-
Posts
3,895 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by gshaw
-
I'm currently testing a new Wi-Fi system to replace our existing Aruba setup and one of the things I'm trying is 802.1X certificate auth for our internal network devices (domain laptops and so on) It works fine in NPS with our Windows CA, with GPO to auto-enroll the certificate and push the SSID profile. Easy for Windows 10 laptops but wondering what people do with... macOS laptops iPads Android tablets Seems like I can go and manually request certificates provided the device's hostname \ FQDN matches perfectly but that seems rather onerous for a large number of devices. Is there anything slicker or do you end up with a separate SSID \ auth method for these? Edit: found a few useful-looking links, anyone using SCEP \ NDES to generate the certificates for Apple devices? or maybe this? https://support.apple.com/en-my/HT204602
-
MS screwed up the client version on 1709 by not including the one that had Files on Demand functionality... wonder if they'll learn this time...
-
I go even further and don't do any form of capture at all. MDT deploys straight from the source WIM and everything else is packages as an Application
-
Be interesting to see which party ends up with the blame for this debacle... is it Sophos at fault or Microsoft I wonder. I guess no surprise given the 2019-04 update includes Spectre / Meltdown fixes, which trashed machines with Sophos AV first time around.
-
Once you move to Office 365 ProPlus it changes every 6 months (or even more regularly if you're brave) so no point putting in the image at that point imo
-
The beauty of thin image approach in MDT - deployment changes for 1809 took all of 5 minutes and so far looking good. Added the new OneDrive per-machine install to the TS as well, looking good so far. Using a different script to remove the apps in 1809 https://www.scconfigmgr.com/2018/11/27/remove-built-in-apps-for-windows-10-version-1809/
-
Hallelujah! Someone at Microsoft seen sense at last. Now just need it added to WSUS for the client updates and we might actually have the product made the way it should've been done in the first place
-
Cumulative Update/s Break Windows Deployment Services
gshaw replied to thatley's topic in Windows Server 2016
This is why I'm such a big fan of this forum, thanks @thatley for posting this Just had the same error appear on my WDS \ MDT after updating it to 8456 release \ 1809 ADK. Just remembered in the back of my mind this thread and looks like the workaround fixes it for me too. Saved chasing my tail blaming the MDT update for something caused by an OS patch! -
Welcome to the new Smoothwall
gshaw replied to Simcfc73's topic in Internet Related/Filtering/Firewall
When the reports don't crash the box (even on the S14) I might have some faith in the product having moved on. Still waiting for the cloud reporting demo we were promised at BETT... -
1809 is back on there today for me, downloading now
-
I was hoping on 1809 being stable by now but it seems a bit of a cursed release, wonder if MS are beginning to give up on it and concentrate efforts on 19H1 instead?
-
New features coming to Remote Desktop Services
gshaw replied to Arthur's topic in Windows Server 2016
@free780 I had a response from the AAD Feedback team, pretty much mirrored the statement on the web page "Yes, this feature is on our roadmap and we are keen on making this integration happen" -
Has anyone got access to the 1809 ISO via VLSC? We only have 1709 and 1803 on ours
-
Is anyone on here running Azure AD Connect with Passthrough Auth configured? We're looking to move off our Federated Identity service and go to Passthrough auth but need to check a few scenarios... if a user has "must change password at next logon" set in AD and logs in externally will this setting be honoured and handled neatly by the Azure AD sign in process? does Seamless SSO work with SharePoint sites? I know it doesn't with the Office 365 portal but our Intranet sits on SharePoint Online and that definitely needs to stay seamless SSO
-
New features coming to Remote Desktop Services
gshaw replied to Arthur's topic in Windows Server 2016
Just emailed them as we're big fans of AAD Application Proxy here -
New features coming to Remote Desktop Services
gshaw replied to Arthur's topic in Windows Server 2016
Was going to turn this on last week then read it doesn't work with Azure AD Application Proxy, sort it out Microsoft [emoji58] -
Stability more than anything, you'd have more time to test the xx09 release before deploying, vs the xx03 release that would've barely been out a month or two. This happened to us with 1709 vs 1803. I'd done months of user acceptance testing with 1709 and was tempted at one point whether to take a punt on 1803. Common sense soon prevailed and I stuck with 1709, which I was very glad about when 1803 had issues with mapped drives initially whilst 1709 behaved exactly as it had in testing; nice and solid [emoji41]
-
Yup, one script in MDT and get your GPOs tight to prevent any other consumer junk "experience" popping up. Pick a stable xx09 release and you're good for 30 months. I went with 1709 and it's been good for our 3000+ machines, only issue related to apps was high traffic due to Smoothwall not processing the proxy requests correctly (now fixed) Looking at testing 1809 with ProPlus instead of Office 2016 for our next round of summer reimaging as it stands. I don't know whether they've been ported into the latest LTSC but there were a lot of Windows Defender security features that came in with 1709 (EMET stuff from Win7 days) that you miss out on with the LTSB build so for that alone I stick with the Education build.
-
We do similar with e-Safe and Impero. e-Safe analyse the logs for us and avoids the bulk of the false positives we get from Impero. However the latter does give some useful context with the screenshots and history logging so works well alongside. Downside to that is two costs for both solutions though. Senso did mention there's an option for a third party to do the log analysis so could be an option? Impero seem to have other Safeguarding packages too but there's too much marketing and product names to keep up with what actually does what.
-
It seems we may need to update .NET from 4.7 to 4.7.2 on our Windows 10 1709 machines but having a bit of a head-scratcher with WSUS. If I go on the Microsoft KB page I see that the installer is KB4054530, available for all OS https://support.microsoft.com/en-gb/help/4054530/microsoft-net-framework-4-7-2-offline-installer-for-windows However in WSUS searching for that same KB article only lists it as available for Windows 7 for x64. Any ideas why it doesn't show up as a Win10 update, or in fact is the "Windows 7" update actually cross-OS as the Microsoft page suggests?
-
Yup that was my thinking too
-
Depending on how you time your deployment maybe not, 30 months support on the xx09 releases
-
Education for us so we can use Files on Demand
-
With Windows 10 and changing releases I've gone down the completely thin route so elements can be swapped out as and when required. Want to change from 1809 to 1903 build? Just switch the WIM. Want to switch from Office 2016 to Office 365 C2R... just switch the Application. The only bit that takes a while is the WSUS phase but again the Cumulative Updates are released monthly so unless you like changing the reference image regularly it doesn't seem worth the effort capturing \ updating it. Used the thin approach with Win10 Education 1709 on 3000+ devices, as long as your MDT and WSUS servers are up to task it'll be fine
-
We're using Micro Focus ZENWorks, pretty good at the software deployment and patching side of things but not so clever at imaging (we use MDT for that)
