-
Posts
1,936 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by DavR
-
Install Windows Store App for all new and existing users
DavR replied to petben's topic in Windows 11
Adding new UWP apps for all users isn't the easiest. Yes, in theory the DISM command provisions the package, but as you've found out, newly provisioned packages don't get added to existing profiles. Currently we don't have any apps that need this, but, my solution when we did was a PowerShell login script that registers the apps into existing profiles. It looked to see if the apps was present in the profile, then added it if not. -
I think we're completely the other end of the scale in terms of attitude, here. Locally saved files are absolutely forbidden, and we still run quite a locked down ship. You can argue the pros and cons of that, but when it comes to replacing devices, we build the new device, and then it's very much pull the old one out, plug in the new one, and teacher logs on and continues much as they did on the old one, bar a few personal settings choices. Why do you allow local storage, if you don't mind me asking. Surely that's a nightmare to manage, or have you set very clear boundaries and expectations?
-
I have been considering the mental gymnastics on that one. If, as I've seen written in a number of places, the TPM chip on your laptop counts as "something you have", then surely the laptop itself could be classed as something you have, also. But then I suppose the laptop itself isn't inherently a security device. For the sake of teachers doing their prep work or school reports, I am considering if I can get away the device itself being the second factor, as it's only on that device, in conjunction with a password, can you access your files. This would treat the staff laptop the same as we treat our onsite desktops, being exempt from "full" MFA via Conditional Access, whereas anything from a device on the wider Internet would required the full MFA challenge. Not that anyone else here cares about security, so it's mainly convincing myself!
-
Ooooh, it could be. I knew of Duo, and it might well do what we want, but wrote it off as an extra cost. I'd need about 20 licenses, but could I make 10 work, I wonder. Thanks for the tip!
-
Yeah, I honestly thought it would be a no-brainer - windows login box, followed by an MFA prompt, same as all their other services. But no, they had to go make it overly complicated (classic Microsoft, I suppose). I can see where they're going with WHfB, but that seems aimed at locking down the account, on the device, assuming a 1-to-1 device model, which we know in schools is rarely the case. What's wrong with at least having the option to tie it to the account?
-
You know, I could probably find the budget for ONE key, purely for R&D purposes.....! It's a thought.
-
Hmmm, in theory that would be a portable user-based second factor, but would that not still require registration on each device? Or can you tie a FIDO2 key to a user account in Azure / Entra in a way that doesn't require that? If it requires registration on each device, we might as well go with a WHfB PIN, the config overhead is very similar. Outside of the theoretical though, there's no budget for hardware keys. What do you use yours for, @PotNoodleTech? Is it to replace traditional second factor, or do you go passwordless on certain devices?
-
I wonder if it's a case of having to be patient - sometimes OneDrive in the background could be taking longer than you think. As a test, how about a fresh PC, do the first student logon, and then leave it for half an hour, see if it takes or not?
-
Weird, not a problem I've seen. The starting, closing, updating and reopening I see all the time on new builds, but SSO has worked all the time for us. What state is SSO in otherwise for you guys, can you open the OneDrive website per student successfully without any extra prompts? I assume when you say you're doing OneDriveSetup.exe /AllUsers, that this is a) a fresh version downloaded from Microsoft, and not a pre-existing version somewhere, and b) all setups etc are completed before you're attempting the Student testing. FWIW, we didn't use Storage Sense or anything like that to manage our disk space, so maybe you could disable that for testing. Never had a problem with disks filling up, we're using the storage restrictions from within OneDrive policies, but depends how big your OneDrive's are I suppose.
-
Ha! Thanks 😉 That's about where I'd got with it tbh. Web login sounded good on paper, but the reality was a bit messy. Windows Hello for Business is the supported solution, but, is not portable between devices, which is a problem in this scenario. We already have MFA on all our cloud services, but, the prompts for this break SSO and the seamless startup of things like OneDrive client, which is a problem in the user experience.
