Jump to content

Steve21

Members
  • Posts

    9,168
  • Joined

Everything posted by Steve21

  1. So we don't force sign in as the automatically signed in profile one below should override that Browser Sign-in Settings -> Enabled (Enable browser sign-in) Configure whether a user always has a default profile automatically signed in with work/school account -> Enabled Disable synchronization of data using Microsoft sync services -> Disabled Force synchronization of browser data and do not show sync consent prompt -> Enabled Then a few others just for nicety, like disabling Guest Mode, removing enable profile creation etc Steve
  2. Which Edge GPOs do you have set currently? Might be easier to tell you what we have different as there wasn't anything specific we did apart from setting the Edge GPOs and ensuring there's the normal Entra Connect etc Steve
  3. No no you misunderstand... Manual scaling DID fix it, but then the customers refreshed too often and broke it again! Steve
  4. Probably worth checking the client version too, as the Windows one had a bug in where groups weren’t being picked up correctly when we rolled out of Summer That’s fixed in a later one Steve
  5. We add SMTP details to Solus and then it emails when a new update is added Not great info apart from “so and so download added” but at least gives a hint Steve
  6. Agent ones for clients are all inbound unless you have your firewalls set to block outbound for extra security Steve
  7. Have you deployed the normal Solus firewall exclusions previously? Did you have it limited to a certain IP/host etc that might have changed? If it's the same domain/credentials etc it's unlikely to be much else I'd have said related to the access denied error Steve
  8. There’s a few that normally affect that things like blocking action centre/notifications from older OS/GPO AppLocker over blocking as that comes via settings/immersive control panel etc over blocking of settings via GPO When you run an RSOP of the user what’s applying to it as might be easier to work backwards Steve
  9. Bearing in mind the 3 locations is locations rather than services Having a backup to two different locations via the same service still counts as part of that 3 steve
  10. Normally it's a SIMs vs Bromcom thing - Not everything SIMs accepts/exports in CTF Bromcom will accept, for example Bromcom won't accept ` characters where SIMs does etc. So some names that are entered like O`Reilly Bromcom won't accept until you change it to O'Reilly etc (Note the difference in `') Normally if you open the CTF it'll tell you inside it which MIS it was created by Steve
  11. First issue I'd check is that you shouldn't be using the extra \ %HOMESHARE%%HOMEPATH%Documents Will resolve to the full path e.g. \\fileserver\Students\25\25JSmith\Documents Secondly it's the permissions on that folder, you shouldn't be having everyone with modify rights etc, that'd be a no no Permissions wise I'd always advise using this (then any additional like your Staff having read permissions etc): CREATOR OWNER - Full Control (Apply onto: Subfolders and Files Only) System - Full Control (Apply onto: This Folder, Subfolders, and Files) Domain Admins - Full Control (Apply onto: This Folder, Subfolders, and Files) Everyone - Create Folder/Append Data (Apply onto: This Folder Only) Everyone - List Folder/Read Data (Apply onto: This Folder Only) Everyone - Read Attributes (Apply onto: This Folder Only) Everyone - Traverse Folder/Execute File (Apply onto: This Folder Only) Everyone only needs to be able to transverse/list/create folders at the folder level, nothing below that should be needed. Then if you're doing it via AD the Creator Owner rights will go to their own user Then finally, they'd just need to ensure that share permissions are high enough for all users (You "can" default to Everyone at Full Control if your NTFS permissions are correct) Steve
  12. We've found that in the past too, been that way for a few years and gave up reporting it. I think it's linked to when .NET gets updated from Windows, as it seems to be almost like it gets upset when there's an update pending/installed until it's fully restarted each service What I noticed is that it'll say "can't start in a timely fashion" but if you restart both the other Impero services (mainly ImperoGuardianSVC), then they'll all start fine even without a full computer restart. We ended up just deploying an schedule task that checks the service every few minutes or so and does the manual fix automatically. This then kicks it back into action if it's broken and just skips it if it's already running. Normally even just restarting the Guardian service then fixes the ClientService as that automatically restarts the service once it's back running again Example: if ((Get-Service "ImperoClientSVC").Status -eq "Stopped") { Restart-Service "ImperoGuardianSVC" } Not exactly a "fix" but a workaround we've been using for a while with Impero at previous schools and seems to fix 99% of the broken clients that stop Steve
  13. Have you checked if there’s any power saving options on the reader? if it’s one of the internal ones that gets detected as usb etc there are options like allowing the computer to disable it to save power which may explain why it works at reboot Steve
  14. Have you installed the office 2024 volume license pack (exe) before trying to activate the key? There is a prerequisite install for new installs on the vamt server Steve
  15. Steve21

