-
Posts
5,684 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by jthompson
-
My Recommendations: Exam Laptops No Internet Access
jthompson replied to MatTheTech's topic in Windows 11
Dedicated exam user accounts, so that everything (AppLocker rules and web proxy configuration) is taken care of by Group Policy. Software deployments taken care of by Group Policy computer configurations. Any computers can then be employed for exam conditions without affecting their use in lessons either side. Exam-specific OS deployment seems overly complicated to me, unless I'm missing something? -
back up VMs to cloud for offsite-What do you use
jthompson replied to sarge's topic in Cloud Services
We've been using Cove Data Protection (part of N-Able) for a few years with no complaints or annoyances. https://www.n-able.com/products/cove-data-protection We don't license that directly, we have it through a supplier/MSP. -
Just like with any other Windows updates that involve a restart, I guess. The download phase would work like with any other updates, resuming as necessary after interruptions, and then if a shutdown was begun during installation, the computer would extend the shutdown phase to allow the installation to do what it needs. You'd then get the completion steps during the next start-up, before the login screen is shown. It would make sense to coordinate things to happen after hours as much as possible. They're not necessarily much bigger of an update than a regular CU, I don't think.
-
I do love a solar watch. Something very satisfying in the energy independence of it, especially when it has an atomic sync as well. Can the radio signal set the date also?
-
I'm going to say yes. That's how we have gone from 23H2 -> 24H2 -> 25H2. Once we were happy with the update on some test machines, and worked out any newly required Group Policy options to turn off any new cruft, etc, we just updated the target version in the GPO(s) and let Windows Updates do the rest. Whether it would do 23H2 directly to 25H2 idk: it may well do. In-place feature updates are not offered to the computer if the hardware isn't officially supported, though, so even if you raise the target version on a computer that's not officially supported, it will just keep applying the monthly CUs thereafter for whatever release it's already on, and it won't be offered the upgrade. I only know that because my cousin did it, but you don't know him and he lives in America now. 😐
-
Agree that this is worth considering. Take a look at https://learn.microsoft.com/en-us/windows/deployment/do/waas-delivery-optimization We have various different buildings here, so I've created some Delivery Optimisation groups and applied those via GPO, so that p2p sharing of Windows update files doesn't traverse too many switches (i.e. not only avoiding every computer downloading all updates individually, but also having loads of large update files being copied from one end of the network to the other). Each group has a handful of machines that are used regularly and get the updates sooner, so that they can have the files available to p2p to the rest of the group a few days later. Whilst "Windows Update for Business reports" is a thing that works, for free, I find it not especially useful: it has a tonne of reporting lag built into it. I prefer to monitor the OS build number of client machines, as reported by an inventory tool (GLPI), since that tells you whether a computer has successfully applied the latest monthly CU, which it 99% of what matters. Other methods of gathering OS build number from your computers will be available. I would also suggest specifying a 'Target Version' in your WUfB GPOs. Use Computer Configuration → Policies → Administrative Templates → Windows Components → Windows Update → Windows Update for Business → Select the target Feature Update version. This would hold computers off upgrading automatically from, say, 25H2 to 26H2, until you decide that you're happy to move on to that target version. When we ran WSUS, we didn't do driver or BIOS updates via it. When we moved to WUfB, we allowed those to come through, so it was another element of things to test and monitor.
-
Extensions are not necessarily required. Chrome has a native screenshot utility that can capture the entire page. Hidden away in Developer tools (Ctrl + Shift I) > Run Command (Ctrl + Shift + P) > Capture full size screenshot. Firefox also has a native full-page screenshot utility (right-click on the page > Take Screenshot). Edge. Probably. Amongst all the clutter 😛
-
Kinda. You can make items available for reservation (https://help.glpi-project.org/documentation/modules/tools/reservations), effectively allowing you to mark it as assigned to a particular person for a particular period of time. That's more intended to allow you to make a pool of devices available for people to book out ahead of time. Alternatively, you can just assign an item to a user more directly, which is probably more suited to teacher laptop assignments or other long-term, indefinite assignments to individuals. For temporary, ad-hoc loans of spare computers, chargers, etc. I made my own thing in Google AppSheet that also updates items in GLPI via its API.
