Jump to content

psydii

Members
  • Posts

    5,195
  • Joined

  • Last visited

Everything posted by psydii

  1. The volume of traffic they handle is staggering. I’ve heard tell YouTube engineering notice the drop in traffic when one of the big uk edu isps has a problem. When they roll out a vendor fix/update it’s likely it will be the first time the code has come into contact with that volume of traffic. That it works at all has amazed me for years. (Says someone waiting for PaddyN @lgfl to push the release button on a fix for a weird ssl/365 Auth problem)
  2. religiously? no. but best-effort, when I have time, and when I know it wont break things? yeah. Caveat - many people here have to maintain a mandated security posture which may require a more "religious" approach. That said, when talking with people who have seen many many orgs in this context, they are reasonably impressed that we've done as much as we have. If you have on-prem AD, having your day-to-day workstation, server and domain admin accounts in the Protected Users group, and all web services behind what ever Azure App Proxy is called these days are the big ones. Azure ATP is also considered a win, particularly if you action the items it puts up on the security score dashboard. Client firewalls also apparently is something of a win though I've been doing that for over a decade so it wasn't an action item on the dashboard.
  3. Yeah, your mistake was not being the SBM. They move a lot faster when it’s the person who signs the cheque calling them.
  4. Probably worth reading Appendix 4 to better understand what “Healthy Fear” was supposed to mean, why it has merit and what the risks are. It strikes me that actually naming their strategy/policy this way set it up, for those less well versed in the theory and nuances, to be execute in the worst possible way.
  5. I'm not sure that the report quite supports that allegation. It does make it pretty clear that those with SEN (and black boys) were disproportionately harmed by the implementation of the policies. While permanent exclusion is the end result of enough behaviour problems, and it follows that SEN/ Black Boys are *likely* to be excluded, that avenue of investigation/discussion wasn't in scope for the report. Generalising to speak to the wider championing of the sorts of policies that lead to this report being necessary, IMHO anyone who works in a school that has to pick up the pieces from one of these ultra-strict academies knows the impact they are having.
  6. Read the report. It is even-handed in this regard.
  7. ...except it appears to get the results. If you can get the 'bottom' 15% out of your classes, then off your books , *and* ensure they underperform where ever they land (outside your Trust), you both juice your numbers, and lower the results of your "competition". Really no downside, because that 15% were going to fail anyway, and who cares if another school has a cohort with disproportionate additional needs?
  8. Reading between the lines, such people are not a good cultural fit, so would not be likely to persist within the organisation for very long. As for how they treat support staff, I imagine support staff would wisely say that they are happy and grateful to be working for such a bold and successful school/trust.
  9. First things first. This is a people thing not a tech thing. (the tech/skills bit will be easy if the people thing is in order) You need to be seen to be open and excited by this teacher’s ideas, and you need to be seen to be thinking about how this change will have a positive outcome to students. you also need to be seen to be cautious. Does the teacher have a track record of delivery. Do they have the support of slt? How dos this alter the safeguarding position? (I suspect you’ve locked down too hard and there is plenty of room to relax, but it needs to be considered and documented that it was considered and reviewed, no problem if the project has slt buy-in) Here’s what I might do: Sit down with the teacher, let them tell you how it can be. Be excited about their story and positive about making better use of the technology you already have to improve the outcomes for the kids. Explain that the set up here is quite different (particularly in that you have shared devices à la 2011 rather than 1:1 or even modern shared iPad/school manager). “Confess” that you don’t know what you don’t know, and while you can read up and reach out to your own network (that’s this place), it might be helpful to bring onboard a partner who could guide you both through the journey from where you are to where this teacher wishes you to be. Maybe he also has a network he can draw on for mentoring and support, but maybe it needs to be paid for. If they have the ear of the head or other powerful slt, work that angle. If your relationship with the levers of power is stronger, make the approach. SLT buy-in is crucial, and you need to be in front of that and seen as a forwarding thinking flexible keystone of these developments. Unless of course the teacher is trying to fly under the radar until they are able to demonstrate success, in which case their ambition is completely dependant on you… so again by talking with them you can reach a mutually beneficial arrangement, and when they take over the world you’ll beat their side. But if they are a loon, made sure you’ve insulated yourself!
  10. Wow. @TwistedHelixis “ 6.31 As one senior leader told me, he could totally see a place" where a child would be sanctioned for turning around looking at the clock, dropping something on the floor, or looking out the window”. He argued that failing to sanction these things is "failing children" because it teaches them that it doesn't matter. There was a biblical like sense that ‘fear was the beginning of wisdom’.” ”
  11. That’s awful. Hope they were able to move on and find somewhere more reasonable. This report is so damning, they even throw IT under the bus: “ 4.27 The CHSCP initially requested MVPA’s behavioural incident logs in January 2025, although no data was released by the Federation until April 2025. The original dataset shared with me was extremely basic, consisting of a 22,000-page PDF document that listed individual sanctions and rewards. It was unusable for the purposes of detailed analysis, and further to requesting an alternative format, I was subsequently advised that a ‘special database query’ was required and that no staff member was available to recompile it. 4.28 I was eventually provided with a CSV copy in November 2025. Whether this substantial delay reflects weak IT functionality, transparency or internal capacity issues, MVPA’s arrangements in this regard point towards an inefficient and unagile system. ” though to be fair if they had to redact the entire behaviour log, that could easily be 3 months work, but that doesn’t excuse taking until November. The federation also comes in for criticism so I wouldn’t be surprised if MVPA gets taken off them.
  12. Its made even more damning when you realise that the report is written by one of the people who helped Mossbourne into existence. I do wonder if they are / going to take a look at the rest of the Mossbourne Federation. I can't imagine the apple has fallen very far from the tree As a side note, I can't find that BBC article in their app, only via the website.
  13. If the PAT team see the same extension leads in place they saw the year before, they get antsy... "that needs to be a fixed installation..." And it could be pretty hard to argue that a digital switching device in display cabinet bolted to the wall wasn't "fixed" even if its got a 13amp plug on one end depending on the electrician you were talking to. Certainly as soon as you get to AC/Air Handling units, I think you are unquestionably into fixed installation territory - I mean these things a drawing 2000W+ which I'm pretty sure exceeds a lot of the Matter IoT devices design specs, so even if its not technically fixed its likely to be a fire hazard. And on laptop trolleys, modern ac adapters and laptop/batteries should have charge management hardware. I'm not sure whether the power you might save with a time based switching device cutting the power over the weekend would worth the additional complexity it brings. God, I'm being a right downer on this. Sorry.
  14. This gap is one of the reasons I don't see our DCs going anywhere soon. We use our internal CA for code signing and device certs for NPS backed 802.1x. There is a new Cloud CA offer from microsoft which if you are pure Intune can be used for 802.1x.. But not for any devices that are not intune managed (like say legacy on prem servers)... and you still need either on prem Radius (typically NPS) or a paid 3rd party product to actually do the authentication. Its such a strange gap for them to have left, makes me wonder if there are some influential customers who need there not to be functional parity between Entra/Intune and on prem Server/AD/NPS etc.
  15. if the switching hardware doesn't meet the BSI standard for insulation, fire retardance etc, it doesn't matter what protocol it uses.
  16. The "enterprise" BMS are not renowned for playing well in "enterprise" LANs. They are also very very complex, and often slightly misconfigured because the number of variables makes them very hard to properly debug. A few bits of Shelly-grade automations on non critical systems on its own vlan shouldn't be too much trouble from a reliability/configurability perspective.. so as long as you don't get carried away and promise more than it can reliably delivery. It is complying with building codes that is the hard part.
  17. Sometimes one regrets asking questions. School and Further Education College Design and Construction - GOV.UK Technical annex 2G: electrical services, communications, fire and security systems Technical annex 2H: energy GDB_Annex_2I_Controls-A-C12 Electrical standards and approved codes of practice - HSE BS EN IEC 61439-1:2021 Low-voltage switchgear and controlgear assemblies General rules
  18. I've found it often feels like they deprioritise requests from IT but jump on things raised by the School Business Manager.
  19. Doesn't "isolate network" block inter vlan traffic when set there? I think you want to set the isolate clients in the ssid settings to achieve what you are looking for, and remove the above setting to allow data to get through to the rm managed router. You will need to review the best practices for Wifi Guests Implementing Network and Client Isolation in UniFi – Ubiquiti Help Center UniFi Hotspots and Captive Portals – Ubiquiti Help Center
  20. This is giving similar vibes to an Intune Company Portal breaking update. (caused by msi logic not updating config files because they don't have version tagging in the original installer, and a newer dll breaks on installs upgraded from an older config Company Portal Stuck on Downloading: Token Error IDX12729) Might be worth looking to see if there is an older config file hanging around.
  21. psydii

