Jump to content

DavR

Members
  • Posts

    1,927
  • Joined

Everything posted by DavR

  1. I see stuff like that on the Repair Shop, and it really is fascinating, as well as very satisfying. I'm not sure I'd ever have the patience or dexterity to do what any of those guys could do, though!
  2. I've always aimed for i5, and fallen back on i3 if prices demand it. TBF for what we ask of them, i3 is probably fine these days. Most of our desktops are Microsoft Office + web browsing these days, it's only mine that does anything remotely intensive.
  3. I used to do a lot of walking, green spaces and/or general exploring, between 5-8 miles at a go. Good exercise, good for your mental health, and ideal for a Sunday so you're at least mildly pooped by bedtime Sadly I can't really do it at the moment due to health issues, but I'm working on it. I used to do gym once a week, but currently lapsed. I kinda loathe it, but also, after a good session you can feel great afterward, it's a great stress buster. Since I reduced my hours earlier in the year, I've been keeping moderately into the art scene, and taking advantage of being able to visit galleries on a weekday when they're quieter. Some of them have been baffling, but some I've found generally enriching, if I can get my head into the right space. Loving the Impressionists, lately!
  4. Another +1 for the HP M400 series. We have M402 and M404 printers in use, each shared between two PCs, but there's probably a newer iteration now. The M404 I seem to recall we initially had some trouble with the devices not waking from sleep, but a few driver changes and that seems to be resolved. I personally wouldn't even consider consumer grade inkjets, yes they're cheap, but they're only going to cause you trouble further down the line. Cheap in purchase cost, expensive in maintenance time.
  5. We set auto download and schedule the install, and specify a deadline in GP. This forces the updates to install in the background during normal use, within a few days of becoming available. We've then got the automatic reboots turned off, with active hours set 7am-7pm. Then finally we've got reboot notifications turned off, just on the laptop trolley OU. In this way, the laptops take their updates in the background during business hours, but don't bug the user for a reboot, as the device will be shutdown and restarted in the normal course of events (we don't use sleep or hibernate, closing the laptop lid will cause a full shutdown). I know some people prefer to wake devices from sleep during a maintenance window, but always felt like too much faff for me, and I've never been a fan of sleep or hibernate. I've not had any complaints about Windows update slowing down start ups, as most of it happens during shutdown, and our laptops are usually up to date in WSUS.
  6. We had to put a policy in place to prevent staff using their phones to take pictures in the classroom, and that any picture had to be taken on a school issued device. To then try and say staff shouldn't be using a school-issued mobile phone seems a bit strong. As long as you've got AUP in place, policies that state that devices can and will be searched/monitored, and the devices enrolled in an MDM, I'm not sure what more you can be asked to do. Beyond perhaps a safeguarding monitoring system client installed, and I don't know if those even exist. I'm sure you've got a good business case for using the issued mobile phones, so I would note their concern, but put it down as an acceptable risk. Maybe you can do a risk assessment from a safeguarding perspective and get it signed by SLT to say that you note the risks and here's how you've mitigated them. Or a DPIA from a data protection angle, perhaps.
  7. DavR

