Jump to content

Gongalong

Members
  • Posts

    2,568
  • Joined

  • Last visited

Everything posted by Gongalong

  1. There are some user defined groups there already, but none show in SMHW, so I'm guessing it needs class groups.
  2. What do you all use for an SMTP server? Would we be safe to use the server given to us by VMB?
  3. That's concerning. I can't see on the SIMS sync app what it's doing in terms of sync, and I don't seem to be able to trigger a sync. We use Schoolcomms and Parents Evening System atm, and although it doesn't sync up as much as Edulink does, these take a minute to sync up, if that. I wonder why Edulink takes so long?
  4. Hi folks, I'm trying to create a class group of all students in a year group so we can have that group appear in Show My Homework. Our SIMS admin says that the class groups have to be created in the timetabling software (Nova) and cannot be created in SIMS itself. Just checking if there are any SIMS gurus out there who know if that's correct? Is there absolutely no way just to use SIMS to create a class group? Thanks
  5. I went ahead anyway, went into Disk Utility, and deleted the two partitions that were there. I didn't delete the System Image partition, but have chosen to install fresh from the Internet. It then wouldn't show me a partition to install to, so I had to go back to the Disk Utility and create a partition to install to. Not exactly intuitive, but it seems to be installing now...
  6. If I choose option 1 from here, does it give the option to format? https://support.apple.com/en-gb/guide/mac-help/mchlp1599/mac
  7. Got binding to work. AD accounts seem to be a bit flakey - will not login at first (gives the shake), but will then login on a second attempt. I've now got an issue when logging in where it gives an error "A keychain cannot be found to store "BeaconStoreKey"." and the login won't progress past this. I'm asking Jamf if it's best just to flatten this test iMac and start again, as it hasn't been reinstalled since it was bought late 2013.
  8. I've tried binding it manually to see if that allows the profile to carry on. Despite that though I can't logon with an AD account. I put in the details, the wheel spins below for a few seconds, then stops. No login, no error.
  9. It has Catalina. Jamf were unhelpful. Just said that the error is created by the Mac, and we need to speak to Apple!
  10. Trying the bind and getting an error (The ‘Directory Binding Account’ payload could not be installed. Attempts to bind to the server ‘redacted.redacted.redacted.local’ returned an unspecified problem.) I've logged it with Jamf support...
  11. And then everyone moves to the company and they explode due to number of customers
  12. I'm amazed it doesn't need the CA role. Thanks Arthur, that's really helpful!
  13. Does this still need the Certificate Authority role on the server to setup? The US$64M question is whether it will generate a certificate with both a public address and a .local SAN.
  14. @Brimstone Thanks, very useful! Then that suggests we're stuffed as far as using LDAP. I'll ping Jamf Support an email and see what they have to say. I kept hearing bad things about binding to AD, that it was unreliable. But obviously not your experience? Is still possible with this to map network drives, much as with Windows? We've only been trialling a couple of months, so not sure. I'll only need to deploy Logic Pro, which we're buying with VPP credits.
  15. It can use Azure, but we federate Office 365 with RM Unify so can't use it. Other options are Google (which we don't use) and SOMToday (no idea, and Google isn't finding much).
  16. Certainly looked at something very similar, linked within Jamf's config page. The guide is a little out of date as Jamf only allow LDAPS, you can't use LDAP anymore. We just can't get the certificate bit sorted out on the DC, which needs to talk to Jamf. They talk about using the Certificate Authority role, which we can't get to work, but even then we've been advised that a bought certificate still needs to have a public facing name and .local name which you cannot do.
  17. It's a cert for Jamf School to talk to LDAPS on our DC. Apparently it needs both the .local name and the public facing name. Proving very difficult to setup, but Jamf can't give any guidance other than an old Microsoft document.
  18. Hi Folks, Is there anyone out there using MDM with Apple iMacs that isn’t using Jamf School/Zuludesk? We are really struggling to get LDAPS set up with it, and although I haven't given up yet it would be helpful to know what alternatives are out there. Basically all we need from MDM is: - It uses our AD accounts to logon to the iMac. - It can map drives to a Windows server. - if it can map a Windows printer and deploy software, even better. We’re only buying 16 iMacs, so won’t have vast numbers. Any recommendations? Thanks
  19. @3s-gtech The common name will be publicly accessible (albeit locked down to certain IPs within the firewall), but the certificate needs a local name as well for the certificate to work with the DC. This is trying to setup Jamf School (cloud based Apple device management system) to talk to our DC. I asked elsewhere and it seems that no cerfiticate companies will offer with a .local domain as well https://cabforum.org/internal-names/ We did initially try to get the Certificate Authority role up and running on the server, but that was so problematic we switched to buying a certificate. This is proving a nightmare to setup!
  20. Hi folks, We’re trying to get LDAPS setup here, and need a certificate with a common name and a subject alternative name (.local domain). Can anyone recommend a straightforward company that can supply this? I’ve checked with GoDaddy and they seem confused that it’s for a server rather than a website, which I didn’t think boded well! Thanks
  21. Hi folks, Curious to know if there are any particularly easily repaired PCs out there. We've got great mileage out of our Very PCs, particularly with the Broadleaf Max case, and they may still be the option going forward (if still available!). But are there other cases out there that are rugged, and particularly have easy to replace front panel connectors? Aside from damage to the case it's the front panel connectors that wear out first. Or has anyone used a different strategy to prevent wear and tear to their PC connectors? TIA
  22. We're using O365 PP, and it's the extra faff of having to sign into RM Unify to get the license. We did warn staff and treated it as a bit of an experiment, and it would help if staff stick to seating plans, but... Not a done deal yet though, just R&D. My understanding is that O365 PP will license automatically if we're going direct to Azure.
  23. I've had a quick read of this https://www.itpromentor.com/soft-vs-hard-match/ Currently we don't use the email address field in the AD record, although that should be easy to populate with that used on O365. We don't use the domain suffix on AD either. Not sure how critical that is?
  24. RM have a couple of tech docs. We have to uninstall the RM sync tool and Groupcall job. We also need to remove federation, otherwise once Unify stops talking to Office 365 it will start deleting accounts. RM won't support us after that point. I'm completely new to the Azure side, so I'm assuming AADConnect is the Microsoft equivalent of RM Unify AD Sync. How does soft match work?
  25. After the Autumn update documentation was still broken, so support told us to run the "Extract" function in SOLUS3 to create an extracted installer. We then ran SIMSCentralServerSetup.exe and that fixed the documentation issue.
×
×
  • Create New...