Jump to content

psydii

Members
  • Posts

    5,195
  • Joined

  • Last visited

Everything posted by psydii

  1. Tried floating that idea. There was some push-back.
  2. If you want SIMS, run it on prem and get involved in using NG - because if that doesn't get good, SIMS is dead. If you don't want to run it on prem right now, change MIS.
  3. Lol. I'm looking at an SAR where a hash of the data subjects name would be in scope, both because they said "all data" but also because they explicitly called out unique numbers or references that may have been created as an anchor between systems including where obfuscation of their identity might have been the goal. Deliberately obfuscating a persons identity for the purposes of avoiding a discovery process by/on behalf of that person is going to get those doing it into trouble.
  4. It's been a while since I really looked into this sort of thing. What are we doing about monitoring / holding the providers to account for performance glitches? I'm thinking How long to logon How long to render a student details page how long to load a register how long to submit a register how long to load a class seating plan (but taking into account how much data is pulled across for each student?) how long to run an attendance report per year group or across the whole school. Time taken for a competent user to complete regular tasks (which tasks?) failure rates of any of the above activities (users / failures per day?) Now I'm wondering if there are any time-motion studies out there for MISs?
  5. Yes. Its part of the training I give here. Use sensitivity labels if you want to stop the email content potentially flashing up on someones screen. Inter-org sharing can be a pain, but this looks like it is properly solved real-soon-now: https://admin.cloud.microsoft/?ref=MessageCenter/:/messages/MC1147390.
  6. In the past i recall ediscovery struggling when there have been too many pivots and filters applied before export. In the early years it used to be so bad that I'd have a ticket open with MS Support for most of ediscovery SARs. In the current version for me (with A5) the export to PST option in the Export fly-out on the right hand side of the screen, under Export Format "Create .PSTs for messages where possible" This isn't an option we use for SAR Cases as we do the redaction etc after export and need the filenames to be the ID (a guid) so we can provide a full audit trail.
  7. Route the outbound messages through your 365 integrated mail infrastructure? Papercut certainly integrates with it, as should any modern application. Configure an SMTP server over OAuth2 for Office 365 or Microsoft 365 | PaperCut We have some ancient ancient stuff lurking around, so we have an on-prem exchange server (mostly firewalled off from everything) through which the legacy apps can route traffic via on-prem authenticated accounts. We don't record the passwords, so there is no danger of account re-use. When a device is swapped out, or a new service created, we either create a new account, or if reusing the old one is appropriate, we reset the password - again not recording it in order to prevent a (lazy/overworked) admin from using it across multiple systems. I should note that our Exchange server is not ancient and, with no end user mailboxes, is almost zero maintenance these days. By the time the OS on which it is installed goes EoL I expect the legacy apps that it exists to support will also have been replaced.
  8. https://support.apple.com/en-gb/guide/deployment/depde72e125f/web for (modern) Windows there is delivery optimisation: https://learn.microsoft.com/en-us/windows/deployment/do/waas-optimize-windows-10-updates or the old WSUS of yore. 365 Apps: https://learn.microsoft.com/en-us/microsoft-365-apps/updates/delivery-optimization or the most modern solution: https://petervanderwoude.nl/post/getting-started-with-microsoft-connected-cache/ Finally, for Adobe applications there is the Adobe update server: https://helpx.adobe.com/enterprise/kb/ausst-release-notes.html
  9. How are you handling filtering for iPads?
  10. Also, if you have last years’s build available, what happens if you redeploy than to a few machines? If that is still good, what happens if you do a windows update to 24h2?
  11. It's arguable that McCoy has 9 years (87-96) as he appeared in the 96 TV Movie and the role was not recast during the break. (I read a lot of the NA stuff from Virgin Publishing during that time, which was the DW equivalent of the SWEU, so to me he *did* have 9 years.) Also McGann I feel ought to get credited with 2 episodes, his starring role in the mini-episode ahead of the 50th anniversary special made me smile. That is a significant part of the problem. Children start to age out and if they still watch it, many reach the point where they are dismissive/critical of new iterations of their childhood things, this affects the children who have not aged out. For those who still find joy, this can be taken from them by peers and adults who have lot it. My eldest (a teenager) who has been frustrated by the messy plots and poorly executed resolutions to a number of arcs in recent years, **loved** the space babies episode until his friends (who didn't like it) took the piss. His joy died that day.
  12. Service health - Microsoft 365 admin center
  13. admin.microsoft.com has been behaving strangely for the last 20-30 minutes too... oh and Intune just broke: "The portal is having issues getting an authentication token. The experience rendered may be degraded. Additional information from the call to get a token: Extension: Microsoft_Intune_DeviceSettings Resource: microsoft.graph Details: code: 400, statusText: Bad Request, message: The extension 'Microsoft_Intune_DeviceSettings' has not defined a resource access entry... "
  14. as long as the cert was valid when it was signed and hasn't been revoked, it doesn't matter if the cert is expired when you run the code.