    System Image

    Most imaging solutions will require you do either a network boot, or boot into some kind of boot image, before applying a new system image. Applying a new system image is the same as reinstalling Windows from scratch. Anything installed on, or saved on, the pre-existing Windows installation will be wiped. If you've got the software automated to reinstall (eg via Group Policy or SCCM/InTune) then it will reinstall, otherwise it's a manual reinstall of that software. I am not aware of a way of taking a clean system image and using it to "upgrade" existing installations, although others may know of a way.
  8. I've had the same with Amazon Basics, I've replaced some of our trunked cabling with Amazon Basics HDMI with great success. I was as surprised as anyone that these were the more reliable!
  9. Not with the Lenovo 100e, but, we've had that failure a lot with the Lenovo 300e 2nd Gen MTK - Thread on this here. Having said that, we've had very few failures with a later batch of 300e which are 2nd Gen AMD, so I'm blaming the MTK (Mediatek) chipsets.
  10. That's right, although the install process should be pretty much the same - yours will be installing Creative Cloud + Acrobat, mine just does Creative Cloud. Either way, it should just be a case of getting that installer to run. Best of luck!
  11. That's a weird one. If it's the MSI version, you should be able to look in Event viewer under Applications to see what errors it's kicked out. Alternatively, you could run it without the /q and see in real time what errors it hits. We're not doing ours through InTune, we're doing it by startup script, but we are calling the MSI to install it. Our command line below. msiexec /i "Creative Cloud Desktop App 5.8.0.msi" MSIRESTARTMANAGERCONTROL=Disable /qn
  12. Yup, it's all run from a client. I suppose you *could* run it on a server if you needed to, but it shouldn't be necessary. The theory being, with Minecraft Education, your class teacher would spin up a server, children connect, and then it's shut down at the end of the lesson.
  13. We use a Hyper-V SET on our Server 2022 box, and we've not done any extra config on the switch end, it's all managed by the OS.
  14. You've got "setup.exe --silent" as your install command, but I don't see a setup.exe in the root of the package folder? If you've created that in Adobe CC packager, I think it's the MSI setup you need to call.
  15. I wouldn't like to say definitively, but, we were in a similar situation, and another 3 year OVS + a few extras was cheapest for us. We looked at M365 A3, and that would have worked well if we'd gone completely serverless, but add on licensing the servers separately, and it was more expensive. Microsoft EES - we didn't look at this route. Yes these have gone down from 1000+ users to 100+ as a minimum for entry, ask your reseller if this might be an option. Link here for differences between EES and OVS - https://download.microsoft.com/download/3/9/0/39090891-52ff-46ec-aa21-57bbe61981aa/Volume_Licensing_Comparison_Academic_and_Partner.pdf
  16. IIRC, as long as you buy machines with a Windows Pro (I think) license, then if you have a Windows product in your OVS subscription, that entitles you to an Edu/Ent upgrade. I think that might be what "Windows Edu Per Device 11 Education" on your agreement might be, but don't quote me on that. Anything on there with 60 is probably your Full Time Equivalent (FTE) licensed product under the OVS agreement. Your FTE products allow you to use that item on as many devices as necessary across your school for the use of 60 FTE teachers (kids go free). I'm not sure about the perpetual licenses, we don't currently have any. But my guess is everything you see there is an annual subscription through OVS. If you don't have any existing perpetual licensing, then buying your licensing outright (especially the servers) will be quite pricey. We recently renewed our licensing, from a not dissimilar position to yourselves, and ended up getting a new OVS, plus a few sundry other items separately. Your best bet is to talk it out with a licensing reseller though, Microsoft licensing is labyrinthian at the best of times.
  17. OVS agreements should be still available, we started a new one just this month. Do you actually own your licensing outright, or do you just have the licenses which came with the machines? If you were using the OVS agreement, it's likely you were using that as a "top up" for certain things.
  18. If you're using extended desktop, my understanding is that this is using two monitors as one big monitor. I don't think there is a way to remotely control an application from one side of your desktop to the other. It sounds like you're either looking at running that app blind, or, using duplicate displays instead. That said, it does depend on the application. What are you using on the blind screen? It may be that there is a secondary way to control that. Eg, an Intranet page could be displayed in a web browser, but you could be looking at the backend in a different program at the same time.
  19. IIRC, when you rebuild a workstation, the workstation will need to redo the hybrid domain join. It may not do this immediately, it might take a short while. Although I must admit in my experience, it's always been ready in time for first login. If you run the PC for a few hours, do you see an update on the machine account in Azure? You can force the hybrid domain join by running a task from Task Scheduler - Go to Task Scheduler Library > Microsoft > Windows > Workplace Join and manually start the task “Automatic-Device-Join“. If you still can't get SSO to work after running that task, it would suggest to me that hybrid join is failing for some reason.
  20. I assume it'll be msiexec /x{GUID} /qn That's the usual silent uninstall command for Windows Installer applications.
  21. Not InTune, but for Adobe CC deployment generally, we create an install package that is just the Adobe CC client, and within that package give the user the option on which packages to install. It's going to depend on your usage scenario. If you know you're going to definitely use a set of applications, then by all means deploy those. We only use it sparingly with a few teachers though, so I deploy the client and let them choose the apps they need themselves.
  22. You could just drop the "if folder exists" condition to simplify that mapping. If the folder doesn't exist, it won't map, and will fail silently. I'd second using a group. You'd then only need one condition, if user is member of group, and that will map the drive to the targeted user. For what it's worth, we don't use "Run in logged-on user's security context".
  23. Just to bump this one up - I'm still getting this error on notification emails from various threads. It's very odd, I get into the headspace of the thread in question, and I get the last message on the above thread - "Its much better than Hot Potatoes" - which is such a bizarre sentence out of context!
  24. Personally, I wouldn't bother - when they first logon, it will happen automatically. If for some reason you did feel the need, I'd say you'll want to write a PowerShell script or something to automate the creation of folders and setting perms. I'm not aware of a native feature that does this automatically, like AD does with home dirs for instance.
  25. Why would you want/need to do this? Profiles are created at logon only, I don't think there's an inbuilt way of pre-creating them. The permissions involved are fiddly enough that I really wouldn't bother unless you've a very specific usage case to do it.
×
×
  • Create New...