Jump to content

Recommended Posts

Posted

Hi All,

After a bit of advice please.

I've started a new role today to replace the previous IT Tech who retired in an RM school. As there was a gap between leaving and starting there's been no handover of information from the previous IT Tech to myself at all.

Anybody got any tips or info, best practices etc on how to proceed?

Thanks

Posted
I would get backup copies of key set ups and key data immediately. Don’t just run whatever they ran, you take it using tools you know. I’d then walk the place and document every switch, router and printer. Start to build a list of issues from users but set their expectations. Low. Study what triage means and adopt it with head and chair of governors support
  • Thanks 1
Posted (edited)

We've taken over schools like this.

 

Does the school need and have the budget for new servers or are you running VMs? If so, now is a good time to start unpicking things and migrating stuff over (to the way you'd like it). Even if you just do it slowly, as needed. Try not to enforce too many changes on users at once though, particularly as you're new (they'll blame you because they can't do things the same way they're used to doing!).

 

Get a phone number or e-mail contact for the last tech if you can. You'll need it someday. We thought we were flying at one school; we had the password list, and were making gradual changes as we unpicked things (which is all you can do sometimes), then suddenly ran into the Trust Relationship issue on a PC and realised we didn't have the local admin account for that machine, and it just refused to play with the usual "unplugging it from the network and using the domain admin account" solution). That was a long day! (for what's usually a 2 minute fix, very annoying!).

 

The priority is probably checking backups/disaster recovery. Don't assume it all works if you didn't set it up yourself. Do a full test on a backup set, and double check everything needed is being backed up (and that you have things like the correct decryption password/key, etc).

 

Talking of which, go through the password list and check everything (assuming you have one).

 

If you can't get hold of the former admin I'd start resetting things now. Things like 2-factor authentication for Google Apps/Office 365/Apple School manager, etc can be a right pain to reset (I think, from memory, Google takes 4 weeks to reset 2FA for the admin account. Apple usually contact the school directly to make sure you have their approval, and that can take a good week). It's better doing stuff like that now rather than when you actually need them!

 

If none of the network cables are labelled (grrr! Who in the hell does this???) you can buy cable testers with remote identifiers (you plug in all the identifiers on one end of the network, take the tester to the other end, and it will tell you which identifier is on the end of each cable). Again, do this when you get time, you'll appreciate the effort you put in when something goes wrong and you need to trace a cable back.

 

I'm sure more will come to me when I think about it!

Edited by Cazale
  • Thanks 1
Posted
Every other place I've worked has had some kind of knowledgebase setup already or something in place to at least read even it was was just a simple word doc! So far today I've got nothing - zero information - about the servers, backup, Internet connection etc. Bit shocking to be honest!
Posted

The last thing I would do is start getting new kit. Survey what you have, how well it works and develop a multi year plan with SLT.

 

Do you have admin credentials for key stuff? Pretty major. Remove / reset old admin accounts.

 

But most of all id talk to staff. Developing a positive relationship will help you long term.

  • Thanks 2
Posted

Thanks for the suggestions folks - much appreciated! :)

 

Had a few meetings with RM who do actually support some of the equipment and setup. But still finding out about things. Not impressed about no handover and documentation though. :ohwell:

Posted

Documentation is often wrong anyway, the only truth is what's running.

 

It's fun to crack your own machines, hashcat is great, find all the security problems as you go, fix them, and then get a side job as a pentester.

 

The most annoying one to sort out is who has the password to the website hosting, easy to check dns to find out where it's running, but easier to follow the money

Posted
Make sure SLT understand the that you can't work miracles. By failing to oversee a proper handover they have been negligent - possibly because they don't understand the issues involved. An Audit needs to be done asap. Ages, dates, versions of servers and client PCs, switches and wireless. Windows 7 and 2008R2 support ends at the end of 2019 - which means you need to have a plan in place to replace any of those - probably over next summer. I'd be working with RM - at least in the short term. I know they get a lot of bad press (and I'm responsible for some of it)...but their CC4 product is a good one (even if it did have troubles in the early days). Its worth at least half a technician. Don't try to manage an RM network by using AD and GPOs. This is often a serious mistake made by network managers who don't understand how RM works - and then get really frustrated with GPO and script changes don't deliver what they expect - and they blame it on RM. RM is a safe, solid product.....yes with irritating limitations.
Posted

I think a few of us have been there, including me a few times. It is easy to get buried in the thick of doing day to day jobs but I think you need to make clear to SMT that you should have some time to map out the network and get to know what servers do, network links, WiFi setup, etc. You are not getting anyone in trouble but you may not know any history between the previous tech and the org. Documentation is a time consiming excersize and unless it is updated not very usefull.

