Jump to content

KK20

Members
  • Posts

    969
  • Joined

Everything posted by KK20

  1. ive never used winget, i'll have a look. At the very least I might get a better insight other than "not applicable"
  2. we have teachers who use microsoft whiteboard (most use openboard). I am trying to get it deployed via intune rather than leave it in our personal store for staff to install themselves (plus the store is going bye bye next year of course). I logged onto the store, "bought" the offline version, sync'd intune connector, assigned the offline app to a suitable set of PC groups, set the licensing to device and thought that was it. Unfortunately I now have a device report of "not applicable" for all my PCs. Any ideas on why it isnt installing? For notes, I then decided to install the "online" version using suitable staff user groups and user licensing - all this went on just fine (but will be useless next year).
  3. My notes tell me this is what I used to create my base WinPE https://joymalya.com/windows-10-deployment-with-osdcloud/ you can specify a local source too if you want to put the ISO on the USB - it doesnt have to be totally online if you dont want it too. https://www.osdcloud.com/deploy/iso
  4. I backed up in veeam and restored to smaller destination, it worked well in my P2V. Depending on how many P2V you are doing, community veeam is free to 10 licenses, I have no idea if the free agent version will work on servers, if so then that will simplify matters enormously. The beauty of this is that you dont need to mess with the source disk (other than defrag and installing a veeam agent). Granted this means you will need a temporary backup destination for veeam repository but you can use a NAS or even a giant USB drive. unmovable blocks will be your only barrier, you know if you have them as you can start the "shrink" process after defrag to see what windows could shrink to (you dont have to commit). This will be the smallest VHDX drive you could use in this method.
  5. https://learn.microsoft.com/en-gb/certifications/exams/md-101
  6. yes. Use OSDcloud to get OS and autopilot profile up and running, no faffing with latest ISO or drivers, OSDcloud sorts it all from a lightweight WinPE. If there is nothing on the drive you need to get an OS on the machine, then the autopilot profile. OSDCloud is automated, you boot off a USB stick and away it goes. Of course there are other methods, I prefer automated ones.
  7. We are moving to a leasing model academic year 2023/24, we will still be hybrid so although we are using autopilot, a domain visibility will still be needed for us for the time being. Serverless is looking like 24/25 i) a new laptop is purchased. How would you bring the laptop in to the controlled environment such that the remote management agent (ConnectWise Automate) and Sophos AV is installed? The leasing company know our tenant and the computer ID appears in autopilot. I assign a profile to it. User gets given the laptop IN SCHOOL and it sets itself up using intune configuration policies. We are hybrid so the device needs to see our onsite domain controller. In the future it wont when we arent hybrid. Intune sorts out the software and all the necessary locking down, certificates, universal printer settings, etc etc ii) a laptop for a leaver is passed to another new user - how do you handle this? I hit wipe on the laptop in intune and the process starts again from above. The same if the device is lost, sold, broken, returned to lease company etc. here is another scenario: I have a hard drive failure on a device that isnt leased but it owned by us. I use OSDcloud to get OS and autopilot profile up and running. Then we are back to (1)
  8. With sharepoint migration tool it is trivial to uplift an onsite share with permissions to a sharepoint library. The same with onedrive although I did things differently (I had a mapped home drive to onedrive and got the staff to move their own stuff with a deadline and reduced onsite quota). I only say hybrid because that is transparent to the users and you get all the permissions sorted already but its your call of course. This also means you can have hybrid AD joined PCs so you can start migrating your settings from GPO to intune with co-existence rather than having to register each PC too. The big gotcha with hybrid is that you still need to manually remove from domain and autopilot them - however you will need to do this anyway - but with hybrid intune will already have all your devices which can be added to autopilot and profiled accordingly beforehand. The biggest issues with intune are GPOs. Intune is much clunkier than GPO (IMHO), I didnt bother with the GPO migration as almost none of my more complex GPOs would work and needed tweaking. Im probably 50% way through migrating my GPOs to intune. If you rely on gpupdate /force for impatience then be aware that refreshing the intune scheduled task and restarting intunemanagement is nowhere near as quick on the uptake. Software installation in Intune is not bad (ive just pushed an update to a line of business MSI around 5 mins ago and I have a status update with waiting to install on 60% of my machines already). Intune and AAD have no concept of OUs, I created a small program that made AAD groups based on my OUs, then I could set up my intune profiles with a mimicry of the onsite setup - not for everyone but this is my network Apart from that ive taken a group policy result of staff and pupils, taken a spreadsheet of the settings and am working down the list creating an intune profile for each one. for intune blocking of store, try this custom OMA-URI /User/Vendor/MSFT/Policy/Config/ApplicationManagement/RequirePrivateStoreOnly with a DWORD of 1 that will lock down teh store app to only show your published MSstore stuff (no idea what this will do when the store shuts down next year)
