Jump to content

IanT

Members
  • Posts

    2,187
  • Joined

  • Last visited

Everything posted by IanT

  1. Anyone seen this issue before, Outlook\OneDrive not connecting\signing in with error AAD Cloud AP plugin call GenericCallPkg returned error: 0xC0048512 in event viewer: We have this on a handful of users
  2. meh - intune, I pulled the intune project at my new place as shared devices was a nightmare!
  3. Desktop and Patch Management
  4. Looking for Alternatives to Intune\SCCM - any decent recommendations?
  5. Hi all, We’ve been chasing down a really odd issue and finally pinned it down to the Impero Client. On our Windows 11 (24H2, latest cumulative update) machines, when a anyone logs in and uses Word (M365 Apps), dropdown menus (e.g. font selector) disappear as soon as you try to scroll, This makes Word basically unusable for those users. After a lot of testing we confirmed: If we disable the Impero services (Impero Service Starter, ImperoClientSVC, ImperoGuardianSvc) → issue immediately disappears. If we start the impero services, boom the issue comes back! So this is 100% tied to Impero injecting itself into the session. Has anyone else seen this on Windows 11 24H2? If so, did you manage to get a fix or hotfix from Impero? We’re planning to escalate to their support, but I’d be keen to know if this is widespread. See video! Video(1).mov
  6. One of the main issues I encountered during testing was that policies were so inconsistent, they would either take a long time to apply, not apply at all, or only kick in several minutes after the user had logged on. Like you, I want to lock down user accounts, but I can’t risk relying on policies that don’t apply properly. We were fully prepared to move over to Intune, but on the final day of term I pulled the plug after realizing how disruptive it could be come September so went back down the SCCM\MDT route. I’m now reviewing our options again. At this stage, I’m leaning towards SCCM with Intune integration, or possibly another device management tool altogether. I’m not comfortable moving to a full Intune setup just yet.
  7. To Intune or not to Intune… At the start of this year, we were seriously considering moving away from on-prem AD and going all-in with Intune. After extensive testing, though, the cracks showed very quickly. Here’s what we ran into: Policy application is inconsistent – Some machines apply policies instantly, others take hours (or never). We saw settings half-applied, conflicting, or simply ignored. For a controlled school environment, that’s a nightmare. Reliability with shared devices – Education doesn’t fit neatly into Intune’s “one user, one device” model. We have shared PCs, laptops, and labs. Intune just doesn’t handle multiple user profiles well, and policy inconsistencies multiply. Drive mapping and legacy dependencies – We still rely on mapped drives, and Intune + cloud identity doesn’t play nicely. Scripts for drive mapping are hit-and-miss, and support for legacy infrastructure feels like an afterthought. App deployment is flaky – Some apps push fine, others stall, fail, or report success when they haven’t actually installed. Troubleshooting is opaque compared to SCCM or GPOs. Limited control and visibility – Reporting is basic. Troubleshooting why something didn’t apply often comes down to guesswork. Event logs and error messages are vague at best. Connectivity dependency – Devices that aren’t online regularly don’t update properly, leaving gaps in compliance. On-prem GPOs don’t have that issue. User frustration – Students and staff logging into a freshly built device often hit delays while policies and apps “drip-feed” in. With shared classroom devices, you don’t get the luxury of a single user waiting 30 minutes for their desktop to be usable. To give credit where it’s due, Intune does have strengths. Windows Updates, driver/firmware updates, and general patching were handled really nicely. I also liked the centralized view of compliance. But overall, the way Intune applies (or doesn’t apply) policies gave me the ick. It’s unreliable, unpredictable, and ultimately not suited to the education space as it stands. Looking ahead to next summer, I can’t justify moving us fully to Intune. I’m instead looking at SCCM with Intune hybrid mode to get the best of both worlds. Has anyone else gone down the hybrid route? Would be interested to hear how it compares in real world education use.
  8. I made the decision on Friday to halt the Intune project. While it's suitable for 1:1 device deployments, it's proven to be a nightmare for shared devices. I'm not willing to implement a compromised solution or rely on hope for stability, it needs to be done properly or not at all.
  9. yeah, it’s honestly becoming a bit of a joke now. We’ve literally just applied some settings to our student policy — they applied fine on first login. Thought "brilliant, finally!" Logged out, logged back in… nope. Gone. Not applied. What the hell is going on? It's genuinely ridiculous. One minute it behaves, the next it forgets it even exists. I get that Microsoft thinks every device is a shiny 1:1 business laptop sitting idle waiting patiently for cloud magic to happen, but come on, this is a school. Kids aren’t waiting 10 minutes for policies to catch up. They’re launching Roblox, opening CMD, and trying to bypass everything before the poor IME even gets out of bed. We're at the start of our rollout and already seeing how shaky this setup is for shared environments. It just doesn’t feel production-ready for education — at least not without a lot of duct tape and swearing.
