psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Two very different options would be Wild beyond the Witchlight, and Oracle of War. I've not run Witchlight, but I've read it, and currently running Oracle of War for my group when we are missing players from our primary campaign. A third option (but I'm not sure I'm recommending it) is the Strixhaven book which is also quite interesting - its a series of scenes/scenarios separated by weeks/months of 'downtime' spanning four years which the players fill with inspiration riffing from the NPCs and extra-curricular activities... or improvised mini adventures if they are more the dungeon-crawl type.
-
I can't speak to the 5412 but i seem to recall the older 8200zl had a split backplane, with two PSUs one on each you would loose half the switch if there was a power/psu failure. You needed 4 PSU if you wanted all ports to stay up. The design being that you connected every host/switch to it via two routes, one on one backplane one on the other - thus losing half the switch wouldn't matter.
-
If it will run from a share it will run from any folder... so you should be able to copy it to where ever you want (%programfiles%, obvs) and run it from there?
-
In place seems to have the majority vote However to address your initial question regarding attaching the existing data disk to a new machine - as well as shares needing to be recreated, you also need to check to see if any local user/groups have been granted permissions on the volumes/shares you are migrating. It was once best practice to use local groups (i.e. stored in that server's SAM) to grant permissions to Universal/domain local groups. This is a problem in your scenario, as the local groups are lost when you connect the disk to another server. I seem to recall that using icacls is the way to update the groups/UUIDs to local equivalents. This is definitely more of a faff than just doing an in-place upgrade (if the server is clean and set up only as a file server). The presence of other roles or 3rd party services may complicate things)
-
Might there be a Papercut setting/script in play?
-
Fortinet FortiAP 231G Connected Classroom problems
psydii replied to bewlay51's topic in Wireless Networks
It’s 2023, how can this be a thing. If the vendor does not know how to configure them, perhaps they misrepresented their competency when tendering for the contract. Do fortinet have a design guide? Has it been followed? If there is variance between the guide and “as deployed”, is the documentation explaining this? Has Fortinet support been engaged? My guess would be around standards based roaming vs proprietary systems vs age and diversity of the clients. -
We move them to the A1 license, hide from the address book, and set an auto reply. A few months later they get added to a group that has a transport rule configured to hard block mail delivery to the mailbox. Some time later (depending on the ex-colleague's former role in the school) we remove their licence and the mailbox and onedrive get purged.
- 5 replies
-
- active directory
- azure ad connect
- (and 3 more)
-
Let’s not forget that interfering with systems you are not expressly permitted is is a violation of the computer misuse act, and one would hope, your AUP and should be resolved through disciplinary action by SLT. Your DPO should be advised of the incident, and you be steered by their review of the risk going forward.
-
Often these things are just performative, but like homeopathic remedies, their existence helps some people. Some of these people are Important People (who we need as allies).
-
Related to the other thread - we have: * daily driver accounts as per all staff. * local administrator account which is a basic domain user, unless it is also a member of specific localadminstrator group(s). * server administrator account which are basic domain users, unless it is also a member of a specific serveradministrator group(s) A very small number of DA accounts for Domain Controllers - and elevating the other accounts into and out of the various admin groups. All users and computers have an associated local administrator group in AD. To get admin we can get our "local administrator account" added our to that group. The .\ADMINISTRATOR password is managed by LAPS. All the accounts that can have administrative privelleges are in the Protected Users group. (except for the original "break-glass" Domain\Administrator) For cloud based devices, we don't have a good solution. I abuse Defender remediation tools to add accounts to the local admin group, and then have to remember to abuse them again to remove the accounts. But that said we almost never need local admin on an Intune managed device. Access to various 365 administrative functions required MFA protected accounts, and while currently handled by one of three seperate, cloud only GA accounts we are invreasingly moving to RBAM for these too.
