-
Posts
1,402 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ADMaster
-
I believe the OP is referring to wifi connections not PC logins. I don't have an answer either but hope I can get you in the right direction. At a tech show last year extreme was advertising this technology but of course that isn't cisco. Have you looked at Cisco's authentication server? It may have rules you can apply, I've switched my radius to NPS so haven't used it in a while. I believe packetfence will do what you want, but I've never got around to setting it up.
- 8 replies
-
- 1
-
-
- active directory
- firewall
-
(and 2 more)
Tagged with:
-
OK sorry about that, let me add all the details. I decided to deploy with the hardware readiness tool using options -cg -enable -autoreboot. I chose the tool because it will allow me to target a few test machines at a time, can be pushed with PDQ and writes reg keys that PDQ can read for status information. After I pushed the script with PDQ and the machines rebooted PDQ did not see them as online. I went to the machine and noticed wifi was not connected, I plugged it into a cable and ran gpupdate but no joy. I did a quick google search for credential guard breaks wifi and found this. The blog details event ids, but in short peap / mschap v2 are not supported and you must use certificate based authentication. This fact is a little one liner in the system requirements easily overlooked. I deploy our wireless settings via GPO it is set to use wpa2 enterprise aes+ccmp, peap (mschap-v2) and use computer authentication. I have ruckus pointing to NPS running on server 2012 r2. I have no PKI setup atm, so I need to set that up then figure out how to do certificate based authentication before I think of this for all staff. I did enable it on my PC and will enable it on a suite of the M73z's as they are wired in. I copied the script to USB and ran it with -cg -disable -autoreboot and the wifi connected as it should with no issues. Also to answer one of my own question for anyone else's curiosity. I configured both a 1511 and 1703 machine to use CG via local GPO when they were on legacy bios. It did not crash I just got errors in the event log, that must have been something else I read about.
-
The wider roll out for this may need to wait until next summer, I just found out it breaks wifi authentication, I'll have to setup certificate auth for this to work.
-
I was overlooking a separate option in bios specifically called secure boot. I thought UEFI by its nature was secure boot. I'd still be interested to know how others are deploying this. It looks like the hardware readiness tool will be most flexible, unless I add a ton of wmi queries to a GPO.
-
I'm planning to roll out credential guard this summer and found a hardware readiness script from Microsoft. It reports that secure boot is not enabled. I am testing on a Lenovo M73z All in one. CSM is disabled and it is UEFI only, this should be secure boot right? When I boot up, I get the lenovo logo instead of the windows logo. I also disabled quick boot as a last try before posting. I updated the bios today to 1.51 as well. Also just a general question about the deployment. I know it can be enabled via GPO, If I apply the GPO to a machine that is not supported what happens? I think I read somewhere about a reboot loop but not finding it now. If that is the case what is the best way to filter the GPO or just deploy via script to known compatible devices? Thanks,
-
GAFE/GSFE: Stop users being able to email distribution lists
ADMaster replied to Garacesh's topic in Cloud Services
I use regex to block sending to the groups. In the same compliance settings instead of contains text choose match regex. This is applied to my students OU. I prefix all distribution lists with list or slist, the 's' denotes a student distribution list such as [email protected] then staff would be [email protected] Here is the regex that will match both of these cases. (?i)(list|slist)-[a-z0-9]+@(example\.com) I have no need to update the rules year after year as long as it is prefixed it will be caught. -
I pay with a PO, but same country as the vendor so that may be why.
-
IT Asset Management and Discovery
ADMaster replied to Theldron's topic in Network and Classroom Management
What assets are you looking to discover / manage. A live view / status or just inventory? I like PDQ Inventory it has paid and free versions. It goes along nicely with pdq deploy. It will inventory all of your windows machines on a domain. Software/hardware and much more. With the paid versions you can define custom scans to look at specific reg keys or files. It is useful for checking the state of a setting such as smbv1. My help desk solarwinds also as an asset piece. It is more of a static inventory. It can pull in information from SCCM and some other sources, but mostly static. I import most of the assets via spreadsheet. I have NPM / switchmap so that takes care of the network infrastructure inventory but they are also in a spreadsheet. I gave up on spiceworks years ago I have ~700 devices. -
So there support stops when the network enters the school, but they control AD and SCCM. That doesn't add up. They could make a change in AD, group policy or SCCM and say oops we don't support our own screw up. I would be extremely uncomfortable with that situation, but here AD and SCCM are my babies. It is true there is an AD change needed for SCCM to work smoothly. I think I'd make a long term plan to move to your own AD domain in house then move to SCCM. Since the LEA has AD why don't they run a WSUS server too seams like a logical step. Do you have control to manager your OU in AD or group policies? Yes SCCM is an improvement and offers more features, but has greater complexity.
-
Do you trust the LEA not to mistakenly reimage your whole school?
-
I don't know about the webscreen bit but radius and captive portal are simple enough. Setup radius in the AAA section with the IP and secret key I use NPS. Then setup the SSID to use 802.1x auth and choose the radius server you previously setup. Ruckus has a captive portal / splash page when you set the SSID as guest. I think they have an option to login as well but I don't use that part.
-
That looks like chrome, but different enough I'm not sure (an old version?). I'd check for a dodgy extension, then when you find it black list it in the admin console / GPO.
