Jump to content

psydii

Members
  • Posts

    5,195
  • Joined

  • Last visited

Everything posted by psydii

  1. From whom you buy microsoft licences? If they are a CSP they will have the right contacts to help.
  2. Given they are clearly signaling that we should be prepared to manage through 4hr power cuts this winter, I wonder how many other switches are going to fail. I don't think our core switch has powered down in 8 years!
  3. Yes we have loads. They are fine.
  4. I mean it's never *necessary* to take a backup. But if it is prudent to do so, it would be hard to talk your way out of needing to refresh your CV if you didn't and something went wrong. Some ADMX support new options or stop supporting options as versions change. Sometimes changes can get tattooed into policies or simply aren't visible when using new/old version of the ADMX. So it's prudent to take a backup of the GPOs before you open/edit them with the new admx in place. You should of course take a backup of the policydefinitions folder at the same time. In the 19 years GPO backups have been in the GUI, I've never needed to roll back a GPOs because of a problem with an ADMX.
  5. Yeah there is a 30 day limit on detailed data from MCAS/Defender for Cloud Apps, which is probably where they are pulling the access logs from. You *can* go back up to 6 months, but you can't filter by say SharePoint site folder as you can with the 30-day data, and you can only search in blocks of 1 week. I think from the data you get back you can export it and run it through excel, but not being able to filter first and the "1 week" limit on returned queries almost certainly makes performing the investigation you have requested impractical, unless it is super-sensitive in which case I guess the team will have to suck it up. FWIW as DP Lead and the Global Admin, I have had to do this once. https://learn.microsoft.com/en-us/defender-cloud-apps/activity-filters-queries#query-activities-six-months-back
  6. There is an agent that sits on our SIMS server for Inventry. We do have the system joined to our domain so we have proper oversight of it (policies, logs, defender etc), and so that the users of the Management Console can connect reliably with modern (well, Kerberos rather than NTLM) protocols.
  7. Had one die a couple of weeks ago after it got powered down for the first time in a couple of years.
  8. It also can be that the device isn't compliant. I've seen a vendor supply kit and insist on also supplying a separate PoE injector because "many switches don't really work with PoE properly even if they say they do" I have hundreds of cameras, phones and wireless aps and cashless/entry logging systems that say differently. But their kit just wouldn't work, and needed the injector. Running a maglock over poe though strikes me as a bit of a stretch for the 2920 era poe standards, so perhaps theirare caveats on what are supported in certain scenarios? I know our Wireless APs operate in a slighlty degraded state if not on at least 802.11at. A quick look at wikipedia, and if the power draw of an 11at device is above 25W then a second pair in the cable are utilized, perhaps you do have a faulty cable?
  9. You can set up a retention policy to delete chats older than say a month, which will remove the bulk of the problem. Then with agreement with the safeguarding team, you can over a weekend, drop the retention policy to say a day, and that will get rid of most of the remaining active chats. You can then increase the retention period back up to something sensible (a month seems to be popular). To get rid of the rest, you can (probably) then block all access to chat over a school holiday period, reduce the retention period back down to a day, only reverting the policies once school starts again. This will be 98% effective. You can then use various reports/PowerShell queries etc to find highly active chats and if necessary work with the individual participants to get them closed down.
  10. That over current count is where I would look to investigate further. After plugging it in, what is the output of sh log -r?
  11. Oh my god. Before working here I used to sail a lot. I stared at your post and a little voice in my head was telling me I should be chuckling, but Hitachi have ruined me.
  12. 5000 pages a year is around 1 ream per half term. I would suggest that there is a risk that at that slow rate, you may find paper curl and jamming starts to increase. I would recommend the M401 or a Pagewide (with original cartridges) for absolutely troublefree printing. However the M401 has been replaced by the more expensive to run M404 and the Pagewide line has been discontinued completely. We are currently buying the M404dn when a printer breaks or a new one is needed. Those that had Pagewides previously are not very happy.
  13. After a fifteen-year decline, we have now gone from projector based IWBs (with broken/no interactivity) to 86" interactive screens. Interactivity on the previous traditional IWBs were used by about 8 people out of 200. Almost everybody uses the interactivity on the new screens. All the interactivity sceptics have admitted they were wrong. We have not rolled out any dedicated IWB software onto the computers, nor do we have the more capable modular PCs installed in the boards - we just have the basic built-in software and treat them as slightly-smart Interactive Screens - so they can perform much like projecting onto a drywipe board, but with something a of a roller-board-like capability. They have transformed lessons. Ultimately they remove problems and restore basic capabilities to every single lesson that have been damaged through poor projectors/IWBS. Teachers' 'flow' is no longer hindered, and everybody is noticeably happier. I have also run scenarios where the interactivity (pen/touch) were driven by the laptop hardware, and this can work, but requires skills and teaching styles that are not standard across the teaching body. Absolutely there are enthusiastic advocates for this style of set up, and in a small school where everyone pulls together to support this 'novel' approach it can be excellent. However, basic board-driven interactivity is in my opinion an absolute baseline of capability, to not provide it is a false economy.
