Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Geoff

Edu Supporters
  • Posts

    13,543
  • Joined

Everything posted by Geoff

  1. How does this work in multiplayer? I've only tried it in singleplayer.
  2. I'm commercial so the licensing works slightly differently (our E5 licenses get MFA included, our E3 licenses have to have the extra 'Enterprise Mobility + Security E3' bolt on) so I am no help for that. We have it setup like @abaxter2 says. Internally normal users don't get MFA. Admins always get MFA. Externally or on untrusted BYOD stuff normal users do get MFA. We use SMS and we also have RSA keyfobs deployed for some users. Note we're purely doing this for O365. MFA wont help stop your users doing the stupid. You need to train them.
  3. Also make sure your Distribution point folders are excluded from AV scanning (and your SCCM inboxes while your at it) on the server.
  4. Used to run call centres. I was a happy customer of: Nexus Orbtalk I was not happy with: Volceflex Anyone re-selling voiceflex.
  5. To upgrade each of your applications packaged with this tool: Replace the 'AppDeployToolkit' folder with the new version The only changes to standard 'Deploy-Application.ps1' are an inclusion of license text in the .SYNOPSIS (Lines 4 - 8) and that the date and version variables have also been bumped as you'd expect: [version]$deployAppScriptVersion = [version]'3.7.0' [string]$deployAppScriptDate = '02/13/2018' The 'Deploy-Application.exe.config' and 'Deploy-Application.exe' have not changed and do not need to be replaced.
  6. Now announcing the new AWS region 'Low Earth Orbit' housed aboard the space station Bezos-1.
  7. 11km/s with the top down and not even a light breeze. The sunburn is a killer though.
  8. Yeah, that would be the plan with SCCM. That's not possible with Citrix as I don't run an SCCM client on the session hosts. It'd have to be a GPO login script or something.
  9. Well as far as I can work out it installs in %APPDATA% which is dumb idea. I can get away with that with SCCM however that isn't going to work on a terminal server. Thanks MS. I'll be using the Web Version too.
  10. To answer my own question, this is by design. Outlook will not let you run macros distributed this way until you've opened up the code editor. The way to do this correctly is to write a VSTO addin in C# for Outlook and distribute that. https://msdn.microsoft.com/en-us/library/cc668191.aspx
  11. Is anyone using Teams? If so how did you deploy it. I would want to push it out via SCCM and also put it on my Citrix session host image. Thanks.
  12. Yes, you have to match your mod versions with the server or it'll kick you off.
  13. I have a company wide macro that does some sanity checks on their emails they are trying to send and also pops up a warning if it is an external address. It uses Application_ItemSend like this example. To get this out to everyone I have distributed it to my users by putting the full 'VbaProject.OTM' into their %APPDATA%\Microsoft\Outlook during login with robocopy. However the macro does not run when an email is sent. I have tried signing the macro. I have also tried disabling macro security. I can get the macro to start running if I open up the VBA editor and close it again. However I can't expect my users to do this. Any ideas?
  14. For people from the future, it's not possible to distribute insider updates to insider clients. You must let these machines talk to MS Update directly for them to update correctly. The way I'm intending to do this with SCCM is with a higher priority client settings that disables Software Updates. I've then deployed it to a collection with the following dynamic query: select SMS_R_SYSTEM.ResourceID, SMS_R_SYSTEM.ResourceType, SMS_R_SYSTEM.Name, SMS_R_SYSTEM.SMSUniqueIdentifier, SMS_R_SYSTEM.ResourceDomainORWorkgroup, SMS_R_SYSTEM.Client from SMS_R_System inner join SMS_G_System_OPERATING_SYSTEM on SMS_G_System_OPERATING_SYSTEM.ResourceID = SMS_R_System.ResourceId where SMS_G_System_OPERATING_SYSTEM.Name like "%Insider%"
  15. Irrelevant because I'm using SCCM.
  16. Geoff

    Staff Size

    In the interests of balance (a la the other side of the fence) 1. Corporate 2. 350 3. 2x First line Techs. Flaming torches and job vacancies are available on request.
  17. Dual scan? https://blogs.technet.microsoft.com/wsus/2017/05/05/demystifying-dual-scan/
  18. Sounds like your power management doesn't work properly. Things to try: Set power plan to high performance disable hibernation / sleep update drivers update bios
  19. path="*.asmx" verb="*" type="System.ServiceModel.Activation.ServiceHttpHandlerFactory, System.ServiceModel.Activation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" preCondition="integratedMode,runtimeVersionv4.0" /> type="System.ServiceModel.Activation.ServiceBuildProvider, System.ServiceModel.Activation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"/> requestEncoding="utf-8" responseEncoding="utf-8" /> priority="1" group="0" /> logMalformedMessages="false" logMessagesAtServiceLevel="false" logMessagesAtTransportLevel="false" maxMessagesToLog="30000" /> name="Microsoft.UpdateServices.Internal.Client" behaviorConfiguration="ClientWebServiceBehaviour"> binding="basicHttpBinding" bindingConfiguration="SSL" contract="Microsoft.UpdateServices.Internal.IClientWebService" /> binding="basicHttpBinding" bindingConfiguration="SSL" contract="Microsoft.UpdateServices.Internal.IClientWebService" /> binding="basicHttpBinding" bindingConfiguration="ClientWebServiceBinding" contract="Microsoft.UpdateServices.Internal.IClientWebService" /> binding="basicHttpBinding" bindingConfiguration="ClientWebServiceBinding" contract="Microsoft.UpdateServices.Internal.IClientWebService" /> closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" maxReceivedMessageSize="1048576" maxBufferSize="1048576" maxBufferPoolSize="134217728" messageEncoding="Text" textEncoding="utf-8"> maxStringContentLength="8192" maxArrayLength="16384" maxBytesPerRead="4096" maxNameTableCharCount="16384" /> closeTimeout="00:01:00" openTimeout="00:01:00" receiveTimeout="00:10:00" sendTimeout="00:01:00" maxReceivedMessageSize="1048576" maxBufferSize="1048576" maxBufferPoolSize="134217728" messageEncoding="Text" textEncoding="utf-8"> maxStringContentLength="8192" maxArrayLength="16384" maxBytesPerRead="4096" maxNameTableCharCount="16384" />
  20. Check the smsts.log(s) on the OSD system. It should tell you why. My domain joins would not work until I specified an OU. So I made a 'SCCM OSD' OU for it to use. If it just refuses to work no matter what you can script it.
  21. StarTech.com M.2 SSD to 2.5in SATA Adapter - £15 https://www.amazon.co.uk/StarTech-com-2-5in-SATA-Adapter-Converter/dp/B00ITJ7U20
  22. Ah did you patch your WSUS for Win10 feature updates? https://support.microsoft.com/en-us/help/3095113/update-to-enable-wsus-support-for-windows-10-feature-upgrades
  23. My understanding is that if you have no GPOs touching WSUS settings what so ever and you have SCCM clients then SCCM will locally manage the local policy of each machine such that you end up with a working config that is talking to the SCCM server for updates (see Picture)
  24. We want to run Insider on a few machines for testing. Does anyone know what the update settings need to be. Currently I have SCCM managing everything. Can I just point Insider machines at SCCM and it'll work? Or do I need to override the SCCM settings and point them back to MS Update?
  25. If are just missing January this may be because you need to set the AV compatibility key to get them. https://support.microsoft.com/en-us/help/4072699/january-3-2018-windows-security-updates-and-antivirus-software
×
×
  • Create New...