-
Posts
5,084 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Koldov
-
Come on whose going to say the indicator (extra points if you're a BMW driver)... Honestly though, my car must have a hundred 'hidden' functions, but mainly because I don't use them (or have the need for them). We got a KIA SW when we upgraded to a larger car (enough to fit 3 Greyhounds) from two smaller ones a couple of years ago, I really wanted something as simple as possible without all the bells and whistles... in my mind it always means there is just more to go wrong. Turns out it's quite difficult to get a 'basic' car anymore, admittedly it's not as flash as some and a lot of the functions are pretty much seen as 'standard' these days...
-
How apt...
-
Nothing as fancy as 'Virtual Console' just an option to remote reboot or something would be nice. But there doesn't appear to be any 'monitoring' options at all though, I literally can't see anything other than the sreenshot!
-
After a bit of a scare last night rebooting the server remotely and not being able to reconnect, I tried iDRAC and found it didn't actually have any useful functions. A bit of research showed that it should have shipped with a basic license of iDRAC 7 (it's a DELL PowerEdge T420 tower), but I'm struggling to find out what this actually means. The trouble is there are NO management options... let alone 'basic' ones, so what does basic management mean? How can I find out what it should be able to do and if the 'basic' license is actually installed (and if not how do I sort it out)? I also tried to find an enterprise trial, but it appears as iDRAC 7 is EOL there are no trial licenses available for it...
-
Glad you're sorted, but (if I'm reading all that correctly), interested to know what the thinking is behind splitting all the roles between various different DCs...? All the PDC roles are on one DC here and I get the fact that's a single point of failure, but I think if something goes wrong it's easier to work out and seize/transfer everything. Any benefit/best practise/gotchas doing it one way or the other? Also thinking for whatever reason it was done, it didn't seem to help? Obviously forget it if I've misunderstood your set-up.... I've always had mine the other way round (pointing to the other DC 'Preferred' and then to itself 'Alternate'). Is the thinking behind the way you do it best practise, as if it loses network connectivity it can still DNS (although it would anyway if it points to itself as 'Alternate'...?
-
This is the first time I've had to consider this... even though we've had iPads for years (given the originals were all iPad mini and they were in STM Dux Cases and the new ones are the larger size and in much cheaper cases* so I was kind of waiting for it to happen)... These are only a year and a half old 9th Gen 10.2" iPads from the DfE and looking at a £279 Apple repair fee compared to a retail cost of about £319, is it even worth repairing? What am I to do (as I know I will be asked)...? It's not something I want to try and take on myself (although I know some of you do and will say it's easy) and there are a million 'Screen Fixerz' type websites that will do it a lot cheaper than Apple if you can even trust 1% of them will do a good job... *SLT decision
-
Also I get that LTSB is nearing EOL (Extended End Date - Windows 10 2016 LTSB Oct 13, 2026), I'm not and will get them updated as soon as possible, I'd like to be better informed on the options but I can't find any information on what builds 'Windows LAPS' should the Microsoft Information just says: I'm aware it specifies 'LTSC versions' but iirc MS calls them all LTSC now. EDIT: Emulation mode might be a solution but it looks just as complicated and means I'd have to reinstall Legacy Laps! https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-scenarios-legacy
-
Sorry, now I'm completely lost... Uninstall 'New LAPS'? I haven't installed it have I? I just did the April update, uninstalled 'Legacy LAPS' and removed old GPO settings, then just pushed out the new GPO settings (changed schema etc.) and that was only because 'Legacy LAPS had broken even though it was installed before the April update and no new GPOs had been set... Anway, it would seem I can still use "Get-LapsADPassword -Identity "computername" -AsPlainText" to retrieve the 'Legacy Laps' password for now!
-
I think how you manage it is up to you, but there is a GPO to reset it after it has been used. https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-management-policy-settings#postauthenticationactions:~:text=to%2024%20hours.-,PostAuthenticationActions,-Use%20this%20setting
-
Yeah thanks, but that's the thing... all the LTSC machines we have are Windows 10 Enterprise 2019 (1809) and have all had the April update and once I'd uninstalled the Legacy LAPS, they pinged up their 'new' LAPS passwords into AD no problem. I always look at extended support dates as the whole reason for using LTSB/LTSC is not to have new 'features' anyway... I was quite happy with Legacy LAPS and only moved over onto the new version because it actually broke (even though I thought I would be OK as they were all installed years ago and going by the slightly confusing information that seemed to say it would only break if Legacy LAPS was installed after the April update)... http://www.edugeek.net/forums/windows-10/232440-local-admin-password-solution-now-built.html#post1992776 Not sure if I can run the two side by side somehow as I have about 10 laptops that I now can't get the local admin password for! Although, I am working on prising those laptops out of the teachers hands, some of them are being surprisingly stubborn (like they can't teach for a day without a laptop)... Going to have start heavily implying they will stop working soon or something...
