psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
LAPS is built into Windows 10 and 11 Edu and Enterprise as of today’s (11th April 2023) Windows update. Improvements over the legacy version include password encryption, AD Directory Service Restore mode password management, and automatic rotation of passwords after use. Integration with Azure AD is in preview. https://techcommunity.microsoft.com/t5/windows-it-pro-blog/by-popular-demand-windows-laps-available-now/ba-p/3788747
- 5 replies
-
- 14
-
-
Mailmerge 200+ users with unique file attachment
psydii replied to DalekSec's topic in How do you do....it?
You can certainly do a mail merge to email through Word (start it in word and the mail merge feature takes care of the rest talking to Outlook on your behalf) 200 individual emails is well below the harder limits of 365. It probably will throttle a bit, but still be way way quicker than sending them by hand. The "difficult" bit is the per-email PDF. Not sure that there is a built in way, even with Acrobat Pro. Perhaps mail merge to pdf first, then a separate mail merge to email to send the links. You could (maybe?) get a bit of VBA to mail merge a cover letter and attach specific pdf using excel as a data source? -
Last time I went it dawned on me that it’s about 1/3 the size of CES, which is about as big as it gets. Yet BETT is Education tech only… And while sense checking my thought before I posted, I find it on this list, which sort of confirms it place as one of the largest trade shows in the world. https://www.techradar.com/news/top-tech-conferences-the-ultimate-tech-events-and-show-guide
-
Filtering/Firewall Logging Data Retention
psydii replied to psynegy's topic in Internet Related/Filtering/Firewall
*States at his E5 log retention* Hmm. I’m going to have to stand up that Sentinal stuff aren’t I? -
Filtering/Firewall Logging Data Retention
psydii replied to psynegy's topic in Internet Related/Filtering/Firewall
In my view, in general: If you are logging for potential safeguarding investigations, aligning retention with your CCTV policy seems reasonable. On the other hand if it forms part of an audit trail for cyber security investigations, then 12 months seems reasonable. If there is an active external investigation, you retain them for as long as your legal department tell you they should be retained. -
https://www.theguardian.com/business/2023/mar/31/capita-it-systems-fail-cyber-attack-nhs-fears They've been down all morning, Cabinet Office and NCSC alerted. Staff using pens paper and radios to run operations at some sites.
-
LGFL IP Allocation Through PFSence
psydii replied to kyle141's topic in London Grid for Learning (LGfL)
Yes it works fine. * We have one of the LGfL 10.x.x.x. ips on the outside of our pfsense, and our own ip range on the inside. Internally everything routes through the core switch and this has the internal IP of the pfsense as the default gateway. The pfsense box has its default gateway set to be the gateway address of the LGFL subnet. We have multiple IP addresses assigned to the external interface of PFSENSE, and NAT rules on the PFSENSE to direct traffic through these 'external' IPs depending on the source subnet/ip. This way we can apply webscreen rules to our subnets or even (if we statically assign and IP to a user's device) individuals. *I can feel @PaddyNewman giving me the side eye from here. -
50,000 users on 2019 hangs but works with 2012R2, any solution?
psydii replied to coderr's topic in Windows Server 2019
I haven’t done an in-place-upgraded of a production SAM to ADDS for about 22 years. I seem to recall one just installs the AD role on the server with the accounts and it just happens. (So realising what I just said, don’t worry about standing up a second server… just add the role to the existing server) The SAM still exists for disaster recovery purposes, so it is possible that lsass will still parse it on boot even when AD is stood up. I think it must be worth opening a ticket with Microsoft about this, probably with the Windows Server team. -
50,000 users on 2019 hangs but works with 2012R2, any solution?
psydii replied to coderr's topic in Windows Server 2019
*Only* LSASS should be doing that. However, "why is it doing that specifically" it not an unreasonable question. What happens on the 2012R2 box? Is something else querying for the users (and it is LSASs's job to respond), or does the post 2016 LSASS query all accounts in the SAM each boot time as part of the changes made (linked in my previous post)? As per @chaplic's suggestion, I wonder how much work it would be to re-tool it for having the accounts in AD stood up for just this task...? Moving from local auth to domain auth in windows applications might be the least painful solution*. This is however upgrading from a 1994-style solution to a 1999-style solution and might be a false economy. *and for the love of god, don't have the Domain doing anything other than serving this application, if it gets compromised it is toast. -
50,000 users on 2019 hangs but works with 2012R2, any solution?
