psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Following on from your extremely helpful insight in a more recent thread, @Seb1780 where did you land with this one?
-
Indeed, I think that @PICNIC should commend SLT for making such a courageous decision.
-
Yes. This question could have been taken from 70-221 Network Infrastructure Design which was considered to be the hardest of the Windows 2000 exams. A generic answer is that the AD OU structure should either mirror the organisational administrative structure or the technical administrative structure, and then use group based security filtering to overlay which ever one is not represented by the OU structure. Then Employ loopback processing to support scenarios such as engineering dept member using a languages faculity computer (becuase the are also taking/lecturing in a Language) However, the correct answer depends on "how are things set up at the moment" "which would be the most common configuration that needs to apply?" "which is likely to be the most common set of configurations that will be needed to be tweaked in day to day operations?". Finding the balance really is a local/personal decision. Personally I sort of hybrid my own advice. Users / Computers are in separate OUs contained within a parent OU (for the purposes of scaling out beyond a single school) Students / Staff are in their own OUs. Students are further subdivided into year of entry OUs (simply to make it easier to manage administratively - setting are generally not applied the the YoE level). Computers are grouped into Facility/Department OUs, except IT suites which are their own OUs. Staff Laptops and Student 1:1 laptops are also their own OU with their Own settings. Adminstrative/Office PCs actually tend to be their own OU like Laptops/Suits and if faculty settings are appropriate they get them through group membership. Where there are IT suites and staff laptops that need settings at the dept/faculty level, we apply those at the parent Devices OU and filter by group membership (which is where loopback processing comes in to ensure staff of a faculty get the faculty specific settings when on a faculty device). Works for us very well. A good rule of thumb is that the structure allows for the most common settings to be linked and applied once is the best one, and then use as few Sub OUs and Group based filters as possible to apply exceptions.
-
I've been thinking about this for a bit, but not really got anywhere, hopefully those who have been through the process can offer their experience/learnings? How do you capture your requirements? SLT can be appallingly vague on the details when they have experienced direct reports who do the day to day work in the current MIS for them. But those who do the day to day work, do the work they do because that's the way to do work that they do in the current MIS. How do you identify when a difference will take the form: "oh the new MIS does this differently and we get the same/better outcome" and: "oh the new MIS does this differently, no hang on, its worse. oh we have to change how we do this completely and the outcome we want are almost impossible/impractical now" How much / how does one free up time for all admin / leaders to update their skills, and processes to align with the way the new MIS works? How does the data team (for example) keep up with the day to day demands, while also learning and deploying the new ways? With some very critical elements like cover and timetable, how do you assess whether the new MIS offer is actually suitable for your needs? Timetablers and the Cover teams always seem *very* attached to their current tools. I've seen timetables abandoned and completely restarted in the legacy tools by those who thought it a good idea to try an newer alternative in the past. What are reasonable success criteria for a migration project?
-
I’m not sure I wanted to learn that lol. Definitely agree a good card at a good price has been long overdue.
-
No, but a couple of months ago I caved and jumped up from a 590 to a 7700xt. When I saw the news about the B580, I was momentarily sad (I didn't really need the perf of the 7700xt but wanted the RAM) until I heard that pricing for the B580 in emea is not in fact on par with the 4060RTX but instead aligned with the 7700xt! Which makes it a daft purchase in the UK for now.
-
And when coders had to work within those limitations, we got per-user vpns and applications that 'install' into AppData.... and also why everything is now web based and the power of the personal computer and applications are diminished, replaced with the anchor of subscription based pricing on a per department/user level.
-
What HE's obligations currently are is outside of my scope of expertise. BUT... Increase duty of care towards its students is certainly on the agenda. https://hansard.parliament.uk/commons/2023-06-05/debates/9BA59E93-4342-4AD6-BA94-379DCA6A24E0/HigherEducationStudentsStatutoryDutyOfCare Prevent certainly applies, and then the are the general content filters you should expect a workplace to provide to minimise the risk of exposure to offensive and harmful materials (from a HR/Liability perspective). So the question might not be quite so off kilter, and KCSIE isn't the worst starting place for thinking about what steps an institution hosting people who months ago were legally children should be considering.
-
We don't stop them, but there are up to five levels of automated review. LGfL Netsweeper, SmartScreen, Defender, and Defender ATP. Furthermore Microsoft Purview Compliance is increasing in the mix depending on what is done with the file after it is downloaded. Sorry, six levels. Applocker might have a view on what happens after a zip file is opened.
-
What do people use for cloud-first shared device authentication (entra/intune / chromebooks/Workplace / Apple/mdm etc)?