    SSIDs

    That's the second time you've mentioned that in the last few hours. I'm intrigued to hear how you do it, as there is a similar problem to overcome for Entra Joined / MDM managed Windows and Apple devices.
  22. I think we've found who is responsible for certificate renewals at ParentPay. 😆 It expires on 1st June. We should meet back here at 31st May, and if the cert is unchanged, brief our schools to expect downtime for the following day.
  23. Wow. Great tip, I don't think I've ever needed to export the profile, so would never have thought to that to compare the settings. Hope to never see this though. Just for reference, what release of windows did you use to create the profile, what release was the profile applied to? Were any other versions used to edit or update the profiles? Is it possible the machine that created the profile (or edited it) had the "System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing" setting applied to it?
  24. https://www.theverge.com/news/837594/crucial-ram-ssd-micron-ai this follows SK Hynix and Samsung exiting the older ddr4 market earlier in the year… (have you noticed ddr4 from recognisable brands has also been drying up?)
  25. Is it possible the clients were holding onto their old IP addresses/leases because they weren't due to expire, remained valid and noting else on the LAN said they couldn't? When doing this sort of thing, its helpful to set a very short lease time a few weeks in advance so when you push the button on the new scope the clients fairly quickly pivot over on their own rather than hanging on to their old leases until they age-out. From what you have said, this appears to be a change driven by moving ISP. Do they mandate your internal range? If not, are you actually changing your internal lan range, or just the DNS servers to use? You refer to DNS forwarders - this suggests you have a local DNS service running that the clients use and that DNS Service forwards request to the ISP/Google/CloudFlare (or whoever you use for pDNS services). Has your local DNS Service changed IP? Or are the clients expected to query the external dns servers directly? How big is your LAN IP Subnet? Is it possible that you've got a subnet mask wrong and the dns server / firewall gateway ip is actually invalid for the subnet as configured in DHCP / on the clients? (I've done that!) this one is a pain to check as it could be on the gateway, on the interfae of the DHCP server, on the interface of the internal DNS server, on the clients, or in the DHCP scope/settings. Also worth checking are ACLs on the core switch - someone may have set up an ACL to allow only the old IP range, and even if you are using it as a flat network the acl could be dropping the traffic.
×
×
  • Create New...