psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Giving Teachers/Heads of Departments Access to Students One Drive
psydii replied to SeeFights's topic in Cloud Services
That looks easier than when I had to do it this way: https://alexandervvittig.github.io/2016/11/09/add-a-group-to-site-collection-administrators-for-sharepoint-online/ things have definitely improved in the last few years. We only ran that once, and the last set of students who's onedrive are accessible to Teachers are in year 13 now, and half of them joined after we stopped doing it. Teams Assignments really has been the correct solution for at least the last 5 years. -
Is it really downloading all their files, or is it simply leaving placeholders on disk so they appear to be there but in fact only take up a few bytes each?
-
Giving Teachers/Heads of Departments Access to Students One Drive
psydii replied to SeeFights's topic in Cloud Services
Yes. Its getting down into the weeds of how SharePoint really works, rather than the dramatically simplified model that 365 presents. Really, Assignments in class Teams are the better option than trying to leverage the "Old Magik" of SharePoint's legacy security model. -
Giving Teachers/Heads of Departments Access to Students One Drive
psydii replied to SeeFights's topic in Cloud Services
Each user’s OneDrive is in fact its own SharePoint site collection. -
Giving Teachers/Heads of Departments Access to Students One Drive
psydii replied to SeeFights's topic in Cloud Services
Students doing work should be doing work in Teams Assignments. Your MIS should be able to link HoD/SLT to courses and your SDS process should be able to mark these HOD/SLT as Owners of the relevant class Teams. Completely solves this problem. (as mentioned above you can do something with Groups and Site Administrators, but this is the wrong way to solve the problem in 2024) This thread should be a useful starting point for a modern Teams Assignments based approach for students digital work: /forums/office-software/237668-coursework-teams-onedrive.html -
Existing laptops struggling with new CA WiFi rules
psydii replied to ITGuyNW's topic in Wireless Networks
Do they definitely trust the root ca? -
If using the Assignments App within the Team (rather than accessing the folder structure directly), yes submitted work it safe from accidental deletion by the student. If you are using the Working Files folders directly, the usual protections for SharePoint apply: 90 days after it is deleted by a user, it is irrevocably gone forever. You might consider retention policies if the work is very important.
-
Checking filtering reports - legal implications.
psydii replied to sigma's topic in Internet Related/Filtering/Firewall
Yes. If your computer downloads it (in the technically pedantic sense) while checking a suspicious link you are within scope of this law. Our filtering/monitoring platform uses language that increases in "alarm" based on what it evaluates the severity of the material to be. Anything that crosses a threshold isn't reviewed, but instead escalated to the CP Lead who will call the student and have them review (verbally, not in the ocular sense) their own browsing/chat history. Stay well well away from anything that might cause your computer to access these types of images. This is also why (generally) the urls of CSAM and Extremist materials are managed at a trans-national / regional level . Your filtering provider should not be sharing those with you. In the UK they operate under the following codes of practice, which are derived from work by the US and EU. https://www.gov.uk/government/publications/online-harms-interim-codes-of-practice/interim-code-of-practice-on-online-child-sexual-exploitation-and-abuse-accessible-version https://www.gov.uk/government/publications/voluntary-guidance-for-internet-infrastructure-providers/voluntary-guidance-for-internet-infrastructure-providers-on-preventing-terrorism-online-accessible-version -
Looking for a new MIS system - updated thoughts on Compass?
psydii replied to lookingforanMIS's topic in MIS Systems
We're a SIMS school, but FWIW our "new" timetabler (the person) was struggling with 'impossible expectations' from the school, (we're a Nova kinda place). Four beers into a Friday evening I suggested they take a look at Timetabler and Options - 'it couldn't hurt'. Turns out it could do what the school wanted, and that was something that 20 years of previous Nova timetablers had all failed to be able to. However it was deemed too late to scrub the provisional TT for 2024-25 and so we're mostly using Nova still. I believe that they did use Options in some capacity. We have a very broad curriculum and alt curriculum and sixth form, and a "higher than national average part time teaching staff". Its quite possible that we'll be using Timetabler etc with SIMS 2025-26, and if that is successful it removes the last SLT objection to moving entirely from SIMS. -
We have both pure Intune/Entra and pure AD/CM managed devices. Horses for courses. We have a fleet of laptop trolleys (I know, 2006 called and wants is strategy back), these work *really* well as intune managed devices - we don't offer printing or any access to legacy apps - its all fully digital web based with 365 auth or nothing. Any device set that requires classic win32 apps is fully AD/CM managed, though we are exploring hybrid for some scenarios. We are all familiar with the classic/legacy set up - and how much of a pain it is trying to make that work via pure intune - my solution: don't bother. The legacy stuff will eventually age out. But I think there has been a shift (again) at Microsoft and they understand that AD/CM (maybe hybrid?) is really here for the long haul for many use cases. CM is pretty mature and workloads only move to intune when it makes sense. Server 2025 has a lot of AD work going on, so for now, hybrid and on prem is here to stay. If we could ditch legacy design (and thinking) and capabilities that AD/CM offers, intune would be fine, but it's Windows and we expect the flexibility that AD/GPO/CM offers. IMHO the key problem is actually fundamental: all MDM's are built from a technology stack that was designed and conceived to manage pre-iPhone smart phones, And Entra (and Google's equivelent) were designed by people operating at a global scale. This does not align well with medium size orgs that expect to shape the core IT service to their needs. Its fine for very small orgs or very large/global orgs but most are in the middle and the limitations are rough.
