Jump to content

gshaw

Members
  • Posts

    3,895
  • Joined

  • Last visited

Everything posted by gshaw

  1. I'm currently testing a new Wi-Fi system to replace our existing Aruba setup and one of the things I'm trying is 802.1X certificate auth for our internal network devices (domain laptops and so on) It works fine in NPS with our Windows CA, with GPO to auto-enroll the certificate and push the SSID profile. Easy for Windows 10 laptops but wondering what people do with... macOS laptops iPads Android tablets Seems like I can go and manually request certificates provided the device's hostname \ FQDN matches perfectly but that seems rather onerous for a large number of devices. Is there anything slicker or do you end up with a separate SSID \ auth method for these? Edit: found a few useful-looking links, anyone using SCEP \ NDES to generate the certificates for Apple devices? or maybe this? https://support.apple.com/en-my/HT204602
  2. MS screwed up the client version on 1709 by not including the one that had Files on Demand functionality... wonder if they'll learn this time...
  3. I go even further and don't do any form of capture at all. MDT deploys straight from the source WIM and everything else is packages as an Application
  4. Be interesting to see which party ends up with the blame for this debacle... is it Sophos at fault or Microsoft I wonder. I guess no surprise given the 2019-04 update includes Spectre / Meltdown fixes, which trashed machines with Sophos AV first time around.
  5. Once you move to Office 365 ProPlus it changes every 6 months (or even more regularly if you're brave) so no point putting in the image at that point imo
  6. The beauty of thin image approach in MDT - deployment changes for 1809 took all of 5 minutes and so far looking good. Added the new OneDrive per-machine install to the TS as well, looking good so far. Using a different script to remove the apps in 1809 https://www.scconfigmgr.com/2018/11/27/remove-built-in-apps-for-windows-10-version-1809/
  7. Hallelujah! Someone at Microsoft seen sense at last. Now just need it added to WSUS for the client updates and we might actually have the product made the way it should've been done in the first place
  8. This is why I'm such a big fan of this forum, thanks @thatley for posting this Just had the same error appear on my WDS \ MDT after updating it to 8456 release \ 1809 ADK. Just remembered in the back of my mind this thread and looks like the workaround fixes it for me too. Saved chasing my tail blaming the MDT update for something caused by an OS patch!
  9. When the reports don't crash the box (even on the S14) I might have some faith in the product having moved on. Still waiting for the cloud reporting demo we were promised at BETT...
  10. 1809 is back on there today for me, downloading now
  11. I was hoping on 1809 being stable by now but it seems a bit of a cursed release, wonder if MS are beginning to give up on it and concentrate efforts on 19H1 instead?
  12. @free780 I had a response from the AAD Feedback team, pretty much mirrored the statement on the web page "Yes, this feature is on our roadmap and we are keen on making this integration happen"
  13. Has anyone got access to the 1809 ISO via VLSC? We only have 1709 and 1803 on ours
  14. Is anyone on here running Azure AD Connect with Passthrough Auth configured? We're looking to move off our Federated Identity service and go to Passthrough auth but need to check a few scenarios... if a user has "must change password at next logon" set in AD and logs in externally will this setting be honoured and handled neatly by the Azure AD sign in process? does Seamless SSO work with SharePoint sites? I know it doesn't with the Office 365 portal but our Intranet sits on SharePoint Online and that definitely needs to stay seamless SSO
  15. Just emailed them as we're big fans of AAD Application Proxy here
  16. Was going to turn this on last week then read it doesn't work with Azure AD Application Proxy, sort it out Microsoft [emoji58]
  17. Stability more than anything, you'd have more time to test the xx09 release before deploying, vs the xx03 release that would've barely been out a month or two. This happened to us with 1709 vs 1803. I'd done months of user acceptance testing with 1709 and was tempted at one point whether to take a punt on 1803. Common sense soon prevailed and I stuck with 1709, which I was very glad about when 1803 had issues with mapped drives initially whilst 1709 behaved exactly as it had in testing; nice and solid [emoji41]
  18. Yup, one script in MDT and get your GPOs tight to prevent any other consumer junk "experience" popping up. Pick a stable xx09 release and you're good for 30 months. I went with 1709 and it's been good for our 3000+ machines, only issue related to apps was high traffic due to Smoothwall not processing the proxy requests correctly (now fixed) Looking at testing 1809 with ProPlus instead of Office 2016 for our next round of summer reimaging as it stands. I don't know whether they've been ported into the latest LTSC but there were a lot of Windows Defender security features that came in with 1709 (EMET stuff from Win7 days) that you miss out on with the LTSB build so for that alone I stick with the Education build.
  19. We do similar with e-Safe and Impero. e-Safe analyse the logs for us and avoids the bulk of the false positives we get from Impero. However the latter does give some useful context with the screenshots and history logging so works well alongside. Downside to that is two costs for both solutions though. Senso did mention there's an option for a third party to do the log analysis so could be an option? Impero seem to have other Safeguarding packages too but there's too much marketing and product names to keep up with what actually does what.
  20. It seems we may need to update .NET from 4.7 to 4.7.2 on our Windows 10 1709 machines but having a bit of a head-scratcher with WSUS. If I go on the Microsoft KB page I see that the installer is KB4054530, available for all OS https://support.microsoft.com/en-gb/help/4054530/microsoft-net-framework-4-7-2-offline-installer-for-windows However in WSUS searching for that same KB article only lists it as available for Windows 7 for x64. Any ideas why it doesn't show up as a Win10 update, or in fact is the "Windows 7" update actually cross-OS as the Microsoft page suggests?
  21. Yup that was my thinking too
  22. Depending on how you time your deployment maybe not, 30 months support on the xx09 releases
  23. Education for us so we can use Files on Demand
  24. With Windows 10 and changing releases I've gone down the completely thin route so elements can be swapped out as and when required. Want to change from 1809 to 1903 build? Just switch the WIM. Want to switch from Office 2016 to Office 365 C2R... just switch the Application. The only bit that takes a while is the WSUS phase but again the Cumulative Updates are released monthly so unless you like changing the reference image regularly it doesn't seem worth the effort capturing \ updating it. Used the thin approach with Win10 Education 1709 on 3000+ devices, as long as your MDT and WSUS servers are up to task it'll be fine
  25. We're using Micro Focus ZENWorks, pretty good at the software deployment and patching side of things but not so clever at imaging (we use MDT for that)
×
×
  • Create New...