Jump to content

smarties11

Members
  • Posts

    645
  • Joined

  • Last visited

Everything posted by smarties11

  1. Cheers Danny - that looks spot on. I'll check it out!
  2. Hi All, Trying to get my head around how to install a fully updated copy of Office 2016, from scratch? I'm deploying Windows 10 at the moment and want Office 2016 to be fully up to date at first install (via SCCM) rather than having to rely on WSUS/SCCM to update after the first install. I've read the various articles about placing the .msp files in the \updates folder of the installation, however getting these .msp files doesn't appear to be easy. I've found this https://docs.microsoft.com/en-us/officeupdates/msp-files-office-2016, an official list of .msp files that have been updated since Office 2016 was released - however I'm not sure how to read the table? There are three columns with applicable KB links to downloads - Non-security, Security and superseded. The problem is, when you download these files and extract them, the .msp files inside all have the same names! So for example, looking at access-x-none there are three downloads - Non-security (02/01/18), security (10/07/18) and security superseded (non-dated). Assume we can ignore the security superseded, but what about the other two? Does the security release include non-security fixes, and vice versa? Sometimes the security release is newer than the non-security and vice versa. I've read about getting an installation on a dummy machine up to date using Windows update, and then using some vbscript to suck out the .msp files but I can't get windows update to pull in Office updates on Windows 10. If I go in to advanced settings on windows updates and tick the option to download updates for other MS software, that setting just unsets itself when I check for updates! And I can't check for updates from within an Office app as we are running a volume licenced version so there is no option to do so! Any ideas?! Thanks!
  3. We had an install done over the summer by GBSG. They did a decent job. They've used HIKVISION kit and the quality is great. I wasn't involved in procurement, only the technical bits where required - but I understand the cost was around 12K for 25 cameras (4 external) and an 16TB NVR.
  4. Hi All, Have got our first IT suite set up here with Windows 10 (1803). All working beautifully so far except for one thing! I have set up ZeroConfigExchange, and in testing this worked perfectly. However, in the real world, there are some users that this doesn't work for. When opening Outlook 2016, they are prompted for their username and password, and on entering it the credentials are rejected. Outlook then quits. It's happening to around 10% of our users, and I cannot see a pattern. It moves with them, it doesn't matter which computer they use - the problem is always there. If an unaffected user logs on to the same computer afterwards, it works fine for them. I'm thinking it must be mailbox configuration, however when comparing a working mailbox to a non-working one, I cannot see any differences. Our accounts and mailboxes are created in bulk at the same time (in the past for our older users this was done with active user manager etc, in recent years with Salamander). I'm scratching my head and can't see anything online. Has anyone else come across this? Thanks! EDIT: Just to add that we use exactly the same method on our Windows 7 machines, which works fine for everyone!
  5. Hi, I realise this an ancient thread for an ancient bit of software, but.....we can't afford to buy the latest version so we are still using CS4 here and I've been working on incorporating it into our latest SCCM CB and Windows 10 1803 deployment. So I'm posting my findings here should anyone else find themselves in the same boat as us and without any solutions available online... After several days wrestling with this I'm pleased to say it is possible to deploy this through and SCCM OSD task sequenece! The steps are.... 1. Create a customised install using the Creative Suite 4 Deployment Toolkit (currently available here http://download.macromedia.com/pub/developer/creativesuite/ADBECSDT1_Mul.exe). You input your serial number and then select all of the options you require. This will create four files - AdobeUberInstaller.exe, AdobeUberUninstaller.exe and their respective XMLs. 2. Create a share on a server somewhere and in it, put your original installation files. Ensure full control permissions for all on the share itself. Also copy the 4 files created in step 1 to the root of this share 3. Ensure the permissions on the folder itself has read permissions set for the 'everyone' group (I tried giving permission to just the SCCM Network Access account and then running the command in step 4 using this account but it failed...) - obviously you can hide the share by putting a dollar on the end of your share name 4. In your SCCM task sequence, create a 'run command line' step. The command line needs to point to the UNC location of your AdobeUberInstaller.exe file, e.g. \\server\CS4$\AdobeUberInstaller.exe. The 'start in' field needs to point to the UNC path, e.g. \\server\CS4$\ 5. !!IMPORTANT!! ensure that on your command line step, tick 'continue on error' on the options tab. This is critical, because under Windows 10 the installation always completes 'with errors'. The Flash element says it has failed to install but has installed successfully. You could find the exit code for the error (for us it was 6) and then include this as a success code but easier all round to 'continue on error' and then just verify installation was successful manually post OSD That's it - for some reason if you do the same steps as above but incorporated into an SCCM software application or package it fails. Hopefully this helps someone - just need to figure out the updates now....