  9. Here are my suggestions. 1) take stock. Dont jump into things. 2) look at what you have, what you pay for, what is licensed already and who your providers are and refresh dates. 3) Have a plan of what you want to do and why. Remember that any changes come with staff training and sometimes issues. 4) Assuming you want to go ahead with removing all onsite you will need azure premium at the least. Do you need a bigger (and redundant) internet connection? 5) I would start with hybrid, then look at first migrating onsite email, then onsite shared files, then onsite documents/home drive. Look at what you are going to do with any "big files" software such as photoshop or CAD or media/video software. 6) BACKUPS! Its all in the cloud now. 7) decommission your file servers then look at how your other services can move to the cloud - printing, MIS, intranet, filters, cleaner clocking in devices, scanners, UPS, finance software, anything else that needs onsite AD credentials. 8) get a cloud MDM sorted, probably intune, and get the GPOs migrated to a cloud version (such as intune configuration profiles). Also look at autopilot for your new devices. 9) once all your local AD dependencies are removed from the system then you can migrate off your AD to AAD completely whether you start with new profiles or not is up to you. 10) you will still need a firewall, DHCP, DNS etc but that can be a small device. I have stopped at "9" as I cannot currently fulfil all of "7". For licensing I recommend John at very-pc. There are others out there of course and im not on commission.
  10. It doesnt need a lot of resources. I use a DS218 at home with a pair of ironwolf drives for my personal family onedrive backup. This is a total of around 3Tb of data on my home accounts including email. This is a daily backup too.
  11. sharepoint calendars can be added to outlook (I use one). go to your full calendar (not the little events web part). Click calendar tab to open the ribbon, click connect to outlook. A popup will open in outlook asking permission to join the calendar. Say yes and you get a separate calendar in outlook. Now the bad news. It is really flaky in outlook, you get errors saying the event has changed, you get popups saying the event is in use would you like to save in your personal calendar (which then adds the event to your own calendar instead of the sharepoint one). Categories dont always change colour, sometimes they do, sometimes not. ignore me, you said LIST not calendar. However the note about the flakiness might dissuade you. A shared mailbox calendar works well though.
  12. never mind. Ive sorted my own issue, I will leave this here in case anyone else sees this behaviour and scratches their head. By design: https://learn.microsoft.com/en-us/answers/questions/318388/duplicate-hybrid-azure-ad-devices.html I didnt spot the join type of Azure AD registered on the DEVICE_SCREEN properties. So all is well, its just AAD being AAD. I simply need to remember to add a filter in the future, once filtered to hybrid join the same device name appeared with the correct GROUP/INTUNE_SCREEN ID's
  13. I wanted to know which groups a device was member of in AAD. So I logged onto AAD, went to devices, searched for the PC name - one result returned - clicked on the device and the groups section said "none" (I will refer to this as DEVICE_SCREEN). This was odd as I know for a fact it is in one group (since it has deployed some intune policies that I know are working). So I went the other way, clicked groups, looked at the group I know the device is in, low and behold the device was there, clicked on the device and that group box tells me the groups the device is listed in (referred as GROUPS_SCREEN). So I looked at the objectID and deviceID for the two screens - both different. Opening intune, looking at the "hardware" screen for this device and the azure AD device ID (INTUNE_SCREEN). Now, the INTUNE_SCREEN azure AD device ID is identical to the GROUPS_SCREEN device ID. If I look in AD on prem, the ObjectGUID is the same as INTUNE_SCREEN and GROUPS_SCREEN. get-adobject returns not found for DEVICE_SCREEN but returned the correct object for INTUNE_SCREEN/GROUPS_SCREEN So why do I seemingly have two devices but only one appears if I search by name? If I search by name I get the (unwanted really) DEVICE_SCREEN id returned? There are no duplicate "names" in the devices screen nor intune devices. This isnt an isolated PC incident either, in fact this happened when I searched first half a dozen - all of them the same behaviour.
