Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. If you do dism /online /get-intl Is the default OS language en-us? If so you need the en-gb Lip I think. Unless you reimage with the international ISO/WIM/Captured Image. Home PCs probably just fetch the Lip fro.. Windows update. If you using WSUS I think you have to enable Features on Demand. You may have to download the Lip from the MSVLC.
  2. Sorry for the thread resurrection. I've been fighting with this for the last few days. I don't mind users updating it themselves. Trying to get that working is hard. We have it on 150 PCs. I managed to get it to launch as system account via a SCCM package so the launcher can auto update. Given uses Full Control over c:\program files\epic games. Which is fine when downloading Unreal Engine as a standard user. But then it wants to run prerequisite Exes as administrator. I can run these as a package in SCCM but the launcher still wants to run them. In this Security /GDPR world obviously we want to get away with granting admin rights. Packaging 40GB seems excessive also it would need to deploy out of hours. The other option is to have a build and capture with a pause and reimage everything nightly when a new version is released. Projects are large and so have to be saved locally. So unless you force Onedrive On demand Files Sync you run the risk of losing student work. Having an updater that runs a Service like Chrome does would be a better solution. Anybody found a way of keeping Unreal Engine up to date?
  3. Why on earth would you allow inbound 443/80 etc to a cctv system? It's just going to appear on Shodan. It's not that hard to setup a VPN even if you have to use the Windows Server one. The new GDPR world might force these companies to do installations properly.
  4. Maybe the exam boards are hoping for schools to setup a share point site with content. Then share to the exam board eliminating any expense for them.
  5. Is it encrypted (with coffee)? This is the best thread I've started.
  6. How does smoothwall handle time outs and logging off from the 802.1x Wireless on shared devices that are really 1:1 devices?
  7. I'd love it to auto map the sharepoint site. Also have the functionality on RDS but it's not there yet.
  8. If configured correctly it doesn't download files unless you open them or save files to it. Users do have to manually click sync in a share point document library. It's early days yet in a shared PC environment for this of course it'll be better on 1:1 devices.
  9. Any reason why your not using Windows 10 1709 with On demand Onedrive for Business and Sharepoint Online sync?
  10. You can do comanagement with SCCM but on prem AD join slows things down a lot. Also when the device is off site the device is constantly looking for DCs etc. Unless you have Direct Access or Always On VPN
  11. I think MS will required Azure AD and enrollment into intune.
  12. IMHO I think only roaming profiles get cleared via the group policy setting. Delprof2 seems to work.
  13. Presumably you've allowed outbound ICMP traffic from your firewall for your VLAN range?
  14. You can force Chrome open certain sites in IE using legacy browser support. Chrome actually has a decent amount of GPO settings compared to Edge.
  15. Are you using Fqdn? If your DHCP options don't add a connection DNS domain you need to do this. Try F8 check ipconfig for a IP and ping your server.
  16. https://blogs.technet.microsoft.com/networking/2012/12/20/the-network-connection-status-icon/ Domains may be different now. Use smsniff from nir soft and restart the service, disable the nic. Then you can either let the domains through your proxy unauthenticated. Or disable the service or configure group policy.
  17. The irony... A few years ago I had to tweak Adobe Reader Protected Mode as Read Write Gold didn't work with it. Could be interesting for text help.
  18. I'd keep it local.
  19. Basically you need a paid MDM. Bear in mind MDMs usually have1:1 scenarios in mind. Also doing per user settings in Pm is limited. I have used SCCM for application deployment. It works but constantly wants to push out the software even though its installed. You can push device settings using SCCM but its labour intensive. Maybe the best thing is to just write a bash script.
  20. Could be interesting with internal sites still on http. They should be https really. Just because it's behind the firewall. Doesn't mean it's safe.
  21. You are brave people.
  22. You need Ems which gives you Azure Information Protection. You can deploy Windows Information Protection via SCCM. Of course encrypt your laptops. But as Tony says an Auto lock is really needed.
  23. Visual Studio is a beast. It's not supported on LTSC, Windows 7 is EOL in 2020. I'd try and leverage the new features in Windows Defender to mitigate 0 days. Keep everything up to date including Visual Studio. Unless you have a lot of resources for a dedicated VM Host to run Windows 10 SAC.
  24. Bitlocker is a good option if you dont have Macs. Azure Information Protection/ Windows Information Protection can tag data; stop it going to cloud services or applciations that are not approved. I think you need a month of read-only and then Deny Read and Write Permissions. Either way there will be some agro; it will also highlight any shadow IT going on to cloud services that are not Office 365 or G-Suite.
  25. Have you tried a Fqdn? Also check the logs on the mac server. If you have errors in the settings they won't apply.
×
×
  • Create New...