Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

PeterH

Members
  • Posts

    108
  • Joined

  • Last visited

Everything posted by PeterH

  1. OK I have just spent the best part of the last week battling with UE-V on Windows 10. There are a number of caveats and in our experience it is less than perfect, but the general configuration outlined below seems to work for us. So to start with, UE-V is part of the latest builds of Windows 10. There is no agent to install - it is already there and simply needs switching on. To configure UE-V, it is best done with group policy. Again, if you are using the latest Windows 10 ADMX templates, the UE-V configuration items will be there already. Firstly to configure UE-V, you will will need two network shares on a server somewhere. The first one is the Settings Storage Location, which is where each user's UE-V settings packages will be stored. The second is the Settings Template Catalogue, which contains the settings templates. These tell UE-V where each application stores is settings, so it knows which file / registry locations to sync. You can find a guide to creating these and the permissions you need here: https://docs.microsoft.com/en-us/microsoft-desktop-optimization-pack/uev-v2/security-considerations-for-ue-v-2x-both-uevv2. However the permissions specified in that document did not work for us! So this is what we used to get it working: Settings Storage Location (e.g. \\server1\uev-settings) Share Permissons Domain Admins: Full Control Domain Users: Full Control NTFS Permissions Domain Admins: Full Control: This folder, subfolders and files Domain Users: List folder / Read Data, Create Folders / Append Data: This folder only Creator Owner: Full Control: Subfolders and Files Only Settings Template Catalogue (e.g. \\server1\uev-templates) Share Permissions Domain Admins: Full Control Domain Computers: Full Control NTFS Permissions Domain Admins: Full Control: This folder, subfolders and files Domain Computers: Modify: This folder, subfolders and files Once you have created your shares, you can configure UE-V using group policy. UE-V is configured in both Computer Configuration and User Configuration. There are a number of settings you will find in Administrative Templates / Windows Components / Microsoft User Experience Virtualization. The settings we made are as follows. Some things can be configured both in Computer and User configuration, so I'm not sure which is best practise, but the following works for us: Computer Configuration Sync Method: None (note that this actually disables the UE_V Sync provider and establishes a direct file connection to the settings storage path. In testing, we found this to be much more reliable) Enable UEV: Enabled (note the auto-register inbox templates option doesn’t seem to work on Windows 10 1709, some searching online suggested this is no longer supported) First Use Notification: Disabled Settings Template Catalog Path: e.g. \\server1\uev-templates Sync unlisted Windows apps: Enabled Synchroinze Windows Settings: Enable all Tray Icon: Disabled Use user Experience Virtualisation: Enabled User Configuration Do not synchronise Windows Apps: Disabled Settings Storage Path: e.g. \\server1\uev-settings\%username% (note you need %username% to create a folder for each user in the settings storage location) Synchronise Windows Settings: Enabled Use User Experience Virtualisation: Enabled Having created all of the above, you need to copy the Microsoft UEV settings templates from a Windows 10 computer into your settings template catalogue share. On 1709, these may be found in C:\ProgramData\microsoft\uev\inboxtemplates - just copy the files over. If you need any additional settings templates, there is a settings location template gallery here: https://go.microsoft.com/fwlink/p/?LinkID=246589. There are some templates to help with roaming desktop settings and pinned items on the taskbar and so on. Reboot one of your workstations and you should find UE-V is working. You can use Powershell to test it, the following commands may be useful: Get-UevConfiguration: This should show that SyncEnabled is True and it should show the settings storage path and the settings template catalog path that you configured in GPO Get-UevTemplate: This should display a list of imported UEV templates and will confirm that your settings template catalog path is working correctly. Finally, as each user logs in, it should create a folder for that user in your UEV Settings Location, containing the settings packages for that account (note that these are in hidden folders so you will not see them unless you are showing hidden files/folders in explorer) There are a few additional items you can set in the registry to configure the UE-V agent. These are all in HLKM\Software\Microsoft\UEV\Agent\Configuration: RepositoryOwnerCheckEnabled:REG_DWORD=1 (see https://docs.microsoft.com/en-us/microsoft-desktop-optimization-pack/uev-v2/security-considerations-for-ue-v-2x-both-uevv2) WaitForSyncOnLogon: REG_DWORD: 1 and WaitForSyncOnApplicationStart: REG_DWORD: 1 (we found setting these seemed to make syncing of pinned taskbar items more reliable) There are a few issues we have discovered and there will be other things I'm sure that crop up: Roaming Outlook profiles with UE-V is not supported (see https://support.microsoft.com/en-gb/help/2850989/migrating-mapi-profiles-with-microsoft-ue-v-is-not-supported). You may have issues with roaming Outlook signatures also, because the default signature is referenced in the Outlook profile. Roaming IE Favorites with UE-V works OK, but Edge Favorites don't roam and is not supported and neither do any other Edge settings. Thanks Microsoft. No wonder people are switching to Chrome. We still have a few issues roaming Office 2016 toolbar settings, which don't seem to work very reliably.
