Jump to content

psydii

Members
  • Posts

    5,195
  • Joined

  • Last visited

Everything posted by psydii

  1. Two thoughts, I wonder if there has been a change to the API license terms, perhaps only impacting one or two (former?) ESS partners. I've not looked into what Wonde and the 3rd parties that use it are able to do, but the structure of the SEN/HR records does seem to me to be little janky when run through a third party service. The ability to get the data into the third party has seemed... lacking... and the ability to sync data back, limited. Do they use the API or are they also only allowed to call through the reporter tool?
  2. Some people (I understand) have the Smoothwall do all the routing, and it has an IP interface in all the VLANs. I'm sure those that do this can talk you through how to set this up. Another way is to have the core switch handle the internal routing between the subnets (with suitable ACLs to prevent say the BYOD subnet being able to send traffic to your MIS or other sensitive servers) Devices in each internal subnet/vlan should have the core switch's ip address (in that subnet) set as their default gateway. (Typically this is done in DHCP scope options, but needs to be done by hand for any manually configured IP stacks e.g servers, printers, door entry systems etc.) The default switch should have a default route set to use the internal IP address of the smoothwall. The Smoothwall then NATs traffic between its internal interface(s) and external interface(s), with additional packet/content filtering as required.
  3. Anyone altering the timetable or running reports that pull data across multiple areas? We find it always has a slow down around census and large curriculum / timetable changes (because attendance marks need to be remapped). What's the underlying disk situation? Are there snapshots running? Do you have a 3rd party attendance or other integrations that might run during the day? Can you try turning these off (in a systematic way) to test if they might be a cause? We also get time outs and slow behaviour when the backup is running.. so might be an idea just to check that's not happening.
  4. We slice and dice the original search results, using filtering and tagging and merge them to additional result sets. We also find that if you search within the initial "Result Set" for say "Angela" the tools include "nearby" results likely to be relevant, so if the initial Collection created a result set that contains all combinations and permutations of "ang" and "angela", you then filter within the Result Set for "angela" you will find that the view it returns included emails that DO NOT actually all contain "angela" but do contain "ang" when it might have been used in context to refer to "Angela" (and also often other spurious results - but when starting with 100,000 items getting it down to 8,000 before having to read each one is a win).
  5. Others may have fought with this to achieve closer to what you want. However, to answer your questions about how we do it and what I meant: - KFM: Not on the intune shared devices. We do an equivalent on the AD/GPO managed devices, but using a mechanism that predates KFM. (If I was implementing it now I'd use KFM for the AD/GPO devices) - We use the Shared Device option. We do not use the Shared Device with OneDrive policy. This I believe does not force the "no local storage" option, but prevent the OneDrive sync client from running. - Windows hybrid joins by default if your ad and 365 instance are linked via AAD/Entra Connect. We use Configuration Manager to on prem software deployment (and monitoring). We have a test group where we co-manage them. This co-management mode is what I meant when talking about hybridising in the future.
  6. Yes we have it working well. To address the issues you listed 1) don't do that. Just access via the web. 2) don't do that. Just take the vanilla OS, settings use them. 3) don't do that. Use Machine policy only. Basically its not a replacement for traditional AD/GPO managed IT Suites. But if you can get away from needing network drives, traditional windows printers, and per-user restrictions and settings, its great. We run a blend of trad AD/GPO and pure Intune. For all of the non technical courses Intune managed shared devices are 100% better than the AD/GPO managed solution of yore. But as soon as the workflow unavoidably requires 'local' data persistence (e.g. Photoshop / Premier / most coding and development environments compsci teachers are comfortable with, etc etc,) then the AD/GPO managed devices are best. Edit: I'm expecting to hybridise our AD/GPO devices this coming year, just to reduce administrative/cognitive load on managing some things in both places (defender, updates etc), but where fine-grained control with a guaranteed first-time logon experience with per-user/group settings interacting with other on-prem server resources being required on a shared Device, I don't see Intune gaining ground any time soon.
  7. ok that's cool. but could you stop making the rest of us look bad?
  8. HSE set the limits https://www.hse.gov.uk/pubns/priced/eh40.pdf AD / F takes them and says the following: Office equipment can emit pollutants, including ozone and organic compounds. For example, a study by Black and Wortham (1999) suggests the following emission rates for laser printers and dry paper copiers assuming 30 minutes use in an hour. a. 25mg/h for TVOC. b. 3mg/h for ozone. To meet the performance criteria for these pollutants requires an extract rate of 20 litres per second per machine during use An older HSE document ( more recent than that 1999 study but now retired and unlisted https://webarchive.nationalarchives.gov.uk/ukgwa/20080730213136/http://www.hse.gov.uk//lau/lacs/90-2.htm ) says "Tests have found 0.12 ppm at the discharge from a cooling fan after 1 100 copies have been produced but, more typically, 0.02 ppm was measured in a number of locations at which a very slight smell of ozone was perceptible. 0.02 ppm is generally regarded as the world wide background concentration level of ozone. In London in summer it averages between 0.04 and 0.06 ppm. On smoggy days it may reach 0. 2 ppm for some hours."
  9. It did take me about a day to nail it down, but it can be done. *I'd been poking around for a few months to come up with a vague plan - so perhaps three days would be a more honest estimate if you're coming at it cold with no prior experience of how the system works.
  10. Windows 10 IoT LTSB will probably be getting security updates for longer that the embedded Android devices they and others sell, and at least with a full-fat Windows OS you can bring the management and monitoring/compliance in house.
  11. Defeatist.
  12. That's BB101 and is current. https://www.gov.uk/government/publications/building-bulletin-101-ventilation-for-school-buildings so if it says 20l/m then that's what's required (in new builds). It is also (word-for-word) including the School Output Specification Generic Design brief (December 2023) document https://www.gov.uk/government/publications/employers-requirements-part-b-generic-design-brief. Which is part of this set of documents: https://www.gov.uk/government/collections/school-design-and-construction. Though this document set has not been updated to include BB101, but instead includes reference to the consultation that was to result in BB101. All of these documents reference this document: https://assets.publishing.service.gov.uk/media/62a761edd3bf7f03667c667e/ADF2_revised.pdf (AD / F) which has to be the definitive word on the matter for all buildings. edit: AD/F cites BB101 as the definitive source of guidance for school buildings.
  13. Plant the seed of the idea in the Head Teachers mind, when they have the flash of inspiration that branded desktop wall paper would be a lovely idea, suggest they ask the Marketing team to put something together for you. (or if you don't quite have the relationship to be able to tell the Head what to do, email marketing yourself with the opening line "Ms/r HeadTeacherName thinks it would be great if....." and cc The Head.
  14. We get ours redone as part of the prospectus/website refresh. Let the pro's do their thing. We just make sure they understand the sizing recommendations.
  15. After Word online turns it into a PDF, the browser's print dialogue appears, or not?
  16. Explain that you can't reasonably be expected to lower your information security posture around email when it is a well known vector for cyber criminals, particularly spoofing/phishing attacks. However you are happy to pro-actively monitor for emails that may be blocked or quarantined and manually release them until such time that your cloud provider's algorithms re-learn that their domain is trustworthy.
  17. I think this article suggested a paging file in each VM is recommended to act as a buffer if the hyper-v memory manager isn't able to adjust quickly enough for the chaning workload. It also offers some performance counters to keep an eye on, and actions to take if they are being crossed. https://learn.microsoft.com/en-us/windows-server/administration/performance-tuning/role/hyper-v-server/memory-performance#correct-memory-sizing-for-child-partitions
  18. Microsoft Translator on iPhone seems to claim to able to translate to Urdu and Pashto with speech output but can't do diction from those languages. It might be worth talking with the SENCO, they usually have access to tools for facilitating communication with people who are non-verbal, which might help these students be able to communicate until they can pick up some English.
  19. In a problem common across many different platform providers (and not unique to Inventry), just because those at head office have sat down and designed the correct firewall rules think it is so, the field engineers/first line teams often add allow/any/any rules because they don't trust/understand Windows or the app. To re-iterate not just an inventry problem. I find it depressingly illuminating to periodically check the firewalls for unexpected deviations from the standard. (I've got BMS, Access Control, CCTV, Cashless Catering systems that all have gained these rules from time to time).
  20. Things that ruined previously good signal strength and required me to move APs over the years: 1) New Fire Alarm system 2) New Heating System (pipes now run in the ceiling voids) 3) LED lighting 4) Metal backed display frames on every corridor wall 5) Replacement IWBs - new ones were of different construction, size and shape. Mostly we were fine as the wifi design had every location provided for by two APs (ish). But after each of the above we'd find one or two classrooms where the signal at the teacher's desk had become very poor, if moving the desk a few feet wasn't an option, we moved the AP, typically just a few feet and the problem would be resolved. So yes. IWBs etc blocking signal is absolutely a thing.
  21. psydii

