Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. We don't update the built-in apps. Most of our site is on 1709 and that WIM had the most of the built-in apps removed. Those that remained, such as calculator, photos, etc were not updated. Users do not have access to the Store. I'm currently testing 1903 and left the built-in apps in the WIM. I'll be using AppLocker to disable access to them and they will also not be updated with users still unable to access the store.
  2. We do two things: 1) For most staff and all students - we use GPOs to redirect their desktop to a fixed place, so that they all get the same icons and nobody can save/delete anything from it. 2) For some admin staff and our own technician workstations, we use GPO to redirect their desktop to their home folder, so their desktop icons are actually saved in H:\Desktop rather than C:\Users\\Desktop. That way they can save items on their desktop and nobody needs to worry when the machine dies because it's all saved on the network share.
  3. I believe VLSC is still needed for Windows and Windows Server licensing, as well as other software such as SQL, SCCM, etc. I think our A3 plan appears in our VLSC, along with the other products we're licensed for.
  4. I always try to stick to one type of Office across the site, with the only exception being testing a newer version on selected clients. This allows me to create a new collection that contains all the workstations called 'Software Updates | Microsoft Office 2016 Professional Plus'. I then target the updates/ADR to that collection. The clients being used for testing will still download the updates from SCCM, but they won't be applied because there's no product to install them against. It'll just appear as a failed install in Software Centre on the client. Though the client will keep trying to reinstall that update each time it's update evaluation cycle runs. Not much of an issue, especially as testing won't be for that long in the grand scheme of things. When it comes to deploying that new version of office, I'd create two new collections, one for deploying the install of Office to and another for deploying the updates to, like Office 2016's update collection. I hope that makes sense.
  5. I'm note sure how I feel about it. An extended trailer:
  6. Since upgrading to 8.0.64, the issue has gone. So it appears that 1903 doesn't like at least 7.4.36 of Impero.
  7. We're running Impero 7.4.36 and that is installed as part of the TS (along with other essential software) and I've found that when Impero installs, it causes 1903 to get stuck in a boot loop. I'm waiting for Impero to upgrade my available version to 8.0.64 so I can use that instead in the TS and see if the problem still exists. Edit: Come to think of it, I've installed 1903 on my workstation and using Impero 7.4.36 without issues. I've just manually installed Impero on the test workstation I removed Impero from the TS for and it's also working fine (and reboots fine). Unless it's an issue with installing Impero during the TS? I'm still working on it.
  8. Yeah, I forgot to mention we have ours chained up to. We failed a fire safety inspection on that, as if it's not chained, someone could move it to the side of the building and set it alight (which has happened to other schools in the past), causing the building to catch fire.
  9. We've used them for a couple of years now and I cannot fault them. They provide a bin and recommend you padlock it so that nothing is stolen and incorrect items are put in it. When it's full, you call them and they come and take the bin and provide a replacement. We're based in Birmingham and I believe they're run out of Doncaster. They've no issues travelling here and the guy has always been friendly. They provide documentation for proof of disposal, which includes serial numbers. You can also get the documentation online, rather than paper if required.
  10. I've been using English International for years, but I have had to configure Unattended.xml to change the primary language from en-US to en-GB in them all. I've had to do that for 1903 too. I'm having an issue on my test workstation with drivers (I assume), which is causing the PC to get stuck in a "Why did my PC restart?" boot loop during the TS (after ConfgMgr has been installed). I disabled all drivers, applications and customisations in the TS and it installed fine. Now I'm working through the extras one by one to find which stage of the TS is causing the problems. I do assume it's driver related, though I'm not ruling out applications like Visigo which hook into the system, etc.
  11. We're using Windows 10 Education and have been since about 2017. Haven't had any issues with it in that time. As I use SCCM to manage Windows Updates, it doesn't push any feature updates automatically. So I'll just download the ISO from VLSC, import it to SCCM and start testing it. Once I'm happy with it, I'll roll that out to a live testing collection of say, 5 machines in each IT suite and some teacher workstations (that the staff have agreed to). Once that's done, it can be rolled out across the site.