-
Chromecast/Cast for education not working with Ruckus
ADMaster replied to Tammie's topic in Wireless Networks
I'd start by giving the chromecast full access just to remove one of the variables. If that works figure out what is getting blocked. Are the wired and wireless PCs on the same vlan? I'm not sure how well cast for edu works across vlans / subnets, but fairly certain you need to be signed in with a GAFE account. I had a teacher here trying to use a bit of software (don't recall the name) that cast her or the students device to the board. I had to setup a bonjour gateway between staff and student vlan in ruckus. I'm sure the chromecast will be similr in that aspect and needs a gateway. In my case it also had to be setup / assigned per AP so I just did it for the one in her classroom. -
Since you already have an SCCM deployment I'd stick with it for now. MDT is free but only does OSD SCCM does the apps, endpoint protection and configuration. intune and autopilot will cost extra and I don't think the setup school app will be as flexible as a SCCM or MDT image. For your 20% even the other 80% just push the task to them and let windows reboot into the OSD. I send a TS to a room collection go around turn them all on and next day they are done. SCCM is a beast to get going right but once done its well worth it, and it sounds like you have a working system.
-
+1 PDQ with inventory you can take it a couple steps further. deploy to only the machines with the old version inventory detects when the PC is online (heartbeat) deploy to all the online machines then schedule a deployment on heartbeat will get the rest as they come online. The retry mentioned previously just tries every hour. Also the paid version has package and collection libraries, so all you need to do is select the packages and click import. They do the rest.
-
Chromebook pilot with teachers advice and recommendations
ADMaster replied to tj2419's topic in Cloud Services
We have had G suite going on 7 years now 5 of those with CBs for students. Just this year I'm getting a few CBs for staff. At our last laptop refresh we discussed moving staff to CBs as well but ran into some of the same challengers already mentioned. The show stopper for us was our gradebook ran on java. However its gone web based for the upcoming school year. Chromebooks are just a breeze to manage, get yourself a good OU structure so you can target apps and settings to the group of users and you'll be set. To the comment on repair, most of our fleet is 11.6" non touch screens and they cost about $70 Most system boards cost around $150 and I can get a new device for $200 I usually repair screens and replace if it needs a board. Then swipe the screen and I'm money ahead. I've got fairly proficient at replacing screens over the years and can have one replaced in 5 minutes or so. The only ones I've not replaced yet and will have the supplier do the first few times while I watch and learn, are the R11 touch screens. -
Here is my source for the plain text screenshot. and an article on gMSAs. I don't have any gMSAs though. It was flagging my sccm admin service account even though its just a standard user with one purpose. I may have to setup a VM and test cain. I've removed them from the DA group and waiting to see what breaks. https://www.dsinternals.com/en/retrieving-cleartext-gmsa-passwords-from-active-directory/
-
There is a GPO that will allow users to install device drivers of the types you choose. https://technet.microsoft.com/en-us/library/cc725772(v=ws.11).aspx This doesn't always work and they end up bringing in the CD for me to install. I am working on setting up different admin accounts too and figuring out the best way to elevate. I have powershell scripts the create / disable users every day, I guess create a job specific account? I read service accounts are stored in plain text?? What permissions do I need to give my sccm / vmm service accounts? Anyone use PDQ inventory, its my go to tool. I launch remote support, pull event logs, launch client center etc. How much of this will break if I'm a standard user?
-
Creating home folder for existing users
ADMaster replied to manamaga2512's topic in How do you do....it?
I have no idea how my post came in 15 minutes later then yours, I thought sure I was the first reply. I open multiple posts in tabs then read and reply, I guess it didn't refresh before I got to replying. For an ongoing management I recommend powershell. I have a scrip that creates the users and their home drives with the correct permissions. I'd also suggest setting of DFS name spaces. DFS will allow you to setup share like \\domain\share\students but point it to \\fs01\students Then when fs01 gets retired and you setup fs02 just change the target in DFS after you copy the data. This means no messing with AD home paths again, and the users don't see a difference in the name of their drive. -
Creating home folder for existing users
ADMaster replied to manamaga2512's topic in How do you do....it?
The quick way is to select all users and go to properties > profile tab tick the box for home folder and fill in the details. \\server\share\%username% %username% will expand to each users username. I think the default permissions are administrators and the user with full control. -
I've never seen this on a chromebook and I have 1700. I have seen this once on a PC when I had to roll chrome back to an older version for one user. Here are a few suggestions. 1. Configure the auto update policies to keep your chromebooks on the same version. 2. Set show user pictures on the home screen, have the users remove their profile from the device and resync. Depending on number of users per device you may want to change this back after the issue is resolved. 3. Set the device to erase all local data on sign off. I'd only leave this one on long enough to fix the issue. 4. Make sure auto reenrollment is turned on and walk the users through a power wash / reset if its just a few devices. How are they getting newer profiles? Do they use personal devices with a newer version of chrome OS, I'm curious. Oh and 5. restrict the devices to only allow sign in from your domain accounts.
-
iBoss and "In line" solutions
ADMaster replied to rfakes's topic in Internet Related/Filtering/Firewall
I use iboss here, every solution has its pros and cons / think the grass is greener. I switched to it a few years ago because the other solution was letting stuff through. Then found out it had issues too, just different ones. I don't recall what they were now. It does an overall good job and support was fairly responsive on most issues. I think it is #1 in my region. I like inline solutions, no messing with proxy settings, it just works for any device connected to the network.
