Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. I've bene searching (without sucess) for a way to log onto multiple computers with different accounts (one account per machine), but not found anything. I know Impero can log onto multiple computers at the same time using one accounts...but I need multiple accounts. Basically, we have a bunch of exam accounts; Exam01, Exam02, etc. I need to log Exam01 to Exam60 on across two ICT suites. Is there an easy way of managing this, or am I best typing them in manually?
  2. Cheers, maybe I should have just tried it before asking! Once deployed, I used GPP to run at each logon, using GPP Files with a 'Replace' action to replace the existing .ini file with the new one, located in NETLOGON. Worked straight away! Thanks for the reply though.
  3. Hello, It's been a very long time since I've used USBDLM, and even then, it was deployed by a colleague in a previous workplace. We are having issues with USB drive letter conflicts and not currently using drive letter management. I'm looking to push USBDLM out to our client machines using SCCM and the MSI. Deploying the MSI isn't the problem...however I'm wondering how I can centrally manage the drive letters? I have seen this help article: USBDLM Help, under the 'Network Letters' section. By the looks of that, I need to push a new settings.ini file to each workstation USBDLM will be installed on, which would point to a remote INI file that I can manage centrally. Am I best just using SCCM/GPO to send and replace the existing .ini file, or is there an easier way?
  4. @Arthur's post on page 11 is the one you want I think: http://www.edugeek.net/forums/windows-10/165029-how-get-rid-candy-crush-soda-saga-other-windows-10-start-menu-junk-good-11.html#post1620538 Even though it is works for 1703 and 1709, I believe it also works for old versions, including 1607 and 1610. I would imagine that you can ignore the 'not found' messages, as the script will be looking to remove features in the newer versions...but obviously 1607 doesn't have them. I would have thought that it would still remove the non-whitelisted apps that it does have installed.
  5. We have Youtube unblocked at the RM level. We use Impero for classroom management and have a group containing all students. We then restrict Youtube on that group to block student access. This allows our staff access to Youtube, but not our students. I've also created groups for individual staff in IT suites so that they can temporarily allow Youtube for students in their lesson, like in Media Studies for example.
  6. Microsoft did say that Windows 10 will be the last 'version' of Windows. The updates will now always come in the form of two major updates per year.
  7. Yes, we've deployed 1607 as our Windows 10 version. For those machine not running 1607, they're still on Windows 8.1. 1703 was too much of a ballache to get working, so I left it alone. 1709 isn't perfect, but a lot better than 1703.
  8. I deploy some applications during the TS using SCCM. For example, I have an Application in SCCM for Google Chrome, which is deployed across the site. I used the 'Install Application' action in the TS and selected 'Install the following applications'. I then added each application I want to deploy via the TS into the list. I've been using this method for a while and it's been working fine. Sure, it does mean it's more content for each client to download during the TS, but generally when I'm imaging multiple machines at once, it's either during the holidays or outside of school hours, so impact on the network is minimal.
  9. Cheers, I think I will remove the store. The likelihood of us using it is slim to on, given we're using SCCM at the moment. I'll leave the others in. Any ideas with the other items? Edit: I enabled the setting: User Configuration > Policies > Administrative Templates > Start Menu and Taskbar > Remove common program groups from Start Menu However that has also removed all items configured on my Start Layout (configured with the XML) that are located in %ProgramData%\Microsoft\Windows\Start Menu\Programs.
  10. I have removed the built-in apps using the script on Windows 10 Education 1709 but so far have the following items in the Start Menu that I cannot seem to remove: Cortana Microsoft Edge Microsoft Store Mixed Reality Portal Settings Windows Accessories (folder) Windows Administrative Tools (folder) Windows Defender Security Centre Windows System (folder) My 'WhiteListedApps' in the script are: # AppX Package Whitelist. These are the apps you want to keep $WhiteListedApps = @( 'Microsoft.MicrosoftStickyNotes', 'Microsoft.MSPaint', 'Microsoft.Windows.Photos', 'Microsoft.WindowsCalculator', 'Microsoft.WindowsStore' Anyone able to remove the above from their Start Menu?