 

Additionally It would be pointless to make any purchase decisions without having some sort of insight of the infrastructure and getting some sort of business case/need together especially in these budget aware times.

Posted
The one purchasing decision that might be worth taking today it is a hosted backup service. Or at least reviewing the last successful backup and at the very least get a NAS to backup to.
Posted
Yes backups are "ESSENTIAL"...probably the only essential thing. More important than having any working service (but that won't be understood by management) Losing records, and data would be - well a sackable offence in my books. Windows server backup (you have to "add it" but you don't need install disks) - works fine - well better than fine really. In fact so well I'm not sure anyone justifies the cost of other backup solutions....and together with a couple of large 8 to 10TB hard disks with a USB to SATA connector.
Posted

I had this at my last school - the previous tech had died suddenly! Then the LEA took over but wouldn't talk to me for several weeks

 

Not even any passwords for anything - fortunately a lot of the PCs logged on automatically

after a few weeks the office staff had to ring up the LEA due to a problem with SIMMS and got hold of someone who had been out to the school once - he dropped a sealed envelope off that evening with the server admin password in it!

I was just about to drop the server to crack the password.

 

As a result I always had every password etc etc written down in a safe place

 

Then when I left I was a bit shocked that the school ignored my advise to put a support contract in place before I left and arrange a handover

When I left they said the intended to look at sorting something out next term

SO I wrote everything down that I could think of - I do wonder if anyone remembered about the green book with the passwords in though.

 

So it still happens - symptom of the lack of importance SMT put on IT staff - until something goes wrong.

  • Thanks 1
Posted

I was exactly in the same position as you.

 

You need to begin by familiarising yourself with the network, try and find out how things are connected, who has access to what, and what services you have/contracts with outside agencies, eg. backup.

 

youll probably find naming schemes, passwords, etc are all over the place so start slowly and begin to do things logically.

We had different users with different login usernames, eg surname.firstname, just their firstname, etc.

Try and get things the same accross the site.

 

Dont try and force everyone to change overnight. It wont happen.

 

Do however spot whats wrong and what needs changing and gradually make it happen.

  • Thanks 1
  • 5 weeks later...
Posted

Thanks for all the tips and advice folks.

 

It's still annoying to have had no handover and this has been the root cause of a lot of the problems I've come across - there's literally ZERO documentation on anything. It's literally as if it was the first day of the business, every day.

 

I've been in touch with some suppliers, some vendors, RM etc and getting round things now. There's still a lot of fire-fighting to do however at the moment!

Posted

...which all goes to show that its REALLY important to document the system(s) you are working at....so that if something happens..

 

Ideally your current school should make this one of your priority tasks....

Posted

With each handover I've had to do, the bare minimum had a network map, a list of all username and passwords the new NA would need and details of what each server did + IP addresses.

And a run down of things like backup strategies + any gotchas and work-arounds you had to put in place.

Obviously you can't list every single detail, but this kind of thing helps greatly I find.

I once took over a network where all I got was a list of possible admin passwords and their combinations!

Posted
Think its worth asking for an extra "fee" arranged at the job application to be paid if there is not sufficient documentation to make the hand over reasonably easy.
Posted

Unless there is a valid excuse (like a death) then moving from one IT support to another org. (e.g. a new tech starting or moving from inhouse to a contract witha company) should always include some time for a personal handover. There are always things that are better passed over between 2 reasonable people than in writing.

 

WHich is why I was really annoyed that my last school only started thinking about IT support to replace me the term AFTER I left

I did my hand over to the Deputy Head - who stopped me at several points as he had no clue what I was on about.

Posted
Yep, management generally don't have a clue about IT issues. Its just switch on an go. If it doesn't go buy another one. Comes as a real shock when they discover exactly how much as to be maintained to deliver the services that just seem automatic to them.
  • Thanks 1
  • 2 weeks later...
Posted

I was (AM) in a similar situation as yourself - I have done my best to try and collate and audit what we have here after 6 months (1 month lead tech was sick and 1 month I was off long-term sick). The "documentation" I had were just screenshots of login screens minus login information etc and equipment audits were undated and unchecked, so I had no idea if I was reviewing spreadsheets with already changed data - making the task tedious and fruitless on many occasions.

 

Also this is my first gig as Network Manager/Senior network tech - I have just been mostly 2nd line desktop support over the past 18 years and have fingers-in-all-pies so to speak. They have RM here which I wasnt told about when I asked at interview so feel like a complete newbie everyday.

 

Just plodding on until I figure out what to do or they get rid of me lol!

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...