-
Posts
1,402 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ADMaster
-
[Request] Looking for a script to pin Office shortcuts to Start
ADMaster replied to ashleylewisms92's topic in Scripts
It sounds like you need to look into the start layout XML.- 17 replies
-
Could you not give it a reservation on the DHCP server?
-
[iphone] Managing iPhones/"Shared" iPhones + GPS tracking
ADMaster replied to karlr's topic in Mobile Devices & Tablets
Change the workflow. Push a generic wifi profile that's one less step for the user. Install the gmail/ outlook app All the user needs to do is sign in. Then when it gets returned do one of two things Remove the account from the app and pass it on as is. Wipe / re enroll / set location yourself so it's ready for the next user. Then use the email app. -
[ltsb, 1607] Slip steam updates in to image being deployed by MDT / WDS
ADMaster replied to kennysarmy's topic in Windows 10
There are scripts out there to collect the msp files from a patched system. This is the first result on Google https://github.com/OSDeploy/Microsoft-Office-Updates I use a script like this, but don't recall what site I pulled it from. It says office 2013, but works for 2016 too. -
[ipad] Retrieving older version of app from iPad?
ADMaster replied to Bev's topic in Mobile Devices & Tablets
My knowledge is dated here but worth trying. I had a first gen Ipad we’re talking 2010 IOS 5. When I synced the ipad with itunes on my PC it put copies of the apps / ipa files in my music library. This path still has ipa files today. Music\iTunes\iTunes Media\Mobile Applications Would an older version if Itunes allow you to do a full backup / restore? It sounds like Apple has changed things, but worth exploring. -
Yes I disable it via GPP.
-
What specs / memory settings is everyone running this on. javaw.exe goes not responding after a while of trying to load.
-
[closed] improvement: New Windows 10 forum prefix
ADMaster replied to Arthur's topic in EduGeek.net Site Problems
On the note of saving space, can we shorten the prefixs to numbers only. Sometimes the prefix is longer then the thread title. I think this site has very small font so at 150 zoom all I see is prefix and a few words. On the MS office 2016 / O365 prefix, the thread title is cut off at normal 100 zoom. Thanks, -
@FN-GM are you still running both O365 and Gsuite? I'll have O365 mid July when the agreement renewal is processed. I'd like to be able to make users change their passwords at first log in. Thanks,
-
When Meraki free did not support push apps with the vpp device license that came with IOS 9 I moved from Meraki free to profile manager. I spent hours on the phone with apple and eventually bought Meraki. I gave it a good month and a half of effort. I don't recall all the issues I had with it but, I think the biggest issue was bulk actions. I had about 250 devices on it. Meraki Pros were ease of use, worked off site, had the location map, reporting on what device have / are missing apps. Ipad use is declining, we're still on ios 9 with ipad 3's so I don't really need all the bells and whistles. I just want to silently push vpp apps to devices, set restrictions and wifi profiles. Off site / map would be nice for when a device grows legs. Reporting to troubleshoot issues. In meraki I find the device and can see a list of actions, it may say no vpp license available. Profile Manager I'd have to dig through log files and may or may not get as helpful info.
-
Sorry to hijack, but does anyone have experience with both Mosyle and Intune? Our agreement is changing this summer, in MS is basically forcing cloud stuff / Intune into the agreement. I’ve been paying for meraki but it’s a bit expensive. I was considering switching to Mosyle this summer. What’s better, Mosyle or Intune? Thanks
-
Our school used media cast years ago, it was expensive so we did not renew. It was windows media based running on server 2003 back then. At home I use emby it has a great netflix style interface. I can set parental controls create custom channels and categories. I can hide a particular category regardless of rating if I choose. The ldap bit is a premiere feature just released so worth looking into. https://emby.media/introducing-ldap-support-for-emby.html
-
What are your client OS's and office versions. I shut down KMS a couple years ago and setup active directory activation. IIRC its win 8+ and Office 2013 + that support it. As soon as a machine is jointed to the domain, it is activated.
-
I should probably break this thread off, but I’m having trouble getting one drive to remove in 1803. Onedrive doesn’t seem to work, but the icon is still in the start menu. The method that has worked for the last several versions involves a few reg keys and adding the onedrivesetup.exe /uninstall command to the runonce key. I tried calling the uninstall from a run command set, but it erred. I also tried calling it through pdq yesterday and it returned an error code, but the icon was gone. I didn’t get a chance to test the time, but it seemed faster. I just did another image with the pdq method and the icon is there and took 10 min for the first admin login. I don't know if this is part of the problem or something separate. Thanks,
-
I found a site that then linked back to a technet article, read the blue note section. https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc753448(v=ws.10) Loopback is permitted on servers by default, but not clients. I've never tried to target a client until now. With only 6 clients I shouldn't hit any SMB concurrent connection limit. I know this ins't the best practice, but its a stop gap until the software gets replace with the hosted version next year. Thanks again Steve, searching the correct terms allowed me to find it.