  15. With a cert from your AD CA?
  16. Oh, now I have an opportunity to share my opinion that Chibnal's arc was a re-working of a fair chunk of the Cartmel Masterplan! And it was good (but harmed by covid/episode count). I will not be discussing this any further.
  17. I know what you mean, seeing it happen in moving pictures was quite jarring, even though The Dalek Book 1964 : Free Download, Borrow, and Streaming : Internet Archive had them for almost as long as they've existed. It is definitely a show that tests ones suspension of disbelief. I do think that adults in 2005 were carried along by a wave of nostalgia, the objective fact that the kids absolutely loved it, despite only a handful of actually good stories. Season two was helped by many many women liking a bit of David Tenant on the screen and the Rose story line. Matt was "too young" and not David. Capaldi was "too old" (though re-watching his stuff ages like good wine), and the kids of 2005 were ageing out and becoming scornful, discouraging the next generation etc etc. So so much has always been soo soo bad, and eventually the cynical naysayers overcame any positive effect that the one or two great episodes that would in previous years have rescued public opinion of it. If recent seasons had been given twice if the episode count, there would have been twice the number of stand-out episodes. But there weren't and modern writers/producers seem to have drunk the "plot doesn't have to work, audiences will love it on vibes" cool aid. When there are too few episodes every one has to be a banger, and they were not. BTW Almost everybody who has enthused to me about the show IRL has been a woman (or a child) and **LOVED** Tenant, despite many ropy stories in that era.
  18. Old PC that can't run windows 11, so that's probably an old HDD too. I seem to recall that some Seagate Baracuda and WD Green drives int he 2010-2018ish era were prone to aggressive power management techniques that when on the far side of a USB adapter might look like a power down to the OS. I think some were mitigated by drive firmware updates?
  19. I wonder if it's the "application first" trend that has been prevalent since the original Google Drive and IOS Apps? These (it seems to me) created mental models that make conceptualising the actual underlying filing system more difficult than necessary. Basically people are being taught wrong (by the UX from Google and Apple), and the second they need their work to interact with the work of others the simple model breaks and they have to learn how to use a filing system - fine in highly motivated adults with peers who know how to do it properly, far less fine in schools where suddenly the English teacher is having to teach basic IT skills. IT Support: "Where did you save it?" User: "In Word" IT Support: **screams into the void in my soul** Maybe in KS1 the need to start* with, "here is your folder where you keep your work." "Here is the menu that lets you create new work in this folder."*DO WORK*, "look see how that work you did is saved in your folder?"... and then using that pattern every lesson, building all additional skills from there, while not worring about the teacher being able to easily get to the work until later. Then perhaps only adding the more complex "well sometimes we need to work together, so here is a folder where you can do that. Let's start a new document in this shared folder" in Year 3, when they arelady have the concepts of a hierarchical filing systems embedded. (By "start" I mean, at the point where the curriculum calls for them to engage with creating files, not necessarily lesson 1 of Year 1!) Consider how kids have different exercise books for each subject, and how they are issued the books, how they are collected and managed. They are taught how to use them and how to manage them, and the expectations upon the students develops as they progress. But crucially (as far as I can tell as a parent, I don't have professional experience of a Primary Setting), from Yr1 they stop working on scraps of paper and move to the exercise book model, learning to organise their work start *very* early. If core IT skills aren't being taught along a similar developmental pathway, perhaps that is what needs to be re-evaluated before accepting that problem as the defining parameters for a technological solution.
  20. It’s late, and I’m three beers down, and I actually paid a consultant to set this up 15 years ago, and I’ve riffed on it ever since. So, I just tried these out two prompts in my LLM Chat Bot of choice and it did a decent job of describing our config: 1) How do I configure ad groups, a CA and nps to put members of different groups onto different vlans when they authenticate to the wireless network ssid? 2) I also need byod devices to be able to authenticate using a username and password without having a device or user certificate. Be careful, the bit where you configure vlan/tunnel type in the nps policies is actually vendor specific, so you should refer to the specific documentation about this from your wireless vendor. On the device that routes your internal vlan/subnet you will need to make rules that ensure traffic from the Boyd vlan can only get to the internet, DHCP servers and DNS Servers. And because I’ve had my nose in my phone writing this, I have just been made to read it out loud. Which explains the minimal typos.
  21. For EAP-TLS (user/device certificate authentication) / PEAP ( user/password auth) the devices don't need line of sight to AD, unless they are needing to access shares and printers. But they do need to see a DHCP and DNS server, but this does not need to be the same ones used for your AD Domain. We have one ssid, and if you auth with a username/password you end up in the BYOD/Guest VLAN, firewalled off from everything bar the internet. If you auth with a valid domain issued computer cert that correctly maps to a computer account in AD, you've proven you're a domain managed device and you get the normal workstation level access to the network. Actually we are more granular depending on group membership of the account used, so we can make you can hit different filtering rules/requirement based your/devices role too.
