Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ADMaster

Members
  • Posts

    1,402
  • Joined

  • Last visited

Everything posted by ADMaster

  1. A few years ago the school got all new wireless clocks. However the office I'm in now has an older style. The time is correct half the year. I honestly don't care or even look at it between my computer, desk phone and mobile.
  2. I can’t score on all fronts as some others. I have an Iboss, but it and firewall are paid for upstream as a larger package. Effective 3.5 – 4 SomeVPNs will drill right through, but that’s going to be almost all products. Ease of use 5 Value N/A Support 4 Reporting, difficult to score, I can make it send alerts to different people for different groups, however it lacks on some of the bandwidth reporting and drilling down to figure out where traffic is flowing. So a basic search terms report for a user is easy, for safeguarding. A tech view of things isn’t as comprehensive as I’d like. Flexibility / configuration 5. Very easy to configure and set different rules for different groups. I have the onsite version, they do have a cloud offering now too. We also use other tools to monitor for safe guarding. I’d also like to add a counter point to @AlanD need for the firewall to know the user / AD group. Yes it would be nice, but you can achieve similar results with Vlans. If you put staff and students in separate vlans, you can apply firewall rules based on subnet.
  3. Google also has an option to prevent printing / downloading. Google will also give you an audit trail of who opened it.
  4. To prevent what @Oaktech is saying I accomplish this in one of two ways. If it is a true re image, the same version and not an upgrade. I create a collection called TSname OSD and set an expiration on the deployment. I also remove them from the collection when they're done. In the case of an upgrade such as to 1709, I deploy to a collection targeting previous versions. Then once the inventory is done on 1709 it will drop out of the collection on its own. If its a one off re image because of issues I just use the PXE option. When re imaging a whole room the remote option is nice.
  5. Is your TS made available to clients or pxe and media only? It needs to be made available to clients.
  6. If you really want a GUI Bulk AD users should do it, but +1 for Duke5a's powershell
  7. This is how I deploy printers. I think the longest bit is installing the driver if it wasn't already there. I used to have 15-20 printers in the list, since setting up follow me that has been reduced. I've never put a watch on it, but I don't think our log in times are too bad.
  8. I guess this will just be a solo thread. I uninstalled dpm and sql then reinstalled. I think something was corrupt with the sql reporting services. I could not restore the DB backup as long as it existed on the server. After the reinstalled I dropped the fresh DB and restored the backup successfully. Then ran dpmsync. I've been monitoring it for a few days now and it seams to be working. I just have two VM's not backing up consistently, but they have been issues for a while.
  9. I have two DCs 2012r2 and 2016 so I'm at 2012 r2 functional level. My print server is 2012 r2. I don't have this issue.
  10. The last time I checked it (1-2 years ago). It did not honor restricted mode, that may be why its labeled mature.
  11. In that case it will probably be less work to install it on a fresh host and restore the database.
  12. My LEA / ISP has an Exinda. The nature of the device means no one user can have more than 1/8* of the bandwidth. Works well for most applications. It does mean I don't get full speed for off site backups and downloading from vlsc. They have their own rules, but I can call up and ask for rules to apply to my circuit so that's nice. I tested one on site, but could not justify it as the ISP had one. (about $12K a few years ago) I do a little qos with the web filter to limit Apple and streaming radio / tv and byod devices. I can check exact numbers if you like. We have 1:1 chromebooks, a cachebox and do fine with bandwidth. *In the required configuration for my ISP, greater then 1.5Gbs multi circuit (queue modes)
  13. Ah good idea, I didn't think of that, option 4 treat it as a p2v.
