Jump to content

Miscbrah

Members
  • Posts

    1,579
  • Joined

  • Last visited

Reputation

7,092 Excellent

About Miscbrah

Personal Information

  • Location
    /bin/false

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. Thanks. This end (with the help of CoPilot and some googling) I've knocked up a script that makes urls (in a local .html file) for teachers to click, and something else (that I have to run manually until I figure out the auth token thing) that assigns the permissions of the OneDrives by url for each student in %group%. It's working. It's less graceful than your approach but it's working. We're going with Salamander ultimately but couldn't get in before the start of the year. A very large part of the appeal is that I won't then have to nurse a set of scripts through updates and retired modules and all that every September.
  2. Ancient bump here, but did anyone ever get a script together that managed to do this?
  3. Thanks. Yeah throughout this process I'm not having a super warm and fuzzy feeling about it... randomly losing files is of course no flippin' good! Similar vintage here also in GP but I've tinkered and changed loads. Add in loads more following this saga! Also 1G/s here and since the first weekend with it, provisioning is actually pretty swift and it does seem to do the redirection thing nicely. Though having said that it's only me gently testing things at this point and not a class of thirty shrieking students. Still have a tiny bit of optimism going though, which is nice. With any luck it all "just works".
  4. Okay we're getting there! Students now log in, the "Known Folder" redirection (Desktop, Documents and Pictures) seem to sync up (and down again) to and from OneDrive. No interactions needed from students, just provisions when that logs in. Neat. Want to have a good long test and it's all still locked down (make sure we don't have them saving to obscure corners/armpits of 😄 or anything.) Happily this doesn't affect staff yet (not ready for that migration at the moment) as any sort of folder redirection just breaks this - so good news there too. Feels like I'm somewhere near the last person in the world to be doing this but if anyone else is stuck and comes across this can share the policies etc that got me going. Most success came after enabling SSO and stopping folder redirection happening at all (even desktop.)
  5. Plodding along here! Little way into the term now but still not got this down. Progress made however. Have a *sigh* Group Policy setup I inherited with one big giant policy with the student lockdown settings in it. With that policy off, all known folder redirection to OneDrive works and with it on it doesn't, so the next hurdle is rummaging through this for culprits and turning them off and on and seeing what breaks and what works. When that's done should be a lot closer. Not using CloudConnect at this point, seems to all be working (bar that policy) with the vanilla Windows offerings. Wish me luck everyone...
  6. Hello Edugeeks - decided it's time to join the 2020s and *deep breath* stop using local storage and just get students saving to OneDrives exclusively. Probably worth mentioning early I do NOT want this to affect staff yet nor break anything for staff; that's coming later in the year and I need to give it way more thought. Staff will occasionally log into these PCs though. Students however are a clean slate at this stage so I'm thinking it's a good time to go for it. They'll still have AD/domain accounts to log onto PCs in traditional fashion, just think it's time to cloud-ify storage for them. Usual (I'm guessing it'd be usual) wish-list applies: 1 - Stop them saving to C:, or indeed any other unwanted crevice of the PC or network other than OneDrives. 2 - Stop them seeing other OneDrives or areas they shouldn't see. 3 - Stop PCs themselves filling up with cached garbage if that's a common (or even uncommon) pitfall I can avoid here. At this point, before I set the accounts up and still have just about a fortnight to test this, my thinking is: A - No home area set in path in AD (be brave Miscbrah...) B - No traditional folder redirection set (as in, nothing set in group policy in User Config > Policies > Windows Settings > Folder Redirection.) C - In group policy, PC OU for the IT suite gets: Computer Config > Admin Templates > OneDrive > Silently sign in users to the OneDrive sync app - Enabled Use OneDrive Files On-Demand - Enabled (And the big one) Silently move Windows known folders to OneDrive - "Documents" and "Pictures" ONLY (along with tenant ID. And I'm guessing without notifying users - I think it'll jsut fox them.) "Desktop" omitted and redirected separately to a share they can't save to, for the sake of enforcing a standard set of shortcuts. They've had that set for years now so are used to it. (Along with the other big one) Prevent users from redirecting their Windows known folders back - Enable Then turn Storage