  22. You can move the spool folder to another drive, I can't find the original article, but here is an archive link www.betaarchive.com
  23. If they sync with OneDrive, you'll need to On-prem really is going away, so building a solution around it in 2025 is, unfortunately the wrong thing to do. Some bits of the scripts on this page might help your IT team automate the bit of the process where the the teacher needs to sync the student OneDrives to their computer. Synchronizing SharePoint Document Libraries with OneDrive using PnP PowerShell - Rishan Solutions (I've not tried it, and OneDrive is a special case of a SharePoint Document Library so has its own quirks when doing this sort of thing, and I'm not sure why pnp would be needed when sites and document library urls are predictable) YMMV Students will then save files at the following path (for trad Windows Apps) File Explorer -~> Documents For staff it will be File Explorer -> School Name ->"Documents - Student Name" On the web students just save to the default location and 365 does the rest. For teachers they will be able to use the 365 landing page to discover the the OneDrives, but also IT could just provide an excel file with links. The tricky bit is if five clicks deep is too complex for 20% of the students, you are in a hole. Perhaps expecting them to produce work that needs to be reviewed by their teacher in a file/folder structure is the problem. In my opinion it is certainly something they ought to be able to do by the end of Year 6. However, even ten years ago I heard teachers who'd moved from primary to secondary teaching lamenting the collapse of basic ICT skills in students arriving at secondary compared to those from previous cohorts. The issue may be systemic.
  24. **stares at 10,000 emails in Purview** and that's just SLT and the SEN team. Very roughly, off the top of my head... Typically if the scope is broad, we do SLT, SEN, Safeguarding Team, and the data subjects Heads of Year, Tutors and teachers. Using the student's name as the keyword. ediscovery seems to do quite an impressive job of pulling up emails where the subject is referred to as "J.B." when the search term was actually "Joe Bloggs", and also sometimes managed to pull up teams chat between staff that is clearly related (you can tell by time and the context) but doesn't mention the name at all. We then do a quick sanity check, and might poke around if there are clearly gaps, tuning our search terms until we are happy we're capturing everything in scope. Once we have our results, we then create a set of tags, with two groups, one "Not for export", the other "For Further Review". Under Not for Export we have "duplicate", "not about subject", "data from MIS" and "privileged". Under "for further review" we have three tags "no redaction required", "requires redaction", "Check with DPO" We use various pivots inside ediscovery to (fairly) quickly tag duplicates and data from sims, not about subject. Tagging any that are actually in scope of the SAR as either not redaction required or requires redaction depending on obvious signals. Very rarely is anything tagged "privileged" and if it is there is already a solicitor sitting with the head and this is bounced over to them for review. Usually it is reclassified to either "no redaction" or "requires redaction" with notes from the solicitor. Similar with anything tagged check with DPO (typically used when there is a potential conflict with safeguarding or third parties). Once we have everything tagged we export to individual files with names based on the guid of the object in ediscovery. This allows much more a much more precise review to be undertaken by the DPO / Solicitors, and for these reviews and conversation to happen over email - since we are talking about guids and not the data subjects data. Also when it makes its way to the data subject as our formal response, they also can reference the guid should theory want to follow up something specific. But I'm jumping ahead. Once we have all the documents/emails exported, we convert to pdf and take a directory listing into Excel. We then redact as appropriate. Though each pdf is run through redaction tools to remove metadata. Justification for all redaction are recorded in the excel sheet. Once complete the folders are then checked, there should be three files per file exported, the original, the pdf and the redacted pdf. We take another directory listing into excel and save as evidence. The redacted pdfs are then moved to either a ready for disclosure folder, or ready for review (if it warrants a review by the DPO, or there are solicitors involved on our side). The results are then handed over and the SAR closed off. We keep the ediscovery case for a year.
  25. If you are going to stick with on-prem servers, It might be better for IT to create a folder for teachers that contain "junction points" to each student's redirected Documents folder. That way the kids just save in Documents, and the teachers can jump into them using a directory that contains only their class. If you don't want on prem, then let windows do its thing with onedrive (by default Documents is redirected into OneDrive, so the default save location is OneDrive), and have IT create links to the student onedrives. The teachers can then "sync" their student's onedrive to their computers for easy accesss through File Explorer. Either way the path to save work is File Explorer -~> Documents for the kids, and File Explorer - SOMEFOLDER - Student Username for staff.
×
×
  • Create New...