-
Posts
4,103 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Boredguy
-
O365 E-mail send & receive blackout times
Boredguy replied to Paid_Peanuts's topic in How do you do....it?
Simple answer is it's not really possible and comes down to the end user to regulate themselves. You could create a script to disable access out of hours, but that would not stop e-mails being delivered by third parties to their mailbox. It could also impact accessing OneDrive or Office at home (if your staff make use of the option to install Office 365 on their home devices) -
You can just get a standard SSL certificate. Doesn't need to be anything fancy Logon to the Zone Director and go to Configure -> Certificate Fill in the Generate a Request form, with your Common name being the FQDN you want to use (I choose wifi.schooldomain.sch.uk) This will give you a CSR file you can then send to any SSL provider you choose. I go via our ISP who places an order with the JISC. They should send you back the completed certificate file, and an intermediate and root certificate (hopefully they give you the last two) You then go back to the Certificate option in the Zone Director, Select your SSL cerficiate via the Browse button in "Import Signed Certificate". If you have an Intermedate one, select the option and that certificate and repeat until all 3 are uploaded. You can then click the Apply option and it will reboot your Zone Director and the new SSL will take effect.
-
We get our certificates via JISC as it works out cheaper than getting a wildcard one for the few domains we need without a self signed. They sent us the QuoVadis Root and Intermediate certificate along with our requested domain ones as part of the certificate pack. Previously then sent similar when they used a different registrar.
-
Did you upload the intermediate certificate at the same time as adding your wildcard SSL? We're getting it as well with a new certificate. Fine for our workstations as they have the latest root update, but student devices don't. I'm adding our root and intermediate certificates at the end of the day
-
Outlook 2016 on Office365 - Multiple huge OST file instances
Boredguy replied to chrisjako's topic in Office Software
Well network cache is not recommended, but can be setup with the following settings. We've run it for Office 2013, 2016 and our current 365 deployment GPO setting is in Microsoft Outlook 201X/Miscellaneous/PST Settings Default location for OST files \\server\share\%username% GPP HKCU\Software\Microsoft\Office\1X.0\Outlook ForceOSTPath with reg_sz value of \\server\share\%username%- 7 replies
-
- 1
-
-
- appdata
- large files
-
(and 2 more)
Tagged with:
-
Outlook 2016 on Office365 - Multiple huge OST file instances
Boredguy replied to chrisjako's topic in Office Software
It just doesn't let them load outlook on the 2nd machine. We recommend users use the OWA where possible.- 7 replies
-
- appdata
- large files
-
(and 2 more)
Tagged with:
-
Outlook 2016 on Office365 - Multiple huge OST file instances
Boredguy replied to chrisjako's topic in Office Software
or you can be creative and go against MS recommendations and use GPO and reg frags to point the OST to a central network location if you want to keep cached mode, but does mean users have to remember to close outlook before using it on another station. Cacheless is easier- 7 replies
-
- appdata
- large files
-
(and 2 more)
Tagged with:
-
We added a bit more to that script DaveP when we moved @echo off C: IF NOT EXIST "C:\Program Files\Sophos" GOTO EOF IF EXIST "C:\Program Files\NewAVFolderName" GOTO SAVREM GOTO EOF :SAVREM Echo Stop Service net stop "Sophos AutoUpdate Service" echo NTP removal MsiExec.exe /X{66967E5F-43E8-4402-87A4-04685EE5C2CB} /qn REBOOT=SUPRESS echo SSP Removal MsiExec.exe /X{1093B57D-A613-47F3-90CF-0FD5C5DCFFE6} /qn REBOOT=SUPRESS echo SAV Removal MsiExec.exe /X{65323B2D-83D4-470D-A209-D769DB30BBDB} /qn REBOOT=SUPRESS echo RMS Removal MsiExec.exe /X{FED1005D-CBC8-45D5-A288-FFC7BB304121} /qn REBOOT=SUPRESS echo SAU Removal MsiExec.exe /X{AFBCA1B9-496C-4AE6-98AE-3EA1CFF65C54} /qn REBOOT=SUPRESS MsiExec.exe /X{BCF53039-A7FC-4C79-A3E3-437AE28FD918} /qn REBOOT=SUPRESS echo SED Removal "C:\Program Files\Sophos\Endpoint Defense\uninstall.exe" IF EXIST "C:\Program Files\Sophos" GOTO CLEANUP GOTO EOF :CLEANUP RD /S /Q "C:\Program Files\Sophos" reg delete "HKLM\SYSTEM\CurrentControlSet\services\Sophos Message Router" /f reg delete "HKLM\SYSTEM\CurrentControlSet\services\Sophos Agent" /f :EOF
-
[ms office - 2016] Office 365 Click to Run: Device based activation
Boredguy replied to KevinB's topic in Office Software
Shared Activation uses the logged on users credentials to activate the office session. So if you have a user that does not have any Office 365 licence, you might find that it says it is not activated. Device Activation creates a computer account in 365 with the A1 Plus for Students licence and does not worry about what licence the current user might have. Both methods are perfectly valid. -
we've been using Defender (or Endpoint protection) via SCCM since is included in our OVS-EES agreement anyway. The cost for the SCCM server licence was a fraction of renewing with another of the AV providers, and gives us application deployment as well. Touch wood not had any issues, and it's been a lower impact on stations compared to our previous Sophos installation.
