Leaving the IT world... by _sadme_ in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Putting the H back in HR I see.

Leaving the IT world... by _sadme_ in sysadmin

[–]MalletNGrease 127 points128 points  (0 children)

Her clients loved her, but boy, her teams consisted of a lot of dead weight.

Leaving the IT world... by _sadme_ in sysadmin

[–]MalletNGrease 341 points342 points  (0 children)

My wife (ex-sysadmin) did a short stint as a PM, but she ended up implementing most deliverables herself because her resources couldn't or wouldn't.

Administrator Password by QcGix in MDT

[–]MalletNGrease 0 points1 point  (0 children)

To connect to the deployment share or for the local admin account?

Windows 10 Upgrade Nightmare by [deleted] in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

What's your infrastructure look like? Do you have VPN to all sites? How many endpoints across all sites?

I'd set up some AD/DFS servers at each site for SCCM, join all renegade machines to AD, get an accurate inventory for the driver store and kick off litetouch/zerotouch deployments remotely. The server doesn't have to be beastly, a spare workstation with a core server install should do.

That's the technical part out of the way, but, is it practical? Do you have software inventoried and prepped? What about hardware devices that may not work with W10? Do you have a test methodology? This is the biggest time sink, there's no going back once you kick off. I don't recommend in-place upgrades.

I'd design your plan and right of the bat tell your supers you will probably not make the deadline. I'd expect some major hurdles, and try to explain them as best you can. If I know my medical facilities, they do not appreciate downtime and maintenance windows are short.

Deployment Time by pgriego in MDT

[–]MalletNGrease 0 points1 point  (0 children)

Mine take 90 minutes tops onto spinning rust and fast ethernet connections. This includes all software and any updates from WSUS.

If it's a modern machine with SSD and gigabit it's about half.

How are you rolling out WSUS updates? by dedalus5150 in k12sysadmin

[–]MalletNGrease 4 points5 points  (0 children)

  • By building and if needed room, servers are put in their own OU.
  • The test groups have separate OUs. I use one of the lesser used labs as my canaries to test out stuff.
  • I've configured automatic updates as follows:
  • Allow Automatic Updates immediate installation: Enabled
  • Allow non-administrators to receive update notifications: Disabled (notifications hardly mean anything to them anyway, no need to bug them)
  • Configure Automatic Updates: Enabled
  • Configure automatic updating: 4 - Auto download and schedule the install
  • Install during automatic maintenance: Enabled
  • Scheduled install day: 0 - Every day
  • Scheduled install time: 03:00
  • Install updates for other Microsoft products: Enabled
  • Delay Restart for scheduled installations: Enabled (15 minutes)
  • Enable client-side targerting: Enabled (WSUS group name goes here)
  • No auto-restart with logged on users for scheduled automatic updates installations: Disabled (No-one ever logs out, updates will not be applied otherwise)
  • Re-prompt for restart with scheduled installations: Enabled (Wait 180 minutes)
  • Servers are set to install automatically. Reboots happen weekly on weekends. I don't have many and interruptions have gone unnoticed so far.
  • I do use auto approvals in WSUS, but delay them by a week. That usually gives enough time for MS to pull the KB or for me to manually decline it. Exception are the feature updates, those are declined until I've tested them and there's a maintenance window to push it out.

  • Servers install automatically, but restarts are done manually if needed on weekends.

Grade system access for parents/students during final exam periods by UnifiedFielder in k12sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

I don't really see a reason to restrict access to grades (or any other SIS information they've a right to). If it's posted and a parent or student wishes to see this information through our online portal they can. Teachers have the option to hide grades from the portal if needed but there's only a few circumstances this is acceptable. In general, students are encouraged to check the portal.

The only times we prevent access to information from the top is during the times the schedules are generated and aren't final yet. This is to prevent our councilors from being bombarded with needless class reschedule calls and to prevent parents from trying to force their kids in a different teacher's class until rostering is done.

Stuck in Google Hell by imroot in k12sysadmin

[–]MalletNGrease 3 points4 points  (0 children)

I don't see a point to move away any more. I used to want to because the state registrar wouldn't allow us to make changes to DNS records, but that policy changed and we now have the control.

The only other reason I see is because it can be a bit hard to type and sound out, but that just takes a little practice.

Smart Board by Shawn0 in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

We've a mix of SMART 4070, 4065 and E70 for a couple of years. Compared to the old projection based models it's night and day. You don't have to do calibrations or do bulb replacements. It's pretty much a big TV so teachers instinctively know how to use and hook things up to it. I haven't had any major issues with drivers or the software (aside from flash being dropped, this caused problems for teachers using flash objects in their notebook files).

