toffee_paul
Members-
Posts
208 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by toffee_paul
-
Has anyone managed to do this yet? Seems like editing an existing VPP token isn't supported (greyed out), and creating a new DDM-based VPP token with the same Apple VPP email address leads a "Duplicate" error. Deleting the original MDM-based VPP makes it sound like all apps linked to that VPP will be removed from devices? Obviously don't want that but don't trust that pushing out the DDM-based token straight after will stop that from happening.
-
@CHiLL Sorry I meant to say did Senso ever fix it, not Impero. We use Impero and adding ai.exe into the injection exclusion list didn't resolve it for us. We are on v8.6.32 which isn't the latest so it may be a newer version fixed this. The changelog doesn't seem to mention it though. Looking at Senso as a potential Impero replacement, are you happy with it?
-
@CHiLL Did Impero ever fix this, do you know?
-
Smoothwall blocking access to Arbor MIS
toffee_paul replied to toffee_paul's topic in Internet Related/Filtering/Firewall
Just to provide a final update for the original issue (inability to access our MIS), this was confirmed not to be a Smoothwall issue and was in fact a DNS issue. Our ISP was failing to resolve the domain cdn.ravenjs.com that hosts JavaScript library necessary for Arbor to load. After opening a ticket with our ISP about a week ago despite some initial to and fro with them, this is finally resolved and the domain now resolves correctly with their DNS forwarders. -
Hi, Anyone else on 3CX and Smoothwall? Can get to our hosted sign-in page ok and as soon as clicking Login button we get a "Disconnected - try again in xx seconds" error. Had to create a HTTPS inspection policy and set it to 'do not inspect' to restore access, after Developer tools in the browser was saying there was issues with WebSockets. Followed this guide: https://kb.smoothwall.com/hc/en-us/articles/360003342820-Allow-access-for-WebSockets Ticket open with 3CX so maybe they've changed something their end, as I was accessing the site fine at the back end of last week. Only thing I've changed is our DNS forwarders from our ISPs own to fix an issue accessing Arbor.
-
Smoothwall blocking access to Arbor MIS
toffee_paul replied to toffee_paul's topic in Internet Related/Filtering/Firewall
No, DNS queries can be cached just like the JavaScript files and other content can be cached locally on machines. -
Papercut MF - How to avoid "Sign in to install" ?
toffee_paul replied to toffee_paul's topic in Enterprise Software
Yep, that setting was the first thing I tried, made no difference. -
Smoothwall blocking access to Arbor MIS
toffee_paul replied to toffee_paul's topic in Internet Related/Filtering/Firewall
Following a call with Smoothwall they believe it to be an issue with DNS. Upon changing the DNS forwarders to Google's (8.8.8.8 / 8.8.4.4) on our on-prem appliance, access to Arbor is now working fine. May be worth changing yours temporarily and see if it makes a difference. @5nowman you mentioned you're on BT Fibre so maybe your issue is different as you mentioned slowness rather than an out-and-out inability the resource itself. Thanks to Alan @ Smoothwall for highlighting this. -
Smoothwall blocking access to Arbor MIS
toffee_paul replied to toffee_paul's topic in Internet Related/Filtering/Firewall
Out of interest what ISP are you both using? -
Smoothwall blocking access to Arbor MIS
toffee_paul replied to toffee_paul's topic in Internet Related/Filtering/Firewall
@SeeFights Try adding the IP of an affected device Guardian > Web Filter > Exceptions page and leaving it a minute or two for it to take effect. Adding IP an exception - site loads fine.. removing the IP and doing a hard refresh (Ctrl+Shift+R) and it's blocked again. Hard refresh forces it to go out and load the JavaScript from the site, and not use a locally cached copy. What's equally frustrating for me is trying to get a response to my ticket. I was asked by the second line support manager for details which I replied back to within a couple of hours and I've heard diddly squat back since then. Even contacted our account manager last week too to see if they could give it a push along and got no response. Really disappointing. Just need someone to remote on and take a look. -
Smoothwall blocking access to Arbor MIS
toffee_paul replied to toffee_paul's topic in Internet Related/Filtering/Firewall
@andy_b Thanks Andy but we're not using any ad-blocking extensions. @SeeFights I'm struggling to think it's NOT a Smoothwall issue to be honest. The fact other Arbor customers have the same issue and they're all on Smoothwall is the primary reason, along with the fact that if I add the IP of an affected device to The Web Filter > Exceptions page it loads Arbor no problem. -
Smoothwall blocking access to Arbor MIS
toffee_paul replied to toffee_paul's topic in Internet Related/Filtering/Firewall
Some screenshots attached. I tried adding the IP address that's returned when pinging cdn.ravenjs.com to Destination exceptions on the Smoothwall but it didn't make a difference. -
