Jump to content

psydii

Members
  • Posts

    5,191
  • Joined

  • Last visited

Everything posted by psydii

  1. USBC tries to be everything to everyone and often fails at some of it. Same with overhead powerline lines vs burried. Same power, very different cables, and very different again to the cables in your domestic circuit. Now imagine how compromised a power cable whose spec was "can perform all three roles" might be.
  2. It's a cable that (likely) has more bandwidth than your ENTIRE server network infrastructure, and can simultaneously carry enough power to boil a kettle in about 20 minutes, but has is flexible enough for end users to be messing with multiple times a day. Think what it would look like if it had been designed for reliable use in a datacentre. Practical on a user's desktop it would not be. Robustness is what has been lost. 10Gb/s and 100W should be what the engineers are building to as a sane standard, but endpoints now reach 80Gb/s at 240W and they are pushing cables beyond what can be economically reliably produced.
  3. They're not over-engineered. They're just built to actually meet the spec, but in a "trust me bro" way. It you want higher levels of assurance then USB-IF branding is what you need to look for. The desire to be able to support multiple 4K monitors, 40Gb/s connections to external storage and network has led to this insanity. If the cable isn't from the supplier of the connected equipment, USB-IF branded, or (maybe) a "truespec" from LTT/CW the chances are, at some level it isn't working the way you think it is - even if you haven't noticed just yet.
  4. Did you figure this out? We are getting really inconsistent behaviour. I believe we're all set up that only people with the guest invitors role can share externally, yet for some users "it just works", even though they do not have the guest invitor role.... the guest account is provisioned and the guest can access?! How are people feeling about this? One thing I don't think happened on the old way was access to document version history... The other is a reticence by external users to "allow access to profile and usage data"... which as far as I can tell just means "we get to see what we'd see if we hadn't told you we were seeing it since that dawn of time" but its scaring people off...
  5. ahh. that would be it. I think you can get an add-on that should light up that capability.
  6. Do you have a3/5?
  7. Yeah, that would have been useful here too. Do the search on keyword, but then in the review set create a filter where they are not a participant. Copy the result to a new review set and then dedupe that.
  8. If you are specifically looking for the keyword in subject lines and message bodies, but not attachments, I'm not sure that is possible. If you don't mind attachments being searched then (keyword) is all you need. I noticed recently that in ediscovery the review set seems to default to presenting the item that matched as the first item in a collapsed list, so if the attachment matched, its the attachment that shows, and the email is revealed by expanding the collapsed list, while if the email subject or body matched that is presented first with the attachments (and related emails) below. I'd not noticed that behaviour before. That said, refreshing the list this last week often causes the order to shuffle (though sometimes it reverts to expected order). It had been pretty stable the last few times I've used it.
  9. Kids these days, over complicating the process. I just walked in to the computing room and read the commissioning engineers notes while he was on a lunch break. ::shrug::
  10. It’s always a good idea to know what tools are being used, and always good to be able to show to the auditors you checked. We start the DPIA process for any new service, and if it only requires users and linking to our authentication system, we glance over their privacy notice and contracts, close the file and wave it on through. If it handles/might handle personal data or does something unusual we instead proceed to a full in depth dpia, which can take a while. Starting the DPIA process takes an hour or two depending on how close it gets to needing the full treatment. We try to start them the same day we get the request so people don’t come to resent the proper (and necessary) business-admin-processes. I.e if a DPIa isn’t really needed, we have a record of that, and the sponsor gets the go ahead same day. Everybody wins.
  11. We allocate a set of devices to become exam devices for the period, with plenty of time for them to pivot over and transition from the generic set of profiles to the ones tuned for exam device use. We also use exam accounts locked to specific devices, and take them off the network for period. They save their work in the local documents. The exams team manage the initial logon (to cache the credentials) and the saving and purging of files before/after each exam.
  12. AMD K6? I also stumbled across one of those today too!
  13. Sorting through somethings in a shed I haven’t been in for a while, and found this:
  14. The category layout they've gone with really reminds me of Program Manager / PC Tools Desktop from the 3.0/3.1 days.
  15. ...just a thought. There have been a lot of driver and firmware updates over the last couple of months.. perhaps its related? I've not seen USB peripherals fail to recover after a reboot/disconnect/reconnect, but transient issues are definately up a bit this month. We have also had distinctly more wifi issues than normal. Devices seem less enthusiastic to connect, and less reliably detecting internet connectivity, sometime even failing to see the DCs even though everythign shows as connected. In a couple of extreme cases we've had devices losing the wireless cards completely, reporting USB errors and generally being janky until (another) bios update was applied and then they returned to working flawlessly again (so far).
