-
Posts
1,927 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by DavR
-
Sophos EC - Web protection unloaded on multiple endpoints
DavR replied to DavR's topic in Enterprise Software
Same here, did a bunch of reinstalls from the console last week and the errors just keep coming back. Also 1703, clean installs all of them. I'll log it with our support (LGfL) and see if they've got any ideas. I needed to speak to them anyway about upgrading to the cloud based console. -
Sophos EC - Web protection unloaded on multiple endpoints
DavR posted a topic in Enterprise Software
Have any Sophos users out there found that they are getting multiple errors in the Enterprise Console about Web Protection being unloaded? I have this error "Web protection is no longer functional. The filtering driver has been bypassed or unloaded [0xa058000c]" on whole bunches of PCs, as described here. As far as I can see web protection is totally knackered, and I'm going to need to reinstall half of our endpoints, unless anyone out there has seen this and can offer some advice? We're freshly built Windows 10 over the holidays, so I'm surprised we're getting endpoint failures so soon. Perhaps September Cumulative Update has knackered part of Sophos. -
I never got my heard round that either, the Uninstall deployment thing is crap for doing an upgrade. Probably not the official recommended method, but in these sort of cases I write a batch file that uninstalls previous and installs the latest, and deploy that as my package.
-
WSUS is a monster for disk space, and quite inefficient at managing cleanup of old files (even if you do run the cleanup routines), so yes, I'm not surprised at 350GB. Only tick the products you definitely need, don't select whole families. I've never tried drivers with WSUS, but I expect they will take up a whole bunch of space, given that any additional option in WSUS always does. Personally I prefer to keep control over driver versions, in theory the WU drivers are clean and tested, but feature-breaking updates are not unheard of.
-
All very entertaining and inventive ways of dealing with the problem. The Pooh method particularly is uniquely primary school, I worked in an office once where anyone who left their desktop unlocked got pranked with "amusing" wallpaper. Tempers were frayed by that game. But seriously though, automatic lock needs to be set in policy these days. Get authorisation from the head and just do it, quote DPA/GDPR, shrug your shoulders and say "we have to".
-
I'm never 100% patched, I've always got a few that are never quite up to date, either because they're rarely used PCs in corners, or laptops that aren't on long enough to finish updates / report in. I look every few months and force the worst offenders, but it's a losing battle!
-
Depends how much you're willing to spend really doesn't it. For our needs (large primary, MIS and email hosted externally), we have a full onsite backup and then key data into an offsite backup using separate software. We don't have offline backups yet because of the management overhead. We do have two well separated buildings, with production and backup servers in different areas, so you could argue that offsite backup is redundant. But, with the way things are going, like @flyinghaggis, I am a little wary of ransomware encrypting my local onsite backup (I did tighten up the security access on the backup server after the NHS debacle). I'm relatively confident that my offsite is safe from ransomware... for now.
-
And this is why we kept replacing projectors for so long!
-
Ah! Found it, buried pretty deep. The solenoid itself is sticky, when even turned off, when you move the mechanism it sticks to the solenoid for a moment before releasing. Good shout @difinity, that could well be my problem. Now to source a replacement!
-
Ah, now that sounds plausible! I've definitely had Samsung printers repaired under warranty where it's been the solenoid that's gone. Don't suppose you know where the solenoid is located on this model, before I strip off everything looking for it?
-
Anyone got any ideas on repairing a Samsung ML-2580N mono laser? I'm getting regular paper jams in the fuser. When I get the jam there will often be a second sheet of paper following, even when I'm printing a single sheet, although the two sheets won't be stuck together. Opening and closing the front door clears the error, and it will print OK when it warms up. I've already replaced the pickup roller and the fuser itself, but it still continues. Print quality is adequate, so I haven't changed the transfer roller, although I have taken that out and cleaned it. Anyone have any suggestions? I expect I'll probably be chucking it, but I wanted to try a repair first as we've still got £100 of toner for thing! Alternatively, anyone wanna buy some toner and/or nearly new fuser unit....
-
@atcoates, gone are the days when Anti Virus was all you needed to protect you from nasties eh! Not that it ever did a particularly good job. It's an ever more paranoid area since WannaCry. @Squelch, yes it is all a balancing act. Gone are the days when Windows Updates could just happen in the background it seems, they're now so big and frequent they need their own schedule. Thanks for sharing your solution!
-
Ah ok, so you're using sleep and those wake and install updates functions. Something to think about for future in our case as that's not our current power policy. Presumably you could replace shutdown with sleep on the start menu to push users towards sleep instead of shutdown? I'm sure I saw a policy along those lines somewhere.
