-
Posts
1,402 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ADMaster
-
"No logon servers available..." Students disabling WiFi!
ADMaster replied to toffee_paul's topic in Windows 7
I had a similar issue years ago, I dug up these commands from my old scripts and GPOs. This was windows 7 32bit and the key was FN+F5. The laptops had a utility called Access Connections. Uninstall Access Connections the guid is most likely different now but here is what was in my script. MsiExec.exe /qn /norestart /X{8E537894-A559-4D60-B3CB-F4485E3D24E3} I also had these two files to be deleted by GPP, they were the exe's behind the FN+F5 key, perhaps you can find something similar on your systems. C:\Program Files\Lenovo\HOTKEY\TpFnF5.exe C:\Program Files\Lenovo\Access Connections\AcFnF5.exe -
Onedrive setup is in the users run reg key, delete that and it will not install. Here are my commands to remove onedrive REG LOAD HKLM\DEFAULT $OSDISK\Users\Default\NTUSER.DAT reg delete HKLM\default\software\Microsoft\Windows\CurrentVersion\Run /v OneDriveSetup /f REG ADD "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce" /v removeonedrive /t REG_SZ /d "%SystemRoot%\SysWOW64\OneDriveSetup.exe /uninstall" /f REG DELETE "HKEY_CLASSES_ROOT\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /f REG DELETE "HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}" /f REG UNLOAD HKLM\DEFAULT This is done during deployment so the default user profile effects every user of the machine.
-
Google Apps for Education - Generic Student Account
ADMaster replied to Duke5A's topic in Cloud Services
You will need to sign up as district admin according to this link. https://support.clever.com/hc/en-us/articles/236009108-How-do-I-bring-Clever-to-my-school- The terminology and school structure is a bit different between US and UK schools. I signed up as a district admin because that is what I am, I handle IT for all the schools in our district. I don't think it is quite the same, but I think our districts are akin to your academy trusts / mats. What is your role / situation that you don't think school or district admin would apply? If your part of a trust perhaps IT for the trust should sign up on behalf of member schools. The district admin role configures the sign on settings, data sync, applications etc. If this is what you will be doing, sign up as district admin. You can always add additional district admins later, or change the account owner. https://support.clever.com/hc/en-us/categories/200147297 -
[1703, cu] Windows 10 Creators Update (v1703) now available to download
ADMaster replied to Arthur's topic in Windows 10
I get a box before the log in screen that says great your connected now checking for updates. I wanted to look and see if there was something new I could add in an unattended xml but I can't build the catalog file. I am using the iso downloaded from vlsc and I've tried generating the catalog several ways running WSIM on the sccm server pointed to the install.wim in the share, and with it copied to the desktop running WSIM on a 1703 VM pointing back to the share and copied to the local desktop. all of the above as admin and not. I get an error that I need read / write access to the win and its folder. Thanks, -
Does applocker / SRP prevent this? Since it spreads via vulnerability and not reliant on user action does it run elevated and bypass these restrictions? I've rolled out the SCCM script to disable smbv1 too so here is hoping I don't break anything.
-
Replicating user home drives - is this possible
ADMaster replied to localzuk's topic in Windows Server 2016
In my experience replicating user data caused issues, but since this is for separate sites it may work out OK. The issue I had was they would access data on fs01 then at class change may access data on fs02 and it wasn't replicated yet, this caused conflicts. This was back on 2008 so I'm sure things have improved quite a bit. How is the data accessed are we talking folder redirection, or mapped drives. It either case groups are the answer, mapped drives can be targeted with GPP and folder redirection has advanced mapping based on security group. If your folder hierarchy is broken out by site move the home folders of those staff into an all sites folder. Staff site a site b site c mobilestaff Create a replication group for this moblestaff folder. Move their home folders. Create and assign members to a mobilestaff security group. Edit your gpos to point at the new home location. I hope this gives you an idea. -
I've got this working now. In addition to the first run file i previously mentioned, you need to deploy a preferences file. Here is the contents of my preferences file { "browser": { "has_seen_welcome_page": true }} be sure to run it through a json validator. Here is my install script for chrome. $OSDISK=(Get-WmiObject Win32_OperatingSystem).SystemDrive New-Item -Path "$OSDISK\Users\Default\AppData\Local\Google\Chrome\User Data\Default\Preferences" -ItemType File -Force copy-Item -path "Preferences" "$OSDISK\Users\Default\AppData\Local\Google\Chrome\User Data\Default" -Force start -Wait msiexec -ArgumentList "/i googlechromestandaloneenterprise64-58.0.3029.96.msi /qn" You could add the first run file into this script too, but I already had it in another script so left it be. I've just deployed this to a VM and it worked great.
-
[1703, cu] Hide settings in the Settings app (new feature in 1703)
ADMaster replied to Arthur's topic in Windows 10
So it is, I was using the link in This PC titled uninstall or change program. This now goes to the settings app instead of the control panel. -
I've started working on my 1703 build and found my work around doesn't work anymore. I tested with some older versions of chrome and it looks like the last version this worked for is 56. I've had a read though the new GPOs for 57 and 58, but don't see anything relevant. I guess the only option is to open chrome and then copy that to the default profile. I keep trying to delete various bits to see what file its looking for but not had any luck yet.
