Jump to content

gshaw

Members
  • Posts

    3,895
  • Joined

  • Last visited

Everything posted by gshaw

  1. But if a user wants to change their password from home you can't without third party product or AAD Premium
  2. Still no password write-back for SSO users without the stupidly priced AAD Premium plan So frustrating MS don't get how much users value that feature and don't even make AAD Premium financially viable for Education. Only good thing is that you get Azure AD Application Proxy features without needing to request the Azure AD Basic licenses separately as you did in the past.
  3. We use their Bulk Users tool as well, good product and very reasonably priced which made me look to see if they did a password tool as well
  4. Bit of both, some users want to change their existing password remotely (or reset with change on next logon set), some have forgotten it and others have expired e.g. over summer Actually caught out by our own integration here... we use Azure AD App Proxy to publish RDWeb and SSO to it via Office 365 login... which is tied to the AD login Potentially yes, been keeping an eye on this as an alternative if Centrify ever kick us off our free plan. As far as I understand it covers the SSO piece but doesn't include any off-site password recovery \ reset features? Edit: clicked one link further and same applies with AAD Premium That's the ugly side of cloud-based licensing, companies using it as an excuse to move from site-based \ FTE licensing to per-user, which is horrible for education price-wise.
  5. We'd like to implement some form of self-service site for users resetting network passwords remotely. Tried a few options so far but no joy: Office 365 built-in features - won't work as we use Azure AD Sync and thus require Password writeback functionality, which brings us onto... Azure AD Premium - ridiculous per-user pricing, shame on you Microsoft Centrify - currently on a free plan and unsure how long features will be supported iamcloud - were on this but dropped the subscription now Microsoft will include proper OneDrive functionality in next version of Windows 10 (their CDM tool was a big feature for us initially) Seen a couple of 3rd party AD-based products we could publish via Azure App Proxy, anyone used any of them? ManageEngine ADSelfService Plus https://www.manageengine.com/products/self-service-password/?MEtab Dovestones Active Directory Self Service Password Reset Active Directory Password Reset, AD Self Password Reset
  6. Since 1607 logon speed has been much better and my latest 1703 image pushed out via MDT logs in under 30 seconds (Samsung Evo SSD). I do have a couple of settings left on from imaging that seem to help (disable first run animation, DesktopSwitchTimeout set to 0) https://blogs.technet.microsoft.com/mniehaus/2015/08/23/windows-10-mdt-2013-update-1-and-hideshell/ Just looking to see if the switch timeout setting has any other side effects, the only thing I can see so far is that some scripts may still be running when desktop appears. All crud apps removed by Powershell script during imaging. Image is built from clean MS media, I don't manually capture a base image as it looks to cause more hassle than it's worth.
  7. Indeed, there doesn't seem to be much benefit at all moving fixed PCs to AAD \ InTune but it's a nice revenue generator for MS.
  8. I have a custom PowerShell script I used in the previous imaging system I built that checks AD for an existing Computer account and joins with that; if no account exists the machine gets joined as a new Computer
  9. @djones here's my current one - the "Remove Windows 10 Apps" is a script you can get from here: https://github.com/W4RH4WK/Debloat-Windows-10/blob/master/scripts/remove-default-apps.ps1 I do things a bit differently in MDT so some steps will look a tad unusual e.g. I use a custom script to Domain Join as it lets me choose whether to put a machine in local Active Directory or Azure AD Windows Updates are installed by a separate utility called ABC Update as it worked better during testing additional steps for custom registry edits and Wi-Fi profiles specific to our network SMART Notebook only installed for machines matching a specific WMI query based on name and role
  10. Virtual, fired up 3 new ones in a DFS Namespace for a migration project not so long ago
  11. Education as only the Current Branch edition will get the funky new OneDrive functionality that's going to be a huge win that makes a Win10 migration worthwhile. That is provided we don't move to Google before then as File Stream works on everything
  12. I'm on this now 1EB, now there's a challenge to try and fill if I ever saw one!
  13. There is a per machine method you can enable when deploying, remember seeing that at an MS seminar. It's more the question of features vs stability, bad enough the OneDrive UI seems to change on an almost daily basis let alone Office.
  14. Had the same thing with Tumblr and in the end it stayed blocked as Smoothwall also confirmed the safe search features are ineffective.
  15. MDT, keep it very clean using the VLSC media and use a script to remove the apps as part of the Task Sequence. When a new version of 10 is released just swap out the .wim file, simples
  16. Sounds like now is a good time to set up some segregation. One vulnerable BYOD device is all it takes to infect your trusted network.
  17. @RLR any chance you could screenshot where the default printer checkbox is? Can't see it on the Deployed Printers page
  18. Cynically it's also a way to make money from old rope selling you InTune licenses to get these devices managed The idea of BYOD that the business \ school controls is more interesting. In a workplace it's usually a way to get users to self-support the hardware and needs locked down for data security, which is understandable but for education where parents \ students are being asked to pay for the privilege of owning the device how do they react to a third-party controlling what they can and can't do?
  19. I've been using MDT to push out a few extra apps then at the end I re-run sysprep to give the out-of-box experience.
  20. Easy guide for those who haven't done it already https://eddwatton.wordpress.com/2017/06/27/use-group-policy-preferences-to-deploy-the-notpetya-vaccine/
  21. Just pushed that perfc file down via GPP as a precaution
  22. Quick straw poll to see if anyone has any ideas on this one... We're aiming to move from a legacy print management product to vanilla Windows Server mapped network printers... fairly simple there. The bigger challenge is mapping them on clients due to the large number of printer objects (100+) so need to box a bit clever with how they're pushed out. I've had a few ideas... create policies per block and use GPP and machine OU per-item filtering to select them use GPO and set per OU (room-based) objects but I think that method doesn't let you explicitly set the default printer use GPO set at Computer OU level with Loopback then use GPP-based policies for each room go retro and use my trusty old VBscript which will then let me use IP ranges \ machine names to narrow down the search Option 3 lets me keep one script and apply that simply to all machines but is a bit more clunky to maintain vs. the GPP option which is point and click but may perform more slowly. Any thoughts?
  23. If there's performance issues it's more likely to be with the environment than the kit imo. Any Intel i5 (common refurb CPU option) over the past 5 years should run Windows (especially 10) at a good pace with no issues. Even older gen kit runs fine on 10, Microsoft did a good job there in optimising that part of it for sure. What does makes me laugh is seeing new machines being offered with HDDs, you'd be crazy to buy any non-SSD machine now for general use such is the huge difference in speed. 4GB RAM and SSD is the minimum I'd push out now, whether refurb or new
  24. I will do a blog post on our new MDT setup soon as it's got quite a few nice bells and whistles on. Very flexible system especially if you like a bit of scripting as well
  25. Local here, used to run Mandatory for classroom machines at my last place but Win10 seems to be a pain for profiles these days. Keeping it nice and simple now, less for MS to break that way (!)
×
×
  • Create New...