StephenPink
Members-
Posts
333 -
Joined
-
Last visited
Reputation
306 ExcellentAbout StephenPink

Personal Information
-
Occupation
Head of Network Services
-
Location
Surrey
Recent Profile Visitors
The recent visitors block is disabled and is not being shown to other users.
-
Enterprise WiFi and Androids
StephenPink replied to synaesthesia's topic in Mobile Devices & Tablets
PM me and can chat pricing/supplier if it helps... I'm not sure I'd want to try and use CloudPath with another vendors APs. I've also been speaking to Unifi about their Endpoint app - as that can do one-click WiFi provisioning, but currently can't deploy certificates... -
Enterprise WiFi and Androids
StephenPink replied to synaesthesia's topic in Mobile Devices & Tablets
R670s/T670s. Nah - for Visitors we use the Guest Portal in R1 instead, with voucher codes that are issued by IT/Reception. No SSL inspection on that network - Securly Guest DNS filtering only. Voucher codes so that it can't be used by students. Cheers -
Enterprise WiFi and Androids
StephenPink replied to synaesthesia's topic in Mobile Devices & Tablets
Yeah you still need to install the root that signs the NPS cert for some Androids, tis annoying. Makes sense - am in the same boat. Will easypass also hand certificate distribution? That's the pain point (still) -
Enterprise WiFi and Androids
StephenPink replied to synaesthesia's topic in Mobile Devices & Tablets
We've recently gone to the Ruckus CloudPath route due to this issue exactly. And still not perfect, but a smidge easier - Android is the worst, not helped by the amount of variation between manufacturer versions as well. The other route is enrol in an MDM... i can share instructions from pre-CloudPath if it helps? Again they were reasonably vague though to try to cover the majority of devices without taking into account the specific variations. Cheers -
GPO details below (not sure the scheduled task deletion actually worked, but the reg keys definitely had the desired effect) I will however also make clear - this is NOT a fix - these devices DO need to replaced due to age, but we are where we are unfortunately... Computer Configuration > Preferences > Windows Settings > Registry: - New > Registry Item: ○ General: § Action: Updated § Hive: HKEY_LOCAL_MACHINE § Key path: SYSTEM\CurrentControlSet\Control\SecureBoot § Value name: AvailableUpdates § Value type: REG_DWORD § Value data: 0 (Decimal) ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No - New > Registry Item: ○ General: § Action: Updated § Hive: HKEY_LOCAL_MACHINE § Key path: SYSTEM\CurrentControlSet\Control\SecureBoot § Value name: HighConfidenceOptOut § Value type: REG_DWORD § Value data: 1 (Decimal) ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No Computer Configuration > Preferences > Control Panel Settings > Scheduled Tasks: - New > Scheduled Task: ○ Task: § Action: Delete § Name: Secure-Boot-Update § Nothing else configured ○ Schedule: § N/A ○ Settings: § N/A ○ Common: § Stop processing items on this extension if an error occurs on this item: No § Run in logged-on user's security context (user policy option): N/A § Remove this item when it is no longer applied: No § Apply once and do not reapply: No § Item-level targeting: No
-
Just in case it helps anyone else - we had this on Win 10 and 11 machines - freezing ~10 minutes after boot, whether logged in or not - it was the Secure Boot certificate updates. Specifically, trying to update them on machines that couldn't take it.
-
Recently gone through Procurement Services to get refurbished hardware; LOT 2 here: IT Hardware, ITAD & Associated Services The framework was quick and easy to use. Definitely easier than trying to get like for like quotes with refurbished kit - quick spec sheet, RFQ out and short turnaround - ended up awarding to BornGood and Tier1 - so far so good. Cheers
-
Have found 2 genuine HP J9150A, the rest are all FS and were working in either a 5412zl or 8212zl Cheers
-
Also generally recommend FS.com for everything - and the reprogramming side of things! More specifically though, I've been taking out a lot HP/Aruba switches and 10Gb SFPs so @Olliedawg if you confirm the exact part numbers you want I'll have a rummage and you're more than welcome to any I have? Cheers
-
DfE Standards / Minimum Requirements
StephenPink replied to UnknownSoundman's topic in AV and Multimedia Related
Makes sense! Yes absolutely a great reference - fills some gaps in the standards as well. Appreciate you finding and sharing. -
DfE Standards / Minimum Requirements
StephenPink replied to UnknownSoundman's topic in AV and Multimedia Related
This is super interesting actually - how did you find this?? and thank you for sharing! -
Connecting Androids to Wireless Network
StephenPink replied to ChosenHillIT's topic in Wireless Networks
Android devices are definitely a pain these days - more so if a 802.1x network! My notes regarding the "no internet" message are below; those URLs need to be excluded from filtering and ideally decryption too. HOWEVER be careful if you exclude the generic one, that as it contains google.com as if you the way it is excluded isn't specific to the exact URL, then there goes all your monitoring of Google searches... Below are the identified Connectivity Test URLs so far (these are required for devices to "think" they have internet access, regardless of if they actually do or don't have access to the rest of the internet) These URLs require adding to the "Custom allowed content" category, which means no filtering, and no decryption Android URLs Generic - google.com/generate_204 Huawei - connectivitycheck.platform.hicloud.com Huawei - connectivitycheck.cbg-app.huawei.com Oppo - connectivitycheck.gstatic.com Oppo - connectivitycheck.android.com Cheers -
iPads & MDMs (How are we doing it??)
StephenPink replied to MrIlly's topic in Mobile Devices & Tablets
Yep Shared iPad still not good enough. For the Junior school, we have 120 "Student iPad" accounts - 1 for each iPad. So they are setup as 1:1, and then the teachers have a record of student name to iPad for filtering/other issues. Then there's no password/code issues either as the teachers know the Managed Apple ID password if required (federated to the Entra account) and these are also still unique per account. No passcode on the iPads, managed layout via Jamf School etc too. Cheers
