Jump to content

LemonEntry

Members
  • Posts

    120
  • Joined

  • Last visited

Everything posted by LemonEntry

  1. Just a quick update to demonstrate my idiocy... The policy to not delete profiles was disabled, hence they disappeared.
  2. Well yes, I'd very much like to do that, but have been vetoed by SLT (I'm all CYA on this, data stored on the desktop is totally not my problem if it disappears, regardless of reason). I'd just like to know why it happened now, not when we pushed 1703, or when we installed the February updates, or whatever else may have caused it, and why it's only these two. Comparing the logs is going to be a chore... Just wondered if anyone had seen something like it and had an idea of a reasonable starting point for diagnosis.
  3. The policy is already rebuilt, but blank. They've lost planning that was stored on the desktop, which is all I'm worried about. I still would like it to not happen to anyone else! (Staff already know not to store things on the desktop; I'm not on the hook. Just trying to avoid derailing into a talk about following policy... I'm only interested in resolving the technical issue!)
  4. Staff laptops should be specifically excluded from local profile deletion, but there is such a policy in place. I'll check the GPO links... Good suggestion! Edit: Not that. Profile deletion is applied to only student laptops and ICT suites. Staff laptops have "Comp > Admin Temp > System > User Profiles > Delete older than X days" specifically disabled by another policy.
  5. Two staff have this morning come to the office with laptops that have blank local profiles, despite being in use since September. Desktop contents, web history, Outlook profile, tile preferences all gone. I've not seen this before without it being at my behest! Both state Friday afternoon as the last time it was working, with one discovering the issue Saturday morning, the other this morning after not working over the weekend. Updates not a factor. Anyone know where I can start looking for solutions? I'm working through System and Application event logs, and nothing in the User Profile Service log aside from normal information entries. Edit: Windows Defender AV, nothing special.
  6. I thought it was common knowledge that "Unsubscribe" links were just a way to verify a good email address. You may well be unsub'd from that one, but you'll find three more mailing lists added soon after (Good luck proving otherwise!)
  7. RocheAV insist on giving contact details for pricing (everything is "POA"), which puts me off. I already get enough spam from companies who didn't provide the best quote at the time, I don't need to add another to the list.
  8. Only if the throw ratio is the same. It may mean a *wider* image in your rooms instead, with more usable horizontal and vertical space. It depends, I suppose, on whether the projection surface fits a 4:3 aspect or 16:9. Ours are a bit of a mix so we're aiming for matching the horizontal width, as that's typically how projector throw ratios are calculated.
  9. I've never liked enforced policies... Having conflicting policies of any sort have always caused headaches. Can you exclude this PC via a security group, i.e. Set up Security Filtering for your Disable Microsoft Store GPO and include all but this one client from a new DisableStore security group?
  10. Has anyone gone WXGA or 1080p? It would be helpful, in my mind, if the projected image was of the same aspect ratio as the connected device (staff laptop). Very few screens are 4:3 anymore... It's odd that projection has remained that way.
  11. *Each* access point?! I have over 80! That can't be necessary... If you don't have captive portal, how do your users use domain credentials for guest wifi?
  12. We have an Alcatel Mobility Switch based WLAN with Captive Portal BYOD authentication via LDAP, and RADIUS AAA to our NPS server. Users logged on to domain-joined PCs and through the captive portal on the BYOD network are identified correctly (Username associated with IP address of device). This information is not passed to our Smoothwall filter (Username is IP address of client), which is causing problems with filtering and monitoring. The NPS server is a RADIUS client of the Smoothwall, and also authenticates users via LDAP to the same DC as on the Wireless network. Do I need to put a direct link (RADIUS client / supplicant) between the WLAN controller and the Smoothwall for the Accounting information to be recognised on the Smoothwall? If so, which is the supplicant? If not, where else could this configuration be incorrect?
  13. I understand I'm necro'ing a post, but is there a resolution to this issue? So far I have one instance of this error, but my entire fleet is 1703 Edu. I was planning on holding off until the Summer to reimage the lot... I don't fancy doing it during term time.
  14. And GPResult shows the policy applies correctly? o_O
  15. Microsoft.Skypeapp is not Skypeapp.exe and Skypehost.exe. Those are "Classic Desktop" applications, not Universal Windows Platform "apps". Create a Packaged App Rule to deny "Skype - Microsoft.Skypeapp". It's separate from Executable rules but still found under AppLocker in Group Policy. I have several deny policies for social and gaming UWP apps located there, all working fine.
  16. I added every URL in the list you posted to the site-wide block list, and whitelisted it for the WSUS server. It's a pretty crude fix, but it's working. No more random updates or high bandwidth usage!
  17. It's more like you've downloaded November's patches (Windows, Office, extras?) on your entire site. That's why I blacklisted those URLs for all but the WSUS server; Clients can't bypass the GPO settings if they tried. It's a DoS, AFAIC. The threat gets mitigated.
  18. I'm looking at Mosyle for the time being. Thanks for the suggestions, all.
  19. So, a little update... It's not really fixed. The domain just changed. I now see traffic to download.windowsupdate.com instead. It's not funny anymore. My "fix" is to whitelist Software Updates for my WSUS server only. If Microsoft can't obey it's own policies with regards to updating, I'll cut them off at the border. I have Software Assurance; I'll open a ticket with Microsoft and see what they suggest. Probably "Install 1709 yolo!!1"
  20. How do you have that configured? We're pretty strict, but I don't think I could sell Management on buying PCs capable of running a software VM just so applications were isolated. We whitelist with AppLocker, but have an exception for CompSci students. They're typically not the troublemakers anyway, and if they are they're bringing Kali in on a memory stick and giving me something interesting to investigate!
  21. Indeed that is the case, but I don't perform driver updates via Windows Update anyway. Updates are tested on a single workstation and deployed using MDT during the next refresh, or via PDQ Deploy if it's mid-term and can't wait (new USB device, for example).
  22. It was configuring "Select when Preview Builds and Feature Updates are received" in Policies\Windows Components\Windows Update\Windows Update for Business\ that caused the issue. Windows Update for Business is for networks without their own WSUS server and connects to Microsoft Update. Resolving it involved setting this back to "Not configured" and also setting the following policies as a "scorched earth" solution: - Do not allow update update deferral policies to cause scans against Windows Update: Enabled - Remove access to Windows Update features: Enabled - Do not connect to any Windows Update Internet locations: Enabled
  23. Microsoft pointed me to this URL: Office 365 URLs and IP address ranges - Authentication and identity
  24. Microsoft pointed me to this URL: Office 365 URLs and IP address ranges - Authentication and identity Exactly the information required.
×
×
  • Create New...