Jump to content

Garacesh

Members
  • Posts

    16,316
  • Joined

  • Last visited

Everything posted by Garacesh

  1. Is the PS4 backwards compatible? Pre-owned PS4's are going in the range of £150 (not that I've been looking...) which gets you a range of critically acclaimed games like Persona 5, God of War, Spiderman, Bloodborne, Street Fighter 5, inFamous: Second Son, The Last of Us Remastered/The Last of Us 2, Uncharted: Lost Legacy, Shadow of the Colossus and Ghosts of Tsushima (Obligatory I haven't played all of these and YMMV, they're just universally praised, maybe with the exception of TLoU2. I have played God of War and Persona 5 though and would highly recommend).
  2. I dunno, do you not? I was under the impression that you needed to feed it a GVLK so that it knew to look for KMS/ADBA, else it would just sit there crying it wasn't genuine...
  3. Yeah.. I must've grabbed the wrong KMS Client Setup key by accident. DUURRR. My TS was applying the right image (Edu, not Pro Edu), but I had the Pro Edu key in the Apply Windows Settings step.
  4. I think I've figured it out.. Level: Warning Date and Time: 12/07/2021 14:46:52 Source: AppLocker Event ID: 8008 Task Category: None Event Details: appidsvc.dll: AppLocker component not available on this SKU. Wait.. Surely it can't be...? WinVer shows me as using Windows 10 Pro Education. There's apparently 2 flavours of Edu now. And I was applying the J447Y key instead of the VCFB2 one. WTH, Microsoft?
  5. Nope, duplicating the variable paths with explicit paths doesn't work either. It just doesn't seem to be actually doing anything, despite GPResult saying the policy is applied. For example, I've changed C:\Users\*\AppData\* to C:\Users\* (I'm pretty sure C:\Users\*\AppData\* is acceptable, but anyway, just to be safe..) If I make a copy of calc.exe and dump it into my test staff's %LOCALAPPDATA%, I can execute it, despite the C:\Users\* block. Same applies if I copy a non-UWP app, such as a portable copy of KeePass 2 Edit: The only thing I've ever known to bugger up AppLocker is if a PC has AppLocker set and a user has Software Restriction Policy set, but I've confirmed this user has no SRP.
  6. Hmm.. Trying to block them with AppLocker and it (Applocker itself) just doesn't seem to be working.. I've confirmed via gpresult that the user has no SRP applied to it, and the computer does have the AppLocker policy applied, but.. nada. Application Identity service is enabled and running. Is there something wrong with my policies? Does an Allow take precedence over a Deny? Am I using wildcards wrong?
  7. I would've chucked them up into the air and whacked them with my racket, but that might have ruined the texture a bit..
  8. To be fair, most destinations still require you to get tested before you fly, and then quarantine and test after you land. Then you still have to do contact tracing and a test upon return to the UK. And airlines/ports are still making you wear facemasks. I'll admit to being one of the people that booked a flight yesterday, because I haven't seen my partner in almost a year. Do I think there are risks? Absolutely. Is it a little bit selfish? Yeah, probably. I did, however, leave enough time on the return journey to quarantine at home should I need to, and I'll be wearing my masks as normal, and getting regular tests. And I've had both jabs (which I know doesn't make me immune, but still, it helps). So I accept the risks and have plans to mitigate them should the worst happen. So I feel that's a reasonable compromise. And I (no doubt in vain) hope that other travellers will be taking the same precautions. But we all know most of them wont. Most people are burnt out and have stopped caring. They're sick to the back teeth of restrictions (which, whilst the restrictions are reasonable, being sick of them is understandable) and simply don't have the capacity to care about COVID any more. Is it justifiable? No, I wouldn't say so. But is it understandable? Absolutely. As much as lockdown has been easy for me, since I'm a introverted hermit who has no social life beyond the internet, I do need to keep reminding myself that I'm not everybody else. People keep bringing mental health into the discussion, but I don't think that's being fairly applied. Extroverts (that have stuck to the rules) have probably had it hell for the past year, and I do sympathise with them. It's a fine balancing act, because there are people who legitimately can't be vaccinated who this virus still poses a huge risk to, and of course the more people with the virus the more chance there is of a mutation. That's why I think masks ought to still be mandatory, and why I'm glad they're still enforcing quarantines for the unvaccinated. But then again, I also think those that were CEV and shielding should still be allowed to do so, that provision should've never gone away. I'm not really sure where I'm going with this ramble. Just a thought-dump I guess.
  9. I'm in the middle of testing a 20H2 build for rollout over the Summer, but these driver apps seem to appear of their own volition (I assume Windows Updates) and I can't find a way of removing them. HP Audio Control HP System Event Utility Intel Graphics Command Center Synaptics Touchpad Though no doubt we'll have other ones on other machines with different hardware/driver combos. Redirecting the start menu the regular way, via User Configuration / Policies / Windows Settings / Folder Redirection User Configuration / Policies / Administrative Templates / Start Menu and Taskbar / Remove common program groups from Start Menu is set to Enabled, and gpresult confirms it's being applied There's no shortcut to these in %PROGRAMDATA%\Microsoft\Windows\Start Menu, and even if there were, the previous GPO should take care of that. I'm not seeing any other GPO's that might apply to these apps, but for obvious reasons, allowing kids to access the graphics settings or touchpad is a terrible idea. The touchpad app straight-up has a 'disable' button there which requires no administrative permissions to use Edit: I'm wondering if 'run test builds on all hardware, figure out the appx id's, remove them in the task sequence' is my only solution here?
