psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Related? "Block user policies created in the Microsoft Teams admin center or PowerShell aren’t blocking users as expected" Service health - Microsoft 365 admin center
-
We work in a building that we designed to be securable in zones, and also open to the public out of hours. Unless teachers forget to lock offices or classrooms (both in violation of CP/Safeguarding practice) the building is intrinsically pretty secure. We have serialised keys (so all staff have access to certain rooms, and others rooms are more restrictive, but some keys open most doors, and a handful of people have keys that open all doors) except certain doors are on completely different locks to provide an additional security boundary. Since the IT office has delegated DPO responsibilities, and the IT Team walk the building for other reasons on a regular basis, unsecured doors, or paperwork left out is spotted and followed up as part of routine operations. If the appropriate remedy is not applied, with a follow-up email or two it becomes the SBM or Head Teacher's problem. It never does.
-
On-prem Exchange? If your public IP(s) are not already blacklisted .... You'd need an on-prem mailbox and a custom transport connector for the purpose and would need to make use of an alternative Outlook Profile for the senders. That special on-prem account/mailbox could be given send-as their daily-(cloud)-account. The on-prem server would be configured to send all email not aimed at onmicrosoft.com addresses directly, you'd need to have a firewall/NAT egress rule for smtp traffic from the server to appear from a specific public IP, which would need all the relevant DNS records, and be configured to require at least TLS 1.2. There'd be a chance you'd get your IP blacklisted, but with all DMARC, SPF and all latest security and identity standard on the mx host/dns records you might get away with it. Of course Exchange 2025 is missing in action and New Outlook doesn't work with Exchange 2022, so you'd need the old Win32 Outlook to remain available to pull this off.
-
I was troubleshooting a door entry system today. the controllers run the following services (i.e. Servers) HTTP FTP TELNET SMTP. Since I can upload arbitrary files to the filesystem and thus make them available to any computer that can connect to TCP:80... they are actually unquestionably servers. They cannot be replaced by "the cloud" because they are physically wired to the door magnets, the proximity readers and the firealarm. Maybe alternatives work by connecting out over 443 to a SAAS platform, but last time I checked, replacing all the controllers and the annual licence for keeping the SAAS element up, would cost as much as replacing the entire VM_HOSTs+SAN that ran the school for the last 10 years.
-
I'm sure containers make sense when your running hundreds of them. But when you are a desktop computer technician, you are way more familiar with installing and managing apps and configurations in the traditional manner. Also in this specific case - the problem is needing to configure devices so they can access the internet through a filter/firewall that is not in the control of the local IT Techs/Service. So putting the configuration on the far side of that (in AWS/GCC/Azure) doesn't seem like the best/most obvious place?
-
Perhaps see if you can re-implement the filter as transparent proxy? Pretty sure this is a standard feature of most filtering systems these days. This way the users see an improvement - it becomes zero config from their point of view, and from the admins, you just have to change pushing a proxy setting for pushing a MITM/TLS inspection root cert, which you probably already do because otherwise your wouldn't be able to monitor/filter 95% of your users web activities. - - - Updated - - - This is both horrific and impressive.
-
Every so often I wonder this, then I remember I made them to apply some sort of setting/policy/access control to a cloud-only user. Why did I have a cloud-only user... well that's because I expressly did not want them to be able to log on to a Domain Joined computer. All fun and games until I need to allow the cloud only user to send to a hybrid (i.e. AD managed) distribution list that has restrictions based on AD group membership. Pretty much the only time I regret hybrid. The moment passes and on we go. Sometimes I wonder if I were to security enabled the group-write-back group(s) I might be able to add the "cloud only" group to the equivalent on-prem group - but then I notice the cloud-only users isn't currently represented by an object in AD. Maybe I'll look into this again, maybe I wont.
-
into the main RDP server? a limited subset of standard staff accounts. Never a DA, and only a local administrator via the VM Session. Into servers in general? each member of the IT team has a dedicated server admin account, and that is a Member of Protected Users. Each server has a domain/Universal group in AD called servername_admins and GPO/GPP makes that group the only member of the servers' local Administrators group. Only members of a servers' local Administrators group can remote onto servers. ..except for a couple of servers where we also allow a small handful of users to remote on to poke a service they 'own' if the need to.... The servername_admins groups should always be empty unless an admin is actually working on a server. The dedicated server admins account also need to be members of what ever groups allow them access to the software repositories and documentation folders.
