Jump to content

Gongalong

Members
  • Posts

    2,568
  • Joined

  • Last visited

Everything posted by Gongalong

  1. That virtual volume control looks perfect. Just something that means I'm not having to use laptop hotkeys. Thanks!
  2. Hi folks, When we have PowerPoint presentations in our main hall it would be really helpful to have a fader style controller for Windows master volume. This would give us much quicker control over the master volume for slides with videos and music compared with trying to use laptop hotkeys. Does such a thing exist, or is there a really simple (but good quality) mixer with a master volume control that is a fader? Thanks
  3. Hi Folks, I need to update the Photos app on our Win 10 classroom PCs so it includes the new Video Editor. We remove the Microsoft Store app from our classroom PCs when they’re built so there’s no direct way of doing it as far as I can see. I think Store apps can be deployed with MEMCM, so that’s my next port of call, although it looks tortuous. Just wondering if anyone has come across an alternative/easier way of updating an installed app when the Store app isn’t present? Thanks
  4. Hi folks, We are looking at computer classroom layouts as we’re having a room converted over. We have always gone with benching and computers around the perimeter, and normal tables and chairs in the centre of the room. Good in terms of flexibility, but the rooms get very full. We are looking at other options for this room e.g. rows of tables with computers on (which is a little easier to get power and network to), or pods (more difficult to get power and network to). What do other schools have, and how have you found the layout from usage terms? Thanks
  5. Hi folks, I have enabled Modern Authentication, as I did not realise it was off for our tenancy. I now want to improve security, and turn off any unnecessary basic authentication protocols. We have clients that use the following: Outlook Web App Outlook 2016 and newer Outlook App on iOS and Android Can I turn off all basic authentication protocols, or should I leave any of them switched on for the above to work? If I turn off the basic authentication protocols will it require staff to delete and recreate their account in the Outlook Desktop App and smartphone apps? Thanks
  6. How many of the basic auth protocols should be switched off? There's a fair few: Outlook client = I'm guessing this is a bad idea if we've got users with the desktop app Exchange ActiveSync (EAS) = no idea Autodiscover = I'm guessing this is also a bad idea if we have desktop app users IMAP4 = I'm guessing this should be off POP3 = Ditto for this Authenticated SMTP = I'm guessing this is less of an issue as it's more for sending emails, albeit could be used to hijack and spam Exchange Online PowerShell = I'm guessing this is best left alone
  7. Yes, as part of the tinkering I've created a conditional access policy (and I've now enabled modern authentication). It prompts when using the Outlook web app, but I don't get any prompt with the desktop app. I can imagine it would be a right pain with the latter depending when it prompts, if it can be configured to prompt?
  8. Mostly Office 365 apps here. The Outlook app seems fine now, but there doesn't seem to be any MFA as part of its setup which surprises me. So if someone has my credentials they can just setup Outlook and access email?
  9. Should have googled. Looks like I have to turn on Modern Auth in 365 admin, then remove any stored passwords in credential manager, and potentially recreate the Outlook profile. Not working yet, but I'm guessing enabling the setting in 365 might require time to take effect.
  10. Hi folks, I'm tinkering with enabling Azure MFA, following the guide here https://docs.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa So far the only problem I've noticed is that it seems to cause an issue with the Outlook desktop app. Some minutes/hours after enabling the desktop app starts prompting for a password. I don't get any two factor request in the authenticator app, and despite entering the correct password it just keeps popping up the same request. Anyone else come across this? Thanks
  11. I've involved our thirdline support, as it's beyond my skillset at this point. A mistake I made was rebooting two DCs with the same role at the same time - I've gotten lazy, and I won't do that again. Thirdline have managed to recover one of the root DCs, it did the thing of rolling back Windows Updates so clearly something had gone awry there. Initially it wouldn't launch directory services, but after a couple of reboots it revived. Thirdline are building an extra root DC for the moment just so we have some additional recovery if it recurs. Stressful!
  12. It only seems to be DCs in my case. I'm sure other servers had the update without issue. This is different to the January boot loop issue as these servers don't even seem to be booting. Whether it's just a local issue here...
  13. Looks like it was two April updates that I reckon are new today: 2022-04 Cumulative Update for Windows Server 2019 (1809) for x64-based System (KB5012647) 2022-04 Cumulative Update for .NET Framework 3.5, 4.7.2 and 4.8 for Windows Server 2019 for x64 (KB5012328) It looks like it's actually four of the six DCs that won't boot. Of the two that are working, one is pending the restart (which I won't do!) and the other seems to have installed the updates and rebooted. Not sure what to do, whether I try and restore one from Veeam from last night's backup. These are VMs on two different Hyper-V setups, so it doesn't seem to be something peculiar to one host server.
  14. Hi folks, Just running through some servers and updating, and three of our six 2019 DCs are stuck at boot. These are all VMs on Hyper-V. Two are stuck at a black screen with the spinning white wheel, and the third is stuck at "Applying computer settings". Is there a bad update out there?
  15. Thanks both, it seems to be working. It's a bit janky, in that my alternative redirected start menu and desktop aren't taking effect, but the usual redirected start menu and desktop aren't taking effect either and that's the key thing as it relies on being on the LAN. The Smoothwall cloud filtering has been tested, and that's still working, which is a key part of it. Will test anyway with the students that are taking the laptops...
  16. Definitely sounds like it, I'll try that. Thanks! I'm doubting myself now. If a GPO is linked to an OU then it applies to any device/user in that OU, right? Otherwise would seem a bit pointless linking them to OUs!
  17. There won't be a vast number, but as I'm adding them to a group anyway presumably I can deny the group? Although I still need the other GPO to apply. Weird request!
  18. Actually, both GPOs apply to Authenticated Users. The second GPO is also set to apply to a group of on-site PCs. I'm going to try putting the home laptops in their own security group, then add that to the scope of the first GPO. Not sure what else to try other than that.
  19. Hi folks, I have some domain joined laptops that I need students to be able to take home. We have a GPO that's at the level of the user OU that applies a fixed start menu based on a scope of authenticated users - that start menu is located on a domain share, so it's no use to the students that take the laptops home. The laptops being taken home are in their own OU, and have some settings applied for Smoothwall cloud filtering. As part of the GPO applying in that folder there's a setting to change where the start menu is located, but the issue is I think that the above GPO applies *after* the home laptop OU because it's based on authenticated user. Is it possible to get the second GPO to apply after the first, even though they're in separate unconnected OUs? Thanks
  20. For those who've not seen it: Windows 11: Microsoft approves desktop watermark for unsupported PCs
  21. It could well be a profit driven thing as well. Microsoft can't seem to make their mind up about charging for upgrades, so if they force hardware changes the manufacturers have to pay them to put it on the new machines. Not that I'm trying to excuse it
  22. We'd had some E10-G-101's previously and I remembered those being straightforward. Also glad it was something simple as I've got around 20 to setup
  23. Or why you shouldn't let Marketing run your company, which unfortunately happens all to often.
  24. It transpires I was being an idiot and was trying to deploy after the deployment had expired. Now that it’s valid all is fine and it’s PXE-ing
  25. Hi Folks, Has anyone had any success getting the Dynabook E10-S-10Q mini laptops from the DfE to PXE boot? The BIOS suggests they’re capable, but they don’t seem to detect the cable is present. I’ve tried with a USB to network adapter, and that doesn’t work either. They don’t seem to play nicely with the boot image on a USB stick either as they start up the PE environment and then eventually just reboot (I’m guessing drivers). I’d really rather not have to build them from a memory stick… Thanks
×
×
  • Create New...