  10. I suspect a large portion of of those people are probably the same people who weren't being careful in the first place because they're too good/important/etc to subject themselves to a minor inconvenience, though from what I'm seeing online there's a lot of people who are just done with it now, they're burned out on anything COVID-related and just don't have the capacity to care any more. Despite the fact that we've got the delta variant ravaging our school, and about a quarter of the school isolating, plenty of kids here are still walking around without facemasks on, staff testing was <40% a few weeks ago, and an average of 60% of kids (or P/G) are consenting to the weekly testing (it was <20% a few weeks ago, before the mandatory-but-not-really testing came in with the NHS staff in gazebos in the car park)
  11. Paywalled. PHE have allegedly said "there is currently no evidence that this variant causes more severe disease or renders the vaccines currently deployed any less effective", though how much stock you put in that is up to you.
  12. That's either really good, or really bad Who will watch vaxx the watchers vaxxers? (To be fair, I mostly jest. I'd imaging those giving out the vaccinations would have already had theirs, since being put in contact with so many people carries a considerable risk of both contracting the virus and spreading it to others)
  13. "However [...] many of these devices have now been taken back or disabled by schools." Well don't turn off the filtering for them, then?! We're recalling most of ours, reimaging them onto the domain, and putting them to work as educational resources within school. We're still offering chromebooks (as they all have a safeguarding extension on them, and work just fine both on and off site) to kids that are isolating, but that does take away from in-school resources. It won't filter their internet, but it'll at least pick up anything dodgy they do go on. A perfect solution? Obviously not, far from it, but it's the best we can do. They've essentially forced our hand. For us to continue to allow the kids to keep the devices, we'd have to incur significant costs to set up off-site filtering which we just don't have the money to do. The devices were supplied with safeguarding protections preinstalled on them. Whilst on one hand you could argue it's not fair to say we want the device back, it's also not fair (especially to less technologically-abled parents) to say "That safeguarding stuff? lolbye, go figure it out yourself." What else are we supposed to do?
  14. Bit of a necrobump, but has this stopped working for anybody else? My rule is: (&(objectClass=user)(objectCategory=person)(mail=*)(!(userAccountControl:1.2.840.113556.1.4.803:=2))) So any user, with an email address, who isn't disabled. Yet it still syncs disabled users if I delete them from G Suite, and doesn't disable users in G Suite if they're disabled in AD. Disregard. Granted my sync user read all permissions for user objects in those OU's and it's working properly again.
  15. Yep. Exactly this. I'd argue it's entirely reasonable for a school to say "We don't control your Internet, so it's up to you to ensure this device isn't being abused." That'll never actually work, mind you, but at least it drives home the point of 'this isn't our network, the onus is on you.' We put Senso on our chromebooks, so that works off-site, but Windows devices (for now, at least) are just set up the way the DfE gave them to us. We'll, ignoring the 50-or-so we've reimaged.
  16. You're going to need a cloud monitoring platform, at minimum. Something like Senso Cloud, or Netsupport DNA. We use Senso here, and I gave a trial of Netsupport a good thrashing, and was suitably impressed. Both of them do keyword monitoring and Web logging. Netsupport can also block websites (though I'd hesitate to say you should use it as a filtering solution) and applications, not sure if Senso can do that though.
  17. Yep. Management want me to keep emailing them. I'm like.. If they haven't listened by the third email, someone with more clout needs to be getting involved -_- Most of ours have been returned in good condition, though. 55 returned, only 1 faulty.
  18. We (and I suspect many others, given the lead times on laptop trolleys...) are having them returned to us, reimaged, and put to work as school resources.
  19. Huh, did not know that. Interesting. But yes, to parrot what's already been said, I, too, have had the same. Numbers (undoubtedly spoofed to be) similar to my own warning me that my NI No has been used fraudulently and the ol' bill will be coming to pick me up if I don't press 1 to speak to an advi- *hangs up* So far I've managed to evade the fuzz rather well. I can only assume this is because of social distancing. Once this pandemic's over I'll no doubt be in the slammer
  20. What about subdermal NFC tags? Can we use those, so staff can't lose them or have them nicked? (I jest.. But I do genuinely want one lol)
  21. Hmm, so it's probably something, no idea what, about the specific adapter we have. Do either of you have a product code/part number to hand?
  22. Did anybody get any Dell Latitude 3190's? And if so, did you manage to PXE boot them? Spec sheet for them says they have USB 3.1 ports, but our USB 3.0-GigE adapter doesn't seem to be working with the one I've got to test. I've made sure boot sequence is set to UEFI, UEFI Network Stack is enabled, and USB Boot Support is enabled, but I still get no PXE option. The closest thing I can find from Dell is this page that mentions enabling Thunderbolt Boot Support and TBT (and PCIE behind TBT) Pre-boot Modules, 'even if you are not connecting to a Thunderbolt dock', but the area of System Configuration that provides this option isn't there in BIOS, even after updating to the latest. Could always be something about this specific adapter it doesn't like, but I've confirmed the adapter works on another model of RJ45-less laptop we have.
  23. Hate to necrobump but just want to check something isn't going screwy.. If the final script produces an ntlmou.csv, pwnedpw.txt, pwnedusers.csv and pwnedusers.txt that're all blank/0KB, is that good news, or has something failed? The powershell window shows no error. Completed in: 18 ms All pwned users output to C:\audit\pwnedusers.txt
  24. Pfft. 1+1. Come back when you can do multiplication! I can do 1+1 and 1x1. And probably eat more pizza! *sadly prods flab*
  25. Yup and yup. We enrolled chromebooks into our domain, but the Windows laptops just went straight out. We don't have InTune or a internet-addressable filter or any of that stuff so there's absolutely zero way we could manage them off-site beyond a Senso instance. We've had around 40% of them come back so far.
×
×
  • Create New...