psydii
Members-
Posts
5,194 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Use of VPNs for Student access
psydii replied to DrummerBoy's topic in Internet Related/Filtering/Firewall
Not at the moment, but I certainly can see a point in time when we might need student devices to use VPN-Like services. Entra Global Secure Access* is increasingly looking like a VPN - as do some on-device filtering platforms. (Defender on iOS, which might be gone now, basically did VPN-like things for web content filtering) Mostly though, VPN use is something the students are doing on their home computers that caused them to get locked out of 365/Google because they don't have MFA set up because phone are about to be banned in schools so we can't enable it. *Basically ISA 2004 /TMG in the cloud -
We had huge problems getting machines to go Windows 10 22h2 to 11 24h2. Eventually they all just started to go late August/September 2025. We abandoned SCC/WSUS in May, and moved to Intune/WUFB. We needed to make sure that in these policies auto update between feature releases was configured. For us, once we had got them into intune/wufb, we then found that sometimes legacy policies from SCCM/GP were not clearing. Missing updates and updates that had applied in the wrong order was another problem and Driver blocks were the final one. Somehow though, every remaining problem cleared just in time for the October EoL of Windows 10, even for machines we hadn't applied manual fixes! I suspect Microsoft has a whole bag of tricks to get machines unstuck, but they are cautious and it can take months or years before they let them autodeploy widely. Assuming you've got things configured to not block, their preferred way for you to get stuck machines to the version you want is a wipe and re-load.
-
Random user account locking out occasionally!
psydii replied to cheaptonersucks's topic in Windows 11
Also can be caused by a device using the account to log on to wifi, but has the wrong/old password? -
Meanwhile TES head off in their own direction: Tes Universal Accounts: Everything you need to know | Tes
-
Weeks? Maybe years. How do we think Cortana / Viva used to work eh?
-
I got my hands on a couple of manufacturing sample B311-31's early on in 2020. They blew me away*. Easily the best devices that could be had at the time, and most still going strong in 2026. It was while trying to figure out why they were so good I learning about emmc5.1a/HS400. *The very moment I realised how good they were is etched in my mind, I was outside in what felt like the first time in months, the sun was shining, London was silent and I'd just managed to defeat a "secure by design" door to retrieve my post, which included said laptops (long story). The next thing i remember is pivoting to intune and turning that house I'd just 'broken into', into a laptop imaging production line.
-
Seating plans help massively. (A school-wide t+l/behaviour management initiative, not an IT lead one, though we had been advocating them as a potential solution to issues for 18 months before they were adopted) For each set of devices, a user is allocated a specific one. This means that all logons after the first one (to a set) is fast and behaves exactly as most tested by Microsoft and app developers. The beauty is that the class teachers set and control the seating plan, so it’s no extra work for IT. Although, if you use intune, shared device profile might be better in some circumstances, but this does force you away from traditional apps with local storage state and into a web only world. (You can force OneDrive client to operate, but this undoes some of the power and purpose of the shared device profile) we use gpo/local profiles for our desktops and “full-fat” laptops and intune shred device profile for trolley laptops (where seating plans don’t help)
-
Intune Shared iPad & Conditional Access
psydii replied to Olliedawg's topic in Mobile Devices & Tablets
never done it with managed iPads, so was just throwing a load of ideas that might help when searching. But here's what I'd look into as next steps: Make sure you deploy a require PIN policy to those two ipads, because otherwise anyone who picks them up would get access to what ever was signed in. Exclude those specific ipads from your general CA policy with something like devices don't match (device.deviceId -eq "<ID of iPad 1>") OR (device.deviceId -eq "<ID of iPad 2>") then create a temporary CA Policy for "those two specific users on those two specific devices must have strong mfa" I really have probably got some of this wrong - I've got a very simple set up with CA Policies here and it was years ago when I set them up. -
Intune Shared iPad & Conditional Access
psydii replied to Olliedawg's topic in Mobile Devices & Tablets
Have a more specific conditional access policy for staff on the ipads that, say, just requires MFA? Or have a completely separate configuration profile for two ipads just for the trip? -
Wow. The narrative has always been that Intune is rough for iPad/Macs and JAMF is the absolute king of the castle. What was wrong with JAMF that you find yourself making such a bold statement? (about 8 years ago, as an experienced Windows Admin (with a bit of 2005-era Mac exposure), it took me a weekend to go from zero JAMF knowledge to having 120 macs set up, and six years ago it took me *TWO WEEKS* to get as confident with inTune for managing Windows)
-
Has anyone got any info / anecdotes on using WhatsApp to message parents like @Babynoush? How does this work? How do you managed contact details and groups? How do you control who can reply?
-
Dymo labels, and reprint when ever one gets peeled off. If a device goes missing, we leverage network and 365 telemetry to locate it and if necessary send round "the boys"* to recover it. We've always avoided the tamper proof labels as finance have a tendency to suddenly want to lease things, and leasing companies have punitive clauses in the lease agreements about permeant markings, so for consistency we just dymo label everything. The absence of a Dymo label is evidence that the device needs a little attention from IT and is swiftly resolved. That IT are seen to be present and hands-on is in itself an encouragement for students (and staff) to treat equipment with the respect it needs. If a device actually goes missing, we have means to recover them, swiftly. *in blue. We still have a Police liaison officer, who is more than happy to pop round for a chat.