-
Anyone else noticed that both the 2930 and the 5400 are still current models? https://buy.hpe.com/us/en/networking/switches/modular-ethernet-switches/5400-zl-switch-products/hpe-aruba-networking-5412r-zl2-switch/p/j9822a https://buy.hpe.com/us/en/networking/switches/fixed-port-l3-managed-ethernet-switches/2930-switch-products/hpe-aruba-networking-2930f-switch-series/p/1008995294
-
Software Requests and renewal how do you handle this?
psydii replied to AlteredAdmin's topic in Licensing Questions
In terms of the process: Request arrives as tickets into the service desk. Though these days this is often an email in my inbox because I'm the Data Protection Lead and they need to upload student data to the new system or service. The usual reviews occurs (Data Protection Impact Assessment, Financial management (do they have on going budget to sustain this service in years to come? do we already pay for something that does the job?), are there any nasty clauses in the licence/contract particularly around automatic renewals etc? What is the install and deployment process etc etc.) If all the hurdles are crossed, its logged in the information asset register and in the software table in the Service Desk (could just as easily be a spreadsheet). This records name, supplier, 'owner', start of contract, end of contract, review date, and can be linked to a 'folder' containing additional information, for example training materials or specific configurations changed for our implementation or install files. If it is IT's budget, it also becomes a line item there. If there is an action (i.e. a change request) needed to implement, that then gets raised for the IT team to deploy or authorise the app. The service desk sends out reminders 30 days before the review deadline, and the separate financial/budget tracker (a spreadsheet) is reviewed at a cadence aligned with the Finance departments needs. Typically I'll put 'deadlines' on the budget/finance tracker into my calendar by hand. -
Software Requests and renewal how do you handle this?
psydii replied to AlteredAdmin's topic in Licensing Questions
This is exactly what we do, except even though departmental software is "their problem" we track it as well because HoD's come and go but the service desk is forever. Since we on-board new HoDs (whether a full induction for a new member of staff, or showing a newly promoted colleague the ropes for how to access systems and processes that their new role requires), we can advise them of software and renewals they may want to keep an eye on. Finance also like us to keep an eye on things so opportunities for joined up thinking/purchasing can be made where appropriate. Its not unheard of for us to realise that a post holder has left, hasn't been replaced, but they had responsibility for a software package/platform that is in use across multiple teams - in these cases we work with middle/senior leadership to nominate an alternative owner of the service. Sometimes middle/senior leadership think a platform isn't being used because it's 'owner' has left, but the 365 logs show that it in fact is (or vice versa). -
Mutually exclusive options I'm afraid. Stuff that works well with your current device fleet might not work ok after a driver or firmware update, or the laptop/desktop you buy tomorrow. The only cabling I have *never* had *any* problems with is the BlueStream stuff, either the 10m copper based stuff, or the 10m+ AOC 8K (overkill for today, but solves all problems in the universe). Same with splitters, switches and cat5/6 converters, if you need it to work without a problem, Bluestream.
-
They've been updating the other desktops apps quite significantly over the years, but Outlook had the immutable technical debt of legacy (on-prem) Exchange support being at the core of its design, and combined with associated security risks I can see why they're pushing to retire it. But consider how the move to a modern OneNote went, if they did that to Word or Excel, I'd imagine many more CIO's would seriously question whether it was worth sticking with Microsoft over Google. Indeed they've rolled back the OneNote migration back into the formerly legacy Win32 based app!
-
We have a few users here who two or three times a year need to send a few hundred mail-merged emails *from* a 'shared mailbox'. We have always used a second Outlook profile for these users that using the 'shared' mailbox as the primary mailbox for the purpose of this task. We've done it like this for probably twenty years. All the "big" mailshots are of course done with a dedicated bulk-mail platform, but for these ones (less than 2000 email per year, and less than 250 emails per mailshot) it seems crazy to pay/set up something completely new with all the hassles of dmarc/spf etc....
-
100%. If its a desktop based IT suite, any deviation from the above is a step (or leap) in the wrong direction. Though I would say that chomebook-style laptop trolleys have been a huge hit where I've seen them deployed. It allows any classroom to become an IT suite at the drop of a hat - but teachers have to be able to teach from the back and themselves be mobile to ensure they are being used effectively. We see almost 100% utilisation of our IT suites from the technical/digital-media heavy courses these days, everyone else shares the laptop trolleys, some periods we have 150+ laptops booked out and round the building over and above the 100% occupancy of the IT suites for Computing / Design / Media / Music / Art-Photography. (and some of those are actually laptop based these days too - because they cannot have the U shaped PC deployment and they need flexibilty - and laptops are better than desktops if the U shaped deployment is not an o We now only have wired desktops where screen real-estate and mouse control are important for the use-case, and even then Photoshop/Illustrator/Sketchup is most often run on laptops!
