-
Posts
6,514 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by kennysarmy
-
Hi We have over 1000 Windows devices all running v2.9.5 of Monitor deployed using a GPO, I've downloaded the latest v2.10.2 and pushed this out to 9 devices to test. I've confirmed the old version has been stripped off and the new version deployed. However in their console, several hours later, it's still showing the old version and the last seen and capture dates are not updating. Anyone seen anything similar?
-
Random user account locking out occasionally!
kennysarmy replied to cheaptonersucks's topic in Windows 11
And you are sure there is not a user on your domain doing this on purpose? Has the user who is being locked out and another user got very similar logon names? -
Quizlet - issues due to ads being blocked apparently!
kennysarmy replied to kennysarmy's topic in Cloud Services
It does look like by unfiltering html-load.com for students it allows the site to function. Any risk to allowing this site? -
Students are today getting a message which states: Please allow ads on our site Our site is supported by ads. Please consider allowing ads on this site so that we can continue to provide quality content. Thank you for your support. Notice: Your school’s security settings may block the site. Please ask your IT department to allow html-load.com. Support: [email protected] I have ensured for a test user that html-load.com is accessible and Quizlet still gives the above warning. Any ideas? Smoothwall is showing some blocked sites: https://tr.snapchat.com/p https://www.google.co.uk/ads/ga-audiences?v=1&t=sr&slf_rd=1&_r=4&tid=G-FVWZ0RM4DH&cid=654107212.1774003660>m=45je63i0v9116367008za200zd9116367008&aip=1&uid=AU1D-0100-001774003783-7KAQ8YW7-UFLQ&dma=0&gcs=G111&gcd=13v3v3v3l5l1&npa=0&frm=0&tag_exp=103116026~103200004~115938465~115938468~116024733~117484252&z=1012733107&safe=active https://analytics.tiktok.com/i18n/pixel/events.js?sdkid=C3E8DRI7V1C28HV6V6D0&lib=ttq
-
Block specific HTML file (Eaglercraft)
kennysarmy replied to Undertoad's topic in How do you do....it?
Really useful - thanks. -
Would you be eligible for a CIF bid for this?
-
In this video he explains how to use a local ESD or ISO so you don't need to download.
-
I only started looking at it last Monday and this morning I'm booting off a USB stick and it's currently installing Win11 25H2 after booting from a USB stick - pulling the image straight from Microsoft, I've added in the drivers for a test Stone PC so hopefully it will also install those - then the next thing would be to get it join the domain automatically and hand off remaining installation tasks to Intune. Saying all that I'm going to keep using MDT for as long as possible.
-
About to start looking at OSDCloud. Currently like the OP, using MDT (WDS) to image and then I use Group Policies to manage settings and push out software, but a little dabbling with Intune means some software is now pushed out via Intune. My plan (I think) is to use OSDCloud to install Windows 25H2 from a standard WIM, booting from a USB, then hand-off to Intune to complete the installation of any required software. I think for now I'll keep running in hybrid mode and use GPO's to lock down the devices. Can anyone point me to any resources to help get me started on this journey? Cheers
-
Issues in schools across our Trust this morning!
-
We have 3 schools in our Trust and are getting pressure from above to bring them all "in-line" though there is some conflict between what the CFO wants and what each individual school wants, until I am provided with a clear vision we can't do too much. School 1 is the mother school, hybrid setup and over 1000 devices using cloud drive mapper to access files held in OneDrive & SharePoint (7-13) School 2 is totally cloud-based (brand new school, only open 4 years) with no on prem. servers, using built in OneDrive client app to access data, c. 500 devices (7-11) School 3 hybrid setup, some use of CDM for certain apps, OneDrive & SharePoint. c 400 devices (7-11) MTO in place between the schools.
-
Random user account locking out occasionally!
kennysarmy replied to cheaptonersucks's topic in Windows 11
We get this sometimes, have they set up O365 access on their phones and recently changed their password? -
Every website Certificate Error
kennysarmy replied to JazzFlute's topic in Internet Related/Filtering/Firewall
We get (from Smoothwall) The server's certificate did not match the domain name URL https://every.education/ -
We've been seeing users occasionally see O365 emails via the browser slow to preview for a few months now, but MS tell us there is no issue, everytime it's reported, users advise other websites are fine. The issue can last anything from a few seconds to 30 seconds waiting for an email to preview...
-
No, students have just learnt to wait. Our last correspondence with them was: Hi Jeff, I understand, thank you for letting me know. My apologies that we weren't able to find the cause quicker for you. I will close your case. I will ask Matt to take a note of this and continue exploring independently on his end to see if any replication can be made that leads to future improvements for this issue. If anything more comes from this I will give you a courtesy email to let you know. Kind Regards, Joseph MiddletonTechnical Support EngineerT. +44 28 9442 8105 Maybe raise the issue with them and feel free to qoute us as having similar issues : Balcarras School.
