psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Apropos of nothing ::cough:: Is your school ready for a multi-day regional/national power outage - one where where internet and cloud also end up offline?
-
Its the wildcards I think. I'm seeing similar errors with winget where hostname/subdomains change e.g. server1.cluster12.MITMexcluded.domain vs server23.cluster11.MITMexcluded.domain etc. It seemed to start about the same time they blocked Generative AI services by default.
-
What RAID setup do you use in your school?
psydii replied to Sonic007's topic in Windows Server 2022
This can actually be quite a high bar given the sort of money many in this sector thinks is appropriate to spend on IT Support. Of course if I buy a NAS/SAN and its underlying tech is ZFS, that's great, the vendor will support it and my school. But roll-your own storage platform is perhaps something that school tech's shouldn't be doing. At this point though, short of support staff suppliers like ESP, or school IT solution providers like XMA weighing in with how many of their people have the level of ZFS (or Storage Spaces Direct) knowledge that could replace what you get with 24/7/15min HP SAN/Server support, I think we are at an impasse. -
What RAID setup do you use in your school?
psydii replied to Sonic007's topic in Windows Server 2022
Yup. If things go sideways, I *want* it to be someone else's job. I also want to be able to walk away at some point and have reasonable confidence that SLT can hire a suitable replacement. Maybe it is indeed because I sit in an org that is not small, but not huge: I have too many things under my remit to expect "virtualisation and storage guru" to *necessarily* be on the CV of otherwise capable candidates. Indeed many things I am responsible for were designed, implemented and backed by 3rd party support to avoid having an impossible list of "must-haves" on the JD. -
What RAID setup do you use in your school?
psydii replied to Sonic007's topic in Windows Server 2022
Scale! Most here have 10 times fewer users. If one has 20,000 users-colleagues one is likely have a budget large enough to have a couple of people on staff who are (somewhat) dedicated to the server/storage infrastructure (or already be fully cloud/SAAS) . The rest of us need point-and-click, setup-once-and-never-think-about-it-again, where SLT can hire in any old tech from ESP who can rock up see the blinking red lights and pick up the phone to HP / Dell / Lenovo and get immediate support. I didn't roll our own storage/virtualisation platform with proxymox/zfs for the same reason I didn't with hyper-v/storage spaces direct. *I know i COULD have* but I don't trust the organisation to be able to hire in alternatives with the right skills should things go sideways (sudden death due to an unfortunate encounter with the Clapham Ominbus, annual leave etc). Instead we bought in basically a standard solution from a vendor that looked exactly like the standard solution from all the other vendors. There is some irony of course, now Broadcom have thrown the SME market under the aforementioned Clapham Omnibus. Perhaps next time I consider storage/servers I'll end up receiving quotes for a load of proxmox/zfs based solutions -
Counter point, how much would it cost to hire people to do the back-end admin work that these tools eliminate. Counter counter point, as long as we have at least three/four big players in what we're loosely referring to as the MIS market we're in the sweet spot (for us customers) of both supplier scale and competition when it comes to pricing..... as long as we (the customers/market) keep choosing the best value combination services and don't accidentally recreate the (effective) single supplier dominance of the 2000/2010's.
-
Yes, this is supposed to eliminate the 2025/win11 machine account password problem. However the information released suggest this is update contains a hard-coded work-around for some the modern behaviours and capabilities that caused the problem, and further work to get these underlying codependencies properly interacting is expected to be undertaken. For most Domain Admins, all we need to know is “computer account password problem” is now fixed. Those who genuinely need to know more (because they needed the new behaviours) likely have tickets open and their own account managers at Microsoft to liaise with. Of course since the problem can take 30 days to manifest, it will be a while yet before we can be sure that this does actually fix the problem.
