Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Michael

Edu Supporters
  • Posts

    12,849
  • Joined

Everything posted by Michael

  1. It definitely looks that way - your template files look newer than mine as the description's shorter.
  2. This GPO is the other way round - a list of allowed .exe's. Run Only specified Windows applications vs Don't run specified Windows applications (I use this one). So long as you have Chrome installed and followed all my other steps, it should work fine. By all means test before deploying to the masses as always!
  3. An easy workaround to not having Edge installed is - User Config > Policies > Admin Templates > System - Don't run specified Windows applications - Enabled, enter - iexplore.exe
  4. Thanks both - for everyone's reference I do make Chrome the default also (once template files are imported) - User Config > Policies > Admin Templates > Google > Google Chrome - Set Google Chrome as Default Browser - Enabled So what's motivated me to do this? - I'm always looking at ways of lowering the surface area of attack (in general) - Good practice to establish browser requirements/compatibility of a school/business - Give end users the best browser experience Microsoft's advice is forever confusing/contradictory + my thought process - - IE support ended in June 2022 - Microsoft Edge with IE mode is the recommendation and is supported until 2029 - Microsoft will disable (not remove) IE on Windows SAC releases as of February 2023 - If you remove IE, (as per my guidance above), Edge with IE mode or Chrome with IE Tab will stop working - This tells me the IE engine is still required and isn't really a true software emulation - This also tells me Microsoft will still need to continue supporting/securing IE in some capacity, or will they? - I suspect a new regedit or GPO will be required to re-enable IE as part of the February 2023 release (if required) - Could IE in future be a new target for malware - similarly to Windows 7 - Removing IE if you've established isn't required for all or most users would seem a sensible approach
  5. Hi all, Thought I'd share my experience of removing IE11 in a network domain. For this example, I'm using Windows 10 x64, Google Chrome x86 and Word 2016 x86. First Step First thing's first, you should have an answer file for Chrome extensions - It's OK to save this in your Netlogon share and configure the GPO - Computer Config > Policies > Admin Templates > Windows Components > File Explorer > Set a default associations configuration file Specify \\servername\netlogon\File_Associations.XML for example. Second Step Within your nominated GPO, navigate to Computer Config > Preferences > Windows Settings > Registry Create the following GPP regedits - Path: HKLM\SOFTWARE\Classes\htmlfile\shell\open\command Value: (Default) Type: REG_SZ Data: "C:\Program Files (x86)\Google\Chrome\Application\Chrome.exe" %1 This registry entry will allow hyperlinks to continue working in Word 2016, otherwise you'll see the following error - Your organization's policies are preventing us from completing this action (or similar). Path: HKLM\SOFTWARE\Wow6432Node\Microsoft\Office\9.0\Common\Internet Value: ForceShellExecute Type: REG_DWORD Data: 1 This registry key will also allow hyperlinks to continue working in Word 2016, otherwise you'll see the following error - Unable to open https://example.com Cannot download the information you requested (or similar). Third Step House keeping - make sure all your shortcuts for users are pointing to Chrome, for example in the Target field - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" https://www.google.co.uk/ Fourth Step Removing Internet Explorer can be achieved in various ways, but here's the command I used - @echo off If not exist "C:\Program Files (x86)\Internet Explorer\iexplore.exe" goto :exit dism /Online /Disable-Feature /Quiet /NoRestart /FeatureName:Internet-Explorer-Optional-amd64 :exit Again you can save this within your Netlogon share as a .bat extension, then navigate to: Computer Config > Policies > Windows Settings > Scripts Startup/Shutdown > Startup Specify \\servername\netlogon\RemoveIE11.bat for example. This'll take a few restarts, but is completely transparent to the end user. IE11 is then seamlessly removed as an optional feature for good, however aspects of it will still exist within Control Panel for other browsers to use. The other way to tell is navigating to C:\Program Files (x86)\Internet Explorer, you'll see there's no iexplore.exe which is why I've configured the script to look for it or skip as required. Recommended - so long as Computer Config > Policies > Admin Templates > System > Logon - Always wait for the network at computer startup and logon is enabled, this script (and others) have a much better chance running sooner. Fifth Step For Birmingham Schools I've actioned this for all user levels - Pupils, Staff, and MIS - even the likes of HR Portal now works in Chrome, as it was the only service I was aware of which only supported IE. I hope you find this guidance useful!
  6. There should an alternative email address set - hopefully something outside the tenancy!
  7. Lindy's definitely the right place for this sort of requirement. They also provide USB cables for extended lengths too.
  8. As far as I can make out, 12th Gen is supported on IoT only.
  9. Yes - I've just got a Dynabook C50-J-12C, running an Intel i3 1115G4 running on LTSC 1809.
  10. Morning all, I found an easy workaround to this issue - if you navigate to C:\Windows\Fonts and copy/paste your font files, no UAC prompt appears... it just works and installs them all one by one.
  11. They're using iris authentication, not that should make any difference. I'd expect it to authenticate once, then install all selected fonts, but it's requesting it per font.
  12. Morning all, Just been asked to install some fonts on a home Windows 11 device - no problem you think, I select all the fonts (roughly 30), select Install for all users, but the UAC prompt appears for every single font. Is this a new feature of Windows 11? Frustrate the user and the admin
  13. Thanks for that - it's just I can literally find nothing online documenting this. Normally Microsoft are pretty good with their Applies to KB articles. I think the functionality was previously there, but at some point Microsoft have retracted it.
  14. Afternoon all, I've been asked what should be a really simple request, but everything I've looked at online is out of date. A user's name in Windows/O365 is officially J Bloggs They want to appear as Joe in a Teams meeting. The user is sync'ed with AAD, but then I cannot rename myself either (not using AAD). Clicking my initials (top right in Teams) does not show a Profile link or similar. Some websites suggest naming yourself (on the mic/camera screen), but I'm not sure if this always appears? TIA.
  15. I've seen similar behaviour and narrowed it down to SFP+ auto-negotiation. Optionally you can force the mode in the controller, which normally works after a reboot.
  16. I've had no reports of outages or performance issues. To the best of my knowledge Bromcom are fully Azure, so even if they took on additional schools, capacity shouldn't be an issue. Arbor comparatively (again to the best of my knowledge) use Amazon and likewise I've not had reports of outages or performance issues. Both companies are right in using highly scalable infrastructures, but there's always the possibility that clusters of these servers could be problematic or under-delivering, so both should have access to full reporting.
  17. Is there any reason why Ctrl+Alt+End wouldn't work?
  18. As a temporary workaround, reserve the IPs allocated to BT handsets, then apply an Allow All rule on the FW. If this doesn't work, then something's amiss!
  19. It's the same here, users enter their email address twice in turn, then their password.
  20. Michael

