Jump to content

Recommended Posts

Posted

Afternoon All,

 

I'm wondering where next to take the network. We've had a massive LEA investment in wifi and new switches. We have Office 365 provided through the Welsh Assembly. We have a 3 server Hyperv V Cluster with a SAN - all backed up.

 

We are (almost) fully Windows 10 with just a few left to move over.

 

What's next? What cool or essential things are you all doing on your networks to keep it developing? To keep it moving forward? I've looked at AppV and LAPS but do I need them? Not sure about AppV - cannot see the point.

 

Or shall I just leave it all alone and love the easy life?

 

Gareth

Posted (edited)
I'd say AppLocker rather than AppV and LAPS are both essential these days. Also if you are not fully W10 yet then maybe looking at your deployment solution might be a good development. I'd like to think most would just change the iso for every release and then pxe the deployment these days. Also I assume from your post your 365 is through HWB - they have Intune/Endpoint Manager available now so that might be a good option. Edited by LukeRowberry
Posted

Now you aim to not be the slower of the 2 friends trying to outrun the ransomware bear.

 

Can I delete your backups without being on site?

 

If I get 1 person's password how much stuff can I access?

 

If there's an unpatched flaw in a device on your network how much power can I obtain?

 

Assume your network is already hacked, what damage can someone do?

Posted

OKies - never looked at that. What sort of things are you blocking?

 

Our deployment solution is fine - we use one ISO with targeted drivers and then PDQDeploy to fire things out depending on rules in PDQInventory.

 

Cheers Luke - appreciate the effort to suggest AppLocker.

Posted
Now you aim to not be the slower of the 2 friends trying to outrun the ransomware bear.

Can I delete your backups without being on site?

If I get 1 person's password how much stuff can I access?

If there's an unpatched flaw in a device on your network how much power can I obtain?

Assume your network is already hacked, what damage can someone do?

 

Cheers @mavhc - great suggestions here for me. Added to the list.

 

Gareth

Posted
Afternoon All,

 

I'm wondering where next to take the network. We've had a massive LEA investment in wifi and new switches. We have Office 365 provided through the Welsh Assembly. We have a 3 server Hyperv V Cluster with a SAN - all backed up.

 

We are (almost) fully Windows 10 with just a few left to move over.

 

What's next? What cool or essential things are you all doing on your networks to keep it developing? To keep it moving forward? I've looked at AppV and LAPS but do I need them? Not sure about AppV - cannot see the point.

 

Or shall I just leave it all alone and love the easy life?

 

Gareth

 

Get rid of the SAN and go cloud storage.

Posted

A little list to look at:

 

Managed Printing - Papercut

Managed Classroom - Impero

Remote connection - Direct Access / Always On VPN

Image Deployment - MDT/WDS

Onesite/Offsite backups - Veeam

Physical Network Access - 802.1x

Door Access - Maglock Areas & Computer rooms using GARDiS

Online Parents Evening - SchoolCloud

Mac Deployment - Jamf

Digital Signage - Raspberry Pis and RiseVision

MIS Integration - Salamander

Web Filtering - Smoothwall

IWB - Smart screens instead of Projectors & IWB

Teacher computers - Dell USBC docking stations (Dell Latitude 3400 series laptops)

CCTV - Dahua cameras

 

Will add more to the list as I think of it :-)

Posted

Deffo make sure your backups are the best you can make of them, especially with how Education is being targeted recently.

 

Would do some documentation on regular backup tests etc

Posted
Printing, classroom management tool, device management such as Desktop Central to assist in updating machines etc, a service desk portal, backups, door access would be a few I would be looking at for starters.
Posted

As others have said, backups. I would try to do a restore from scratch using your backups and make sure they truly work.

 

Ensure MFA is enabled for all staff.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...