Jump to content

psydii

Members
  • Posts

    5,195
  • Joined

  • Last visited

Everything posted by psydii

  1. Start here: Microsoft 365 Copilot Chat for Students 13+ | Microsoft Community Hub
  2. Mulholland Drive. Found in a DVD library in an Airbnb. “Ooh I’ve not seen that, seem to recall people talking about it when it came out, yeah let’s watch that.” If you know nothing of this film, I strongly recommend you watch it *before* learning anything more. It’s quite a ride.
  3. https://learn.microsoft.com/en-us/windows/deployment/windows-subscription-activation?pivots=windows-11#subscription-activation-for-education " in order to use subscription activation for Education, the device must have Windows Pro Education and an active subscription plan with an Enterprise license." Emphasis mine. Perhaps this is being enforced?
  4. I'd argue that an account tied (restricted) to a specific piece of secured hardware, with an audit trail of who is holding that hardware at any given time, with a regularly rotated password is not in fact a shared account as per the intention of the requirements. Sometime I lose these sorts of arguments, but usually* someone pragmatic makes and amendment/update to the rules to match my expectation. *eventually
  5. Hmm. Your Root CA certificate used to securely issue/validate certificates for the AP management API expired. Poking around the HP / Aruba forums (and an old edugeek thread here), these certificates are generally updated by HP, with the last one being issued in 2020, which was generous as it was some years after the MSM went end of life/end of support. The "Dummy" certificate apparently shouldn't matter, it's just aesthetics (apparently). You might try throwing yourself at the mercy of HP/Aruba support, to see if there is anyone left there who can generate a suitable replacement certificate for you, but given the initial certificate was generated over 20 years ago - this platform might just have finally run out of road and come to a permanent hard stop. The other way (maybe/maybe a terrible idea - I wouldn't want to try it) could be to somehow generate and install a new root and issue new certs from that for the SOAP XML services to all the aps - I suspect this is undocumented, and might potentially end you up in a worse place.
  6. Treat the laptop (and that it is in school) as the second factor.
  7. In the end, everybody gets a laptop. It's not an IT budget problem, its a having people problem.
  8. Accepting your previous assessment, I'm not sure how they could maintain and update / upgrade a service without having administrative access to the box on which the service is installed. Its fundamentally a product built on 1990s-2010's Microsoft architecture with locally hosted Windows/SQL/ .net framework based servers and clients (the aforementioned horse and cart). It is what it is, and increasingly it is not the right product for people in the 2020's.
  9. I moderate my language to avoid libel, but that is not an entirely inaccurate assessment.
  10. All the technological/security/operational concerns (for single site installations) can be overcome with an AD Join, appropriate settings deployed by GPO and your LGfL Sophos licence. However, since you are philosophically (and practically) committed to a serverless environment, I would say the Inventry system is not the right product for you.
  11. Every supply teacher is issued a numbered laptop from a pool. With the laptop they are issued a numbered generic account "locked" to that laptop. The generic account has limitations that full staff do not. Specifically we have limitations that applied to any account/user where they have not completed our internally delivered statutory training (including Data Protection). These generic accounts are always restricted. If the supply teacher is here for any significant length of time, their details are processed by hr and they are issued access to the training materials and their own dedicated account. The generic supply account passwords are rotated periodically.
  12. seems like a perfect time to try out this trick for comparing the registry before and after a change: Microsoft PowerShell lets you track Windows Registry changes First run on the working PC, then deploy the sccm client and run it again. then do the diff.
  13. Make sure you've got logging enabled, require (at least) remote signed, and have an av solution that supports AMSI
  14. It depends. None (in general) If it was 2005 though, 2.5/10Gig would give enormous opportunities around super-fast device reset/reimaging even allowing for swapping out software sets or personalised device image deployments at logon. Heck, everyone would agree that roaming profiles were the right solution! It's 2025 though, so maybe devices in a media classroom where the raw footage is on a SAN? If a school has a fast internet connection, everything has moved to the cloud and since almost no one has a multi-gig internet feed, having more than a gig to desktop seems unnecessary. If a school has a slow internet connection, and is still server heavy because of it... maybe? But the theoretical 2005 scenario isn't well (at all?) supported by industry tooling because of the move to cloud and the rise of wifi (nobody is getting 1G+ to any devices in a room full of laptops, and nobody has ever demonstrated that even a modern AP can push 1g+ in total once its supporting more than a handful of clients) so that is moot. The final concern I have is cabling. If the endpoints and switches support 2.5G+ what happens when the cables don't... not everyone is has a Cat 6a network, not every cable is 90m or less. HOWEVER. If we are talking about it as part of 15-30 year investment I'd want things spec'd for it because a multi-gig internet connection will become the norm, and so will 2.5G+ switches and endpoints.
  15. Yeah copilot is coming to 13+ real soon now. Forcing this homepage has made people hate copilot and made it harder for them to use 365 quickly. I'm almost ready to throw in the towel and let the growing contingent of pro-google newbies take over.
