Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ADMaster

Members
  • Posts

    1,402
  • Joined

  • Last visited

Everything posted by ADMaster

  1. Add get-random into your powershell reset script example #8 looks to be what you need. Get-Random If you want a gui Bulk AD users is good, but I think it will set them all the same password, or complete random.
  2. I had this issue on an early version of W10 too. The answer is to set OSDPreserveDriveLetter to false. I don't think I have needed that variable in the TS for a while now. This is a short term fix, you really should upgrade to 1710.
  3. run it as a log off script something like rd /s /q %userprofile%\[color=#333333]App[/color][color=#333333]Data\Local\Temp [/color] if you really want to do it remotely perhaps a nested foreach loop of hostnames and c:\users in powershell. What remote admin tools do you have? You can cut the hostnames foreach by deploying the powershell script via SCCM or PDQ.
  4. Gmail app here too, in addition to what others have already said, the label colors come across on it to quickly spot different emails.
  5. mostly yes, I should have enclosed it in code tags. the space should have been a plus sign + every full stop / period should be escaped with a back slash \ it almost looks like a pipe the way it is formatted now. also if you include the dash in the brackets as part of the range of characters escaping the dash, it will work the same as including it in the parenthesis with the pipe | OR These two appear to function the same. (?i)abc-students-[a-z0-9\-]+@school\.org\.uk (?i)abc-students-([a-z0-9]|-)+@school\.org\.uk
  6. I'd look at your software to see if there was any way to prefix abc-students or something similar that you can match on. If these were user created groups there is a setting to add a prefix to any user created group. However I think you will need to look into your sync software for this. The syntax I posted above will match abc-students-any length of letters or numbers then @example.com. Since you have the dashes in there this will need modified a bit. try this, providing you have a prefix to match on. The parenthesis adds grouping and the pipe indicates OR. match abc-students-any length letters and numbers or dash @example.com (?i)abc-students-([a-z0-9]|-) @example\.com
  7. I provide my syntax in post 27 it should be a matter of putting ABC in place of my slist and adding students [a-z0-9] like this. (?i)abc-students-[a-z0-9]+@example\.com The rule is also set on internal sending matching all envelope recipients. The rule has its own regex tester, but here is another one to try. https://regex101.com/
  8. I'm glad you got it sorted, I'll just leave a bit more applocker planning advice here for your migration. The default allow rules of program files windows etc cover most things with out breaking stuff. The 3 gotcha areas are... Programs that install in c:\appname we have 2 or 3 so needed to allow those. Programs that install into the user profile like gotomeeting webex etc, allow these via certificate / publisher rules. logon scripts. I have my entries listed several times just to be sure. \\domainfqdn\netlog\* \\domainfqdn\sysvol\* \\dc01\netlogon\* \\dc01\sysvol\* \\dc02\netlogon\* \\dc02\sysvol\* It may be overkill but I didn't want my scripts breaking.
  9. Well knock on wood, I don't think I have ever had this issue if I do its rare. I think over the course of the last year or so I have had to manually add the printer to 3-4 staff machines. Is that the same issue, or have other staff figured out how to add it back them selves who knows? It is certainly not a daily / weekly thing like described here. I'll compare settings if you like. Printer server 2012 r2 running papercut Clients are a mix of 8.1 and 10 1511 - 1709 All printers are deployed via GPP All clients have local profiles and I do not delete them. Let me know if there are specific settings / GPOs you want checked.
  10. Not entirely true. SRP can be configured for a white or black list approach. Applocker should be able to do a blacklist approach too. I've not tested this as I have a white list. However create a rule that allows everything for everyone, then add your deny rules. deny rules trump allowed rules. Applocker can also be configured with user groups, so you could deny word to just an AD group of test takers. Another idea, but I have no experience with... the new windows 10 test mode.
  11. You will want an allow list though, otherwise all apps will be removed the next time a user logs in. This includes things like gmail, docs, slides, camera, etc. It took me a few times of swapping a test account between OUs to find the built in apps across different models.
  12. You're in the right place under user settings, see attached. This can be done on a per org unit basis so you can block for students and allow for staff. You can also go to the app management screen to change what org units are allowed / forced installed too.