-
Well, web log-in was a bust. Apart from being quite messy at the login screen, requiring the user to hit the sign in button twice before starting the actual sign in, and having last user remembered (ick, Shared Device remember), I couldn't quite get conditional MFA to cause a MFA prompt during the windows login, even though I had it on an external 4G connection, which should prompt MFA to kick in as it's outside of school IP range. So the end result was no different to a regular login, and still other apps are complaining they need MFA. There may be a way to hammer this until CA and login-based MFA work as I want, but ultimately it seems a very messy way of doing things. I'm now looking at Windows Hello for Business. Hopefully, if I set it up right, this would be OK for long term users and fulfill the MFA requirement. I can't quite see a way to get casual users, ie, those who might borrow a laptop for a few days at a time and then return it, set up without dropping the MFA requirement in that scenario completely. It's far from ideal, but, increasingly looking like the least painful way.
-
What's the current feeling about how to manage MFA on off site laptops? I'm putting together a batch of Windows 11 laptops for staff to borrow offsite. The model has been based around AAD joined devices only, Intune management, with the users Microsoft account for sign in plus MFA from Microsoft Authenticator. These will be shared devices, and I have 'Shared PC with OneDrive Sync' settings enabled. We have MFA enabled for any offsite login, but, this doesn't seem to apply to Windows device logins. Instead, it logs onto the device with just a password, and SSO then breaks and prompts for MFA for other applications such as OneDrive. Initially I thought password + MFA at the login box would be the best way to go, certainly it would be the conceptually easiest for our staff to understand, but the only way to do that seems to be by changing to Web Login provider. Windows Hello for Business wouldn't be the right product, as it's a per-device install, and we can't guarantee staff will be always using that device. I could relax MFA to not apply to these devices, on the logic that the laptop counts as "something you have", but that doesn't feel very secure IMO. Any suggestions welcome!
-
Ah yes, home is a very different kettle of fish. I may, or may not, still be running an exhausted HP 990c inkjet at home, due to still having a box of cheap cartridges....
-
Yeah, it is a nuisance that known folders only includes some, not all, known folders. At a guess, maybe they excluded Music and Video from GPO options as it might lead to a very large amount of data syncing, and crippling networks, as per @speakercon's comment. At a less charitable guess, they only bothered doing half the job!
-
I spent far too much time on our older Samsung printers trying to replace parts and keep them going - in the end I got a price to replace them, and was pleasantly surprised how cheap new HPs were. So we did that, and I've barely had to intervene beyond changing toners since. Granted, this was a few years back now, but printers certainly were at practically disposable prices, next to the costs of the toner cartridges.
-
I've just been prepping 24H2 this week, and have now got a working image which we'll be rolling out over the summer. FYI, the May ISO is now available, with the May cumulative already included. One thing that threw me during testing, though, was I somehow managed to create an image that installs a broken Windows Recovery partition. I don't think I would have noticed, if I wasn't testing Wipe from the Intune console at the time. The Wipe command would start, but drop out at about 20% and say "There was a problem when resetting your PC. No changes were made.". Recreating the image resolved this, though.
-
It's quite a while since I set up our OneDrive redirection, but, I used the environment variable method, as described here - https://community.spiceworks.com/t/onedrive-folder-redirection/1012141 You create a new environment variable that refers to your OneDrive location, and use GP to redirect My Documents to the %OneDriveLocation% variable. That achieved, you can then tell all your other folder redirects to follow the Documents folder.
-
Has anyone got any thoughts on what the removal of WMIC from Windows 11 24H2 onwards is going to mean for MDT? I always thought it would be deprecation of VB script that would kill it off, but wmic might get there first... From what I understand (or have read from murky Internet sources), MDT uses WMIC during the task sequence to get make and model, which is necessary for those of us who use the Total Control method of installing drivers. If, then, wmic is removed, this action may fail. AFAIK, this step is done in WinPE, so as long as your boot images still have WMIC enabled, you should be OK. I'm not sure where it leaves steps that are dependent on a WMI query, though. For instance, I have several software install steps that only run if certain hardware is present, and that's achieved by a WMI query under the options on that step. I don't know how that's evaluated though, whether it's a WMIC command, or it uses some other method. Thoughts? (Yes I know MDT is itself deprecated and unsupported, but its still very powerful and widely used. I have succession plans in place for when the day DOES come, I'd just rather it wasn't today....)