-
Cloudstrike, Azure, Google, etc. When cloud computing goes wrong...
psydii replied to Koldov's topic in General Chat
Microsoft release a new recovery tool to assist in recovering machines impacted by the CloudStrike update. https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959 This new recovery tool can be run from inside WinPE from existing PXE Boot infrastructure such as Configuration Manager, used to create an emergency PXE Boot server for the purpose, or booted from USB that it helps you build. Even if you don't have cloudstrike, I think this tool might be worth a look - just to see how it's put together, some of the techniques it employs might be handy for solving other jobs around the place! Of course you still need to be be able to get to the bitlocker keys - no keys, no boot. (Though there have been rumours in some configurations safe mode is reachable without keys, allowing for recovery with the local administrator password, but without the bitlocker keys.) -
Cloudstrike, Azure, Google, etc. When cloud computing goes wrong...
psydii replied to Koldov's topic in General Chat
Yes the cloudstrike element of the last 24hrs is not intrinsically a cloud problem, but its impact is due to broadly the same flaw as relying on a single cloud provider - a lack of diversity in the eco system. Though one might argue the minimal impact to most education establishments in the uk suggests perhaps we've got enough - but is that because edu (mostly) can't afford cloudstrike's products, and the 365 outage was basically overnight and mostly in the US? That said, looking simply at the timing, and the (fairly) swift recovery/rollback, it wouldn't surprise me if it turns out the 'configuration change' in azure that brought US-Central down along with a significant chunk of 365 may have been the deployment of VMs with that contained the cloudstrike update. -
Cloudstrike, Azure, Google, etc. When cloud computing goes wrong...
psydii replied to Koldov's topic in General Chat
Our Business Continuity Plan requires diversity within our back-end platforms for precisely this sort of thing (the azure wobble). We have two telecoms providers, two sms providers, and can get to core student and staff data through three platforms. Files and email are all on a single provider, but with local caches of 'hot' data we can survive a temporary cloud outage. We could even bring email up with on-prem dialtone mailboxes if our cloud provider looked like it was going to be down for too long. Key cloud mailboxes and shared folders are backed up separately and could be migrated to the other provider of these services for education with "relative" ease, not that that's relevant in this particular scenario. But I'm definitely reviewing our endpoint protection diversity following this, I need to make sure a bad update can't take down our imaging/software deployment platform *and* our end-user devices at the same time. Not sure whether the cloud-platform providers would be happy to confirm what their endpoint-equivelent protection platforms are. -
If you’ve got entra connect set up right hybrid join just happens and that what make sso for OneDrive work. On a client device what is the output of dsregcmd /status? (As both a normal user and as local admin)
-
Is BitLocker encryption compulsory for schools?
psydii replied to aia125's topic in Data Protection & Information Handling
Bitlocker is on by default for almost all editions of Windows 11 from 24h2 https://www.tomshardware.com/software/windows/windows-11-24h2-will-enable-bitlocker-encryption-for-everyone-happens-on-both-clean-installs-and-reinstalls As other have said/ alluded, when you have a breach, what is your justification for not having your devices encrypted. What ever it was, it was wrong. -
I’ve found that Amazon basics has been an extremely reliable brand for this sort of thing. Not sure they have a hdmi/displayport cable long enough though. As above, optical would be better, which I don’t thing Amazon Basics have in their range. Maybe look at “active” and directional cables, these tend to have better engineering behind them. Is UsbC an option? Not what you want to hear, but since Amazon stopped their 10m hdmi cables, we’ve ended up buying very expensive cables to get things consistently reliable here
-
Using in-box tools only: If the ssd supports TCG OPAL 2.0 then you could just enable hardware encryption and then wipe and reset the drive which in effect throws away the keys rendering the data unrecoverable. To go a little beyond that you could then re-initialise the drive, and then in Windows use the cipher.exe to overwrite the free space again. https://www.thewindowsclub.com/cipher-command-line-tool-windows followed by defrag - optimise drive (which forces retrim if the os hasn't already done it) If you have SCCM set up for OS deployment via a winpe boot image, you might also consider the Bios reset of the disk and a tpm reset, followed by a custom Task Sequence to partition and encrypt the volume again followed by the command "manage-bde -wipefreespace C:" just to be sure.
