Jump to content

gshaw

Members
  • Posts

    3,895
  • Joined

  • Last visited

Everything posted by gshaw

  1. At some point I think the days of free cloud will be taken away but only once the majority of on-site servers go. Microsoft already starting to go down that road with the recent price increases on EES and slowly changing the agreements to be cloud-first and per-user rather than per-FTE \ site license.
  2. That's meant to already be out on the latest 2016 builds but MS slipped on the release it seems (along with proper O365 integration, although I've worked around that using Azure AD Application Proxy)
  3. Keeping The Register: Sci/Tech News for the World on my phone's browser launch page - pretty much on there every day which usually reveals breaking news in the tech world. It helped with the ransomware outbreaks as the vaccine files appeared on there well before a lot of the AV vendors picked it up. Also tech update webinars, events etc. can be useful to keep an eye on new product launches, features and so on.
  4. Not ordering any just yet but may be some closer to summer
  5. In theory I agree with you and given the choice I'd only go with the business lines but our budgets have been hammered so much we're being asked to deploy 20 laptops at barely £300 each. SSD is non-negotiable and at that price point it's either refurb (maybe even with a new battery that could be a better bet tbh) or these budget ranges. Now it's fair enough to expect they won't be as solid, screens won't be as nice, have to create driver packs manually rather than having a nice SCCM package etc. but there's no excuse for any bit of IT kit in 2018 to ship with such serious firmware \ hardware issues that they can't even keep BIOS settings and the date correctly. On top of that as a company don't do any of the following... lie directly to your customers saying no-one else has the same issues (Lenovo do you honestly think IT pros don't talk to each other?) blame the OS \ imaging system for a BIOS-level bug that's clearly been resolved after flashing the updated firmware absolve yourself of all responsibility for warranty of products with your name on blame the suppliers for selling the kit rather than accepting there's a basic design flaw that needs addressing As an aside the Dell equivalent range we've had since have been rock solid (didn't exist when the V110 first came out) and even some 3-year old A-series Fujitsu laptops are still going strong with just the a broken screen taking one out of action. Even more hilarious the V110 they had on their stand at BETT (so if they're not meant to be supplied to edu why did you take them an education-specific show?!) had a broken touchpad. Couldn't make it up!
  6. OK in theory but say the next bug only affects IIS and your test server doesn't have it. Then you need one of each OS and role. Before you know it you have a job on its own going through all the different permutations to cover the bases.
  7. This is interesting as I saw comments on The Register slating various practices from using static IP addresses on servers (really?) up to the usual "should have a test network" Sad reality is many people don't have the resource (spare servers to make a like for like copy of live environment) no time to rigourously test these patches. With the security landscape as it is now quick patching *seems* to trump heavy testing for non-critical networks so what can you do? For every person that says delay patching you'll get another saying that in itself is poor practice.
  8. I found a script that did it some years back but does depend on how you run your login scripts due to when Explorer loads https://gshaw0.wordpress.com/2012/04/02/how-to-get-a-perfect-windows-7-managed-start-menu-and-taskbar/
  9. Would be interesting if you benchmark LTSB vs the current 1709 Edu build - the version the last LTSB was built on (1607) was horrific for first logins but that's improved a lot in 1703 and 1709
  10. Are all your affected VMs using the VMXNET3 adapter type?
  11. My self-diagnosed fix from the previous page also seems to have held firm. However the hardware is now failing on the screen hinge where there's some sort of loose connection / fraying cable on some of them that means the screen goes off at a certain angle of tilt (usually the one the user would want!) Lenovo have really blackened their reputation with these devices, steer well clear!
  12. Battery life is the concern on refurb laptops, after 2-3 years of charging cycles they've surely deteriorated?
  13. They are an awful bit of kit, screens failing on the hinges is the latest tale of woe. Lenovo blaming resellers saying these shouldn't be supplied to edu but that's no excuse for such poor build quality regardless of who buys it them.
  14. PRTG has a Syslog sensor that both stores the events and can alert you to errors etc. Free for up to 100 sensors too https://blog.paessler.com/paessler-offers-prtg-100-for-free