-
we found the registry hack to launch taskkill as the debugger worked very well for us. For those wondering, several entry points into the Recovery Environment, do not actually start WinRE initially, instead they tear down most of the current windows environment and launch a special shell "bootim.exe" that looks a lot like the WinRE gui, and has many of its functions. This is why simply disabling winre with reagent /disable, and/or changing options in the boot configuration database editor is not enough. We use all three. That said, ensuring a device is bitlocker encrypted goes a long way to closing off many of the work-around that students find even with almost everything around the Windows Recovery environment locked down. For those who might find this thread in the future, here is a list of other things we do to protect the integrity of the Windows OS and its security: Bios/EUFI password - required to enter /edit settings Bios/EUFI boot device options menu password: required to enter the boot device options menu Boot order configured for HDD/SSD/NVMe with the windows partition on it, ONLY. USB/Network boot disabled. The Windows 11 security defaults around Virtualisation/Boot/App/OS Integrity. Bitlocker. The WinRE disabling configurations with REAGENT, BCDEDIT, and the BOOTIM/TASKKILL trick. Applocker rules restricting apps to launch from only locations that users do not have RW access (with exceptions, but these need to be carefully managed - don't do something silly like allow all apps signed by Microsoft to run from any folder, as this can be chained against other tricks to launch things you thought you'd restricted!) Have I missed anything?
-
14 years after I first noticed it, and exacerbated by the demise of the technet blogs and RSS feeds, I am still puzzled how Arthur manages to remain so on the bleeding edge of update news. To comment on this particular update though, Microsoft seem to have "fixed it" with a work-around, excluding certain things from protection by 'Credential Gurad.' The patch notes I think being the first place Microsoft announced the disablement of this feature, and its new, quirky spelling: April 8, 2025—KB5055523 (OS Build 26100.3775) - Microsoft Support [Authentication] This update addresses an issue affecting machine password rotation in the Identity Update Manager certificate/Public Key Cryptography for Initial Authentication (PKNIT) path. This issue occurred particularly when Kerberos was used and Credential Guard was enabled, potentially causing user authentication problems. The feature Machine Accounts in Credential Gurad, which is dependent on password rotation via Kerberos, has also been disabled, until a permanent fix is made available.
-
Esports Local Authourity Filtering and Firewall issues
psydii replied to PotNoodleTech's topic in Esports
What seems to be the problem (on a technical level) with LA-class filtering/firewall and esports? If it’s that they won’t allow UDP any-any rules, it’s not an LA/RBC problem, it’s that a local network manager isn’t a full time network/security analyst and might not fully understand/appreciatethe risks involved in opening things up so wide. Don’t forget LA/RBC firewalls and their administrators have a much broader perspective on the harm that can come from such open rules. if it’s that they won’t open up for *specific* endpoints, or urls, or filter by internal user…. Again that’s hard (and expensive) at scale, but should be do-able in 2025. we’re in LGfL and there are a couple of PlayStations on site that have their own rule sets/policies, and seem to work just fine. There are quite a few “moving parts” to make it work, but we are able to have rules for those specific devices do not compromise the rest of the network. perhaps it helps we have our own internal ip range, dhcp scopes, swtich/router access control list, and firewall behind the LA/RBC managed IP range…. …but in a even simple LA/RBC managed environment, you ought at least to be able to have specific IPs allocated to specific devices from which esports is to be allowed, and perhaps even have time based rules too? Pretty sure this was possible/normal 20 years ago! -
Have others been able to verify @petben's experience? Specifically via boot/logon monitoring with procmon? This feels like it would benefit everybody if a few people could open a ticket with Microsoft...
-
We're getting old. I saw my first mac at a friends house in '89, actually I saw *three* macs at that time, his dad was very much into them and had basically bought each new model as it was released. His dad's retired, but we are only middle aged!
-
as per @olliedawg @julian and @StephenPink. DHCP logs can be useful for cross referencing when investigating incidents, so make sure you have logging enabled what ever platform you choose. If you don't already have it set up you will also need to configure an IP/UDP/DHCP Helper/Relay in the config of each vlan/ip interface on the core-switch/router so that DHCP traffic from each VLAN to be served is relayed between the clients and the servers. You will need both DHCP servers in the config otherwise one wont be used *and* a random-but-non-trivial amount DCHP requests will timeout.
-
What RAID setup do you use in your school?
psydii replied to Sonic007's topic in Windows Server 2022
Now waiting for name_redacted to pop up and berate us for having to choose between RAID6 or services that can be taken out by a monolithic disk/server failure, when we should be using kubernetes or something. -
Just interested to hear from those who have done it: how did you have schedule migrating the timetabling and exams entry/results processes when switching MIS? Also did you bring across history results into the new MIS, and if not what did you do to preserve this data?