  12. I've had a call directed to my office from our reception staff in the past, where an Indian sounding man was trying to get information from me about my BT line. We were with Link2ICT at the time. I'd completely forgotten about this until your post jogged my memory. Clearly they're going after businesses too, not just home users.
  13. I simply don't touch the profiles and use delprof to delete profiles older than two weeks (we are only a one week timetable school...I'd probably set it to 3/4 weeks if we were using a two week timetable). We have 120GB SSDs in our machines, so not a massive amount...yet we don't really have an issue with storage space. We've had this configuration running now for almost four years.
  14. Yes, cannot emphasis enough how good the RCT Tools are from Recast. Set aside some time for this, it's a massive beast to wrap your head around. Maybe just take a look at it in stages, such as getting it installed and configured purely to deploy OSs. Then look into app deployment, then Software Updates, etc.
  15. Welcome to Edugeek, you'll find tonnes of useful info on here. Now to the main question; How are you tea making skills?
  16. We use SCCM, which is Microsoft's (not free) management software to deploy /manage operating systems, updates, applications and more. It incorporates WDS/PXE and can also have MDT configured too. SCCM is a beast of a system to wrap your head around, but when configured correctly, you can just PXE boot a client, select the OS (Task Sequence) from the list and away it goes for a 'zero touch' deployment. For example, mine will install Windows 10, install the correct drivers, install core applications needed on the PC (like Office, Adobe Reader, 7-Zip, etc...because the rest of the applications are automatically pushed to the PC by SCCM at a later point), install extra features (such as .NET), install missing Windows updates and perform extra things, such as setting registry settings, etc.
  17. SSD without a doubt, the improvement will be even more noticeable on those specs.
  18. We do not redirect Application Data, we've had no reason so. There are only a handful of applications that store necessary data in Application Data and even fewer staff who use those apps. We do run DelProf on student machines, though it's set to only remove profiles from machines that haven't been used in more than 14 days. Generally we don't run DelProf on staff/admin machines unless we have do (usually for a corrupted profile).
  19. We're just using local profiles and haven't had any issues. Sure, a couple of things are stored in the profile, but there isn't that much anymore. I have worked in schools previously where we've had roaming profiles for Windows XP/7 but since 10, I've not bothered.
  20. I logged into my VLSC account last week and saw no products/downloads and attributed it to this global issue. Logged in again today and it's still the same. I've raised a ticket with Microsoft and will see what they say.
  21. The on-site version? If you've configured the AD integration, it will use pass through authentication I believe.
  22. We used to use the self-hosted version of Spiceworks, but found it to be quite buggy. For the past couple of years we've been using the Spiceworks Cloud Help desk, completely hosted by Spiceworks. Sure, it's only the Help desk (not the inventory), but that's all we need. If you want your users to authenticate via AD, all you need to do is install the AD connector onto one of your servers and configure it to your AD. The only change we did was regarding the email address staff use to email their requests to. Spiceworks Cloud defaults to [email protected]. We configured a Office 365 mailbox called [email protected] and configured automatic forwarding on that mailbox to forward all incoming emails to [email protected].
