KK20
Members-
Posts
969 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by KK20
-
Our oldest digital TV in school is around 8 years old. The school logo has been sat in the same spot for that time and it is power cycled from 6pm till 7.30AM. There is no burn in - it does not have a setting for the time updating when the clocks change so it needs its clock updating twice a year, it was "clean" the last time I changed it. It is a LG.
-
A handful of teachers use various tablets of their own, some android, some ipads. They have asked the question "is it possible for me to be able to control my school desktop PC with my tablet?". Their thinking is to walk about the class with their tablet in their hand, have "something" open on their class desktop PC (which is connected to a projector) and be able to remote control (for want of a better word) the PC from their tablet. VNC was first on my thinking but the guest WIFI (that teachers are connected to) is firewalled off from the main network. We do install VNC on our desktop PCs and I dont want to open up VNC to the guest network, that seems foolish. I have also tried onenote, which does work but is very laggy (30 seconds to a minute for the sync to update on either side). This would only work for onenote through and would be no help for pausing a video for discussion (example). Teams was also considered but a faff to start a teams each lesson, join the session, share, etc. Does anyone have any ideas or use a solution to do this? Even a collaboration software might work (perhaps I could convince people to roll this out to pupils if the collaboration works well)
-
Do you have a source for that? https://techcommunity.microsoft.com/t5/exchange-team-blog/removing-your-last-exchange-server-faq/ba-p/3455411 MS still advise to keep a local exchange even with the new tools - i.e. dont actually remove the server as it is intrinsically linked to onsite AD. So I suppose you can run the new tools and mothball your exchange server, just never power that VM on again :-)
-
this is normal use for a company transitioning mail. in fact it is what we did. Unless you are migrating active directory completely then you are stuck with a local instance of exchange for management anyway. This is what we did: 1) working onsite exchange and AD 2) created 365 tenant 3) sync ad with 365 tenant (AD connect) 4) setup hybrid but leave all mail flow as it is - leave MX and SPF etc - so all mail is flowing into onsite, all mailboxes are onsite. 365 tenant is aware that onsite mailboxes and server exists. The hybrid setup took care of all the connectors. 5) migrate a couple of mailboxes and test at this point mail is still coming into the onsite then going up to 365 as necessary. If I send an email using a 365 migrated mailbox, the mail still egresses from the onsite exchange server. Likewise incoming mail still goes to onsite first. The only different part is that OWA will not work for migrated accounts, you need to use the 365 web portal - this meant we needed two web links for people depending on whether they were migrated or not. 6) migrate more mailboxes and test 7) change mailflow to go into 365 with MX, SPF, rules, dkim, anti spam etc at this point all mail goes to 365 regardless of mailbox location. We could theoretically shutdown the exchange server and mail will work for all those migrated but not for those with onsite accounts. 8) lock down firewall for onsite exchange so it can only communicate with 365 9) migrate rest of mailboxes 10) semi decommission exchange (compact database, compact drive etc) 11) at this point I can shut down the exchange server unless I need to do administrative tasks. Email flow is all to 365, mailboxes are all in 365, although the connectors are in place we have no onsite mailboxes (well, I think there are a couple for test or service purposes but no mail flows to them anyway) I still have a relay available on the local exchange server for a UPS and photocopier that wont accept 365 accounts. I could well have missed a step but this was done a number of years ago! Basically you dont need to change a thing with hybrid if you dont want to. You could leave all the mailboxes and flow on the local exchange server should you require and only move a couple of test mailboxes as you see fit. Or even have all the mail flow into and out of 365 but leave the mailboxes local should you wish. A couple of gotchas. Dont expect AD to automatically link new 365 mailboxes to the onsite AD mail attributes, if you create a new onsite AD account, this will then sync to AAD normally, a 365 mailbox will be created but not necessarily synced back to the correct onsite AD attributes, you need to periodically update the onsite AD with AAD/365 mailbox - I use Enable-RemoteMailbox and Set-RemoteMailbox with the GUIDs as appropriate. Dont forget that everything needs to work to begin with. I know this sounds silly but your certificates need to be trusted, an external "proper" domain needs to be used for your servers, you need to have control of your DNS so you can change MX later, outlook needs to work with the same domains, tenant needs to trust the domains. We use letsencrypt so that will do just fine for your SSL.