-
Very siilar to Chuckster we have a collection of groups per resource. Say we have a share, there are (theoretically) three groups: share_sharename_readonly share_sharename_fullcontrol share_sharename_chage (to be fair, usually we don't bother with this one) These groups are the only groups that have access to the share (and the Local Administrator group of the server). Into these group we nest groups of *ROLES* that need that level of access. So role_fileserver_Administrators is in the _fullcontrol group. And role_FileServer_Adminsitrators contains a set of accounts that are to be administrators of the serer. These are never our daily driver accounts, and more recently they are not our DA accountes either. Other roles might include role_Teachers role_SupportStaff role_Students. We get more granular too. Each Deperartment has a set of role groups role_english_teachers role_english_admin role_english_HeadofDepartment role_english_HeadofKS3 role_english_HeadofKS4 role_english_HeadofKS5 role_english_LitteracyLead. All these group are members of the role_English_members group. Then on file server there is a folder for the English Department. This has three groups built for it: folder_EnglishDepartment_ReadOnly folder_EngishDepartment_FullControl folder_EnglishDepartment_Change For departmental folders we have role_staff as member of these _readonly groups the group role_english_members is a member of _Change the server administrator group is a member of _fullcontrol And we iterate through all folders/departments/teams/functions like that. We have a dirty set of scripts that sync the _members groups to their equivalent 365 Groups/Teams. There are other groups like role_headsofdepartment_members that contain all the _headofdepartment groups and the each of the _headofdepartment groups are used to provide additional access into 3rd party services that read from AD such as papercut. Other role and capability groups are used to filter access to 365 authenticated apps. etc. For each server there is an group called serveradmin_servername and we use gpp to add this to the local administrators group. When we need admin on a server we add our serveradmin_ittechsname account to the appropriate serveradmin_servername group, and then hop on via a fresh remote session. It needs to be fresh so it picks up the appropriate tickets/tokens. One can fudge it with klist, but it is more reliable/faster just to start a new session. the serveradmin_servername groups are purged regularly to prevent any account building too much authority over the infrastructure. These accounts are in the Protected Users group so authentication details are not cached.
-
No. USB-C is too fragile to be relied upon to support all those requirements and not to cause issues with hot-desking teachers and their laptops. The best you can hope for is for it to always be good enough to get you the 60W PD and USB 2. Anything beyond that is at the mercy of wear-and-tear of the cable (and that sourcing cables that support all the standard you need are very hard). I've found that lightly damaged laptop ports, dodgey firmware (at the laptop and at the dock) and everything in between can create 'viral' problems that spread between rooms. Cables can go bad, and cause the laptop ports to go bad, which cause the next dock to be connected to go bad. Its a nightmare. We've found that relying the dock for power and usb2 (for interactivity / keyboards/ mice / visualizers) and 60W of power is a safe baseline. We route HDMI direct to the laptop. Teachers can cope with two cables to connect. This is our Plan C for the classroom connectivity. A signle USB C cable was Plan B. Plan A was fully wireless; we actually have a Wi-Gig Dock (802.11ad for those that remember), which we thought would be the future, but never received the 11ad enabled laptop with which it was supposed to be paired! Intel withdrew the hardware short afterwards. With USB-C docks, you are putting a 10G cables into the hands of users - it take a lot of engineering to get 10G into a cable that small, and it needs to be handled with care - care that people don't really have time for.
-
Yes you were very very lucky. That is not how it is in most schools still. I also have been very very lucky (for the most part). But it can pivot overnight, with people saying "what do you even do" "psydii doesn't need any more toys" (when I was advocating the replacement of the aging server infrastructure) "we don't need the rolls-royce solution" (it was just a mid-tier flat panel for the classrooms) "stop being so inflexible" (the deployment plan had very specific critical path, and trying to implement D before B was a disaster). Also to look to your link to the Google SRE handbook. Translate and scale that back to a single site school.... it is clear (to me) that some of the equivalent reporting would indeed have pro-active interventions and incidents that were serious but customer impact was avoided, written up and shared with the relevant teams. In schools its just that some of the relevant teams are not IT but instead SLT / Governors.
-
While you are right... the context is a school. SLT need to be reminded that the money spent by IT *actually* prevented an outage today. Otherwise they forget that resilient and reliable IT requires ongoing investment and next year slash your budget and hire another teacher.
-
type .\ in the username box.
-
It’s your SAN. The very core of the IT service. Buy a new one or get a warranty /support contract (including software updates) on the existing one. We ran our old San for 10 years, but recently migrated to a newer model. Only had two problems in all that time, but 24/7 4hr break-fix saved our bacon both times.
- 1 reply
-
- 1
-
-
A bill? for AzureAD Connect?
-
Help with Stange Display Port/HMDI issue
psydii replied to mdrabble's topic in AV and Multimedia Related
It may be worth opening a ticket with Iiyama support. Drivers and firmware aren't the preserve of just computers these days. I'm sure they will want they kit to work with the widest range of end user hardware, so perhaps they can tweak something to make things more reliable/predictable. -
So, it is typical for a PA to have access to their boss's mailbox. But what if the email they are handling is particularly sensitive. With the PA to the "chief exec" that goes with the job. But what of lesser roles where a general department admin is de facto the HoD's PA and the HoD holds some of elements of SEN /DSL roles...? What hurdles need to be cleared to be able to allow the admin person to fully support their HoD? Is it even achievable?