  2. You need to determine what is blocking it. If a software restriction policy is blocking it then it will be logged in the application event log and you can see it in event viewer. It will say something like 'Access to your.exe has been restricted by your administrator by the default software restriction policy'. If you don't see any such events in your log then you can stop looking at software restriction policies as this is not the issue. However if it does look like a software restriction policy is blocking it, then there are some advanced logging options that might help to troubleshoot it: https://technet.microsoft.com/en-us/library/hh994586(v=ws.11).aspx Failing that, you would need to use something like Process Monitor (https://docs.microsoft.com/en-gb/sysinternals/downloads/procmon) to see what the app is trying to do. Probably attempting to write to the filesystem or registry somewhere the user doesn't have permission. If it fails straight away when it is started, it should be fairly easy to spot.
  3. Assume you're talking about software restriction policies, so you could do this by creating a hash rule for thonny.exe rather than a path rule. This will allow the exe to run from anywhere. If you do that, do keep in mind that if the exe is upgraded at some point in the future to a new version, the file hash will be different, so you will need to re-create the rule.
  4. Have a look at these two pages. This one talks about options for configuring the start menu layout, and allowing users to customize if you want to: Everything you wanted to know about virtualizing, optimizing and managing Windows 10?but were afraid to ask ? part #5: THE START MENU - HTG | Howell Technology Group And this one about issues with roaming the start menu layout: Everything you wanted to know about virtualizing, optimizing and managing Windows 10...but were afraid to ask - part #6: ROAMING - HTG | Howell Technology Group
  5. Roll-up screens and ultra-short throw projectors don't work very well together as a rule. If the screen is not perfectly flat, it will result in noticeable image distortion. You really need a rigid screen for an ultra-short throw.
  6. When you've installed Windows 10 Pro, you need to login and then run: c:\windows\system32\sysprep\sysprep.exe -oobe Then it will shut down. Switch back on again and you will get the regional settings screen where you can set the language and so on. Whilst on that screen, plug in the USB stick. It will recognize it after a couple of seconds and offer to apply the package for you.
