Gobstopper
Members-
Posts
21 -
Joined
-
Last visited
Reputation
0 NeutralAbout Gobstopper

Personal Information
-
Occupation
IT Tech
-
Location
UK
-
Good afternoon everyone, I look after an independent school that has an all Apple provision, there is no existing server infrastructure of any kind. Until recently, the school didn't even have Apple School Manager and were just buying devices from local retailers and refurb providers and setting devices up with local accounts. All a bit of a mess! The school now has the following in place: 1. Microsoft 365 is being used as the directory service and has been linked and syncs with the local Smoothwall appliance (Currently a Staff and Student Group). 2. Apple School Manager has been configured for federation with Microsoft 365 for managed Apple ID creation 3. All devices (iPads, iMacs and MacBooks) enrolled into Apple School Manager 4. Jamf Pro has been configured for MDM and all devices are managed by Jamf Pro. 5. Jamf Connect has been configured for Microsoft 365 sign-in on MacOS devices. 6. Smoothwall Cloud Connect has been set up and the Unified Client has been deployed to all MacOS devices along with with the Google Chrome extension. As things stand I am now getting filtering, albeit, whoever logs in is being treated as a default user by Smoothwall and while not ideal, I can now at least search internet use by username but I am lacking reporting and user/group specific filtering. This ultimately means that while I have basic filtering, it isn't compliant and is lacking a lot of control. Whenever I speak with Smoothwall support I don't seem to get anyone who seems to be overly familiar with Apple and have been told that while Smoothwall can work, its not as feature complete or as well integrated. Is this actually the case? If it is, I need to look at alternatives as a matter of urgency. The school does have an on-prem appliance so at some point I would guess that Smoothwall must have said that it would be a fully compliant solution. Any assistance / clarification from fellow forum members or Smoothwall would be greatly appreciated. Thanks!
-
Smoothwall for an all Apple School
Gobstopper replied to Gobstopper's topic in Internet Related/Filtering/Firewall
Thank you so much for the heads up ibpalle I really appreciate it, I have raised it on the Smoothwall support portal, to get this implemented. I must admit, I thought there was a missing link in all of this and this makes total sense! -
Smoothwall for an all Apple School
Gobstopper replied to Gobstopper's topic in Internet Related/Filtering/Firewall
Evening all, many thanks for the help with this Apple project - it was put on hiatus but is now up and running again. I am hoping for a final bit of guidance if possible. 1. Smoothwall is now configured to use Azure for the directory service, synchronization is working - green ticks across the board. I have linked the Students Group on Smoothwall with the Students Group on Azure. 2. School is now registered with Apple School Manager and I have enrolled an iMac M1 using Apple Configurator 3. Jamf School has been registered and is linked with Apple School Manager - Synchronization is working fine. 4. Jamf Connect has been installed and configured on the iMac M1 and I can now log in with Microsoft 365 accounts I feel that I am most of the way there, but there are a couple of outstanding issues that I am wondering if I need Jamf Pro for. 1. Although I can sign in with an Office 365 account, its not SSO and doesn't automatically sign-in to the users corresponding Apple ID or Microsoft services. 2. Whilst I see the device in Smoothwall the username in real-time web filter shows the IP of the device and not the username of the account that is signed in. I have read that I need to set up Jamf Pro to use SSO via Enterprise apps registrations and have the Microsoft company portal app installed on the iMac, but I am using Jamf School and it isn't as feature complete. If I could trouble anyone for some further guidance, I'd really appreciate it! -
Smoothwall for an all Apple School
Gobstopper replied to Gobstopper's topic in Internet Related/Filtering/Firewall
Thank you all so much for the help, this is massively useful and I think I can now see a way forward - it all looks pretty straight forward which is a bonus. -
Smoothwall for an all Apple School
Gobstopper replied to Gobstopper's topic in Internet Related/Filtering/Firewall
Thanks for the insightful reply, its incredibly helpful and appreciated! The school have recently been registered with Apple School Manager and Mosyle MDM (as its Free for basics). The school have 15 iMacs and about 10 iPads, they are a small independent school. They have a Smoothwall S8 which was installed prior to me supporting them but the school outright purchased the devices from Currys and not an Apple authorized reseller, so as I understood it, I'd need to use Apple configurator to enroll the devices into Apple School Manager. Your suggestion around the iPads being named against who they are assigned to with the Smoothwall browser replacing safari is something I thought about as a backup plan, thanks for confirming that would work as I wasn't entirely sure! I am beginning to think that Smoothwall for an all Apple provision is not suitable if I am unable to track users on iOS and MacOS which is a real shame as I have used Smoothwall in other schools, albeit in an AD environment, and its been great. -
Hi everyone, I am currently looking after a school that has bought an entire apple provision and is not currently set up for Apple School Manager or MDM. I am in the process of resolving this with apple configurator etc. The issue I have is that they have an on-prem smoothwall appliance and the school would like to monitor web activity by username, rather than device. The current set up is not compliant with current KSIE or Safeguarding requirements. In the past I have achieved this with an AD environment using iDex and joining the iMacs to the domain but I don't have that option here. Could any please point me in the right direction on how to achieve this on an all apple provision? I have been told I might need to use a smoothwall browser etc. Thanks again!
