-
Posts
3,614 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by free780
-
You’ll find there are probably all sorts of internal politics where marketing wants to use mailchimp and service X and Y. The shift in governance to engage with IT is seen as ‘too hard’. Until your domain gets spoofed with some repetitional damage it’s going to be difficult to get change to happen.
-
Yep or orgs with no dmarc record! That’s going to create delivery issues.
-
It’s a business move by Microsoft. If you don’t mind being in unsupported land you can do this. https://www.deploymentresearch.com/windows-11-deployment-using-mdt-8456-with-windows-adk-23h2-build-25398/
-
If you have MECM deployed you could look at standalone media. https://learn.microsoft.com/en-us/mem/configmgr/osd/deploy-use/create-stand-alone-media
-
Windows 11 and Server 2022 are not supported in MDT. https://learn.microsoft.com/en-us/mem/configmgr/mdt/release-notes#supported-platforms You have to use Intune or MECM.
-
Sims slow load excruciating across three different schools
free780 replied to johnpd's topic in MIS Systems
Sounds like it’s the client. Run procmon. May be Anti Malware slowing things down. You could exclude the processes involved. -
Check the SAN for the correct DNS entries.
-
Am I the only person who doesn't like Intune (when used in schools)
free780 replied to _techie_'s topic in Cloud Services
One of my colleagues calls it this. I actually delved into the scheduled task that look like the exes that get triggered for a sync. I couldn’t sync via command line which would have been helpful. Other times it’s quite fast. I think a lot of the slowness is server side. Changing the image for a Win32 app got updated very quick in company portal. For testing it was easier to revert a VM to checkpoint to prevent caching. We had a licensing issue for months and was suddenly fixed after a lengthy support call. -
Am I the only person who doesn't like Intune (when used in schools)
free780 replied to _techie_'s topic in Cloud Services
I’ve had this debate for quite a few years. Even deploy VPN profiles is easier with a PowerShell script wrapped in an app deployment within Intune. I think you need MECM for Servers and shared clients. There also nothing to say that you can’t deploy from both. You get so many logs with MECM but not Intune. The idea is good but the speed is slow and 1:1 devices are the primary focus. It’s also a lot quicker to apply GPP items than having to write scripts within Intune to do the same thing. -
Azure AD, Fortinet Filtering
free780 replied to Alawil's topic in Internet Related/Filtering/Firewall
I’m using the FSSO collector with Domain Controller Agents. It works most of the time. I had to enable remote registry on clients and allow SMB in from the collector server. I tested the SAML method but thought a captive portal was a bit disruptive. If you’ve got the budget Forticlient might relay the logged on user. -
On the flip side. I’m paying for a landline I do not use and cannot cancel. With Vodafone FTTP it’s voip. I wish I could cancel as Vodafone keeps increasing their monthly cost. Zen seems to honour the cost over the contract length.
-
Denying Log On Locally to doman admin but allow runas
free780 replied to colly72's topic in Windows Server 2016
You can use runas /netonly to do this. Ideally you shouldn’t need to. Microsoft recommend you do not remove domain admins from local administrators which would seem logical. -
Yep you need to make sure there’s no SSL Inspection or security checking for the domains.
-
Does it work if you try using the IP instead or hostname/FQDN ? Presumably your Connector can rdp to the destination?
-
I found its unclear if UDP traffic is supported. I managed to get RDP to work with DNS (maybe use TCP). There is a drawback that there is no inbound access to clients as you get with VPNs.
-
Nothing like kicking the Windows 11 can down the road. We had to purchase Sophos licenses for 2008 R2. Why is it so hard to stay current?
-
Electron Memory Hog Edition Web View 2 Version for Work Web View 2 Version for Work/Does anyone use teams consumer?
-
Currently paying for a landline which isn’t used: Thanks Vodafone. The In laws use FaceTime and the landline would only get scam calls from India. Worked with an old cordless Phillips phone. There is some weird rule where you can use your own router if you don’t pay for a landline. I only needed to use a Gi.Net travel router as the Vodafone router broke on a weekend. Is it time to move on from landlines for domestic?
-
[ms office - o365] Deleting a teams post
free780 replied to chrisgreenwood's topic in Office Software
Probably need a compliance search and removal. An Export will release Teams messages as emails. -
It’s a long slog but using something like mailgun or send grid can simplify the process.
-
Why on earth isn’t certificate authentication or user authentication via SAML being used? It’s much more secure. You can disable accounts or revoke certificates.
-
This will start Teams. If you want to clear the cache. Untested so may remove some settings. I've attempted to maintain settings (why are they not they stored in the cloud?). This was due to the broken spellcheck a few weeks ago.
-
Enforced 2FA: Conditional Access solution in schools
free780 replied to AnimatedCarrots's topic in Windows
Do your students need to external access? Limit access to Hybrid Joined Devices. You can roll out certificate authentication as 2nd factor. Most likely only work practically on managed devices where you can set up user enrolment.- 18 replies
-
- 2fa
- conditional access
-
(and 3 more)
Tagged with:
-
Jan Windows update issues - Resizing recovery partition
free780 replied to TwistedHelixis's topic in Enterprise Software
I believe for Windows 11 22H2+ the patch was wrapped up in the January CU. If I can parse the Microsoft speak. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20666# -
Jan Windows update issues - Resizing recovery partition
free780 replied to TwistedHelixis's topic in Enterprise Software
If you are not using Bitlocker on the server/client there isn’t a risk. The vulnerability requires physically access. If it’s only clients that are using bitlocker. Then I would be tempted to wait to get them upgraded to win11 and do the resizing then. I did a script for clients and some servers that aren’t using WSUS/MECM. The fact that MS didn’t push to WSUS says something about the confidence of the patch. I’m going to see what patch Wednesday brings.
