psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
get-windowsautopilotinfo.ps1 is probably your best bet! Manually register devices with Windows Autopilot | Microsoft Learn This one is also worth a look. There have been times where some of the features in MS's version broke (because the author left MS), and so an MVP who he had previously worked with took it on. It seem they are both still being developed. For what you are trying to do (get a csv) I think the MS one has always worked.
-
You forgot SIMS NG/ Connected! I'll see myself out
- 12 replies
-
- 5
-
-
- sims
- sims update
-
(and 3 more)
Tagged with:
-
I'd go with an email along the lines of "Sorry, I've been in the weeds with this too long and I can't see a way out. Could you help me understand how we can put a pin on these devices while also having them used by half a dozen different students each day that doesn't result in the pin being written on a post-it taped to the back of the iPad, since this would (I think) negate the whole point of having a pin in the first place? Perhaps there is another path we can take that meets the security standard on this?"
-
what can the iPads access? how does a pin help protect personal data in a shared device scenario? I wonder whether either you or the auditor has misunderstood the use case/scenario here and a face to face conversation with a demonstration of the use case and explanation of the perceived risk might afford clarity and thus a pragmatic resolution. We have a couple of shared iPads that have access to highly sensitive data. It has a (well known) PIN and the account that accesses the sensitive data is configured to be passwordless, and needs re-authentication every hour with Authenticator and the device PIN. The device locks rapidly, and if it ever goes missing for more than a few minutes we lock the account out completely. Its a pain-in-the-behind for everybody, but not so much that we'd buy one iPad for all the users instead. We certainly wouldn't think of adding a PIN to the student facing shared devices when we have remote lock/remote wipe capabilities.
-
User, Technician, and Administrator accounts
psydii replied to Sephiroth's topic in How do you do....it?
A couple of threads that might also be useful: Each tech for us has their own their daily driver account (exactly the same as all staff) A endpoint local admin account (protected account, with gpo managing membership of local adminstrators for all endpoints (clients not servers) as per one of the above threads) A server admin account (as per the local admin, but where our working practice is to purge membership of the serveradmin_servername groups daily/when we are done working on the server. Only half of the team have a domain admin account (for use only when working on Domain Controllers or other tier 1 systems). Currently this means any changes to users accounts/groups and/or group policy is done on a DC with a DA account. Adding privilege levels to delegate group policy management or group management adds more complexity that benefit at the 4 people-2000 user scale (in my opinion). We do however delegate password reset right for objects in the student OU to a group of which our daily driver accounts are members. We have also implemented best practice around accounts used by Configuration Manager. -
Calendar event sent to a group with externals in
psydii replied to Danp's topic in ChromeOS & Cloud Based OS
...now I note in which specific forum this was posted. d'oh! -
Calendar event sent to a group with externals in
psydii replied to Danp's topic in ChromeOS & Cloud Based OS
If 365 groups are they "subscribed"? get-UnifiedGroupLinks -Identity (get-unifiedgroup -anr "staff").id -LinkType subscriber -
Visually impaired student coming in September
psydii replied to Jawloms's topic in Educational Software
Yeah, we use Teams for this, and I've heard splashtop is great too. It is completely dependant on the individual Teachers stepping up to their responsibilities to make the lesson accessible while preventing leaking of sensitive data. Just as it is when they connect to the IWB/Panel. If they can't be bothered to use the tools (splashtop or Teams) properly, that really is between the SENCO, HR and the Teacher to sort out. Lockdown teaching proved it was possible and pretty easy. -
No roaming or mandatory profiles, no AppData redirection. OD Client running and syncing their OD by default. Folder redirection for Documents etc into folders in the OD folder. ***For courses that are not producing "Office Based" documents as their 'physical' output, students then sync their "Working Files" folder (from the Class Teams/SharePoint) and work in that. For all other courses, either work in the Assignments App, or save work into Documents We have seating plans so they always use the same computer/laptop in each class (where possible) We have two classes of device. Traditional GPO managed Desktop/Laptops configured as above and Intune Managed shared devices. Intune managed shared devices do not support OneDrive client by default and we treat them as "web only" devices - so no desktop apps and certainly no Photoshop etc. Traditional GPO managed Desktop/Laptop devices need at least 512GB storage to not be a pain to manage if photoshop is in play. With some scripts aggressively purging of cached profiles devices with 256GB can be made to work. If you can use MDM configuration, deploying parts of the shared device configuration profile via a script (to automatically aggressively delete old profiles, and dehydrate files) 256GB is quite manageable. Key to making it work though is the seating plan - the student only needs to set up the sync once per course (or devices set). If they move computers every lesson then things quickly become unworkable. This constraint works fine for us.