  14. I went the other way around too and MS has a tool to convert vmdk to vhd/x. I believe virtual box will convert between formats. I think you have 3 options. 1. If vmware has a tool for the job, unlikely as your asking. I've not used vmware for about 5 years now. 2. Use something to convert the disks. Make a copy, convert, attach to new VM with the same settings. 3. Use your backups to do a BMR into vmware. I let the systems run side by side for a time and just slowly converted a few servers at a time. Some servers were left until they retired because they just didn't want to move nicely. Although newer versions of windows handle hardware changes better. One of the servers that stayed for a while was a Linux VM because hyper-v didn't support it at the time. That won't be an issue for you because it is supported now and you're going the other way.
  15. Only 12.04 appears to be supported on hyper-v. https://docs.microsoft.com/en-us/windows-server/virtualization/hyper-v/supported-ubuntu-virtual-machines-on-hyper-v If you were planning to keep the server the best solution is to spin up a fresh box and migrate the data / services. Running that many inplace upgrades is bound to break something. IIRC network settings when through major changes in 10.04-12.04. All my Ubuntu servers are shell only, but if you have a gui that went through several changes on the desktop side anyway. If you really want to take it virtual, I'd take a full backup with something like clonezilla and try deploying that in a VM. If hyper-v doesn't work there is always vmware / virtual box. This forum post indicates a disk image created from a live CD can be converted direct to VDI. https://askubuntu.com/questions/34802/convert-my-physical-operating-system-to-a-virtualbox-disk Out of curiosity what is the server doing?
  16. Anyone? I thought I had a snapshot from before the upgrade, but do have January's monthly offsite I can go to. How will that effect the data disk with February restore points or is that why dpmsync does? Thanks,
  17. Digital signatures should do the trick. I have it setup that way for the likes of webex and gotomeeting. I've not tested log me in specifically.
  18. I was just able to right click and create a manual recovery point so confusing.
  19. My DPM server is reporting most protection groups as OK, but they all have a last backup of 2/21 I did the upgrade on 2/22. I just looked at the jobs list and a data sync was completed every day including just a half hour ago. However the newest restore point is two weeks old. I did a manual sync for a database on 3/5 and have that recovery point. Looking at the job history I have successful sync, consistency, and replica creation for various job types. VMs, Sql and User files are the main types. Anyone else updated to 1801 have this issue, or know where to look. I've just rebooted the server this morning too so will see if that helps. Thanks,
  20. I am using the enhanced editor, but I copy from the built in powershell ise. Its too late to edit my previous post so I'll install vs code and try next time. Thanks,
  21. yeah my post 4 uses code tags but its plain compared to post 7.
  22. This possibly should be two threads but I found one as a consequence of the other. The end goal is to enable credential guard which requires certificate based authentication. I setup ADCS and have issued certs to all of my machines. I have added smart card / other certificate to the default connection policy using my NPS computer cert. The peap option is still using a valid public cert. I have enabled credential guard on my machine. I created a GPO to use smart card / other cert and ticked all the cert options, also computer only. I have gone back and forth several times on settings, as of now it just doesn't connect. At one point I got an error about it not being compatible, and another the logs showed cert revocation errors. I have reissued the cert to fix the revocation chain, but as of now I'm not seeing anything in event log for my machine. This brings me to my next issue, NPS is a pain to troubleshoot. Any good log viewers? When I bring up NPS logs in event viewer the CPU goes to 100 and clients fail to authenticate until it settles down or I kill the process. I stopped the VM today and gave it more CPUs, that has helped. I came across this blog but it isn't working. I used to have ACS which had a nice log in troubleshooting interface. I can post screen shots later. Thanks,
  23. I want to know how you got the forum to color code / format your code nicely?
  24. This is not tested and probably has a couple syntax errors, but should be a good start. $users = Get-ADUser -SearchScope subtree -SearchBase "OU= [intake Year],OU=Students,OU=User Resources,OU=[school Name],OU=[Academy],DC=[DC Name],DC=[],DC=[]" -Filter * foreach ($user in $users){ $password = Get-Random -InputObject "cat", "dog", "red" $password = ConvertTo-SecureString $password -AsPlainText -Force Set-ADAccountPassword -Identity $user -NewPassword $password $password = $null }
×
×
  • Create New...