  23. A couple of months ago, after a bunch of research I did an in-place upgrade on our physical DC (DC1) from Server 2012 R2 to Server 2019 (this is not our PDC). It went well and the server/domain functioned correctly. During the half term I did an in-place upgrade of DC2, our PDC VM, from 2012 R2 to 2019 and the function level was increased from 2012 R2 to 2016. The domain seemed to function correctly until yesterday when a couple of issues started occurring. Firstly, we have Always-On VPN configured and I am not able to get the certificate to automatically enrol for the user. This has worked perfectly until now and it is showing the following message in the event log on the client: Certificate enrollment for failed in authentication to all urls for enrollment server associated with policy id: {2F1553CE-7833-423E-BF60-2F04FE7ADC15} (The RPC server is unavailable. 0x800706ba (WIN32: 1722 RPC_S_SERVER_UNAVAILABLE)). Failed to enroll for template: VPNUsers I queried which DC the device was connecting to, and it was DC1. I logged onto DC1 and checked the logs and these were being shown: Level: Warning. Source: Browser. EventID 8021. The browser service was unable to retrieve a list of servers from the browser master \\DC2 on the network \Device\NetBT_Tcpip_{993D5DD2-7A4A-4669-B78E-7241C01886C9}. Browser master: \\DC2 Network: \Device\NetBT_Tcpip_{993D5DD2-7A4A-4669-B78E-7241C01886C9} This event may be caused by a temporary loss of network connectivity. If this message appears again, verify that the server is still connected to the network. The return code is in the Data text box. The above error only appears on DC1, DC2 is fine. I did notice that DC1 had turned UAC back on, despite it had previously been turned off by our servers GPO (User Account Control: Admin Approval Mode for the Built-in Administrator account: Enabled). The DC is still in AD and is still in the Domain Controllers OU, which is receiving the Default Domain Controllers GPO, as well as our custom Servers GPO, neither of which have been modified in years. However the following error appears on both DCs: Level: Error. Source: NETLOGON. Event ID: 5722 The session setup from the computer failed to authenticate. The name(s) of the account(s) referenced in the security database is SCIENCE-TBLT20$. The following error occurred: Access is denied. I'm suspecting that there's something wrong with DC1, but I'm unsure how to resolve it. We have not made any changes since upgrading to 2019 to our domain. Edit: DCDiag reports passes on both DCs for all except for DFSREvent which reports this warning: Starting test: DFSREvent There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems. I also have the Microsoft AD Replication Tool 1.0 installed on my workstation and that reports correct synchronisation between the two DCs. I have also restarted DC1, to no avail. Edit 2: I have output the dcdiag result to a text file and it has reported the following: Starting test: DFSREvent The DFS Replication Event Log. There are warning or error events within the last 24 hours after the SYSVOL has been shared. Failing SYSVOL replication problems may cause Group Policy problems. A warning event occurred. EventID: 0x80001396 Time Generated: 05/07/2019 15:52:55 Event String: The DFS Replication service is stopping communication with partner DC1 for replication group Domain System Volume due to an error. The service will retry the connection periodically. Additional Information: Error: 1723 (The RPC server is too busy to complete this operation.) Connection ID: 96698CB3-F0C2-4473-A4EC-B093A7EB911F Replication Group ID: D028633F-A4B8-47E3-8B26-5751949FCF85 An error event occurred. EventID: 0xC0001390 Time Generated: 05/07/2019 15:53:49 Event String: The DFS Replication service failed to communicate with partner DC1 for replication group Domain System Volume. This error can occur if the host is unreachable, or if the DFS Replication service is not running on the server. Partner DNS Address: DC1.SJW.Internal Optional data if available: Partner WINS Address: DC1 Partner IP Address: 10.22.11.11 The service will retry the connection periodically. Additional Information: Error: 1722 (The RPC server is unavailable.) Connection ID: 96698CB3-F0C2-4473-A4EC-B093A7EB911F Replication Group ID: D028633F-A4B8-47E3-8B26-5751949FCF85 ......................... DC2 failed test DFSREvent
  24. Don't worry, it does make sense, especially working in schools! It's been a good while since I last looked at this, but from what I can remember, there is no global default save value anywhere. Some apps may simply use Explorer's default value, but not all do. A lot have their own value. Some can be set via GPO, such as Office applications, file explorer, etc. However the random other apps you can't, unless it happens to use Explorer's values or you can find the registry entry for each app and then push that through GPP. I may be wrong, but I think that's how it was the last time I looked into this.
  25. If you aren't mapping their home areas, where do their Documents, etc point to? The local machine?
×
×
  • Create New...