  7. Has anyone tried the Microsoft Setup Schools PC app for Win10? It's really quite good. I wanted to try it out for some old laptops without having to bother about domain-joining them and then installing a load of software. You just download the app and install it, and set a few options. It creates a setup package file that you put onto a memory stick. To set up computers, you just plug in the memory stick during the Windows 10 setup "oobe" phase and it sets the machine up for you. The idea is that you could unbox a brand new laptop, switch it on, plug in your memory stick and be up and running with a useable machine in just a few minutes. It seems to be designed to live in the cloud. You can set it up to log into Azure AD (Office 365). No domain join is required if you use this option. If you have Office365 with ad sync, you can log in using your school email and password. Log in and you get a start menu populated with tiles for the Office 365 web apps. Clicking on one will pop it open in Edge, logged into your account and ready to go without any further logins required. Opening the OneDrive app will open your OneDrive storage and show all your files. Clicking to open an office document will open it in the web app so you can edit it. No local install of Office required. Photos and videos will open in the OneDrive app. There's no local storage available, so there's no My Documents, My Pictures and so on. However, you can easily upload files from a memory stick to your OneDrive. The restrictions aren't that great. There's nothing to stop users installing apps from the store, running exe files off a memory stick, or from downloading for example Chrome and installing it. It won't let them run MSIs but that seems to be about the only restriction I can find. There's nothing to stop them going into network settings and disconnecting the WiFi which will stop anyone else from logging in until it is reconnected. There are very few customisation options at the moment. There's no way to customise the login screen, the start page for Edge, or to choose which tiles get displayed on the start menu for example. Although You could probably achieve something by hacking around with login scripts. I wondered if it would make a good alternative to Chromebooks. I've often thought it is about time that Microsoft came up with something similar to a chrome book, because google are going to rapidly dominate education otherwise, especially with budgets being cut so much at the moment. I'm not in a hurry to go down the Chromebook route as we don't have google accounts or google directory sync (not yet). So I'm hoping that Microsoft will continue to develop this and address some of the issues. If you're signed up to Office 365, It could be a nice solution for Win10 devices that just need basic internet/cloud/office apps.
  8. You can split each service to run in its own service host, then it should be listed individually in Task Manager and you should be able to identify which one is causing the problem. sc config servicename type=own The problem is you will need to do it for each service on the machine and there will be lots of them. But if you look here How to find memory usage of individual Windows services? - Server Fault there is a powershell script that can do it for you. We had a very similar problem a year or so ago and turned out to be windows update consuming huge amounts of memory shortly after the computers were started up. Try disabling the Windows Update service and see if that makes any difference. That was on Win 7 however.
  9. Yes we've had a go at this. The following page tells you how to create and run an unattended installation of Visual Studio: https://msdn.microsoft.com/en-us/library/ee225237.aspx Basically, you download the web installer exe and then run it with the /layout switch to create an administrative installation point containing all the files it needs to install. Then you have to play around and create a deployment XML file which you can configure to include the components you need. Biggest problem is it's a huge installation package that takes ages to install.
  10. We bought three of these, they seem to work quite well: https://www.amazon.co.uk/AccuPower-AP1216-Charger-Rechargeable-Battery/dp/B00N2GEX70/ref=sr_1_1?ie=UTF8&qid=1461156695&sr=8-1&keywords=B00N2GEX70
  11. We used to use the SSL login page but don't any more. But I seem to recall that to get the SSL login page working, we had to go into System | Administration | External Access and add : Interface : (Your wireless network) Source : ALL Service : Other web acccess on HTTP (80) Interface : (Your wireless network) Source : ALL Service : Other web acccess on HTTPS (442)
  12. We had something similar to that happen once. Have you checked in Services | DHCP | Global | Interfaces. We found that the main school LAN had got ticked in there somehow. Unticked it and it's been OK since even after many shutdowns/restarts.
  13. I've always thought MoviePlus was the best of the Serif software. It's always done the job, easy to use and never had a problem with it. However it looks like it is being discontinued: https://community.serif.com/forum/movieplus/36571/movieplus-x7-and-mkv-files?page=1#answer147276 Really disappointed about that. MoviePlus X6 is still available, but I don't think has been updated for a few years now. So might have to start looking for something else for the future.
  14. Don't redirect to a mapped drive, redirect to a UNC path instead. Shouldn't be a problem with that. I suspect the problem is that it is trying to access the redirected Appdata folder before the drive mapping has been established.
