Jump to content

Recommended Posts

Posted (edited)

Glad to find this forum, hoping lots of helpful people will be able to provide me with some knowledge and insight into managing IT. I'm working as an IT Technician in a Special School, as the only IT person in the building I am effectively the IT Lead (managed by the SBM). I'm hoping to get some understanding of best practices, documentation and general tips and tricks for working in the industry.

 

I'm sure many threads like this exist, so please feel free to point me in that direction too.

 

What documentation is a must have? I have created a Network diagram and simple diagrams of our data cabinets - should I be keeping anything else well documented?

I have old documents of Computer set-ups, which is essentially a tick-list of applications to install, is there a better way of doing this?

 

We are a Microsoft school, currently still on-prem AD but moving to the cloud is our next steps.

We use Office 365 for email and office licensing, how do you manage users that have left? Do we have an obligation to keep emails for a certain period (or is this based on our schools/LAs policies)?

 

Any tips. tricks or thoughts would be appreciated, trying to expand my knowledge and bring the school up to speed in the IT world.

 

Edit: Also, any worthwhile training courses that you can recommend would be helpful.

Edited by carlin_w
  • Thanks 1
Posted

I'd say you've already done the best thing you can by signing up here! There are already some members who work in Special Schools.

 

The DfE recently updated some guidelines: http://www.edugeek.net/forums/security/229855-dfe-standards-published.html

 

I'd say MDT/WDS for installations. BUT if you are only doing the odd machine it may be overkill. That said, I have got it set up at all three of my sites even though only one uses it regularly - mainly as it's quick and familiar (once set up and you get to know it). Depending on the existing setup you might find using Group Policy to install software worth looking (if you don't already) into as you will be able to update without visiting machines.

 

I personally lock leavers, but have never got a good answer on how long to keep the accounts from SMT. So this answer will also subscribe me in case someone has the definitive answer!

Posted (edited)

What documentation is a must have? I have created a Network diagram and simple diagrams of our data cabinets - should I be keeping anything else well documented?

I have old documents of Computer set-ups, which is essentially a tick-list of applications to install, is there a better way of doing this?

 

Document the network at a level such that a suitably technical person could (should you win the lottery) step into your shoes with minimal faff.

 

Then add the bits that @carlin_w from the future will appreciate that you've written down as it's 6 months since they last touched it.

 

Lots of people like OneNote for personal notes, I prefer a wiki (dokuwiki is what we use, there are others). The important thing is that the documentation exists in N+1 places and (should you win the lottery) someone else knows it exists.

 

I tend to have a page per device / application / service. Include what it does, dependencies (things that depend on it working, things that it depends on), serials, support contacts, configuration and datestamped changes (not so much "installed October patches", more "changed configuration from X to Y as per ticket #1234")

 

We use Office 365 for email and office licensing, how do you manage users that have left? Do we have an obligation to keep emails for a certain period (or is this based on our schools/LAs policies)?

 

We follow the retention policy (disable account, add alias to appropriate mailbox (depending on role), retain for 180 days for staff).

 

Your school should have a retention and destruction policy that details how long you keep certain data and why (often linked to specific legislation, DfE best practices or school policies). Bear in mind your retention limits should be reasonable (short version, a judge can say "nope, you can't delete emails after 2 weeks even if your policy says you can"). There are templates out there - the IRMS Records Management Toolkit for Schools is a good starting point: https://irms.org.uk/page/SchoolsToolkit.

Edited by pete
  • Thanks 3
Posted (edited)

Have important account details in a password manager, with details of how that can be accessed sealed in an envelope and stored in a safe. That's the school's break-glass option in case you become suddenly unavailable.

 

Have your documentation available independently of any other school systems. If the AD domain becomes unavailable, you'll still want to have ready access to your documentation. We use DokuWiki, hosted online and entirely separate from our other systems (and not reliant on any single sign-on).

 

In terms of useful things to document, perhaps document any workflows for things like new user provisioning, name changes and staff leaver deprovisioning. Even if you automate stuff as much as possible, there may still be some manual tasks associated with those things. I've also found it useful to document all the various tasks that need doing at the beginning of a new academic year, since there are lots of different things to do and you'll never remember them all from one year to the next. They might also change slightly from one year to the next, so tweak your documentation as you go.

Edited by jthompson
Posted

Backup, backups, backups!

And ensure they work once done. Often overlooked, right up until the point you need them.

As @Areku posted, you do need a distaster recover plan and ensure your bosses know about this and what it entails for when it is needed.

