Jump to content

Oaktech

Members
  • Posts

    9,067
  • Joined

  • Last visited

Everything posted by Oaktech

  1. It fouls up longer GPO operations like software installs and file copy, so yes, disabled as a step during SCCM build here. It is a startup hit, but how much depends on what your machines actually do. All of our machines are shutdown at night by PSShutdown and wired machines that are WOL capable are started up every morning so most people don't notice anything.
  2. I have a slightly different approach, but for the same reasons. All desktops are fixed, all normal locations are redirected except downloads. Downloads don't move with the user. Chrome and IE are both directed by GPO to the local profile location.
  3. I'd get that desktop locked and redirected. Saving stuff on the desktop is a bad idea, both for performance and for data security.
  4. My Large Primary structure is Exec Head - NM (Me) - Technician My Old Senior school structure (4 years ago now) was 'Exec Head - HOS - NM - Senior Tech (me) - 3x Tech'. I believe the structure there now is 'Director of Technical Services - Senior Tech - 3x Tech.' The Academy is about 2500 users/1500 devices across a 2 sites: senior school and free school. They also look after a 3 form/500 pupil 0-Y6 Primary school. The Director of Technical Services oversees: Site Management (buildings maintenance, caretaking), Estate Services (Grounds Maintenance), Music & Theatre Tech, IT, Reprographics, Security & Access.
  5. Nailed it... Seriously though, we all do stuff like that from time to time. I couldn't work out why one of our windows tablets just wouldn't pick up a load of settings. Did all kinds of analysis on it. Realised after a couple of days that I hadn't moved it from the Build OU to the production OU.
  6. I'm not doing it to a promethean panel, I'm just doing it to a big TV, but a short-ish, less than 5m, run seems fine on a passive adapter.
  7. We use MyConcern. I've never even seen it. It just works.
  8. I've put the standalone flash player in a student accessible location, made it read only and they just file->open in it.
  9. I've just been learning via the RTFM route... I learnt concepts in university and it's just the names that change between manufacturers!
  10. Got Impero? Add DLLHost.exe to injection exclusions...
  11. I think we are talking at cross purposes. Once you licence data centre there are no further licence costs for standard guest VMs. The role can be installed on any version of windows server for free, but then you have to then licence the guests on anything except datacentre. There is a free standalone hypervisor that you can install that is just the role without the rest of the OS - like the VMware offering, but you have to licence the guests. It's your choice as to which is more beneficial.
  12. Yes and no - Windows DataCentre with the Hyper V role installed allows you to run and activate as many VMs as you like with no further licensing implications however you have to licence data centre in the first place. It isn't cheap, but it's often cheaper than VM Ware. The HyperV hypervisor is free, but you have to licence the guests you run on top of it, choose whichever benefits you most. https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-server-2016 I've had no problems at all with Hyper V in the last, nearly 3 years. I run a 2 host-SAN cluster and a separate 2 host replica set up and they've been flawless.
  13. Now might be the time to redirect the desktop - up to you whether you force a mandatory desktop they can't change or continue to allow access.
  14. Time and Date OK? Do you have a GPO profile deletion set up that could have been fooled by a clock wobble?
  15. Pinterest - Specific incident. Gambling - Policy handed down from governors. I always use the same pages too.
  16. All of this... Plus, I use 888.com to force an override page - gambling is not blocked on the lightly filtered accounts. If I need a teacher to have supervised access to something that would normally be blocked, a visit to 888.com and the entering of a different set of credentials on the override page that appears gets them to Vimeo or Pinterest which are normally blocked. I've used it, maybe 6 times in 3 years. Attempting to access p**nhub gives a hard block even on 'unfiltered' accounts and sometimes it's necessary to prove to people it's there.
  17. Your core switches? Are they 6 core to be distributed around the building, or 6 in a stack to make a core - In which case I would start looking at an HP 5412ZL2 which, whilst not cheap is excellent.
  18. I just remove edge at build time. It's not necessary when you have IE and Chrome.
  19. I had all the exclusions except DLLHost in already. I've added it and rebooted a the suites. Initial results seem to be that it is shortening logins from sometimes upwards of 5 minutes to around 40 seconds...
  20. Yes - I find specifying it in the SRP breaks a whole bunch of stuff but specifying it in the 'do not run' section has no noticeable effect other than it can no longer be invoked manually by the user the GPO applies to.
  21. It's not been my experience that changing those permissions affects the ability to run scripts, but I guess that's because all the scripts I have that apply run in an elevated context. Adding the powershell exe to the do not run GPO stops it from running from the start menu search unless you elevate it.
  22. Can you share the exclusions?
  23. It doesn't bypass changing the file permissions unless you run as admin...
  24. It appeared when we went to 6249... I'm looking at doing an upgrade to the latest version first week of summer holidays...
×
×
  • Create New...