-
Based on your description, it think there maybe a typo? I think you meant to write 'old', perhaps a better word would be 'vintage': Sometimes the old ideas are the best ideas.
-
As someone who has done the "wow factor" a few times (1:1 laptops and classroom projectors in 1998, full IWBs in 2001-2, a chance to remodel a school with £25M in 2008, 1:1 ipads in 2012, and a 1:1 remote learning pivot in 2020) ... the best most flexible space for where IT is to be used is a 65m^2+ room with HUGE digital display (typically interactive tv/panel these days) on the 'front' wall, benching round the outside and desks in the middle, and bullet-proof wireless. With laptops and wireless you don't even need to flood wire for power and data! A layout where a teacher can view all the students screen by simply moving their eyes from left-to-right across the room is not to be underestimated. If the teacher can also walk around the room and annotate wirelessly to the screen at the front, then you have all the innovation you (IT) need to provide; everything else comes from the teachers' vision and can evolve rapidly based on the kids, the course, and their experience. The toys are toys, they have their place and purpose, but will come and go every few years. Flexibility is the wow factor. Classroom management of the students and the resources they are to use is key. If you are going for a non-traditional layout the teacher has to be able to have a zero-effort way to check for on/off task students - and some form of remote viewing software is not the answer. If the room isn;t big enough for the U shaped deployment + desks in the middle, then ensure the teachers can teach from the back of the room so they can see the students's screens.
-
try this: https://oofhours.com/2023/12/27/use-the-new-community-modules-for-autopilot/ Here is the repository on GitHub: https://github.com/andrew-s-taylor/WindowsAutopilotInfo
-
We use them as pure InTune managed with the shared device profile. 64Gb is (just) enough. You can almost get away with domain joined/gpo managed if you have them assigned to a single user and keep the apps installed down to just the core 365 suite. But they work best either way when managed through InTune/Entra only. Also on soldered vs m.2, many of this class of laptop can be either. If you were ordering enough you could get them customised to your spec'd. DfE were certainly ordering enough, so it seems plausible to me that initial devices sourced from the channel or already on the production lines might have been m.2 and later on ones ordered direct by DfE were cost-optimised (e.g. slower and soldered flash). Might even been the other way around... I had early production samples from a couple of brands with m.2, but the off-the-shelf models were soldered, but some later DfE ones had m.2 slots. ::shrug::
-
Oops, typo and a lack of clarity of thought. I meant "one notch m.2 whether sata or nvme", I hold up my previous post at 11:04 on this thread as evidence. Not quite as bad as my standard typo where I miss out the word "not" in written sentences.
-
I'm not sure that is correct. 2010-2020(ish?) Macbooks did funky things with m.2-like ssds but one-notch sata nvme seems to be the norm based on a quick search. To be honest I kinda skipped out on the whole sata thing and went straight from ide/ata to nvme when it came to putting stuff together, so maybe I'm wrong.
-
https://pcguide101.com/storage/does-ssd-need-power/ the power comes from a connector from the PSU. That said, the mainboard has an m.2 drive slot. Look up in the manual to check if that is nvme. If it is then you don't need the add in card. Also the card you linked to from amazon is a full height card, it wont fit in that case, if you do need a card, one more like this: https://www.amazon.co.uk/dp/B07FN3YZ8P/ref=sspa_dk_hqp_detail_aax_0?psc=1&sp_csd=d2lkZ2V0TmFtZT1zcF9ocXBfc2hhcmVk appears to have an bracket that is half height and therefor should fit.
-
The one in the first pic is "SSD, M.2 PCIe SSD, M.2 2280, PCIe, NVMe, 1 TB, NAND, AES 256-bit" apparently https://uk.farnell.com/micron/mtfdkba1t0tfk-1bc1aabyy/ssd-pcie-nvme-nand-1tb/dp/3935609?CMP=KNC-MUK-GEN-KWL&msclkid=534cc73974cc1800cfe8a08780af50fb (based on the part number in your photo) A nvme m.2 ssd in a nvme pcie adapter card, with the appropriate bios config should be able to be made bootable just like a SATA drive can be made bootable. The card you show from amazon should do the job. However, it has a lot of capacity, and depending on the motherboard and what else you have hanging off the PCIE bus may have limitations/create limitations and bottlenecks. I have never managed to get my head round what does and does not steal PCIe lanes from the GPU slot or force things down to PCIe2.0 speeds, but someone here might be able to explain that better than I.
