Jump to content

Garacesh

Members
  • Posts

    16,316
  • Joined

  • Last visited

Everything posted by Garacesh

  1. I have to admit, I've gotten waaay more use out of the bluetooth earbuds than I thought I would. The edibles/drinkables have been stashed as 'emergency brew supplies'. Cup, biscuit, cappuccino and teabag. Covers enough scenarios I reckon.
  2. We don't really have anything set here though we're looking into it (and I have several choice words to say about the supplier that the BM bought without asking me....), but my last school was Paxton for the staff (2 different sign in/out points, one at the front door, one in the car park), with an InVentry box at reception for visitors. We did nothing for the kids as they had their own separate entrance that was continually staffed. While InVentry wasn't perfect, it was good. I did have a few niggles with it, mostly the hardware they supplied not being glass-fronted so the touchscreen eventually ended up somewhat unresponsive. The link with MIS was decent, and we had it so that if someone said they were here to see X member of staff, it would email that member of staff a "So-and-so is here to see you" and attach the photo it took for the badges, which was useful. The extra module they give you to print off all the visitor lists in case of a fire evac was a good idea, too. Double-click the exe, select a printer, done. No way to muck it up.
  3. Isn't the issue with installers not that they need to be explicitly a localadmin, but that non-administrative users don't have permission over %ProgramFiles% and other such directories? Maybe you could manually install the software yourself, and give specific members of staff control over %ProgramFiles%\Overwatch or wherever it installs? Could you use something like ProcMon to see what files it's dumping where? Worth trying with a test account, perhaps? You'd have to wait until Blizzard release an update though.
  4. I'd imagine that if you were allowed, you'd have to personally contact Blizzard for some kind of special accounts. I'd imagine that they do some kind of tournament/net café style of account you could apply for? If not that, then each kid needs their own personal account because the base T&C's absolutely do not allow for shared accounts under no uncertain terms. So the school couldn't buy the game x amount of times and share the accounts. Which means each kid is also gonna have to fork out the cash themselves, which seems a bit crappy to ask the parents to do. I'd imagine most parents to expect that if the school was going to run a club, the school would provide the equipment, no? I'd also suggest you don't want to buy the kids a copy on their personal accounts with the school card. There's probably some real iffy rules surrounding that one that could raise a few eyebrows.
  5. I'm fine with language changing, so long as we're not normalising the greengrocer's apostrophe.
  6. 9/10, got the Richard Harris one wrong, but I'm fine with that.
  7. It's kind of both, in a way. You group disks together as one logical disk (except it doesn't show up in Disk Management, or get a drive letter, because why would it? That would make too much sense! ) and then mirror those disks, essentially. So you end up with a folder, in my case, C:\ClusterStorage\$S2DDiskName\ and that gets replicated on both servers. So all my virtual machines, their disks, snapshots, etc are all told to live in subdirectories of that path. Edit: Also worth adding, if you go with 2 servers, you'll need to set up a quorum witness too, just to make sure both hosts don't try to spin up all the VM's thinking the other is dead (there's a name for this but I can't remember what it is..). But that's really easy to do. You can stick that function on any of your existing (physical) servers.
  8. No worries, you're basically me a year ago Most of the stuff in this thread is probably still applicable. I ended up going with 2 big ol servers, dual Intel Xeons and 192GB DDR4, set up in a cluster with their NVME drives set up in S2D (needs Datacentre, though if you're going Hyper-V you might as well buy Datacentre anyway for the infinite VM allocation). They're working a treat here. Failover takes around 30 seconds from 'server died' to 'everything's back up and running' Edit: Just be aware, if you go down the same route, don't make my mistake: you cannot mix SATA/SAS/NVMe drives in S2D, they all gotta be the same type. Not including the Datacentre licenses themselves, was about 7 and a half grand. Edit2: Looking back on my OP, I did end up siphoning the file server off onto a physical box, instead of hosting it virtually. But so far I'm running a DC, an application server, a print server, SIMS, MECM, an RDS server and our backup server on them, and they're chugging along just fine
  9. Yeah, most of that is probably Bolton! I've been keeping an vague eye on Greater Manchester's stats and everywhere is doing really well, except there. Not got a clue why they're so high, but something is going on there. All I've seen so far is that they've got one of these exotic Indian flavours that's supposed to be more infectious?
