16:00 and all the work before 09:00 and we managed to get our working hours changed back.
-
Managing IT jobs list over summer holidays
CHiLL replied to DrBeaker's topic in How do you do....it?
I use OneNote to manage my holiday works, specifically using the checkboxes/tasks options. The OneNote document is shared between me and my manager, so we can both see/amend it at the same time. It may not be the most elegant, but it works for us. -
Is this for a work computer or personal? What sort of workload will it be doing? If you just need to drive some monitors, then a Palit GeForce GT 710 2GB would be enough to meet your needs. When I rebuilt my office workstation a few months ago, I opted for this card to drive three monitors. It uses a PCIe x8 slot (which I can confirm because I currently have it plugged into a PCIe x16 slot and it does not take up all of the slot...and it's advertised as a x8 slot).
-
Take a look at AppLocker to prevent users from running UWP apps. Note: Do this on a test OU first Computer Configuration > Windows Settings > Application Control Policies > AppLocker Right click AppLocker and select properties. Tick Configured under Packaged app Rules Create a basic rule with the following: Action: Allow User: Everyone Name: Signed by * Then if you're editing the GPO on the same OS version that you're deploying, you can: Right click Packages Select Automatically Generate Rules Follow the wizard and change any settings as necessary, such as changing the User to your All Students security group (ensure you leave the Action rule as Allow) Go through the imported list and toggle all those you want to disable to: Action: Deny This requires a bunch of testing because some apps may run automatically every now and again in the user's context. If it does and it's blocked by AppLocker, the user will receive a popup saying that the app has been blocked by their administrator.
-
SMART Notebook 11.4 - Silent Install without reboot
CHiLL replied to CHiLL's topic in Educational Software
After a lot of testing I have concluded that Visigo is causing these issues. If I remove Visigo from the machine - SMART Notebook installs completely without asking for a restart. If I put Visigo back on the machine, SMART will ask for the restart during the installation. I have raised a ticket with Smoothwall, so I'll see where we go. If anyone else uses SMART Notebook with Visigo, can you please test it for me and let me know your results? -
SMART Notebook 11.4 - Silent Install without reboot
CHiLL replied to CHiLL's topic in Educational Software
So this morning I installed a vanilla version of Windows 10 Education 1903 64-bit (the same ISO that SCCM is configured with), NOT joined to the domain and copied the install files locally. used MSIEXEC to install the MSI and TRANSFORMS file and it installed correctly, no restart prompt. This rules out the version of Windows being the culprit. I then removed SMART Notebook and rebooted the machine, then joined it to our domain, moved the computer account into our normal teacher PCs OU (to get all of our computer policies). I rebooted the machine several times, to ensure it receives all the policies. I then installed SMART Notebook MSI (with TRANSFORMS) and it installed correctly, no restart prompt. Does this mean my only variable left here is SCCM? I'll next be taking a copy of the TS and disabling all of our drivers installations, software installations, customisations (but I'll not be amending unattend/customsettings ini files). -
Office 365 Emails for staff who get married and change name?
CHiLL replied to kennysarmy's topic in Cloud Services
As others have said - just rename it and AAD Sync will take care of the rest for Office 365. Just be sure to amend all required fields in the AD account, including some in the Attribute Editor. -
Assigning Messaging policies to groups in MS Teams
CHiLL replied to wickit's topic in Cloud Services
I have a similar thing. We don't want to disable Teams for students completely - we just want to stop them from being able to create groups. So staff can create groups and add students, and students can participate - but student's can't create groups for themselves and other students. Therefore we can't just remove the Teams license from student's accounts in Office 365. We have raised this with Microsoft through Office 365 support and they've been working on it for weeks now, with no resolution. One issue appears to stem around the fact that they would use a GAL to restrict this - however we already have a GAL in place to prevent students from searching for staff in the address book. -
SMART Notebook 11.4 - Silent Install without reboot
CHiLL replied to CHiLL's topic in Educational Software
Sorry to bump this thread, but I didn't want to create a new one for the same thing, especially since I'm the OP! So I've been continuing to battle this issue and had given up for a good while, resorting to manual installations where required instead of automated. Now we've been looking at the free version of SMART Notebook 19.0 and found it has the exact same issue that I've been experiencing - a restart prompt when it installs the SMART Product Drivers. If it an automated install by SCCM/GPO, then it will time out and fail the installation. If it's installed (even with a /q command) when a user is logged in, it will provide a popup asking to restart. If the machine is restarted there and then, the installation is cancelled and does not restart. If it is postponed, SMART Notebook will carry on installing and work correctly. I raised this with SMART and they cannot replicate the issue on any version of Windows (I've experienced this on 1709, 1803, 1809 and 1903). So I've taken a vanilla image from VLSC and installed Windows 10 Education 1903 64-bit and copied the SMART installation files to a USB drive. When installed (the exact same command line) on this fresh install of Windows (not joined to the domain)...it installs correctly without a restart prompt! The only variables I can see are the fact that we have three domain level GPOs (including the Default Domain Policy) and the fact that we deploy the OS via MDT/SCCM. The GPO settings mentioned above are: Name: Default Domain Policy Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Password Policy Enforce password history: 24 passwords remembered Maximum password age: 42 days Minimum password age: 0 days Minimum password length: 6 characters Store