tcable
Members-
Posts
15 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by tcable
-
Preferred Aad Tenant Domain Name with multiple domains in tenant
tcable replied to tcable's topic in Cloud Services
just seen this on the page: Unsupported scenarios - The following scenarios are not supported. Sign-in with non-UPN email for: Microsoft Entra hybrid joined devices Microsoft Entra joined devices Microsoft Entra registered devices Resource Owner Password Credentials (ROPC) Single Sign-On and App Protection Policies on Mobile Platform Legacy authentication such as POP3 and SMTP Skype for Business Which may suggest it doesn't work, but i'll still give it a go. -
Preferred Aad Tenant Domain Name with multiple domains in tenant
tcable replied to tcable's topic in Cloud Services
I'll give this a go - i suppose I'm thinking that the username is the field that matters, as that's the login id, so an alias won't matter. I'll give this a go tomorrow and report back. -
Hi I don't think this is actually possible, as I can't find anything on the internet, but lets see. I know 'Preferred Aad Tenant Domain Name' exists, and what it does, however can it handle multiple domains? For example we have 2 domains: domain1.co.uk and domain2.co.uk in our tenant, and users that use one or other to log on. This is under a single office 365 subscription. In 90% of cases we know what domain is likely to log onto a machine, so not a problem to have two different ones and use a group to filter them out. But for the other 10% users from either domain could log in. Now I know that you can put in the full UPN and it will overwrite the default setting, however for the purposes of making everything universal and not having to explain to my users that on some machines you need to put in the full email address and some you don't, it would be nice if it didn't matter what domain the user was on, they could just use the first part of there email address (like domain computers do) If it's not possible (which I don't think it is), I don't think I will apply this setting at all, but before I rule it out completely, want to make sure there's no trick out there to make it work.
-
Mr L - I've not got to where i am today by listening to you, and I'm certainly not going to start now Thanks for the replies. I couldn't wait until Easter so decided to give 'Self-Deploying' a go, and it deployed fine (in the end). Kept getting error 0x800705b4 on 'securing your hardware', which seemed to suggest a TPM error, however it seems to be because of filtering somewhere as if i attach it to an unfiltered network then it goes fine. Need to go through the logs to see what website is being blocked on this stage. From what i can see using this method doesn't apply a primary user to the machine within intune. I seemed to be able to access the on-prem network fine. Managed to get onto some services that don't have an internet presence ok, and it seemed to install a printer from my printer server ok (no VPN running yet, but do have azure AD connect running which is what i think helps make this possible). Still a few weird things happening that I need to test (like I logged on first and it made me an admin, despite it being set to standard account in account type settings, however the second account to login was a standard user), and a few policies to migrate to the cloud and the shared PC policy to dig through a bit more, but so far i give it a good start for a first attempt. Whilst i still have some testing to do, it does seem that the configuration policies apply a lot faster than when on a hybrid machine. This might just be a weird coincidence at this stage though. If anyone knows how to put an answer file onto a USB stick that's been created with Rufus , that would be handy getting fed up of selecting the keyboard layout every time i reinstall the machine!
-
intune device groups in a hybrid environment with SCCM
tcable replied to tcable's topic in Enterprise Software
For the moment, i have a PowerShell script that populates ad security groups based on the OU, and removes any computers that was in the group but it can't find in the OU. (i.e. any computer objects in the staff computer science OU is put into the staff computer science AD group) Set as a scheduled task to run every 20 minutes. These groups sync to azure AD and then used in intune where specialist software is deployed to certain groups. works fine as a stop gap for the moment. I do have collections set up in SCCM, however i wanted to avoid using these as i want to phase out SCCM which is likely to go before i get rid of active directory. -
Hi All, Been slowly moving our on prem to the cloud (got app and polices running though Intune, windows updates over Easter), and we are currently co-managed using sccm. Once i have completed these, that only thing i think i will be using SCCM for is OS deployment. I want to start to use autopilot to provision devices instead of SCCM and move away from co-management, but I'm getting super confused on where to start and set this up. I've tried ready various articles and scrolling though the forum here, but not really finding the answers that i want (or at least not or a educational setting with devices used by more than one user). I know how to get the hardware ID from devices and import into Intune - I've already done that for my test device - and i believe the best way to reinstall windows is through a USB version of the OS, but it's the deployment profile that I am getting confused with. Do I need user-driven or self-deploying? I think user-driven is for 1:1 laptops, and self-deploying is for shared devices? or are they the same thing, just not as automated? if it's a shared device, do i need to do anything special once it is all deployed? I.e. I know intune deploys a primary user, so does this need to be removed, and if it does, is there an automated way of doing it?) Do i need a 'deployment' account to sign into the machine for the first time to complete the setup? All devices will go to IT first to be configured before going out to users/classrooms. Can I still access my on prem network if a device is entra connected? Ideally I want to move away from hybrid approach so I can manage everything in the cloud and manage devices regardless of where they physically are, but I'll still need to access some on-prem services like SIMS and a few legacy group policies that i haven't managed to migrate to intune yet, so this is a requirement. I assume if this is the case, then it needs to be set up as a hybrid device, rather than entra joined. sorry for all the questions and if this is basic - I'm just starting to confuse myself (and possibly taking something that is very simple and making it very confusing) and hopefully get some guidance before I start to test this after the Easter holidays. Thanks in advance.