    HDMI Quirks

    What resolution though? If they're running 1080p on a laptop and you're trying to run 4k that's very different lengths that are officially supported etc Steve
  16. Steve21

    HDMI Quirks

    Generally that normally happens with too long cables or wrong type of cables when it's automatically trying to work out resolution etc. How long is the full connection from board to device? including any wall boxes/docks etc Steve
  17. Go for the laserprona page for the older ones for different mainboards Mercury III Drivers On the machine you can find the current firmware on the panel if you go to func -> information -> firmware or something similar to that 5206 Mainboard is something like 1.0X~ 5272 V1 Mainboard is around 3.0X~ 5272 V2/V3 Mainboard is around 5.0X~ Steve Steve
  18. Did you check what mainboard your Mercury 3 is using? (5206, 5272 v1, or 5272 v2/3) There are 3 different versions of it (all 3 called Mercury 3), but they have different drivers for each one, and the latest driver on some sites only work with some firmware versions. For example, one of our Mercury 3 was mainboard 5206 running firmware 1.0.6 and another was mainboard 5272 running firmware 5.03 which needed different versions of drivers installing else gave that same PCL errors when using the highest driver on an older mainboard Steve
  19. Really not sure what exactly was tested on this prior to release, as most the bugs that I'm raising are being acknowledged and sent to Dev's to fix, but that just confirms they haven't been tested very well! "We have also located a bug with the "waiting for screen" and this is currently with our QA team to be reviewed and then updated to our live platform, which should resolve the screen issues also" Steve
  20. It's absolutely terrible, nothing seems to be working properly to the extent we haven't even rolled it out to staff yet after the upgrade (and that's even compared to the "semi-working" V1...) So many features we used to use have had to be raised back to them as items aren't even working Definitely doesn't feel like this has been tested at all, or in such a small use case that testers only have had one device to test it on Steve
  21. It's amazing how SLTAI knew about a killing months before it happened to create a script about it... (Take this in jest but just an observation as to when said files were created and then again modified, maybe for another incident?) But if you delve through the attached document it still has the same inaccuracies mentioned about AI previously where all it seems to be doing is scraping info that isn't always accurate and just repackaging it in yet another format that we're being told to totally believe in. Silly examples, but just to make the point: "During a public event at a college" - UVSC was changed to a university in 2008 "Charlie Kirk was shot and seriously injured" - You sure? "happened right in front of hundreds of people" - More than 3000 people were attending according to most new articles AI keeps being spouted as the way forward yet all these examples seem to keep showing is that it's better to go to the original sources to read information, rather than relying on things that are being taken from across hundreds of sites and glued together. As it always seems to be mixing up multiple articles and sources and just getting random info that isn't accurate because it can't understand the context of the data. Just my own two cents there, but I can just imagine the backlash from SLT who are using a script to tell students information that they would then argue against, and as soon as it's given incorrect answers once no-one would trust it again "Sir, Charlie was killed", "No Bobby, my script says he was injured!" Steve
  22. Depends what bit you're referring to here, but roughly 50/50 split For example, installation - external companies normally (but if it's an internal one anything drilling/power etc is site, anything cabling/programming IT). Standard maintenance like cleaning/power issues - Site, anything programming/access control/badges - IT Steve
  23. It depends how you have it setup in terms of best place to add it Guardian -> Categories (or group depending how you have your staff setup) -> add to your allow list (or remove from your block again depending how you have it setup) -> Browse down to "Web and Infrastructure" -> Remote Access Tools -> ConnectWise Whether you want to add it to a single group/user/whitelist whole lot etc, but there's already a premade category for it, so you just need to add to allow/remove from block on said groups Steve
  24. Terrible Even trying to update group memberships take 4-5 attempts before it applies Connections seem worse off too Steve
  25. That looks like the old key you're using for the "non-Chromy" edge Admin Templates -> Microsoft Edge -> Configure InPrivate mode Availibility Set to Enabled (then drop-down "InPrivate Mode Disabled") Steve
×
×
  • Create New...