munkey
Members-
Posts
38 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by munkey
-
I un shared it from the file server, so run fsmgmt.msc on the file server, under shares find the one right click and stop sharing Have a ganders as to what's under the registry location "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" to see if there are any blanks as that's where known folder locations are defined, although not sure why it's removed the path all together as I've not seen folder redirection do this. If it is blank and is happening to every machine a workaround could be a login script to set the missing registry value
-
If the users are already redirected to OD rather then onprem storage is there a need to share the onprem profiles still? - You could set NTFS permissions to read only but no-one should be accessing it if redirection is working correctly unless I'm misunderstanding it After our OD migration we just kept the file server spinning but only un-shared the user profiles location. If there was anything that failed to migrate they got in contact with IT but there wasn't a single ticket raised in the end. After a couple of terms this was captured to tape backup anyway so could be wiped from the server
-
Minecraft edu - help please
munkey replied to Scifigirl's topic in Internet Related/Filtering/Firewall
Pretty sure its a https inspection thing, do you use the WatchGuard as your filtering appliance or another service? We had to make sure inspection was disabled for the domain education.minecraft.net otherwise students couldn't download maps (none of the thumbnails loaded for the download buttons) -
Yup we used iBoss for 3 years and when there were downloads around 2gb it would fail in exactly the same way... If I recall correctly our AV (Sophos) caused havoc with it, even when the AV's web inspection features were disabled iBoss wouldn't behave right. My memory gets foggy here but I think we created a script to force kill the AV's "web protection" service upon machine boot - something to do with the WFP drivers clashing. It didn't solve everything but it tied us over until the renewal where we moved away from the product all together due to its reliability issues I'm not familiar with Defender but maybe disable it completely on a test machine?
-
Hi all, We got a batch of Windows 11 Surface Go laptops so as per routine we re-imaged them with MDT to Windows 10 Ent 22H2 and even after doing "diskpart clean", the fresh Windows 10 install comes defaulted into S mode before doing any updates etc. This is the first time I've seen S mode being forced on when using our image which has been applied on 100s of installs with no issues like this on previous batches. Has Microsoft now enforced S mode to be enabled at a hardware level or something? its very frustrating as these are take-home student devices with the MS Store is disabled so getting manual access to the machines is difficult once handed out. Thanks
-
We use the locked print functionality but no directory integration, if that's the same thing - I'll have a play with locked print disabled at some point and see how I get on. Unfortunately this is a requirement as the printers are few and far between so can be located several floors away, if there are sensitive documents being printed students could easily wonder off with it.
-
Hi All, We run a small print setup using the classic print server and GP to deploy network printers. When printing from Windows store apps (such as Photos, Snip & Sketch etc) the print queue gets jammed and the print spool files need to be manually deleted from the server so people can continue printing. I've tried updating the Ricoh PCL6 v4 drivers to the latest version and even installed directly on the machine as a test, this made no odds. I then tried installing the Ricoh print driver utility (also a Windows store app) - this didn't jam the print queue but the document failed to print all together. As far as I can tell the Windows store apps don't use the system print driver but some Microsoft generic thing which not only lacks many printing features it doesn't even work. Is there any way of making the store apps use system print drivers, or any workaround? Thanks
-
As an alternative you may be able to use AppLocker to restrict Windows packaged apps from running https://ccmexec.com/2015/08/blocking-built-in-apps-in-windows-10-using-applocker/
- 2 replies
-
- gpo
- store apps
-
(and 2 more)
Tagged with:
-
Hi, We have a bunch of Windows 10 20H2 laptops with Outlook 2016 installed and wish to make use of autodiscover to streamline the user's setup. The laptops are AAD joint (synced from on premises DC) and managed by InTune, we use Exchange online with autodiscover on the on prem desktop PCs which works a charm with almost zero interaction to get a user setup on a new email profile. On our AAD joint laptops the Outlook wizard stops at the enter in details step where autodiscover would normally kick in. Other settings worth mentioning is SSO is enabled in AAD sync settings, we have modern authentication enabled, the autodiscover domain appears to have no issues, I have placed the PreferLocalXML..xml manually. Is there anything I am overlooking? Thanks in advance
-
Airwatch and VPP to Apple schools manager migration
munkey replied to munkey's topic in Mobile Devices & Tablets
Sorry for the dumb question but just so I don't make this mistake again, in practice, how does planning for technology look? At the moment staff request devices, apps and whatever misc tech, if that involves money it needs the seal of approval from SMT, then I go do it. What should happen? -
Airwatch and VPP to Apple schools manager migration
munkey replied to munkey's topic in Mobile Devices & Tablets
Alrighty, so according to Airwatch support I had to add every existing app as a "public" app and assign it to the same groups so they are in parallel with the main app library pulled from ASM. This stops the Airwatch from issuing a remove app command - then we can seamlessly delete the old token and add the new, remove the public apps and supposedly the licences and all that jive will be the same as before the migration. Sounds OK right? But a large number of apps we still use has now been since removed from the app store or replaced with a different identifier so I cannot add them into the public apps section (or re-install them when the tokens swap over). I got a quarter way through and realised i'd have to speak to the departments to find alternatives as there were no like-for-like replacements... and that's as far as I got given everything else that's going on, excuse the rant but I'm not sure what i'm doing wrong but bringing managed iPads into school has been nothing but an absolute pain in the . -
I had something identical and it ended up being a very specific combination of software not agreeing with each other. We had iBoss plus Sophos AV plus Windows Defender going into some deadlock on login occasionally. Anything notable in the event viewer?