-
All Teaching Staff Getting Laptops - Anyone got an expectations form ?
psydii replied to mattysmith80's topic in Hardware
New staff always get a new laptop. The leaver's laptop is recycled into the spares pool if it falls within supportability. We have a pool of laptops dedicated for supply staff (standard staff laptops bought new for the purpose). They are allocated to the cover manager who is responsible for keeping track of them. We have a pool of laptops for trainee teachers (a set of devices we 'refreshed' early for the purpose of building a pool). They are allocated to the Trainee Teacher Manager, but are with IT when we don't have trainees with us. Maternity Cover is a cost of doing business/having people. Generally a laptop is bought for the person brought in to cover. Long Term Absence is a cost of doing business/having people. Generally a laptop is bought for the person brought in to cover. Generally laptops bought in for a long-term cover are recycled into the spares pool when the need for cover ends. Sometimes the person being covered actually becomes due a new device while they are off, in which case they will inherit the new from their cover on their return. Sometimes (quite often actually) the long-term-supply actually transitions to full time employee in some capacity, at which point they continue to hold the laptop. -
How are people blocking software/apps in windows 11
psydii replied to User3204's topic in Windows 11
Has Applocker via Intune got to a workable state yet, or is all hand crafting xml rules still? -
Been there done that. I've tripped myself up with that in the past. There was a script that was supposed to be used to add and remove members from various groups, setting them as subscribed... but occasionally a user would be added via the GUI, and because that flag wasn't set, they'd never get copies of the emails.
-
Ingram Micro still silent 14 hours after global outage began • The Register They are one of the two distributors most of our resellers use for all hardware and software. The article appears to imply that MSPs are unable to manage customer licencing renewals for backup software and 365 (amongst other things)... If they don't a a DR plan more robust and responsive the M&S, this could be months of chaos and higher prices for all things IT.
-
If I am not mistaken these people (Scottish National Investment Bank plc, IFM Investors Pty Ltd, Edmond de Rothschild (Suisse) S.A.'s BRIDGE and Royal Bank of Canada) are expecting a return on the £140M they put into the (current) holding company in order to make the various purchases that have resulted in the everway brand.
-
A *nix box would be my initial plan, I think, if I were getting rid of the windows infrastructure in anything but the smallest of LANs. Running on a linux server you get to pick and choose the actual dns and dhcp servers to suit your specific needs, but with a switch (like Windows) you have to take what ever the vendor baked in. Though, if solution is to have a standalone DNS/DHCP server, how do you monitor and maintain it? When you have servers you probably have a monitoring and maintenance platform of some kind. But when you've just got a single little nuc or Pi with two services, what do you do that doesn't further violate the *intent* that drove the decision to go serverless? But with a goal of eliminating "servers" (that run software) you are forced to use what ever the remaining vendors made available in the "firmware" of the switches/aps/routers or portal (in LGFL's case) Also once you pop a server into the mix, I could see myself sliding into having radius and a CA (to eliminate all those cert errors when managing all those network devices with embedded web servers)... at which point from a "time is money" perspective - I might as well just pay for two perpetual Windows server 2025 licences, and keep the core of the old AD infra running in perpetuity. (less *fun*, but orgs don't want core infra to be fun). Now since *any* step away from the goal of "serverless" clearly results in you either replicating the Windows network infrastructure capabilties on a new linux server, or just keeping you old core Windows AD servers, the only correct* solution is to stick with what is available on the switches/aps/firewall/LGfL portal. *YMMV.
-
To speak to your initial question though, if you've got rid of on prem manamgement and authentication, then the tight integration of MS DHCP and DNS (and AD) is no longer relevent.... so having your switch handle both (if its got enough oomph) and configured to pass queries to LGFLs DNS seems like a no-brainer. But if considering having no on-prem dns server, bear in mind that you find it of benefit to have on prem devices registering in local dns (printers, building management system, doors controllers, wifi APs, switches, phones, ups, franking machines, cashless catering tills, etc) for ease of management and troubleshooting.
