-
Posts
3,895 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by gshaw
-
I had issues with GPP when we were piloting Windows 10, seemed that printers sometimes only mapped on the second login. Other times took multiple attempts with gpupdate /force This is no good for the way our users work with the machines so I went retro and used GPO Deployed Printers instead. These map as Computer Settings (per machine) rather than Per User and seem to have been more reliable. Default printer is then set via script that runs after login, which checks the Computer's OU and does an If \ Then \ Else lookup for the correct default printer to map.
-
Been reading around this for a while and wondering if anyone is using it... So it seems with Office 365 \ Azure AD services you have a couple of options basic user password sync, no SSO ADFS (or equivalent 3rd party) Federated SSO Azure AD Connect Passthrough SSO In most cases it seems ADFS or Passthrough Auth give similar user experiences e.g. Office SSO, browser O365 apps SSO etc. What I'm looking at is whether to go further and do the Hybrid AD Join where internal Windows 10 machines are joined to both the local AD and Azure AD. That seems to rely on Azure AD Connect and running the dnscmd command on scheduled task. The main advantage I can see is... Windows Store for Education SSO (currently relies on entering a username \ password even with ADFS in place) struggling to find anything else... @Arthur have you tried this at all?
-
@Mic_Impero already done this but my query is in the other direction - is Impero trying to inject *into* the AV process?
-
Hoping sihost does the trick, we're already on the latest 7.1.32 so hoping this all does the trick. @Mic_Impero should we also exempt our AV from Injection? I've noticed Sophos service errors on a few machines which I've never seen before and wonder if they don't like being tampered with
-
Windows Security Update KB4343909 (Very Slow Log In Times)
gshaw replied to Safa's topic in Windows 10
@Safa what was the symptom in terms of where the login got stuck? Was it either "Preparing Windows", the welcome animation or a blank black screen? -
Our Smoothwall Office 365 URL list hasn't been updated in years (it's a static entry) so unless they start making that dynamic it's fighting a losing battle to keep up with Microsoft's ever-changing lists of domains.
-
@Safa thanks for this, by "install the updates throughout the day" does that mean you've set a scheduled install time or changed the maintenance window so it's outside normal hours and therefore updates will install as and when required?
-
With the majority of our Win10 machines deployed now I've noticed something that may come back to bite us or it may be a non-issue, hoping someone who's been running it for longer can confirm... Until now we've used the "Download and Notify for install" option in WSUS with updates effectively installing on Shutdown. This works pretty well, used to have them on a schedule but it caused problems with exams and classes as machines were slowing down mid-lesson to install the updates. Now with Windows 10 it seems that install on shutdown isn't a "thing" anymore and you'll only see that option once updates have already been installed and the machine needs to reboot. My question is if we don't schedule an install and have Active Hours set on default (8am-5pm) does that mean that updates will never actually install at all? I know after a certain period users will get that unavoidable nag screen saying "You need some updates" but again they can still cancel out of the install (as most will I'd imagine). We've bought Impero this year and that seems to WoL machines better than anything else we've used in the past so that may become an option but not ideal as machines get unplugged, taken out the wall etc. so can't rely on a WoL maintenance window entirely for updates. Any thoughts on how to get around MS latest bout of silliness?
-
@alfatec first login, I clear the profiles with DelProf2 to run further tests as subsequent logins seem to be OK @Rob_D interesting, I see a Windows Tile Repository error on some machines but that may be a red herring, perhaps 1709 doesn't like a 1703 StartMenuLayout file despite it working fine in terms of applying the layout as expected Have also noticed if I log in a room of machines (via Impero console) with the same account I'll get the black screen issues, however if I log in a bunch of (different) accounts it's fine. For the concurrent logins the black screen issue seems to be related to Folder Redirection as accounts without redirection configured don't experience the issue.
-
@alfatec anywhere from 30 seconds to 2 minutes
-
@Arthur is this completely resolved for you or still getting instances of the black screen? We've tried a whole list of things with support including running the latest early-release 7.1.29 client, still seeing the black screen on about 50% of machines on a first login when using the Impero Console to log them in all at once. Back to the testing tomorrow to try and isolate it further
-
I've just logged a case for this exact same issue, will try the exclusions list on Monday unless support say differently. It hasn't shown up on any of the individual machines I've been working with in my office but logging in a batch of 15 in a classroom today was almost 50% stuck on the black background. On the latest 7.0.65 Impero Client too.
