Showing posts with label LENOVO. Show all posts
Showing posts with label LENOVO. Show all posts

Thursday, July 7, 2016

Lessons learned from WMUG and SCUG last month (part 2)

Last month (June 2016) I went to both Windows Management User Group (WMUG) and System Center User Group (SCUG). Both with great sessions and speakers. On WMUG both Mirko Colemberg and Mike Terrill were speaking. On SCUG I listen to Pieter Wigleven, Stefan van der Wiele, Mirko Colemberg and Peter Daalmans. Let's have a look at some notes taken.
 
SCUG #1 (Pieter Wigleven)
-Windows 10 enrollment options: Join devices to Azure AD, Password reset, Require multi-factor, Sync settings, Application proxy
-Apps like Twitter (for example) can be installed automatically
-Windows Information Protection policies within Intune standalone (AKA Enterprise Data Protection)
-Edition upgrade policy Pro > Enterprise (or the other way around) with a provisioning package

-Wi-Fi profile and Defender block (within Intune policy)
-Use
myapps.microsoft.com (access panel) for additional apps (with SSO support)
-Deploy Line-Of-Business (LOB) apps via Microsoft Business store
-Add x86 software to Microsoft Business store (future usage)

-When using BitLocker encryption policies, the recovery password will be kept in Azure too.
-No Direct Access support in Azure till now, but Auto-VPN instead.

SCUG #2 (Mirko Colemberg)
-Session on Microsoft Advanced Threat Analytics (ATA) and Windows Defender Advanced Threat Protection (ATP)
-Story (ATA): 200+ days. That's the average amount of time that attackers reside within your network until they are detected, gathering classified data and information, waiting to strike at just the right moment. Microsoft ATA helps you identify breaches and threats using behavioral analysis and provides a clear, actionable report on a simple attack timeline.

-Story (ATP): Protecting our enterprise customers has never been more challenging. Security threats are increasingly brazen and highly sophisticated. A new Windows 10 service that helps our customers to detect, investigate and respond to targeted and advanced attacks on their network.
-Source: Microsoft ATA & Microsoft ATP
-Microsoft ATA is only for information, not for protection. Maybe it will be combined with Defender in future.
-Windows Defender ATP policies will be in SCCM (next build), but is not in Intune available at the moment.

SCUG #3 (Peter Daalmans)
-Start with ConfigMgr 1511 during clean install or upgrade. Don't use build 1602 for this. Possible but not recommended!
-Since ConfigMgr Technical Preview (1511) there was an update every month (with new features)! Very good job Microsoft.
-New ConfigMgr Current Branch builds needs to be installed within a year, to be supported. No LTSB version available.
-Use the service connection tool for new ConfigMgr builds, when in offline mode or behind a proxy. Cool stuff! >
Microsoft
-After 1602 it's not possible to upgrade or install newer builds directly. It will break ConfigMgr and missing features!


More on Servicing here: Promote the ConfigMgr client in Current Branch (1602)

More about WMUG and SCUG sessions HERE.

Monday, July 4, 2016

Lessons learned from WMUG and SCUG last month (part 1)

Last month (June 2016) I went to both Windows Management User Group (WMUG) and System Center User Group (SCUG). Both with great sessions and speakers. On WMUG both Mirko Colemberg and Mike Terrill were speaking. On SCUG I listen to Pieter Wigleven, Stefan van der Wiele, Mirko Colemberg and Peter Daalmans. Let's have a look at some notes taken.

WMUG #1 (Mirko Colemberg)
-Integrate Windows Store for Business (WSfB) in ConfigMgr 1605TP or 1606 directly. Just advertise them within ConfigMgr directly.
-Assign to users or user groups? Also for user groups! (WSfB)
-Wsreset.exe = reset the store (when it's malfunction)
-You can drawback apps too! Then the user cannot open the app anymore.
-Block Windows 10 Public Store using Microsoft Intune (but still allow the business store) > Microsoft
-Integration in MS Intune available, all apps are visible there too! Just advertise them within MS Intune directly.
-Use developer.microsoft.com for creating LOB apps yourself.
-Some Windows 10 apps are for Mobile usage only, others for Desktops usage.
-Apps can be used online and (sometimes) offline. It depends..
-Use PowerShell for adding APPX packages, not the CM or Intune wizard.


