johnpd
Members-
Posts
142 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by johnpd
-
Hi Paul - I agree - it’s just a shame Microsoft edu Intune can’t have standard ready to go profiles which just need some WiFi and a certificate or two adding. I notice they have express configuration which is easy to use, and I also found a shared kiosk/labs template. It does seem some of it is ready done, but I really need a firm which is 100% Intune and laptop delivery for 1:1 (staff firstly) and it’s difficult to find any firm which can 100% say they have it already written down. This makes me feel like it’s a swim through Mud experience to get the detail done rather than a joyful experience I had with iPads. With the advent of autopilot and CSP partner integration, maybe vendors could charge for on boarding the hardwareHash as a way to make markup? Thanks John
-
Hi all - I’m wondering if there are any companies out there that have deployed 1:1 Intune for Windows devices in the edu sector - that won’t need to charge me a day rate to discuss the setup/scope of works. Simply put I’ve done iPad 1:1 roll outs via tender before and it’s a great success with GBM who did a lot of the work for me. It seems when it comes to windows devices there is an unknown number of days to talk about it and then deliver IT... surely there must be a few out there that can go - here is our turn key solution for schools - basic locked down setup and we won’t charge you to set it up if you buy laptops from us etc etc I don’t want to do anyone out of fair pricing and work done either, but if I can get Apple iPads delivered through JamfSchool without major costs, maybe the same could be done with Intune for schools wishing to have laptops 1:1. I’m upgrading our SCCM over coming week(s) to ensure it’s co managed before we make the move to tendering for this solution. Any ideas on how your sites have successfully rolled out windows and Intune management would be greatly appreciated. Thanks John
-
Ok thanks... as much as I agree with it, the workload is silly - searching and entire office 365 with SAR cases and extracting them into PST, sharepoint etc is not something I have time for.
-
What are the rules around putting in SAR requests against other members of staff mailboxes to find out what they are saying about you? Just had one- seems like a good way to see if I’m being put on staff naughty list if you ask me but in this case staff member feels they have been treated unfairly and want to use this method. Thanks John
-
AD Sync accounts that have moved to another domain
johnpd replied to mrwoberts's topic in Cloud Services
You should maybe create a fake account on admin and do the above as a test if it makes you feel better [emoji51] -
AD Sync accounts that have moved to another domain
johnpd replied to mrwoberts's topic in Cloud Services
And yes what you describe is fine -
AD Sync accounts that have moved to another domain
johnpd replied to mrwoberts's topic in Cloud Services
You want to run a delta sync but I’ve had a few beers now but it’s one line -
Can’t you place the papercut client on a server and have the pcclient as a startup item from a unc? EDIT sorry didn’t read the whole issue...not the solution...
-
AD Sync accounts that have moved to another domain
johnpd replied to mrwoberts's topic in Cloud Services
If you delete the AD account and do an AD/Azure sync, Azure AD will automatically soft-delete the user and mailbox. Once soft-deleted, it will appear when you run this: Get-MsolUser -ReturnDeletedUsers | ft UserPrincipalName Use the UPN from that output in the code below: $OldUserPrincipalName = (old UPN) Restore-MsolUser -UserPrincipalName $OldUserPrincipalName Set-MsolUser -UserPrincipalName $OldUserPrincipalName -ImmutableId "" If you also wanted to change the UPN, you would do this…. Set-MsolUserPrincipalName -UserPrincipalName $OldUserPrincipalName -NewUserPrincipalName (new UPN) Now you have an in-cloud account in Azure AD that is independent to AD but ready to be re-associated. Create an AD user account with the correct username, and don’t forget to set the right UPN. Finally, do an AD/Azure sync, and Azure AD will automatically match the AD user to the Azure user and make it an on-premises synced account, as long as the UPN matches and the ImmutableId was cleared. Do all of this outside of that staff-member’s normal working hours, as it will impact them otherwise. You may need to wait a while for syncs etc. This helpful advice was provided to me by an engineer who is worth every penny. If you ever need a recommendation for this type of work on mass I can let him know you are interested. Thanks John -
AD Sync accounts that have moved to another domain
johnpd replied to mrwoberts's topic in Cloud Services
You need the clear the immutable id- ive got a power shell script somewhere - three school domains migrated over many years also resulted in similar panic attacks [emoji23] -
Forgot to say - goto Admin centre for OneDrive and sharepoint and set to least permissive settings and disable sharing with external users. This will help with data loss policy.
