Jump to content

psydii

Members
  • Posts

    5,191
  • Joined

  • Last visited

Reputation

13,305 Excellent

About psydii

Personal Information

  • Location
    A windowless Server Room, London

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. recycled some dfe laptops and dedicated them for the purpose. wifi is switched off, acounts wiped by exams team after scripts handed in via usb/printing. Devices are maintained with a monthly reconnect over a weekend, and again over the holidays.
  2. but why though?
  3. Assuming BYOD, are you installing the root CA or the cert used by the radius server? Also what about the cert for MITM web traffic inspection? Does andriod limit the scope for these, or are you required to make personal devices trust all certs for all purposes issued by your CA?
  4. Its definately worse this september than it has ever been.
  5. Consider this an anecdote: My account wasn't playing nice at home over the weekend either, with similar errors, and absolutely resolutely failed to reauthenticate with a passkey or any other method.
  6. This just crossed my radar, not seen anything yet, but not checked either. Thought I'd drop it here in case it's useful for anyone. KB5124008 Is Breaking Domain Logons on Windows 11 25H2 —… — EndpointWeekly
  7. 1996 is calling with a prior art claim. This is how I saw it done when the printers were connected to VMS, the clients were Windows 3.11 / 95 and the domain was NT 3.51.
  8. IRMS (2020) advised DoB+31. The basis was the EHCP is (was?) valid until the individual reaches 25 years, and then there is the +6yrs in line with the limitation Act. DfE removed the bit about retaining SEND date last year. From Updates - Data protection in schools - Guidance - GOV.UK: Both can still be true - there may be no specific statutory duty, but between the final school needing to retain records in general until 25th birthday, and best practice to protect both parties in view of the limitations act, 31 seems to remain the prudent choice. However some safeguarding still needs to be kept potentially until a person's 75th birthday: Data protection in schools - Record keeping and management - Guidance - GOV.UK
  9. We actually find it about as reliable as redirected folders - which also used a sync engine under the hood (the csc.sys driver/redirector that actually sat between the gui and network shares). That said locating missing files is much easier with OD - the online recycle bin and that "cached" files are in a user accessible folder enable self-service recovery by students/teachers.
  10. Don't some IWB vendors offer firmware that defaults to lower refresh rates for just this reason?
  11. FWIW our GPO architecture dates back to 2003-2006ish. When we moved over we set a policy with a higher precedence, and that policy changed redirection and applied OneDrive related settings, filtered based on group membership (because we were rolling it out progressively). That said our method predates "known folder move" by about five years, so YMMV. I would caution that we put in place seating plans ahead of the migration so students OneDrive's were basically already sync'd (after they'd logged on once in that room) when/where ever they log on, this seems to have eliminated "missing files" problems that some schools seem to suffer with. We do have a 1G/s link up and down, so syncing is pretty quick (but way way slower than just mapping a drive).
  12. The RAM in them is probably worth more than that.
  13. You are just asking a question, but I'm not sure anyone else who is having a problem is actually allowed to say so in public. We don't use CPOMS, so I can say with certainty we aren't having those problems! Though we are having serious issues with a similar platform from somebody else - and groupcall appears to be the common factor. Not had a chance to dig in to see if GC is actually the root of it yet though.
  14. Dunno. Just followed the guide in the KB articles (and also as prompted via id.sims.co.uk) and this set up the new ParentPay App inside EntraID-Entrprise Applications. I assume the equivalent flow for Google is triggered the same way. To me it is very clear that the intention of this new SSO via a new app registration is to allow single sign-on as we (and DfE) expect rather than taking the spiteful path TES have chosen.
  15. I think you are missing something. The new process complete removes the current (janky) flow to link accounts to external authentication systes. All NEW users need to do is (on the new logon page) click the "logon with 365" or "logon with Google" buttons. That action triggers the sending of a verification code which they enter and, voila they are logged on to the webapp. Future logons don't require the auth code (though MFA might be required if that's how you've configured Entra/365 or Google). But first the sims and google/365 admin need to liaise to set up the new "app" (enterprise app in 365/entra parlance) as per the KB articles mentioned above. I got to go through this flow again today when I logged onto id.sims.co.uk. However, users are not yet seeing the new streamlined logon page.
×
×
  • Create New...