-
Has anybody encountered/thought through how these classroom tools bump into the requirement of the RPA insurance to keep devices secure, and KCSIE in knowing who is accessing what on our networks? To expand a little: the "smart" Interactive screens all run various bespoke Android distributions to drive their basic PC-free interactive capabilities. This will typically include the ability to share screens/whiteboard slides, Google Drive / OneDrive integration and web browsing. All of these things need up to date software to remain compatible with current cloud services and to remain secure. Which is manageable for a few years after an individual screen is purchased, but I have not seen any manufacturer promising greater than 5 years of support - they all say they align with the Android support timeline which seems to be generally 2 years. We also must not be allowing browsing of the web where we can't trace it back to a specific user (or that seems to be a generally accepted consequence of KCSIE 2023). On the boards users are not authenticated. So what to do? What do *you* do, and have you considered the above... or is that simply next year's problem for now?
-
Where else would one test? :-/ Apropos of nothing: https://arstechnica.com/gadgets/2023/07/microsoft-changes-default-font-in-word-and-other-apps-for-the-first-time-since-2007/
-
Its the cabling/dongles. You need to at least get the dongles out of the loop. Also make sure the ports you connect the different screens to are consistent across the rooms. All our problems went away once we had decent cables. You might think you have good cables, but you probably don't (its ridiculously hard to get good cables - we now use Bluestream and they work flawlessly every time, and the computers/screens sync up and display the image in a fraction of the time it might take with other cables...but they don't do displayport cables). In contrast to some here, we never got active fibre cables to work reliably. I had a chat with VESA about this a few years ago and they recommended choosing the a cable that was rated to support your target resolution/refresh and NO HIGHER. This prevents the end to end system trying to negotiate speed higher than you need, and then failing. HBR is all you need for 1080p 30, which is all you need at the front of a classroom - even with an 80"+ screen, and achieving HBR3 over a 10m run is difficult/unreliable. Perhaps reach out to them https://www.displayport.org/faq/#tab-ask-displayport ? Prior to bluestream, Amazon Basics worked (for us) flawlessly, but we needed 10m cables, and amazon stopped selling their branded ones. After several attempts with other brands, Bluestream were the only ones to work as well. Assuming that experience translates (which is an untested assumption), This product might be the one for you: https://amzn.eu/d/9HliAsL We have a few of these where we have displayport docks. We had a load of issues with cables, (esp usbc) docks, DP / HDMI, and ended up eliminating most DP from the site as part of our desperate troubleshooting. Ensuring Amazon/BlueStream cables and removing dongles (and docks) from the video path worked for us. Now, three years later, we've started rolling out (very very slowly) usb-c docks with dual HDMI outputs... so it goes computer DP-ALT Mode over USB-C -> Dock -> HDMI 1, HDMI 2. This works well so far - with amazon/bluestream cables, and the current batch of USB-C cables (they are their own nightmare to get reliable). I really feel for you.
-
Schools contain over 10% of the population. I'm not sure that is small. Also remember the pandemic, when they buckled as little under the load of edu on boarding petabytes of data, and consuming so much server resource that they had to limit the resources available to business customers to keep edu and health care running? - we're noticeable, and that is why they have realised there is value to be extracted from our consumption of storage. As a school with a relatively huge data foot print, 100Tb is enough for us, and an upgrade on the 40Tb SAN we migrated from. If we were in a MAT made from multiple secondaries - 100Tb would absolutely not be enough, but we could easily absorb the half dozen local primaries into our current tenant. I'm sure there will be movement on the limits for MATs. I would expect that the conversations have already started.... and there are usually a few senior/influential Microsoft staff at BETT if you utter the correct incantations (or have done your research so you recognise them!)
-
TBH I'm slightly surprised nobody has said Papercut Print Deploy is the way to do this most effectively. I'd heard good things about it. https://www.papercut.com/discover/easy-printing/network-printer-deployment/#why-is-printing-difficult
-
does the admin account you used on the second/other machine(s) have rights to see the share/folders where the driver is? local admin accounts without rights to common sysadmin network shares catch members of my team out on a regular basis. Tripple check by mounting a drive to the share and browsing around from there..... also another thing that I've seen produce those symptoms is trying to run a command from an invalid drive... e.g. the cmd prompt says your are at n:\ but the share backing that location is offline/gone/invalid permissions... then most/all commands run from the commandline fail. Solution is to change the current working drive to something that exists (typically c: )
