-
Posts
12,849 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Michael
-
It was 13th > 16th February. Currently cloud only, be will be AD synced shortly. Currently duplicate users/temp duplicate passwords have been created for on prem, then I'll marry the two together. Everything else is working, but just wondering if it's other O365 tenancies which are somehow caching the old account details? It's just really poor if this is the norm from Microsoft.
-
Anyone any thoughts, even if it's just speculation?
-
Morning all, I recently migrated a school from one O365 tenancy to the other, whilst maintaining the same domain. Old accounts were renamed to [email protected] which freed up the native domain - nativedomain.co.uk This has all worked as expected, however Teams has been a real problem. If I sign into Teams as [email protected] the user was/is a guest member of other Teams external to the organisation, however interestingly if I select Manage team > Members and guests they're still listed as [email protected], when I'd expected the account to read [email protected]. Is this normal, or is it anything to do with this O365 tenancy being managed by a local authority? I've requested the user signs in as [email protected] and leaves each Team in turn, then sign out. Ask the owners to re-submit the invitation, which of course should go straight to [email protected] Does all this sound correct? Any pointers would be appreciated.
-
Any prefix of some kind is helpful, depending on how big your MAT is. Remember structuring your OUs properly, it isn't always necessary to specify the room. You could always label the OU the room.
-
Are the SMTP settings on the MFPs themselves and if so what make/model, or are you using something managed like Papercut MF?
-
That's how I've done it too - a single properly named domain in a forest, with each school in its own OU. All user and computer objects then belong under this OU. It also makes it easier/simpler to share the same GPOs where possible instead of doubling up on work. Each site still has its own subnet, but it's just a case of creating some reverse DNS zones and everything then just resolves as expected.
-
If you have an unused or alias domain, you could always set it up with O365 (as one suggestion)?
-
On the surface, the settings look identical to O365 looking here You've verified the password hasn't expired (would be my first thing to check), but then presumably the firewall is set to allow smtp.gmail.com ? I agree that on newer devices, you can check whether smtp.gmail.com (just as I would smtp.office365.com) is resolvable, directly from the MFP which is useful. Presumably it's resolvable on a workstation? The only other issue I've come across before, is that MFPs themselves can and do have a self-signed certificate embedded within the firmware, whether this has expired?
-
Once all keys are restored, you can export all to a CSV file directly from VLSC which is handy.
-
Unfortunately no, other than stick with basic graphics, which is fine until someone plugs in a VGA or HDMI cable and get nothing. LTSC19's absolutely fine and is a mature OS.
-
I'm currently working on an HP 255 G7 with LTSC19 on it. If the HP 250 uses Intel UHD graphics (I suspect it does), like the HP 255, you will need LTSC19 or stick with basic graphics (not recommended).
-
Google Chrome all the way, given for years it was solid/reliable and controllable via GPO. It's the new Edge which has now aligned itself with Chromium. I never actively used or deployed the old Edge in a live environment, only test environments. I can't help but think it'll be Microsoft always playing catch up, given it's Google who control the source code. I know Microsoft can optionally add features and tweak the GUI, but I think it's still very much in its infancy. Give it 12 months and I think the differences will be more noticeable.
-
LTSB/LTSC support lifecycle cut to 5yrs for 21H2 release & later
Michael replied to computer_expert's topic in Windows 10
As above, LTSB and LTSC are essentially the same/equivalent to Windows Server 2016 and 2019, but without the server components. Why you wouldn't want the same stability and longevity to support your users, I guess it's very subjective. I've deployed LTSB and LTSC for years without issue. I also can't help but notice Windows 10 releases - such as 1507, 1511, 1703, 1709, 1803, 1903, 1909, 2004 and 20H2, which all fall out the scope of mainstream server releases are far more troublesome than 1607 and 1809. I don't think this is a coincidence. The only recent limitation I've come across is the lack of Direct Access in LTSB/LTSC versions, but other than this, I've not had the issue where a user requires a specific Windows app. The vast majority of educational resources are either a legacy app, or a browser based service. I suppose the only irony now that Microsoft have made this announcement, is a newer LTSC 2021 will expire before both LTSB 2016 and LTSC 2019 and likewise the same with Office 2016/2019. It will be interesting to see if this model will apply to Windows Server 2021/22, as it will greatly shake things up in terms of upgrades going forward. -
Have a look here. This is what I've used on many hundreds of devices.
-
I should add that once the January/February 2021 patches are applied, the startup sequence then returns to normal.
-
I do exactly that for some users - redirect their Desktop so it's a subfolder of Documents using GPO.
-
I've seen this happen with January and February 2021 updates.
-
It sounds like the classic the school are the legal owner, but the LA are the technical contact and process domain record changes. This is absolutely fine if you have no IT support, but the LA should still add/remove whichever domain records required. With O365 they all follow a standard pattern in my experience.
-
I'd look at a different domain extension, there are absolutely loads out there. I do agree though, the shorter the better. You can still keep your .sch.uk as an alias.
-
Hi all, This patch is massive and I've already started to deploy to Windows Server 2016 servers. A description of what it plugs is here including a zero day vulnerability. One thing that caught my eye - This also enforces the RPC lock on DCs, first reported in August 2020 (Zerologon).
-
Replying to students in Google Classroom
Michael replied to WannabrewUK's topic in Internet Related/Filtering/Firewall
This issue appears to be fixed now, all reports have gone quiet! -
Replying to students in Google Classroom
Michael replied to WannabrewUK's topic in Internet Related/Filtering/Firewall
Definitely not working - I've tried VPN'ing into site, launching Chrome and the same thing happens with Google Meet. -
Replying to students in Google Classroom
Michael replied to WannabrewUK's topic in Internet Related/Filtering/Firewall
Google Meet appears down too, as of 18:50. -
I've had a read of these notes and plan on testing on a small site. Other than removing the Intranet location and Client side targeting GPOs, as well as enabling/configuring Feature and Quality GPOs, the policies have remained identical. The Quality updates in particular are deferred for 30 days from the point of release. They'll be using Windows 10 LTSC 1809, patched up to December 2020 as standard. A lot of the services they use are cloud based, rather than legacy, which also influenced my decision on this. I'll report back in a few months (if I remember)!
-
Thanks all. There's a good guide here. In summary you need to setup a downstream replica (not ideal for smaller sites) and place it in in the DMZ, apply an SSL cert and manipulate DNS. I don't know what the risks are exposing ports 8530 and 8531 to the internet, even if it was in the DMZ? The guide also describes to enable 'Do not store updates locally' in WSUS, which leads me to think it's pointless, as all clients internally will download from MU anyway. If I did store updates locally, it would then put a lot more stress on the WAN uplink. I'm a bit stuck on this one. Yesterday I downloaded/imported the latest 20H2 ADMX templates, just to see if there any new enhancements or options.