psydii replied to coderr's topic in Windows Server 2019
I'm hesitant to recommend lowering the security posture of a server, but this might point you in the right direction: https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-access-restrict-clients-allowed-to-make-remote-sam-calls Basically Since 2016 there is a 'new' security limitation on accessing the SAM. It might be that it is this check that is slowing you down. I don't think there is a documented way to disable the check. A check that takes 100ms per account (perhaps there is a timeout? I wonder what account/subsystem is calling the sam at this time?) would account for the hour delay during boot. It might be time to make friends with this: https://learn.microsoft.com/en-us/windows-hardware/test/wpt/windows-performance-analyzer It can record *everything* that is going on at boot time. Try comparing a clean 2019 boot trace to one captured from your problem server. -
https://support.microsoft.com/en-us/topic/microsoft-professional-support-pay-per-incident-faq-575821bc-17bb-7484-4935-334c5437639f https://support.serviceshub.microsoft.com/supportforbusiness/create
-
It's the Head. If it doesn't work for them, change the rest of the school. Move everyone over to OneDrive/SharePoint. (I say that in jest, but it is the correct answer - saving to network volumes/shares is increasingly niche)
-
50,000 users on 2019 hangs but works with 2012R2, any solution?
psydii replied to coderr's topic in Windows Server 2019
Quite, but it might be worth opening a ticket with Microsoft Support. -
This sort of oddness is sometimes caused by anti-virus software tripping up the app.
-
Several departments manage their own resources through Eclipse-MLS. Its not great but it works. (DSLRs Video Cameras, laptops and iPads are all managed this way) Central IT has bookable resources, and these require at least 24hrs notice and are generally delivered and collected by members of the IT team. (this is from six bookable sets of 15) ad-hoc loans to specific students (1-7 days) require teacher authorization and get logged in a spreadsheet which is shared with Reception (who are the backup return point) and items are signed in and out. A ticket in the helpdesk keeps the sponsoring teacher responsible for the device's good health. For students who have laptops permanently allocated, they either operate as per ad-hoc (but with pre-authorization), or we issue a full 1:1 device with paperwork home etc etc. The SENCO tells us which would be most appropriate in each case.
-
Windows 10 built in photo app is currently the recommended option. They way MS have been going with new capabilities recently I fear that if/when they do integrate ClipChamp to 365, it'll be an addon to E5. Hopefully they remember iMovie still exists and is free.
-
SIMS has a pronouns field these days!
-
50,000 users on 2019 hangs but works with 2012R2, any solution?
psydii replied to coderr's topic in Windows Server 2019
Take a look at whether your getting per user firewall rules created. https://community.spiceworks.com/topic/2285411-server2019-rds-hundreds-of-firewall-rules-per-user-per-session -
I’ve heard that ChatGPT is quite good at summarising policies into a more accessible form.
-
A head/deputy should own this, and check the distribution groups before any email is sent. On a technical level: Populate the groups using the data from your MIS. Tweak it by hand as advised by the Head/Deputy. The lists can be hidden from the address book and emails sent to the lists should use the bcc field.
-
HTA is a tech from Internet Explorer. Internet Explorer is retired:https://www.microsoft.com/en-gb/download/internet-explorer.aspx Therefore HTA is dead too. https://stackoverflow.com/questions/10619990/hta-equivalents-in-firefox-chrome-is-this-old-technology tag does not work in IE10 | Microsoft Connect There maybe some legacy bits and bobs that may keep it working in edge cases (no pun intended), but efforts would be better spent elsewhere. That said, this might help: https://stackoverflow.com/questions/71890698/hta-files-and-microsoft-edge
-
Bechtle have been pretty good for us over the last few years. Their licensing team are the best I have encountered.
-
NIGHTMARE - Large media files and Microsoft 365 Cloud Storage!
psydii replied to ConceroEdu_Brad's topic in Cloud Services
Seating plans also offset the ‘slow to sync’ problem. -
Addressing parent frustration on school communications
psydii replied to ceilfors's topic in Educational Software
Don't forget the old adage GIGO. It won't matter how slick the system is if it has the wrong data. -
Leavers have their passwords reset, and accounts disabled in AD, they are then stripped of group memberships, and then added to a group that gives them an A1 licence and a "block mail delivery" group. This latter group is then used in a transport rule to provide a custom bounce message advising the sender that the recipient has left and they should update their contact information (with a reference to the main office email and website to assist them in identifying the appropriate individual) At some point later accounts are stripped of the A1 licence. We have defender /azure atp keep an eye on these disabled accounts for unexpected activity.
