-
Posts
12,849 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Michael
-
I should add most users are absolutely fine, which makes the issue more difficult to isolate as to why. Have tried all obvious things such as resetting browser to default. Both users are using transparent proxy, if that makes any difference?
-
Happening with both, one of each, pretty much at the same time.
-
We ran Wireshark (at their request) and sent off the log file, but they're now ruling out the MTU being the issue. - - - Updated - - - It is something filtering related, as the issue doesn't occur at other schools (different ISPs) and the issue doesn't occur at home either.
-
Afternoon all, I have a handful of users who use EXA as their ISP and for some weeks now O365 emails do not automatically pop-up on arrival, forcing users to refresh of press F5. They've narrowed it down to filtering and the MTU size being the issue, but it still persists. Has anyone else experienced this and if so have you reported it? Using Google Chrome, all up-to-date. At home (on a school provided device), no problems.
-
Thanks Steve - to go through your points - 1, 2 and 3 - LTSB and LTSC versions of Windows 10 do not have Feature updates, only Quality updates. At any point however, you can defer Quality Updates up to 30 days (as I do) and optionally pause. At any point you can also defer Feature Updates up to 365 days and optionally pause. In both cases, to remove the pause, you simply remove the date entered from the GPO. 4. In regards to Cyber Essentials, I think a balance needs to be weighed up. As per my example, March 2021 for Windows Updates has been a disaster. I very much doubt any of these organisations have an answer to this kind of scenario. I appreciate this isn't the same every month, yet Microsoft have a reputation for releasing problematic Quality or Feature updates. I would also say that with the WSUS model, you could easily have notebooks which are months out of date if they're not brought back on site (for whatever the reason). 5. Yes, notebooks, workstations/desktops and servers. I'd also say I enforce the Windows Firewall when devices are used off site, but disable it when devices are on the LAN (again all by GPO), which offers a degree of protection. By all means, far from perfect, but I still think it's a better set up than WSUS. Alternatively you can make your WSUS public via SSL, but I've no idea what the risks are, even if you VLAN'ed the WSUS off, or placed it in the DMZ.
-
Just to update this discussion - Windows Update for Business has worked so well, I'll be decommissioning all WSUS servers in the near future. These are the things I've observed - - By far devices obtain fixes quicker and install faster - I think the above is due a combination of devices being able to download update files from any location, as well as peer to peer - Remaining 30 days behind, for both workstations and servers seems to be a working strategy. March 2021 patches have been somewhat a disaster, with Microsoft publishing two updates for Windows 10 1607 and four updates for Windows 10 1809 - Currently exploring options such as this whereby I can query the network and get a report back (possibly even emailed), as an easy solution to keep tabs on workstation status Any thoughts or something I've missed? Let me know!
-
Have you gotten rid of IE11 yet?
Michael replied to Jaan's topic in Internet Related/Filtering/Firewall
Just to update this discussion - removing Internet Explorer on a server hasn't created any issues, however I've observed the following - Powerchute Business Edition points to - https://localhost:6547/ Papercut MF points to - This is a CDN address Unifi Controller points to - https://localhost:8443/manage/ (requires Chrome or Edge anyway) if not using a Cloud Key. So in all of these cases, installing Edge or Chrome is one solution, or alternatively manage on a remote host. -
I literally do it that way in batches of 20GB, works fine.
-
Maybe the flux capacitor needs changing (sorry couldn't resist). Other than flashing the BIOS which you've done, I can't think of why it would default to 2032.
-
This is why I don't bother with upgrades to ActivInspire, unless there's an essential need. I've had no issues users ticking the box to ignore Flash and admin.ini keeps all users on the same version, which also helps. Previously without it, I found user Downloads folders were literally full of 200MB+ ActivInspire install files!
-
I'm curious, what compelled you to upgrade to 2.21? I still have users on 2.14 with the latest ActivPanel and everything works fine. Implementing the admin.ini solution, it stops ActivInspire searching/downloading any new updates upon loading it up.
-
I agree when you have the likes of Google Drive and OneDrive/SharePoint. The money saved from buying/creating/maintaining a SAN can be re-invested in faster connectivity into school.
-
Will Access Points ever need two data points?
Michael replied to kennysarmy's topic in Wireless Networks
Yes - one step closer before they're all natively fibre I suspect! -
The USW-Pro-48-POE vs. the USW-48-POE does have 4 x SFP+ Likewise the USW-Pro-24-POE has 2 x SFP+ They also support 802.3bt PoE++ There's also the US-16-XG which has 10 x SFP+ ports and 4 x 10GbE ports.
-
If you check within Control Panel, can you see Flash? If not then chances are it's been removed. KB4577586 also applies to 1607 LTSB. As above, it's time to update to HTML5 versions, otherwise it could be a security issue later down the line.
-
Have you gotten rid of IE11 yet?
Michael replied to Jaan's topic in Internet Related/Filtering/Firewall
So I ran the command on a Server 2016 DC and you're then prompted to restart. It's all pretty quick and painless. The only other role of this server is Azure AD Connect. Internet Explorer's removed from the Taskbar, as well as Windows Accessories. It's also removed from Control Panel > Default Programs > Set Default Programs Internet Options in Control Panel is still there, but various buttons have been removed. C:\Program Files (x86)\Internet Explorer and C:\Program Files\Internet Explorer still exist, but no iexplore.exe which is perfect. Initial impressions, I'd say definitely look into it, but approach with caution! I can't guarantee something won't break! -
Have you gotten rid of IE11 yet?
Michael replied to Jaan's topic in Internet Related/Filtering/Firewall
I'm just thinking of scenarios such as Domain Controllers, File Servers, Print Servers. Even with IIS installed, you could still install Chrome or Edge only where there's a need. I think I need to trial it. -
We leave this disabled for that exact reason - users can copy data and then delete thereafter optionally. I agree it's much safer and space isn't an issue!
- 1 reply
-
- 1
-
-
Have you gotten rid of IE11 yet?
Michael replied to Jaan's topic in Internet Related/Filtering/Firewall
Here's how to remove Internet Explorer on Windows Vista and upwards (client and server editions) - Elevated command prompt - Disable Feature dism /online /Disable-Feature /FeatureName:Internet-Explorer-Optional-amd64 Elevated command prompt - Re-enable Feature dism /online /Enable-Feature /FeatureName:Internet-Explorer-Optional-amd64 Still contemplating whether to do this on servers sooner rather than later, even with IE Enhanced Security? And does this also mean I could have a browser-less server without any issues? -
Have you gotten rid of IE11 yet?
Michael replied to Jaan's topic in Internet Related/Filtering/Firewall
A lot of Birmingham schools still use HR Portal - works only in IE, in Compatibility mode, with Java installed and a million exceptions. A good example how to host a website from 1995. -
On closer inspection, I've performed a test with another tenancy I manage and it works as expected. Comparing the emails it reads - You have been added as a guest to School in Microsoft Teams (my working invite) J Bloggs invited you to access applications within their organisation (clicking the invite link, you're sent to https://myapplications.microsoft.com/ and it's blank). I've never come across this before?
-
I've asked the user to contact the user hosting the Team (external O365 tenancy), to remove them as a guest, but also for the O365 admin to remove them from Users > Guests and start again from fresh. Really starting to run out of ideas!!