  16. We see this problem about once every 10,000 or so logons. A quick query in defender and we know where they were when they saved the file. Departments that upload big media files have it baked into their working practice that need to have finished copying files to sync'd onedrive/sharepiont folders 10 minutes before the end of the lesson to give things a chance to sync up. In practice they know this level of caution is only actually needed when kids are dumping multiple gigs from media cards into onedrive. If its just a couple of photos, and the sync is done in seconds. We (the school) have a behaviour policy that requires teachers to have a seating plan, so kids sit in the same place (and therefor) use the same computer each time - this helps massively smoothing out sync issues and logon times. We extend this to using the same laptops (this requires a bit of admin work on our part to ensure trolleys go to the same classes each time). With chromebook-like devices, onedrive sync is disabled and they use the web instead.
  17. Yup Ausus motherboards in most cases too. A couple of instances where they keyboard was connected via a old anker usb/etherenet combo dongle. Though if left for a few minutes they recover without intervention. We first noticed it happening yesterday after June's update started rolling out. Nothing actually on the service desk about it, but I've been hopping over lots of machines ahead of next weeks' secure boot cert expirery so I've had much more opportunity than usual to be touching machines that are coming out of sleep/hardware detection states.
  18. If you think you are important but your PA doesn't ensure your laptop is up to date before the deadline for scheduled checks/updates hits... are you really that important?
  19. Not sure exactly how with intune, but with ad/gp, set cached logins to zero and set the lid close action to restart or shutdown. For Entra, maybe: conditional access, (test user) all resources network, condition include the set of laptops, exclude your lan/location, access control block access. be very careful not to lock yourself out of your tenant messing with the above. I haven’t tested it at all and only vaguely think it might work.
  20. Windows 10 and 11 with OneDrive is incompatible with roaming profiles, and so after 17 years of using folder redirection, roaming profiles and CSC, we just walked away from those abilities. Staff are mostly on 1:1 laptops or desktops at their desk with files sync'd via OneDrive, web stuff sync'd via however Edge/Chrome does that, and the fact that most things are web apps these days, meant that the impact was minimal. Once we moved to Windows 11, the recent files capabilities returned.
  21. Business Continuity / Disaster Recovery Plan has an overview of all systems and services, ips, support and owner info. This document includes charts of business processes and how data flows. There are two "how things are done here" documents that are intended for new IT Service team members (or to be read by external emergency cover in the event something bad happens and we loose service and the IT team at the same time). SBM and HT PA know that nobody should touch anything without reading those first. Each major service / system / process has commissioning note in a shared folder and a "Configuration Item" in our CMDB, all changes are logged through tickets against those CI's More complex changes are documented in a shared folder with the service name, CI# and ticket #. Might be a word doc, might be a pdf, might be a spreadsheet. For a lot of stuff though, the configuration is the documentation. The "house style" is described in the "how things are done here" documents, and then you look at the live config to get an understanding of how a specific thing is set up. We have backups of all the GPOs, AD Objects, Deployments etc which can be referenced/used in the event we need to rebuild from scratch without reference to the existing management plane. Where ever a system allows for configuration backups to be easily taken, we take those before making a change. IT processes are documented in Standard Operating Procedures folder. (onboarding, offboarding, asset life-cyle, managing change request, escalations process, troubleshooting notes, maintenance schedules etc) Every year I spend a few days improving it, pruning obsolete info, adding new info that didn't get documented properly in the rush to get it done "now!", improving that I can.
  22. It was certainly being mentioned by the usual MVPs over the last month or so. Despite what MS say, it's almost certainly because reboots are required for the Secure Boot Certificate update, and the deadline for that is about 6 days away.
  23. dedicated cover accounts, restricted to specific laptops, with access to the cover folders only. passwords rotated on a weekly basis. Accounts can't be used unless on the specific cover laptop to which it is attached. (MFA enforced when devicename does not match. Somebody in the IT office has the all the accounts in their Authenticator) For anyone here longer than a few days, they go into the MIS and get a real account, and if they are here long enough, they get issued a non-covers/supply laptop.
  24. In addition to what others have said, no matter what technology you put in place, you should still have a home school agreement where there is responsibility put upon the parent to provide appropriate supervision of device use. Given enough devices and enough idle students, some of them are going to get around your efforts, and having an explicit shared responsibilty will afford some protection.
  25. You probably have between 30 and 180 days before devices notice the previous licence has expired. We use shared account activation (or at least we used to, I haven;t actually checked the config of the office deployment is years). As others have mentioned, this requires the user to be checked for a licence, but it doesn't count against their activation limit, so isn't a way to avoid cloud syncing your student accounts. It is necessary when a user is likely to use more than 5 devices in a month. Get sso working. job done. ...and also a dozen other little things that are just better with sso working properly. Salamander, Locker, or your MIS provider all offer user provisioning, we just have salamander provision in AD and let Entra Connect do the sync and provisioning in the cloud. (licences deployed on a group basis). Entra Sync would almost certainly be the way to go in 2026.
×
×
  • Create New...