Planehazza
Members-
Posts
325 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Planehazza
-
School iPads linked to previous ASM/ADE/DEP
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
We've currently got 591 iPads in our ASM. I, alone, had to push them up to DEP manually using a 2010 Mac Mini. Yep. It sucks 😅😅 The onboarding of the existing schools into IT was a nightmare and noone knew (convinient) who bought the devices and when. Doesn't help that of our <10 schools, five LAs/support companies have been involved in handovers 🤦 -
School iPads linked to previous ASM/ADE/DEP
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
Interesting, I never thouught the supplier would be able to reallocate these, but it's extremely unlikely this information is anywhere now. It's a very small primary school (~20 students per year group on average) and staff turnover has been... interesting. -
School iPads linked to previous ASM/ADE/DEP
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
Spoken to Apple ASM UK support and been very helpful. I was escalated up and I'm awaiting an email with various verification steps. It might take a few days/weeks, but it sounds like Apple will be able to get me into the previous ASM account to release the devices. I can confirm, that Apple themselves cannot release devices from an ASM, but it sounds very hopeful they can help via other methods. -
A year after taking on board a school into our trust, teachers are still coming forward with iPads that they've "found at home" or "found in cupboards". This time, it's three 7th gen iPad LTE, a good £1500 worth of stuff. They're locked to the ASM account of a previous IT support who aren't able to assist (yet) with releasing said devices. I do not recall ever being given handover documents for this and Apple aren't really being helpful. Has anyone ever managed to prove ownership to Apple to have them force transfer iPads from from ASM to another? Any tips? the EU support wasn't really helpful; I don't think he understand what I was meaning by organisation and didn't appreciated that the school and the central team are the same company... I'd hate for these three devices to just get skipped 🤦 I've read, and previously believed that Apple themselves cannot release iPads from one DEP/ADE to another, but the agent at Apple I spoke to certainly seemed to suggest it was possible, but he was really quite confusing to be honest.
-
Locker here too. Very good support. Locker itself doesn't have great features for AD group membership. It will natively allow for identification of teaching/non teaching, but you cannot natively put SLT staff into an SLT AD group, FirstAiders etc. Requires custom scripts and UDFs. Not had much luck getting this working with Bromcom but worked well with SIMS (the irony).
-
School burns while Fire evac prints - InVentry & Papercut
Planehazza replied to EliteCommander's topic in Physical Security
Weird. I've added a duplicate queue to my print server, essentially two queues to the same copier. I've added the printer name FIRE EVACUATION to the ignore list following the guide, restarted the service and confirmed that the deleted printer in PaperCut does not reappear. However, clicking print test page from the server to either queue on the same IP port, nothing happens. I see the job appear immediately disappear from the print queue just like what happens when PaperCut handles it. Something's not quite right. Does PaperCut not liking having multiple printers on the same port? I see nothing relating to my user or document in Jobs Pending Release section, so it's like PaperCut is instead immediately rejecting the job? The Job Log section, however, does show it as printed, which it certainly is not. 100% the correct IP, I'm sat next to the copier and have just checked it locally. Thanks!- 23 replies
-
- evacuation
- fire drill
-
(and 2 more)
Tagged with:
-
School burns while Fire evac prints - InVentry & Papercut
Planehazza replied to EliteCommander's topic in Physical Security
Hi, This link is dead now it seems. Is there an updated article I can look at, please? EDIT, for anyone else needing it: https://www.papercut.com/help/manuals/ng-mf/applicationserver/printer-add-remove-printer/- 23 replies
-
- evacuation
- fire drill
-
(and 2 more)
Tagged with:
-
iPads & MDMs (How are we doing it??)
Planehazza replied to MrIlly's topic in Mobile Devices & Tablets
Similar situation here. Teachers all have custom admin roles to reset student passwords, but they're not prepared to manage these themselves. Getting curriculum and IT policies to align is half our battle too. IT say no generic accounts, but how do you get a KS1 student to remember and email address and password? It's just bonkers. I wanted to implement a solution from Clever, but unfortunately it was shot down by the money team. -
iPads & MDMs (How are we doing it??)
