Jump to content

gshaw

Members
  • Posts

    3,895
  • Joined

  • Last visited

Everything posted by gshaw

  1. I'm not doing any captures with Win10, just deploy from the base WIM upwards and run the apps removal script at the end as an Application What with the Cumulative Rollups and regular releases there's not that many updates for MDT to catch up on and building from the clean media seems to be easiest in terms of updating as new versions of Win10 get released.
  2. Microsoft Classroom is dead, replaced with Teams (which isn't really the same thing at all but it's the new direction of travel) There's a set of plugins available to link Moodle with O365 so you can pick files from OneDrive, use OneNote etc. natively
  3. Using MDT for our Win10 test builds and aiming to go one step further and lose the "Master" image entirely. Just built from the standard WIM and slot everything else in dynamically. Win7 is a bit more of a pain until MS release some updated media, tried slipstreaming the Convenience Update in but seems to cause errors in the deployment for some reason as yet unknown
  4. Set up a 2016 RDS server and then get them to run as thin clients?
  5. Be interesting to see if there's a hook into the OneDrive API so the deleted file goes into the online recycle bin rather than the local one on the PC. You'd hope so given MS make both products but... it is MS
  6. https://blogs.office.com/2017/05/11/introducing-onedrive-files-on-demand-and-additional-features-making-it-easier-to-access-and-share-files/#%2EWRTM2qJsbog%2Elinkedin A bit more info on how it looks. Amazing that after telling us how wrong we all were about Placeholders and that sync was the only reliable method for users to understand they've now made the exact same UI all the User Voice posters were asking for It's the feature that likely makes a migration to Win10 worthwhile
  7. So have you all disabled SMBv1 on everything? Since the rollups came in there's too many failures in WSUS for me to be 100% certain on the clients so adding Jose's startup script sounds like a good idea.
  8. Haha given it's poor detection rates and needing Intercept X to plug the gaps (at almost same cost as the AV solution itself) they've got some barefaced cheek coming out with those lines
  9. Had an email on one of my tech lists doing a bit of a sales pitch for Sophos Intercept X as this was happening. Very nice to know it helped prevent infections in this case (although as we've seen from some people's testing on here it's far from bulletproof) but it still annoys me that the security companies are trying to make a pretty sizeable profit line out of this. Basically their AV products aren't fit for purpose for evolving threats so rather than providing value to the product you pay good money for they hit you for another additional subscription to plug the gap. People will then ask why the NHS didn't have this in place, I can imagine full well why in some places... "we need to address the ransomware threat" "what's that?" "tech explains the threat" "what do you need to prevent it" "an extra piece of software at £x per machine" "can't the current AV do it" "no" "sorry no budget, just tell the users not to open attachments" Extra layers of protection like the honeypot files and early warning scripts we have on here can help but it is a constantly evolving threat coming at a time when resources are getting cut that are required to deal with it.
  10. Finally MS have the OneDrive functionality we all want planned for next update A bleary-eyed Microsoft wakes up after its cloud, IoT party, clears throat: 'Oh yeah, so Windows...' ? The Register Typical it'll arrive after our summer imaging runs but still, progress at last.
  11. As above just one wildcard cert covering your external domain should do the trick
  12. You may need to change the RD Published Name setting to get around this, had to do something similar with ours https://gshaw0.wordpress.com/2017/02/02/server-2016-rds-via-azure-ad-application-proxy-end-to-end-guide/
  13. Started playing with it but then gone back to MDT so I can deploy Office etc. as part of the image then run sysprep at the end although our tablets are for staff use right now rather than student. Re: profiles from what I remember the shared PC deployment has built-in cleanup processes to remove aged profiles to ensure the local drive doesn't fill up
  14. I've used these guys for a couple of sites, live chat support is excellent... https://www.webhosting.uk.com/cpanel-hosting/
  15. If you want to send encrypted mail you'll need to set up Azure RMS (rights management services) on your new tenant. Comes free as part of your EES \ O365 subscription.
  16. gshaw

    Windows 10 S

    Indeed, basically wondering if this is a "set and forget" OS experience like the Chromebooks or if it degrades in the same way as a standard Windows installation. That review device looks like the kind of thing MS need to be aiming at, hoping Dell create something similar to the Chromebook 11 and get the price point the same (around £200-250 max)
  17. gshaw

    Windows 10 S

    Script-based / browser exploit perhaps? Is IE part of the image still?
  18. gshaw

    Windows 10 S

    Is it actually a lighter Windows install aka Chrome OS or just a hobbled version of Windows 10 "Pro"? If it's the latter it still needs AV, vulnerable to ransomware attacks etc. which makes the exercise somewhat pointless apart from increasing MS Store revenues by cutting off standard Win32 installation methods. The "Shared PC" mode is nothing new, just a Microsoft compiled set of scripts many of us have been using for years and is available in Win10 "Pro" already. Need to get hands on it to see what's actually different from an engineering POV as it sounds more policy-based than tech-based as it stands.
  19. Just noticed a couple of our machines haven't checked for updates in some time and are showing in WSUS with failures on some of the Rollup Updates e.g. KB3197868 (apparently pulled and reissued due to bugs). Has anyone else had similar and how are you fixing up these failed machines, we've got 2500+ endpoints here and cleaning up the mess manually each time a poor quality rollup fails doesn't sound much fun
  20. Got both here too, O365 has the MX record and Google is being used for Drive / Classroom / Chromebooks
  21. Quick question in case anyone has done it before... We'd like to try using our internal CA to provide digital signatures for documents. Already got all the CA stuff running but want to make it as easy as possible for users. In theory with auto-enrolment they should receive the cert automatically but most guides suggest duplicating the standard "User" template. That seems to be enabled by default and set to Enrol as well so if I make a second template does that mean users will end up with two certificates instead? Anyone using the default User template for this?
  22. And you use Smoothwall as a proxy with HTTPS inspection? What version of Smoothwall is it? What happens if you visit www.google.com www.google.co.uk www.google.ie
  23. @duzzie ours didn't resolve with the SHA2 update, most sites OK but Google still has issues. What version are you running of each product?
  24. Just tried on a test machine but no joy
  25. Although we have an idea where our particular issue lies it's odd that Google and Google get the error but google.ie, google.fr etc. work fine. Very strange!
×
×
  • Create New...