-
We had an issue in SharePoint where even though you make it private and members only - there exists a group by default called everyone - effectively allows members to accidentally open doors to private sites. The same goes for my authority/authenticated users group In SharePoint and visitors group. So disabled sharepoint licence would be helpful to get things in order firstly.
-
There is now support from Sims ID for timetables in calendars and write back in onenote to assessment manager marksheets: https://id.sims.co.uk/support/wiki/41/microsoft-school-data-sync
-
I like Sophos security bundle and if I had that little extra money at the time I might have gone that way. Instead we have smoothwall s8 and s4’s across our sites and recently changed our broadband to wave9. We get great throughout and we are now doing training as a team to make sure we get the most out of the product. Fortinet are military grade, and again if I could afford it I would - I had demo and thought the educational safeguarding reporting was more important and it didn’t have that feature , so went with smoothwall. We have HP switches and the fortinet security appliance can do SDN stuff like turn off Aruba switch port 14 in the science lab if malware is detected etc there is a YouTube video of the setup and I was impressed! Don’t know much about sonicwall but I think it’s considered highly in industry. Pfsense I think is an option if you have no money - I believe there is a firewall and filtering version which is open source and you could implement it via a virtual appliance etc. On LinkedIn training (now Microsoft) there is a video series on how to setup the firewall and filter. If I had a primary school etc with no money you could do this and maybe look at opendns cloud dns safety filtering ? I do like my Smoothwall’s but still learning what they can do, so I guess it’s budget and safeguarding features for me. Wave9 have been great with getting my sites gig bearer broadband and I can highly recommend them. Thanks John
-
Pretty much how each one of my sites are now, except I hadn’t thought of doing DAC for switch in server room... I’ll have a look at that ! I couldn’t afford two 5406zl but sooner or later you could add another I guess when money is available. John
-
I’ve just started up snipe it asset management system on our web host ... it can generate labels and using the iPad camera with qr code we can do maintenance/pat test/room checks in bulk or by individual
-
Thanks it looks interesting for many tasks! You never stop learning in IT!
-
windows 10 Start Menu - How is everyone else doing iT?
johnpd replied to JVSuper's topic in Windows 10
If you DM me I’ll send you the notes -
Hi is there a way to re transmit a remote location, tunnelled and then outputted again fully unadulterated - like you can do as a switch monitor port setup ... I’ve got a situation where I have a building too far to cable and I need to access a device that is wireless direct only. Maybe there are some cool boosters out there than can do this with vpn tunnels? Thanks John
-
Has it been disabled now? How do I get my hands on this beauty?
-
Hi could you help me with driver packing as I’ve gone fully 1803 via sccm and a few machines graphics cards I think needed a helping hand. Also redirected desktop but I’d like to discuss what your pupils do with the desktop etc
-
Hi we have this in 1803 clean system and clean gpo setup with nothing legacy (fresh site install). I’ve seen a troubleshooter suggesting graphics card drivers as the issue...
-
windows 10 Start Menu - How is everyone else doing iT?
johnpd replied to JVSuper's topic in Windows 10
I’m not using any xml - just gpp with targeting if file exists create shortcut and also security group scopes for staff and students. Works a treat and can be explained to a primary teacher. -
Windows Defender - Anyone brave enough to drop their Endpoint Security?
johnpd replied to MagicMadjeski's topic in Windows 10
Just had a 1803 install and the sccm deployment was as simple as making a policy as the win 10 1803 has the included files as standard which then just need a policy to manage them. Currently I’m going through best practices and have just moved wsus to sccm today as well with help from my it provider. This means all reporting and updates are now central in sccm. We pay £1280 ish for server data centre (x2 rack servers) and sccm pack included ( basically unlimited servers and full sccm )