    Wave Browser

    I've seen this previously and it lives in the: C:\Users\%username%\Wavesor Software directory. You can't block it as a Google extension (via GPO) as it's not an extension.
  21. Sounds about right from previous experience. All I will say is I still see quite a few running Windows 7 as the OS... maybe a good opportunity to upgrade?
  22. In the end I decided to remove IE on every server, regardless what role(s) it was running and only installed Google Chrome on servers that require it. Examples in my case are Papercut MF and ePortal - useful to be able to test on the VM itself, but should also lower the surface area of attack longer term.
  23. One of my schools had three power outages in an hour last week. It was out of hours, but it proves my point. In working hours no backup would have worked, without putting all your equipment on a UPS.
  24. I guess my thinking is why would you need to amend three separate sites simultaneously? You can also stage upgrades at a smaller site, then the larger sites. I've done both - Windows Server and Cloud Key. I just find Cloud Key more polished, one less VM to manage and less issues with the controller service being unavailable. The original white one is 32Bit Gen1 (so avoid this), the black ones are 64Bit Gen2, so you want these. Alternatively a hosted controller on a VPS is another alternative, but you pay x amount per month of course. Most do controller upgrades for you.
  25. I would recommend a Cloud Key Controller per site, rather than all on one. You can still manage this using one account. Separately, can you even source Unifi Pro 6's? Everywhere in the UK has no or limited stock!
×
×
  • Create New...