-
Why enable them? These are multi-user devices, they should be shut down properly after each use, not just close the lid and hibernate, saving the previous users session. I've always found the sleep function a hindrance in an enterprise environment, you sacrifice a bit of performance for faster startup. But that's a whole other thread.
-
Sounds like overnight might be the way to go if the update reboots get in the way. What mechanism are you using to do these wakeups for update, WoL or something in Windows Update itself? I saw some wake up options in group policy, but they were all talking about wake from sleep or hibernate, we've disabled these and use proper shutdowns.
-
The program itself is simple and pleasant enough.... from a deployment point of view though the current Windows 10 MSI mucks up C++ if you've got it installed (and by extension SCCM client in my instance!), and is a £$%^ for turning off the auto update function...
-
I think the logic behind having both is that anything more than a month out of date gets the full CU, but the more up to date ones just get delta patches. You're right though, it's really quite difficult keeping up with this. Anyone would think MS were making this up as they go along....
-
There's always one.... even if you give them the option of how to change or resolve something, they'll still prefer to moan!
-
Just implemented this here for start of September, at the same time as updating and enforcing a new password policy. There's no hard and fast rule exactly as to what password policy / locking you have to enforce, but with GDPR coming I've been using the line "to comply with current data protection standards". Just make sure you have SLT on board to back you up. We have user switching enabled, teachers have a 15 minute timeout, admin staff have a 10 minute timeout. Teachers are already in the habit of using the freeze tool on projectors / displays, so there really is no business case for needing to leave screens unlocked for any longer. I've had surprisingly few complaints to be honest, most people recognise this is a legitimate security issue.
-
The 65s are big enough for us, but we are a primary so don't have very big classrooms. There were a few rumblings about the size, but these were quickly silenced by the sheer clarity of them compare to projected systems. Problem is, it's quite a big jump in price from the 65 to the 70, somewhere in the region of another £600, or else we would have looked at those. With the model we have, if you view them side on at say 10-20 degree angle you get ghosting, but can still see the image. This isn't a problem for us as you have to be sat at a really silly angle for it to be an issue. Re pen vs touch etc, hasn't been an issue for us as we've been used to old Prometheans, where you have to choose between pen and touch anyway. There are some inbuilt annotation tools which can differentiate between a point (pen) and the flat of your hand (eraser) but we haven't fully explored these yet.
-
Presumable because they're being usurped by the interactive displays... On that subject though, I was quoted fairly good prices for refurbed boards from Refurbished ICT Store - if you find yourself in a situation of having to replace on a low budget. I think I was quoted £150 for a Promethean ActivBoard 2 a year or so back, as presumably the market is flooded with people upgrading.
-
Update: so ignore my above comment on times in testing, that was for Sept CU from scratch, rather than just as an update. Starting with a base level of August CU, I installed the Sept CU and the Sept Delta update separately, and both had a reboot time of about 8 minutes. As WSUS installs updates in the background, it is mainly the shutdown or startup delays that concern me, as that's the actual disruption. The delta upgrades would be faster in terms of file copying and may install faster, but aren't cutting out the above delays, which would seem to be unavoidable. I guess I'll just stick with full CUs for now (these arrive in my WSUS and are approved automatically, the deltas I'd need to intervene) and see if anyone complains. As an aside, while reading up I found this article which states that the delta upgrades are an interim measure for 1607 and 1703 only, and won't be released for 1709. It looks like MS recommended best practice from this point forward is to use Express Update Files, which expand the files on the WSUS server, allowing delta updates on machines that way. The storage requirements for that though are phenomenal!
-
We had eight Promethean boards replaced with iiYama interactive displays over the summer. We got Prolite 65s for about £1800 + VAT a piece installed, and even with a basic training session from their rep. We were plodding along just replacing projectors and patching up, but we've had some money raised from parent donations and the head decided this was the best place to invest. We now hope to pursue this for the rest of the school, over time. Our lot really do use the interactivity, I'm very surprised to hear so many schools happy to do without it!
-
We're using AirServer too (it's brilliant btw, would totally recommend above buying Apple TVs etc). As far as I know there is no way of restricting which device can AirPlay to which receiving PC, but we've got round this by not having AirServer run on Startup. Teachers have to launch the AirServer receiver on their PC, then the iPad makes a connection. We haven't chosen to replace visualisers with iPad / AirServer though. The visualisers can be angled and placed above documents etc, iPads not easily.
-
I did a bit of testing on a my spare PC this afternoon. Full cumulative update installs from WSUS in the background quietly, which is good, but does then take 7 minutes on shutdown, and 6 minutes to start back up again. So not as bad as I'd worried, but in terms of switch-on usability still a bit naff. This is on a decent spec machine, though not SSD, so I will have some faster and plenty slower. Gonna have a bash with the Delta update on Monday, on the same machine for reference, hopefully it can do better than that.