More on WSfB here: Using the new Windows Store for Business for apps on Windows devices

WMUG #2 (Mike Terrill)
-Using Resource Explorer to watch BIOS and UEFI information on Dell, HP and Lenovo systems.
-For Windows 10 Redstone you need ConfigMgr Current Branch, not 2012 (R2) anymore (because not supported)
-Using 1507 (RTM) or 1511 boot images? Hotfix needed for 1511, so better use the 1507 bits.
-Upgrade BIOS versions during task sequence possible! Need to test this myself first, and report later.
-Download package content > task sequence working directory (for reference packages)
-Dell systems: Use Dell Client Configuration Utility > Download
-HP systems: Use HP BIOS Configuration Utility > Download
-Lenovo systems: Use BIOS Deployment Guide > Download
-New dynamic variables available within ConfigMgr builds
-Using 1E’s Free Tools > Download

More on UEFI here: Choosing between BIOS (Legacy) or UEFI during deployment

Stay tuned for more information in a next blogpost!

Friday, February 7, 2014

How to import Lenovo drivers in ConfigMgr easily

Good news! When you are using MDT and/or SCCM/ConfigMgr and want to create driver packages, you can download them for Dell, HP and Lenovo systems. That saves a lot of time, because to need to download every single driver available. Let's have a look at the different methods for companies. More about that here: Download Driver packages for Dell, HP and Lenovo systems

When looking for Lenovo driver packages, there are a lot of models missing. You can browse the Lenovo website, download each individual driver, extract the driver and import them into ConfigMgr, but this must be done for every model then. Looking on the internet I found the following blogpost: Getting Lenovo drivers into SCCM – The easy way

It mentions using the Lenovo Update Retriever (download) and a VBS script to get the job done. That way every single driver per model can be downloaded at once. The script is extracting all drivers to a different location so drivers can be imported in ConfigMgr easily afterwards. The VBS script needs some modification on a few values, but works perfectly. Really easy this way!

The order for ConfigMgr integration will be:
1. Download (Lenovo Update Retriever)
2. VBS script (copy from website)
3. Import drivers in ConfigMgr
4. Create driver packages in ConfigMgr

That's all for now. Hope it helps!

Monday, December 9, 2013

Download Driver packages for Dell, HP and Lenovo systems

Good news! When you are using MDT and/or SCCM/ConfigMgr and want to create driver packages, you can download them for Dell, HP and Lenovo systems. That saves a lot of time, because to need to download every single driver available. Let's have a look at the different methods for companies.

Dell has a website available for Driver CAB files for Enterprise Client OS Deployment. This can be used for WinPE (5.0 also!), XPS systems, Venue systems, Latitude systems, Optiplex systems and Precision systems. There are also combo packs available. They can be found here: http://en.community.dell.com/techcenter/enterprise-client/w/wiki/2065.dell-driver-cab-files-for-enterprise-client-os-deployment.aspx
Just use "Dell Client Integration Pack" to import Driver CAB files in a easy way: http://en.community.dell.com/techcenter/os-applications/w/wiki/2565.dell-client-integration-pack.aspx

HP takes the next step and provides ready-made driver packages for MDT and SCCM for the business models of notebooks, desktops and workstations. The packages can be obtained via SoftPaq Download Manager (SDM) or from the HP support website. It appears they are primarily for the current generation of products. To get the download manager, navigate to the HP manageability website: www.hp.com/go/easydeploy or directly to www.hp.com/go/sdm

Lenovo has a website available for "Microsoft SCCM and MDT Package Index". This can be used for ThinkCentre systems, ThinkStation systems and ThinkPad systems. Packages provide the device drivers in .inf form for, in order to allow you to deploy Windows images with SCCM by importing the device drivers. These driver packs are also supported with MDT. They can be found here: http://support.lenovo.com/en_US/downloads/detail.page?DocID=HT074984

Really great to see that known vendors has support for MDT and/or SCCM/ConfigMgr now!


Update: HP Client Integration Kit for ConfigMgr 2012 R2