-
Is BitLocker encryption compulsory for schools?
psydii replied to aia125's topic in Data Protection & Information Handling
https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/laptop-desktop-and-tablet-standards#devices-should-be-safe-and-secure I'm sure this used to explicitly call out the need for encryption, but it seems to have been removed. However it cites https://www.ncsc.gov.uk/collection/device-security-guidance as guidance on how to achieve this standard, and *that* does state that encryption should be applied. The GDPR's impact is covered here, with a check list to self-evaluate your posture. I really don't see how you could end up in a place where a school's data protection policy doesn't implicitly (or explicitly) require you to encrypt all devices. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/a-guide-to-data-security/ There is wiggle room (assessment of feasibility/cost etc), but if your devices have a TPM / Secure Enclave / Equivalent they should be encrypted, and your policies should state this. We still have some devices which do not have TPMs. Staff are not permitted to use these, and they will all have been replaced by September. -
I imaging it is because Bromcom have gone head to head legally with SIMS at least once and the DfE stepped in before things got too expensive with the lawyers. Perhaps this time they have too much at stake to take that risk. So this time we have Arbor taking the risk, and Bromcom attempting to prove that the legal, api-based method is not possible, together they bring the case forward that DfE/Competition Commission need to step in.
-
Parents rights to access a childs education record
psydii replied to Ditto's topic in Data Protection & Information Handling
If its recorded in your MIS then it would be hard to argue it isn't covered by The Education (Pupil Information) (England) Regulations 2005. We release request for these records without referring to the child for permission. If the request goes beyond the scope of an Education Records Request, then it (generally) requires the pupil's consent (if over 12). Looking back over our logs, if there is a records request for an (ex)pupil who is now over the age of 18 we treat that as a data subject access request and require the ex-pupils consent. If we got push-back, we'd throw it over the fence to our outsourced DPO who has a team of people with letters after their names to provide their professional advice on a case by case basis. My opinion is that he Regulations specifically include ex-pupils, and parents are (generally) still parents even after the pupil has left and is over 18, so probably are forevermore entitled to that data; but there's no harm in getting the ex-pupil's consent, and if this 'scares off' the request then they probably didn't have best interest at heart. -
Looking at the Damon's clarification, all that is necessary is screenshot evidence that you could use the stated tools to extract the data - you don't need to supply the code or an application. I don't think they are trying to get the community to solve the problem per-se. I strongly suspect they are expecting the problem as defined to be unsolvable via the API/Reporting tools they are allowed to use, and this is an exercise in demonstrating that. If it turns out that someone here (or the other place) is able to demonstrate its possible, then that person collects the money and Bromcom (and others) move on.
-
That only took 5-7 years to port the capabilities to the dotnet version. Their cloud platform has taken 12 years and isn't yet as capable as the 2002 demos of SIMS.net.
-
New Laptops - Physical security and accountability
psydii replied to AndrewPowell's topic in Hardware
We run our trolleys like science manage their equipment/stock. Technician dedicated to booking, delivery and (physical) management of the devices. On busy periods all techs assist with deliver/collection. For some very busy periods we co-ordinate with trusted teachers and they might collect their own trolley. Trusted teachers are something we figure out over time. Trusted Teachers might also hold a trolley if they have a non-contiguous booking. The tech responsible keeps a close eye on the daily cover sheet , since cover not supposed to assume their normal access to IT (but we are flexible for trusted supply/cover teachers.) We also have trolley permanently deployed in departments whose entire course requires access to IT almost every single lesson, these are practical subjects and have a technician who looks after them. These departments are charges for repairs. The Head and finance managers have to be fully bought in to a) the necessity of the trolleys and b) accountability of the teachers. The necessity for us is the breadth of academic offer and the flexibility in the timetable we prioritise is not possible to deliver without 50% of our student IT being mobile. Our break-fix workload has actually gone down over the last three years since we deployed the intune managed laptop trolleys, and the team is fitter for all the walking they have to do. -
Which one, what setting was causing that behavior?
-
Is your domain controller holding the PDC(e) role ok ?
