Jump to content

TwistedHelixis

Members
  • Posts

    3,401
  • Joined

  • Last visited

Everything posted by TwistedHelixis

  1. I cant comment on what it was like previously, but I can deploy the same policies that InTune uses. Perhaps that wasn't the case before? As far as I can tell, GCPW clients are locked down as much as an inTune client is. I have deployed similar security policies to the ones on our current DC (locking down app installs, Bitlocker, removing settings access from pupils), the list goes on, and now I also have 2 step authentication during Windows logon. Before I even started down this path, I looked into the security aspects and also found a good number of schools that are already fully GCPW setup, its just none of them seem to be using Smoothall Cloud, hence this post. Thanks for the input, but I really don't want this going off topic too much. 👍
  2. Hi, Based on your questions I am going to guess you have not used GCPW, perhaps you have, but will explain how that works first, just in case. GCPW is (can be) a complete replacement to Active directory or Entra ID, it can also run along side either. After installing the GCPW on the client, when you next reboot the Windows device, you will now have the option of logging into Windows using a Google Account. Behind the scenes, in the Google admin GUI, you can control lots of the same settings like similar to Group Policy or InTune, but everything (logins & settings) are now controlled from Google and not Microsoft. We are in the final final testing stages of using GCPW (Google credential provider). I have had a couple of teachers testing it for the past month in the classroom and it has worked very well. All the previous settings we had deployed from our DC are now being deployed from Google, our final issue is getting GCPW devices to work with Smoothwall Cloud, rather than the local Smoothwall system, which does work with GCPW, but I really wanted our filtering to be cloud based. Anyway, to answer your questions.... How does the login look like for both the computer and your Google domain? The user logs in to the device using their [email protected] Google creds If you are not using MS-AD, do you mean you are using Entra ID (Azure AD) No, We are not going to be using either, GCPW can be a complete replacement. How do you manage your PCs? The PCs are going to be managed from GCPW What permissions does the student have on the computer? Staff and students are standard users, and will have very similar permissions to the Windows domain system they currently use.
  3. Would be very handy if another school has manged to get his working, as the MAT above are also using MS AD Domain, which is a very different setup to our non-AD setup.
  4. Out of interest, are you a school? The more info I can pass back to the local authority, the better 👍
  5. Hi all, Just wondering if anyone has ever used Smoothwall Cloud on a Windows device, that is using Google Credential provider? I don't have any access to the Smoothwall systems we go though, so have no way to test, but have been informed that it doesn't work. I am not sure how much testing went on, perhaps it doesn't work, but would love to have a second opinion if possible, just to stop my OCD going into overdrive over sometime I cant actual test.
  6. I would love to be able to test, but the problem I have is that it is all controlled from the local authority. I can only go on what they are feeding back to me. Think I might create a new post asking if anyone has got it working, just so a few more people might notice. Then I can feed that back to the LA.
  7. Do you have Smoothwall cloud filtering working on a GCPW Windows device. I was informed it doesn't work.
  8. Would you mind explaining what a Smoothwall Unified Client is? Thanks
  9. Perhaps it was something else and not a bios setting. Oddly, I don't seem to remember having an issue with the trackpad
  10. I managed to get it working. Think I needed to do a bios update or downgrade. Also needed some odd BIOS setting changing, cant remember now.
  11. Originally I thought it would not be a good thing, due to the Play Store issue, but then the IT lead sat down for a while and found web based apps for about 95% of the Play apps they were using on the Chromebooks. Recently I removed the Play Store apps from the Chromebooks, so all the devices work the same way.
  12. This is why I have been going round in circles for ages. Their help page literally says this isn't possible 😭
  13. Yes, I thought that if I wanted the teacher to be local admin I would need to move the set-up account into the admin OU, which I assumed would then make the teacher an admin, but after testing I can just move the teacher into an admin OU, which is perfect.
  14. OK, so I am still not getting this. I logged onto the laptop first with my setup account. Next I logged into the laptop with a teacher account. then, I moved the teacher account into a new OU with admin rights enabled. After a few reboots, the teacher now has admin access on the laptop. Is this the expected behavior? I thought that the only account that could be affected by the policies and the Windows settings was the first account that logged onto the laptop, and all other accounts that would logon would just get those same settings. I'm now really confused.
  15. Just thought of a possible issue. I know the policy settings are only applied to the first user account, and I believe also the Windows settings, like updates or bit locker settings etc. If I login first to all staff devices using a staff device setup account, will I then be able to make a specific user that has subsequently logged in, a local admin for a short while using the Workspace admin settings? Or would I need to make my account local admin, which would then make all accounts on all device local admin, which is not good? EDIT - If i am the first user to login, can I later make other user of just that device a local admin?
  16. I managed to get the policy to apply which removed the Gaming tab from Windows settings page. So I now have a good way of instantly knowing if the policies are applying or not.
  17. Thanks Paul. I created a policy to hide some menu settings, but hey are still displayed on the laptop after logging in with my GCPW acc. Not sure if its a sync issue or policy creation issue. Do you have that one policy you have created, that you can always check has applied, so you know it must be syncing?
  18. So I could in theory, create a GCPW teacher acc, log into all the devices first, then hand those devices out to the staff?
  19. Is it due to any other users getting the same settings as the first user that logs in?
  20. I know the first account to log into a Windows device that has Google credential provider installed, becomes the Master account. All the setup steps suggest getting the actual device user to log in first. I am just wondering what the implications are if its always the same account that logs in first? Does anyone do this already, or do you always get the owner to login first?
  21. Google implemented something like this last year. Recently setup DMARC on all my primary schools, not because of this issue, but because its a good thing to do anyway.
  22. How do schools sign up for this? When I do a search it takes me different company websites and the DFE page about it doesn't seem to have a sign-up page
  23. I notice a sync section in workspace, but it only seems to enable the option for users to then have the option to sync or not. Would be great to also have forced sync.
  24. Does anyone has a copy of Mobility print 1.0.317 I cant find any past versions on the PaperCut website 😞
×
×
  • Create New...