  15. @enjay follow the guide here... https://blogs.technet.microsoft.com/askpfeplat/2013/06/09/how-to-enable-user-based-controlenforcement-of-bitlocker-on-removable-data-drives/ However the page isn't very clear and doesn't make the key point that one of the values is set in a different location to the others so check out my GPP dump here http://www.edugeek.net/forums/windows-10/179827-per-user-bitlocker-usb-encryption-2.html to make sure you've got everything in the right place
  16. @fiza @mavhc the BitLocker GPO is but you can hack around it using GPP under User Configuration to switch the registry key flags around to enable it per-user
  17. Encrypted for now via GPO (for staff only, no restrictions for students). Eventually would prefer to drop completely but have to manage the process to avoid user outcry.
  18. @Arthur yeah looks the same tool and that bit about Bulk Token. Do you use any Azure AD joined machines at all? Edit: just tried the app again, looks like it makes a ppkg file joining the devices as the user who runs it, interesting. May end up doing the initial image work with MDT then just apply the School PCs ppkg at the end to get the Azure part done.
  19. @maark do you have InTune then? That seems to be the key and more £££ on our licensing (not a huge amount but need to get it approved nonetheless) The lack of customisation is kinda why I want to build my on WICD package rather than use the Set up School PCs one.
  20. I'm currently trying to set up a loan pool of devices that we can give out to students for home use and as such joining them to Azure AD seems to make the most sense. In technical terms you could call them COPE devices (corporate owned personally enabled). None of them are new devices so will need reimaging to get to Win10 Education, hence requiring some form of initial imaging method to wipe and upgrade them. I'm trying to do the following: image using MDT, push down some required software use a Provisioning Package to join to Azure AD with shared logon enabled complete updates etc. and leave machine ready to use no InTune at present Now initially I looked at the "Set up School PCs" app that seems to do most of that; however all the documentation seems to suggest it's only for 1703 build at latest? So instead I looked at doing basically the same using Windows Imaging Configuration Designer as I know I can then push the ppkg file as part of MDT. However there seems to be another issue, in WICD I can select Azure AD join but it asks for a Bulk Token, which it seems I can only obtain if we have an InTune subscription, or even worse AAD Premium (crazy £££ as it's priced per user even for Education). https://docs.microsoft.com/en-us/intune/windows-bulk-enroll https://docs.microsoft.com/en-us/intune/windows-enroll#enable-windows-10-automatic-enrollment So at that point I wonder how does the Set up School PCs app work as it must use the same Bulk Enrolment to join to Azure AD? is it supported on 1709 build? will we have to work around the InTune requirement by using the OOBE method for students to assign themselves in a 1:1 fashion to a particular device? @Arthur any thoughts?
  21. @johnpd when you say insert... with DISM?
  22. Just wondering if anyone else is experiencing this? Usually the WSUS step in my MDT TS works fine and pulls down updates with no issue but I've been stuck all day with a Surface 3 not updating this one particular patch. Gets all the way along then seems to get stuck \ time out \ sit doing nothing. Have managed to get the TS moving again by killing the Windows Update Installer Worker process but that just defers the installation of the patch a bit further. Anyone have any ideas? I prefer not to use Build and Capture to keep the deployment from clean media if I can help it... Edit: just tried to bring up Task Manager and now the machine decides to complete and reboot (!)
  23. We've started rolling out Google Classroom as a pilot in some areas but we've been asked if it's possible to generate the kind of detailed analytics & user reports we're used to getting from our current VLE (Moodle) Tried a small reporting plugin from the Chrome Web Store but that hasn't given enough detail, been recommended this but it looks a bit pricey https://generalaudittool.com/ Anyone using anything else that doesn't cost the earth (or better, free!)
  24. In true MS fashion they'll admit to it 4-6 hours later then say the issue is resolved while it's still going on (!)
  25. Interesting, thanks all for the responses... I'm not going mad then! That secure.aadcdn.microsoftonline-p.com address sounds about right as when the login page was part loading it was missing background images, svgs etc. that had at least part of that URL in the name. The Google cache theory is particularly interesting, really sloppy from MS if they've dropped a domain without taking the effects on DNS into account.
×
×
  • Create New...