Some decent network monitoring is also a nice to have, there are plenty of free and paid for (supported) systems out there you can use - https://www.comparitech.com/net-admin/network-server-application-mon-smbs/

When it comes to making a network map this may be of help too - https://www.capterra.com/network-mapping-software/s/free/

  • Thanks 1
Posted
Agree totally with Dos_Box... also get SMT buy-in on an RTO (Recovery Time Objective) - i.e. how quickly stuff can be back up and running. Remember, it might be that some things have a faster RTO than others... i.e. DCs and MIS back up and running quickly, everything else as as secondary concern.
Posted

On RTO's - one thing we have put in place when we last went through ours was making the cashless catering system the highest priority service to get up and running after the core infrastructure - we loose thousands a day if it is down. Your local situation may be different.

 

Retention policy:

https://www.gov.uk/government/publications/data-protection-toolkit-for-schools

https://irms.org.uk/page/SchoolsToolkit

 

Stream of consciousness follows - I'm a bit tight on time to edit this into something fully coherent:

 

Ensure that all assets are tracked.

Ensure that all support requests are logged, and ideally linked to an asset/user

Ensure that all changes to configurations are tracked (probably through the same system you use for assets and requests)

(reading backwards through change requests is very enlightening)

 

Make sure you have a document that tracks the age of each asset, and outlines the replacement strategy. Make sure your manager and the finance team know what assets need replacing over the next 12, 24 and 36 months.

 

Document how you on-board and offboard users. Tie this in with buy-in from Student admissions and HR.

 

Develop an SLA - specially with "time to respond" and "time to fix" metrics. Don't make them aspirational, work with your manager so they understand how long things can take - e.g. if a desktop has a hardware fault, how long would it take to get an appropriately configured replacement onto the desk - We could do it in about 15 minutes after we first confirmed the nature of the fault because we have spares ready to go, but for many years we were not afforded that luxury and so a hardware failure might take a week or two to resolve (waiting for payments to be authorised so parts could be shipped etc etc). Also as a one-man-band, you need sufficient slack in the SLA to be able to attend meetings, and support users, and perform routine maintenance around the site. An SLA of 15 minutes break-fix will have you chained to the helpdesk and you will not be able to maintain the service, nor build the rapport with colleagues necessary to have them onboard for changes.

 

Make sure there is adequate time put aside for training of staff on systems (particularly where change is involved). Make sure adequate time is put aside for your own professional development.

 

Work with middle leaders to understand their needs, and to make sure they understand how and with what you are able to help. If a trend emerges where they require flexibility that jeopardizes the agreed SLA's work with your manager to reach a compromise position.

Posted
Disaster recovery plan. (DRP) - its one of those things often missed... until you need it.

 

I've been asking to do this for two years. Keep getting pushback. "It's expensive and we don't need it as we've never needed it before."

Posted

Try to implement least privilege as much as you can.

 

Separate your "work email / user account" from all admin access.

 

Don't use the domain admin account unless its an emergency (set a very complex password and secure it) - make a few accounts that you can switch between to do things like user access, computer domain join, desktop admin etc.

 

Best thing I did for managing systems is learn scripting - PowerShell can take a bit to learn but once you get into it, the time it can save you is fantastic.

  • Thanks 1
Posted (edited)

Best practice IMO is to automate everything that is possible as Infrastructure as Code for the following benefits:

 

It is self documenting how everything fits together.

Other staff on your team get to review every change before it happens

There is a log of every change

Rollback on changes is straightforward

You get to test major changes before they go live

You can instantly spin up replicas of your production infrastructure

DR is built in

You can perform DR in minutes/hours on the entire infrastructure

Any problems and you just blow away the device and rebuild it as it's quicker than fixing

Edited by dmj
Posted
[ATTACH]66702[/ATTACH]

 

Hi Tech13

 

I downloaded the attached DR template from this site a few months ago.

 

It’s ok - needs some work. Recovery Time Objectives for example.

  • Thanks 1
  • 2 months later...
Posted
Backup, backups, backups!

And ensure they work once done. Often overlooked, right up until the point you need them.

As @Areku posted, you do need a distaster recover plan and ensure your bosses know about this and what it entails for when it is needed.

Some decent network monitoring is also a nice to have, there are plenty of free and paid for (supported) systems out there you can use - https://www.comparitech.com/net-admin/network-server-application-mon-smbs/

When it comes to making a network map this may be of help too - https://www.capterra.com/network-mapping-software/s/free/

 

Hi

 

Can you recommend best paid or free network mapping software?

 

Thanks

Posted

With regards to 'mapping' networks I'm a strong believer these tools are not even close to best practice, at best they are a stepping stone so you can see what you need to automate. The picture alone isn't going to be a huge amount of help to diagnose, fix, recover from a failure or deploy changes.

 

Anyway, once you've got the 'map', login to each network device and download it's configuration, from there you can use your preferred automation toolset to deploy configuration to your network equipment (and servers). The configuration is the real map - a single, backed up location with audit control over the entire estate.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...