Jump to content

Planehazza

Members
  • Posts

    323
  • Joined

  • Last visited

Everything posted by Planehazza

  1. Got a weird one. A lot of our Dell machines, particularly 3060 and 3080 will not get past "NBP file downloaded successfully...". After that, when it would then start to pull down the boot wim, it loads either Windows boot manager or system diagnostics. HOWEVER, and this is the weird part... if the existing OS on the device already has the SCCM client install and I add it to a device collection that has the task sequence deployed to it, the device PXE boots just fine. I don't think it's NIC drivers, as it's not even getting to the PXE BE yet; it can't even load the wim file UNLESS the SCCM client has been added to collection that has the task seq. deployed to it. Any ideas on where to look please?
  2. Yeah Lightspeed as an MDM is clunky, and I preferred Meraki in my last role, but secured a 200 device free account when they were available and we use Lightspeed for filtering in my new place. It does a good job though, but I recently seem to have issues with app updates failing and them being stuck mid install.
  3. It's very simple to install and set up; it's only time consuming if you have many DCs. The only caveat is the way that it means users can no longer change their password via their google account settings, but for most this is absolutely no problem. Tell me 5 people at your school that proactively change their passwords without being made to... The SSO profile bit for the change password redirect URL is a bit fiddly and I couldn't get it to work. The Google Password Sync documentations says you can assign it to the organisation SSO settings OR you can create profiles and assign them to OUs, but the latter wouldn't work and the google lad wasn't really that helpful, so I ended up just applying it at org level. Again, not a problem as people with password change admin rights (teachers and SLT at my schools) can still reset forgotten google passwords for students anyway. The documentation for the most part is pretty good and will give you the CLI to create and set up the project. It's a lot more straight forward to set up than GCDS was and that wasn't really too bad. Whilst your in the Google Cloud Console setting this stuff up, take a look at GAM. It's a third party CLI tool, a bit like PowerShell for O365, but not as powerful.
  4. Urgh, think I may have sussed it, and if correct, it's really f***ing annoying. Stand by... EDIT: in the default policy at root level we have our password policy set, and minimum age for changing is 1 day. I coincidentally changed my admin password at 4PM yesterday and I cannot change my password today either. I've change it to 0 days and still no luck but I suspect the policy hasn't updated yet. EDIT2: Yep. Just done a live test with a friendly member of staff whose password was change more than 24 hours ago and it worked perfectly. So password sync is working for accounts within my test OU, just now need to get the SSO profile to come out of 'Draft' status so I can apply it to the Google OUs so that any google password change attempts redirect to a instructional site I have created. Any ideas on why it's still 'Draft' status 24 hours later?
  5. Yeah that's what I understood it to be too, just confusing the hell out of me as to why it's not working for this test account. It'll turn out to be some horrific, non related coincidence, I'm sure
  6. Just built a VM without lightspeed agent and still have the same problem. If I reset the password for the test account on the DC, it works. If I make the test account change the password at next logon, it also works. However, if the test user simply presses ctrl alt del and 'change a password', it says the password isn't complex enough. I'm confirming with certainty that the passwords are unique, haven't been used, and matches the requirements. It's like the user don't have permission to change and sync the password. I need to find the logs to see if it's Google or AD breaking the chain... I've just asked a real user to change their AD password and they had no issue, and I've moved the test user outside of the Base DN scope for password sync, but it would NOT accept the password. Something very weird is going on...
  7. I have indeed. With them all authorised with a service account and application security context. I have double checked my project settings and that the admin account is authorised to use the service account and all checks out. I suspect if any of this was wrong then I would not be able to change and sync test account password on the DC. We use Lightspeed so I'm wondering if that is causing a problem as I believe it installs itself as a proxy...
  8. Has anyone implemented Password Sync to sync AD password changes to Google Workspace? I've got it in, but having problems. If I reset the password on a DC via a domain admin account, it changes and syncs just fine. However, if the test user does it, I receive the windows password complexity message. I can confirm with 100% certainty that the password is meeting the GPO defined password complexity. Has anyone encountered this? the only step I haven't completed yet is the SSO profile that redirects users to a Google Site to tell them how to change their password, but this should have no bearing on the actual password sync process. Anyone been in my shoes?? Ready to give up on the project... Thanks, Harry
  9. Yup, Jigsaw24 have done this for me in the past. Alas, we took over from the local authority last year and we were given absolutely zero information on where they were purchased. I could have tried the obvious people and fed them a couple of sample serials, but they all needed wiping and resupervising anyway, so adding the DEP enrolment to the blueprint was just one extra step
  10. I have this set too, but for some reason it has never worked for me. Though this is because I'm manually having to (via blueprints) prepare 500+ iPads via AC2 to enrol them up to DEP/ASM. I assume the auto assign works when a resellers assigns them to my ASM organisation.
  11. I've been plague with a super frustrating problem assigning devices in Apple School Manager to my MDM. I would select devices and when I click on the 'Edit MDM Server' button, only 'Unassign from the current server' would appear to select. The work around is simple. Just click on Apps and Books, let it refresh itself and list the books and this will bring back your MDM server in the Devices section
  12. Sorted. For any future unlucky sod dealing with this, I hadn't set up my connection lists correctly. You have to define ALL the SPSite URLs in the connection, then your scoped views will be able to query all the sites for child document libraries.