Smoothwall blocking access to Arbor MIS
toffee_paul replied to toffee_paul's topic in Internet Related/Filtering/Firewall
@5nowman Use Developer Tools and you'll see that it reaches out to various sites and pulls things in. In the case of Arbor they use the JavaScript library at ravenjs.com. @simpsonj I'm on Edge (chromium) and I can only see the domain, not an IP address. This is what it tries to load: https://cdn.ravenjs.com/3.16.1/raven.min.js @tom_newton Arbor have told me four customer have reported the same issue occurring at the same time. Maybe it's something unique to the on-prem config of all five schools then? All I know if our web policies haven't changed in quite a while, and we can get to Arbor when bypassing the Smoothwall. -
Is anyone else experiencing an issue whereby Arbor is inaccessible due to Smoothwall blocking it? I've narrowed this down to a JavaScript library (ravenjs.com) that Arbor use and which is loaded from cdn.ravenjs.com when our Arbor site is accessed. We have a category named 'App - Arbor' containing all the recommended URLs Arbor say should be whitelisted. This has been added to a web filtering policy and set it to ‘Do Not Filter’. Also added a HTTPS Inspection Policy and set that to 'Do Not Inspect'. Arbor have told me they have multiple customers affected by this and the common denominator is that all are using Smoothwall. We have a ticket open with Smoothwall but they haven't responded since Thursday. Access to our Arbor site works perfectly when: - accessed from a mobile device using a mobile data connection. - when I add the IP address to Web Filter > Exceptions page thereby giving unfiltered access to the internet. I can't be giving unfiltered access to the internet to staff for obvious reasons. Arbor have told me that another school who raised a ticket with them for the same problem had a Smoothwall engineer tell them they're blocking an IP address because they see it as malicious. I've not been able to get a response from Smoothwall to my ticket and my account manager is on annual leave so we are stuck with no access to Arbor and an inability to send comms to parents.
-
Papercut Print Deploy client launch issue
toffee_paul replied to JSpaced's topic in Enterprise Software
@PaperCutterAl What's the new method and is it in available yet? We have the .bat file method in use (Logon script, deployed by Group Policy). As we use AppLocker I created a Publisher rule to exclude the blocking of the executables. -
Papercut MF - How to avoid "Sign in to install" ?
toffee_paul replied to toffee_paul's topic in Enterprise Software
Our print solutions provider has been in touch with PaperCut directly and they've told him it's not possible to avoid the "Sign in to install" button, even when not using cloned Mobility Print queues. We're going to test it out shortly. We're on AD/GPO but hybrid. Ultimately we'll do full Entra-joined and Intune-managed so will need to use the Entra/M365 auth method but for the foreseeable we're hybrid domain-joined. We currently push our printer connections out using Group Policy Preferences (User Configuration) which installs the drivers if they aren't already on the device. So it's possible to deploy our two Follow Me queues using Group Policy? Not seen any PaperCut docs that mention this as a possibility, could you tell me how this is done? -
Papercut MF - How to avoid "Sign in to install" ?
toffee_paul replied to toffee_paul's topic in Enterprise Software
Is this only able to get done if we have multiple zones? We only have one zone to keep costs to a minimum. I've had a look here https://www.papercut.com/help/manuals/print-deploy/set-up/add-zones-user-groups/ and it doesn't seem to infer that the print queue installation is automatic if we target specific IP ranges. -
Hi all, New to Papercut MF here. How do we avoid the "Sign in to install" prompt when using Print Deploy and have the queues auto-install without the user being prompted? In admin portal, Auth options is set to Username/Password, Identity set to TRUST. UAC is disabled and non-admin users have permission to install print drivers from our print server/papercut server.
-
Yep, no actual need to implement the manual workaround. I done it on a single test devices I had a spare few mins and natural curiosity took over to see if it actually did work as with MS you never know!
-
Yeah it's taken them a few weeks to publically acknowledge the issue but it's here now along with workaround. Here's the Microsoft article. https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#3706msgdesc I've tested the workaround this afternoon (on one device) and can confirm that on fully up-to-date devices that have the ESU MAK product key installed and activated, the Windows Update now reports "You're up to date", instead of the previous message about it being unsupported. I used the Group Polixy ADMX/L central store method and targetted the policy at a test device, ran gpupdate /force, restarted, and all was good.