  13. The short answer is no, that is not how ssl works. We do ssl on our own devices, and do not on byod / guest devices. There are some client side options you have that would not use ssl, but forcing a guest device to sign in with their school account is another matter. Gat+ Shield can do keyword monitoring client side with an extension. I think go guardian and securly could do this too, most chromebook specific filtering solutions will rely on an extension. There are several out there. These solutions all rely on your users using the chrome browser, and signed into it with their gsuite account. I know its not the answer you want, but I'd start with doing ssl on your own devices. You could simply block youtube for guest devices if it becomes an issue. I'd think at the higher ed / college level there would not be as great of a need to filter.
  14. Its a reg key originally posted by @Arthur http://www.edugeek.net/forums/windows-10/187732-date-released-fall-creators-update-4.html#post1620206 Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{0DB7E03F-FC29-4DC6-9020-FF41B59E513A}] [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NameSpace\{0DB7E03F-FC29-4DC6-9020-FF41B59E513A}]
  15. I've deployed every version since 1511 so can't recall what changed with each one. I deploy in a VM to find changes and tweak the deployment as needed. A few changes off the top of my head for 1709 are the people icon, and the default lock screen went from img100 to img103. If you were disabling SMBV1 in your TS, that isn't needed for 1709. I added a step to remove the 3D objects folder in 1709 too. There is also the mixed reality stuff, but I never figured out how to remove it properly. I don't recall if this was a 1607 or 1703 change, but at some point I needed to add a reg key to disable defender first run ui. I'm sure there are a few changes I'm forgetting.
  16. This sounds like it applies after the job is released, but worth a look anyway. Source: Papercut
  17. I install chrome as default but users can pick what they want to use. We are GAFE so I highly recommend chrome to everyone. The biggest plugin issue is google trying to kill flash, but there are GPO's for that. I don't know of anything the average user needs activex for. I've needed it to manage some archaic systems. Gotoassist and the sort usually install an extension and work just fine.
  18. That will probably do it. When I first setup GAFE I had simple passwords for the younger students, they got a captcha nearly every time. Once they met googles minimum things went a lot smoother.
  19. We have a GAFE domain so that's configured by OU. However I did come across a new feature in DNS for server 2016. DNS Policies This will allow you to resolve a different IP based on the client subnet. It's not by AD group but perhaps you can have student IP ranges resolve restricted and normal for staff.
  20. I'm all Lenovo here so I'd go for a thinkpad e570 or e575. My current batch is e550 and I think it was the last with VGA.
  21. Do you have any rogue dhcp servers? You can check with this tool. Roadkil.Net - Roadkil's DHCP Find Program Download
  22. Its not an easily read format to human eyes, but do a snmpwalk on the ZD https://support.solarwinds.com/Success_Center/Network_Performance_Monitor_(NPM)/SolarWinds_SNMP_Walk_A_new_tool_for_collecting_SNMP_MIB_walks I ran this against my ZD and it returned address of connected clients, and connected APs. How spiceworks makes sense of that data is a different story. I also have a ZD3000, so that may play a difference. I also noticed a tick box in my ZD that is not set, but looks like it may help. Inherit SNMPv2 for APs
  23. What did you not like about Webhelpdesk? I assume the Manage engine free is only the standard version? I've used webhelpdesk for 7 years now. I'm not sure if Manage engine had the free offering then. Back then my top picks were webhelpdesk and sysaid. Sometimes I consider moving to something free just for the price tag, but dread migrating ticket history. I also use the asset / parts / PO piece albeit not as much as I should.
  24. I use f.lux at home https://justgetflux.com/ but color veil looks better suited for this task. On somewhat of a related note I had a user make their screen go monochrome with that new shortcut. Odd I just read it in the other thread yesterday and it happens today.
  25. I use NPM and I have the zone director setup in it with snmp. It pulls in all the APs and gives me their status. I get connected clients with signal strength etc. If spice works doesn't do this for you, you may try downloading the mib package from support. Does spice works let you configure custom pollers / query OID values?
×
×
  • Create New...