Jump to content

jthompson

Members
  • Posts

    5,685
  • Joined

  • Last visited

Everything posted by jthompson

  1. Sounds like it could be the scripting issue with the later ADKs. When I'm in tomorrow I'll share my notes on what I had to do to get Win11 deploying.
  2. I've found that some of our models encrypt automatically according to GPO, but other don't and need to have encryption started manually. I did dig into the finer details of it (msinfo32?) and IIRC it was something to do with chipsets supporting Credential Guard or not.
  3. Maybe it heats the bread by rapidly compressing it.
  4. Yes. "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced", "LaunchTo" REG_DWORD updated to 1. I found that AppX removal during task sequence in MDT was unreliable (due to some unpredictable sequencing behind the scenes) which meant that some packages weren't ultimately removed every time. May be different in SCCM/MECM, I guess. That's why I use Mount-WindowsImage against the raw ISO, run the Remove-AppxProvisionedPackage commands and then save using Dismount-WindowsImage before importing that modified ISO.
  5. Install .Net Framework 3.5 . The Surpass SecureClient exam software requires that, so it's nice to not have to wrestle with installing that at short notice during exams season.
  6. IIRC it's about £300 and then £10 per month per school thereafter. We use ours for a whole bunch of different projects now. User provisioning/deprovisioning is one, but we also have various other little spreadsheets and AppSheet apps where a list of staff is automatically maintained, etc. We use SIMS so don't have an MIS with a proper API, but it's nice to know that our custom apps are MIS-agnostic and won't be a reason for not switching MIS at some point.
  7. It's more the odd machine in a room that needs reimaging, but can be finished in 20mins and ready for the next lesson rather than taking the best part of an hour and not being ready. That's my main reason for wanting to optimise for minimal deployment time, at the expense of an automated build and capture needing a few hours every few months to complete. Routinely reimaging entire rooms doesn't happen as often these days, mainly because the lion's share of configuration is done by Group Policy and not baked in by imaging.
  8. I'm assuming the OP is referring to how the person themselves is introduced the systems and procedures of the school, rather than the account provisioning workflow.
  9. I leave that largely to the organisation as a whole. HR hand them quite a bit of stuff when they join. For instance, it's not down to IT Support to introduce them to CPOMS, that would be someone from safeguarding. If a new starter is in our office to collect a laptop, then I'll go through signing them into Chrome, Gmail and Google Drive for Desktop: just the ultra basics. They'll have plenty of other information being thrown at them.
  10. IME having a captured image with Office and updates installed deduplicates a tonne of processing and network traffic, and halves our deployment time on the client (MDT). Would be interested to hear what others' experiences are on that front with regards to MECM and deploying captured vs vanilla images.
  11. Aim to do as much of that stuff via Group Policy (Quick Access vs This PC can be done by GPO). I remove unwanted AppX packages from the vanilla ISO prior to importing it (still using MDT here but am assuming the same principle applies). It can be done in a single command that works off a CSV. Removing them in the task sequence doesn't work reliably.
  12. I've just tested using the following Group Policy option and it works here as advertised. Computer Configuration -> Policies -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> Interactive logon: Display user information when the session is locked. Set to User display name, domain and user names. That then shows the display name as normal, with "DOMAIN\username" in smaller type underneath that. When not configured, it just shows the display name. That's on both Win10 22H2 and Win11 23H2.
  13. Do you mean username (sAMAccountName), or the user's name (displayName)?
  14. Are you using Google Workspace? If so, look at a Google Group and whether you can set each member's subscription to be in the form of a daily digest, rather than forwarding each message as they arrive. Not sure you'd have control over the timing of the digest, though.
  15. We don't have anything like that, but I'm wondering whether a group chat might be worth consideration.
  16. Buy a big tub of Cadbury's Heroes and add labels to your keyfobs that read: Returning on time: 3 sweeties Returning late: only 1 sweetie On a more constructive note, there are a bunch of new entrants into this market that make use of the Google Find My Device network. I've not used any of them, but A 4-pack of these ones is £90 - https://chipolo.net/en/products/chipolo-one-point.
  17. https://www.sciencealert.com/study-links-preference-for-loud-cars-to-some-unsurprising-personality-traits
  18. RE: Flex, I'd be worried about burning through licenses when machines need the OS reinstalling. With Chromebooks that's not really an issue as on the odd occasion where a device has needed to be powerwashed, the license sticks to it after reenrollment. I don't yet know whether Flex devices would behave in the same way.
  19. If it were me, I'd first look at getting some dummy keytags that look like tracker tags but are just a lump of inexpensive plastic, and see to what degree that encourages human compliance.
  20. Would that one-off license for ChromeOS Flex be transferrable between devices, do you know?
  21. As long as this doesn't mean having to install some flaky vendor-made smartphone app that does some weird WiFi hotspot shenanigans in order to begin any kind of onboarding.
  22. No experience of deploying iOS devices here, but I can safely say that Chromebooks are an absolute dream for us. The more embedded Google Workspace is in your school's way of working (particularly Drive, Docs and Classroom), the easier Chromebooks will slot in. If the Google life is all very novel though, then it may take a little bit more mental gymnastics for people. In many cases for us, they are a fit and forget. I notice that you say you'd need GWfE Standard licenses. You won't necessarily need that for deploying Chromebooks, but you would need an Enterprise Upgrade license for each Chromebook in order to manage the device. The pricing for that is less clear these days: most web search results indicate that it's an annual cost, but edu tenancies can still purchase them as a one-off perpetual license for the life of the device - https://support.google.com/chrome/a/answer/9147838. -- Edit That's all with regard to Chromebooks, and not ex-Windows devices running Chrome OS Flex. AFAIK Chrome OS Flex is a £35 annual license per device in order to mange them within Google Workspace, which you'd need to do in order to do any locking down of the devices' settings.
  23. 'Sustainable' is perhaps not what I mean as much as 'low wastage'
  24. Interesting RE: leveraging the 'Visit a class' feature. Do staff leave specific cover work in their Google Classroom classes then? How do you manage it with external cover staff?
  25. That was our experience, too. Even mounting a network-hosted ISO copy of a purchased disc fell foul of licensing. We needed to purchase X number of copies in order to have X concurrent uses, all running from local, physical discs. IME anyone who isn't me is terrible at keeping optical discs from looking like they've used to polish the floor, so it's hardly sustainable.
×
×
  • Create New...