-
Firewalls have to convert the hostname to an IP address at somepoint, because unless the filtering is via a proxy, ultimately firewalls make their decisions at the IP/Protocol level. 0365 HVE DNS records have a TTL of 2 seconds, and in systems that are already processing a lot, changing firewall rules every two seconds is going to be a struggle to get reliable. I think this is something Microsoft might have to revisit before the service comes out of preview.
-
Oh wait. You need to upgrade your configuration to eap-TLS. eap-peap is not supported in windows 11 anymore. all your devices will also need their own certificate.
-
On freshly imaged computers? I seem to recall that the initial certificate request/deployment has to occour over a wired connection if using windows 2000 era gpo settings. I don’t recall seeing reference to this in the last decade so maybe it not a thing anymore, but it seems to match your scenrio from what you have shared. Perhaps you are pivoting the device to wireless before it has picked up it’s certificate?
-
Broadcom VMware cease or desist or be Audited
psydii replied to loxford01's topic in Licensing Questions
Push it up the chain to DfE Procurement / Cabinet Office. They are the only orgs of sufficient scale and power to get this sorted. -
When I had the misfortune of having to run my house of a 4g moden for a few months, the absolute killer was devices failing their updates and downloading and downloading and downloading again. I'd have though the smoothwall should be able to provide reports/telemetry to assist in figuring out what is eating all your bandwidth. (its been a busy month here for driver updates following some changes in windows that necessitated releases and tweaks, and if you have adobe updating from the cloud (rather than an on prem update server), that can also knock the numbers up a bit)
-
On a technical note, make sure that you have Windows Delivery Optimisation configured, and Apple Caching Service (if you have iOS or macos devices in play), and look into other web caching technologies (its been years since I've had any within my sphere of control, I'm not even sure wither MiTM proxies do caching these days?)
-
I'd think twice before taking that approach. The cap does make it impractical to use a school's primary internet link, but the danger with a public display of frustration is that Starlink/DfE just pull it entirely. This is one of those times where you need the dfe and starlink to quietly agree to a "unlimited for schools" deal behind the scenes so they (StarLink) can continue to jack up prices for commercial and residential users without those customers really knowing that schools get it "for free". Launching things into space is hard and expensive, and there is only a finite amount of bandwidth, if a customer is using 10s of TB a month, that is 10s of TB not available to other customers... supply and demand, free market economics etc etc. Making a very public fuss that draw public/investor attention to the deal schools need might well scupper the deal. For now, this is a teething problem in a trial/new service and should be dealt with through the private channels.
-
All Teaching Staff Getting Laptops - Anyone got an expectations form ?
psydii replied to mattysmith80's topic in Hardware
I use the "..violate rule 1" line at staff induction (when we're on-boarding large groups, not in a 1:1 session) it gets a laugh and makes the point, and reminds them of rule 1. -
All Teaching Staff Getting Laptops - Anyone got an expectations form ?
psydii replied to mattysmith80's topic in Hardware
I'm pretty sure your refresh strategy isn't going to work in the long term. At a rate of 20 desktops per year it will take you 40 years to replace your fleet. 10 years at a push seems to be the outer edge of what is possible on Windows at the moment, and keeping in compliance with cyber-security insurance policies, that likely reduces that to between 5-7 years depending on the OEM's support policy. Of course laptops will have higher attrition even when considered to have the same refresh cadence as desktops, but then we're into your org's approach to cost/benefit (philosophy again). Our Laptop refresh is also roughly 1/5th of the fleet per year. We get 6-7 years out of each cohort (less attrition), with the oldest (surviving) getting cycled out, which gives us a bit of a buffer. We have contingency plans should the 6-7 year old devices suddenly stop getting firmware updates, but thus far the OEM has been matching Apple in that regard (despite "officially" being out of support). The devices are considered a cost of having people, so I am not constrained to the quantities I predicted during the budget planning cycle. Of course if the spend starts to diverge significant from expected, there are discussions, but IT spend is (somewhat) a function of staffing and activities undertaken (courses, projects etc), and flexibility is required. FWIW in our context a £250 desktop PC is not going to cut it. If there was significant change to the school's vision, ethos, philosophy, core sense of being, and we ditched most of our halo subjects that differentiate us from most of the "competition", then they absolutely would be (I've just built a 4 core, 16G 1Tb nuc for that price), and the laptop vs desktop cost/benefit calculus would need to be reconsidered. But also I'm not at all sure a £250 computer is that likely to be getting oem firmware updates beyond 3 years, though I haven't looked into it.
