Jump to content

buzzard

Members
  • Posts

    430
  • Joined

  • Last visited

Everything posted by buzzard

  1. Well as we seem to be splitting hairs, I'd suggest that best practice is that all accounts have MFA activated (as I stated earlier) but the OP was asking specifically about 2FA on 365 admin accounts hence the above statement........
  2. Think I've gone a bit of topic off MFA on Office 365 admin accounts which should have MFA enabled as default as per the consensus.
  3. Not disagreeing with your example at all and completely agree (and I enforce MFA for staff anywhere and students out of school), just that MFA, using SSO on trusted IP ranges is MFA, just not explicit MFA it doesnt have to be a generated code etc, could even be a security question or text code etc
  4. Not really, their logon to the school domain is their second factor? that then passes through AAD Connect to 365, not all MFA methods need to be explicit
  5. Unifi, worth looking at their Dream Machine Pro if you want USG and Cloudkey2 etc in one package
  6. sorry to resurrect an old thread but did anyone get the Apps deployed via Intune (Endpoint Manager)? I've the packages made up individually in cloud packager and i'm under the impression to w32app them with a PS1 to initiate the install. Would appreciate if anyone has any scripts/advice they could share to save me some time! TIA
  7. Thanks @snagrat, thought that was the case, i've done lots of config in themain console and just discovered the Intune for Education portal but couldn't see Config profiles etc, i'll stick to the main one for the time being! Thanks once again!
  8. Ok should be a simple question but I can't get a definitive answer, is the Intune for Education a basic cut down interface to the Endpoint Manager portal, so thats https://endpoint.microsoft.com/ and https://intuneeducation.portal.azure.com/ ??
  9. I always use the method detailed here - https://www.digicert.com/ssl-certificate-installation-microsoft-active-directory-ldap-2012.htm If you're using other certs from other CA's just miss out the Digicert tool sections and use alternative methods
  10. I've seen this, not yet had time to look at yet, it has for us only started recently. I was wondering on a windows update/device driver?
  11. TBH the I thought the latest version works fine with Chrome, I believe it installs a plugin to Chrome, but its while since I had to touch it....
  12. It is a bit of a minefield, I cant find nor has anyone returned my calls from MS to clarify the exact definition of who needs to be counted as FTE. You'd think this would be well documented and posted on a website somewhere!
  13. Again resurrecting this thread, does anyone know what the stance is on this? As the MS memorandum of understanding has expired what are we now counting as FTE?? Any pointers or official MS text would be great, I'm really struggling to find anything!
  14. I have to say, I've worked on W10 for 18 months (now for a 3rd party supplier to schools and businesses) and once you get to a working platform (we run with 1803) it does work. I totally get how much effort it takes and the issues in getting there. I had a battle here to get them to drop cloning (Using Acronis Snap Deploy) and move over to MDT and then to move from other traditional technology to the "Windows 10" way of doing things and in the whole it works well, its not as stable or forgiving as a W7 system, but thats had the best part of a decade to iron bugs out. I've been around long enough that I've worked on all flavours of Windows from 3.1/NT upwards in schools and for me W10 is the best imho. Staff need to be aware that the crappy old obsolete apps such as RM Maths wont work on Windows 10 correctly etc and when they first migrate to W10 the start menu will be basic (we just present Chrome, IE and 6 Office 2016/365 Apps) We use roaming profiles and use folder redirection (inc AppData). Most of our data is cloud based (in Box) and we use OneLogin for SSO for all of our Website subscriptions services and it all just works well. As usual the hardest thing is making sure you have enough resource, mainly time to be able to develop and test the W10 system, including UAT testing (we tend to do one traditional IT Classroom), but you do need SLT/Staff on board. Good luck with it and keep going, once its mature it'll be better!
  15. update the deployment share and then update the boot images in WDS, that worked for me especially if you've updated MDT
  16. we copy a shortcut from the server to the local drive and then in the xml for the start menu (which you've generated) point it at the local shortcut, not to explorer.exe as it doesn't like it. We copied the shortcut via the Machine GP to %ProgramData%\Microsoft\Windows\Start Menu\Programs\File Explorer.lnk
  17. I'd start by looking at your Office 2016 policies, probably around trusted sites/security, what have you set there?
  18. buzzard

    Bitlocker

    We use cloud storage (Box) for all data and on all devices we disable the USB in BIOS to prevent their use. All Laptops and PCs are bitlockered through MBAM. I do remember having the discussion in a number of primaries where I mentioned blocking USB drives and it took a few years of negotiation. One good thing about GDPR is its raised the awareness and SLT are now even more aware of the responsibilities they have!
  19. No Idea David, i though the same when they said it, but it worked straight away and has been since Oct 2017!I've not tried it on 1803 though.... Barclays dont seem to bothered about it working without Incognito mode.
  20. After speaking with Barclays about Gemalto not working when we went to 1709 (worked fine in 1703), they said try IE in incognito mode, thats still the only way our admin users manage to use Gemalto....
  21. I dont suppose anyone's had a chance to look at this at all? I'm not getting very far with regards to consistency, if anything the more I try, the more I end up with 1709 machines that will no longer call home to WSUS
  22. I'm planning on having a GP that, using a WMI query, will ID it as 1803 then 'run once' a PS script on startup to strip out the crap 1803 installs. its the forcing the update to install that I cant find any info on, closest I've found is this - https://gal.vin/2017/08/23/upgrading-to-windows-10-from-previous-version-of-windows/
  23. Hi, I'm looking for a way to force the upgrade from 1709 to 1803 (Education), I'm just doing some testing prior to actually pushing this into the live environment. We've the deployment rings set up in WSUS as per MS Articles for WSUS and W10 and I've got the 1803 update to appear to the end user (teacher laptop). Knowing the teachers, they'll keep clicking not now, I've been looking for a way to force the update on either a date or before a date other than a manual intervention but have only come up with ways of deferring the update. I've not needed to update W10 version yet as we went live with 1709. Any pointers or advice from those who have already updated previously would be great. Thanks
  24. bit late but I'm guessing they've gotten around to cleaning/removing the old proxy so it finally stopped working?
×
×
  • Create New...