  10. I'm just seeing so much inconsistency - we have a configuration policy which restricts the like of control panel etc.............you log on, it doesnt apply so the kids can start changing stuff.............10 minutes later its applied, this cannot be right surely with how slow it is?!
  11. I’m currently in the early stages of deploying Windows 11 devices using Microsoft Intune (Entra joined), and I’ve started to notice some frustrating behavior around user policies applying very slowly or inconsistently. When a user logs into a freshly deployed device for the first time (especially shared/student machines), the device itself is enrolled, apps install fine, and configurations eventually apply. However, the user policies – things like restricting PowerShell/CMD access, locking down settings, hiding control panel etc – either: Take several minutes to apply Or don’t apply until after a log out and log back in And in some cases, they don’t seem to apply at all on first use This delay poses a concern, especially in an education setting, where a student could easily access critical system tools before the policy has kicked in. We’re deploying mapped drives using ADMX-backed configuration profiles. These too sometimes don’t appear until a second logon, despite the config being correct and devices/users in scope. Anyone has this?
  12. Yeah, that’s exactly my thinking too, using MDT with a TS for the latest Windows 11 build. I’m getting seriously fed up with waiting around for apps to come down from the cloud. Even with forced syncs and ESP tweaks, you’re still at the mercy of Microsoft’s timing. I’d much rather preload the core apps in the image via MDT, that way I’ve got more control over the process and can actually get machines ready in a sensible timeframe. Autopilot’s great once it’s rolling, but for existing domain devices it just feels too sluggish without a bit of prep work up front.
  13. I've been experimenting with Intune and onboarding devices, and we have a few hundred existing Windows 11-compliant machines that we're planning to AutoPilot over the summer. I'm curious, how do you typically handle imaging for existing devices? Do you wipe them with a vanilla Windows 11 OS and then run the AutoPilot scripts, or take a different approach?
  14. Does anyone still have Physical Domain Controllers on-site which still hold all FSMO roles?
  15. I've had enough of SCCM. Everywhere I've been, I’ve rarely seen it working properly. It feels like I spend more time troubleshooting and massaging the product just to get it to do what it’s supposed to. Every update seems to introduce new issues, and frankly, I’m fed up with wasting time on a tool that constantly needs babysitting. I'm on the lookout for reliable alternatives that can handle software deployment, patch management, and device management without all the hassle. I need something that actually works as intended without endless troubleshooting sessions. Would appreciate any recommendations or experiences you can share! Thanks in advance!
  16. I’ll be starting in this role in May, and yes, it will be reporting to me. I’m conducting interviews via Teams next week. If you’re interested, feel free to send me a PM.
  17. Update, I was given the wrong information, the salary is £34,420 - £38,002 per annum Apologies.
  18. Evening, I am looking for a Assistant Network Manager to join my team at Collingwood College, details in the link below: The Assistant Network Manager is a newly created role aimed at optimising network performance and delivering outstanding IT support services to users across the College. The Assistant Network Manager will work closely with other members of the IT Support Department and deputise for the IT Systems Manager as required to proactively manage the College’s network, maintain the availability of services and devices, and respond quickly and effectively to support requests of varying complexity. This opportunity comes at an exciting time as the successful applicant will play a key role in supporting the continuing delivery of major upgrades to the College’s core network infrastructure and cloud transformation over the next 2-3 years. The Assistant Network Manager will have the opportunity to provide their input in the development of the College’s long-term strategy in this area and develop their own technical and managerial skills to ensure continuous best-in-class service and performance Please message me for more details Corrected to £34,420 - £38,002 per annum
  19. https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16
  20. You’ve just started a new job as an IT Manager/Network Manager at a school—what are your top priorities for your first week?
  21. Open a ticket with Microsoft to address this issue. However, it's important to note that performing an in-place upgrade of a Domain Controller is not recommended. Additionally, it's best practice to wait 6 to 12 months before rolling out or upgrading to a new operating system to ensure stability and compatibility.