-
Does this work on LTSB machines...? I configured this last week and 99% of my machines have converted and stored a password in AD. However I noticed a few missing and it appears they are the 1% of machines still on LTSB (the others are all on LTSC)... All in the same OU, all show GPO applied with RSoP/GPResult, all have the correct local admin account, all have the correct registry entries.
-
Does this work on LTSB machines...? I configured this last week and 99% of my machines have converted and stored a password in AD. However I noticed a few missing and it appears they are the 1% of machines still on LTSB (the others are all on LTSC)... All in the same OU, all show GPO applied with RSoP/GPResult, all have the correct local admin account, all have the correct registry entries. I know it's half 3 on a Friday, but I'm not getting any sense out of the internet...
-
Restoring Servers will fail after 9th May 2023's Updates.
Koldov replied to psydii's topic in O/S Deployment
This is pretty big... how are we only finding out about this the day after patch Tuesday...? Am I understanding this right...? After I apply the revocations (additional manual steps), the backup I would take before applying such a major change would be useless unless I do all the steps involved in manually updating the recovery media...? "CAUTION After the revocations are applied, bootable media that is not updated will no longer work as expected. Do not proceed with “Step 3: Apply” until you have followed the guidance regarding bootable media." Then to apply the revocations on 1000's of devices, we have to do that manually...? "Open a Command Prompt window running as an Administrator, type each of the following commands and then press Enter to copy the Code Integrity Boot Policy to the devices EFI partition." "After installing the Windows updates released on or after May 9, 2023, open a Command Prompt window running as an Administrator, type the following command and then press Enter:" "Important: An additional restart is required to fully initialize the revocation protections." Like I could even get my lot to restart once a month... Do we just delete all previous ISO files that we have or re-download them/update them somehow? What happens to the average Joe/Jolene consumer who created a back-up (as if) or is relying on their built-in OEM restore partition and doesn't have a clue? Will there be a time when this is all 'automagically' applied? I guess this bit? "NOTE We are working on SafeOS dynamic updates for an upcoming release" -
I think in all honesty we'd be looking at something even smaller than that and no need for management. Currently they have an old Brother MFC-6890CDW ink-jet A3 MFD (doesn't need to be A3 though) and although it hasn't had a lot of use, it is a bit slow and has the occasional misfeed/paper jam even though I've cleaned the rollers etc... which leads to me getting the call and the usual 'oh it's broken again, it's such a load of old junk - can we have a new one?'
-
I have one of the SLT moaning about the printer in their office and so have been told to get another one... Trouble is I can't even remember the last time I looked into small consumer grade printers! Only two people in the office and it wouldn't get a lot of use, inkjet is OK I suppose for the workload, would be helpful if it could be networked (one uses desktop the other laptop). Don't really know what else to think of... Any ideas?
-
Actually, you're right.... I'm not sure it actually creates any 'issue' as such and this may be how it is expected to work, but coming from Office 2016 where this didn't happen it just surprises me that it feels it needs to now, it was more a question of what's the point? I also really see it as 'not' signing into to Office if you see what I mean...? I'm just using Outlook to access various email accounts in a combined format... and I'm signing into to various email accounts through Outlook, I'm not signing into Office... maybe that's just me? I guess it comes from the type of email account I'm signing into (as I believe they are O365 accounts), the 'Exchange' type account (grey box auth) doesn't appear in the other Office apps. I don't see the need for it and I guess this may be as we don't use all the fully featured 'benefits' this behaviour brings. It doesn't sync with OneDrive (as we don't have it), there aren't any fancy personalised templates, or customisations, nothing that 'signing-in' to Office improves for us. It doesn't need to be signed in to validate a license or account as it's activated by a MAK key... we don't even really have control of these accounts as such, as they were (in fact the whole MS tenancy was) created for us purely for email accounts by a 3rd party provider. I can't get the SLT to move away from this set-up and so there is no point in using any O365 apps from it considering the disaster that would ensue from it's removal at some point in the possible future (in fact this is one of the reasons I've always preferred a static on-prem solution - it's bad enough that when the internet goes down they can't email or show YouTube videos, but if I were to add to that no (O365) office apps and no (OneDrive) file access.... that and the fact that I'm stuck in the past and don't trust that new fangled cloud thingy...), or trying to get a whole new tenancy created and have email from one source and O365 from another. So anyway there is no reason I can see for 'signing-in' to Microsoft Office (especially as it uses the accounts I've mentioned).