-
Long time user of GLPI here (self-hosted) and I love it. I don't know if Snipe-IT has an agent or any network discovery features, but GLPI's agent is really good. All the computers will peridocially report all their inventory data (hardware components, firmware versions, OS build details, installed software) which has become central to managing the fleet (which computers are behind on monthlies, which are still running older versions of an app, etc.) It can also do scheduled inventories over the networok of printers, switches, etc. to keep details of those up to date as well. Doesn't get much love on here, but once set up it's a beast.
-
For Google Workspace, there's no 2FA bypass for onsite sign-ins, so we've had to avoid enforcing it for students. That was even before we introduced Yondr pouches. I'm hoping that someone either in government or oppostion will soon announce their intention to provide free YubiKeys for every child. There must be some reason why that announcement has been delayed for so long. \s IMHO, the phone pouches are an example of how a 'good enough' barrier being deployed at scale can bring about a decent result. Yes, individuals can have a secret phone or buy a big magnet, but most won't bother when there's a bit of a network effect with all of their friends also having to bother with the same.
-
We just use regular Dymo labels (well, Brother P-Touch) if our original branded asset tag labels are picked off. Our computers are named for the life of the device with their asset tag, so the hostname or serial number will always be a route for us to identify them.
-
Further to this, here are some repos (GitHub) for some of the software that lots of use will be deploying in schools. audacity/audacity dotnet/runtime FFmpeg/FFmpeg HandBrake/HandBrake ip7z/7zip microsoft/PowerToys musescore/MuseScore notepad-plus-plus/notepad-plus-plus videolan/vlc
-
Software release notification system: https://newreleases.io/ Create a list of GitHub repos to watch and get notified of any new releases for them. Free to use. Includes options to post notifications to Teams and offers webhooks and an API. Yes, you could do similar just with a GitHub account or some custom code to query the GitHub API, but this presents things nicely.
-
I thought this might be worth pointing out explicitly, but I hadn't noticed that since v8.8.8 there is now an official MSI installer available from https://notepad-plus-plus.org/downloads/
-
My children's school uses Arbor, so I'm a parent end-user of Arbor. Not a great experience. My #1 bugbear being that it's forcing password changes at 180 days and offers no kind of MFA. The next is that messages recieved in Arbor don't get copied or notified to me via email, which is unhelpful.
-
Yup, creating and assigning all the various roles and permissions was somehting our data office did, rather than me. They started out with the OOB "Class teacher" and "Admin" roles in Bromcom, and built out from there. In terms of timing of a migration, the two main constraints for us were the SIMS renewal date and exams. Finding a time in the year that didn't land in the middle of something exams-wise was almost impossible. We went live during the October half term break: avoiding going live right at the start of September, but ahead of as much other stuff as possible.
-
Switched from SIMS & EduLink to Bromcom last term. I guess it's 'okay'. From my POV as a user admin more than anything, I've noticed the following: Menus are all a bit confused, with things living under different top-level items. Especially for sysadmin items. e.g. Modules > Setup > System Users and Config > Setup > Roles and Permissions. It likes to load full lists of groups, students, staff, etc before then giving you filters to search down. That adds lots of friction, and presumably is less than optimal. The web UI is not responsive, so can't really be used on mobile. Even on laptops with smaller screens, taking a register involves users really needing to zoom the page out prior to opening their register. Given that it looks like it's built on Bootstrap, I found that gobsmacking. It basically forces some teachers to need to use the mobile app, when ideally they wouldn't. The mobile apps are very odd. There are three (parents, students, teachers) with no coherent branding or naming. The SSO capability of the web app isn't carried over to the mobile apps, so the teacher app for instance authenticates by scanning a QR code from the teacher's web browser on another machine, with no visibility or management of those sessions by admins. Onboarding of students feels like a afterthought that was subsequently forgotten about. Email features are not as good or intuitive for staff as in EduLink. Whilst scheduling of reports is more straightforward than with SIMS, there's no "don't output this if there are no results" option, meaning that I have empty reports sent to me each week when really I would just need to know about the odd times when they're not empty. The positives for me: You can add pages to a Favourites section of the menu, which helps on the unintuitive menu structure front. The global search box is useful for quickly surfacing individual student, contact or staff records, which was lacking in SIMS. You can search for contacts via email address, which is a welcome upgrade for me. We've just about managed to not have to continue paying for EduLink. SSO into the web app via MS or Google accounts works well for staff, with no end-user steps required in the first instance. That was helpful during the migration. SIMS Connected made an absolute meal out of SSO, by comparison. Bromcom did a thorough job project-managing the migration, including supporting our data migration from SIMS really well. Ahead of the go-live, we had access to a fully-functional test instance of Bromcom, so that we could test pretty much everything using a copy of our real data first. Overall, I think it was definitely worth migrating away from SIMS, but its idiosyncrasies will become apparent quite quickly and begin to grate.
