Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

LemonEntry

Members
  • Posts

    120
  • Joined

  • Last visited

Everything posted by LemonEntry

  1. I've added more URLs as they appear in the filter. Currently only two students cannot use Visual Studio. Do I need to look at a replacement?
  2. How are you licensing Visual Studio, or are you not using at all? I have students who must not access the internet for their CS Controlled Assessment. Visual Studio Community Edition, free to schools, requires an Office 365 account to use. How are these two compatible? I've tried to unblock the domains only for O365 sign in (without actually allowing access to O365) but I still have a couple of students who cannot utilise Visual Studio. This seems to be since the new sign in method was released by MS, but I can't exactly pin point it down. We don't have the budget for Pro / Enterprise. If we can't license Community Ed without releasing internet access, it'll need to be replaced. Any suggestions?
  3. My CS students are using VS2017CE as their IDE. Board controlled assessment criteria requires no internet access. VS2017CE checks license validity online every 12 hours. Currently I have the following in my filtering exceptions list. Has anyone else noticed any more URLs used for this purpose? Activation seems to still be failing, but not for everyone. officeclient.microsoft.com vo.msecnd.net vortex.data.microsoft.com vsspsext.visualstudio.com azure.com vssps.visualstudio.com digicert.com graph.windows.net
  4. Same way I always have. Build and test a new up to date image during the summer term, reimage the site over the holiday. 1703 will be supported until September 2018, so I see no reason not to hold off on 1709 and whatever the next release will be (1803?). MDT is set up so we just drop in a WIM with the bundled apps removed and nothing else... Total time before sysprep is less than an hour.
  5. I updated the OP after checking the policies. I've changed the last policy to "Disabled" which causes the updates to install at the next scheduled installation time (every night at 0100).
  6. Win10 PCs across the site are restarting for updates in the middle of use. 5 days remain on the update deadline. What the hell did i screw up? Edit: I've checked WSUS GPO: [TABLE=width: 500] [TR] [TD]Allow non-administrators to receive update notifications[/TD] [TD]Enabled, didn't work[/TD] [/TR] [TR] [TD]Allow Automatic Updates immediate installation[/TD] [TD]Enabled, only install patches requiring no restart[/TD] [/TR] [TR] [TD]No auto-restart with logged on users for scheduled automatic update installations[/TD] [TD]Enabled[/TD] [/TR] [TR] [TD]Re-prompt for restart with scheduled installations[/TD] [TD]Enabled[/TD] [/TR] [TR] [TD]Delay restart for scheduled installations[/TD] [TD]Not configured (15 mins default)[/TD] [/TR] [TR] [TD]Configure automatic updates[/TD] [TD]Enabled, Download and schedule, 01:00 daily[/TD] [/TR] [TR] [TD]Reschedule Automatic Updates scheduled installations[/TD] [TD]Wait 30 mins after startup.[/TD] [/TR] [/TABLE] That last policy states Windows 7 and Server 2008 and older, but could this be it? It was ~30 mins after login that clients restarted.
  7. We have "free" Meraki MDM available in the form of a Legacy license, but it's been abandoned for over a year and the certificate has expired. I can reconfigure it and regenerate the cert, but if I'm doing that I may as well create a whole new setup with a different MDM. Also just discovered that my iPads are 5 years old and can only run 10.3.3 -_-
  8. We have a student here who qualifies for ESA allowances, and has been assigned an iPad for individual use both in school and at home. We use Apple Configurator to manage iPads (10, plus this extra 1) at the school site, but this won't work for one taken outside of our network. Are there any MDM solutions which are suitable for just one device? I'm happy to use Configurator to handle profiles and configuration, but something to lock it down and track it when off site is required. We have VPP and Apple School accounts, but are currently only used for licensing applications.
  9. Turns out the policy change did resolve the issue, I just had to wait a few days for the policy to apply to sufficient workstations to make a difference to the bandwidth readout.
  10. I'm looking at the Smoothwall Bandwidth module stats... Microsoft Update (Windows Update and BITS) is using 0KB/s, but I'm still seeing the domain filter past in the Recent Blocks list on the Dashboard, and the total bandwidth used isn't decreasing. And I still have slow internet access everywhere -_- Maybe it's DNS? Isn't it always?
  11. 24 hours after the policy was applied: 7.tlu.dl.delivery.mp.microsoft.com 84.8 (GBytes) 3.tlu.dl.delivery.mp.microsoft.com 74.4 (GBytes) 2.tlu.dl.delivery.mp.microsoft.com 59.2 (GBytes) I'm tempted to just blackhole the domains.
  12. So from reading the blog post from @atcoates I shouldn't be using any upgrade deferral settings. These cause Windows 10 to operate in "Windows Update for Business" mode and check against Microsoft Update for patches. The fix is to just leave the original WSUS settings in place and ignore everything else. I'll let you know if it works! Edit: I had the policy "Select when Preview Builds and Feature Updates are received" enabled and configured which is inside the subsection Computer Policies\Administrative Templates\Windows Components\Windows Update\Windows Update for Business. Now I think about it, I'm managing availability of Feature Updates via WSUS, so I don't need to defer them. If that's not how it works and I end up with a mixed 1703 / 1709 environment, I'll go become a goat herder. I've had enough of this tomfoolery.
  13. I've disabled the Store, and configured my Windows 10 clients to check our local WSUS server for updates, defer Feature Updates for 365 days, prevented deferral policies from causing scans against Windows Update, prevented connection to any WIndows Update Internet locations, and removed access to use all Windows Update features. I am still seeing 300GB of traffic per day from subdomains of tlu.dl.delivery.mp.microsoft.com.What else can I do to kill this traffic? Would blocking these domains on the Smoothwall cause problems?
  14. Exactly the information I needed! Not bad for a first post!
  15. Can Smoothwall pull account information of users already authenticated to an AAA server via a third-party Captive Portal? We already authenticate guests on our Guest WLAN via RADIUS. I have configured Smoothwall as a Client on the AAA server, but the reports still show IP-based "Default Users" in reporting instead of the AD account with which that client is authenticated. Have I missed some part of the RADIUS configuration? Does Smoothwall need to also authenticate clients through RADIUS in order to match up the accounts?
  16. It's *a* DISM method. You can pull them out manually after mounting the WIM, or you can script it as in this example.
  17. Configure Windows 10 taskbar - Remove default apps and add your own
  18. Uhhh... Sysvol is readable by authenticated users anyway. If you're hiding secrets in there then you're using it wrong.
  19. I'm not modifying the WIM at all. All configuration is done in GPO and task sequence.
  20. It all depends on which application shortcuts exist in the path specified in the XML file: %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\ If you currently redirect the start menu it is likely that you won't see many tiles at all, except for the Metro apps you've listed (Which are always available in Start, if installed. I hate you, Microsoft).
  21. Request Denied.
  22. Just tried it myself and it reports it's registered, so here's hoping...
  23. By any chance do you know if it can be registered as part of an O365 education tenancy?
  24. And where, for the love of all that is holy, is that Explorer icon?! It's not even in the XML... Everything works except the Start Menu. I can't even.
  25. On restart, icons in %AppData% subdir are returned to default, ProgramData subdir are blank. I've a policy somewhere that is screwing up my Start Menu...
×
×
  • Create New...