Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

ADMaster

Members
  • Posts

    1,402
  • Joined

  • Last visited

Everything posted by ADMaster

  1. Its a small world, systemax was my go to supplier about 5 years ago, It went down hill when my account manager jumped ship. I still have a few of their PCs in service. The big brands trying to cut out their resellers has happened here too. I had two companies contact me directly after getting a quote through a reseller.
  2. In my test VM login with a new local profile is less than 30 seconds. I'll have to see how that translates to real hardware.
  3. Exactly, a bit of cloud dashboard would be nice, or build it into SCCM. Speaking of SCCM how does all this new defender stuff fit with it. I'm a GSuite school so don't plan on doing any of the cloud MS stuff anytime soon. Azure AD / ATP etc would be nice, but I can't justify the cost. Moving to SCCM cost wise was cheap compared to other AV solutions at the time, but now I have to have multiple subscriptions if I want to fully utilize it. Every release of Windows is pushing more cloud and less on premise.
  4. That all looks nice, but where do I get access to those dashboards? Last I checked those were all an extra subscription, but he mentioned premium feature. Does that me some of it is included with my current EES / SCCM license and some is extra? EDIT: the articles I found all asked me to sign up for a free trial. Anyone have a rough cost?
  5. Looks like I won't need that reg tweak after all. A lot of new defender policies to test and configure before the upgrade.
  6. Downloaded from vlsc and swapped it into my test W10 TS and deployed to a VM with no other changes. It went surprisingly well. A few tweaks I'll have to make such as removing the people icon, I've already found the reg key for that. I'm disappointed the settings page visibility GPO isn't per user yet. I'll have to upgrade my ADK tomorrow now that it is out. Any word on the 1709 ADMX files or should I just copy up from the client install?
  7. I'm glad to hear that, I'm hoping 1709 will address a driver issue I've been having. How much time will this add to deployment? I'd think the wim will be much larger this time around?
  8. I run this in between terms or when i notice space being taken up by recycle bins. $studirs = gci d:\Students\ -Recurse -Directory -Attributes h -Filter `$RECYCLE.BIN foreach ($stu in $studirs ) { $dir = $stu.FullName echo $dir $colItems = (Get-ChildItem $dir -recurse | Measure-Object -property length -sum) "{0:N2}" -f ($colItems.sum / 1MB) + " MB" $total += $colItems.Sum Remove-Item $dir -Recurse -Force } $totaldel = "{0:N2}" -f ($total / 1gb) echo "Total Deleted $totaldel GB"
  9. You can create your own package in PDQ free to do the job. you need to extract the msi and use the correct silent switches. However the paid version is well worth the money.
  10. I found a company to buy all mine EOL chromebooks last year. but that model was the only one to use that screen. A new screen here is between $60-$70. If the screens will fit models you still have in service part them out and recycle the rest. I would not sell to staff, they'll still want you to support it. If the screens won't fit anything else, I hope you can find a company to come in and take the whole lot off your hands.
  11. I don't use it but I read a while back about Amazon glacier. https://aws.amazon.com/glacier/ Cheep to backup, costly to restore. I have my backups on a server in a different building across the site. so semi online / private cloud.
  12. I'd like to link a few systems there are just some I don't feel comfortable touching. HR is done by HR and its archaic not going there with any scripts. Door fobs requite someone programming the fob anyway so still manual. But I'd like to automate the deactivation of them if I could. Again not one easy to link with. The golden system so to speak would be MIS / AD. Staff are created with a script so they are consistent, but not automatic. Its a script I run and fill in the details HR give me. Students are automatic with MIS to AD AD goes to Google MIS goes to clever MIS also goes to kitchens / busing software A few stubborn sites require I upload a csv direct to them. When a student leaves their account is disabled automatically. Every summer I create / share a spreadsheet with HR tracking any new and leaving staff. Give HR a list of staff accounts to verify. On the rare occasion staff leave mid year I'm usually notified and asked to remove their access.
  13. One of my suppliers has a computerized engraver / laser cutter. For an extra fee they etch the school logo onto the laptop lid. Or just the school name / asset ID. Never taken them up on the offer myself, we still have bar code stickers.
  14. @HPlum78 Interesting reads, thanks. I probably fall into the last paragraph of the first link, that's the way it was done with VB and Batch. I'll consider using the other options but for debugging as I explained echo is just easy.
  15. If your reading an entire webpage there is the option to share to read now and share to add to reading list. Just in the way you can copy text, you can copy a link and it will read the whole page. It will also open downloaded files, txt, epub, pdf etc. I've never used PDF though. Here is the user manual @Voice Aloud Reader Manual It looks a bit outdated, but still has good info. I use this every day, and not found anything better. If you do find something else let me know.
