Jump to content

StephenPink

Members
  • Posts

    333
  • Joined

  • Last visited

Everything posted by StephenPink

  1. Not directly related to this - but have got 1 2022 DC and 1 2025 DC and the 2025 definitely has some odd behaviours; - Kerberos Local Key Distribution Center service is stuck "Start Pending" - Defender Firewall sets itself to "Public" - NETLOGON error on boot - This computer was not able to set up a secure session with a domain controller in domain XXXXX due to the following: An internal error occurred. No issues on the 2022 DC; this is currently the Master still. the 2025 has had the 2025-02 Cumulative Update applied yesterday and no change. All very odd!
  2. Recently moved to iTrent - can't comment that much on how good it is though as haven't been that involved...
  3. Thanks - has gone down very well with the team, and Computing who are next door! A very nice suprise
  4. Hey all, I'm looking into federating Google with Entra/Azure AD at the moment - reading through Federate Google Cloud with Microsoft Entra ID (formerly Azure AD) | Cloud Architecture Center it seems fairly straight forward (famous last words). However, I'd appreciate if anyone has any experience from doing this themselves in the past, or any recommendations for third-parties that may be able advise/support the process. Thanks, Stephen
  5. I found it was no longer required - previously there was an issue with the build getting "stuck" on a network or cortana screen, but took the unattend file out completely and no issues with 10 22H2 or 11 24H2 Cheers
  6. So...late to the game, and now trying to push this out in a bit of a rush! Few questions; - anyone willing to share a GPO for the whole setup of user/computer running EWP? - I've tried to push custom json settings during the install, but it doesn't seem to work? that's the msiexec with SETTINGSFILE switch - they're just not applied. Have I misunderstood? Any other tips/tricks to get this up and running quickly would be much appreciated! Please PM if easier. Thank you
  7. Noooooooo say what?? Where did you hear/see this please? That would be massively disappointing - I can't see anything in my Dell Premier Portal. Thanks
  8. Thanks for this - I'm not super familiar with Android and that hasn't helped trying to streamline the BYOD people connecting. I got someone to test however, and this was the response; Option 1 - Dont validate - Lets me connect to the AP but there is no internet when trying to browse the webOption 2 - Use system certificates - Does not let me connect to the AP Andriod version - 14 One UI version - 6.1 Anything that's been missed? Thanks
  9. We're using the Dell UD22 docks - with Dell laptops, HP laptops, Macbook Pros all with 3 screens (2 DP, 1 HDMI) and so far so good. There was a little bit of DisplayLink driver faff on the Macbooks at the beginning, but otherwise reliable. And I think they're around £110 ext VAT.
  10. Resurrecting this again as still on the list and may be prioritised this year, however there are now 2 scenarios; 1. Local AD > Google This one is currently Local AD > Google using GCDS and Password Sync (and then Local AD > Entra using Entra Connect) Figure this would probably me more straight forward - those that mentioned Cloud Connector Enterprise app is this still the way to go? Not sure I fully understand that one though... What would be the biggest risks/gotchas to look out for here? 2. Separate AD and Google This is a Local AD > Entra using Entra Connect, and then a completely separate Google domain. The UPN/Email is the same (99%) but the accounts/identities are not connected in any way. Seems like this is more complex! Not even sure where to start with this? Again also, biggest risks/gotchas to look out for here? Any recommendations/suggestions for companies that may be able to help with this sort of work? Primary driving force for this is MFA - enforcing MFA across all sites, but don't want people to have set up multiple MFA apps/accounts for what they see as the "same" account. And just generally shoring up identities to reduce confusion/likelihood of poor passwords etc etc Cheers
  11. Thanks appreciated - yes I configured DFS at the other site, actually as part of a File Server Cluster. We're talking about ~50GB per student, without around 300 students in Media alone though - it's the scale here (and the current state of the network) that is making me question it. There is a current Media share that is 14TB and has around 2TB free... I was wondering as well in terms of affecting the otheer subjects and network access across the site, when all teaching simultaneously and trying to read/write to the same storage (or keep them separate) Hopefully that makes sense! Cheers
  12. Hey all, Wondering what others are doing (if anything specific) for the large, and growing larger, amount of storage required for student work in subjects such as; Creative Media, Music, Graphic Design, Photography etc Current thoughts are; - Standard Windows File Server - at the moment, the hardware we have is too old/small and too slow. Perhaps an investment here would work better - but then reliant on local networking and probably don't want those subjects to affect the rest of the network - Cloud storage - the local download/upload for caching and working seems and issue here. Maybe I'm wrong... - Localised NAS - not sure how I feel about this, but some form of networked NAS that is physically located in the subject areas to serve their work? Open to ideas and suggestions! Obviously whatever route we go down has implications; - Cost is the biggest factor of course... - Would need to backed up, ideally in line with the rest of the infrastructure backups (currently Veeam) Cheers, Stephen