-
with FSRM file screen it makes no difference if you are running on premises exchange. You make a screen to detect a file in a directory. This emails you using whatever email server you set up in FSRM with whatever email you set up in the screen. So you can set up to detect file "I_HAVE_INSTALLED.DAT" in "c:\mydirectory" emailing to "[email protected]" using whatever email server you like. There was no noticeable overhead when we used to use it for cryptocanary and that had HUNDREDS of file extensions set up in about a dozen screens. You can set up the email in a particular way so you can add an outlook rule and file the email accordingly. Have your install script create the file "I_HAVE INSTALLED.DAT" and you are gravy. FSRM was designed to do this (amongst other things such as quotas). If you have quotas set up then you already have FSRM installed.
-
Azure AD - Sharepoint Testing Questions/Issues Thread
KK20 replied to cheekycharly's topic in Cloud Services
I can recommend John Levis at VeryPC too, they will work with you. Not connected in any way, we moved to them this year John is active on here.- 34 replies
-
- 1
-
-
- a1 students
- azure
-
(and 3 more)
Tagged with:
-
thats it. groups were added as a supported measure at some point as I now use a dynamic group. Speed is much much quicker when you only need to add two members (dont forget the service account!)
-
I have a script that adds a dynamic group as site collector admin on student onedrive - ive wrote about this before on here (somewhere). Then I can add staff to the dynamic group for access. I generate a CSV for the student onedrive links and publish this in a sharepoint library that is locked down to the same group. Since we are hybrid, this script runs when the 365 -> AD email link is updated, I would advise against running this script regularly en masse as you will probably get throttled calling a lot of small hits on APIs (depends on your student numbers of course!) The likes of salamander do the same sort if thing I believe.
-
Ive been using SetUserFTA for years, I know you can create a default fileassociation XML and deploy but quite frankly I have never had a one size fits all, even in OUs. I have been moving my GPOs to intune and refining them in the process (trimming the years of cruft more like). One such policy is my scripting of SetUserFTA for essentials (outlook instead of windows mail, acrobat instead of edge for example) and I was wondering if people used a different approach? Im very surprised SetUserFTA still works (although I havent tried it on windows 11 yet).
-
[windows software] My Microsoft Licensing Portal is Gone. It's all gone.
KK20 replied to jmair's topic in Licensing Questions
Years ago, for some reason my annual renewal wouldnt go through unless I gave them another previously unused email address. I ended up with a half a dozen [email protected] [email protected] etc in the manage users. The irony was, I could still use [email protected] to log in, it only needed a new email to register the econtract annually. Very annoying. This seemed to sort itself out one year so I blame the reseller at the time for being rubbish. -
This is what we have for our device licensing (this is under "products".) A created package looks like this for us a new package gives these options and the contract shows pretty much the same as "product" page Looking at your licensing vs mine I would say you do not have a license for shared device.
-
We allow students to lock their PCs, we also advise them to do so if they get up to go to the MFDs for printouts. No issues for us. We have some pretty ancient PCs and they handle account switching ok.
-
indeed, the same method - intune doesnt allow the MST to be added to its MSI deployment but you can create a package with a script file too. Moot point if you arent using intune though!
-
the problem you might have is sending the email as the account you use to image may not have rights to send an email. If that is the case, have the client save a text file in a file server share, then you can have an FSRM file screen email you when the pattern file is detected. Like the old fashioned "crypto canary" but in a more wanted sense!
-
22H2 - intune/WUFB will only try into upgrade anyway so I might as well have the latest version to deploy.
-
Intune isnt bad for doing things like this. You can package up an installer with a script for logic. We do this for a few apps - check registry versions then uninstall and reinstall as necessary - package it up and ensure the .PS is given for the installer (and a corresponding uninstaller). Relatively neat. For example, it has worked well for acrobat reader installations with the MST and some tidyup afterwards.
