-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
Office 365 - Device Based Activation/Shared Computer Activation
CHiLL replied to Gobstopper's topic in Licensing Questions
I don't think there's a difference between activations between OVS-ES and ESS now that they allowed shared device licensing on OVS-ES (which was our original issue), though I may be wrong. I'm pretty sure I remember we used to use the SharedComputerLicensing flag on Office 2016 ProPlus and earlier versions of Office for shared devices. We are deploying M365 Apps via the MECM using the configuration file I posted. However, looking at the date modified of the files, they're dated January 2023, which is presumably the last time I had to reconfigure the apps in MECM. That must mean we're deploying an out of date M365 package, which is then updated by MECM Software Updates or Intune WufB, depending on the client and their update settings. -
We have Impero and utilise it's shutdown options on specific groups of devices.
-
Quite the necro thread. If this thread was a student, they'd be in year 11 now.
-
That rings a bell, I a long time ago having issues configuring ports to different VLANs because AAA was enabled and there were issues with GVRP too. We are using HP ProCurve 2530 switches with a 5406zl core. If I reenable AAA on a specific port, do I set all the VLANs on that port to auto? If this becomes too much back and forth from this thread, I'll split it out into it's own.
-
For domain joined devices, we utilise NPS/RADIUS and Dot1x. Our domain machines accounts are members of either a group called "Dot1xStaff" or "Dot1xStudents". NPS is configured certificates and the clients receive the config via GPO. Assuming all the conditions are met, NPS will drop the machine into a specific VLAN. For other devices such as iPads, personal/BYOD devices, etc, we have other WPA2 SSIDs for those, depending on requirements. On a somewhat related but not directly note, back in 2015 when our network was redesigned, we had 802.1x implemented on both the Wi-Fi and wired networks. We had issues with Impero, mainly with WoL and broadcasting and turned 802.1x off for the wired network as a quick fix and all the network switch ports that devices were connected to were configured to an "UNAUTH" port, which dropped them into a large VLAN pool. It's now been like this for almost a decade and I would like to test 802.1x again by reenabling it on the wired network, but unsure how to go about it, because I've forgotten how to do this sort of network configuration. Is it simply a case of tagging the necessary VLAN ports on the switch or do any have to be left as untagged?
-
Office 365 - Device Based Activation/Shared Computer Activation
CHiLL replied to Gobstopper's topic in Licensing Questions
When Microsoft started to switch to C2R and the monthly channel version of Office, using a device based license was restricted to ESS customers, which left us OVS customers high and dry. That is no longer the case and we've been using it fine with just the A1 license for at least a couple of years now. Looking at my config file, we aren't actually using DBL, but just "SharedComputerLicensing". Here's a copy of our config file: Each user has the A1 faculty or A1 student license assigned and that's it. -
Since Microsoft's change to OAuth, our M365 SMTP stopped working. After some troubleshooting, I wasn't able to get it sorted and the school needed to continue to email, so a decision was made to purchase Bromcom's email service. It's been working fine and while free is cheaper, it's not the worst costing.
-
[ms office - o365] Office 365 Ent Updates - How do you manage?
CHiLL replied to newpersn's topic in Office Software
I had been using MECM (SCCM) to managed M365 (Office) updates for many years, but have recently been testing WufB with Intune with a pilot ring (for Windows Updates also). It seems to work surprisingly well and pretty much a set and forget type of thing and my plan is to migrate everything over to Intune and stop the MECM deployments. The only thing I need to figure out is Windows Server updates, but I haven't looked at that yet. -
Intel Core i5 or AMD Ryzen 5 (basically anything equivalent to 12th gen or newer) 8GB RAM for students and 16GB RAM for staff 22" 1080p displays 256GB SSD
-
OneDrive - View online option missing on Windows 11
CHiLL replied to CHiLL's topic in Cloud Services
Unfortunately I haven't gotten any further with this and haven't been able to put much time into troubleshooting it since. I've just tested this, however the OneDrive options are still missing. It appears as though despite it's using the Win10 menu, it's just the same menu as in "Show more options" in the Win11 menu, just without the step and thus if any options are missing within "Show more options", then they'll be missing with this registry tweak too. -
Back in about 2015, that's what we were advised from Apple and other sources. We later discovered that it wasn't necessary and added extra cost at having to purchase apps many times. Since about 2017, we've been using the same single Apple ID and have approximately 175 iPads configured this way.
- 17 replies
-
- apple configurator
- ipad configurator
-
(and 1 more)
Tagged with:
-
Windows 11 Gpo settings and REG settings that might be useful
CHiLL replied to Jaan's topic in Windows 11
There are some useful registry tweaks listed here: https://kittenlabs.de/blog/2024/08/20/windows-11-tweaks-usability-improvements/?utm_source=unknownews. Some may have been to resolve things such as performance issues, which may have since been patched out. -
https://www.bbc.co.uk/news/articles/c0kjrp2rngzo Estimated wind speeds of 13,508 mph in London and overnight temperatures of 404C in Nottingham.
