-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
We were a SIMS and FMS school and migrated to Bromcom for the MIS a couple of years ago. We were going to move finance over too, but if I recall the details from our finance officer correctly, the council played hardball and threatened that if we move away from FMS, they will not be able to accept certain files or something from us, since Bromcom's finance module cannot/could not create it. We are now becoming a cheque book school, as the council divorce all schools and our finance officer would like to keep FMS at least until this process is complete for stability and possibly look at it again in a year or two. So for now, we are stuck with FMS.
-
How much of that is driven by either people having issues and need assistance/confirmation or requesting features because you don't have them yet?
-
Migrate from KMS to embedded license activation
CHiLL replied to CHiLL's topic in How do you do....it?
That's what I would have thought, but we actually don't specify any keys in our TS and we don't use a custom/captured image. It's just an ISO from Microsoft that's deployed by an SCCM TS and the product key section is blank. I believe the AD activation is tied with DNS, which is probably how the clients know how to access Windows must have some baked in method to know to check for activation servers. I'm going to try it on a couple of test stations and slowly expand from there if successful, I just wanted to gauge where any issues might arise, if any. -
Migrate from KMS to embedded license activation
CHiLL replied to CHiLL's topic in How do you do....it?
Since we don't appear to have any direct configuration to tell clients how/where to activate, I just wondered if I made the change to embedded keys on a client, would it try and change back to the KMS key automatically, based on AD configuration? -
We have migrated from A1 to A3 licensing and this have the caveat that we are no longer licensed via VLSC for Windows Education, activated by our Active Directory KMS activation services. Instead, we need to utilise embedded licenses that come with the devices, which appear to be Windows Pro Edu if I inspect the shiny Windows sticker. I know that we need to use a command line/script to switch the activation over to the embedded version, but I am unsure what to do with our volume activation services. It's currently installed as a role on a server with Active Directory integration. I cannot seem to find any GPO or other configuration that specifies our clients to use the volume activation services. My concern is that if I just remove that role, it's going to break licensing on clients that either have not taken the new licensing or don't have a valid embedded license. What would be the best way to approach this?
-
We use it standalone, we don't have any of their other products. I also forgot to mention that lockdown is also denoted with a specific bell pattern, along with the popup. Same with when lockdown is lifted.
-
Currently using NetSupport Notify to send popups, including lock down alerts. Relatively cheap and cheerful.
-
Office 365 - Unable to block profile picture changed at this URL
CHiLL replied to robyholmes's topic in Cloud Services
We always experienced this with M365 too and couldn't prevent it, so we gave up. We just deal with any inappropriate profile pictures like any other disciplinary action. -
Office 365 - Unable to block profile picture changed at this URL
CHiLL replied to robyholmes's topic in Cloud Services
If I remember correctly, this is a long standing issue. The only solution that I can recall was to have a scheduled task to remove the profile pictures overnight. -
It's been down all morning for us. Aren't TES (Class Charts) and The Parent Pay Group (ESS) separate entities?
-
Cloud-only service account and conditional access to log onto local server
CHiLL replied to CHiLL's topic in Cloud Services
Salamander just told me to contact Microsoft if we are unsure. I have a ticket open with them, but it's pretty slow going at the moment. I've only had the "we've got your ticket" and an introductory reply from the assigned agent so far. They need the admin rights to not only create the on-site AD accounts, but also manage the accounts, licensing, SDS and other scheduled tasks and configurations that they run. It would have been nice to have known about it before our sync broke completely and this needs to be done in order to get it working again. -
Cloud-only service account and conditional access to log onto local server
CHiLL replied to CHiLL's topic in Cloud Services
We are using Azure AD Connect, but Salamander have said "Microsoft has made some changes to its security requirements.", so I think it's a fairly recent change. -
Cloud-only service account and conditional access to log onto local server
CHiLL replied to CHiLL's topic in Cloud Services
Thanks for your reply @StephenPink, however is that related to the Salamander account being created in the on-site AD environment and then being synced online? We are being told by Salamander that it is now a requirement that the account must be cloud-only, as in not an on-site account synched to Azure. -
Cloud-only service account and conditional access to log onto local server
CHiLL replied to CHiLL's topic in Cloud Services
Is anyone able to advise on this, as it appears our Salamander sync is broken until we sort this cloud account with conditional access. -
We converted all our classrooms at the turn of this calendar year to USB-C docks, specifically using the "HP USB-C Essential Dock G5". They've been very solid for us and have been a set and forget solution, with every classroom designed to work the same for all the teachers. Some things we've learned along the way: If your projector/interactive TV is a HDMI run, it should be no longer than 10m on a normal HDMI cable. Any longer and they should be active/optic cables. If your display is an interactive TV, depending on the HDMI cabling spec, you may need to adjust the EDID on the TV to specify HDMI 1.4. Ours were trying to default to HDMI 2.0 and the HDMI wall box converters are not rated for that, only HDMI 1.4 quality (don't Google the price of HDMI 2.0 wall adapters from the likes of Vision, you may have a heart attack). USB-C works most of the time, though we have encountered a couple of situations where upgrading the firmware on either the dock itself or the USB-C laptop sorted some issues, such as power and Ethernet working, but no display. We had more success with BENFI HDMI to VGA adapters than DP to VGA adapters we had, when connecting the dock to VGA projector runs
- 13 replies
-
- docking monitor
- docking station
-
(and 3 more)
Tagged with:
-
Is this not unsimilar to what the likes of Google and Facebook did, with Alphabet and Meta respectively?