Sense on (Admin Templates > Storage Sense) to stop the whole "PC fills up with cached garbage" situation. D - User policies for the students will be set to: User Config > Policies > Admin Templates > Microsoft Office > Default save location (set to OneDrive) - I must get the admx files for 2024 and do this... Then by my reckoning I should achieve a euphoric state of flawless digital triumph. But just in case that's not right, or vaguely right, or someone (I daresay most people these days) have done this differently or better, is there anything else you'd recommend I do at this stage or change? I do have Burconix Cloud Connect which is rad tbh but think I've all but moved away from that for students with the above. So yeah, firstly thanks for reading all that! Please chime in with anything in the above that looks doomed or broken or terrible! Thanks all!
  7. You're both lovely thank you! I'll have a read of the info there.
  8. Morning everybody - apologies in advance if this is painful but I'm no Apple person. Trying to seize some old independently-created Apple accounts the former IT manager made (for resetting of passwords etc) and made some progress, but also not entirely sure what I'm expecting here. So, in Apple school manager, domain is federated in (I guess??) the correct way: Great. I don't know entirely why there's 142 Apple accounts unmanaged with anything to do with my school out there in the world or what they are, so I guess that's question 1. Next step I guess is also to start the domain capture. Nervously pressing the link I get this: Right, this bit starts to worry me. I have visions of clicking this and nobody being able to log into their Microsoft accounts again because *something* happened and I can't figure out the *something*. So question 2 would be, in general terms, what the heck will happen with or to my Microsoft accounts after this? Also, what will they then be able to sign in with and do re the Apple store, Apple services and purchases etc etc? Can't really do anything else though without that toggle, and clicking that does this: Well no actually, now you mention it I'm not sure about any of this any more and delighted to hear whatever I'm pondering doing has no way back! Reading the help articles on the Apple knowledgebase and it seems like that all will do what I want, but I'm not so certain of it that I'd start clicking things without understanding the full implications of it. If anyone's passing and reading this and fancies literally spoonfeeding me through this ominous set of hazards it'd be amazing of you! Bit too daunted to go further at this stage. Thanks hugely for reading even!
  9. Could I have one also please.
  10. Revisiting this one (after a couple of years) with a bit of a query - thinking of reviving in anger a previous google school setup that never really got going. If we have google accounts set up for teachers and students with GCDS and chrome sign-ins, and they dutifully sign in to chrome (although I'm hoping there's something in an SSO thing out there that handles this) will they still be served youtube ads or does this stop it? Nothing like a couple of breakfast cereal or mobile game ads to really enhance a lesson/assembly! Thanks all.
  11. Felt optimistic so I got back in touch with Microsoft and explained the above. They said that actually does work, as if all along they hadn't been telling me it's literally impossible. I'm baffled but my Office is all working so go me I guess! Thanks again everybody for the help/sanity with that one.
  12. Ok so I ran the .exe for 2024 STANDARD on the KMS server in preparation for the AD-based auth for 2024 STANDARD and went back to check the test 2024 PRO PLUS machine and it's just fine now. Product activated. I'll give it a week to make sure it's "safe" to roll out and it stays authenticated and then I'll just say it's fine. I don't know quite why this is working now. Nobody from Microsoft I talk to knows why/why not or what I can/can't authenticate or which way I can/can't so at least I'm ending this crap-shoot with a licensed install. Hopefully... Thanks everyone you were all more help than the people who actually make and sell this stuff!
  13. Haha yeah actually it's TWO of them who've fibbed now. I might go in for the hat-trick and try again tomorrow...
  14. Thanks all - sorry didn't mention I do have a KMS server and AD, was looking to authenticate with KMS. Microsoft told me categorically there is NO KMS option for this, so I'm just moving to standard 2024 which does seem to. Even though @BKGarry it does seem like somewhere out there (and from what I've been reading) there actually might be. Just not for me it looks like. If all else fails will indeed put the MAK in the config xml and stop my faffing. Thanks again everyone.
  15. Hi everyone. Looking to deploy Office 2024 LTSC Pro Plus to clients but no KMS option. Anyone else rolling this out? If so, how did you authenticate it?
×
×
  • Create New...