  6. One thing to bear in mind is that if no one in your postcode has previously ordered fibre, then the speed estimates are just that - they are not based on real world data. We also live in a tiny village. We are 1.5 miles away from our cabinet which was FTTC enabled a few years ago. Our predicted fibre speed was 6mb, and we were currently getting 3mb on ADSL. No one in our postcode had bothered to upgrade to FTTC and in fact at the time, only TalkTalk would even let us do it as most other providers would only supply a VDSL connection if the predicted speed was 15mb+. Anyway, we risked it and our initial sync speed was 22mb! This settled down to around 18mb during the training phase and has remained so since. Shortly after, the predicted speed for our postcode increased in line with our actual speeds and then all the neighbours upgraded too! I think the Vodafone rep is talking tripe. Online it says they offer 15% discount off your bill if your sync speed drops below 25mb, until they fix it. There's no way on this earth they are going to fund a new cabinet to solve that for you, and I bet there's small print to say that the predicted speed must be greater than 25mb in the first place! Have you tried inputting your details into the openreach checker at https://www.btwholesale.com/includes/adsl/adsl.htm?s_cid=ws_furls_adslchecker? Often the broadband companies quote less than openreach to cover themselves. Make sure you use either the phone number or address checker options - postcode search won't give accurate results for fibre. HTH
  7. Where does it stop? It stops here, with this unprecedented situation that covers data which we didn't want to collect in the first place, that many parents objected to, that has seen scandal in the media, but we were required to do so by the DfE, but are no longer required to collect. Each to their own - we're deleting it and guaranteeing it won't bite us in the future - if you wish to take that risk with your school then that's your call!
  8. Personally I say it is safer for it to be removed completely. If you don't, and then lets say it appears on the data collection form, you are then asking parents to check and confirm a piece of data you are holding without a legal basis or consent. You don't need this data to provide an education service to the pupil, and you'd have a hard time justify why you are retaining this data to an angry parent or the ICO. It was controversial when it was brought in, suspicions were raised that this data was being shared with the home office so the chances of a parent being annoyed at this data being retained are quite high.
  9. Three things to check and ensure are in place... On the proxy settings page in IE make sure that the "automatically detect settings" check box is NOT ticked In your proxy exceptions, ensure that your exchange server is covered by an exception. Either by having a *.domain.com wildcard value in there or by manually specifying exchangeserver.domain.com Ensure autodiscover is set up correctly in Exchange and DNS (should be in your case if it is allowing you to set up the mailbox profile in Outlook) Both of these can be rolled out by GPO
  10. Hi All, Now the DfE have published the technical guidance for the 2018-19 census runs (https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/720748/2018-19_School_Census_Business_and_Technical_Specifications_Version-v1.1.pdf), it confirms the removal of Proficiency in English, Pupil Nationality and Pupil Country of Birth data collection items, in line with their u-turn on this earlier in the year Under GDPR, we will no longer have a legal basis to collect this data; so we would either need to ask for consent from parents to continue to hold it - or delete the data. As it isn't critical to their education we will be deleting it. It is possible to remove COB and PIE using bulk update (for current students only) but there is no bulk update routine I can see to remove pupil nationality, nor is there any easy way to remove this data for leavers or pre-admissions? Any ideas? Perhaps SIMS will provide this facility in the next update? @PhilNeal? Thanks!
  11. We use the SIMS admission number including the leading zeros. Moved to this system 14 years ago when I started after inheriting a system that was based on year of entry and initials. Works well and you'll never have any duplicates! EDIT: to aid students remembering their numbers initially, we ask them to write them in their planners at the beginning of Y7
  12. Haha, no worries at all - pleased to help! I've noticed a lot of inconsistencies with policy names and descriptions whilst setting up our Win10 deployment! I wish also they'd go through and remove all the old settings that only apply to old non-supported OSs like 2000 and XP!
  13. What about the policy for "remove computer icon on the desktop" and/or "hide and disable all items on the desktop"? EDIT: Yes, it's the "remove computer icon on the desktop" setting. Just enabled it in my test environment and it hides "This PC" in explorer windows. Text from GPO description - "If you enable this setting, Computer is hidden on the desktop, the new Start menu, the Explorer folder tree pane, and the Explorer Web views. If the user manages to navigate to Computer, the folder will be empty." Computer = This PC in Win10 You don't need this setting anyway - as I said earlier, if you've got "hide and disable all items on the desktop" then no need for the individual settings too 8-)
  14. I'm not sure if this will be causing your issues, however I notice you've got a lot of unneccessary settings in your GPO. For example, you have set "prohibit access to control panel and pc settings" to enabled - but have then set individual settings for all the control panel applets (e.g. personalisation, printers, programs etc). There is no need to do this - the first settings prevents access to all control panel / settings apps including all entry points. Likewise, you have 'hide and disable all items on the desktop' set to enable - but have then set individual settings to hide IE icon, computer icon. Then in Network, you have 'prohibit access to properties of a LAN connection' and then have individual settings to prohibit various settings within the LAN connection. Might be worth removing these unnecessary settings and see if things improve? Unfortunately, for some settings, setting them to 'not configured' isn't always enough to remove the registry entries on the PCs - you either need to test with a freshly imaged PC after changing the settings, or set the settings that are no longer required to disabled first - do a gpupdate on a test machine, and then set them to not configured. Hope this helps!