Planehazza replied to MrIlly's topic in Mobile Devices & Tablets
Been Managing iPads via VPP/ASM/MDMs (Meraki and Lighspeed) for 10 years now, and as others have yet, the best functional solution I have found is 1:1 mapping. The :1 doesn't have to be a real user. We (me in IT) have implement pseudo accounts, ie [email protected] and assigned iPads in lightspeed. Teachers are instructed to manage this in the classroom using register order or a paper check sheets, but it never actually happens. The ideal solution would be have an actual login function with devices in shared device mode via MDM, but again as said by others, it's bizarrely still just not there. I've attended numerous Lightspeed webinars and I think even Lightspeed are aware this is a major issue of concern, but I think it depends on Apple functionality that just isn't there. It's really annoying and is quite a serious safeguarding concern, particular in primaries. We just have Lightspeed Alert set up to alert DSLS and they attend the classroom as the alert comes in to find out which student has device X or Y etc. So many potentials cracks or flaws for vulnerable students to fall through, but haven't found a better solution... It's a while since I've looked at this in great detail, so I guess like OP, if anyone knows a way to (without additional cost, that's another problem...) to allow students to sign in and out of iPads (and not be able to use them otherwise, like a Chromebook etc) it would be a game changer. I'm aware of federating accounts in ASM against Google, but it's useless without a true login feature. Manage iTunes accounts are pointless if they still force you to 1:1 assign devices. For those that use Lightspeed for filtering and MDM, I do fancy trying this, just not sure how easy/suitable it is for students. Also, it would mean having to convert ~580 iPads and redeploying config/setup files to them, meaning they'd all need wiped and set up afresh. https://help.lightspeedsystems.com/s/article/device-management-shared-ipad -
Yeah mate, SSL decryption strikes again. Added the RDG addresses to the SSL exclusion list.
-
Slight change of subject, and bit of a thread necro... Anyone know how to make GCDS honour group email changes? I want to change email group OLD-AllStaff to NEW-AllStaff, and have I updated the LDAP group search rules, but instead of amending the existing group in Google (like it would a user object) it's just treating NEW-AllStaff as new group and creating it. It doesn't seem to link groups with immutable IDs like it does users, so I'm fearing the answer is "you can't". I can just use GAM to rename them all in Google and then make the same changes in Google with sync temporarily disabled, but I was hoping for a more standard GCDS approach.
-
Ah nope unforunately not. Our papercut seems to be using hexadecimal, and when I enter the ID into cell B2 from the papercut primary ID field it comes with with !VALUE errors If I convert to decimal and punch that number in,the resultant number for net 2 doesn't match what I see for my fob that is already registered to both...
-
Update... I hate these kind of topics. Turns out it's the Lightspeed agent filter and that in my mind fog of staring at this problem for so long I overlooked something embarrassingly simple... if you don't install the CCM client on the PCs duing the TS, then subsequent deployed apps do not install either. I started installing these manually, testing as I went and once I'd installed Lightspeed client, bam, broken. No idea why it has suddenly become a conflict, regardless of version. Support ticket in with lightspeed in the mean time... 🤦🤦
-
Yep, so it's definitely the SCCM agent at fault. If I run a TS that does not install the SCCM client I can connect to external RDGs just fine. If I install it manually from the SCCM CCM share, it starts failing, and subsequently removing it does not restore functionality. This makes me suspect client settings but I cannot see anything that would affect it. Does SCCM client enforce anything TLS or NTLM etc wise that could be causing this headache?
-
After many hours (basically a whole work week) of trialling, troubleshooting, it seems that SCCM client is at fault. I went through the steps of the SCCM TS manually, installing OS, updates, apps etc one by one manually with two reboots between each step and and it worked until SCCM agent went on. I now suspect that either client settings are corrupting something, or the agent files aren't updating. This would explain why Windows 10 PCs were working fine, and W11 were't. I put an affected PC back to W10 and the problem started happening there, so it seems like a recent SCCM update has tweaked or broken something...
-
Yep, NTLM is something I've been looking at too, but I can't see why this would work on clients that have never seen the domain, even when no GPOs have applied. I've looked at this and set the value to 3, to no avail: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-security-lan-manager-authentication-level
-
Bit of an odd one that has been stressing me for days. Just wondering if anyone has had this? The issue Connecting to internal devices via RDP, works perfectly fine. Connecting to RDP gateways for Iris Financials or the LA's payroll systems etc, work fine on W10. Windows 11 Pro Education, no joy. It prompts for credentials, accepts them if they're valid, but then sticks on 'Initiating remote connection...'. Clicking on details when it times out, I see Error 0x204 It also shows the timestamp in UTC and American date format, so it's an hour behind our GMT+1 I doubt this is anything of note though, as it works with w10 devices. Troubleshooting thus far We don't use a captured imaged, just a wim that I've injected some files into and stripped various AppX packages like Solitaire, Xbox etc. However, I have ruled this out as the cause by replacing the wim with the bog standard, untouched W11 24h2 install.wim. We use Lightspeed but I've made a test SCCM task sequence that doesn't deploy them, so ruled that out also. Windows firewall has been disabled entirely, no joy. Since discovered that the same TS works for these gateways only if the client never sees our domain, ie workgroup. This screams a bad GPO somewhere, but I've got the clients joining a root level OU that is isolated from all GPOs. If it domain joins, then put into a workgroup and rebooted, it still fails, so it seems that joining our domain is breaking something and removing it from the domain is not enough to revert whatever this is. I've tried various suggested reg keys from googling but no avail I can't see any obvious event logs, but if someone with more RDP experience than I can tell me precisely which logs to look at that would be a great help Desperate for help if anyone has any ideas. Thanks!
