-
Posts
1,927 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by DavR
-
On your intranet VM, what happens when you do ipconfig /all? What servers does it show under the DNS Servers field?
-
I think the only devices you'd be looking at brand new for that kind of money would be the Microsoft Education range, formerly Microsoft Hero devices. These are Chromebook spec'd, but loaded with Windows. I got given a leaflets for these, all in the £200-300 bracket, last week - https://www.microsoft.com/en-gb/education/devices I'd be reluctant to buy a Celeron though, and expect it to do full domain functionality. Anyone else have any experience with these devices?
-
Nothing to do with the old DC, leave it in it's grave for now. We're talking about other machines still looking for this server by IP. Check the settings on your DHCP servers, to see if they are still handing out the IP address of the dead DC as a DNS server (DHCP option 006). If you haven't removed the IP of the old DC, it may well still be here. As an example, on the VM your Intranet server is running on, what happens when you do ipconfig /all? What servers does it show under the DNS Servers field? The sites issue may be because the firewall on the affected VM is treating local subnet and remote subnet clients differently. Fix the DNS bug, and you allow it to choose the correct firewall profile.
-
If it is this problem, then this setting is either going to be in the list of DNS servers handed out by DHCP (so, in the DHCP options), or the list of DNS servers set on the NIC of the machine, if done statically. This problem would be occurring on the host machine that you can't reach, rather than a client machine that can't reach it. Maybe do an ipconfig /all from a command prompt on the unavailable host, and see if your old DNS server is listed.
-
If you are getting the network adapters showing as "DOMAIN.internal 2 (Unuthenticated)" or similar, which is fixed by disable / enable of the adapter, this normally means yup, it's DNS after all. This state occurs when the machine can't find a DNS server when it needs to, to authenticate it's on a domain, and choose the domain firewall policy, rather than public. If it defaults to public, it's going to lock down a bunch of ports. Look at the DNS server settings, either static or being handed out by DHCP. Sounds to me like your old DC is still in there as a DNS server. Your intranet VM then looks for that DNS server, fails, and defaults to public firewall, at a guess.
-
ActivInspire crashes if more than one user logged on
DavR replied to DavR's topic in Promethean Direct Support
Thanks for confirming that @DangPro. Do you know what sort of timescale we're expecting on that? If it's not going to be this side of Christmas, I will probably roll back to v2.9 in the meantime. -
We recently upgraded ActivInspire to version 2.17, and a problem has come up when we have multiple users on a computer. If we have User1 logged on and using ActivInspire, when User2 comes along, uses Switch User and then tries to open ActivInspire, it crashes. There are a few different ways that Inspire.exe might die, either with an error message or silently, or in a few cases it has been activdashboard.exe. Either way, I can reproduce a failure if you have two people logged onto one machine, trying to use the program. We use Switch User a fair bit in the school, we're a primary so it's usually just the class teacher, but we do have language, music and art teachers that drop in to teach classes during the day. Is there a fix for this, or is it a known bug? We upgraded from 2.9, where this wasn't an issue. Thanks!
-
It always felt to me that navigating and fixing the appalling application form was part of the application process. I wonder how many prospective employers evaluate how well you've manipulated their form, as a measure of your office skills.
-
You can still back the recovery key for devices without TPM, just enable the backup to Active Directory options in group policy. You will still need to manually run through the BitLocker encryption wizard though.
-
Not that I've found, using vanilla deployment with group policy. Without a TPM, you need to either stick a pin code or password in there, I found no way to automate that.
-
I'm buying 22" height adjustable as a minimum. We still have old square 17" and some 19" widescreens around the building, but not in any of the offices, and as old 4:3 projectors are replaced, 22" widescreens are going into all teaching areas as a matter of course. SLT & myself have 24". It just makes such a difference being able to put two documents side by side. Thinking outside the box, can you take out and reuse the flat panels from the RM Ones? Dell all-in-ones you could, way back when. If you can get a job load of VESA mounts for cheap, might save you money you could use elsewhere. But hell no, do not put any real money into new 19" monitors in this day and age, it's a false economy.