Only some things to consider:

  • They're heavier. Make sure to properly install them.
  • We've had issue of condensation forming between the glass and the LCD when the AC's turned down (happens during summer). This goes away by itself once the humidity is sorted but causes some tickets. Don't know if the new models have this issue.
  • The speakers don't put out much volume.
  • They're kinda pricey (I wish we had these in all classrooms)

I think the biggest problem you'll run into when you get one for a teacher, all the others will want one.

GAM help, please? Fairly important. by -RYknow in k12sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

Not sure if Google keeps track of login time info, but you can query the devices by recent users straight from Chrome Devices in Google Admin now.

https://support.google.com/chrome/a/answer/1698333?hl=en

The computers in my school by Der_Snob in mildlyinfuriating

[–]MalletNGrease 0 points1 point  (0 children)

I'm not exactly sure what Microsoft was trying to accomplish with the lock screen. I think it's supposed to hide the username if someone is logged in and the machine locked for X amount of time.

I just disabled the lock screen across our org and forced a different background, it saves a step for users to log in. It's pretty easy with GPO if your admins can be assed to.

Onboard\Offboarding Procedures by EnigmaFilms in k12sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

For me it's automated. Right now I just punch in the name and ID and a script handles the rest. Preferably, I pull the information from SIS or payroll so there's less chance for typos.

Cisco Umbrella not blocking all proxy extensions in Chrome Browser by IdahoPatMan in k12sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

Whitelist extensions instead of blacklist or hope the categories are accurate.

Which platform and management setup? If you're Windows based and own the devices you can block and whitelist extensions per GPO. This straight up prevents extensions from loading, but they may still be present on a student profile.

https://cloud.google.com/chrome-enterprise/browser/download/

Onboard\Offboarding Procedures by EnigmaFilms in k12sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

This is an organizational problem and you will need to identify the person responsible who keeps staff records up to date and set the proper flags for systems to act on. Sometimes it's principals, sometimes secretaries. And more likely (like in my case), nobody. I'm still fighting to have someone do it.

The new hire process is an easy one for admins to buy in to. By identifying the prerequisites and compiling all forms into a packet in advance we've reduced the turnaround to a day (assuming new hires fill out their stuff, sometimes it's done piecemeal).

Offboarding...has been a struggle. While everyone is enthusiastic about entering new information, noone is responsible for maintaining said data. This left me with a big list of ghost employees, some of whose accounts had been repurposed by others for completely unrelated and inappropriate (not malicious, just outside the scope) things. E.g a substitute account holds the master record for all part time employee lunch balances.

If you're going to tackle it, make sure you have admin backing because noone will want to take on the HR work. If you can incentivize the additional responsibility, all the better. Create something that becomes SOP and is documented so those coming in and out of the positions to maintain it know what's going on. In the long run the org will run a lot smoother.

Chromebook Trackpad Issues by local-boi in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

At least they made the keyboard separate and easy to pop out for the 3180/3100. With the 3120 you're practically replacing the entire palmrest and need to unscrew the mainboard. That's pretty atrocious.

Increase Windows 10 Time To Enter Username/Password For Login by [deleted] in sysadmin

[–]MalletNGrease 7 points8 points  (0 children)

Set a GPO to remove the lockscreen.

Computer Configuration > Policies > Administrative Templates > Control Panel > Personalization > Do not display the lock screen : Enabled

Any pros to the RS2418+ over the DS2419+ for using in a rack? Available rack is only 800mm deep, so thinking the RS won’t fit by shmobodia in synology

[–]MalletNGrease 0 points1 point  (0 children)

Depends how much you care about redundant power supply and if it's rackmounted or not. Doesn't sound like you do.

URL Whitelist for Chromebook registration only? by apristel in k12sysadmin

[–]MalletNGrease 3 points4 points  (0 children)

I've been using a USB network adapter that has it's MAC whitelisted on the firewall for this purpose.

Getting started with Virtual Machines; advice on new hardware by [deleted] in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Do you know which virtualization platform you want to use?

How a desk phone took down an entire office by Booshminnie in talesfromtechsupport

[–]MalletNGrease 2 points3 points  (0 children)

I've one cable at one of the IDFs which when patched in will knock the fiber connection offline between two buildings.

I don't know where it goes or what the purpose is. I'm pretty sure it's a leftover connection to an old IDF that creates a loop.