Jump to content

Razzy

Members
  • Posts

    13
  • Joined

  • Last visited

Reputation

5 Neutral

About Razzy

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. We are happy to do what is needed to ensure everything is compliant. Just reaching out to see who has gone through this, and what they have put in place.
  2. Hi All, We have been asked to look into what we would need to be able to achieve the Cyber Essentials and Cyber Essentials + certifications. A key aspect appears to be that BYOD devices are in scope. We were not initially concerned by this as we don't currently allow staff or students to bring devices in. However, the definition that CE use is "devices not owned by the organisation which are used to access organisational data and services, A personally-owned device used to access company emails would be an example of BYOD". This is a game changer. We currently allow staff to pop their email accounts onto their phones which appears to be in scope. We offer a Virtual Desktop solution to staff and students, which I understand means the devices they use to access the virtual desktop service on, are in scope. This would also include any device staff use to access M365. I appreciate that the CE accreditation is not specifically designed for Education, and that in a corporate world, users are probably given laptops in order to do their work. I find it interesting that the scope does not include students devices, which would clearly be as much of if not potentially more of a risk to security than staff devices. For those of you who have considered CE or who have achieved compliance, any advice on what you needed to do, or advice in general would be most appreciated.
  3. Hi all, I would be very interested to get in touch with anyone who could share their experience (good or bad) of centralising IT across a group of schools. There is a feeling with our group that the benefits far outweigh the costs, but it would be amazing to speak to those of you who have already done this. Any assistance would be appreciated.
  4. Hi all, Just a thought on centralisation. We have had all kinds of thoughts on how this will look at the end stage. Could anyone who has gone through this shed any light on the model you adopted and why? Initially we were thinking of a single tenancy, with a single AD structure, and move everyone over. Now wandering if the initial goal should be to get the single tenancy up and running first. Spoke to one solution provider who said to just push everything to the cloud. Any insight would be appreciated.
  5. Hi Steve, Thanks for the reply. Do you have MFA applied to students? Do they have 1 to 1 devices? How do you handle the students setting up MFA? The concern is not the staff, its the students. We would not be able to force them to sort MFA internally, as they are not permitted to use their phones during the day.
  6. Hi all, We have MFA applied to all student and staff accounts via conditional access policy in Entra. Like a number of schools students are not to use phones during the school day so we whitelist internal IP's to negate the need for MFA internally. When (if) students attempt to access their M365 account externally, they are prompted to set up MFA. However, there are a number of students who have not done this. We are thinking that this is an issue as these accounts are then only protected by login and password. Should these details be phished, just copied by someone seeing someone logging in internally, or any other method, the details could be used by someone to setup MFA to their own device. We have told governors in good faith that we have MFA in place, but technically, only students who have tried to access resources and have had to setup MFA are actually protected. Has anyone else come accross this and what method did you use to mitigate? Ideally there would be some way to give a grace period for when the users join the school to set up MFA or else their account be automatically blocked from being able to register for MFA, we can then pick genuine cases up as they occur. Any insight would be welcome.
  7. Hi everyone, we are a group of 9 secondaries and 3 primaries who have decided to move away from the current IT arrangements and try to improve things. The schools currently operate individually with completely separate domains. Have any of your MAT's gone through a similar process? I would welcome any insight into the problems you sought to overcome and how such things as domains and forests were structured at the end of the process. Also, apart from your assistance, are their any good transformation companies out there which wont rip us off?
  8. Hi all, I was wandering if anyone could help. We are currently a MAT of 6 schools who have completely independent IT systems. The Trustees are beginning to ask if this is the best way to do things, or if centralisation is worth considering. Would any of you who work in a similarly sized MAT have any experiences to share about any of the following at all. Has it been worth the effort in centralising? What have been the true pro's and con's. What processes did you go through to get from decentralised, to centralised. What advice would you give for a MAT thinking about this? Any pointers / advice / rants would be most welcome.
  9. Hi all, I have seen similar topics but not specific to my query. We have let a number of trustworthy teachers loose creating Teams to evaluate the usefulness for teaching. We did tell them that they needed to use the same Team name as the associated class name used in our MIS. Some have really got to grips with it and now are relying on Teams quite heavily. When we get to the summer we would like to archive these Teams and recreate using SDS. The Teams generated so far have been created ad-hoc not via SDS. I understand doing everything through SDS would have been the best option as we would then be able to expire the Teams and get SDS to rename and archive them. This would then allow a new SDS synch to recreate the new Teams with the same names. What are our options? Has anyone successfully run one of the scripts to be found on Edugeek to auto archive Teams based on a csv? Were you then able to use SDS and the same class names to create your new Teams? I understand that messing with Teams names does not ripple through to the sharepoint folders, I am keen to avoid issues with not being able to create classes as there is already a (archived) Team with the same name etc.
  10. Cheers for the reply These pcs have Nvidia FX1400 cards in them with dual DVI outputs. We plug a dell supplied DVI -> Vga converter into them and then a VGA cable to the Dell monitor and one to the Samsung. The image is set to 'Clone'. Hmmm, not sure about the system standby, Thats worth a look..... /sound of footsteps off into the distance All the power saving features are off, Anyone got any other suggestions? I am tempted to get an engineer in, But with the system working they will probably prod it and blame the pc.
  11. Hi All, We are currently trialing 2 Samsung 650TS 65" Interactive Whiteboards out in the classrooms both connected to networked Dell Precision 380's. Every few weeks or so we will get a call to say they are not working. When we get there the pc's are on but there is no image on the Samsung and the Power light is blinking green. According to the manual this indicates the Samsung is in power saving mode and to 'Press a key on the keyboard'. Once they are in this condition the only way to get the screen showing the pc output is to turn the screen off, turn the pc off, Turn the screen on and then the pc. This is less than ideal however as the Samsungs are wall fitted and so the only way to turn them off is at the wall (in both cases the power socket is not easy to get to). I have tried disabling the power saving option in the Samsung's menu but this has not stopped the problem. Has anyone else had a similar issue? Thanks in advance Razzy
  12. Hi Deano, Yes we had exactly the same issue. Not sure how to get Orienting working without local admin access as the orientation process actually makes registry changes. (you can see a non-admin users failed registry writes if you goto smartboard tools - diagnostics) We basically had to create a group on the server called TempAdmin. Then made every member of staff a member of this group, Then went around each Whiteboard pc, Logged in with our admin login and went to Control Panel - Administrative tools - Computer Management - Local Users and Groups - Groups. Right Clicked the Administrators entry and selected 'Add to Group'. Then 'Add' and typed in our domain\TempAdmin 'Ok' 'Apply'. This is allowing Orientation settings to be written to the registry when a member of staff is logged into the pc, But still keep the kids from installing programs etc. We were having an issue with 'single finger panning' too. I would have loved to have read the group policy fix mentioned above before we rang SmartTech. Their solution was to go into Device Manager and uninstall the Smart Virtual Tablet PC under Human Interface Devices. This works as it removes the 'Pen and Touch' Component in Control Panel and therefore removes the 'single finger panning' option altogether. Its a bit of a hammer to crack a nut however as it also removes some other options you might actually want. We are running Windows 7 and most of our wb's are 6-10 years old.
×
×
  • Create New...