-
Hi Just starting to migrate from on premises SCCM to intune, and most is going well; the only thing that i can't get my head round is how to do dynamic device groups if i want to target software. At the moment, in SCCM, i have device groups based on the OU that the computer is in, be it computer room or department, and that's how it decides what software should be installed on that device. I can't work out how to do that in intune as i can't use OU as a filter, so was wondering how others get round this. I'm looking for something fairly automated like SCCM at the moment, as i know it will either get messy or forgotten if i am left to try and remember it myself. Thanks
-
done it. it turns out CTFile is not the same as CTfile which is the format that the header is after.
- 39 replies
-
- ctf
- ctf import
-
(and 1 more)
Tagged with:
-
Hi not 100% sure if what i am trying is 100% possible, but thought i would ask. We're currently taking admissions for new year 7's, and they are currently completing online forms with there information. We are looking to create a CTF XML file so our admin lady can import straight into SIMS rather than copying and pasting from a spreadsheet. After a lot of playing, i've managed to create an XML file for each student, and it appears to match current CTF's that we get from other schools. The error message we get on import is: "invlaid XML File Error. The error description is 'System foes not support the specified encoding. could not find preparted statement with handle 0 sp_xml_removeddocument. The value supplied for paramerter number 1 is invalid. The statement has been terminated" I'm not 100% sure what this means, unless i haven't got a complete CTF file. I thought it might be because i'm using classic ASP to query the SQL database and create the file, but even copying and pasting into a fresh file, it does the same. Is what i am trying possible, or am i wasting my time? Thanks Tony Cable
- 39 replies
-
- ctf
- ctf import
-
(and 1 more)
Tagged with:
-
Excellent, seems to work fine, just need to change the messages a little bit, and the font, but other than that, working just how I want it to. Thank you again for your help.
-
That's looking good, I've applied it to a few printers here to give it a go. I wasn't getting very far with my script combining (kept getting script errors). I'll test it over the next few days and let you 1. know if it works, 2. if I tweak it, i'll explain why and post the tweaked script. Thanks for your help.
-
The two scripts above are those already built into papercut! It's just combining them correctly that I am having trouble with. I think I need to create a function called something like if (inputs.job.isGrayscale) { and move the alerting code into there
-
actually looking at it again, i think this needs to be my starting point, as this seems to make more sense.: /* * Request user for grayscale/color printing * */ function printJobHook1(inputs, actions) { /* * This print hook will need access to all job details * so return if full job analysis is not yet complete. * The only job details that are available before analysis * are metadata such as username, printer name, and date. * * See reference documentation for full explanation. */ var CONVERT_MESSAGE = 'Your job contains color pages. Would you like to convert your job to grayscale? Selecting "No" will print the job in color, Selecting "YES" will change the job to greyscale.'; if (!inputs.job.isAnalysisComplete) { // No job details yet so return. return; } if (inputs.job.isColor) { /* Color job, ask the use if they want to print. */ if (inputs.client.isRunning) { // User is running the client software. Ask if they want to convert to grayscale or cancel. var response = actions.client.promptYesNo(CONVERT_MESSAGE); if (response == 'NO') { actions.log.debug('User chose to keep on printing in color'); } else if (response == 'TIMEOUT') { actions.log.debug('Dialog timed out, canceling job.'); actions.job.cancel(); } else { actions.log.debug('User chose to convert their job to grayscale.'); actions.job.convertToGrayscale(); } } else { actions.log.debug('Canceling job due to high number of color pages and user not running client software.'); actions.job.cancel(); } } } /* * Confirm jobs with a high number of pages * * Users printing jobs with many pages are asked via the client tool whether * they meant to print such a large document, giving them the opportunity to * cancel. The message is displayed in large red letters. This can be useful * for users who forget to enter a page range when printing and instead send * the whole document. */ function printJobHook2(inputs, actions) { var LIMIT = 0; // Show message for jobs over 0 pages. /* * This print hook will need access to all job details * so return if full job analysis is not yet complete. * The only job