-
Configure Start Pins group policy settin (Windows 11 25H2)
toffee_paul replied to toffee_paul's topic in Windows 11
Our reason for doing it here is to stop students getting distracted and opening some random app up. This was so much easier with Win10, and even that was a pain at times. -
Configure Start Pins group policy settin (Windows 11 25H2)
toffee_paul replied to toffee_paul's topic in Windows 11
Yeah could just be that you need to change your $json to $json = '{"applyOnce":true,"pinnedList":[{"desktopAppLink":"%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Google Chrome.lnk"},{"desktopAppLink":"%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\File Explorer.lnk"},{"packagedAppId":"Microsoft.WindowsCalculator_8wekyb3d8bbwe!App"},{"packagedAppId":"windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel"},{"packagedAppId":"Microsoft.ScreenSketch_8wekyb3d8bbwe!App"},{"desktopAppLink":"%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\VideoLAN\\VLC media player.lnk"},{"desktopAppLink":"%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Microsoft Configuration Manager\\Configuration Manager\\Software Center.lnk"},{"packagedAppId":"Microsoft.CompanyPortal_8wekyb3d8bbwe!App"},{"desktopAppLink":"%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\lenovo\\System Update.lnk"},{"desktopAppLink":"%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Dell\\Command Update\\Dell Command Update.lnk"},{"packagedAppId":"E046963F.LenovoSettingsforEnterprise_k1h2ywk1493x8!App"}]}' Your alternative way of populating the ConfigureStartPins group policy setting has me thinking. I might try loading it directly into the registry and see what happens, at least until Microsoft get round to fixing the problem. -
I get "This update is not applicable to your computer" with both of these updates. All my devices are Win10 22H2 and are on the October 2025 cumulative update so these updates aren't applicable. Windows Update for Business is in place and they've never been paused for updates. Tried deleting SoftwareDistribution folder and the DISM command and still no luck.
-
This is what all my test machines show. I had a response back from our reseller and the say the distributor is aware of other customers having issues with ESU but didn't go into details about what that might be. Just have to play the waiting game and see what they come back with.
-
I get this too. Here's a typical output of slmgr /dlv here. Microsoft (R) Windows Script Host Version 5.812 Copyright (C) Microsoft Corporation. All rights reserved. Software licensing service version: 10.0.19041.6456 Name: Windows(R), Education edition Description: Windows(R) Operating System, VOLUME_KMSCLIENT channel Activation ID: <withheld> Application ID: <withheld> Extended PID: <withheld> Product Key Channel: Volume:GVLK Installation ID: <withheld> Partial Product Key: <withheld> License Status: Licensed Volume activation expiration: 250630 minute(s) (175 day(s)) Remaining Windows rearm count: 1001 Remaining SKU rearm count: 1001 Trusted time: 21/10/2025 10:52:35 Configured Activation Type: All Most recent activation information: AD Activation client information Activation Object name: Windows 10/11 Product Activation <withheld> AO DN: <withheld> AO extended PID: <withheld> AO activation ID: <withheld> Name: Windows(R), Client-ESU-Year1 add-on for Education,EducationN,Enterprise,EnterpriseN,Professional,ProfessionalEducation,ProfessionalEducationN,ProfessionalN,ProfessionalWorkstation,ProfessionalWorkstationN,ServerRdsh,Core,CoreN,CoreCountrySpecific,CoreSingleLanguage,IoTEnterprise,PPIPro Description: Windows(R) Operating System, VOLUME_MAK channel Activation ID: f520e45e-7413-4a34-a497-d2765967d094 Application ID: <withheld> Extended PID: <withheld> Product Key Channel: Volume:MAK Installation ID: <withheld> Use License URL: https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail Validation URL: https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx Partial Product Key: <withheld> License Status: Licensed Remaining Windows rearm count: 1001 Remaining SKU rearm count: 1001 Trusted time: 21/10/2025 10:52:37 I actually tried removing the KMS activation from a test device and installing/activating the ESU MAK key and Windows didn't like this at all and refused to activate. Wondering whether the ESU licence isn't actually a standalone licence and it needs a 'base' licence installed for it to show as 'Licenced'. The words 'add-on' in the Name field might suggest this is true but regardless, even when slmgr /dlv shows it as Licenced, Windows Update is saying otherwise. I thought there may be others having this same issue but it doesn't seem as widespread as I thought. Maybe most organisations have already upgraded to Win11. We still have about 15% of our devices on Win10 and as this ESU programme exists we thought it best to pay a nominal fee to keep them going for a year before replacing with new machines in next years budget. Read somewhere that Microsoft issued some faulty ESU keys to resellers. Who knows, we could be affected by that. Can't even get a response from our reseller/distributor at the moment.