  10. See this right here is why I've always liked NetSupport. I ain't even given them any money and they're still actioning feedback. Top quality support, all around!
  11. Not even close. It rebounds the radiation into a single focal point, that you then leave for a few days to grow, before walking into it and developing superpowers. Obviously Fairly certain I've read that stuff like this is illegal, but nobody bothers to enforce it.
  12. XML. Malformed. Bloody. XML. Solution was found The Web.config xml that the IIS post-install task creates? Broken. After all the technet posts, blogs by helpful indian blokes, folks helping me on Discord, and historical threads on EduGeek, I accidentally stumbled across the solution by going through permissions on the WSUS Administration IIS Site, and opening up IIS Authentication settings of ClientWebService Line 180 of C:\Program Files\Update Services\WebServices\ClientWebService\Web.config reads: Turns out IIS doesn't particularly like having that multipleSiteBindingsEnabled="true" in there twice. Why is it in there twice? Not a clue. Did I modify it? Pretty sure I didn't. All I did was change 400 to 800 as everyone recommended. So, yeah. Three weeks wasted on a bork'd default config. If nothing else, I hope this thread helps someone else in the future!
  13. They're not technically 'allowed' iirc, it's just a flaw with the system. Allegedly (see bbc new link I posted above) there's a plan to stamp it out, but I can't predict how much it will help as the majority of these calls come out of New Delhi or Kolkata, and I don't know enough about phones to know if any changes here will affect calls coming from elsewhere.
  14. @GrumbleDook Managed to square it with whoever I spoke to at NetSupport, the chromebook thing they confirmed was an issue and got it fixed, and they offered to write me a custom dll (or ini, I forget?) that tells NSDNA to include the URL of the blocked website in the email, but ultimately our time ran out and we have had to renew Senso for a year, and the logging-on-online thing was either the PIN email failed to send, or I failed to click it. Gonna eat humble pie and suggest it was probably the latter, but spare me some pity and assume it was the former, 'eh? That being said, lesson learned, and I now know when Senso is due to run out, so I can start seeing what's out there with a bit more time to spare next year! Happy for you to drop me a line if you want some more detailed feedback of what went in to choosing to renew though.
  15. Huh, I was about to say "It looks like they've bought out a block of 07868 026xxx, as I just got another from 07868 026325" but I guess not Going hard on this today, aren't they? Geez..
  16. I mean, you know it's bad when Ofcom themselves are telling the public to straight-up not trust Caller ID. Allegedly they're working on a fix for number spoofing, though that won't help all that much as most scam calls aren't spoofed, they're just easily-disposable rented numbers. Personally I've only ever seen HMRC's number get spoofed (though I hear about it happening for banks, too), all the other calls have been generic number. Most of them aren't even withheld.
  17. Illegal use of my NI number again! Oh no! This is time-sensitive and if I didn't press 1 to speak to somebody, I would be arrested and have my assets seized! This time, from a mobile number though. 07868 026760 I'm not mega clued up on VOIP services, but that's the first time I've seen it come from a mobile number. Could be 'legit', they've actually bought sim cards, I guess it doesn't really matter in the long run though.
  18. The Mrs and I have been bingeing The Circle recently. Clocked the US copy on Netflix, gave S01E01 a bash expecting it to be a bit drab, but it turned out to be super entertaining. We finished US S01 and are now making our way through the UK flavour until the US S02 finishes and we can binge that.
