-
Posts
1,927 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by DavR
-
This is what we did, it's a bit clunky, but works well enough. It's a retrograde step sure, much as I understand the financial logic behind removing native DVD playback. It's like being back in XP days, scrabbling around for a working version of Cyberlink PowerDVD. What I don't get is, if VLC can offer this functionality for free, why can't Microsoft....
-
Bit late to this party, but for info, you can now tell Chrome to store Bookmarks in the user's roaming profile / appdata, if you're using that - https://getadmx.com/?Category=Chrome&Policy=Google.Policies.Chrome::RoamingProfileSupportEnabled&Language=en-gb Interesting to see that people are letting Chrome self update. I always turn off updates, but that's just by habit.
-
Another half baked release thrown out there without proper testing! How about one new release a year, and test it properly first..... anybody?
-
I installed quite a few of these in a previous job, but in all honesty, the majority of schools never used them. Logging onto a VPN was too much of a PITA when they could just use USB sticks or email files home. If you do go this route, you need to close down the easier insecure options, and have a training push as to why they need to use the VPN.
-
A fair point. Again though, that probably falls under the category of where reasonably possible. When people request their data deleted, you don't have to delete every record, you have the right to retain certain records, and they may still reside on backups and other mediums where it is not practical to delete individual files. You're right of course that USB sticks are a terrible idea in terms of keeping control and managing records, but any situation where files leave school, they leave your control, regardless of the transfer medium. Sounds like this school are dead set on keeping them, you can only advise them and their DPO that this is not a great idea. It's their risk, and I don't think anything in the GDPR outlaws it.
-
To be honest, it's inevitable that staff are going to take files home to work on. If you stop them using USB sticks, then they're only going to use another method, like emailing things to themselves. We chose to enforce Bitlocker on USB drives, and push staff towards using the school-approved Google Drive. This also came with a briefing about data security in general. The letter of the law on GDPR is to take appropriate measures to secure personal data, it doesn't specify yes / no on any one technology. I'd say encrypted USB drives would be an "appropriate" measure for now, although that may change.
-
I haven't done it with the Vostros 15, but I have done it with Optiplex and Latitude. I put a bunch of BIOS upgrades in a Task Sequence, each step WMI filtered by model, and then had a TS reboot at the end. Each BIOS upgrade I added as a package with the switches /s for silent and /f for force. I also used /l to log the outcomes, but that's a matter of preference. You may additionally need to add "0 2 3010" as the success codes for the TS steps - as far as I know, that's "succeeded but reboot required", which is what we're expecting it to say.
-
No great security risks I guess, as long as your permissions are in good shape, but Cortana does expose a whole world of items that the end user shouldn't even have view access too. Windows 10 modern apps as a whole have been a nightmare in terms of group policy control. Where there are administrative controls, such as Applocker, they're always very clunky. And you know what? For me, these apps have added nothing. The only ones we use existed as perfectly serviceable and GP managed regular executable before. With Windows 10 it's like you've got bluesky thinkers in one room developing the product, and some poor souls in the next room who then have to try and add some control on afterwards, and the two never talk.
-
Yes, and no. We've got Cortana disabled by policy, but on Enterprise it's a fundamental part of the Start Menu so it's never completely off.
-
Definitely block completely for students, if you look into the policy settings above further though, you can block / allow individual MMC snap-ins.
-
New Windows 10 Cumulative Updates (20th Sept.). Lots of bugs fixed!!!
DavR replied to Arthur's topic in Windows 10
Oh, I know. Haven't applied Settings Page Visibility at computer level for that reason, it would interfere with maintenance and testing. It's not highest priority, just been nice to finally patch that hole. The whole Settings app is blocked for students, it'd just be nice to be a bit more granular for staff. -
There's no reason an end use should ever be in MMC. We've got MMC blocked for staff and students through Admin Templates | Windows Components | Microsoft Management Console, and had no repercussions. Our users can see Service.msc through idiot Cortana, but if they click to open it, nothing happens.
-
New Windows 10 Cumulative Updates (20th Sept.). Lots of bugs fixed!!!
DavR replied to Arthur's topic in Windows 10
Thanks Arthur. Sit and wait a few weeks I guess - been waiting for this setting since implementation in summer 17, I suppose I can wait a few more weeks -
Hi all, I did some reading around on this yesterday and came up with no useful answers, so I thought I'd put it out to the experts. Has anyone found a way of allowing LogMeIn Rescue through the local Windows Firewall? One of our suppliers uses it regularly to support their frequently broken product, but it always prompts for an admin login to allow through firewall. I've tracked down the file I need to allow, LMI_Rescue.exe, but, it lives in a temp file in the user's AppData, which is never the same location twice. Anyone got ideas on how to allow an executable through Windows local firewall, but from a dynamic location? Alternatively, any ideas on how to give a user group access to add their own firewall exceptions? Thanks!
-
New Windows 10 Cumulative Updates (20th Sept.). Lots of bugs fixed!!!
DavR replied to Arthur's topic in Windows 10
Anybody got any ideas when this update will roll out to WSUS? Keen to use the Settings Visibility policies! -
+1 for NTFSFix, I used to use that all the time for home drives when I did server migrations. I got round the Dot Net 1 nonsense by tweaking the source MSI as I recall.
-
Hi all, I've been investigating an intermittent bug with our backups, and I'm 90% sure that it's Sophos AV that's behind it. We're using Veeam, but the bug discussed covers any backup software that uses the Windows VSS writers. Not every time, but now and then, one or two of our virtual machines fails to backup with the error "VSSControl: Failed to freeze guest over network, wait timeout". They'd then work just fine after a retry, which is why it's taken me a while to spot the fault. It's been discussed extensively here, but looks like the Sophos Health Service is using VSS at the same time as Veeam tries to, causing a failure. There's a workaround described here which I'm currently testing, but thought I'd share for any other Sophos Central users on here who might be having backup issues.
-
- 3
-
-
Tested and deployed version 4 - can confirm that it now works over a locked screen in Win 10 1803! It also wakes up the screen if it's gone into power saving.
-
One of our librarians reported on Friday that she was having problems scanning books into Junior Librarian, but worked if she typed the number in. Typically though, she plodded through them and only told me afterwards, when there were no examples left to test with, so I haven't gone anywhere with it.
-
Never mind, got the updated keys off support and registered on My Products.
-
Thanks @Tom_NetSupport - can you point us toward the updated installers? https://www.netsupportnotify.com/downloads/ doesn't contain any download links, or at least, it doesn't for us. Your family of sites is a bit ropey for us (LGfL school).
-
Great news - I'm glad I bought into the maintenance agreement now!
-
As I said, there's the version 1 and the version 2 boards. The version one only has one proprietary socket to plug into, the version two has a proprietary socket, and a USB, so that's an easy way to tell them apart. This is the version 1 serial cable. The business end of the plug is 14mm across, and there are push releases on the short sides. This is the version 2 serial cable. The business end is bigger, about 18mm. It has the push release on the top, not the sides.
-
Right, I think you're in luck @FN-GM. In my best Delboy accent... For your version 1s, I've got serial to board, and USB to board For your version 2s, I've got serial to board, and also direct power to board Version 1 had only the one connector for signal and power, version 2 has a serial/power and separate USB connection.
-
Hmmm, can't remember now whether I kept these or not, we junked our first gen recently. I'll have a look.