  22. Our central IT team is looking for a Server Infrastructure Manager to take responsibility for for the delivery and day to day operations of all server, storage and related services. This will include delivering continual improvement of infrastructure services and automation along with building and maintaining effective cross departmental and academy relationships and working practices to ensure the long-term strategic planning and delivery aligned with the business requirements. About Us The Harris Federation mission is to transform education in London so that every student in a Harris Academy receives an outstanding education. Closing the gap between children from disadvantaged backgrounds and their peers has always been a core mission. The founder, Chairman and sponsor of the Harris Federation, Lord Harris of Peckham, opened our first school in 1990. We now have 51 primary and secondary academies across London and Essex, employing over 5,000 staff and educating some 40,000 young people. We are widely recognised as a force for social mobility and we are immensely proud of the role that our alumni are now beginning to play in the world and of what we believe our current generation of pupils will go on to achieve. As a large, successful group of academies, we have the size and scope to be far more than the sum of our parts. Main Areas of Responsibility You will be responsible for developing and maintaining the following services: On Premise Server Infrastructure (including new physical and virtual servers) across the Federation Monitoring and capacity planning of the server infrastructure Server backups Active Directory user provisioning Web filtering The security and on-going patch management of all servers Additional responsibilities will include: Reviewing and analysing current technology infrastructure and its ability to support strategic corporate objectives Identifying and proposing specific strategies, initiatives, and remedies to align technology infrastructure with corporate objectives Supporting development of business drivers, business case and high level program implementation plan Continually researching new technologies to ensure systems are as efficient, effective, resilient and secure as possible Promoting awareness of new technologies, maintaining up to date knowledge of leading-edge technology and associated vendors, and liaising with vendors, partners and service providers as appropriate. Disseminating information about new systems to the immediate and remote IT Team Designing, building and maintaining the systems to ensure that they: are secure; are resilient; are appropriate for needs; have sufficient capacity; have perform as required; are available when required; provide value for money; are documented appropriately. Promoting shared and common infrastructure Developing and maintaining standard processes and procedures Developing and maintaining a consistent operational monitoring and reporting platform Ensuring that all ICT solutions are fit for purpose, scalable, adaptable and compliant Developing and maintaining standard migration processes Identifying training requirements for ICT support staff Ensuring that deployed solutions and underlying documentation are regularly reviewed and refreshed Maintaining strong lines of communication with all relevant areas of the organisation and with relevant external entities This is not a full job description, and should be read in conjunction with the Job Pack. Qualifications & Experience The successful candidate will have: Demonstrable experience of balancing priorities and successful delivery of objectives, in a fast paced, constantly changing environment Ability to troubleshoot, investigate and resolve technical issues Ability to react quickly and effectively to issues and opportunities Substantial experience of carrying out a similar role Proven track record in working to strict timescales and of working with staff at all levels Experience of working in an on-site IT based Customer Service Understanding of Storage Devices (SAN, NAS, DAS) Detailed knowledge of : Microsoft server (Server 2012, 2016, 2019 and 2022) and desktop products (Windows 10,11 and Apple MAC) Microsoft Hyper-V 2019, Microsoft Failover Cluster and VMWare vSphere Powershell and automation tools Active Directory Azure SSO authentication Hybrid environments (AD and Exchange) Managing Microsoft SCCM products (inc Data Protection Manager) HPE Server Hardware Server Monitoring platforms (such as PRTG or Solarwinds) Web Filtering platforms Different cyber technologies across Infrastructure protection, Application Security & Information Protection. Professional Development & Benefits We offer a competitive rewards and benefits package which includes our Harris Allowance, a Performance and Loyalty Bonus, Pension Scheme, a Wellbeing Cash Plan and many other benefits. Our head office staff also benefit from flexible working on a core hours basis, offering the opportunity to choose the working hours that suit you, as well as hybrid working, details of which can be discussed at interview. Safeguarding Notice The Harris Federation and all our academies are committed to ensuring the highest levels of safeguarding and promoting the welfare of children, and we expect all our staff and volunteers to share in this commitment. All offers of employment are subject to an Enhanced DBS check, references, and where applicable, a prohibition from teaching check will be completed for all applicants.Before applying, please review our Policy Statement on the Recruitment of Ex-Offenders. Equal Opportunities The Harris Federation is an equal opportunities employer and welcomes applications from all suitably qualified candidates.As a provider of employment and education, we value the diversity of our staff and students, and all our staff are equally valued and respected. We are committed to providing a fair, equitable and mutually supportive learning and working environment for our students and staff. https://www.adzuna.co.uk/jobs/details/3145636578?after_login=3145636578&apply=1&error=logged_out&utm_source=linkedin3
      • 1
      • Thanks
  23. https://www.harriscareers.org.uk/200/search-our-vacancies/career/252/ict-technician?phase_open=true&list_view=true&Phase=&Academy=&Position=8,&Subject=
×
×
  • Create New...