-
Evening all. I am hoping someone can clarify some questions I have around licensing, I have been in contact with a few resellers to try and find the answers but this has caused a bit of confusion on my end, we are currently sorting our volume licensing out and I want to make sure I have everything needed. All of our schools are currently using Entra and what I'd like to do is use device based activation/shared computer activation for Office 365 as we are currently using Office Pro Plus 2019 and Staff and Students are only using the standard A1 licensing. I was under the impression that to make use of the Office 365 in this way I needed A1 plus for Facuty and Student but I have since been informed that these iare being discontinued by Microsoft later this year. Some resellers have told me that I now need to buy the A3 plan for all Staff and Students which isn't free but other resellers have told me that I need the following which is apparently free. M365 Apps Enterprise Open Faculty M365 Apps Enterprise Open Student O365 A1 Edu Open Faculty O365 A1 Edu Open Student My goal is to simply deploy Office 365 and use the device based activation/shared computer activation methods on our Staff and Student devices. Can someone please give me some guidance on how to proceed please? It's all a tad confusing! Thanks Guys!
-
Good evening all, I am hoping for a bit of guidance on how I make the first steps in migrating an On-Prem AD to 365. We support a number of Primary Schools that would like to migrate to the cloud and get as close to a serverless configuration as possible. Most have been configured with Entra Connect and are happily using OneDrive storage with SSO. They all have an OVS agreement but only show A1 Staff and Student licensing on 365. Would someone please guide me on what I need to start this process based on the current configuration? From what I understand I may need Intune licensing? If I get this, is it just a case of generating HWIDs for the device and uploading csv files to Entra? Really sorry to sound like a newbie but I am not entirely sure where to start! Thanks as always!
-
Evening all, The headteacher of our secondary school would like to invest further into the Google Cloud and migrate everything to Google Drive, Classroom etc. I am completely happy to support this decision if we do things properly. My main concern is around what a Google technical support agent told me and what I have read in supporting documentation around backups. We currently have Barracuda backing up our Office 365 tenancy (SharePoint, OneDrive etc.) In the support documentation I have read it states that file retention on the Google platfrom is 55 days which assumes the file lives in the recycle bin for 30 days, you then have an additional 25 days to recover a perminant deletion. Obviously, if a file is deleted before the 30 day period then the 25 days begins from that point which means there will be less time to recover data. When I quizzed the Google technical support they confirmed this and when I asked about backups, they escilated to 2nd line which I never heard back from and the rep said that Google has no opinion on the matter of backups which I thought was crazy. I have a quote from Redstor to provide a cloud to cloud backup of Workspace but my headteacher is now being told a backup in completely unnecessary on the Google Platform, this has come from a colleague that she has worked with in the past. I guess my question is, have I been misinformed on the requirement of a backup solution for Google Workspace? If I have then great, it will make the job easier and save a lot of money but I wanted to ask those who have done this move already. Cheers as always!