  15. Users can't see a history of what they have printed but can see their current account balance and any jobs they have submitted but not printed. Docupro is installed on the server, in our case its on our print server. There is a small client that you can install on the PCs. It puts an icon down in the system tray so users can see outstanding jobs and current balance and can also cancel outstanding jobs. DocuPro does manage the MFDs if they have the DocuPro OpenAPI software on them. Yes it does print release, you can submit a job to a central queue and then print from anywhere. Also handles scan and copy. You can set an age limit for print jobs, so the queue doesn't get filled up with unprinted jobs. You can also get DocuPro to manage ordinary desktop lasers, and it will do accounting but not print release You can create groups in DocuPro based on OUs in AD. Once you have those groups you can impose restrictions such as colour/mono, max number of pages, enforce double-sided etc. And you can set prices for printing and there's a scheduler which allows you to automatically top up account balances if you want to. As far as routing large documents to different devices, I have a feeling it can but not 100% sure as we don't do that. Our Docupro installation is a few years old now, so newer versions might be a bit different.
  16. We're battling with this as well in a very similar set up. It's a real pain and worse still doesn't seem to be fixed even in Windows 8.1. The problem seems to be that Windows loses the WLAN profile and can't re-import it. If you dig into the event log and go to Applications and Service logs | Microsoft | Windows | WLAN-Autoconfig | Operational you will find event ID 14003 WLGPA saying "A wireless group policy couldn't be applied to your computer". That is the cause of the problem, but I don't know what triggers it. The net result is that the computer loses the wlan profile and cannot connect to your wlan. I don't really have a solution, but we are in the process of developing a startup script that will check if the WLAN profile exists and then re-import it if it doesn't. The script itself would obviously need to reside on the hard drive of the laptop not on the network. It uses the netsh wlan commands and does something along the lines of: netsh wlan connect "your wlan profile name" 'Read the netsh wlan output and check for a known error netsh wlan add profile filename ="c:\windows\your-wlan-profile.xml" netsh wlan connect "your wlan profile name" For the script to work you need an xml file containing your wlan profile. You can get this by doing this on a working machine: netsh wlan show profiles netsh wlan export profile "your wlan profile name" folder=c:\windows You would need to ensure that the xml file and startup script exists on each machine, so you would need to distribute them somehow, perhaps using group policy prefs. The script would then run each time the machine starts up, check to see if it can connect to the wlan and then import the profile if it can't. Hopefully that might give you a few ideas. I can post the script if you like, but it's written in vbscript, and not well tested at this stage.
  17. Check what group policy settings set being applied.... Administrative Templates | Windows Components | Tablet PC | Touch Input | Turn off tablet PC touch input I seem to remember that enabling this prevents touch from working on Smartboards, but the pens still work OK. You can set this policy for computers and for users so you might need to check both.
  18. Got Profile Manager half working on OS X Server (Mavericks). I can get it to push device settings out to our Mac OS X 10.9 clients no problem. But how do you get it to push settings out to users? I have created some OD users, added them to a group in Profile Manager and made some settings for that group. But the settings never get applied on the clients. You don't even get anything showing up in Active Tasks or Completed Tasks in Profile Manager. It never appears anywhere. Tried it for both users and groups. Any ideas?
  19. When you create your report, you need to base it on Student, On Roll and then add the Attendance Marks subreport. From here, you can add the Mark and Mark Date. You then need to create a filter on the subreport by clicking the little red book icon on the right-hand side, then click New at the bottom and add the Mark date field. The key is to create the filter on the Attendance Marks subreport, not on the main report. This will give you a list of students attendance marks between the two dates, so it probably won't be in exactly the format you want. You'll probably need to bring it into Excel and do some group or summing or whatever to produce the weekly totals.
  20. OK just a couple of thoughts - Is your Exchange server configured to send outgoing emails through relay.inthehive.net? Check in Org Configuration | Hub Transport | Send Connectors | Properties | Network Also is the IP address of your server on the EMBC network as Capita sees it (e.g. 10.x.x.x) the same as it was before your network change? If not, that would explain why you are unable to receive incoming emails. It sounds like the IP of your Exchange server has changed. Capita will need this in order to relay inbound email to you.
