-
Posts
3,895 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by gshaw
-
Don't know if they've ported the following into the new LTSC release but these come in with 1709 and above... Windows Defender Exploit Protection OneDrive Files on Demand Not sure what the status of things like Azure Hybrid AD Join and suchlike are like if you got down LTSC but as above more relevant if you're fully integrated with Office 365.
-
Still a customer whether you pay for the service or not
-
Amount of time is irrelevant, deleting users' existing data isn't an acceptable way to run a cloud service. As Arthur mentions above Google took a much more sensible stance when making their changes for example.
-
Any version before 1607, definitely Any version after 1709 (so far), pretty much Any version without the default crud cleaned out, definitely With some time and effort and optimal GPOs, scripts etc. it is a good base OS and faster \ more secure than Windows 7. Frustrating really, there's a really good product in there but some very silly decisions at MS are dragging it through the mire. Simple steps to getting back trust in the market... remove the intrusive tracking \ telemetry go to a single release per year, which would've been beta tested for 6 months after the xx03 release first previews new features remove all the bundled crud from anything other than Home editions reinstate internal QA teams to ensure Cumulative Updates are of sufficient quality for release I think MS have partially started the climbdown by extending the support periods for 1709 etc. which seems to be an admission that the release schedule is too fast for businesses to keep up with. Perhaps just about stage managing it now?
-
Basically with 10 you do have to break away from a lot of what you've done previously and look for new solutions to problems that didn't previously exist. For example the removing apps script, disabling telemetry & consumer experiences, deploying from an unaltered base WIM rather than a modified one (granted some people are working OK with their own captures but it seems very hit and miss depending on what you do during that manual sysprep stage) You also have to drop stuff like roaming profiles and either go local profiles or UE-V otherwise experience a world of pain. The rate of change is faster but the concepts updating isn't that much different from going from XP to 7 all those years ago. What is proving problematic is this constant break-fix-break again attitude to Windows Updates. What worked one day might not tomorrow off the back of a Cumulative Update you can't control (and can't really avoid deploying either due to the constant churn on security exploits these days). Have to say unless MS get their act together on the QA front they'll end up handing the market to Google.
-
The regression bugs are definitely a thing, the recent case of disappearing printers confirms as much as with 1709 we had no issues early on in term but after the last Cumulative Update it started happening. It's a shame the QA is so poor as the base OS itself is actually good (much faster than 7) and some of the new features in the security and cloud integration (OneDrive) areas are big improvements. However the twice-yearly updates are too much and MS can't seem to keep up with the releases in terms of supplying a quality product within a 6-month window. Under Nadella MS are purely looking at Azure now, on Windows side their strategy seems to be to take over the entire ecosystem in a direct-supply model via Microsoft Managed Desktop aka "we supply the device, we supply the install and config and we supply the end-user delivery. You supply the money"
-
Regardless of who bought what, when and why it comes down to this... user signs up to a service under particular terms e.g. 1TB storage user stores data they value in the service, under the impression it's safe company gets bought out \ decides to cash grab company retrospectively changes the original terms company deletes data If they'd grandfathered the 1TB users and just stopped offering the service to new sign-ups that's fine, however going in and deleting people's data definitely isn't. It's similar to what Photobucket did, destroying years of content on forums (although admittedly Photobucket were worse as they didn't offer a grace period). Either way Flickr goes on my blacklist of sites I'll actively avoid and advise others to do the same from here on.
-
Sorry @abaxter2 one more question, does the Seamless SSO work OK in the latest version of Chrome? Just reading through the conversion documentation and found a few posts online about Chrome, just wanted to check if that's working OK now.
-
They'd never dare to it to businesses but in the consumer game trusting any one provider is really risky imo. Multiple copies on multiple providers and an olde-worlde local HDD backup seems to be the only way to have faith your data won't be sent away with the fairies at some point.
-
Changing the terms of the deal for existing customers and then deleting their data is poor form, regardless of whether you get notice about it or not. Seems standard form by consumer cloud providers to treat their customers with contempt. Microsoft tried to do the same with OneDrive cutting free storage for long-term users - in the end they relented after the backlash but it shows how little regard and value is placed on consumer data.
-
The portrayal of this Doctor's personality thus far comes across like she doesn't seem to know quite what she's doing. For an episode or two it's the usual regeneration effect but by now it comes across more like a lack of self-confidence and knowledge. Maybe that's a character growth thing that'll get resolved later in the series but doesn't really do JW many favours imo.
-
@tri_94 which bit in particular? On Computer Settings I configure these... BitLocker encryption to AES 256-bit only our organisation ID allowed (bit controversial but ensures we can recover any encrypted sticks) Store recovery passwords and key packages in AD configure DRA certificate and assign to policy On the User side it's all GPP registry settings using the keys I posted on the previous page. RDVConfigureBDE RDVAllowBDE RDVDenyCrossOrg RDVDenyWriteAccess The way I do it differently is just one group called BitLocker-Enforce and inside that I put any groups I want to have it enabled for e.g. Staff. The GPP sets those keys either to 1 if a member of the BitLocker-Enforce group or 0 if not. That way BitLocker is configured at each login to make sure it's correct for the current user.