-
A postscript on the MSI install of Minecraft........... turns out it's got an autoupdater attached! Our deployment updated itself from 1.12.0 to 1.12.5 this week without warning, causing minor havoc in SCCM. It's a matter of preference, but personally, I like to nobble all autoupdaters so I know what's on my network. I'm just preparing an updated deployment, if anyone else wants to know how to disable this feature, you need the change MSI property INSTALL_UPDATER to NO (well, any value other than INSTALL really). I've done this by creating my own MST with Orca, it's under the main Property table.
-
YouTube - Do you block or allow access to students?
DavR replied to Nausing's topic in How do you do....it?
Our ISP, LGfL, were working on a system just like that but shelved it for some reason. It's a real shame, as the idea of being able to whitelist videos really appealed. I've yet to find a way of allowing a single video. -
I've yet to meet an agency teacher with their own professional email address. Arguably you'd be in even more trouble GDPR wise putting a third party email address onto your internal all staff distribution list.
-
Long term supply and agency you have to treat as a full member of staff really, otherwise it is very difficult for them to do their job. I share your unease but very difficult to get round in my experience.
-
Careful with that. If the policy is teachers take the register, TAs may well just share their MIS logins with the student teacher. They don't see it as access to MIS and student records, just the password to do registers. We get it the other way round all the time, teachers go on PPA and leave a TA in charge, and instead of anyone requesting I give said TA a login, they'll just share theirs. You can tell them til you're blue in the face, but they'll keep on doing it. Depending on your MIS, can you give the student a super restricted MIS account? Sadly I think most MIS just give blanket access to the student record when you give permissions to run attendance though.
-
My two-penneth..... after being confronted with an almost tearful teacher this lunchtime, who's work crashed at lack of disk space, I finally gave in and put something in place to manage this. As with everyone else, both my ntuser.dat and ntuser.ini files were not giving useful dates that I could use DelProf2 to work with, so I've gone with the nuclear option - a full clear down of roaming profiles, four times a year. I've done this with DelProf2.exe /r /u, pushed as a scheduled task via group policy. It'll ignore any logged on user and any local profiles, the only inconvenience is that other users will have a slower logon once a quarter.
-
Good to know, thanks We've only put out Chrome, its the one people mostly seem to ask for, but I've let users make their own choice on default browsers.
-
How is Firefox in enterprise these days, I haven't looked for ages. Last I saw Mozilla weren't doing an enterprise version, but there were a few unofficial ones.....
-
We had a similar issue with our guest wifi, Aerohive so a different system, but similar scenario. We could access external web content, but not LGfL. With LGfL, you're part of their WAN, so when you access LGfL services, you're not actually going onto the Internet par se, just accessing the WAN. Your Local LAN setting probably blocks access to everything bar the gateway out of the WAN to the Internet, thus also blocking LGfL services. That's my understanding of it anyway. We allowed the Guest SSID access to a 172.x.x.x range, as well as Internet, and that released LGfL services.
- 1 reply
-
- 1
-
-
Depends on your environment. We're still using roaming profiles for staff, by default Favourites sit in local app data so do not roam, but there is a setting in GP to put these into roaming app data instead. The setting for this is "Enable the creation of roaming copies for Google Chrome profile data" in the user policy.
-
We use the Feem app to transfer files between iPads and Windows. You have the Feem app on the iPad, and a Windows client on the teacher desktops. Students then send files to the teacher over the local wireless network, no cloud, no cables, all internal (I say students, it's normally staff that do it for them). It works well for us, but does unfortunately make it easy for people to dump large video files on the Windows network.
-
We treat them as regular members of staff, they get the basic level of access to everything. It would be nice to lock them down to just their own files, but realistically, they need access to all the same teaching resources as a regular member of staff. Anything personal like SEN records etc is already restricted from general view anyway.
-
We have switch user enabled, it doesn't cause us any problems performance wise. Or at least, none that have been reported to me. We are a primary, so a teacher will be sat mainly at their class computer, but subject teachers sometimes drop in during the day and need to take over for a few hours. Switch user is the ideal scenario for us in that scenario.
-
Congratulations btw @Ratcliffepg, that's no mean feat to achieve
