Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. Sounds like Applocker. Could try the Applocker powershell cmdlet that tells you which rule triggered it.
  2. You can test adhoc with Drvload. exe.
  3. I think they want to head for Progressive Web apps. So eventually we'll have subscriptions, Web apps and no Win32 code. Could be interesting with Photoshop, Autodesk etc.
  4. Telling the truth about technical limitations of a product/service would be a start.
  5. It's tied to the idea that identity is going to be on the phone more and more. Think 2 factor authentication.
  6. Probably will be a fresh build rather than an upgrade. Might be worth putting a test VM on insider.
  7. Those using RDS are going to have to make some choices. Today you can deploy Office 365 Pro plus but it will be u supported on Server 2016 which is effectively LTSC. Hopefully the SAC server release will include Onedrive On demand sync and support for Office 365 Pro plus. I see no reason for the VL version particularly if you are invested in Office 365.
  8. The VL installer is an exe which calls msi's. The C2R is still setup.exe where you can download a local copy of the installer. Really you need SCCM to deploy Office 365 Pro plus or Office 2019. Updates will probably be controlled via GPO/registry and then SCCM SUP/WSUS.
  9. Try this https://www.nirsoft.net/utils/smsniff.html. Check event viewer. Does Outlook work in safe mode? Can't remember the switches right now.
  10. Pm can't seem to deal with large AD environments. I've had to go into the backend to remove printers before. It may be easier just to manage them via intune or similar.
  11. You an do a user install to a user collection. Never tried it. Though a pain when you need to update or does it self update?
  12. Well you should standardise on Office 365 of G-Suite. Azure can force users to use a work account to Dropbox etc. https://docs.microsoft.com/en-us/azure/active-directory/active-directory-appssoaccess-whatis Need a subscription though. You could of course block Dropbox etc for staff.
  13. Are they waking from a Scheduled Task or WOL? If scheduled task you could include a reboot at 5/6am.
  14. I think MS want you to really have a ATP subscription which is part of A5 Microsoft 365. Defender is probably the most widely used AV. But AV is not enough currently. Applocker or similar will stop some malware. Just keeping everything up to date and enabling the cloud detection in Defender will help.
  15. You may be able to powershell to the affected folders.
  16. The ideal from a GDPR perspective is to not print at all. As it's very easy for data to leak. Comparable to unencrypted USB sticks or laptops. Files can been controlled. ACLs, Azure information Protection etc. But it would be very hard to implement this.
  17. Anybody been able to update a bios with these silently via command line?
  18. Or you need planet estream or click view with a free view recorder.
  19. You could setup a windows vm with fiddler and point the mac to it. I'm assuming you use the same authentication method on Windows and Mac. A lot of apple stuff isn't proxy friendly or SSL mitm.
  20. Same issue. I found the UEFI firmware doesn't pass the information correctly to the PXE server. You can use DHCP options as a work around. However you may not be able to legacy boot on the subnet. Really updated firmware is needed such as when lenevo laptops had the issues. I think Stone laptops are a re-badge so it's up to the original vendor. I hit the same issues with Stone NUCs.
  21. I had this with 8th generation Intel CPUs and UEFI PXE Boot. Does it legacy PXE boot?
  22. i can see why you have that GPO. Particularly if you expire passwords in domain accounts. Telling users they have 1 password to login to the laptop which will change when reconnected back to your network is confusing. Either you setup direct access which is a VPN over https so when your offste you have access to everything you would din your network. Though you do need a PKI setup. Or you have laptops non domain joined and managed through intune etc.
  23. I tested a user GPO as you may have an AD Group as an exception. I would be tempted to run read only for a while and inform users. It depends if you want to force bitlocker to go or just ban them outright.
  24. I think ideally they want you to use named licences. However you need ADFS or Shibboleth setup.
×
×
  • Create New...