Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. Share X is best for this sort of thing.
  2. If MS came up with a £100 laptop then it could work. Unfortunately people see Windows and want Photoshop, Impero etc. Everything seems to be swaying to 1:1.
  3. At a former. Job we actually had seperate DNS servers. ACLs protecting the subnets. Different subnets for student, staff, guests. These days I'm thinking you need a provision ssid where devices can Windows Update etc before they are allowed on.
  4. Are you using the work profile or fully managed?
  5. Bring the mailboxes back on prem. Yes you've still got IMAP/Pop3 traffic within your network. In October MS will stop legacy authentication apart from SMTP to Office 365.
  6. Unless they mean upgrading on a SAC version can remove the drivers. You'll get away with it on LTSC.
  7. I don't think intune is ready for shared devices. If your willing to adopt a light touch then it can work for 1:1 laptops. I thought it may be good for programming PCs where less restrictions are needed. But there's no GPP. No Remote Control like SCCM and smoothwall can't authenticate against AzureAD.
  8. It was more of a cloud issue.
  9. Ouch. Password Reset seems overkill unless DC's got hit. Or it's phishing
  10. You can write a powershell script to sign your powershell scripts. Monitoring and forwarding the powershell logs is possible. You'll need to forward to a SQL Server ideally and Write some queries. This is for anything you are not expecting. E.g a student using test-connection to scan your server subnet. You really need to employ someone Full Time to monitor this and to patch everything. In education we seem to not have the staffing levels to have a security administrator which is why mainly these steps are not taken.
  11. Prehaps they should buy this? https://www.paessler.com/prtg
  12. Or someone has to give the magic money tree a shake? Every year.
  13. Use MS Whiteboard or PowerPoint your going to be paying for it anyway. We went with Lynx which can open smart files.
  14. You can put the gateway behind the Azure App Proxy which means it's protected by Microsoft's DDOS protection etc. However you can't leave Azure AD as the authentication mechanism. You have to pass through so you can't force 2FA unless you use the raidus plug in for NPS. The user won't get an on screen prompt. Also RDP gateway is only avaliable on IE without downloading a rdp file. You can use ericom access now or similar solutions which will work in any browser and safe guarded with AzureAD. Microsoft's own html5 rdp client may work with the NPS plug in but it doesn't SSO with AzureAD.
  15. Do you have a PKI? If you don't have ADCS. Do not put it on a DC. I'm not sure if Let's Encrypt can be used.
  16. Don't put a CA on a DC in production. You will be in a world of pain if you need to move it or your CRL is on the DC.
  17. Yes but I always make SCCM install it from the share created on the sever.
  18. Well I was using a transparent proxy at the gateway level. With AzureAD/Office365 domains whitelisted. This has some useful information. https://oofhours.com/2019/08/27/windows-autopilot-and-proxy-servers/
  19. I also had this behaviour. I think I hadn't let the autopilot service sync with Intune long enough. I already had profiles configured. I was going to test with a direct to firewall connection to rule out proxies. Michael Nielhaus did a blog post on how he hates proxies so I'm not sure if autopilot struggles when behind a proxy.
  20. If you allow staff/students to install pro plus in personal devices this will create a lot of support calls. The Office cloud policy service does not support the policy to suppress the install of the bing extension.
  21. HKEY_CURRENT_USER\SOFTWARE\Unity Technologies\Unity Editor 5.x EditorUpdateShowAtStartup REG_DWORD = 0 This suppresses the message box. Just add it to GPP where c:\Program Files\Unity exists.
  22. I found the registry setting. It stops the prompt. If I remember I'll find it tomorrow.
  23. If via the store or SCCM you need to have that setting disabled.
  24. Not to mention shared storage space for work. Also safeguarding and accountability of students.
  25. Hopefully it won't in place upgrade Windows 10. Make sure you have Dual Scan disabled.
×
×
  • Create New...