-
There have been some odd goings on with permissions and security when 365 Groups are involved. From what I can intuit, most front-end systems have been coded so that 365 Groups behave (as far as a user is concerned) like a security group, but are in fact not actually security groups. A back-end change in May-October last year broke the mechanism by which the front end performed this sleight-of-hand, and then as part of an attempted global fix to this mess, they further broke customers bespoke configs as well. While they try and unwind that mess, there have been increasing numbers of incidents on the Health Dashboard around permissions on various SharePoint/OneDrive/Exchange and adjacent "apps". ...so it seems likely to me there is something the old backend-frontend set up did in 2023 to users/groups that it has stopped doing, and now you are seeing problems as MS try to rollout/back further changes. [edit - you have in fact got a ticket open with them already]
-
Yeah: open up net2, click a few times, select, copy. open up inventry, click a few times and then paste, click OK a few times. Repeat for each user. However, there is no guarantee at all that the Paxton readers and the inventry readers are interpreting the card numbers the same way round - so you may have to run them through a conversion tool first. The real trick is to provision the cards in a system that lets you export to other systems. When we've done a large print run (typically at the start of the year), the support team of the system that produced the cards exports the necessary details to csv for Inventry support team to bulk import into their system. Much like MicroDigitUK describes. (though inventry have never offered access to the tool - it seems they want to keep that out of our hands)
-
Tumblr: Is it still the Wild West?
psydii replied to LeMarchand's topic in Internet Related/Filtering/Firewall
While their current policy is that NSFW stuff *must* be flagged as such, and is excluded from search etc, I don't know how well they enforce that. Deep links I expect just work still (which is why we keep seeing it pop up in our filter reports), so I've left it blocked. If your filtering system does content inspection after applying url filtering, and it is good, then maybe its ok. But those are your dice to roll.- 1 reply
-
- 1
-
-
I wonder if get-dnsstatistics might yield useful data? Also in the final example in this article: https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/dns-client-resolution-timeouts the timeout seen is 12ish seconds, which matches what you are seeing. And, (per that article) “ Any Name Error response by any of the DNS servers will cause the process to stop - client doesn't retry with the next server if the response was negative. Client tries new servers only if the previous are unreachable.” Which leads me to the question: are you sure when you have a timeout the client is even able to reach the dns servers? Other random things that jump to mind based on other’s suggestions earlier in the thread: What other roles do your DNS server hold? How many clients are connected/using those services? If virtual, is the performance latency at the host level ok? is it possible there is another device with the same IP/MAC address as the server on the network somewhere? is there any network flood protection kicking in at a switch level? There is also dns logging that you can turn on- it is extremely verbose so you will need to plan/use careful to not run out disk quite quickly.
-
Sounds like you have a far better handle on this that I. Nobody should take what I have to say on the actually technical bits of a filtering platform too seriously. I've not poked around with proxy auth since Pavilion Internet's NINAA and very early RM IFL offerings.... which is why I'm surprised/disappointed that the current best-available solution (for auth) still seems to be from a the same era.
-
I'd hope so too. To be clear, everything from the word "Easy" was 100% tongue-in-cheek/a joke. The bit before, was me genuinely spit-balling how I might approach this with only a vague recollection of how Kerberos/KDCs work from a 2000-era MCP course and basically no programming experience.
-
Why isn't there a way for Chrome to securely pass the auth token to the proxy? That would be entirely OS agnostic and thus a win on every platform! Because Google don't want to. It's not Microsoft that is at fault in this *specific* case. @dhicks If I were to naively designing a solution, it might look something like: Proxy Server/filtering platform runs on a host that is its own KDC. Client machines run service that authenticates the local service to the proxy's KDC (to ensure proxy-client trust) Client machine run a per-user service that presents the user's local auth token to the machine-wide service, i.e. The per-user service says to the machine wide service "hey, I'm running as local\user1 here's my auth token". the machine wide service validates the user token and translates the username to cloud-equivalent username. The machine wide service then sends that (securely) to the proxy service, which in turn looks up group membership etc against the cloud auth provider, and returns a token (probably just text string rather that anything Kerberos or OAuth like) to the user client (or maybe the machine-wide client, depending on how OS/Browser security really works) The local service then injects this token into the header of all HTTP traffic which the proxy service then uses to make filtering policy decisions. Easy. To be honest I'd be surprised if Tom doesn't just use that as an LLM Prompt and have the code pushed to customers by lunchtime.
-
Yeah it just makes me sad that its 2025 the suboptimal interim solutions first seen in the early 2000's (late 90's?) are still in play. I'm also aware that the maker of the most popular browser in the world has almost as a core value, a philosophy that requires them to make this sort of thing as close to impossible as is practical.
-
That seems unwise. Is that not open to privilege escalation (in the most high-level sense of privilege and escalation) “oh hi smoothie, you trust me right? Well I’m actually the Head Teacher, now let me get to all the AI Sites, KThanxBye.”?
-
Edu app installers behaving like malware is *so* 2004.
-
I've seen worse business cases presented.