-
1. Understand what you’re changing (important mindset shift) Before touching anything, align stakeholders on this: WSUS = you approve individual updates and control distribution centrally WUfB = Microsoft hosts updates, you control policies, rings, and deferrals No update approvals No on-prem update content Reporting is done via Intune / Update Compliance / Azure Monitor, not WSUS 👉 If leadership expects “Approve KBs like before,” reset expectations now. 2. Prerequisites & readiness checks Identity & management Devices are Hybrid Azure AD joined ✅ Decide how you will manage policies: Intune (recommended) Group Policy (supported but legacy) Ensure devices can reach: windowsupdate.microsoft.com *.windowsupdate.com *.delivery.mp.microsoft.com Check firewall / proxy rules (very common blocker) Licensing WUfB itself is free, but good reporting requires: Windows Update for Business Reports (via Intune) Or Update Compliance (Log Analytics) 3. Inventory your current WSUS setup Document this before dismantling anything: OS versions in use (Win 10 / Win 11, builds) Current update cadence Monthly patch timing Feature update frequency WSUS policies applied via GPO: Specify intranet Microsoft update service location Do not connect to Windows Update Internet locations WSUS cleanup status (declined/superseded updates) This helps you recreate the intent in WUfB. 4. Design your WUfB update rings For ~1000 devices, keep it simple: Example ring structure Ring % Purpose Pilot 5% IT & early adopters Broad 85% Main workforce Critical 10% Execs, kiosks, production Decide per ring: Quality update deferral (e.g. 0 / 7 / 14 days) Feature update deferral (e.g. 0 / 30 / 90 days) Deadline + grace period Active hours Auto-restart behavior Write this down first. Don’t build policies ad-hoc. 5. Configure WUfB policies (Intune route – recommended) Create Update Rings In Intune → Devices → Windows → Update rings for Windows 10 and later: For each ring: Enable: Quality updates Feature updates Set deferrals per your design Configure deadlines (strongly recommended) Assign Azure AD device groups 💡 Use dynamic device groups where possible. 6. Remove WSUS enforcement (critical step) This is where most migrations fail. Identify WSUS GPOs Look for policies setting: Specify intranet Microsoft update service location Do not connect to any Windows Update Internet locations Options: Option A – Modify existing GPO Set WSUS policies to Not Configured Option B – New “WUfB” GPO Explicitly disable WSUS settings Link higher in OU structure Key setting to remove: HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate WUServer WUStatusServer ⚠️ If these remain, devices will never use WUfB. 7. Pilot phase (do NOT skip) Scope 20–50 devices Mix of: Laptops Desktops Different sites VPN vs non-VPN Validate: Settings → Windows Update shows “Managed by your organization” Updates come from Microsoft, not WSUS Feature updates are offered correctly Reboots respect deadlines VPN traffic doesn’t spike unexpectedly Use: Get-WindowsUpdateLog and reg query HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate 8. Configure reporting & monitoring Option 1 – Windows Update for Business Reports (best) Enable in Intune Uses Azure Monitor + Log Analytics Near-real-time visibility Option 2 – Update Compliance (legacy but useful) Log Analytics workspace More complex setup Track: Update compliance % Devices stuck on old builds Restart pending failures 9. Gradual rollout to remaining rings Move Broad ring devices in batches Monitor: Patch success rate Helpdesk tickets VPN / WAN bandwidth If needed: Use Delivery Optimization Configure DO Group / Cache servers 10. Decommission WSUS Only after: 95%+ devices updating successfully via WUfB No critical systems dependent on WSUS Steps: Decline all approvals Stop WSUS service Monitor for 30 days Decommission server Remove WSUS GPOs entirely If anyone can add anything to the above before I make a start it would be appreciated. J
-
Outlook Cloud Microsoft Emails not displaying preview
kennysarmy replied to kennysarmy's topic in Cloud Services
We have seen that message too. We have another user who has issues when they move an email in to another folder (out of Inbox) then check back later the email has not moved and is back in the Inbox. -
We are seeing quite a few users randomly having issues using Chrome and Edge browsers whereby the preview of their emails don't display, but then magically do after seconds or minutes of waiting and or refreshing. I've had the issue myself and confirmed it happens even bypassing our on-prem Smoothwall, so my connection to the internet is straight out through our Wave9 managed Sophos Firewalls. I've provided Wave9 with the times when I've seend this (and have been bypassing the Smoothwall) and they have checked the firewall and found no issues. When users have the issue they now know to check other websites for functionality and always report other sites such as bbc etc are fine to load and navigate. I'm now on to my 3rd ticket with Microsoft and I appreciate that random issues are hard to diagnose, but they are basically fobbing us off with seemingly no real idea of how to troubleshoot this problem. Does anyone have any ideas at all as to what might be causing this and what further troubleshooting I could ask the users to do, bearing in mind they are of course restricted accounts.
-
Notepad++ v8.9.1 regression fixes, bug-fixes & new improvements:
-
Classroom Management Options
kennysarmy replied to BassBone99's topic in Network and Classroom Management
In one of our schools we had ABTutor Cloud and replaced it with https://classroom.cloud/ - we trialled another option (off the top of my head can't remember what it was) But ultimately https://classroom.cloud/ won through and is working well in a fully cloud secondary school of 900 users. -
I'm curious as to how others are monitoring their M365 Sign-In Logs, I would like to do more of this to ascertain each morning if there has been any suspicious activity but as we're seeing almost 1000 failed attempts each 24 hours I need some method to remove the crud.
-
DfE Standards Updated To Include IT Support Standards For Schools
kennysarmy replied to PrimaryNetMan's topic in General Chat
Has anyone started to put their Information Asset Register (IAR) together yet? Anyone happy to start brainstorming what data from an IT point of view needs to be provided to the DPO?