  11. More Ferrari posturing. I'm sure they threaten this every other year.
  12. Has anyone tried this with 1709 yet? I'm about to modify my WIM and see what's left. Edit: I have just ran the following command: Get-AppxPackage | Sort-Object -Property Name | Select-Object -Property Name Which has returned the following: 1527c705-839a-4832-9118-54d4Bd6a0c89 c5e2524a-ea46-4f67-841f-6a9465d9d515 E2A4F912-2574-4A75-9BB0-0D023378592B F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE InputApp Microsoft.AAD.BrokerPlugin Microsoft.AccountsControl Microsoft.Advertising.Xaml Microsoft.Advertising.Xaml Microsoft.BingWeather Microsoft.BioEnrollment Microsoft.CredDialogHost Microsoft.DesktopAppInstaller Microsoft.ECApp Microsoft.GetHelp Microsoft.Getstarted Microsoft.LockApp Microsoft.Messaging Microsoft.Microsoft3DViewer Microsoft.MicrosoftEdge Microsoft.MicrosoftOfficeHub Microsoft.MicrosoftSolitaireCollection Microsoft.MicrosoftStickyNotes Microsoft.MSPaint Microsoft.NET.Native.Framework.1.3 Microsoft.NET.Native.Framework.1.3 Microsoft.NET.Native.Framework.1.6 Microsoft.NET.Native.Framework.1.6 Microsoft.NET.Native.Runtime.1.3 Microsoft.NET.Native.Runtime.1.3 Microsoft.NET.Native.Runtime.1.4 Microsoft.NET.Native.Runtime.1.4 Microsoft.NET.Native.Runtime.1.6 Microsoft.NET.Native.Runtime.1.6 Microsoft.Office.OneNote Microsoft.OneConnect Microsoft.People Microsoft.PPIProjection Microsoft.Print3D Microsoft.Services.Store.Engagement Microsoft.Services.Store.Engagement Microsoft.SkypeApp Microsoft.StorePurchaseApp Microsoft.VCLibs.140.00 Microsoft.VCLibs.140.00 Microsoft.VCLibs.140.00.UWPDesktop Microsoft.VCLibs.140.00.UWPDesktop Microsoft.Wallet Microsoft.Windows.Apprep.ChxApp Microsoft.Windows.AssignedAccessLockApp Microsoft.Windows.CloudExperienceHost Microsoft.Windows.ContentDeliveryManager Microsoft.Windows.Cortana Microsoft.Windows.HolographicFirstRun Microsoft.Windows.OOBENetworkCaptivePortal Microsoft.Windows.OOBENetworkConnectionFlow Microsoft.Windows.ParentalControls Microsoft.Windows.PeopleExperienceHost Microsoft.Windows.Photos Microsoft.Windows.PinningConfirmationDialog Microsoft.Windows.SecHealthUI Microsoft.Windows.SecondaryTileExperience Microsoft.Windows.SecureAssessmentBrowser Microsoft.Windows.ShellExperienceHost Microsoft.WindowsAlarms Microsoft.WindowsCalculator Microsoft.WindowsCamera microsoft.windowscommunicationsapps Microsoft.WindowsFeedbackHub Microsoft.WindowsMaps Microsoft.WindowsSoundRecorder Microsoft.WindowsStore Microsoft.Xbox.TCUI Microsoft.XboxApp Microsoft.XboxGameCallableUI Microsoft.XboxGameOverlay Microsoft.XboxIdentityProvider Microsoft.XboxSpeechToTextOverlay Microsoft.ZuneMusic Microsoft.ZuneVideo windows.immersivecontrolpanel Windows.PrintDialog Now to find out what I should and shouldn't remove!
  13. I hope this is the right section! We are testing ZuluDesk as an MDM for our iPads and we are going to use LDAPS to authenticate with our AD. However, I'm having issues with the authentication. We don't have an external IP or firewall ports open for our DC. Ideally, I'd rather not expose our DC directly. When testing internally, LDAPS is enabled on our DCs and working (tested and confirmed using ldp.exe). We do have AD FS enabled, with a server located in our DMZ. I am led to believe that AD FS has LDAPS enabled, or at least can communicate to AD using LDAPS. However, despite allowing TCP port 363 on both inbound and outbound rules on the AD FS server, I cannot get ldp.exe to communicate with our AD FS server's internal FQDN address. I don't know if I've got the wrong end of the stick completely regarding LDAPS, AD FS and authentication. Can anybody advise?
  14. We are using RM's SafetyNet as our filtering. Users are not admins on the machines. I'll take a look at making Windows Firewall treat all networks as public except our own. We're using SCEP from SCCM as our AV, with SCCM managing the updates. With DA, I'm hoping that clients will be able to connect to SCCM from home to receive updates. Microsoft EMET appears to going EOL next year, plus our clients are currently running either Windows 8.1 or Windows 10 1607 (with Windows 10 1607 slowly replacing the Windows 8.1 clients), so hopefully they contain at least some of the protection mechanisms that EMET covers.