  13. Hi all, Bit of a random one. I was wanting to play with the Project Management within SharePoint/Teams. However, as we are an Education tenant, when creating a Team from a template, none of the templates actually appear - other then the specific Education ones. Guidance from Microsoft doesn't seem to explain how to get the others to appear (Get started with team templates in the Teams admin center - Microsoft Teams | Microsoft Learn) and I can't see them in the admin center either. Anyone know why or how to get these templates to appear? Someone else also having the same question: Teams Templates Missing for Education version of Teams | Microsoft Community Hub but no answer... Cheers
  14. When I asked this, I was told it wasn't possible and they don't have audit logs... which was a bit of a shocker!
  15. SC-900 please and thanks!
  16. As far as I'm aware/can tell, it's not explicitly stated, however it does state the below regarding MFA: There are four types of additional factor to consider: - a managed/enterprise device - an app on a trusted device - a physically separate token - a known or trusted account So I read that as, a "trusted network" or the like, is not considered an additional factor.
  17. Thanks both! Do you have to be existing NetSupport customers/using any other NetSupport products or can this be used standalone?
  18. Hey all, Just wondering what people are using for their lockdown alerting/communications systems please. Or any that you have used in the past and feedback! Cheers, Stephen
  19. Piggy backing on this - in a similar situation. Currently use PaperCut MF on-prem, have got one Canon with Uniflow Online (seems to work well) however the Canon copiers are more expensive than others. Be interested to hear how the PaperCut Hive + Intune is working these days; and if any of them can work with both existing on-prem AND the "new" intune devices at the same time... Cheers
  20. Jumping on the back of this (sorry OP!) - also recommendations for a supplier of touch AND non-touch displays, and potentially installer around the Surrey/Hampshire area. We have no interest or need for any specific software; however a built-in ability for Airplay/Chromecast/Miracast is appealing (depending on small print there). Currently have a mixed bag, and each time there's a failure it's a bit of a job finding what's currently available at a good price, and then negotiating the install costs. Whilst it would be great to do a massive overhaul, it's simply not practical at the moment, so some sort of relationship where we can get reduced installation costs for the "emergency" replacements and plan in regular replacements spread over the year would be amazing. Cheers
  21. Is there a way to remove that "Add shortcut to OneDrive" button? As that's caused us a few issues - people have clicked that instead of "sync" and then find they can't sync because of the shortcut, and of course they have no idea where they've saved the shortcut either...
  22. Hm maybe check with Salamander what they require admin access for in Azure/Entra? If syncing from local AD I can't see why they would - Microsoft have changed the requirements regarding MFA for admin accounts in Azure/Entra, but like I said, the Salamander account shouldn't need to have admin permissions?
  23. Yes but not synced - think this was last year? So there is an-site AD account, and then a separate, cloud-only account - but that is only used for email notifications. Assuming you're using AD Connect/Entra Connect/whatever it's been renamed to now, is that not still the case? Wondering if something else has changed either with Microsoft or Salamander that's changed the cloud account requirements?
  24. Ignore me - found my notes from the last Salamander. I did the below, as they don't require Cloud Admin access (excuse formatting): Salamander Accounts and Permissions Based on the instructions in the Salamander pre-reqs the below AD account has been created; [TABLE=width: 1] [TR] [TD] Username [/TD] [TD] Password [/TD] [TD] Location [/TD] [TD] Member of [/TD] [TD] Additional Permissions [/TD] [/TR] [TR] [TD] USERNAME [/TD] [TD] PASSWORD [/TD] [TD] OU [/TD] [TD] LOCAL AD GROUPS [/TD] [TD] Delegated Control with the following permissions: - List contents, Read all properties, Write all properties, Read permissions, Create User objects, Delete User objects Applies to: - This object and all descendant objects Delegated Control with the following permissions: - List contents, Read all properties, Read permissions, Change password, Reset password Applies to: - Descendant User Objects Set on the following OUs: - OU [/TD] [/TR] [TR] [TD] [/TD] [TD] [/TD] [TD] [/TD] [TD] [/TD] [TD] Delegated Control with the following permissions: - List contents, Read all properties, Read permissions, Create Group objects, Delete Group objects Applies to: - This object and all descendant objects Set on the following OUs: - OU Delegated Control with the following permissions: - List contents, Read all properties, Read permissions, Create Group objects, Delete Group objects Applies to: - This object and all descendant objects Set on the following OUs: - OU [/TD] [/TR] [/TABLE] In addition, the Group Policy Object "" has been created and applied, to grant the Salamander AD Account Local Administrator rights on SERVER. This is NOT synced to Azure for security purposes . The below Azure user has been created to enable a mailbox for notification emails; [TABLE=width: 1] [TR] [TD] Username [/TD] [TD] Password [/TD] [TD] License [/TD] [TD] Roles [/TD] [TD] Additional Permissions [/TD] [/TR] [TR] [TD] Salamander@DOMAIN [/TD] [TD] In Credentials [/TD] [TD] Office 365 A1 for faculty (no desktop apps required) [/TD] [TD] No additional roles required [/TD] [TD] No additional permissions required [/TD] [/TR] [/TABLE]
  25. Can't you just create a conditional access policy something like this; - User is Salamander account - Allow access: from site external IP only From memory the default is then block all other accesses for that user account Do you need to be as specific as from that server? I don't think you can specify internal IPs in conditional access Sorry if vague just quickly typing off the top of my head!
×
×
  • Create New...