-
powershell script to add members to office 365 group
Boredguy replied to chekmate1984's topic in Scripts
We have several AD based distribution groups, both ones with users as direct members and ones that have nested groups. All of which work as long as the group scope is set to universal. We leave the group type as Security and put the e-mail address in the mail field and 365 syncs it all up happily -
powershell script to add members to office 365 group
Boredguy replied to chekmate1984's topic in Scripts
On your server where Azure AD Connect is installed, you can force a full sync via powershell Import-Module ADSync Start-ADSyncSyncCycle -PolicyType Initial -
Intermittent fault - Screen not duplicating to Promethean projector
Boredguy replied to Jeff_Buck's topic in Windows 10
We still get this issue, but it's mainly down to PowerPoint 365 ignoring the settings not to use extended desktop so when they press ESC it turns off the monitor and leaves the ActivPanel as primary -
powershell script to add members to office 365 group
Boredguy replied to chekmate1984's topic in Scripts
In AD you can highlight all your accounts within an OU, right click and select to add to a group. The delta sync every 15/20 minutes by Azure Connect will then upload them to 365 Also make sure your group was a Universal scope and has the e-mail address value set -
Downsizing the case is possible, but depends if you have a dedicate GPU and the size of your current Motherboard. You could get a MicroATX case if your using onboard graphics. Obviously if you need to replace the motherboard, your likely going to need a new copy of Windows as well, in which case a mini ITX would be a good shout for a small form factor
-
[ms office - 2016] Office 365 Click to Run: Device based activation
Boredguy replied to KevinB's topic in Office Software
https://sysadminedu.wordpress.com/2017/01/07/step-by-step-guide-to-deploying-office-365-pro-plus-with-device-based-activation-with-sccm/ has the details for Device based activation as long as you have A1 Plus for Students in your O365 licence allocation -
Microsoft releases Office 2019 for Windows and Mac
Boredguy replied to Zoom7000's topic in Office Software
Office 365 A1 Plus for faculty / Students should be free to add to your tenancy as it was part of the self signup options, but I know that several people have had great fun with getting MS to assign the licence to them as their domain has not been flagged as a valid educational establishment or some such reason. Of course you should still ensure you have a MS agreement in place that covers you for Office (such as EES-OVS) but it then means you can deploy the C2R version instead of the MSI one -
well they should only have Parent, if they are a parent of a child (and your running SLG)
-
There isn't a list per say, but as ThomL posted, there is the spreadsheet that gives you a breakdown for the SIMS roles. We created our own role for our admin assistants based on what it was within SIMS that they needed to access
-
[windows software] Education Open License. License Numbers?
Boredguy replied to Gongalong's topic in Licensing Questions
It covers any stations your establishment owns regardless if you class them as student or staff (which is why the support guy was confused). You can also install Office on a Mac under the OVS-EES agreement -
[windows software] Education Open License. License Numbers?
Boredguy replied to Gongalong's topic in Licensing Questions
You mean the EES-OVS where you pay each year based on the number of FTE staff you have. It's not free for student PC's -
Office 365: Giving student access to email again
Boredguy replied to kestrel1's topic in Cloud Services
Don't worry it's doesn't exactly jump out and say "Click here to see the licence parts you have turned on and off". It says on so you think that's all that's needed -
Office 365: Giving student access to email again
Boredguy replied to kestrel1's topic in Cloud Services
In the Office 365 Admin console, Select to Edit a user and find the user in question. Under Product Licences, click Edit If they have a licence applied it should show as "On" and there is a drop down on the left of the licence name which expands the box so you can turn on and off certain portions of the licence such as the Exchange Online Plan -
Yes but if comodo is not already in the device as a trusted RA it fails on that step. Latest version of Chrome fails due to how it handles certificates now.
-
We have the same issue with the self signed certificates, but all the devices/browsers we have, give the option to click advanced and then to carry on to the captive page. I am planning on getting a proper SSL from janet later in the month, once I know which provider they are using these days which should resolve the self signed warning again.