-
[1703, cu] Hide settings in the Settings app (new feature in 1703)
ADMaster replied to Arthur's topic in Windows 10
This being a computer setting effects admins too. I could not access add / remove programs, that's one of the things that moved out of the old control panel. -
[1703, cu] Hide settings in the Settings app (new feature in 1703)
ADMaster replied to Arthur's topic in Windows 10
This seams like it should be in user configuration. Has anyone tested this with loopback yet? I've started my 1703 build and testing the new GPOs. Thanks, EDIT: loopback works for user settings against a computer, not the other way around. -
[1703, cu] Windows 10 Creators Update (v1703) now available to download
ADMaster replied to Arthur's topic in Windows 10
I updated my home PC with the update assistant this weekend it took less than 30 minutes. I downloaded the ISO from VLSC yesterday and imported it into SCCM. I just pointed the OS part of my normal task sequence to 1703 and set it to image before I left for the day. Today it was waiting at the log on legal disclaimer screen; I clicked OK and was at the normal log on screen. It appeared to remove most of the Apps, and apply all the settings I had for 1607. Cortana is back as mentioned before but hidden per my search registry tweak for 1607 Edge is pinned to the task bar where it was not in 1607 but the rest of the start layout xml worked. Some new apps are installed that were not in my remove list for 1607. I have not decided if I want to keep them or not. I’ve been reading this thread and need to have a good look though all the new gpos. Overall it looks like most of my work on 1607 will carry over. -
Thanks, the job is done now. I setup a new 2016 VM and created a new VHDX for user data, it needed expanded anyway. I then used robocopy to get the data on to it, setup the shares, then changed the path in DFS. No one noticed the change at all. Then for the vhdx that contains my install shares etc. I shut down the old server, attached the vhdx to the new one. On the new server I brought it online, setup the shares, and changed the DFS path. That worked great too.
-
Edugeek Minecraft: The 1.7.10 Pack Details
ADMaster replied to localzuk's topic in EduGeek Minecraft
I went to the end tonight and killed the dragon. I collected some end stone so we can grow pearls better and I was able to get an enderman's head. I then created the soul binder so we can create spawners now. I'm not sure what we want spawned at this point with the magic crops going. -
bump bump
-
Google Apps for Education - Generic Student Account
ADMaster replied to Duke5A's topic in Cloud Services
They are as durable as you make them. You get a PDF that needs printing. Many of our teachers put them on heavier paper with other information then laminated it all together. -
Hello all, What is the thought on separate staff and student home shares on to different drives? Here is a bit of my back story on the file server. Back on 2003/2008 I had all the shares on the same drive and that made the old style of quotas difficult to have staff and student set a different levels. Between the new way of doing quotas and not really using them, anymore that’s not an issue. When I virtualized the server onto 2012 I setup separate vhdxs for staff and students. This has worked fairly well but I’ve run into some growth issues. We have digital art classes and recently introduced video editing into that. I have the raw space, I just expanded the students vhdx file. The home area of the digital art teacher has grown to over 100GB. If I had staff and students on the same volume, I could take advantage of data deduplication. I’d guess most of the pictures and videos they have are copies of the student projects. To address the space issue now I cam simply expand the staff vhdx file, but I’d also like to move to 2016. Here are a few ideas I have for going forward. In place upgrade and retain the separation. In place upgrade and migrate data to single volume. New VM and attach existing data vhdx files to it. New VM and migrate the data. Are there any security concerns with having staff and student data on the same volume provided the permissions are set correctly? Do you think the benefits of deduplication outweigh potential security concerns? Anything obvious I’m overlooking? I think I’m overthinking this one. Thank you
-
I've also seen this because chrome doesn't auto run flash. Some sites click to play works and others don't. I've fixed it a few times individually by going to chrome content settings and telling flash to always run. I've deployed GPO settings today that will fix it for all users. Google chrome / Allow outdated plug ins to run > Enabled Google chrome/content/ default plugin settings > Allow all sites to automatically run plugins.
-
Yes your secondary should also point to the ISP. The secondary is there in case the primary is not available or too busy. If you forward all of the traffic to it anyway you may as well only have one.
-
File explorer in start menu - Windows 10 Anniversary
ADMaster replied to cdwyer's topic in Windows 10
The little file explorer icon on the far left, I was not able to do anything with. My solution was to pin it to the start menu and use the xml file. -
Google Apps for Education - Generic Student Account
ADMaster replied to Duke5A's topic in Cloud Services
Yes it is free, I've been using them since September. My understanding is the application developers pay and it is free to schools. Although we have had some applications pass a small fee to us, it is worth it. -
Google Apps for Education - Generic Student Account
ADMaster replied to Duke5A's topic in Cloud Services
In short they don't. They of course have the option of signing into their google account to save things if they want. I setup public sessions for younger students who could not log in themselves. The homepage of the public session is links to educational resources used in the classroom. When they are old enough to start typing documents that need saved they are old enough to learn to log on. Since the badges have served us well this year. I'll be removing the public session option next year. -
Google Apps for Education - Generic Student Account
ADMaster replied to Duke5A's topic in Cloud Services
I now use clever badges but prior to that I used public sessions. https://support.google.com/chrome/a/answer/3017014?hl=en -
Please vote for this change in Google Team drive
ADMaster replied to FN-GM's topic in Cloud Services
I've up voted all three.