-
Apple School Manager - Federated domain and conflicts
CHiLL replied to CHiLL's topic in Mobile Devices & Tablets
I don't know how this would work with our old Apple accounts that were created manually. For example, our headteacher created their own Apple ID many years ago and used their school email address but they are being prompted to enter a new email address to continue using the account, however they cannot use any email address that contains our federated email domain. It was my understanding that merges where both users had the same email address would be merged, but that doesn't appear to be happening for us and it has said "46 days remaining" for over a week now. It's then my understanding that this would then mean any purchases they may have made are stuck on this non-federated account, when we'd want them to only use their federated account. I've only been following Apple's official guide, ChatGPT, some Reddit threads and a pinch of just YOLOing it. We have previously been able to call Apple's school/business support for issues in the past, however it requires an in-warranty device to log the case under...which we don't have and don't have the money to purchase another at the moment. -
I have added our Entra domain into our ASM and it is reporting that there are 81 username conflicts. When I click through, it tells me that our domain is verified, there are 7 managed apple accounts and sign in with Entra is enabled. It also says that there are 81 username conflicts, with "Resolving 81 username conflicts, 46 days left", which it's said now for two weeks. It also does not tell me what usernames are conflicting and no way to force it. Does anyone know how to resolve this?
-
For Salamander AD, we need to create a cloud global admin account in M365 but it also needs to be have permission to log on/authenticate to a server that is located on-site. I've created the cloud account but struggling with the local server aspect. I believe we need to use conditional access to allow the account to authenticate against the server, but the server OU is not linked via Azure AD Connect and thus doesn't appear as a selectable machine target when configuring conditional access to the server. I believe my options are: Link the server OU so all server objects are synced to Entra Create a sub-OU just for this server and only link that sub-OU in Azure AD Connect Use an authentication agent that I can't seem to find too much information about The first option is the easiest - I just wondered if there is any reason why I shouldn't link the server OU, such as security concerns. ChatGPT seems to suggest that it's beneficial for conditional access, but it can have some risks, including increased attack surface by exposing more AD details or unnecessary permissions may be added to the objects.
-
They aren't using Impact/Biostore ID Manager anymore, following contract disputes with IRIS, who own Biostore. Cunninghams are now using Impact Back Office, ID Store Admin and it's all built in-house, so it should be even easier for them.
-
I've been asked to look at Fusion again after a year of not using it and it looks like they've updated the deployment method and no longer supporting the batch file method. Instead you can create a custom install method and deploy it from that - problem is that Fusion doesn't come up as a supported custom install method from the available licenses, despite we are licensed for education (which I've just renewed) and can log in and use it online and via the old install method.
-
Since an iPad in shared mode will have location services disabled by default and each user that uses the iPad will have to choose to enable it manually, how does locate device work if the iPad goes missing? It's not uncommon for us to have to locate an iPad because someone has left it in a specific part of the building or something. It's my understanding that the iPad will only use the less accurate WiFi services and report back a less accurate position, as having location services disabled will prevent GPS coordinates being sent back to Intune. Is that correct?
-
I'd presume the first thing would be to ensure you've signed your wife's account out of the OneDrive app. Without an account linked, the OneDrive client can't sync the changes back to the cloud. Anything that is deleted from OneDrive, even via sync back is restorable via the recycle bin. Alternatively, you could always move them to another location on the C:\ drive to check to see if it does delete the items online or not. If it does, at least you still have them to restore. Or alternatively alternatively, you could manually upload all the files to a backup folder in her OneDrive via the web interface, rather than the app. It may double up the files, but at least they aren't deleted. She can then delete the folder after some time.to
-
Interesting, I seem to have a memory that Microsoft used to be funny about downloading ISOs from them and would only want to provide it via official channels, such as purchases, etc. Maybe I'm misremembering or massively out of date with that information. If I can legitimately get the ISOs from Microsoft, then that should be fine. The supplier suggested that our devices would need to revert to using the license that comes with the device, such as Pro as opposed to Education that we've been pushing for years. I've always used Education because it's effectively built from Enterprise, whereas Pro was built on Home and (at least used to) missed features, such as local GPO editing, etc.
-
We are at the end of our Microsoft licensing agreement and obtaining a quote from our current reseller to upgrade from A1 to A3. One thing that has come out of the meeting we had was that we would loose access to download Windows desktop ISO (Win10/Win11, etc) from the M365 Admin Center. We would still be able to download Windows Server ISOs, just not the desktop operating system ISOs and instead, we would have to rely on Autopilot. This is what they're being told from their Microsoft contact. We are not yet ready to migrate to Intune for OS deployment and also don't want to use the OS that comes preinstalled on devices, as we prefer to push a clean image. Can anyone on A3 confirm whether or not this information is accurate?