-
Sounds like it's worth us migrating, especially now we have Azure AD Premium the password write-back sits nicely in with the AAD Connect side Is your installation configured for "Seamless single sign-on" in Azure AD Connect?
-
@mcolbourn check out the parallel thread on this http://www.edugeek.net/forums/windows-10/191185-disappearing-printers.html
-
Knew that was coming as soon as they were taken over, glad I never used it as a backup location now. Again shows the dark side of the cloud, your data becomes almost transient to some of these providers, who think nothing of deleting it as soon as it becomes an inconvenience to them
-
350 here, mainly because we have one GPO per room (lots of rooms!) for Deployed Printers. Also got some LanSchool per-room GPOs that can be deleted now we've moved to Impero so that will reduce the number to under 200. Generally it's about 5 GPOs that apply to any given machine; a Base plus some specific ones for WSUS (per site), BitLocker etc. Similar for per-user, a Base policy plus some specific ones for Staff \ Students, Folder Redirection and so on. As per above making sure it's lean and mean is better than just number of objects.
-
@DaveP feel free to send one my way
-
Interesting, so if you try the following does it work? find a SharePoint site on your Office 365 copy link to a desktop shortcut open link into browser Just to confirm you get no email address prompts at all and the first thing you see is the site? In which case AAD Connect with the Hybrid Join must've improved and removed that additional step where it used to ask for your username, then signed in with SSO (i.e. no password required)
-
@abaxter thanks for the confirmation, that does seem the only way to achieve a seamless experience but we'd have to change our SSO provider from our existing Centrify SaaS IdP to Azure AD Connect to do it as Hybrid Join only seems to be supported when using Microsoft-only identity products. I think that would mean losing ADFS Smart Links functionality, which we use to open up our SharePoint Intranet without username prompts so what I gain with one hand I lose with the other... unless I then go to Azure AD Connect + ADFS (which then means I need to put some of the ADFS in Azure for high availability)... arrgh! We have the Education Store configured at present and restrict it to organisation-only apps, that element works well (apart from it sending emails when new apps are assigned which look remarkably like phishing emails!)
-
I've got a 3-pronged attack for this now... GPO deployed printers VBS script to re-map and set default user-launchable script Bundle to restart print spooler and run mapping script again If the GPO doesn't get it, the VBScript should and if all of that somehow fails then the user can double-click a shortcut to restart spooler service (seems to bring GPO deployed printers down if missing) and if that still doesn't do it re-run the script again The script I've knocked together looks at AD Sites and OUs to cycle through the PC location as quickly as it can then uses normal VBScript mapping method Select Case strComputerOU Case "ROOM1" objNetwork.AddWindowsPrinterConnection "\\printserver\ROOM1-COL" objNetwork.SetDefaultPrinter "\\printserver\ROOM1-COL" @KK20 are you setting the scripts as Login Scripts in GPO? Also try Administrative Templates > System > Logon > Run these programs at user logon as that will only execute once the desktop appears, rather than the somewhat random behaviour of when Login scripts run depending on synchronous \ asynchronous processing etc.
-
Quoting my past self as a correction - turns out it's possibly to deploy UWP apps with DISM, which can be used via any deployment method
-
I'm currently trying to deploy Microsoft Whiteboard across our Smartboard PCs (and then perhaps other devices) so we can trial the collaborative whiteboard feature. So far I've cracked these bits... sign up with Windows Store for Education enable Offline downloads obtain AppX package for Whiteboard deploy to all users on a machine using DISM However when a user opens up the app it doesn't perform any SSO, contrary to everything else on Windows 10 \ Office 365 that federates via our Centrify (similar to ADFS) system. Users get asked for their account, which then signs in and prompts this rather strange message As far as I can tell from running dsregcmd /status saying Yes here triggers a User Workplace Join, the benefits \ drawbacks of which I'm uncertain of on a domained PC. We aren't yet using Hybrid Domain Join yet, which I believe may be the only way to get true SSO with the Store apps (well done MS ) but has anyone tried the above and got it to work smoothly?
-
Glad I'm not going mad! Currently trying adding an extra line to our set default printer script to map the printer first so if it doesn't already exist from the GPO it gets mapped by VBscript instead. Seems to be giving some strange results on my machine but trying on some classroom machines for a better test.
-
Just as a heads-up the disappearing printer issue seems to have started rearing its ugly head in places for us too now, even with the GPO deployment. All was fine until the past week or two so I'm suspecting Microsoft may have bugged it again in the last Cumulative Update