- 11 replies
-
- bbc
- bbc weather
-
(and 1 more)
Tagged with:
-
Intune Primary Users - M365 Apps/Edge/OneDrive sign in issues
CHiLL replied to CHiLL's topic in Enterprise Software
Of course of all the test users we have, I picked the only one that has @school.local set as the primary suffix! I changed that and it signed in automatically. Since our users were signed out due to the original issue, it appears that despite the configuration for SSO being enabled, it doesn't apply at the first log on, but does from subsequent logons after the profile is cached, which is pretty much what @georgeescott described. -
Intune Primary Users - M365 Apps/Edge/OneDrive sign in issues
CHiLL replied to CHiLL's topic in Enterprise Software
It appears that we had an issue with our Entra Connect Sync (Azure AD Connect), where it had lost it's entire configuration and needed setting up again from scratch. That has been done and it is syncing correctly. However, office apps are not signing in users automatically. I can see that it is, kind of, but the apps aren't licensed and the users are prompted to sign in. At the top right of an app, such as Word, it will display the user's login details that it's pulled from Windows. For example, it will show "[email protected]", which is the local domain name. Whereas students log in with their M365 domain credentials, such as [email protected]. Seamless SSO is enabled in Entra Connect Sync and I've confirmed it's enabled within Entra Admin Center. I can see that and confirm by a gpresult that the following settings are set and being applied: Location: User Configuration > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page > Site to Zone Assignment List Value name: https://autologon.microsoftazuread-sso.com Value (data): 1 Location: User Configuration > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page > Intranet Zone Value name: Allow updates to status bar via script Value (data): Enabled HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin, “BlockAADWorkplaceJoin”=dword:00000001 I just don't know why it won't auto-sign in the user. -
Update: It appears this was due to our Entra Connect Sync (Azure AD Connect) had lost it's configuration and needed setting up from scratch, therefore was synchronising data with Azure.
-
I accidentally deleted the devices of a SCCM co-managed IT suite from Intune. I thought no big issue, I'll just re-image the devices with SCCM and they'll be added back into Intune via SCCM co-management. So I re-imaged them...but they haven't appeared in Intune. There's no enrolment log in C:\Windows\CCM\Logs and from my research, enrolment of a device is user driven by a logged on user. We have previously limited enrolment capabilities via in Intune (Intune admin centre > Devices > Enrolment > Windows > Automatic Enrolment) and specified "Some", which is a security group containing our admin accounts. This was to prevent users from enrolling their own devices, especially when prompted during signing into Office apps. How can I get SCCM to enrol devices automatically without having to log on as one of the admins? I just want to start the imaging process and it does it all itself.
-
We noticed that all of our SCCM co-managed devices appearing in Intune had primary users associated and had issues communicating with Intune, which is problematic since Intune is managing updates via WufB. Company Portal also work correctly if the user logged is not the primary user. I have removed the primary user from a bunch of machines to convert them to shared devices, which is what we did with our DFE Intune only (not SCCM) laptops, used at home by students and that worked for those devices. However, we started getting reports shortly afterwards that users were being signed out of their apps, specifically their Microsoft apps, such as Word, PowerPoint, Excel, Edge, OneDrive, etc. So it seems that removing the primary user has reset the device's settings, including authentication information, even if the user logged in was not the primary user. Users are having to manually sign into the apps and go through the enrol device dialogue box within Word/PowerPoint in order to access the app's features. We have had necessary GPOs in place that should do this automatically and silently (and have had for years, without anything being changed in those), so it must have something to do with the primary user change. What are the necessary GPO settings to get this working as desired or am I missing something?
-
[24h2 / lts 2024] Windows 11, version 24H2: What’s new for IT pros
CHiLL replied to 6Foot2's topic in Windows 11
Surprisingly it's already on our VLSC, which usually only appears after couple of weeks from release. -
What a pathetic post and to top it all off, they reference a quote from The ParentPay Group, who's subsidiary, EES, have not exactly been straight with their contracts for SIMS. @Bromcom_Darren is this really what you need on this forum? Bromcom's reputation for reliability isn't exactly stellar on here and now your own company is posting stuff like this.
-
My boss is Polish and says that the wage is simply not possible and even if it was monthly, that's far too high for a public sector education position in Poland. He had a thought that since the website linked has nothing to do with the advertised job, but is education related, the OP may be trying to get clicks or gain traction for their site.
-
I've decided just to use the individual apps for the two brands of TVs we have (Newline and BenQ). I used Miracast, though I wasn't too happy with the idea that it's just always available in the viewable list of devices and it's easy to broadcast without having to enter a code. I don't want to open it up to students trying to cast to the TVs. Using the app, at least the casting screen needs to be open, the code entered and approved on the TV. On another note, we've noticed that InstaShare 2 installs it's own virtual speakers and microphone. In an effort to reduce complication for end users, especially with Teams configurations, is it possible to install InstaShare 2 without the virtual speaker and microphone? We're finding that it's taking over the default/last selection of the settings in Teams or adding extra options that are confusing staff.
-
I've amended my post as I believe it's also in the A3 license. I'm looking at setting the timezone to automatic in Intune but there's no native Intune way to do it and the recommendation is to use a proactive remediation script. If this article is anything to go by, they say A3 includes it: https://www.mrgtech.net/setting-timezone-automatically/