  14. Try one of these: https://www.purple-cat.co.uk/blustream-sp12ab-v2.html we have a couple and some of their HDBASET transmitters and have been very happy with them, though not sure we have had machines going to sleep while connected. These came recommended by AV install company as there go-to "it must work" bit of kit. We even have Iiyama monitor at the end of one of the runs! I think our laptops go into presenter mode when connecting HDMI so sleep is disabled. Perhaps this is why it works well for us?
  15. So... we have emergency medical and contact information printed in a secure store on site. We also have paper registers printed ready to go, and can run for two days before we need to print more. So we can run without the main MIS for a day or so without major issue.* We also have a container full of heaters, and air conditioners** We can also enable registers/contact to run through alternative providers in the event they are up and for some reason the MIS is down for an extended period. Finally, and somewhat theoretically, with careful execution we can (on reasonably bright, but not necessarily sunny day) run the internal lights, and the comms rooms from the solar array*** on the roof. We'd lose the airhandling units, water/heating pumps, the fridges/freezers in the kitchens, classroom sockets (so no IT suites, or IWBS, DT/FT hardware) But it could (perhaps) be done. But of course it will be the middle of winter so the lack of heating and sunlight will probably force us to close the site. *after a massive SIMS crash back in '04 lessons were learned. **built up over a period of several years of heating/cooling issues. ***I am not sure how we ended up with this, but it certainly is taking the edge off the electricity price rises.
  16. Profiles are created per computer. Seating plans are key, so students use the same computer week in week out, this allows storage sense to manage each profile in turn, and the student only has a 'long wait' (about a minute) on the first logon. We have 256Gb SSD and in this configuration storage sense does mostly keep on top of things. Occasionally we need to clear out old profiles (particularly when a class that makes heavy use of media files no longer uses a room we have found their profiles and hydrated files hang around) Depending on your usage pattern, and what apps are on the desktops, 128Gb might require a tight maintenance programme to work.
  17. We don't use Cloud Drive Mapper or FSLogix, but FWIW we migrated documents overnight using the "sharepoint migration tool", and went through the users in batches (which is what step 3 in my post above enables)
  18. Interesting. The fix for most of this, surely, is to put temporary files in %temp% like any properly behaved application?
  19. These feel like firmware related failures. We saw very similar a few years ago on the (Windows based) Thinkpad 13's, L380's and USB C Docks. Firmware updates started to come thick and fast, and resolved most of them (though no help if a machine had already succumbed to the failure). We've even had updates to these 6 year old platform in April 2022. I note that the Windows variant of the 100e G2 devices have BIOS and EMMC firmware updates available on the Lenovo's website. I wonder if Chrome OS is getting equivalents? On the E590's we have seen a lot of USB C charging port failures. While we did discover that the laptops are a little large for the trolleys in which they are contained, and need to be put in at an angle so the doors don't stress the charging ports when plugged in, they too have many firmware updates that might perhaps improve reliability of the platform. Unfortunately the E series does not get updates available through enterprise channels, so we didn't realize we were missing them for quite a while. On 'identical' devices having variations like the presence or not of a M.2/NVMe slot, we were lucky enough to have some evaluation hardware and early production runs of various models shipped to use at the very start of the pandemic. When I observed the port to our contact at the OEM they advised that early runs often have motherboards capable of multiple configurations, and once the market has decided what configuration is the most profitable, the unused capabilities are removed from later runs. (i.e. I shouldn't make any decisions based on the apparent upgradability of 1st/pre-production runs of the hardware)
  20. To solve the buzzing and get stereo you need this: https://www.interspaceind.com/av-audio-products/product/28-pcbb%C2%B2/category_pathway-41.html It plugs into a consumer-grade 3.5mm line out, and coverts it to Left and Right channel XLR sorting out any earth loops in the process. Keywords I've heard in connection with this are PC Balance Box, Earth Loop / Ground loop eliminator / Earth Lift.
  21. The JQA ICE has evolved over the last few years. I think the guidance the OP was given is inflexibly strictly accurate against a prior version of the ICE. However, I've just skimmed the current version https://www.jcq.org.uk/wp-content/uploads/2022/08/ICE_22-23_FINAL.pdf and all of the impracticalities they imposed on the use of word processors have been removed by rewording of requirements. The spirit of the instructions remains unchanged, but the clauses that prohibit network connections or that could be interpreted as requiring *unreasonable* measures to lock down the machines have been removed. Before just now, I haven't checked for a few years so maybe this changed happened a while ago?
  22. Ok so they are out today. They haven't replaced the base model, the new 10th Gen iPad basically sites where the low-end of the iPad Air range sat a couple of years ago. The 9th Gen iPad basic model is still lightening based. Definitely talk with an apple education specialist to gauge what is the correct route for you from here, I am not sure my advice above still stands.
