Jump to content

DavR

Members
  • Posts

    1,927
  • Joined

Everything posted by DavR

  1. Oh! How did you manage that, do you know? The guy I've got seems perfectly willing to action my request, but entirely clueless as to how.
  2. For that sort of control on macOS, you'd be looking at some form of MDM (mobile device management) solution. Using this, you can create profiles, which are files containing settings that get enforced on machines / users. If you have an Apple server on site, you can get the Server app for about £20-30, which contains Profile Manager to do that. Otherwise you'd be looking at something like Meraki or JAMF for a cloud based solution. I think Intune has some Apple profile capabilities, but I've not used it myself. School Manager doesn't, I don't think, it's more about Device Enrollment and licensing.
  3. There's little or no difference in user experience on the enterprise version as far as I'm aware (happy to be corrected); it just means that you can control it properly with group policy. You're an enterprise, go ahead and use the enterprise version
  4. Hi @Wosburn7, The MSI installers can be downloaded from here - https://cloud.google.com/chrome-enterprise/browser/download/. You download a zip, installers ADMX etc are all in there. Personally I put MSTs on my MSIs to prevent the automatic update feature, especially when it's so easy to roll out new versions. But, each to their own.
  5. This is a useful little addition to the support site, thanks guys. On a quick glance I can already see that there are DNS entries that have been dead for years - I'm sure @PaddyNewman is looking forward to the extra support calls now he's made that active
  6. Ok thanks, I'll let our office staff know.
  7. We use Feem file transfer app. It's free, and all file transfers stay within your school network. It's essentially the same principle as Airdrop, but you can also have a Windows client. In theory then at the end of a lesson, all your students can use Feem to send their work to the teacher's Windows PC directly. The only gotcha I will mention is that it also makes it very easy for iPad users to create huge video files and then drop them on your main server storage(!).
  8. Which scam is it you're getting? Is it the illegal activity on your IP address one? I'll warn our office team.
  9. Same. The cache tab on ours reports 0, until you actually click configure, then it shows you the actual cache size.
  10. Eh, the server and the disk isn't important enough to keep, it's literally just hosting a few files. I'll probably stick the datafiles in a zip for archive purposes, like you say, seven years.
  11. Oh really? Never had a problem here. But then, I've not necessarily been checking, or had to fall back on the AD backups. System drives would just get wiped, and memory sticks are the user's problem.
  12. Good to know! I might phase out my script then.
  13. I moved everything onto Windows 10 a few summers back, it's just my home PC to do now(!) which I'll probably attempt over the Christmas holidays. This thread has just reminded me that I have one legacy Server 2008 R2 VM running though. All it does is host the data file for our (old) RM Finance system, I should probably look at retiring that now.... anyone familiar with the RM Finance quirk where it can't host the data file on a server newer than 2008 R2? It's a legacy situation here that was before my time.
  14. I didn't know you could change the cache setting size from the SCCM console. I've got ours being set by a Powershell script in the task sequence when the machine is built.
  15. On for staff, off for students. We use DNS forwarders to set it as fully unrestricted, but would have to review that if we ever opened it up to students. Very occasionally we need to make a video available to students, in those circumstances I temporarily host it elsewhere. Doesn't happen often enough for me to come up with a more legit solution, thankfully.
  16. Not technically true, if you set Bitlocker to save recovery information to Active Directory, you can get the Bitlocker recovery password from AD, as long as you know which PC encrypted the drive. Although yes, a bit of tactical fibbing / managing expectation is far easier. Pretty much all the settings you want for this are under Windows Components | BitLocker Drive Encryption | Removable Data Drives. Pretty sure you can achieve most combinations between fully open and fully encrypted here, but it is a case of trying settings until you get what you want. The key setting for us was "Deny write access to removable drives not protected by BitLocker". This means users can only write to encrypted drives, but can read from unencrypted ones, eg, for when we have visiting trainers / speakers etc with presentations on USB sticks.
  17. I have seen USB stick blocking done, but it was a real headache. We've taken the middle approach of saying the using USB sticks is discouraged, please use the corporate Google Drive. If they must use a USB stick, we force encryption before you can write any school data and take it off site. We took it more as a data protection issue, rather than an antivirus issue.
  18. +1 for Server 2019. I initially tried Server 2016, again not wanting to go latest and greatest, and found the slow updating just made it unusable. 2019 works fine though, absolutely no problems with the domain promotion, adprep etc runs seamlessly. It's just the FRS to DFSR migration that you need to be aware of really. Currently running 2012 R2 and 2019 DCs side by side with no problems.
  19. Not my decision, someone else in the family is the Linux nut. It's worked out quite well though, she only wants email and her games.
  20. One of the helpful Microsoft chaps called my gran once, who was duly concerned and tried to do everything they asked to help them "fix" Windows.... unfortunately for them though, she's running on Linux.
  21. I won't bore everyone with the latest painful lack of progress in my case, BUT, I just thought I'd share this gem of a quote that came in an email from Office 365 support: So there we go. Confirmation that they're making this more difficult than it needs to be, on purpose!
  22. Another week or so has passed..... Volume Licensing found the product, seemed to understand the situation, in as much as it is DEFINITELY O365 support's remit..... O365 remain affable, but clueless. Today I had a conference call with the Billing department who believe that it's not even Microsoft's problem, I need to go to a re-seller to buy the product. It's a free product, which we are qualified for, as per Microsoft's own FAQ on the matter I feel like I'm being gaslighted by a major multinational, I'm about a month and a half into this support call. It's so tiring.
  23. Blimey. Just had a conference call with the Volume Licensing and O365 support agents at the same time! None of them know how to provision A1 Plus of course.....
  24. Blast, and they're the ones that have proved least sane / intelligent out of the two. Oh well.
×
×
  • Create New...