-
Advice on Exchange 2016 - Hybrid on Server 2012 R2
Gobstopper replied to Gobstopper's topic in Enterprise Software
Thanks for the pointer again Chaplic It does all seem to be going the correct way so far and I imagine it could've been much worse! I had a look at the Autodiscover CNAME record on our web domain and it does appear to be pointing to our on-prem exchange server, not autodiscover.outlook.com Also, looking through ADSI it would also appear that the Autodiscover is set to our on-prem exchange which I found under the property of ServiceBindingInformation, this makes sense to me. So my logic is telling me that I can simply flip it and change both to autodiscover.outlook.com which would then (presumably!) stop Outlook clients trying to connect to the on-prem exchange server and go directly to 365. With MX records pointing to Barracuda (as we currently buy into their email defence module) I can't see any major problems? I appreciate that I am still incredibly green with on-prem Exchange so I don't want to assume too much! -
Advice on Exchange 2016 - Hybrid on Server 2012 R2
Gobstopper replied to Gobstopper's topic in Enterprise Software
Thanks for the tips Chaplic, they have been incredibly useful, however COVID slowed down my progress on this, back now though! So using the messagetackinglog I can see the background noise from Exchange that you mentioned above, the only email addresses I see after that are from our on-prem Smoothwall, which seems to be for reporting purposes. We also have Salamander but I am in the process of planning a migration with them. As for Scan to Email/Notifications it would appear Papercut is pointing to .mail.protection.outlook.com so I am guessing that means Papercut is sending straight to 365. Other than the above, I see no specific users which is presumably a good thing! -
Advice on Exchange 2016 - Hybrid on Server 2012 R2
Gobstopper replied to Gobstopper's topic in Enterprise Software
Thanks guys, this is massively helping me - I appreciate the time your taking to help! Following on from the advice above I have managed to gather the following: 1. All mailboxes are in Office 365 2. We have no Federation in place, just AD Connect 3. Mailflow appears to be Sender > Barracuda > Office 365 > Reciepient, MX Records on DNS Host point to Barracuda - I can't see any references to our internal Exchange server - Is there any way I can double check this? I did consider turning off the VM to see what stopped working!! 4. Exchange online has our domain set to Authoritative and not Internal Relay Thanks again guys! -
Advice on Exchange 2016 - Hybrid on Server 2012 R2
Gobstopper replied to Gobstopper's topic in Enterprise Software
Well I have managed to get access to our volume licensing agreement and I do have access to Exchange 2019, which I have downloaded ready to use in the October break. So on balance, given that 2016 is rather old I thought it would probably be sensible to install the tools from from Exchange 2019 onto something like a Server 2019/2022 VM and let it update the AD attributes and then kill that vm. The plan is then to turn off the Exchange 2016 Server 2012R2 vm whilst in no way uninstalling it. From what you guys have said, this seems OK and relatively straight forward to do? Feedback welcome! -
Advice on Exchange 2016 - Hybrid on Server 2012 R2
Gobstopper replied to Gobstopper's topic in Enterprise Software
This is exactly the kind of advice I was after, thank you to you both - I can now plan with a bit more confidence! -
Hi all, I am looking for a bit of advice, I recently inherited a school network that is currently using Exchange 2016 on Server 2012 R2 in a hybrid configuration. I can do the day to day stuff in Exchange and am comfortable with the powershell side of it but admittedly I am a tad inexperienced with Exchange, all of my previous schools have had their mail solution completely cloud driven, most moved from RM Easymail straight to Google Workspace or Office 365. This is the first school I have worked in that has Exchange on-prem in hybrid. With Server 2012 R2 reaching EoL on the 10/10/23 I need to look at my options, I wondered if anyone has been in this situation or something similar that could offer a bit of advice? My options, as I see it are: Turn off exchange and manage everything with Powershell, I am told this is now doable but am unsure on the process. Install a newer version of Exchange on a newer version of Win Server, not entirely sure how I do this as I assume it is not straight forward. Any advice massively appreciated!