  16. I'm not well versed in the SW Legacy EU lore, but wasn't the slip between republic/empire and forgetting about Jedis/Sith etc "blamed" on the absence of books from the (creative) universe? I note that a major MIS-adjacent provider seems to have erased almost all records of what could (should?) have been a business-ending outage a few years ago from the internet. It's not just governments-of-the-day that can use the law to manipulate the collective understanding of what is the truth.
  17. Bromcom and Arbor remain pretty even if Secondary schools are your focus. Both having about a 6% growth this year. SIMS' decline is considerably less that I thought it might be, but perhaps there are more schools with the option to leave next year than the initial 3-year cycle suggested. The notes about Bromcom's profitability vis-a-vis the Private Equity backed competition, I think, will become an increasing point of interest over the next 10 years. My prediction is that Arbor and SIMS will both need to dramatically increase their prices to satisfy expectations of the PE investors/owners. While Bromcom does not, and will likely keep a check on MIS inflation until such time as ownership of the business changes. (Anyone got any idea what the succession plan is for Bromcom Computers PLC?)
  18. That really is problematic, as you say, who gets to decide? Both the Guardian and the Telegraph (often) publish pieces so extraordinarily biased that they are considered to be misinformation by those who lean the other way and the Mail has been flagged by news verification services as unreliable or publishing verifiable false/hateful information. And let us not forget the dear old beeb which is both the occasional mouth-piece for government propaganda and the whipping boy of the left/right (depending who is in power that year). Combined with the AI slop dominating new web content and commentary (particularly sites that were formerly champions of "citizen journalism", we are entering a the very worst timeline (unless you are a billionaire). Does anyone have any thoughts on NewsGuard in Microsoft Edge? Its supposed to warn of strong bias/misinformation when searching for / reading news. I wonder if we'll end up seeing the DfE doing a centralised procurement for a service like it or ground.news (the sponsor of many podcasters at the moment, not that that is any real endorsement see previous sponsorships for dodgy VPNs , or the double-dipping privacy thieving retailer backstabbing Honey)
  19. you could have a scheduled task that monitors for event id 11724 and then reapplies the registry key. A bit crude because it will trigger on any uninstall, but might get the job done.
  20. Apropos of nothing, I am just taking this opportunity to note that while a market leader, CPOMS is a service not without its problems and flaws. Are they any worse than others' flaws? SIMS, Bromcom, MLS, Classcharts all have (had?) similar mega threads here and elsewhere, and they all* still get new customers - because eventually they improved/stabilised. Things improve, things regress, but a perfect (or even "good") reputation from time to time they do not have. And it is important that we can share and talk about this. *even SIMS, though they are perhaps in single digits, and it was contractual shenanigans not service delivery/stability that really did for them - don't upset the "money people"!
  21. Try the scripts towards the end of this article: How to Delete Old User Profiles in Windows | Windows OS Hub The key thing compared to yours is that assessing the last used date for user profiles is much more complex that it was when the gpo evaluation rules were written for Windows 2000 through 7/8. Though I thought Microsoft had updated them to reflect how profiles work around the 22h2 release, but perhaps not. I think we have a customised version that uses CIM modules rather than the depreciated WMI ones. Not sure whether this makes and difference today, but it might in the future when the wmi cmdlets are removed. By the way, a better way is to manage local profiles is in the shared device profile from Intune (if its available for you). Finally, if your have onedrive in play and the profile contains un-sync'd items we have found that the folders containing the unsync'd items are left behind, as a last ditch effort by the operating system to prevent you from forcing data loss on the user. Edit because I linked to the wrong script -should have realised and things were more different that I was expecting.
  22. There's been a site dedicated to our school for years now. We keep an eye on it while appearing to be oblivious. Everybody uses it, so the kids don't need to wander off into the potentially darker/less well understood sites. That said very occasionally we need to intervene and ask the student if I need to look into what they've been doing to find sites that I need to block - that keeps things in check. Recently though its been a desire to get to the Generative AI sites that's fuelled a huge surge in kids using proxy-bypass sites - and consequently they have also moved away from the traditional bypass site they've been using for years. This has fueled complaints from staff that kids are all playing games, accessing in appropriate material. Absolute pain, we're now into the ever escalating efforts to restrict things while they look for ways to bypass them. I'm looking forward to when we can light-up copilot/chat for students (September?) and hopefully they'll come back within the rails (as it were).
  23. No I would not expect to see that, unless perhaps you are sniffing on a port that has multiple tagged vlans. Is there a cable somewhere looping from one vlan to another on ports that have the various bpdu/loop protection etc relaxed?
  24. If the iPads are used by any English teachers (or any teachers who had to write essays for their degree), maybe get them to help you redraft that truly dreadful run-on sentence I posted above… then with a bit of spin you can claim to have got key stakeholder feedback too!
×
×
  • Create New...