-
Moving from 365 A1 Plsu to A3 - can't assign licenses
psydii replied to Sheridan's topic in Cloud Services
Last time I checked, without OVS users need A3 to enable edit capabilities inside the desktop apps. AFAIK the Share Computer Activation use case here is to prevent hot-desking users incrementing their activation count (an A3-E5 has a limit number of product activation, and if you hop between a dozen computers a week you might find apps stop working if SCA isn't configured) -
How to make an Admin only for local computers?
psydii replied to jmair's topic in Windows Server 2022
We also have all the local admin accounts set flagged as Protected Users in AD, so their auth tokens expire quickly, hindering replay attacks and lateral movement paths even if the account is and admin on more than one computer. The main administrator account on each machine is also protected by LAPS (classic for now), and as per jmak, and used only as a break-glass account. -
How to make an Admin only for local computers?
psydii replied to jmair's topic in Windows Server 2022
If all the staff computers are in an OU that does not contain other types of computers: Create a Universal Security group, and into that put the users you wish to be admin. (call it something like ladmin_staffcomputers) Create a GPO (or use existing staff computers gpo if its scope is sufficiently narrow) Use GPP within that GPO to add the ladmin_staffcomputers to the local administrators group. It is a very similar process if there isn't an OU and all the computers are comingled. In addition to the ladmin security group, you will need to create a security group for the computers e.g. "computers_StaffComputers" and add all the staff computer accounts to that. Then you will need to create an empty GPO (as above) and filter it by security group (the security group being the "computers_StaffComputers" you just created. Now make the GPP settings as above. -
Moving from 365 A1 Plsu to A3 - can't assign licenses
psydii replied to Sheridan's topic in Cloud Services
You need to unassign the A1 licence before the A3 can be applied. -
If you are just needing to dump the attached documents to some folders, RecordLink eXporter cost way less. It is well worth looking at if you still have SIMS and have large enough school that sending student files is a frequent activity. It saves us several hours a week. Recordlink - Home
-
FTFY. Although, typing in those 'corrections' leaves me conflicted.
-
Definitely a holiday job, but in-place LTSC to LTSC should work. You might want to have inventry on standby to remote in post install and fix anything/everything that might have broken. (in place upgrades basically install a new OS side by side, replay all the installers into the new OS, rename a few folders alter the boot manager and then boot into the new OS. Fine for 99.5% of software, but the low-volume-installers (such as you find in little bespoke systems like cashless, visitor management, scan to sims etc) may have quirks that result in them needing to be manually re-installed into the new OS. Worst case: the software comes over automatically, but is broken in ways nobody has seen before. Might be better to get Inventry Support to confirm a backup of the database and configuration, then you wipe the machine and install windows clean, and get Inventry Support re-install their system and restore the config and data from backup?
-
The following doesn't describe the scenario faced in this thread, however it does indicate that there have been recent kerberos/certificate handling changes that (if I were to guess) may be being enforced in Server 2025 that are otherwise compatibility phase: https://support.microsoft.com/en-us/topic/kb5037754-how-to-manage-pac-validation-changes-related-to-cve-2024-26248-and-cve-2024-29056-6e661d4f-799a-4217-b948-be0a1943fef1 And this page seems to recommend reviewing CA/DC certificate configuration on domains that were commissioned pre-Server 2016: https://dirteam.com/sander/2022/09/14/todo-upgrade-the-certificates-for-your-windows-server-2016-based-domain-controllers-and-up-to-enable-windows-hello-for-business-hybrid-scenarios/ perhaps the older templates etc are in play? Do we know if a green-field 2025 Domain exhibits these issues?
-
On the other hand with all of you jumping ship, and our simple single site on-prem requirements, I've found Inventry support to be dramatically improved these last few months.
-
Welcome @johndball. That seems to me to be a promising set of steps. It's probably worth all those with older domains checking (and *testing* deployment of) these settings well ahead of deploying server 2025. I wouldn't be surprised to see this getting written up into a blog or perhaps a page on learn.microsoft.com if it gets positive feedback here. On versioning. In lieu of the Advance GP management tool (depreciated?) I've always insisted that GPO comment field contains the change request ticket number, and GPOs are backed up before *any* change to a common folder, and all gpos are items in our CMDB (serial number = GPO guid, name/description = the GPO's name). This level of change control/management seems to be almost impossible in InTune though
-
Seems to be up, but slow as of about 20-30 minutes ago.
-
Cloud-only service account and conditional access to log onto local server
psydii replied to CHiLL's topic in Cloud Services
I had a "we need global admin without MFA" response to a change request I made recently. Seems so odd to me, I thought that the method papercut uses would be transferable to the set of rights needed to perform the sort of user/group/mailbox customisations salamander needs. Maybe I missed it, but I think a support/blog/post from them might be in order to explain what appears to be a retrograde step in their approach to security. -
I question the truth of this. It was a common argument for years and years here. Eventually after much anecdotal/empirical evidence showing was collected showing otherwise, we just pushed ahead with going for an app. Special steps are taken for homes where we know this doesn't work; it is a tiny tiny percentage. It was vital that it was an app that 'does everything'. It shows homework, attendance, behaviour, progress etc - it has become a one-stop shop for almost all communications, except ironically, it doesn't support a 'shop' and also despite its primary function is not "show my homework". The app was rolled out via parents evenings over an 18 month period before it became the main conduit for school communications. For urgent, extremely time-sensitive matters messages will be sent out through the platform, and augmented with SMS. FWIW IMHO the move to using an App required a powerful voice on SLT who believed the assertion (that many parents couldn't/wouldn't install the app) to be true (because it was in 2009) to leave, and be replaced by someone whose opinions could still be swayed by data.
-
Deja vu? /forums/wireless-networks/229570-aruba-515-poor-wifi.html