-
I have a similar but slightly different issue with it that I posted about a while ago, but didn't really get any answers for, so it's stopped my plans for a roll-out' for the time being.... It seems to be the 'Office' way, but a bit like you I wanted machine installs (although it's doubtful that our users will go into 5 device territory anyway as we have 1-1 teacher and admin devices). Anyway, bear with me for relevance... When I open Outlook, I have 4 accounts... 1 of which I sign in with an 80s-style grey box (no problem), but 3 of which require some sort of sign-in to a portal (Modern Auth...?). This is where it gets complicated as I think the 'grey box' account one must be some sort of Exchange set-up and the portal one goes to O365.... I have also tried turning off Modern Auth on these accounts (O365 tenancy), but found I couldn't even sign-in then and it got too complicated to mess with a 'live' prod system... So, once all signed-in to the email accounts in Outlook everything is fine, but then I open Excel and find I have been signed into those as well (with the first account I sign-in to Outlook with)... However, if I sign-out of that Excel still works fine obviously and that is how I want them to work... Unfortunately, I will now find I am signed-out of that account in Outlook AND signed-in to Excel with the next account I used for Outlook!!!!!
-
How do you workout which computers are no longer needed in AD
Koldov replied to TwistedHelixis's topic in Enterprise Software
Looking at the properties of a computer in AD and the 'Attribute Editor' tab has a 'lastLogonTimestamp' value and this seems to correspond with the properties of the 'Object' 'tab 'Modified' date/time value. I'm presuming this is the date/time of the last interaction with AD, so maybe you could find a PS script to query either of these values and produce a list, then work through starting from the oldest. Interesting point as to why there are so many, any reason? -
OK, so I'm getting quite annoyed with myself for not even being able to understand what I need to do to get this sorted... Every time I change the Domain\Administrator account password (which I do regularly) VEEAM has an utter meltdown, as it appears I have a lot of services that run as Domain\Administrator! I must have made a few mistakes on the install as I didn't really understand what accounts I needed to put in, but when I tried to be clever recently on the v12 upgrade I changed it to SYSTEM and then found I couldn't even log in to the console... I have been advised to create a separate VEEAM user (give it a complex password and never change it), but I've heard this can cause issues on restores and to be fair I have no real idea how to create a specific user and give it all the permissions/rights to do every job VEEAM needs to do. So, first things first, will I break anything if I change all these services to SYSTEM...? Next, if I change all of these to some other user what will break (also can I delete all of those 'root' credentials)? Lastly I do not want the console to be allowed to log in with 'Windows session authentication' (as long as I can manually sign-in) is there anyway to change that?
-
[sims] Spring 2023 SIMS update - .NET errors - 'commandreportimporter.exe'
Koldov replied to Koldov's topic in MIS Systems
No, I haven't yet... only found out at the start of the school day and as it's a main server I can't until tonight. Which is a shame as it's a Friday on a Bank Holiday weekend so no chance of support until Tuesday... I've seen it mentioned a couple of times that rebooting after a SIMS update is a 'thing'... never needed to here though. -
Did the Spring 2023 SIMS update last night and have had these errors pop up multiple times every hour since... ID: 1026 .NET Runtime Application: commandreportimporter.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.IO.FileLoadException at SIMS.UserInterfaces.CommandReportImporter.importReport(System.String[]) at SIMS.UserInterfaces.CommandReportImporter.Main(System.String[]) Error ID: 1000 Application Error Faulting application name: commandreportimporter.exe, version: 7.208.23.0, time stamp: 0x635fad77 Faulting module name: KERNELBASE.dll, version: 6.3.9600.20876, time stamp: 0x64004f95 Exception code: 0xe0434352 Fault offset: 0x0002dfd8 Faulting process id: 0x5d44 Faulting application start time: 0x01d97eadb88b8587 Faulting application path: C:\Program Files (x86)\SIMS\SIMS .net\commandreportimporter.exe Faulting module path: C:\Windows\SYSTEM32\KERNELBASE.dll Report Id: f6e55396-eaa0-11ed-81d2-549f35045c63 Faulting package full name: Faulting package-relative application ID: Mentions 'Framework Version: v4.0.30319' but I can't find much about it (or why it is being used... but it is SIMS)... The only thing I can find relating to that on the server could be the following: I've looked in C:\Windows\Microsoft.NET\Framework and the v4.0.30319 folder is there...
-
What words do you (or someone you know) say incorrectly...?
Koldov replied to Koldov's topic in General Chat
Who really knows though... how long have we been saying Hyundai and Ikea 'incorrectly'... -
What words do you (or someone you know) say incorrectly...?
Koldov replied to Koldov's topic in General Chat
I was almost waiting for a 'Four Candles/Fork Handles' type story there... Not so much a pronunciation error from the OH last night, but a 'you know when you can't think of the right word, but say what's in your head anyway' wrong word moment.... On thinking that someone who is well read, she said they were very 'literal'.... in her defence she knew it was 'wrong' but couldn't come up with a better word (I can't think of one either, 'literate' meaning you can read/write, or 'literary' which is 'of literature') so I'll stick with 'well read'. Then later on, there was something else but I forget what it was, as it descended into a 'you're picking on me' argument....
