Jump to content

foofighterjim

Members
  • Posts

    1,672
  • Joined

Everything posted by foofighterjim

  1. No, it had been working fine this morning (GMT) but I had a laptop fail during a Fresh Start about 2 hours ago.
  2. Dell, I do have some HPs to do this afternoon though!
  3. I am getting the same problem but with a different error code (0x800705b4). Has been working fine all morning, so MS may not be aware / updated their status page yet.
  4. It used to actively drop the connection, it would not resolve anything without the correct proxy information.
  5. Turns out that the Transparent connection policy on the .49 address needed to be enabled and HTTPS filtering needed to be on. This still doesn't drop the connection like the old appliance was but at least the content is filtered, it gives me something to work with at least.
  6. Hop 1: Core switch Hop 2: Smoothwalls IP on that VLAN. Hop 3: Public IP Then eventually to Google.
  7. Gateway for the guest VLAN is 10.122.203.1 (the core switch), this is because we are not using the Smoothwall for DHCP of this VLAN. As mentioned, the unfiltered transparent issue is not isolated to this VLAN, it is happening on all VLANS with the exception of the BYOD.
  8. An interesting thought, the main IP of the Smoothwall is the .49 address, this was originally different whilst I was running the old Smoothwall at the same time and copying settings. Unfortunately modifying the .49 policy, saving and restarting hasn't changed anything, I am still completely unfiltered without a proxy on any VLAN. Our core switch is the Gateway for the clients on the Guest SSID.
  9. This is what we have for Transparent proxy: The BYOD setup is working fine, but the Guest VLAN is not being filtered despite directing to a group for no auth and then having a rule in guardian for that location and group.
  10. We upgraded from an older S8 appliance to a new S10 back in May, in my infinite wisdom I decided not to do a backup and restore but only copy the settings that were still relevant (we had a number of things setup that were not needed anymore). I have just discovered that our Smoothwall is not filtering in the manner I would expect, for instance; on our Domain DHCP location we use a non-transparent connection and this is working correctly, when removing the proxy settings however, the connection is completely unfiltered, previously the Smoothwall would have refused the request without the proxy information. I have also tried to configure our Guest SSID VLAN to take our standard staff level filtering but this too is bypassing the filtering altogether. I obviously have something fairly fundamental set incorrectly somewhere, I just don't know where. I have had a support call open for this for a few days but no sign of them investigating so far. I've even called and not been able to get through this morning, and I need to resolve the issue by this evening. If anyone has any ideas on things I could check it would be greatly appreciated.
  11. It was the cleanest / simplest way to set the profile retentions and also gives a "clean" login window on each boot i.e. not always showing and defaulting to the last logged on user. I'm sure the settings are also somewhere in the Administrative Templates section; that said, who knows when MS is concerned.
  12. I actually have our policy to only delete the profile after 60 days or when the local drive hits 75% full, not sure if this is actually happening or not at this point though (least of my worries right now). I think I might need to reset the device as OneDrive is now automatically signing in, but I'm not sure if this is because I had previously started it manually from that account or if it is because the policy is now working. Can't help but feel that this would be much easier on a Chromebook (he says, having never even used one).
  13. Just looking for a bit of a sanity check and advice on this one. I have a requirement to run software that we can only deploy via Intune (Windows App), none of our domain computers are currently Azure AD joined and even if they were the software has Bluetooth requirements that our domain computers do not meet. I have some leftover DfE laptops (Dell 3190s) that would work spec wise. I thought it best to approach this as an Intune project rather than worrying about joining the domain and ADD with potentially conflicting policies. I am fairly familiar with Intune, having spent some time getting it setup for student loan devices; unfortunately, because of this, all policies need to be device based. So far I have: Enrolled a laptop into Intune. Set it up as a shared device as multiple students will be using it. Successfully deployed the required software. Now here lies the problem, I believe marking it as a shared device is causing issues as ideally I need to enable OneDrive and known folder move to allow students to easily save their work. I have this working flawlessly with our loan devices, but they are not marked as shared devices as they are 1:1. Initially marking as a shared device hid everything except the downloads folder, which means that unless using apps with OneDrive integration the students would not be able to save their work (not sure why MS thought doing this was a good idea), I have relaxed this so users can now see the local documents and drives knowing that I should be able to sort the risks of that out with AppLocker, but I can't get OneDrive and KFM to kick in. I have read a few things where creating a custom policy with the following entries should enable it, and OneDrive does now work when manually run: ./Device/Vendor/MSFT/Policy/Config/System/DisableOneDriveFileSync (Integer = 0) ./Device/Vendor/MSFT/Policy/Config/ControlPolicyConflict/MDMWinsOverGP (Integer = 1) I'm just not sure how to get it to run automatically on login like the loan laptops do.
  14. If you would rather a hosted solution (thinking long term), I can recommend Yodeck.
  15. I'm looking at the iPhone 11 or 12 mini as they've had good price reductions now, leaning towards the 12 mini simply for the 5G. In either event, it'll be some upgrade on my Pixel 2!
  16. I haven't tested this with the built in applications but have successfully removed desktop shortcuts from 3rd party software, you could try creating a GPO to remove the shortcut at user level: User Config> Windows Settings> Shortcuts Create a shortcut with the following: Action: Delete Name: Target Type: File System Object Location: Start Menu Make sure the name is identical to the link you want to remove.
  17. To be honest, I'm dreading it. After a high pressured year and barely having any time off, we've just had a steaming pile of **** landed on us at the last minute. Any hopes of enjoying my time off this summer are now gone because I'll be worrying of how we will get so much work done in such a short space of time. Why leave it so late when they must have known this weeks ago, I'm done with bailing others out of the muck.
  18. I may be misunderstanding the setup, but with Aerohive, authentication happens at the AP, so each AP needs to be added as an authorised RADIUS Client.
  19. Start here: https://get-help-with-tech.education.gov.uk/devices/replace-a-faulty-device Just had to report a fault of my own.
  20. Probably a very dumb question, do we need to follow the reset procedure if we are going to re-image them? We had some Lenovo 100e devices in our first batch and the factory reset installs a load of bloatware including a McAfee trial. I can remove this as part of an Autopilot deployment but it adds around 20 minutes to the deployment. My thoughts were to just install the consumer version of Windows 10 over the top (hopefully it will activate the license) and just Autopilot from there.
  21. It wouldn't surprise me if they ditched traditional GPOs for this and go purely for Intune management. If they do continue with GPOs, they should do it properly, rather than the half job that was the early releases of Windows 10. Even now, you can't help but feel the GPOs are lacking in some areas (the bodge that was the new News & Interest widget in the taskbar springs to mind).
  22. I have actually seen 1:1 schemes (including parental contribution) with these as one of the device options.
  23. With current concerns regarding security considered, I think I would want a very detailed argument as to why they would need this. I don't see why they would need GA, if they need to manage subscriptions I believe there are built-in security groups for that in O365.
  24. A warning to those on 1909 or later, this months CU has introduced a news and interests widget on the taskbar. At first glance I thought it was just a weather widget, but on closer inspection it also had links to news articles that you would not desire to be front and centre in an educational establishment. A quick google returned: https://techcommunity.microsoft.com/t5/windows-it-pro-blog/group-configuration-news-and-interests-on-the-windows-taskbar/ba-p/2281005 TLDR; go to: Computer Configuration > Administrative Templates > Windows Components > News and interests > Enable news and interests on the taskbar The ADMX templates have been updated for 20H2, earlier releases will need to obtain the Feeds.admx once the update has downloaded.
×
×
  • Create New...