-
Airwatch and VPP to Apple schools manager migration
munkey replied to munkey's topic in Mobile Devices & Tablets
I'd like to move away from Airwatch as iPads are now a bane to manage - Since that's the only MDM i've used I assumed it was "the way it is" Any comments on Lightspeed/Jamf/others? -
Airwatch and VPP to Apple schools manager migration
munkey replied to munkey's topic in Mobile Devices & Tablets
I am told by their support AirWatch can only accept one VPP token. To add the new token means clearing the old one and when I do so it warns all deployed apps will be removed. We had issues when we tried to merge the apps from our two VPP accounts into AW... ended up cutting our losses and just binning one of our VPP accounts. -
Airwatch and VPP to Apple schools manager migration
munkey replied to munkey's topic in Mobile Devices & Tablets
Just though i'd throw an update out there. I ended up raising a ticket to Apple & AirWatch, turns out this is expected behavior and we need to uninstall every single app on every iPad so Apple Schools Manager "absorbs" the spare licenses, then add the new app sync token to AirWatch and re-install every single app again. Given we normally have a 30% failure rate in the uptake of apps from Airwatch resulting in the iPad being factory reset so it sounds like a job for the Christmas holidays to me after i've collected everyone's device in (ouch) -
Airwatch and VPP to Apple schools manager migration
munkey replied to munkey's topic in Mobile Devices & Tablets
Getting closer, I tried this and airwatch kicked up the error: Save Failed Uploaded sToken is not the renewed version of the old sToken There is an option to clear the current token but it warns me it will uninstall all assigned applications which is undesirable during term time. It's exact words are "Deleting the sToken will uninstall VPP applications purchased for your VPP account from all assigned devices and revoke the licenses. The applications that have been purchased using the sToken will no longer be available for assignment. Are you sure you want to continue?" - something to raise with Airwatch? Thanks -
Airwatch and VPP to Apple schools manager migration
munkey replied to munkey's topic in Mobile Devices & Tablets
Thanks for your reply, I saw that article on the other thread but I failed to see any button to transfer in the details section unless im looking in the wrong place? Here is a screenshot of what I am seeing: https://imgur.com/LHtSJk4 -
Hi All, I didn't want to hijack the thread similar to this - but we got forced to switch over to apple school manager instead of the legacy VPP site today... and now we have lost all our spare available app licenses and unable to sync any new ones. We use Airwatch MDM to manage our iPads. When Apple Schools manager I hit the move licenses button as per apple support page and renewed the VPP (legacy) token for good measure and synced assets. When re syncing our apps in Airwatch all of our spare purchased licenses has disappeared (I always purchase a few extra just in case). In ASM I can see there are X available but none spare are showing in AW. Any help is appreciated! Thanks
-
I just checked the APN token and it doesn't expire until mid this year. It's strange because a few iPads (which were enrolled on the same day) can install apps just fine. Here's a screenshot of the expiry: Edit: Here is the event logs for one of the iPads failing to install one of the apps. It seems to get stuck in a cycle of these two events. In this instance this log entry was created when I tried to manually force it to install
-
Oh dear, i'm back! (sorry) So now that users are syncing with ASM, I am now unable to deploy apps to the majority of devices! When I view the app install status from the devices list on AirWatch I get the message: Out-of-date. App assigned but not installed. I've tried pushing it out manually, rebooting devices, updating the app from AW and yet 90% of devices won't take it up even after several days. Any ideas? Thanks
-
Ah, thanks for confirming - i'm 99% sure I enabled location services on the initial setup wizard you get put through during enrollment so it's strange it has disabled itself Well, ever since the time has been corrected to not be in the past most of the iPads have pulled down their new class lists which is good news. On a quiet day I will have to check if thats reflected across all devices.
-
Yup the VPP and DEP are up to date. I spent yesterday digging around AW and found this profile signing cert https://imgur.com/a/jiAsSX2 Is this the same as the Push token? How do I ensure I am using the new rules. Will it automatically do this when I renew? On another note, I noticed the time and date are all wrong on the shared iPads which may throw the certificates off. When I look at the local settings on the iPad it is set to automatically sync however this fails if the location services is turned off which appears to be a user-specific setting so I just spent a few hours logging into each user on each shared iPad and enabling location services for it to pull down the correct time. There has to be a way to enable location services from MDM so I don't have to do this each time a new user is added?
-
Thanks for the link, I hadn't heard of Apples push cert portal before. I just checked and it seems to expire in July 29th 2020 - I think that explains the yearly issue we have! That's one to add into the calendar... It seems as if apps and such are being pushed out fine, just not the Apple School's classes and students Ju [TD="class: standard"]Jul 29, 2020
-
Hi All, A few months back we set up shared iPad trolleys (with the help on this forum!) employing AirWatch as our MDM. It was working fine for about 4-6 weeks then any changes made to students/teachers on Apple Schools (i.e. we wanted to add a new students) would not sync up with the iPads. I have synced AirWatch with Apple Schools and the changes show up in the AirWatch console but it never reaches the devices. We had issues, which is still not solved, that caused all our iPads to drop off our MDM and stop checking in around the same time every year so I went around doing a manual factory reset on every single iPad to get it to re-enroll. I really, really, don't want to do that again... I think this is a separate issue as the re-enrollment problem normally crops up during summer and the devices are still showing up as "recently seen" in AirWatch. Any ideas? Thanks!
-
I think you are spot on - I assumed students and instructors had to be owners of devices. I tested on two last week with just the instructor as the device owner and it seemed to work, so tomorrow ill try on a set of 20 and see how that goes. Cheers for your help