  14. nope. Part of the ICT practical is to design a website so that cant be done.
  15. Looking at ICT exams and the requirements for the practical assessments. This academic year is the first exam since the new syllabus. Previously students were allowed to use the internet plus all the normal working applications. Since covid this has changed it seems, now the students are not allowed to use the internet. We are using office 365 so that will be fun licensing our users with no internet. So, looking at a solution that will allow office365 to license but student having the internet denied I have these thoughts: Students use an exam domain logon (that has a 365 account associated). Exchange rules prevent sending and receiving emails. Member of an ict group so I can lock down via GPO (we are hybrid). 1) first option was to create a whitelist internet group in our filter, that way office 365 can authenticate and license but pupils wont be able to use internet pages. This would naturally open up sharepoint but that is ok because the ICT pupils use an examination logon rather than their usual logon (so easily locked down). Problem though, Securly isnt as good at doing this as our previous filter, sure you can create a whitelist profile BUT! global exceptions are allowed - not just the whitelist allow, this means ALL those bypass sites that have been approved using their teacher allow web page will need to be removed from the global list and added to the individual profiles. A non starter. Why securly couldnt have a second switch under the whitelist option to give you a choice of include global allows or not is beyond me. 2) second option. "Extended offline access" for 365. I dont know much about this so I will need to look into it. I assume it is a non starter because a user would need to log into their exam account first, then have the internet blocked. Seems a lot of work. 3) Specialised PAC file. We use securly and their PAC, I block internet to the exam accounts by putting a non existent proxy via GPO. I could create my own PAC that examines the address and either lets it through to securly (microsoft logon sites) or sends the user a non existent proxy address. Im leaning more to (3) as that seems simple and least work. However I will need to look for office 365 logon urls (I dont want to blanket allow *.microsoft.com as that will open up the website portion at the same time).
  16. urgh. no filter for operatingsystemversion. I exported a CSV, started at the 10.0.22000 for azure ad registered and searched for the first 6. Nothing in the keys. I could use graph for https://learn.microsoft.com/en-us/graph/api/bitlocker-list-recoverykeys?view=graph-rest-1.0 but im too busy at the moment. perhaps none of our students/staff are affected for whatever reason, perhaps hybrid behaves differently (our onsite laptops do not have their keys listed in azure AD, only in on-prem AD), perhaps I picked 6 that had no TPM. If it becomes an issue for us then I will create a powershell script and tack it onto our housekeeping scheduler. I will keep a database of deviceID that I have emailed, periodically download the graphapi bitlocker keys, email the username first registered with the device and send the bitlocker key with an explanation of why im emailing them then update my database to say ive contacted for that device id. Problem solved from my part. If it truly bothers then im not sure if you can lock down a conditional access to block apps access, that way they cant azure register - browser only.
  17. you have to be careful with these sorts of agreements, especially for businesses. A good friend of mine had a very similar issue in Lancashire near the (as was then) new buckshaw village development , they used point to point wireless and came to an agreement with a business in the middle of buckshaw village. This went well until the lease holder got involved a few years later - apparently the business started to act as a repeater for others and it all went south badly. Ironically by this time the provider couldnt get permission to put a proper larger mast up in buckshaw as there was too much development so my friend lost out for a few years until other internet options arrived. He ran a small dairy on the outskirts of the development so it was a business line.