  19. Right. I give up. I've tried everything I can possibly think of, now I'm coming to you lot, arms outstretched, bowl in hand, "Please sir, I want some more..." Try as I might, I just cannot get MECM to push out Windows Updates. The server is a Windows Server 2019 Hyper-V machine, with the Web Server (IIS) and Windows Server Update Services roles, as well as the Background Intelligence Transfer Service (BITS) feature installed. Whilst WSUS is installed, I haven't configured it in any way, in fact, I've just launched it to check, and been given the Before You Begin wizard, which I then cancelled out of. The firewall on the server has inbound and outbound rules allowing :80, :443, :8530 and :8531 (both TCP and UDP because I couldn't get a solid answer on which one it is...) as those are the ports WSUS and IIS use. The WsusPool Application Pool in IIS has had its Private Memory Limit increased to 4194000 to stop it falling over all the time. The instance of MECM/the Site Server has the Software Update Point role, on the standard :8530 and :8531 ports, configured to obtain updates from Microsoft. The server is set as the Site system server of the boundary group, and most devices in the Devices list are showing the correct Site Code and Boundary Group(s) (there's the occasional blank) If I fire up the Configuration Manager Console, and go to Software Library / Software Updates / All Software Updates, the list is populated in all its green-arrow-y glory. Some of them even say required! But those that do only say Required: 1, Installed: 0, Percent compliant: 0, Downloaded: No, Is Deployed: Yes - I initially thought this 'Required' meant the update was assessed to be as matching one of the ADRs, but there's only 21 of these 'Required: 1' updates, so it's not that...) Those that don't, say Required: 0, Installed: 0, Percent compliant: 0, Downloaded: No, Is Deployed: Yes I have automatic deployment rules set up, let's take my "PC Windows 10 Updates" ADR. Product: "Windows 10" OR "Windows 10, version 1903 and later" OR "Windows 10, version 1903 and later"* Superseded: No Update Classification: "Critical Updates" OR "Definition Updates" OR "Security Updates" OR "Update Rollups" OR "Updates" * Yes, that's in the product list twice. I have no idea why. Clicking 'Preview' nets me a lovely list of 134 updates, at the time of writing. This ADR is deployed to my 'All end-user computers' device group, which currently has 339 devices in it. These devices are all W10 endpoints. If I manually search for updates on one of those devices, Windows Update throws 0x8024401f, which a few different sources (such as this one) have said enabling Directory Browsing in IIS fixes, however that has borne no fruit for me. Navigating to http://server.domain.local:8530/ in a web browser drops me into a root folder with directories App_Data and aspnet_client Navigating to /Content throws error 403, which I'm told is correct. Navigating to /selfupdate gets me a directory with 2 subdirectories AU and WSUS3; and 2 files, iuident.cab and wuident.cab. Random sampling indicates I am fully capable of browsing these directories and downloading all the files within. On the MECM server, WCM.log has no errors, or at least, nothing immediately obvious. I can see the occasional "wait timed out after 0 minutes while waiting for at least one trigger event.", "Timed out..." but nothing is highlighted in red or yellow. The same applies to WSUSCtrl.log, nothing highlighted, nothing immediately out of place. On my test endpoint, the reg keys at HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: WUServer and SUStatusServer are both the correct hostname and port of the MECM server. GPResult /Scope:Computer shows the winning policy to be Local Security Policy, so it's not a rogue GPO screwing with the WSUS GPO settings. If I run Get-WindowsUpdateLog on a client, however, I do get a bunch o' red. Agent: *FAILED* [8024043D] GetIsInventoryRequired WebServices: *FAILED* [8024401F] Web Service Call ProtocolTalker: *FAILED* [8024401F] GetConfig_WithRecovery failed ProtocolTalker: *FAILED* [8024401F] RefreshConfig failed ProtocolTalker: *FAILED* [8024401F] RefreshPTState failed ProtocolTalker: *FAILED* [8024401F] Sync of Updates ProtocolTalker: *FAILED* [8024401F] SyncServerUpdatesInternal failed Agent: *FAILED* [2084401F] Syncronize Unfortunately, none of these errors give any further information about the failure. The keen-eyed amongst you may, like I, notice that most of those error codes are the same as the error code searching for updates gives me. Unfortunately this seems to be hindering rather than helping. And this is where I sit, completely stuck for anything else to check now, Google results not really listing anything conclusive. I'm really hoping about six of you are gonna swan into the thread and go "Oh that?! Yeah that's easy, just change X" and it's dead simple and I can just move on to other stuff
  20. Much appreciated, I shall do some digging when I get a bit of free time (whenever that's going to be..)
  21. Probably. But if the filtering stops, internet access on those devices dies, no? Because they'll be trying to contact a web filter that isn't there any more? And, as they're restricted accounts that can't even install software, that pretty much reduces the device to 'a doorstop that can play MP3s' Well I guess it depends, they're set up via intune, right? So they could push an update that gets rid of the filtering, I think? Not sure. Don't have much experience with intune. Or any, really.