details that are available before analysis * are metadata such as username, printer name, and date. * * See reference documentation for full explanation. */ if (!inputs.job.isAnalysisComplete) { // No job details yet so return. return; } if (inputs.job.totalPages > LIMIT) { /* * Job is larger than our page limit, so ask the user to confirm via * red warning message so we grab their attention. */ var message = "" + "Please confirm the job." + ""; var response = actions.client.promptPrintCancel(message); if (response == "CANCEL" || response == "TIMEOUT") { // Cancel the job and exit the script. actions.job.cancel(); return; } // User pressed OK, so allow it to print - simply return taking no action. } } function printJobHook(inputs, actions) { printJobHook1(inputs, actions); printJobHook2(inputs, actions); }
-
well this is what i have at the moment: /* * Color print jobs require user confirmation * * Color printing is expensive so users should be encouraged to print * in grayscale whenever they print in color. No confirmation is required * for grayscale jobs. */ function printJobHook1(inputs, actions) { /* * This print hook will need access to all job details * so return if full job analysis is not yet complete. * The only job details that are available before analysis * are metadata such as username, printer name, and date. * * See reference documentation for full explanation. */ if (!inputs.job.isAnalysisComplete) { // No job details yet so return. return; } if (inputs.job.isColor) { /* Color job, ask the use if they want to print. The job cost is displayed * prominently to encourage users to consider black and white printing instead. */ var response = actions.client.promptPrintCancel( "This print job is color" + " and costs " + inputs.utils.formatCost(inputs.job.cost) + ". You can save money by printing the job in grayscale. " + "Do you want to print this job?", {"dialogTitle" : "Color print job", "dialogDesc" : "Consider printing in grayscale to reduce costs"}); if (response == "CANCEL" || response == "TIMEOUT") { // User did not respond, cancel the job and exit script. actions.job.cancel(); return; } } } /* * Confirm jobs with a high number of pages * * Users printing jobs with many pages are asked via the client tool whether * they meant to print such a large document, giving them the opportunity to * cancel. The message is displayed in large red letters. This can be useful * for users who forget to enter a page range when printing and instead send * the whole document. */ function printJobHook2(inputs, actions) { var LIMIT = 0; // Show message for jobs over 0 pages. /* * This print hook will need access to all job details * so return if full job analysis is not yet complete. * The only job details that are available before analysis * are metadata such as username, printer name, and date. * * See reference documentation for full explanation. */ if (!inputs.job.isAnalysisComplete) { // No job details yet so return. return; } if (inputs.job.totalPages > LIMIT) { /* * Job is larger than our page limit, so ask the user to confirm via * red warning message so we grab their attention. */ var message = "" + "Please confirm the job." + ""; var response = actions.client.promptPrintCancel(message); if (response == "CANCEL" || response == "TIMEOUT") { // Cancel the job and exit the script. actions.job.cancel(); return; } // User pressed OK, so allow it to print - simply return taking no action. } } function printJobHook(inputs, actions) { printJobHook1(inputs, actions); printJobHook2(inputs, actions); } The main problem is it brings up two alert boxes, and i want to combine it so i only get one alert box. so yes i'm after a If, Else statement really.
-
Hi I'm trying to develop a papercut script, but hit a bit of a brick wall, so i'm hoping someone who can code better than me can help! Basically what i am after is a single script that will do the following: If print job is colour, show an alert to ask if they want to print in colour, convert to greyscale, or cancel the job. Print/charge depending on selection Else If print job is greyscale, then show an alert asking if they want to continue, with either yes/no or print/cancel buttons I also want to put costs and various other bits in, but i can develop that once i've got the basics in. Tthe code that i have at the moment is basically what's already in papercut to alert every time, plus the colour/greyscale option combined using: function printJobHook(inputs, actions) { printJobHook1(inputs, actions); printJobHook2(inputs, actions); [color=#444444] } [/color], and isn't really what i am after. hook1 is the colour/grey/cancel hook 2 is the alert. but it charges after hook1 if they don't cancel the job, regardless of what is chosen in hook2 I can post what i have already if it helps, but i'm not sure it's going to Thanks