  15. We are currently testing DirectAccess for the purposes of staff accessing school data and SIMS, amongst other resources. Using Split Tunnelling - we can connect. There are some issues, such as SIMS not detecting the connect.ini file, but that can be looked at at a later time. We have had a thought about Internet filtering. Whilst in school, our Internet is proxied through our ISP's web-filtering, which is great as it blocks a lot of malicious sites. On top of that, all of our devices are protected by an anti-virus. However we're just thinking that if someone gets infected whilst at home and using DirectAccess, it could easily spread across to our network via the mapped shares. Yes, that is a normal risk when they are on site, but we see more infections in general on laptops that go home than we do on the static in-school machines. We've turned on Full Tunnelling, to force all traffic through our network (so hopefully the Internet will get routed through also) however I've lost connection to my test device at home. So until I get home, we can't test further (We get no mobile data signal, so we can't hotspot either). After doing some research, a lot of people appear to have issues with Full Tunnelling. Usually with either it not working at all, or having dire performance issues and people seem to recommend using Split Tunnelling with another solution in-place the Internet connection, such as OpenDNS. I don't think OpenDNS is free for non-private use, so that won't be an option, along with any other solutions that require payment. Any ideas on how I can provide more Internet-based security on our Split Tunnelling DA clients whilst off-site?
  16. We have multiple Task Sequences configured and primarily image over the network/PXE. When we image using these TSs, we get a prompt to enter a computer name if we want to specify one. This is great as it means we don't have to do it at a later date and when it automatically joins the domain. However, when I 'Create Task Sequence Media' for a standalone deployment with the same TS for use on a tablet with no LAN, only WiFi/USB...that computer name prompt does not appear. This is despite no change being made to the TS. Is there any way I can get that prompt for offline media?
  17. I am currently investigating DirectAccess and would like to know if we can use our existing edge/Internet facing server which hosts our RDS Gateway? If so, it would save me the hassle of setting up another edge server. We actually have two edge servers, one for RDS as I mentioned earlier, and another for ADFS. Would DirectAccess conflict with either of these if it was installed on one of these servers?
  18. I use a combination of a redirected Start Menu and this script: http://www.edugeek.net/forums/windows-10/165029-how-get-rid-candy-crush-soda-saga-other-windows-10-start-menu-junk-good-9.html#post1572403, thanks to @Arthur and @3s-gtech. I don't see any extra items, including the ones you mentioned.
  19. We have SCCM 1702 installed and push out applications. I have noticed that once an application has been installed and it requires a reboot - Software Center on the client machine will inform the user that it will restart in 90 minutes. Then after 75 minutes, a dialogue box appears on the bottom right of the screen, displaying a 15 minute restart countdown. Then the machine automatically reboots. We use also deploy Software Updates via SCCM, which has an option to suppress reboots. This works fine. When I deploy an application, it is scheduled as soon as possible, with a deadline 7 days after the deployment creation. I also allow 'Software Installation' to be allowed outside of the maintenance windows. However, I ensure that I leave the box 'System restart' unchecked. We do have a single Maintenance Window on our collection that contains all workstations. Does this Maintenance Window also cover sub-collections, or any device that falls within it? Does it also apply if a deployment has been sent to a different collection, but the machines in question also appear in the collection with the Maintenance Window?
  20. It is enabled for the apps, which is why I was confused. But the fact that it's happening for OneDrive and Dropbox leads me to think this is just how it works.
  21. Thanks for the response, however this appears to happen to other cloud upload apps too. Dropbox also requires the app to at least be running for the upload to commence.
  22. Honestly, I don't know what I should be using to deploy Windows 10 at the moment. We have SCCM to deploy OS's, updates, applications and endpoint protection. However, there's MDT, Setup Schools PC app, InTune (standalone), InTune (SCCM), Windows 10 Provisioning and now AutoPilot. I just want to deploy Windows 10 Education 1703 using PXE boot for 80% of our devices. The other 20% are not able to PXE boot, therefore have the Task Sequence as a USB boot image. What deployment method(s) should I be using for best practice, results and ease?!
  23. We've been having issues with Google Chrome's built in PDF Viewer and have disabled it in favour of Adobe Reader. At the moment, any PDF a user selects in Chrome is downloaded and can be opened from their downloads folder. I've force installed the Adobe Reader Chrome extension via GPO, so that they can view the PDF in the browser. This works, however we have an issue with the installation of the extension. The issue manifests itself on 'new' logins, whether it's a machine the user has not used before, or a machine that has had the profiles deleted using DelProf. When a user logs in for what is effectively the first time and launches Chrome, a new tab is opened entitled 'Adobe Acrobat extension for Chrome' with a description of what the extension can do. This is all well and good, but it appears every single time the user logs on to a machine. I've tried installing the extension both as a User Configuration item and also as a Computer Configuration item. Both have the same problem. For the moment, I have removed the extension and the user will have to open the PDF from their downloads. Is there any way I can prevent that tab from opening? Impero doesn't have the ability to close a tab, only the whole browser, so we can't use that.
  24. Has anyone got the OneDrive app working with background uploading of photos/videos? It works if I have the app running, but if the app is force closed, the photos won't upload. This is despite having the following settings enabled within the OneDrive app: Location > Always Photos > Enabled Background App Refresh > Enabled. I'm using the latest OneDrive app on an iPad Mini 2 running iOS 10.3.2.
  25. What attribute did you modify?
×
×
  • Create New...