-
Chromebook Extended Updates - Opt In Required
DavR replied to DavR's topic in ChromeOS & Cloud Based OS
In our experience, I think you just have to leave it a while. I've just been to check on ours, which were expiring May/June 2025, and they're now showing as Extended Support - Enabled with a start date of June 2025. It took quite a while for this to show up, so I don't think it's something you can push through. AFAIK, as long as they're eligible and you've set that setting (and you aren't locked to a specific OS version anywhere) you can just walk away and let Admin Console and device work it out for themselves. Maybe give it a week and see what the console looks like then. -
Projector does not auto detect screen resolution over VGA
DavR replied to DavR's topic in AV and Multimedia Related
Yes, although the other way round I think. If projector is on first, then PC boots into already on projector, projector is unaware of change, so no negotiation takes place re screen settings. Incorrect image occurs. If PC is on first, then projector turns on, projector detects source during startup and shows correct image. Yup. Might be something extra in the GFX settings when I try dual displays, you never know. An extra setting to check when I get that far! -
Projector does not auto detect screen resolution over VGA
DavR replied to DavR's topic in AV and Multimedia Related
The splitter isn't faulty as such, I've swapped it out for another and the results are the same. But arguably it is the weak link, yes. One port is marked as the "Plug and Play" port, which makes sense re DDC only working on one port. I've been running it with the monitor on that port, because the other way round, I get a small image on the projector, and a distorted one on the monitor. This was round, we get a decent image on the monitor, but, sometimes, you need to redetect on the projector to get the proper image! There's no winning down that route, it seems. We've been running VGA and splitter for this long purely for reliability - a split VGA signal (used to) work out of the box every time, no settings required - where going duplicate display requires additional settings, introducing extra problems. I can try running it as duplicate display, VGA for projector and a secondary for the monitor, but I'll have to stick a graphics card in the PC. My concern then is that the detected VGA will show up very small, as it did when I ran VGA direct, and presumably DDC took hold between projector and PC, and I couldn't stretch that image to fit the screen. Dunno why that's happening, when going through the splitter the image fills the screen. Weird. -
Projector does not auto detect screen resolution over VGA
DavR replied to DavR's topic in AV and Multimedia Related
Nah, that didn't do it. Not a bad suggestion though. Low res behaves the same way as higher res. To rule out the splitter and the monitor, I ran VGA direct from the PC to the projector (well, through the infrastructure cabling). This way, gave me full resolution 1280x1024, but, at a really small picture size that I couldn't expand! Baffled 😂 -
Projector does not auto detect screen resolution over VGA
DavR replied to DavR's topic in AV and Multimedia Related
I'm not sure what the maximum resolution is on the projector, it should be fairly capable though. When it has successfully detected the right screen size, it displays 1280x1024 quite happily. Having said that though, it could be an idea throwing it onto a lower resolution and seeing if it copes better. We used to have a tiny monitor on it which maxed out at 1024x768, and I don't remember it giving us these problems back then. -
Bit of a conundrum for you guys, regarding auto setting screen size and apect via VGA. We have a PC connected to a projector in one of our halls, both a few years old but still quite serviceable. We're using a single VGA out from the PC, into a VGA splitter, to a monitor and also the projector. HDMI is not an option, VGA is the only line available without running new cables. When we start up PC first, then projector, the projector detects the PC input correctly, and shows it at the right size and aspect. However, if we start up the projector first and then the PC afterwards, something gets missed and the screen size is not detected, we get a distorted image on the projector. This is fixed by changing the channel on the remote, or using "Source Search" to select the correct source. Is something wrong in our setup, or, do we think this is the system behaving as expected? I did wonder whether maybe the PnP pin somewhere on the VGA run is busted, but then, the monitor is using the PnP port, not the projector, so that shouldn't come into play. Both PC and projector get switched off at the mains after use, so there is a permanence issue. I wondered if the onboard battery on either could be dead, but then, other settings are remembered, so perhaps not. Any ideas how I can get round this?
-
Thanks for sharing that pricing @Space_Munkey, that's really useful. We're currently utilising the free A1, plus Entra ID P1 @ about £6 per license. I'm currently playing around with InTune, and although I would only need it for a subset of our users, it looks like it wouldn't cost us that much more to give everyone EMS A3 @ £9 per license instead, covering both add-on products. Useful to bear in mind for our next renewal.
