Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hello everyone,

 

I hope someone may be able to shed some light please.

 

We are using Cisco Umbrella for our Internet filtering and such, but since moving to Intune and Entra ID only, it seems there is some issues going on in terms of very slow apps showing up in Company Portal and policies coming down to devices (even after multiple restarts).

 

I was recommended to use the Intune Network Requirements powershell script to check for any issues (Ref: https://github.com/MHimken/IntuneNetworkRequirements) and that has flagged a few issues up with Windows Notification Service.

 

I'm currently trying to find the correct place where I could white list or trust the various URLs from Microsoft/Intune within Umbrella but wanted to ask if anyone else has come across this please?

 

Any tips would be appreciated please

 

Many thanks,
Philip

  • 3 weeks later...
Posted

Hello,

 

Oh, I didn't know that.

Do you happen to have a link I can see this on please so I can let me colleagues know?

 

Thanks

Posted

Thanks.

 

Why would you not use this please?

 

I've mentioned this to my colleagues today and their googling suggests that Cisco Umbrella is allowed.

Posted

Its deployable in multiple methods. If you've got full decryption rather than their grey list inspection, thats better, but they also make use of DNSCrypt which is counter intuitive to the ECH breaking methods you should have to view obfuscated DNS lookups.

 

Its a trust thing. I trust Cisco to make switches and firewalls, same as FortiGate. I wouldnt use either as filtering, its a 2nd thought add on, not a purpose built filter. Sounds harsh, but theres a reason there aren't hundreds of firewall big names, same for filtering big names. 

 

Also, OK to use vs compliant and accredited are very different. My home filter is fine and would stop the bad stuff, I wouldn't have it in a school or somewhere that has a degree of safeguarding responsibilities. 

 

As long as you feel you can meet the requirements to correctly filter users based on age, provide different policies and be age appropriate, report on a per user basis and can decrypt their traffic, you are ok, but its just not accredited. Horses for courses etc. 

Posted (edited)

Also Reading: Meeting digital and technology standards in schools and colleges - Filtering and monitoring: core standard - Guidance - GOV.UK for example

 

Quote

The Internet Watch Foundation (IWF) and Counter-Terrorism Internet Referral Unit (CTIRU) provide lists of illegal websites that filtering providers can block as part of their service, known as blocklists. Schools and colleges must make sure these blocklists are implemented with their filtering solutions. Filtering solutions must be designed so that these blocklists cannot be disabled, overridden, or altered by any user in a school, college, multi-academy trust (MAT), local authority or any other responsible body, including system administrators, at any level.

Also make sure that your filtering provider is: 

  • a member of IWF
  • signed up to CTIRU
  • regularly updating blocklists based on information from IWF and CTIRU

 

IWF they have a category for, but cannot see anything for Counter-Terrorism Internet Referral Unit (CTIRU) list in Cisco Umbrella. If that's the case it would not meet DFE standards. 

Edited by willtech
  • Like 1
Posted

I guess you could test by running testfiltering.com as the school option and check your report, should give you adult/porn, terrorism, profanity and IWF denies at a minimum. Always handy to test to know where you are at base. 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...