-
Periodically people complain about something. I email SLT to ask them how I should prioritise it given project x, y or z that they already have me working on. The pictures remain. We do reset student pictures to those from the MIS periodically, and any really inappropriate ones get reset immediately with sanctions. If they 'just don't like it' then re-shoots are done promptly. But then again we also don't shy away from Job Titles or Teacher's first names in the address book either since if there is nothing special about knowing a teacher's first name, it holds no power, and does not impact behaviour management. Students don't, and by cutlure here shouldn't, use a teacher's first name when talking to our about them. Seems to work just fine.
-
Traditional desktop apps do not work well in pure cloud first environments (chromebooks get around this by not running Windows or Mac apps *at all* so that option is off the table before you even start) You need OneDrive client for this - there is guidance on how to unwind the block the default shared-device policy puts on OneDrive client starting. Onedrive then runs with the default options (so files are not downloaded until accessed, and files are uploaded automatically) If your devices have less that 512Gb local disks, you will need *extremely* aggressive Storage Sense settings, and profile deletion (the latter comes from the default shared-device policy). The biggest change you can make to support this is requiring seating plans - student use the same computer(s)/laptops week by week so the setup and sync time is minimised and their is only one set of their work on disk on site. Technically we have mandated seating plans, in practice teachers allow (because the need it) some flexibility, but the fewer moves the more reliable the IT (and the student behaviour) is!
-
I'm not a Bromcom customer (at the moment) but I would not use 365 smtp services for any bulk email. Even the 365 "high volume" smtp service is limited to 2000 recipients per day, and this limit is coming to all mailboxes in October 2025. At the moment a single user/mailbox is limited to about 30 recipients per minute. So systems sending though exchange online need to behave gracefully with the smtp server tells them to back-off for a bit. This might be an avenue you can take for troubleshooting: Continuous error throttling for SMTP AUTH submissions in Exchange Online | Microsoft Learn More info: Exchange Online limits - Service Descriptions | Microsoft Learn Exchange Online to introduce External Recipient Rate Limit | Microsoft Community Hub Manage high volume emails for Microsoft 365 in Exchange Online Public preview | Microsoft Learn Does Bromcom integrate with GOV.UK Notify?
-
SIMS Crashing for One User Only When Completing Register - Deadlock
psydii replied to ICT-Joe's topic in MIS Systems
Long shot - layer 1/2 network problems? Run wireshark to get a capture and if there is loads of black or red on the screen bad things are happening. If there is nothing quite that obvious,m compare the captures between the two systems and look for notable differences (if you are not experienced in wireshark - just go a bit Neo and look for glaring similarities/differences inthe patterns it makes on the screen when you quickly scroll through them!) -
We had a bit of oddness yesterday with search (particularly outlook), I figured it was related to the Purview issue - as it seemed (I didn't bother to cross check) from memory that those having issues were those who were also involved in purview cases, and the issues were transient/inconsistent. However specifically relating to your error message that you posted: TenantAccessBlockedError - Microsoft Community Might be worth going through that checklist. Though perhaps the rest of the error you see seems to me more like a problem starting Exchange services after a back-end patch so ::shrug:: If it is still happening after 10 minutes definitely raise a support ticket via the admin portal. If you can't get to the admin portal call your CSP and they can take it forward on your behalf.
-
SIMS Crashing for One User Only When Completing Register - Deadlock
psydii replied to ICT-Joe's topic in MIS Systems
Timeout settings for in sims/connect ini on that one machine? -
Windows 11 School Devices Wifi - Unable to Connect to this network
psydii replied to Theldron's topic in Windows 11
Windows 11 credential guard is on by default. This breaks EAP-CHAPv2 if you are using EAP, you likely already have NPS and a CA from where you can automatically deploy machine based certificates. For us it was trivial to tweak the config to light-up the eap-TLS option and push out an updated gpo for the new authentication scheme. -
I just replaced a toner cartridge installed in 2018, it’s was the second cartridge the printer has had since we bought it in 2014.
-
I don't think I ever quite understood the connection between "thanks" "reputation" "post count" and the rank achieved. For a moment I though reputation/thanks count had gone but i found them still there on the profile page. I quite liked being able to see everyone's reputation/thanks-to-post ratio as a proxy indicator of quality/trustworthiness. Hope this can come back at some point.
