peakrock
Members-
Posts
7 -
Joined
-
Last visited
Reputation
0 NeutralAbout peakrock

Personal Information
-
Location
Norfolk
-
Do you have the OneDrive app installed on the machine - we only have it via the web at the moment as it seemed simpler. Does the user have to log into OneDrive just the once or everytime they logon the machine and are they signing in across multiple machines which is what we'd be doing. It seems each machine holds user profiles as the first time a user logs onto a different machine it has to prepare the environment. I had considered the registry option so will give it a try if it works for your. Hiding it in GPO causes an Intune script to throw up an error message. Any other advice/tips would be appreciated. I've had a much shorter time than I would have liked to get all this tested and working properly before term starts for a number of reasons outside of my control..!
-
One of the small primary schools I work with has decided to move from Server 2012/Windows 8.1 (which has worked very well for the last 6 years) to 365, Sharepoint, Azure, Intune for Education etc. This is due to needing to replace or rebuild the server and to move to Windows 10 as I'm retiring soon and they'll have an OS that more people will be familiar with etc. One of the school Governors works in IT support so knows 365, Sharepoint and Teams fairly well whereas I would be the first to admit I don't know it well at all, having come from a server/client environment. I had imagined it would be a fairly straightforward with our combined knowledge but so far, that's not been the case. The desktops all have Windows 10 Pro Education installed and work well as standalone machines. They're joined to an Azure domain and I'm finding management via Azure and Intune a real pain. In the old environment there was a local admin account on each domain joined PC so it was possible to have full control of the machine and to quickly test GPO changes you'd made. In this new environment, even with a local admin account, the PC keeps the settings from what's been defined in Intune. So, you lock down Settings for example, only to find when you're logged on as local admin that you can't access Settings. Instead you have to disable blocking settings in Intune and then wait an indeterminate amount of time for this to permeate through. OneDrive only appears when you're running Office so you have the problem of where to store data from other apps. If you lock down local storage then the non Microsoft apps can't see any storage location, if you leave it unblocked the the pupils can see the C Drive. If you hide the C drive in local machine GPO then you get a srcipt error message when logging on. Some things just don't seem to work like assigning Browser home page etc. There are also a lot less settings compared with the server GPO templates. Sure, you can manage it virtually anywhere and hopefully it will get better but it seems to me that this is not a mature product set and doesn't compare with the rich function in a traditional client/server environment. As I said earlier I'm in no way an expert in this new environment and if anyone has more experience and/or advice that would be appreciated....
-
[android] Managing Android Tablets at School
peakrock replied to peakrock's topic in Mobile Devices & Tablets
Update now Tablets are deployed at the school: First of all I couldn't find anything that was cost effective or suitable from a centralised management point of view for 16 tablets so set them up manually. The tablets are set up with an Admin user account such that each tablet has its own Google account although it is only used to access the Play Store and no payment option was specified. Free apps that were not user specific and had minimal or no Ads were downloaded via the Play store. A restricted generic pupil user account was added to each tablet and the relevant apps and permissions were added to the account. Each tablet has the same Admin PIN code which is needed on power up as well as to access the Admin user. It makes the tablet harder to hack should it be stolen but if a pupil powers off the tablet completely rather than putting it in sleep mode then the Admin PIN needs to be entered next time it powers up and the tablet switched back to Pupil user mode. As it's a school with an external proxy server and SSL certificate (Updata) it was (annoyingly) necessary to set up each tablet in pupil mode to connect to the Wi-Fi access points and to specify the Proxy settings for each connection. It was also necessary to download and install the SSL certificate in Pupil mode even though it had been installed under the Amin id. This also required generating a PIN code for the credential store which in turn meant that instead of a PIN free pupil sign on, pupils now need to enter a simple PIN to log on. The resulting environment is somewhat locked down in that there is no access to the Play Store and Apps can't be installed by Pupils and the Proxy Server/SSL certificate policies will police most of the Web. However, it is possible to move icons around or remove them as well as change the Wi-Fi settings. I experimented and although the icons can be deleted the app itself remains on the tablet and be reinstated via the Admin id. We have appointed a couple of responsible Year 6 pupils as Tablet monitors and they will check the tablets out and back in again to try and keep them in order but it remains to be seen how this will work out in the long term. I was somewhat reluctant to introduce tablets into the school as I thought they would be harder to manage centrally than the traditional client/server setup that we have but it's hard to get this over especially when a pot of money has been raised by the Friends of the school with the objective of buying tablets.... -
[android] Managing Android Tablets at School
peakrock replied to peakrock's topic in Mobile Devices & Tablets
Having spent a few more hours on this I have now discovered that Google are discontinuing the Android for Education offering and not accepting any new signups so the ability to manage tablets this way will no longer exist. I've been looking at setting up a work profile within G Suite and whilst it offers a lot of centralised control the main flaw for a school is that the work profile is accessed from the main user sign in which would still give pupils access to most apps. I can set a restricted user profile up on the tablets which provides the lockdown needed for You Tube etc but it's then not possible to select the work profile in this mode so there is no centralised control for apps to be pushed out. G suite still gives some centralised setup such as setting network proxies etc so it should be of some use but I'm now going to test this out. I don't claim to be an Android expert by the way so comments/corrections welcome ! -
I need to manage 16 new Android Tablets (Samsung Galaxy Tab A) that will be shared across all pupils at a primary school. They will need proxy server setup, and to be well locked down with restrictions on You Tube, Play Store etc. I've looked at TabPilot which would seem to do the job but it's a $500 annual licence fee for up to 30 tablets so it's too expensive. I've also been looking at Google G Suite which has a device management feature and is also free for Education. I have got as far as activating the admin console and looking at the options. However, it seems rather complicated for what I need and is going to require some appreciable time investment in working out exactly what I do and don't need to set up. Has anyone used G Suite for this purpose and do you know of any resources I might access, I was hoping to find a list of recommended options for quick setup. Alternatively, are there any other management tools that work well, I've looked around on the web but not found anything that stands out. Thanks
-
My school has just bought new Lenovo B50-70 laptops with Windows 7 Professional SP1 64bit. I've installed ActivPrimary3 version 3.7.19 and ActivDriver x64 v5.10 from the Promethean website. When I plug the ActivBoard into the laptop it recognises it fine and I can calibrate it etc. However, when I start ActivPrimary3 it doesn't recognise that there is an Activboard attached. If I go into ActivDoctor it shows a raft of software under Installed ActivPrimary but nothing for Installed ActivDriver. I've tried uninstalling both pieces of software and then ActivPrimary3 first and then ActivDriver afterwards but it still doesn't show an installed driver under ActivDoctor... Help appreciated....