-
As above, I have wrestled this for a long time. I believe you can do this with the JAMF management app, this is merely hearsay though as I dont have JAMF plus my notes are sketchy on this (I use Intune). The problem is that Apple do not pass anything along following an appleID+passcode "log in" to a shared ipad. the best you can get is the email address but certainly not an authentication ticket. So the minimum is appleID+passcode then open microsoft auth app and use azureAD+azurepassword and you are sorted for that logon on that shared ipad. If you set up the microsoft authenticator and the SSO extension then theoretically once you log into one MS app then all of them should recognise SSO, I have the most issues with outlook - it works SSO almost all of the time but occasionally will spit its dummy out and ignore the fact you can open word, lens, onedrive without prompt. There are other things you cannot do on shared ipads, the big one being screen timeout. You can set the passcode grace time but the screen will be off during this grace time. This grace time is also bad because you cannot manually lock the device as the grace time also runs. This catches teacher out a lot. The passcode is only for logging onto the shared ipads, the icloud logons are still the azureID+azurePW. Again our pupils get this wrong (even though it is a 365 logon page). We tend to tell people to manually save in onedrive (and dont tell them about the icloud sync) I have never used user affinity as we only have ipad trolleys. Even for the teachers. Im not sure what you mean by this? If you mean "should you want to change the grace lock time this is not easy on a shared ipad that is in use" then you are correct, its a full wipe and redeploy profile, not just a configuration profile change. Luckily there arent many settings in the shared ipad configuration. Manageengine were working on their MDM app to replicate some mimicry but we couldnt afford to double budget a 3rd party MDM when we get intune with the rest of our licensing so I need to make do with Intune.
-
you need to make autologon.microsoftazuread-sso.com trusted so that you can pass the kerberos tickets to an internet/cloud site. Unless you have your security set so low that any internet site can request (!!). Im not sure if you actually need any other sites setting to trusted for SSO to work, we certainly dont have many in our zone allocation. Ive seen people putting *.office.com and *.sharepoint.com in there, we certainly havent.
-
isams gets a negative vote from me. Their support is shocking. So far since the start of term ive submitted 5 tickets. *NONE* have been solved, in the end I scripted my own fix. I escalated a complaint two weeks ago and still haven't heard back from them despite requesting an update weekly. I have an email from their support for the first ticket I sent (a postcode checking error), the update after three weeks read "sorry we are taking our time, we have just taken on another 200 schools so our support is very busy". Classy. I have another email chain that has this very support ping pong spread over a week and a half - "sending to technical support", "escalating to business support", "sending to technical support", "escalating to technical support". Helpful. I had a 500 error for a product license error, that one was unresolved for a whole month, this meant we couldn't export anything to excel, which doesn't help for those functions that can ONLY export to excel. The data export errors in the pupil reporting module I fixed by using a homebrew API to CSV c# program, that ticket is still unresolved (coming up to a month). PArent portal has been moved to FireFly and communications is now with schoolpost. If you require full access to your data you need to push for database access. The paid for API module will not give all the data back to you, notable absence is anything that isnt current - the API wont pull back staff or pupils who have left amongst other things. The inbuilt reporting is very lightweight and cannot access all the data. You can get custom reports written for you but they cost quite a bit even with their report plan. It used to be much easier in the SSRS days If you do go with isams, make sure you get all the modules you need up front so you can get all the training with them, this costs quite a bit later on if you chop and change. In short, the product is ok, the support is ridiculous. I have the green light to start looking for alternatives and are exploring as we speak.
-
In the end I used PAC. There is already a powershell command for generating a suitable MS Office 365 list of domains for use as a PAC. https://learn.microsoft.com/en-gb/microsoft-365/enterprise/managing-office-365-endpoints?view=o365-worldwide#pacfiles I used common and sharepoint, the common files are stored in a sharepoint library folder, the rest is locked down so it works out nicely. No email but the exam group rules in exchange already sort that out.
-
so it still has the same limitations that you cannot apply a transform (or other modification) with the installation. So for Adobe reader DC we are still downloading, repackaging with an MST and kludgy batch file before uploading as a W32 app. There are probably a few apps that require the odd switch of setting that dont necessarily exist as a simply custom intune policy.
-
Luckily after I had the teachers sort out the licensing, the teachers soon saw how bad a company autodesk were and how much of a faff before moving off to use something else. I cant say what as its an online "something" that needs no input from me. Thus we could throw 360 into the bin. where it belongs. The software is good, the way the company go about making it available to install and set up for schools is terrible.
-
Autopilot self deployment profile for the shared device (as there will be no primary user). then a configuration profile in intune set up for shared multi user enabling shared PC mode and probably locking down guest mode so you need an azure account to log in. Thats about it really. Ive not looked at any sort of roaming at the moment though, our users are used to mandatory profiles so this is not an issue for us. I am looking at enterprise state roaming as a potential solution, this is the "new" UE-V I believe but im some way off that yet. One gotcha with this approach is to delete the device before repurposing with self deployment https://learn.microsoft.com/en-us/mem/autopilot/known-issues
-
I havent heard of intune for education. If there are fewer features then I would prefer to keep on intune premium.
-
wasabi and veeam.