  13. Hi, I have been tasked with migrating ~250 (potentially 2000+) SPO sites to Google workspace in very little time. Staff were originally going to simply pull the files down from SPO and reupload them manually to Google, but I'm really not keen on that. I have configured Google Workspace Migrate and set up all the on prem servers and required config, and am able to move entire sharepoint site contents to google. However, I'm having trouble mapping libraries. I'd rather not move entire sites as a lot of files and resources that make up a site are unessecarily included wasting time and space. Whenever I map an SPLibrary or SPFolder in the csv file, I get the following error: [font=&amp]The request made is invalid: Code:InvalidImport No object was found at the specified location[/font] Has anyone used this functionality and managed to create a mapping file that points tells an SPO library to go to a Google Drive? Thanks!
  14. Yep, one of the first things I set up on the user search area: [ATTACH=CONFIG]68773[/ATTACH]
  15. Anyone ever had an issue with GCDS not paying attention to entires in proxyAddresses attribute? I've tried "SMTP:[email protected]", "stmp:[email protected]", "[email protected]", "a.bcd"... no joy!
  16. Doh, you're right, can't believe I forgot that, thanks! Also, I worked out my issue with knowing where to define the OU mappings. I turned off the option in org mappings "do not create or delete Google Organisations..." which then allowed me to tell the search rules to derive target Google OUs from Org mappings. Result! Current issue is syncing group managers. It doesn't seem to be honouring the managedBy attribute defined in the group search rule...
  17. Hi all, Just bumping an existing thread rather than create a new one. Just looking for some advice. The gist: AD and Google are already built with OUs created, and we have six sites, each with the following OU structures: Site1 >Groups >Staff >Students > Intake 23 > Intake 24 etc. In my testing OUs, I have defined one to one OU mappings for each OU. This works well and reliably but it's going to be a lot of work for each OU for the six schools. Is there a way I can sort of semi dynamically 'auto map' AD OUs to Google OUs assuming the names and structure are the same? Failing that, and I need to define each mapping manually (and remember to do it annually during induction) is there a way I can do this via CLI or batch file etc? I'm also getting a little confused as to where I should be defining where user objects go to when synced to Google? Do I map ou=intake xx,ou=students,ou=site x... to ../site x/students/Intake xx in each search rule, or in the org mappings section? Or both?!
  18. Thanks all, I'll keep all this in mind. I'm tempted to give this a trial, but does it seem that Clever has outages regularly?
  19. THey have a page on their site that says it's not yet available to EU/UK due to GDPR, but I think it's an outdate article. Certainly the research I did today suggested it was now indeed GDPR compliant... This suggests not... https://support.clever.com/s/articles/236009108?language=en_US However this suggests it is? https://support.clever.com/s/articles/202043013?language=en_US#gdpr I would like to see what Wonde can do as suggested above, as we already have Wonde integration in several of our schools
  20. We're having trouble getting teachers and students to use their Google accounts on the Chromebooks, with them saying it's too hard for the Y3-Y6s to remember their username and passwords. I want a simpler solution for them and have discovered Clever, where a selection of images or a QR code that is generated uniquely for each student can be used. Just wondering if anyone has used this service? It appears to be GDPR compliant and is free for schools: https://clever.com/products/badges Thanks!
  21. Hi all, This article for reference... https://help.lightspeedsystems.com/s/article/group-management-add-users-to-groups?language=en_US I have two trolleys of 30 iPads, that are shared amongst the school. Year 6 could be using them one lesson, year 4 the next. Every teacher has their own iPad and I want to make it that so any teacher is a teacher of the Apple Class 'Trolley 1', but Lightspeed MDM only lets me assign teacher role to one user per group. Has anyone found a way around this please? TL;DR - I want all teaching staff to be an apple classroom teacher of all apple classrooms using LS MDM managed classrooms. Thanks!
  22. That’s the plan…well to be more precise I’ll probably use generic accounts so the trolley iPads aren’t 1:1, as its primary and the kids just go and grab any device. Teacher devices will be 1:1 assigned to staff. The problem is currently that the root functionality won’t enabl and I don’t think the amount of users in a group would break it at this level. Otherwise light speed would have documentation with big warning’s saying early on to not exceed 99 users in any group ever… Currently I only have one test class in ASM with a teacher but no students. Does light speed simple cease working with classroom if there are no valid classes? Ie I can’t even enable it? Ifso that’s pretty stupid…
  23. Hi all, Me again. Got my iPad enrolment working nicely, albeit slowly until I get a decent USB hub. I'm trying now to get Apple classroom working via managed MDM (I'm bored at home and have the option of overtime so why not), but am struggling to enable the functionality. I'm working through this LSM guide and am struggling to see any steps I've missed or not done correctly: https://help.lightspeedsystems.com/s/article/device-management-apple-classroom However, as per my screenshot, I cannot click save to commit the tickbox to enable it: There is a message there that is always there for me, but does not appear in the LSM documentation: "Classroom is not able to be used in groups with more than 100 users." Obviously, with two high schools in Google Workspace that is synced to LSM, I will have multiple groups with 200+ cohorts. Am I really to restructure my entire Google OUs to have less than 100 users per group? I thought at this level I was just enabling the Apple Classroom functionality before enabling the feature on a per group level (where obviously I would target class size groups). Thanks!
  24. SOrry, I know this is an old thread, but any ideas why Home > Device Management > Apple Classroom > Enable Classroom can be ticked, but the Save button will not let me click it?
  25. Anyone know if there's a way to tell multiple iPads to remove a profile? I've had to deploy a WiFi Profiles as part of the prepare step in AC2, but I don't want that on the device once it has pulled down the correct SSID details from Lightspeed. The reason for two is, as I'm sure you've all encountered before, something on our network is blocking part of the enrollment stage I get a horrible long error on AC2 if I deploy the school WiFi in the prepare stage. TL;DR - is there a way in Lightspeed to remove an AC2 deployed profile from multiple devices at once? Cheers!
×
×
  • Create New...