  22. I have not, admittedly. It originally struck me that the issue was to do with outdated hardware, a lot of our computers are old i3-3xxx, 4GB DDR3 machines, but even with newer hardware (i5-7xxx, 8GB DDR4, SSD) staff are still complaining it's considerably slow or buggy. I spoke with the head of IT yesterday and he mentioned that sometimes peripheral input is still disabled after unlocking computers, sometimes issuing commands just flat-out doesn't work, and that the web UI is slow and/or unresponsive when trying to control a remote machine (the latter of the 3 which I personally have experience of, as previously mentioned). There's also the issue of having to assign staff to certain rooms. Which seems a bit of a bizarre choice, really. Surely it shouldn't matter who the member of staff is, it should matter where the member of staff is? Ideally a classroom management solution allows any user of PC X (the staff device) to control the PC's A, B, C, D, [...] because they 'know' they're in the same room, especially when you consider rooms with ICT provision are usually shared, bookable, or available for ad-hoc use. I appreciate the user front-end is entirely cloud-based, so it's not a 1:1 comparison, and figuring out what device a user is using isn't so simple when your software is built that way, but that's entirely my point, and is why I say your safeguarding is great but your classroom management leaves much to be desired.
  23. On-paper? The latter. In practice? Probably going to be the former. That being said, the DfE filtering/etc dies in.. October? Was it? So they're going to have to come back to us sooner or later.
  24. I mean, they're not fantastic, but the HP G7's will do as general purpose, and the chromebooks are, well, chromebooks. We're finding ways to repurpose ours, we've done a set of 20 G7's for music (probably mostly for musescore to be honest), we're waiting on a trolley so we can do a set of 30 G7's for art (though we've bought extra RAM* for those ones, just to be safe), and we've given a set of 20 chromebooks to maths. Plus another trolley on order for a set of 30 chromebooks that I suspect will just be 'generic use' and run as a bookable resource. Once we've got that done, I'm going to take stock of what's left, and probably argue that we toss out maths' old aging set (a mix of utterly ancient Samsung XE303C12's and a few not-as-bad-but-still-not-great HP 11-v051na's) and give them another set of 20 new ones. That'll probably end up using the majority of devices we were given, as we're not asking for them back from the year 10's and 11's. * Fair warning, the G7's only have one RAM slot, so you have to buy 8GB sticks and then just have a bunch of 4GB ones sat around doing nowt..
  25. Hmm, so I spoke with a NetSupport bod last night, they've confirmed that NS-DNA currently isn't able to track what's being typed into a google docs tab on a chromebook. Nor is it, for some reason, telling the server when it blocks an attempt to access a restricted website (though it does block the request and redirect to the specified url as programmed) on a chromebook. They have confirmed this isn't intentional, though - that bit was working but now is not, so they've passed that on to the relevant folks. However, from further testing, it's looking like safeguarding team need to be able to access a computer with the DNA client on it, because I'm the only person that can log in to the cloud platform (at dnaauthentication-uksouth.azurewebsites.net). Even if I make second operator that's given the Administrator permissions and role, it returns Incorrect email or password. Except, even when I log in, I don't have access to Alerts, only phrases/eSafety, so I can't monitor 'Attempt to access a restricted website' (and the email alert that attempt generates doesn't list the URL, so they'd need to be able to access the Alerts section to see what site). So even if we did get the cloud login working, some of the things they want to check, they can only do when they're on-site via the client. I could load NetSupport DNA onto the Remote Desktop server, but then if all they have is a phone that's going to be such a pain to use. All in all - and I say this as someone that came from a school that used NetSupport School, and really likes NetSupport - it's really looking like NetSupport DNA is aaaallllmost there, but not quite. There's just those few core niggles that make it unsuitable for our current needs/environment. Which is also a massive shame, because as good as Senso's safeguarding seems to be, the ICT staff (and other rooms where there's high IT capacity, library, technology, etc) genuinely prefer to use our old, klunky, perpetual license of LanSchool from 2016 rather than Senso's classroom management tools - that's just how poorly the website performs. I had to use it as a pseudo-remote-access tool when I first started here and good lord, it was painful. So Senso seems to be giving us the best suited safeguarding, but a poor classroom management, whereas NetSupport offers a great classroom management tool, but has a few issues with the safeguarding.
×
×
  • Create New...