  23. Just for fun: You will certainly need to familiarise yourself with this on your journey: https://learn.microsoft.com/en-us/windows-server/storage/dfs-replication/migrate-sysvol-to-dfsr Also you are likely to have things like NTLM hashes, and older security defaults in the GPOs. You might want to check it's not still in 'Mixed Mode' for NT4 compatibility. Look into SMB1 support - I'm pretty sure 2022 will have that disabled if not unavailable, but with 2000 it's the default (with fall back to netbios) Also as you progress through the versions, you might find client support an issue, can clients that are happy still talking to W2k Active directory actually talk to a 2022 AD? You may have to pay attention to cypher suites too. https://learn.microsoft.com/en-us/windows/win32/secauthn/tls-cipher-suites-in-windows-server-2022 https://support.microsoft.com/en-us/topic/improving-cipher-security-in-windows-server-2003-sp2-1ca3df4d-f7c8-b4df-41e6-520279eb478d Also with such an old system, might well have tools like telnet and ftp in play. What about imaging client devices - what have they got going on there. I mean, the default back then was RIS. I assume it will be something image based like Ghost? That might not translate well into a modern environment. Finally, is there an exchange server? I'm guessing not or you'd probably have mentioned it. 2003 was the last version that supported AD with only 2K DCs, that would be a fun project on its own! All that said, though... Before you start though you might want to take some screen shots of any old artifacts is it possible the domain pre-dates AD? There aren't many of those left, and there is a change the DC was an in place upgrade from NT4, having evidence of taking such an old domain to 2022 would give you bragging rights in certain corners of the internet.
  24. Managed Service desk surely? All the assets should be in there already, along with their locations. Ours doesn't have a place for photos, or drawings specifically, but if it were a requirement to have the assets/drawings/photos all in one place, I would open ticket against each asset and attach the photo to the ticket. Ticket title would be ASSET NUMBER - photo / Asset Number - Cabinet Drawing etc to make it easy to spot in the asset's ticket history. In actual fact what we do is have a spreadsheet for the site infrastructure assets that is reviewable and consumable by SLT and Auditors. This sheet has links out to the appropriate additional information such as the asset record in the service desk, the folder of hardware documentation, the folder of service vendor documentation etc etc.
  25. Enterprise solutions are always a bodge to some extent. I can't for the life of me find my notes from 2018 when we rolled this out, but broadly what we did was 1) Created a computer based GPP that on every machine creates the following folders %SystemDrive%\Users\Default\OneDrive - *Org Name*\Attachments %SystemDrive%\Users\Default\OneDrive - *Org Name*\Documents %SystemDrive%\Users\Default\OneDrive - *Org Name*\Photos %SystemDrive%\Users\Default\OneDrive - *Org Name*\Videos etc This means the folder redirection targets are ready the first time the user logs on, even though the first time the user logs on OneDrive hasn't run. Thus folder redirection works and a few moments after logon the user's files start to appear for them, once they have logged on once to a machine, their files are visible immediately. 2) In the GPO that has the above settings we enforce 'enable files on demand' (I think this is the default these days), migrate pre-existing Team Sites (probably not needed in 2022), and silently configure OneDrive using Primary Windows account (again I think this is probably default behavior in 2022) We also set "enable co-authoring in app sharing for Office files" (again probably the default behaviour these days) and prevent users from syncing personal OneDrive account (to save space and a futile step to prevent data leakage from staff to personal accounts) 3) Now in that same GPO create a User scoped GPP that creates the following folders in each users' profile OneDrive - *Org Name* OneDrive - *Org Name*\Documents OneDrive - *Org Name*\Pictures OneDrive - *Org Name*\Videos etc. This catches any users that have got profiles that were created before the computer GPP entries in step 1 applied. 4) Also in the same GPO in the user scoped create an GPP environment variable called "OneDriveSync" with the value of %userprofile%\OneDrive - *Org Name* 3) Created a 2nd GPO to supersede the original user folder redirection policy and instead redirect folders to the appropriate OneDrive location e.g. Documents to %OneDriveSync%\Documents Control the application of this policy via group membership so you can control the roll out of the migration. It has been so long I can't remember whether for users who had existing profiles saw the redirection occur automatically the first time, or whether it took two logons. Certainly, I clearly hoped that be creating the folders using GPP that GPP runs before folder redirection, but if not, it wasn't a big deal we were rolling out slowly and nobody complained. However, for users with fresh user profiles the redirection happens perfectly first time. This method was actually in the official Microsoft documentation for a while, but has been replaced by Known Folder Move. We attempt no roaming of profiles beyond what ever is left of ESR and Chromium settings roaming. EDIT: Well gosh, I found it! The old guidance upon which the above is built: https://github.com/MicrosoftDocs/OfficeDocs-SharePoint/blob/92b3c82c523a3b1babc723a889c6c13012afef82/OneDrive/redirect-windows-known-folders.md and the current guidance based around known folder move: https://learn.microsoft.com/en-gb/sharepoint/redirect-known-folders
×
×
  • Create New...