snagrat
Members-
Posts
2,432 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by snagrat
-
We still license through OVS-ES so the MAK keys. The in Intune there is a configuration policy to upgrade the client to EDU SKU and enter the MAK key. As soon as a Pro device joins AzureAD it is updated to EDU and activated
-
You create restrictions via Intune and deploy to Devices/Users Configuration Policies I believe they are called. It is limited compared to GPO but we feel it restricts as much as you really need. For example, hiding c: is possible only via a Powershell script and users can still browse to it via cmd or the address bar. But we don’t mind this as they can’t then save anything there as they are standard users.
-
Machines are joined to AzureAD. Users login using Office 365 credentials, which are synced from local AD (AADConnect) For us AutoPilot adds the machine to AzureAD. If you are looking to keep SCCM then you may need a hybrid setup. We didn’t bother and just went full Intune managed. We don’t image machine anymore. Unbox, turn on, let AutoPilot run and then user logs in. Apps then get deployed. If we need to image anything, we just build from Windows 10 USB image.
-
Isn’t that the issue with ADK 2004 and BIOS devices. There is a fix for it if it is.
-
I’m working on the theory you have blanked out the serial and it’s not just showing as blank?
-
I have created a script that downloads and installs the required components, creates the hardware hash file and uploads it to OneDrive. We deployed this to around 800 machines so I could upload all the hash first then it was just a simple step to reset the machine. There was the manual step of combining all individual files into one but that wasn’t too hard and gave us the ability to check the computers. Since we have had two batches of 200 Surface Go’s delivered and they get given out to the Pupils without needing to touch them.
-
Get the hardware hash first and upload to AutoPilot. Make sure the deployment profile gets assigned. OOBE the device and restart. You will be asked for Keyboard layout etc and then to join a network. Then it detects you are joined to an Org and give you the “Welcome to Org” screen. At this point you sign in to enrol the device. In future Hash can be sent by laptop manufacturer. You/They import and ship devices. End user just turns on, enter WiFi details and boom they are joined to Org. No need for IT to touch the device.
-
https://docs.microsoft.com/en-us/mem/autopilot/add-devices#collecting-the-hardware-hash-from-existing-devices-using-powershell
-
Have you imported the Hardware Hash into AutoPilot?
-
Epson projectors - a standard spider bracket fits, right?
snagrat replied to pete's topic in AV and Multimedia Related
Yes they do. Generally all Epson projectors use the same screw layout -
I use Cloudiway to do this. Costs around $4 per user and will migrate all Exchange and OneDrive data. It will also do SharePoint/Teams if you pay for the extra licenses. All runs in their cloud so no need to install anything on your servers. I mist have transferred nearly 20million emails to date with a 99.96 success rate
-
Yes you can, although my accounts seem to hit a limit of 100 and won’t allow anymore. Even though it should be unlimited for Admins. I have several accounts. Only problem with do it this way is that the device is then assigned to you and not to e Student. That just means the Company Portal does not work
-
Yes we use it for Students, although sometimes we just do it with an Admin account to get it enrolled. You can disable Windows Hello for Business, this is causing the prompt for text/2FA etc
-
I did then moved back to User Driven as some features are missing. Not sure why it is too complicated for end user? They simply get presented with a login screen for your Org and sign in, then it passes these credentials to the first Windows login as well. I never had to download a JSON file. Just imported devices into AutoPilot and ran the OOBE sysprep. On reboot they joined Intune automatically.
-
For OVS the part number is FYS-00001 at around £0.50 per FTE per month
-
Endpoint Win32 app detection rule workaround?
snagrat replied to jblackburnHWGA's topic in Cloud Services
If it’s an Msi then you can just use the msi string as detection. This will be prepopulated during the wizard. If it is an exe then you will need to specify it manually. I usually install the software on a test machine and see what path is created. Then set the detection rule to file within that new location. I’ve done C++ recently so can dig it out in a bit if you want? -
You should be able to set the bandwidth used by SCCM so that it does not kill your WiFi.
-
We sell JAMF School and do not have to charge this. Are you buying from a reseller or direct from JAMF?
-
DHCP Scope Full of "BAD_ADDRESS" - Weirdness and Carnage
snagrat replied to JRA's topic in Windows Server 2012
I’ve had this before where it is one of those plug in wireless booster things. The MAC address of bad addresses wasn’t the full length, that was a sign. Once I turned off the wireless on said device it stopped. -
Did you enable RSTP on your flunk switches in the end? And if so did you just accept the default settings? I’m looking to do the same but wonder if I need to configure them in a specific way. We have dlink at Core and Edge. And finally, did you keep loop back detection turned on for all ports of you did enable RSTP?
-
If you are the Paul I think you are then it may be helpful to give a bit of detail on your history with Education and why you are joining Zoom. I imagine many people are just seeing you as a sales guy trying to flog Zoom.
-
If the switch is tagged as a trunk on native vlan 30 then the Cambium should be set to Vlan1 Set it in AP Groups - GroupName - Configuration - Network
-