    DC time sync

    I have literally woken up in a cold sweat thinking about ways this can go wrong: https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/fixing-when-your-domain-traveled-back-in-time-the-great-system/ba-p/255877 https://www.researchgate.net/publication/334244678_Impact_of_GPS_Time_Spoofing_Attacks_on_Cyber_Physical_Systems
  22. FWIW Our Google Apps For Education exists only to enable us to have restricted mode by default and provide a mechanism for staff to review and authorise videos that might otherwise be blocked. (our GAFE uses 365 for its authentication)
  23. Never been particularly happy with Inventry's idea of security. As well as having a unique PIN, ours is isolated using ACLs on the core switch. The head unit is domain joined and has a bespoke firewall policy enforced along with AV and Windows Update settings. We use IPSec to restrict access to the shares to a group of users. AppLocker rules ensure that our users can only run exe's that were signed by inventry ltd. Access to the device's power and data ports are behind lock and key. We've not noticed a problem with the barcode reader, but we use proximity cards for staff and students, and guests tend to use the GUI on the head unit to sign out.
  24. psydii

    DC time sync

    I’ve not seen it myself but this could be part of it: “W32Time in Server 2016 includes the Secure Time Seeding feature. This feature determines the approximate current time from outgoing SSL connections. This time value is used to monitor the local system clock and correct any gross errors.” Yup. If a random cert/server on the internet has the wrong time, it can mess up the time on your DC. The view of an AD Escalation engineer at Microsoft: https://x.com/josephryanries/status/1488342795874193412 A write up on Arstechnica a few months after that tweet: https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/ Chat from last week about this very behaviour breaking a site this year! Turn that feature off! https://learn.microsoft.com/en-us/windows-server/networking/windows-time-service/windows-server-2016-improvements#secure-time-seeding Of course as the escalation engineer and other on this edugeek thread say, there are many ways time can be set automatically, so this might not be the actually cause, but it should be disabled to prevent it being the problem.
  25. You’re not wrong, and classroom AV doesn’t need 8K 120hz, but if either endpoint supports it, it will try to negotiate its link at that speed, and then incrementally downwards until it achieves a mutually agreeable datarate. If the cables are long or of insufficient specification all sorts of oddness can occour. The capability of the hardware in the endpoints is outstripping our needs, and if our cables aren’t up to it, somewhat ironically we will end up with less reliable connections. That said, most of our “wired desktops” are actually on the wireless these days. So as long as the cabling to the APs is good perhaps everything else is moot.
×
×
  • Create New...