-
I've been using LTSB on our signage machines, does the trick and is the only place I use the LTSB branch
-
Smoothwall root cert not fully OpenSSL compliant?
gshaw replied to Bruce123's topic in Internet Related/Filtering/Firewall
eSafe say the libressl library is very particular about SSL compliance and therefore it's down to something Smoothwall is doing -
Will it fix the battery drain issues that plagued Oreo? I don't dare upgrade my OP6 at present as it seems pot luck whether battery will stay at current levels or lose 50% capacity due to "Android System" constantly draining for no reason. Same issue killed my HTC 10 as well
-
Smoothwall root cert not fully OpenSSL compliant?
gshaw replied to Bruce123's topic in Internet Related/Filtering/Firewall
Have had constant issues with Smoothwall and eSafe not playing together nicely, getting bored of it now and seems more Smoothwall's end. We had the Kenilworth fix, which helped initially then we found another bunch of errors with Google not so long ago as well. -
Suggestions on upgrading the PCs from windows 7 to 10
gshaw replied to genesis's topic in Windows 10
Education and Enterprise are pretty much the same apart from the badge. In fact when you import the WIM file you actually see ENTERPRISE even when using an Education ISO. Education vs LTSB however is the pertinent question on here usually. Pros for Education are OneDrive Files on Demand, ability to use Store apps (if you have any). Cons are needing to remove the cruft that comes down (use an App removal PowerShell script, easily found on here) and managing the regular releases. -
[ms office - 2016] BASIC Basic Deployment - No 365/One Drive?
gshaw replied to JRA's topic in Office Software
SCCM if you have it or MDT Application at image time or alternative deployment solution (have heard PDQ Deploy mentioned a fair bit on here with good feedback) -
@LeMarchand are you running Windows 10 and Wi-Fi with it out of interest? Had GPP set up for printers as part of our 10 migration but found it to be unreliable, printers mapping every second login and suchlike. With constantly changing users and short-lived profiles it wasn't stable enough and caused complaints during the pilot roll out. Ended up going a bit retro and using GPO Deployed Printers, which map under the Computer rather than User session and seem to be working better. Only downside being that setting default printer needs to be done via script but I've done a really nifty VBS for that, so far so good if a slightly less friendly method to admin.
-
Indeed, although unfortunately some of the heftiest \ priciest systems are the ones that are the most deeply ingrained and hard to replace e.g. MIS, access control etc. Also have to watch out for sneaky price increases for cloud equivalents, Sophos have been the worst for this at the moment when we looked to move our on-prem to Central (pricing changes from an overall site license to one where servers get charged at a higher rate than clients, which makes it a fair bit more expensive than anything we had before). Certainly the per-user model can become expensive very quickly and needs to be costed carefully. Finally integration is the other hidden cost to watch for. Whereas on-prem you can often dig into a SQL database to extract data from systems in cloud you're at the mercy of APIs being made available. For some places that may not be an issue but it's about analysing your current environment and making a balanced judgement as opposed to the shiny sales pitch
-
If you're fairly free of legacy applications you potentially could but once you have to start spinning up Windows VMs in Azure etc. to run "on-prem" software then it can get expensive pretty quick unless the costs have come down considerably since I last looked. Lack of a true cloud MIS is probably the biggest barrier to being completely free of on-prem. Hosted ones running in a massive Azure \ AWS VM don't count as that's a really pricey way to "cloud" a product imo. For now we take the view that if a product is available as a native cloud app e.g. O365, G-Suite then make that the default go-to. However if it's Windows server-based then keep it on-prem as even with power and cooling it seems less pricey than putting that up in the cloud.
-
@arjanver you can run a script on Logoff that will clear the OneDrive cache so disk space use doesn't build up. https://www.google.co.uk/amp/s/gshaw0.wordpress.com/2017/11/08/onedrive-files-on-demand-first-steps/amp/
-
Suggestions on upgrading the PCs from windows 7 to 10
gshaw replied to genesis's topic in Windows 10
2012 R2 Domain Controllers work fine, no plans to upgrade those at present -
Interesting feedback @MYK-IT as I'm on v1 too and been wondering if it's worth changing to the newer version to get the nice "encrypt message" button in Outlook rather than relying on subject lines. Sounds like it's not 100% at the moment though so will stick with v1 until that reply issue gets sorted. Edit: that said we're running Office 2013 and upgrading to 2016 shortly so it may not be an issue? We've had a few people have issues with opening OME v1 messages, ironically it's the most secure organisations who need the encryption the most that can't open the messages (!) Think most have got there in the end apart from one from what I remember.
