Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. Don't think so. Can they not just register for AzureAD Self Service Password Reset?
  2. Most of the exam boards think you have a dedicated exam IT Suite where you use a dedicated user. In reality the PCs edu orgs use are very shared devices.
  3. It's the same with defender application guard. I don't see any logic by restricting it to the enterprise SKU.
  4. I'm slowly readying 1809 due to the longer support life. If I can automate the image creation it doesn't matter when I release it.
  5. If its secureassess I'd stick with the default. It needs to be able to self update as any user.
  6. Yep just over a year to go for support. You won't get any alerting without SCCM.
  7. I believe so the actual DFS config can be found via ADSIedit. When a namespace is removed it is removed from AD.
  8. Turn on auditing and forward to a server and pull off proxy logs?
  9. 365 Proplus had less issues than with the Old VL version. I had to pull patches before that broke functionality. Like it all not its all leaning to Office 365.
  10. Update your Admxs. Create a test OU. Put a test VM with Windows 10 edu block inheritance . Join the domain and tweak the computer GPO settings. Then create a test user and do a user GPO. Try not to use any Windows 7 policies as a lot has change in Windows 10. Use MDT/Configmgr to create images. With just over a year to go for Win7 support this Summer may be crunch time.
  11. You could force all users to go through a VPN/RDS and not allow any data on personal devices. I can't see not being able to use email on your phone unthinkable.
  12. The WIP only works with 1:1 scenarios. It affects all users of a shared home device. Other than that it's rock solid. You can deploy.it using Configmgr I think.
  13. You can actually force encryption of files and monitor if they appear in Dropbox etc. It all boils down too cost of fine + damage to reputation vs trusting staff to follow policy.
  14. It can depend on how quick you need to reimage PCs. If you can automate the image creation say via MDT you can still use a hybrid image. I deal with some large parts of pieces of software and imaging still has its place. You can apply a Culmative update when imaging to bring the image up to date.
  15. I got a bit more information. Looks like a seperate licence will be avaliable for education in the Admin Console, the bad news is user logins are mandatory so it looks like you have to sync your users to the admin console. Then assign a device licence which doesn't count against the user activations. We won't know until Q1 2019. I can share the scripts I have at present which are only used for home use rights for staff.
  16. Yep and pushing it to LTSC which means it's not really current. If your a gsuite org it may work. Once you get round the Chrome extension issue on UPDs. I have 400 thin clients and also use it for remote access. It'll be interesting with MS licensing over the next couple of years. I have no issue with Microsoft 365 but it seems RDS is being ignored. Trying to gauge the cost of WVD is going to be difficult. Interesting the SKU is on the 1809 ISO. Maybe MS are expecting pushback.
  17. I've got Smart Notebook 11.4 running on Windows 10 x64 1709 and not had many issues. Though it is a ticking time bomb. Trying to move staff to use PowerPoint, the builtin Windows 10 functionality, the whiteboard app. The export to PowerPoint function is broken unless you have a legacy version of Office installed.
  18. I would seriously move away from RDS. Microsoft only seems to be investing in Windows virtual Desktop on Azure. There are many things that don't work as required in Server 2016 Onedrive sync client, store apps. I don't think Server 2019 will be any different. I'd stay clear of Onenote as the desktop app is EOL and there isn't an alternative on RDS other than the website. If your not a Office365 org you may get away with using RDS. The black screen issue is to do with per user firewall rules being created when a user logs on. The latest CU on server 2016 mitigates this with a reg key. But I would look at moving to standard PCs.
  19. Can they make a browser that doesn't eat up so much memory. Chrome, Firefox and Edge all seem to gobble up memory.
  20. I think you need to be on 1803 to be able to do SSPR from the logon screen. All your PCs need to be hybrid joined to AzureAD.
  21. Yep wait and see. Currently named user licensing only supports 2 activations per user. Which is fine if your doing 1:1 devices but most edu orgs are not. So we will see. I think we'll have to sync lists of PCs up to Adobe's cloud.
  22. Turn 2 factor authentication for the student or conditional access. Depends if you have these setup and if the student is primary/secondary/fe/he. Maybe restrict the account to only be able to send to internal addresses for now.
  23. The thing is store apps install per user so unless your script can add the minecraft app to be provisioned for all users. You can force sccm to update the machine and app deployment policy on the client. https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains To control the joins switch this to disabled across your domain. By default. The AAD join is set to enabled. Then isolate an OU with a test PC with the setting enabled. You may be able to just add that OU to AD Connect while testing. OpenServer Manager, and then go toTools > Group Policy Management. Go to the domain node that corresponds to the domain where you want to disable/enable the auto-registration. Right-clickGroup Policy Objects, and then selectNew. Type a name (for example,Hybrid Azure AD join) for your Group Policy object. ClickOK. Right-click your new GPO, and then selectEdit. Go toComputer Configuration > Policies > Administrative Templates > Windows Components > Device Registration. Right-clickRegister domain-joined computers as devices, and then selectEdit.
  24. Yes to provision modern apps PC must be hybrid joined. If your using AD Connect there is a wizard to run and some domains that must be allowed through your proxy so that PCs can reach them. You can control the rollout via group policy. I'd start with a test PC and see if any intune policies get applied. The SCCM deployment method means everytime there's an update you have to push the update. Updating via the store is preferable.
×
×
  • Create New...