Jump to content

gshaw

Members
  • Posts

    3,895
  • Joined

  • Last visited

Everything posted by gshaw

  1. Wiping clean but with Education 1709 as we've done all our testing on that build and 1803 had some bugs on initial release. Made new Win10 specific policies I can roll out alongside our existing base GPOs including a few bits such as... > set Store to O365 managed version only > disable ability to boot to recovery from within Windows (check posts on here for why) > set up SSO to OneDrive Files on Demand (finally cloud storage using a native desktop API!) > managed Start Menu layout that also allows user to add additional tiles but not remove Office etc. > File Associations to use Adobe for PDFs rather than Edge > disable Hybrid Boot (seemed to cause issues with GPOs during our tests) > reduce Telemetry to bare minimum There's some others but need to read back through the GPO to remember them all now. Should be a few to get you started
  2. Some public bodies will only accept data transferred via some form of encryption, be it Egress Switch or in our case Office 365 Message Encryption... that's been our experience anyway
  3. @karlr I see this method mentioned a lot but do you repeat it 12x a year to keep up with the monthly CUs? With 10 updating so regularly I've tried to avoid any capture steps and just been building on top of the base WIM from MS media then letting WSUS handle the rest.
  4. May be good for the environment but bad for your wallet... I recall reading an article recently where the loose items were priced to be much more expensive than the plastic wrapped multi item version.
  5. DCs are 2012 R2
  6. Just wondering if anyone else has been experiencing this... Windows 10 Education, 1709 x64... all been working fine until recently when GPMC keeps hanging (not responding) when viewing and editing GPOs. Got to a point where I'm having to use it via another server instead as it's so unreliable on my machine. Tried removing RSAT and reinstalling with latest version, no joy. The other tools in the RSAT pack seem to be working fine. OS Build 16299.492, dcdiag ran on all DCs and passed tests fine
  7. Might be worth trying these guys I saw at BETT http://www.laptopsandspares.com Laptops and Spares
  8. SSL inspection is a tough one, on one hand the web basically goes dark as far as filtering is concerned without it but the amount of issues also make it difficult... - devices are increasingly naggy about installing root CAs e.g. Android persistently warns about the security of the device once a certificate is installed, thus users feel "spyware" has been installed on the device - some apps break once MITM SSL inspection is turned on = poor BYOD user experience We SSL inspect on domained devices but BYOD puts us in a difficult place.
  9. Education 1709 - done all our testing on it so seems risky to jump onto 1803 just before we start deploying. Again Files on Demand is the big driver.
  10. @Sir if the user says they won't put a work-related app on their personal phone are they effectively locked out of remote access?
  11. If it helps I deploy x86 images from an x64 server with no issues. Just imported the WIM from original media and it was happy. As above we have x86 and x64 Boot Images provisioned. MDT 8443 deploying Windows 10 1709 and LTSB
  12. Suggested all our tutors move to Autodesk given the free licensing
  13. Looks like the HTML5 feature is going to be part of Server 2019 instead... https://searchenterprisedesktop.techtarget.com/blog/Windows-Enterprise-Desktop/Windows-Server-2019-RDSH-is-a-go
  14. It shouldn't be a problem but in practice I found apps don't switch neatly when they're open on 4G then connected to Wi-Fi where Quic is blocked. Force closing and reopening tends to do the trick in terms of restarting with a fresh connection but pretty poor end-user experience and many will just think something is "broken" The issues with Quic soon became irrelevant because of the pinning issues you describe afterwards - was either allow YouTube without inspection or have the app not working.
  15. Just looking to get some additional input into this as I've read various suggestions on forums... We currently have WSUS configured for our Windows 7 machines to Download updates but leave them to install on shutdown, GPOs set such as... Configure automatic updating: 3 - Auto download and notify for install No auto-restart with logged on users for scheduled automatic updates installations Enabled Re-prompt for restart with scheduled installations Enabled Now it seems in Windows 10 those settings may well carry over but aren't necessarily enough to keep it under control. There's no good time in terms of Quiet Hours as machines are used all day and don't WoL at night so having a mandatory window isn't great. However it seems there's no way to disable the full screen prompt of "Updates need to be installed" even if you can hit Esc to close it. Does anyone have a set of Windows Update settings that give an acceptable end-user experience or realistically is it going to be a pain point we'll have to take on the chin?
  16. You'd be surprised, loads connect to our BYOD Wi-Fi and I think they do it to save their data. It's a similar story with battery life and charging off of PCs etc. The contracts aren't as generous as you'd think, especially on the higher-end phones. Something like 10GB doesn't last long with lots of video. As for the filtering it's becoming more and more of an issue, once again battling with e-Safe and Smoothwall clashing with each other doing two lots of SSL interception and that's before we get anywhere near Quic and certificate pinning. Also going forward from July Google are forcing most of the web towards SSL, even for sites that don't particularly need it so the problem will only get worse. Chrome is also getting very fussy and flags certificate errors at the slightest provocation - horrible end-user experience when they change something but equally you can't stay on old versions because of the Flash patching. Stuck in the middle to some extent at the moment...
  17. Quick way to get control of their own x64 architecture perhaps go out and buy AMD?
  18. Same here with Planet eStream but running on an eclectic collection of hardware but all being rebuilt to Windows 10 LTSB. @themightymrp what's the performance of a RasPi like running the eSign client? Been waiting for the Linux version for years
  19. For all you playing with Azure AD Premium... have you seen how much it is?! MS force you to pay per per user and not per FTE as you'd be used to on any other EES license. Blew it out the water for us, real shame as I wanted the password self-service reset functionality amongst others.
  20. Got a variant of this using GPP in the User Configuration but applied to machines as a Loopback Merge policy. Again seems to work most of the time but had a few not map until second logon (mostly on Wi-Fi, which is struggling at the moment due to age and lack of density in AP deployment)
  21. Interestingly this just popped up in my email feed, Google adding proactive anti-phishing features to G-Suite https://www.cnet.com/news/new-anti-phishing-features-come-to-google-g-suite At the moment to get these features in Office 365 takes a paid third-party product because the default O365 filter is frankly appalling when it comes to protecting against phishing attacks. Your move Microsoft...
  22. Use the Office Deployment Tool to remove OneDrive components from the Office installation. Configure Office ADMX files \ GPOs to prevent access to OneDrive features Should be pretty good to go from there
  23. Absolutely - the worst thing is to get caught inside an education bubble. Always keep an open mind of what's out there and apply the best bits to your own environment
  24. Wish they'd hurry up and get it released We've already got ours running through App Proxy using https://www.vroege.biz/?p=2462 but would be nice to have an out-the-box integration and the HTML5 for iPads (as the RDS client for non-Windows machines is really poor in terms of supporting Modern Auth)
  25. Bug, definitely Unsupported operating systems... They may have been hiding behind that as the official line but when the date goes wrong at boot time well before even booting an OS it's a BIOS level bug imo. Reset button "aka Novo button" doesn't do much aside from being easier to access the boot menu.
×
×
  • Create New...