  15. Bear in mind that if you allow staff to use their own encrypted memory sticks, it's difficult for you to recall these if that member of staff leaves. We felt it better to issue our own encrypted sticks, and use the BitLocker identification field to prevent staff writing to BitLocker drives that don't have our unique identifier set. We also prevent staff from encrypting removable storage on school devices. It would be possible for staff to encrypt at home and use the same identifier but 99% wouldn't know how to do this. This way we can recall the sticks (and the data) when they leave, and our Staff AUP states that they should never save personal information onto their own privately owned devices and removable storage. It's the only way we could come up with that shows we have done everything we can to prevent loss of sensitive data when using removable storage.
  16. Obviously it would be too expensive for just this requirement, but Salamander can do this for you and automatically update as frequently as you wish. It can also provision your users automatically from SIMS, add timetable to their email calendars, set exchange permissions, create and update class distribution lists, create and update 'teachers of X student's distribution lists, set O365 licenses and a million more things. Highly recommended!
  17. If your DPO cannot see the necessity of encrypting data in transit, such as on a USB stick, then you need a new DPO. With BitLocker it isn't possible to prevent non-encrypted sticks to be read from, but you have to start somewhere. It's better to start the ball rolling than to put your head in the sand. Issue staff with BitLocker encrypted drives and then mandate them by policy to use these and stop using any non-school issued removable storage. Have a look at the ICO guidance here https://ico.org.uk/for-organisations/guide-to-data-protection/encryption/scenarios/transferring-personal-data-by-usb-device/
  18. Hi All, I'm at the stage of configuring AppLocker ready for our Windows 10 deployment. For everything up to and including Windows 7, we have used Software Restriction Policies, so this is my first experience with AppLocker. I'm trying to get straight in my head the best way to do this. In this article (https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-allow-and-deny-actions-on-rules), Microsoft state that it isn't recommended to have the default allow rules in place, and then use a block rule to block certain files. My original plan was to use the default rules to allow all the executables in Windows and Program Files, and then block things like regedit etc that I don't want users to have access to. But it seems I shouldn't be doing this. So what is everyone doing, and how is it working for you? It seems the recommended approach would be to use the collection tool to pick-up all of the executables in Windows and Program Files, creating individual whitelist rules for each - and then just deleting the rules for the programs you don't want to run. This seems a bit tedious - not to mention a pain to manage when windows updates and new Windows builds introduce new and replacement executables? All input appreciated! Thanks
  19. That's great news! As you say I'm sure this will fix your issue, especially where you were deploying successfully to pre-1709 machines.
  20. GDPR doesn't state that you can't store data outside the EU. But you do have to ensure the security of your personal and sensitive data wherever it is stored. I.e. you have to be confident that the measures in place to secure the data meet our data protection standards. Survey responses shouldn't be classed as sensitive data as long as they are anonymous, but you may be storing email addresses when inviting participants? There are plenty of alternatives to Survey Monkey if you are concerned - Microsoft Forms is free and part of O365, or we use LimeSurvey which is open source and hosted on our own servers.
  21. It's definitely not an SMBv1 issue. The SOLUS agent works with SMBv2 as confirmed by SIMS on another thread, and myself on our site. I haven't enabled SMBv1 on our 1803 clients and am able to install the agent no problem. You can get it to work with SMBv2 as long as it is set up correctly. The main difference for 1709 onwards is that file and print sharing are disabled by default, as per my previous post. If you enable these either manually on each client or with a group policy, you'll be able to access the admin shares of those clients. No need to enable an insecure protocol!
  22. When you say you 'started a new file' - did you go into your existing timetable, and then use Data | Transfer Curriculum? This allows you to copy/promote your existing structures. For example in our school I would promote Y7->Y8, Y8->Y9, Y10->Y11, Y12->Y13 and then copy Y10->Y10 and Y12->Y12. This gives me a new curriculum plan that is 80% correct in terms of form bands, block structures, timetable cycle etc and is much easier than starting from scratch completely!
  23. You really should keep this box ticked to be honest. NLA asks for the credentials before the RDP session connects and is more secure. Has been supported on all OS's since Vista/Server 2008 IIRC
  24. File and print sharing is disabled by default in 1709. It needs enabling, you'll then be able to browse the admin shares and assuming you have the firewall configured for SOLUS and WMI exceptions it should work OK. The SOLUS user guide has all the instructions for configuring these.
  25. CAT6 is fine for up to 55m @ 10GbE, no need for 6A. The only time to consider fibre really is when you are beyond the distance limitations of cable, or if you need multicore. 50m of pre terminated 4-core fibre will cost you about 80-100 quid, plus you'll need the transceivers at either end too. Fibre would be a waste of money IMHO and give you no benefits
×
×
  • Create New...