  21. He didn't tolerate her sin though did he? He didn't say "I don't agree with you, but whatever". He gave her a command "go now and leave your life of sin." It wasn't just a desire for her to leave her life of sin behind, but it was a command for her to follow. You could perhaps argue that he was being tolerant in the sense of not applying the punishment that the Old Testament law called for. But Jesus tempers the law with the good news of the Gospel - in living a perfect, sinless life, he has fully satisfied the demands of the law. And in carrying our sin on the cross, he has fully satisfied God's just requirement that sin is not tolerated, but dealt with. What we see here is not tolerance, but mercy. Sin is not tolerated - it is dealt with. The question is, where will our sin be dealt with? Has it been dealt with by Jesus on the cross in our place, or will we have to face its horrific consequences ourselves in the future? We don't know for sure whether she was forgiven, and freed from eternal condemnation becauase we don't know whether she followed Jesus' command to leave her life of sin. Yes she might have been "let off the hook" as far the the law was concerned, but she might just have ignored what Jesus said and gone back to her old life, with no sorrow or remorse over her sin at all. We cannot be forgiven if we don't see our need or if we don't intend to turn from our sinful ways. But if we do, we can claim for ourslves God's mercy and grace, we can know for sure that our sin has been completely dealt with, and that "there is now no condemnation for those who are in Christ Jesus."
  22. Tolerance sounds great and up to a point it is, because of course we must respect and seek to live in peace with those who disagree with us. But "tolerance" becomes a problem when we think we can live our lives however we wish, because it will be "tolerated". "Tolerance" becomes a problem when potentially harmful behaviour and un-wise choices become acceptable because we must "tolerate" everyone and anything. Do you think Jesus was being tolerant when he condemned the Pharisees and religious leaders of his day for their hypocrisy, their pride, their false teaching and their refusal to believe in him? Do you think he was being tolerant when he commanded the woman caught in adultery to "go now and leave your life of sin"? The message of the New Testament is not simply love and tolerance. It is repentance - the need for us to turn away from the sinful courses of our lives and to turn to Godly ways of righteousness. It is not just religious hypocrites and adulterers in need of repentance - it's all of us, the Bible is clear that all of us have a sin problem, we've failed to live our lives as we should and we need to repent, and to receive forgiveness and new life that God offers us. He gave us the best gift that he had to save us from the consequences of our sin. He gave us his son who came into this world and lived the perfect life that we could not, and yet who bore the punishment for sin that we deserve. Through his death and suffering, God offers us not tolerance of whatever sinful choices we choose to indulge in, not a license to live our lives however we wish, but he offers love and forgiveness to those who confess their sinfulness and cast themselves upon his mercy.
  23. Yep, you need to remove the Allow Logon Locally right from those users using either the local security policy on those servers or through group policy - Computer config | Policies | Windows Settings | Security Settings | Local Policies | User Rights Assignment | Allow log on locally PH
  24. OK, we have a Mac OS X Server about 5 years old. Been working fine, but this morning found it hung on the login screen with the spinning coloured wheel. Forced it to shut down, but now just get a flashing folder with a question mark. Seems like it can't find its startup disk, so booted off the server installation DVD and went into Disk Utility - it can only see the DVD drive. Went into RAID utility - everything looks good - 3 good HDDs, a good RAID Set called RS1 and a volume called R1V1 - everything seems fine. But nothing else can see the disk. Startup utility can't see it, Disk utility can't see it, the OS X Server Installer can't see it. For some reason it's like the RAID isn't presenting the disk to the host? Have tried an NVRAM reset, but no difference. Any ideas anyone? Many thanks, PH
  25. Not sure... my understanding was that Office 2013 was "part of" Windows RT and that all RT devices would include it. I was looking at the details of the Asus VivoTab RT which includes a "preview" version of Office 2013. And according to Office Home & Student RT Preview - Office.com this can be upgraded "for free" to the release version. As for licensing, yes it's not for commercial or business use. And I guess they don't want schools purchasing them just for classroom use, as they'd prefer you to buy a full Office license, but if they're being used at home as well, perhaps that might be OK?
×
×
  • Create New...