  16. Was anyone accessing the old path while the copy was going on? Do the logs report any errors? If yes to either, make sure the users are using the new path and run again to catch any changes they made on the old share after the copy process started.
  17. not quite, if you do that my script will look for a Downloads folder in every subfolder of your home drive. Make a copy of your drive and a few others. Lets say E:\Shares\StaffHomecopy Then my script will find E:\Shares\StaffHomecopy\enjay\Downloads There is probably a better way of doing it too but this is what I came up with. Yes add logging, but I disagree about the console bit. I run scripts / and use echo from the console all the time. Particularly in the development and testing phase. I also run them in the console if they are one off scripts that are only run occasionally. If they are to be as a scheduled task then console output does no good. Example last week I was writing a script where the main action is to install a program but must meet certain conditions first. I'd put in a echo every stage of the if statements stating the current conditions with the install code commented out. This allowed me to work the bugs out a little easier. Also if your deploying a ps script with something like PDQ the echo statements will show up in your output log that pdq gives. In this case I can see the same results in the pdq console and a log file on the PC. Sorry for derailing a bit there.
  18. You are going to want to use a nested foreach loop. The first one finds the downloads path for each profile. Assuming the path is D:\profile\Downloads The second one loops through every file in the downloads folder where the date is 90 days old. The first two action commands echos the full path to be deleted to screen and a text file. The third command that is commented out removes that path. I suggest running on a test copy of data first make sure the echoed output is what you want to deleted. There is also the -whatif command. dir is just an alias for Get-ChildItem you can change the 90 to how ever many days you want. When your ready to delete data for real un comment the remove item line. $profiles = dir d:\profiles $date = (get-date).AddDays(-90) foreach ($profile in $profiles){ $path = $profile.FullName + "\Downloads" $files = dir $path -Recurse | where {$_.LastWriteTime -lt $date} foreach ($file in $files ){ echo "$file.fullname will be deleted" echo "$file.fullname will be deleted" >> todelete.txt #Remove-Item $file -Recurse -Force }}
  19. Best thing you can do in this case is give the firewall provider the android IP try to trigger and update. Then ask them to review the connections for that time. Maybe I'm lucky in that way, my provider will work with me to troubleshoot ports and open stuff on the fly to test things. But then ask for the changes in writing to make if official and all.
  20. Did you miss the second half of my post? Just for clarity after re reading that... @Voice Aloud Reader is in the store, the Ivona Amy voice is not. However there are free voices built in from google and other TTS providers you can get voices from.
  21. I normally use /s /e but I think that is redundant. /mir is good too. If your copping for the first time there won't be anything to delete. /mir will delete files at the destination that are not in source. So getting user directories in sync to a new server /mir is good. If its backing things up I'd use the /e so your not deleting anything from the backup. /copyall will get all the file info including acls which you may want since it is user directories. If you want output to a file add /log I usually set the number of threads, retries and timeout as well. https://technet.microsoft.com/en-us/library/cc733145(v=ws.11).aspx
  22. Can you install apps on the tablets? Google play uses 5228 but I'm not sure if that is where OS updates come from.
  23. Yes I do it all the time for a quick user backup scripts. I stack things like Desktop, Documents etc.
  24. Yes, this is the way I've done it since W8. My upgrade from 1607 to 1703 was painless, just had to adjust a few scripts and point the TS at the new wim. Here are a few items to add to your list, these are all done during OSD for me. Disable SMBv1 (don't think that will be an issue with 1709) Disable startup repair Disable PC reset Disable consumer experience Set file associations Set start layout xml Disable wifi on wired in all in ones I also disable defender first run which does not apply to you and setup theme / branding.
  25. I've done this with group policy since W7 so no need to put in image I only have a few pieces of software that require this so push it as needed. Don't use myself so OK check and check I do this with a script during OSD This may be a part of the above mentioned script will have to check Not bothered, but sure I could do this during OSD too. I use defender Done with a script during OSD slipstreamed in via the SCCM console (I know that's not what its called anymore but don't know the new term) Not relevant, do everything via scripts during OSD and forget the build / capture process. I'm sure you can delete printers enable .net / app-v and do the defender / sophos bit during OSD too. scripts for .net/app-v, script or group policy for the printers and application for sophos.
×
×
  • Create New...