-
I find the silver paint comes off most on the ones that are assigned to staff who take them in and out of cases or bags with a zip (especially metal zips). Or where they've stickered them up. Other than that, the silver 5000s have worked really well for us over time. The hinges on the earlier black 5000s always worked loose and needed regular retightening, but the silver ones seem better in that regard.
-
I had a job working in a big electricals retailer at around that time, and remember fawning over one of those that was on display. The year 2000 me would probably have opted for the Psion Series 7 that was slightly further along the display stand, though.
-
My thinking is that the safest place for my Seamaster is actually on my wrist, rather than left behind in an empty house! I agree with the jewelry aspect, although I'll add wedding ring to that. It sounds like a really nice list. Mine is: Omega Seamaster Pro, black dial, quartz, 36mm. Had this since new in the late 90's and was my only watch for ages. Only now beginning to fully appreciate how good it is! Pebble 2. Still just about going, after fitting a new battery and replacing the failed silicone buttons with some 3D-printed ones. Absolutely zero splash resistance as a result, and I just use it as a vibration alarm to wake me up without waking up my OH. No longer interested in getting notifications on my watch, and having near-infinite choice of watch faces is not all it's made out to be (IMHO one of those mile-wide-but-an-inch-deep things). Wenger Urban Chronograph. Bought on a whim as it looked nice on the Internet, but in reality it's too big, not a useful chronograph (30min max) and the dial legibility suffers in most real-world light. Works well on a few different NATO straps though, if I do decide to wear it. Redwood Pilot Type-B Solar. I quite like the look of pilot watches in general, and love the simple design of this one. G-Shock GW-BX5600. Only just got this. It has the new-style MIP display, with absolutely none of the viewing-angle washout that you get with the regular-style LCDs. Loving wearing it, but the alarm/timer sound is quiet and short (10s) to the point of being useless. I'd love for it to have vibration instead, but I appreciate that that might not be feasible in a solar watch with a whole bunch of shock-resistance around it. I used to have a Casio AE-21W growing up, so having a Casio again feels kinda nice. Apart from the Omega, they're all watches that I could replace without issue if it came to it, but reckon 3 good choices is where my natural limit probably lies. I'd want to be wearing them. I'm not sure I want to spend too much on any one watch, unless I won the lottery or some such.
-
Oh man, I'm glad somebody is keeping a list of offenders! It always puzzles me when SSO is not an option: it's basically some other big tech firm doing the work for them. Doesn't it mean that they can offer best-in-class authentication at no cost to themselves? I'm also puzzled/annoyed when a site offers Microsoft SSO, but not Google?! I mean... c'mon.
-
I run mine against the factory image after first importing it into MDT, rather than doing it as part of a TS. Either way, this shows you which AppX packages are being removed. The paths here may need adjusting to suit your environment. Mount the vanilla image Mount-WindowsImage -ImagePath "E:\DeploymentShare01\Operating Systems\Windows 11 Education 24H2 (Oct 2024)\sources\install.wim" -Index 1 -Path "E:\Mounted" Run the script # Create a list of unwanted AppX package names. $Apps = @( "*DevHome*" "*FeedbackHub*" "*GamingApp*" "*GetHelp*" "*Getstarted*" "*Microsoft3DViewer*" "*MicrosoftOfficeHub*" "*MixedReality*" "*News*" "*OneNote*" "*Outlook*" "*People*" "*PowerAutomateDesktop*" "*Skype*" "*Solitaire*" "*Todos*" "*Weather*" "*WindowsMaps*" "*Xbox*" "*YourPhone*" ) # Remove packages for all users. ForEach($App in $Apps){ Get-AppxProvisionedPackage -Path "E:\Mounted" | where {$_.PackageName -like $App} | Remove-AppxProvisionedPackage } Dismount and save the new image Dismount-WindowsImage -Path "E:\Mounted" -Save
-
Nice. Will Jeff Goldblum be there?
-
GCSE results will be available online this summer
jthompson replied to 6Foot2's topic in General Chat
Spoilsport 🙂