  18. we use a business 80/20 FTTC for our failover.. Our main is a 250/250 using P2P wireless, we have no FTTP and no trunking to get a reasonable connection up our geographically tricky location but at least we can get 80/20 on our copper. Our firewall does the failover portion and we use active-active (although I tend to divert the guest WIFI over the failover link unless the main is down). A low TTL DNS services looks after our external DNS (we host our own intranet and VPN) sorts the DNS failover (this emails me when it fails over so I know something has gone on, it emails me if NEITHER can be reached which only happens when I take the HA firewall down for some reason). SLA on the main, nothing on the failover but it is only a failover. I can count on one hand the number of times we have been on the failover only in the last few years so it is a worthwhile investment. We pay £35 for the DSL and £350 for the 250/250 per month. I cant remember the firewall subscription per month nor the DNS but it isnt that much. I would love to see these 500mb for £65 per month quotes and where they will supply. It would be worth paying the 30k to dig up the very long driveway if those can be installed as I can factor in a reasonable return cost into my proposal!
  19. Dont have a force encryption of registered devices. Only have one for joined devices.
  20. Nothing our end, I imagine because the admin portal is locked down and you need the admin portal to be available in order to create a new tenant (afterall the first step is "log into the admin portal"). However, I am not sure if there are third party apps that can bypass this or powershell commands that do not need the admin portal - they would only need the rights to be able to do so. That being said, the first tooltip from "Restrict access to Azure AD administration portal" is "this is not a security measure"
  21. In the words of Sam, "Oh boy" I especially like the bit "anyone who creates a tenant will become the global administrator for that tenant"
  22. why would you want a BYOD or home device to not register? For example I have an intune compliance policy that disallows rooted devices so all those pupils who try to connect their email to our system and have rooted phones are not allowed.
  23. This is my quandry. I would love to move off hybrid and fully cloud based but there are quite a few obstacles. Most of those issues will be AD permissions for unavoidable local file shares. Art, Drama and DT. These three subjects create mahoosive files for us. We currently use a (backup up) HA cheap drives NAS with some mapped drives to store files for these pupils. Part of the teams script I use also maintains the shared folders for pupils on a mapped drive. It is simply not feasible for us to sync these work files with the cloud, especially when we are talking gigabytes of raw workfiles per pupil. Cheap SSD caching on these NAS works wonders when the bell goes and people click save. There is no way in hell these files would sync to onedrive in short order! The same can be said for certain software (looking at you finance) that also create large local shared files, im sure there are cloud equivalents but for whatever reason it has been declined or not migrated. Cost. I do like all the companies that claim moving the cloud with everything will save us money. sure, maybe if we were on a 3 year hardware refresh cycle with the latest and greatest SANs and servers but we arent. Moving our BMS offsite, paxton upgrade, CCTV would be a monster undertaking and simply not worth the return on investment to simply get rid of onsite AD. We already have a BYOD that works for our learning with onedrive and sharepoint storage, cloud VLE, cloud printing to email; I would have a hard sell for the SLT. Staff use their laptops with cached credentials and can access all the cloud stuff or they can VPN for apps with "school" storage - not ideal but it worked well enough during lockdown. we wanted to move isams to the cloud but could not get a cast iron guarantee from them that we could access our data - the API does not let you export "staff who have left" for example where we currently grab it from the database - they could not say if we would be given a database access in the future, so onsite it stays. I looked at moving our onsite SQL server server offsite - we only use a 4 core license so this would surely be cheaper using an azure SQL server you would think. Nope. Again, costing this out over say 3 years worked out more expensive in azure than having a local VM instance with its storage burden. Now I could have overestimate the vcore/hour rates I seem to remember running a profiler over a few days (this could have been heavier than normal days) but we get away with a 4 core SQL server on its 3tb datastore quite happily. So for the time being I am stuck with hybrid and all the creaking that entails.
  24. I stand corrected, it does work on servers https://learn.microsoft.com/en-us/windows/deployment/update/waas-configure-wufb all I needed to do was read.
  25. nope and I wouldnt use it even if it did. I believe Azure Update Management is the correct way to go for server update management, ive not looked at that yet: I patch my servers semi manually, I use a Get-WUInstall script after I have tested an update run first. I didnt use WSUS for our servers since I used WSUS with autoapprove critical and security for the desktops without testing (time constraints) hence my move to WUFB wasnt onerous as I installed all the updates anyway.
×
×
  • Create New...