-
I have local profiles and everything is done during OSD. I did notice one drive wasn't getting removed properly so I'm imaging again and will give it another go. My process... standard OSD format apply wim etc. run customization scripts, branding, startup repair, pc reset, 3d objects, onedrive, start layout, file associations, remove apps, consumer experience, edge icon, chrome first run, defender first run, print drivers. Some of those scripts such as chrome and defender first run modify the default ntuser.dat file. Then I install software. Adobe reader, chrome, drive fs, vlc, office, lanschool, enable cred guard, June CU and then gpupdate. I'm running the image again without the June CU and office to cut time. I should be able to post results within the hour. Thanks,
-
Hello all, A bit of background, we have a program that relies on a file share for a shared access database. The share was on server 2016 file server and accessed via dfs. The manager program runs on a win 10 machine pointing to the dfs path. Clients also run on win 10 pointing to the dfs path. Due to performance ( really need a san but that's another topic), I moved the file share to the manager machine and re targeted dfs. The clients can access the program just fine, the manager gets accessed denied. However the manager can access the files by going direct to the share or locally. The quick fix would be to point the manager to the local path, but I'd like to fix it properly. From the win10 machine; \\namespace\target access denied \\win10\target works share permissions are everyone full control, NTFS permissions are administrators, system and program users full control. I suspect there is something in windows 10 / client OS that doesn't allow it to access dfs name space to itself. I setup another DFS target to a share on my own machine and it gave the same results. I even gave everyone full control. However if I go to the server 2016 file server I can access the dfs targets just as a client would. Thank you,
-
I'm testing 1803, I have two VMs with identical specs, same host, same physical disk, same OU. I noticed in 1709 the very first logon after an image is slower then the rest, I don't know if its still downloading content or what. 1803 takes 10+ minutes to logon for the first time. They are not exactly scientific and some seam to be contrary, but here are my tests. I repeated the test twice by reverting to a snapshot and rebooting. Anyone else seeing these login times. TEST 1 1709 first logon first boot 2:13.63 1803 first logon first boot 10:41.77 1709 subsequent 20.53 1803 subsequent 24.56 1709 new user second user logon after boot 47.48 1803 new user second user logon after boot 1:09.7 1709 new user after reboot 45.60 1803 new user after reboot 49.59 TEST 2 1709 first logon first boot 2:00:13 1803 first logon first boot 11:12.18 1709 subsequent 14.66 1803 subsequent 45.08 1709 new user second user logon after boot 37.15 1803 new user second user logon after boot 1:08.81 1709 new user after reboot 49.15 1803 new user after reboot 28.94
-
Last name first initial last 4 of MIS number. Joe Bloggs ID# 9871234 bloggsj1234 Never had a duplicate with this method even with twins. Jane Bloggs ID#9871235 bloggsj1235 To the safeguarding aspect, some schools around here only do numbers too, advice from years ago. However I agree if they are to the point of giving out their email, they have probably given away much more on social media. This method only gives away their name and not an approximate age. I have rules setup that prevent younger students emailing outside of the domain, so that negates most of the safeguarding argument.
-
Yeah I did similar and broke my contacts from syncing. In my mind the contacts app had permission so it should have worked, but as Steve said its a middle man / api thing.
-
Hello all, I was just told today by my account rep that my volume agreement will be changing. I can stay on the current plan for a years grace period, but then I need to switch. I currently have the desktop bundle, I don't have any online services setup. The new agreement will put me on the A3 which includes aadp p1, intue for edu and ATA. Over they years we have had 4 domains internal ad school.school.k12.state.us email school.k12.state.us new gafe domain schoolname.org shorter gafe domain, primary email and sign in now, schoolinitials.us Schoolname.org does not need to transfer If I run azure ad connect all my computers and users are in the local ad of school.school.k12.state.us, but every use has a UPN of [email protected] When I migrate do I just add these two domains, and will both computers and users sync correctly? I don't plan to use O365 for email, but the azure ad and intue look nice. I've read quite a few docs this afternoon, but any pointers welcome. Thanks,
-
I've got mine sanitized of school specific data now. Nicks looks much nicer and connects to sims for you, but here is mine if you want to take a peek. A few notes; I put the student ID in the pobox field this is the unique key for all changes I work from students grad year, not intake like many of you. All students are put into a security group of their grad year, and have that put in the description field. The description field can then be parsed to identify grade level changes in case of early advancement or failure. I have multiple buildings that are accounted for in the OU structure. All the aup check stuff is commented out, it caused a catch 22 when we went to online forms. This is designed to be run as a scheduled task and will email you a change report. It connects to an sftp server to download the data as my SIS not not on site. After cleaning this up I've noticed a few changes and cleanup I can do, but here it is, as is. addusers.txt
-
I assume sims is capable of an automated csv export? I wrote a script that has two foreach loops at its core. One loops though the csv creating new accounts, the second loops though the students OU disabling accounts that are not in the csv. It does much more, but that's the gist.
-
I just deployed 1803 to a VM with all my 1709 settings. The first two items that caught my attention are onedrive and edge. Edge is an icon on the desktop now. It is on the user desktop and not in public, I also don't see it in the default profile. So I'm not sure where it is coming from. It gets copied over to a redirected desktop too. One Drive is in the start menu,but doesn't appear to be functional. The article linked a few posts up mentions quickassist. I missed that in 1709 so it is there too. And of course mixed reality that we never could remove.
-
Everything I've read indicates most new features require an MS account for subscription to take full advantage of them. I've not looked at it myself yet, waiting until it hits vlsc. Timeline, personally I couldn't care less, but we do not have o365 etc, users are on local AD. So there is no syncing across devices. Security improvements most are behind an ATP subscription if I'm reading it right. New deployment features, nice, but what have is working well. 1709 has been a solid build for us, so may stick with it into next school year. Given that I'm on local AD no MS accounts and no subscriptions, are there any compelling reasons to upgrade?
