garethEds Posted June 10, 2021 Posted June 10, 2021 Afternoon All, I'm wondering where next to take the network. We've had a massive LEA investment in wifi and new switches. We have Office 365 provided through the Welsh Assembly. We have a 3 server Hyperv V Cluster with a SAN - all backed up. We are (almost) fully Windows 10 with just a few left to move over. What's next? What cool or essential things are you all doing on your networks to keep it developing? To keep it moving forward? I've looked at AppV and LAPS but do I need them? Not sure about AppV - cannot see the point. Or shall I just leave it all alone and love the easy life? Gareth
Mako Posted June 10, 2021 Posted June 10, 2021 Enjoy the easy life, then tell us all what it feels like.
LukeRowberry Posted June 10, 2021 Posted June 10, 2021 (edited) I'd say AppLocker rather than AppV and LAPS are both essential these days. Also if you are not fully W10 yet then maybe looking at your deployment solution might be a good development. I'd like to think most would just change the iso for every release and then pxe the deployment these days. Also I assume from your post your 365 is through HWB - they have Intune/Endpoint Manager available now so that might be a good option. Edited June 10, 2021 by LukeRowberry
mavhc Posted June 10, 2021 Posted June 10, 2021 Now you aim to not be the slower of the 2 friends trying to outrun the ransomware bear. Can I delete your backups without being on site? If I get 1 person's password how much stuff can I access? If there's an unpatched flaw in a device on your network how much power can I obtain? Assume your network is already hacked, what damage can someone do?
garethEds Posted June 10, 2021 Author Posted June 10, 2021 Enjoy the easy life, then tell us all what it feels like. Love it.
garethEds Posted June 10, 2021 Author Posted June 10, 2021 OKies - never looked at that. What sort of things are you blocking? Our deployment solution is fine - we use one ISO with targeted drivers and then PDQDeploy to fire things out depending on rules in PDQInventory. Cheers Luke - appreciate the effort to suggest AppLocker.
garethEds Posted June 10, 2021 Author Posted June 10, 2021 Now you aim to not be the slower of the 2 friends trying to outrun the ransomware bear. Can I delete your backups without being on site? If I get 1 person's password how much stuff can I access? If there's an unpatched flaw in a device on your network how much power can I obtain? Assume your network is already hacked, what damage can someone do? Cheers @mavhc - great suggestions here for me. Added to the list. Gareth
supportman Posted June 10, 2021 Posted June 10, 2021 Afternoon All, I'm wondering where next to take the network. We've had a massive LEA investment in wifi and new switches. We have Office 365 provided through the Welsh Assembly. We have a 3 server Hyperv V Cluster with a SAN - all backed up. We are (almost) fully Windows 10 with just a few left to move over. What's next? What cool or essential things are you all doing on your networks to keep it developing? To keep it moving forward? I've looked at AppV and LAPS but do I need them? Not sure about AppV - cannot see the point. Or shall I just leave it all alone and love the easy life? Gareth Get rid of the SAN and go cloud storage.
jthompson Posted June 10, 2021 Posted June 10, 2021 What's next? I'm going to be boring and say... documentation. 2
TriggerHappyUK Posted June 10, 2021 Posted June 10, 2021 A little list to look at: Managed Printing - Papercut Managed Classroom - Impero Remote connection - Direct Access / Always On VPN Image Deployment - MDT/WDS Onesite/Offsite backups - Veeam Physical Network Access - 802.1x Door Access - Maglock Areas & Computer rooms using GARDiS Online Parents Evening - SchoolCloud Mac Deployment - Jamf Digital Signage - Raspberry Pis and RiseVision MIS Integration - Salamander Web Filtering - Smoothwall IWB - Smart screens instead of Projectors & IWB Teacher computers - Dell USBC docking stations (Dell Latitude 3400 series laptops) CCTV - Dahua cameras Will add more to the list as I think of it :-)
Jcx500 Posted June 10, 2021 Posted June 10, 2021 Deffo make sure your backups are the best you can make of them, especially with how Education is being targeted recently. Would do some documentation on regular backup tests etc
MatthewL Posted June 10, 2021 Posted June 10, 2021 Printing, classroom management tool, device management such as Desktop Central to assist in updating machines etc, a service desk portal, backups, door access would be a few I would be looking at for starters.
gmonks Posted June 11, 2021 Posted June 11, 2021 As others have said, backups. I would try to do a restore from scratch using your backups and make sure they truly work. Ensure MFA is enabled for all staff. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now