passwords using reversible encryption: Disabled Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Account Lockout Policy Account lockout threshold: 0 invalid logon attempts Computer Configuration > Policies > Windows Settings > Security Settings > Account Policies > Kerberos Policy Enforce user logon restrictions: Enabled Maximum lifetime for service ticket: 600 minutes Maximum lifetime for user ticket: 10 hours Maximum lifetime for user ticket renewal: 7 days Maximum tolerance for computer clock syncronisation: 5 minutes Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > Network Access Network access: Allow anonymous SID/Name translation: Disabled Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options > Network Security Network security: Do not store LAN Manager hash value on next password change: Enabled Network security: Force logoff when logon hours expire: Disabled Computer Configuration > Policies > Windows Settings > Public Key Policies > Encrypting File System > Certificates Issued to Administrator, Issued by: Administrator, Expiration date: 04/07/2115 09:57:15, Intended Purposes: File Recovery Name: C - Smoothwall Certificate Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies/Trusted Root Certification Authorities > Certificates Issued to: smoothwall.domain.local, Issued by smoothwall.domain.local, Expiration Date: 12/03/2021 10:28:16, Intended Purposes: Client Authentication, Server Authentication, OCSP Signing, Code Signing, Time Stamping Name: C - Deny Interactive Logon For Service Accounts Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment Deny log on locally: Domain\Service Accounts Deny log on through Terminal Services: Domain\Service Accounts The only differences are during the deployment. I use MDT within SCCM to create a TS and deploy the OS. There are some customisations/extra steps that SCCM does that aren't part of the default MDT steps, which include; CustomSettings.ini [ATTACH]54224[/ATTACH] Install drivers as driver packages (uses WMI query to determine the make/model and install appropriate drivers) Install drivers as applications (uses WMI query to determine the make/model and install appropriate drivers) Configures Windows based on unattend.xml Unattend.xml [ATTACH]54225[/ATTACH] Specify the local administrator password Sets the time zone to London Joins the domain and moves it to a specific OU named 'Deployment' (which has no GPOs assigned, apart from the three listed above) Installs essential apps like 7-Zip, Adobe Reader, Office 2016, Impero Client, etc Disable WinRE Set Windows 10 default app associations Enable Windows Photo Viewer Re-register the Windows 10 AppX Photos package Disable Windows Updates connecting to the Internet Add machine AD object to a specific security group Sorry for the bombardment of information but I feel that I'm quite close but yet so far. -
Our AUP states that all activity is logged and monitored, regardless of who the user is. This allows management to ask us to generate a report for a specific individual if they have concerns and covers their backs. As for the actual screen monitoring - we do have Impero on all workstations and are able to view them all, however we are in a 'position of trust' and know what is and isn't acceptable (much like how I am a sysadmin in SIMS, which opens up all the data).
-
I finished What We Do In The Shadows over the weekend - thoroughly enjoyed it and would recommend it to anyone! You weren't kidding. I obviously knew to expect it, but didn't expect to see who I did and as many people as I did!
-
Spider-Man: Far From Home Really enjoyed it and re-affirms my thoughts that Tom Holland is my favourite Spider-Man.
-
My boss and I recently purchased the components for our replacement PCs and built them ourselves, with it all totalling around £1000. We were running 2013 era Dell XPS systems, which were fine, however they kept crashing when working on multiple projects. We had to justify to the Head that our old machines were not up to the job of our workload and promise to re-deploy those workstations elsewhere if needed, for less demanding workloads (which they'd still be perfectly fine at). If you prefer using a laptop for mobility, have you thought about buying a dock and using a monitor for when you're in the office? All the benefits of the desktop size and laptop mobility.
-
No problem. To remove 'Run' from the Start Menu: User Configuration > Administrative Templates > Start Menu and Taskbar > Remove Run from Start Menu: Enabled To disable Win+ keyboard shortcuts: User Configuration > Administrative Templates > Windows Components > File Explorer > Turn off Windows Key hotkeys: Enabled To prevent the user from right clicking the Start Menu: User Configuration > Preferences > Windows Settings > Folders Add the following entries:
-
Have you considered removing the apps from the WIM and deploying that? That's how I was doing it and didn't have issues with re-appearing apps. Take a look at the Removing Candy Crush sticky thread in this forum section. It's important to note that removing the Solitaire Collection in 1903 can break other apps. I have stopped removing apps from my deployment and use AppLocker to prevent them from being launched. Yes, they still appear in the Start Menu and it triggers me - but it's easier than fighting with removing apps every time I move to a new version of Windows 10.
-
According to Probrand's marketplace, they currently have over 600 in stock at £20.78.
-
Kingston A400 240GB SSDs should do you fine. I would expect to may more than £20-£25 (ex-VAT) per unit.
-
Not from my experience. I've moved away from startup scripts, but those GPO settings have been in place for years, including when we did have logon scripts.
-
I have the following GPO items set: User Configuration > Policies > Administrative Templates > System: Don't run the specified Windows applications cmd.exe powershell.exe powershell_ise.exe User Configuration > Policies > Administrative Templates > Start Menu and Taskbar > Add the Run command to the Start Menu: Disabled I also use File Screen on the file server to prevent users from saving certain file types to their Documents and also disabled the ability to right click the Start Menu.
-
I have also got that on my SkyQ box. I got into Doctor Who while he was writing it and I've heard a lot of good things about it. It's a wonder I find the time to do anything else, with all the TV I'm watching!
