psydii
Members-
Posts
5,194 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Nothing to report about "slow" internet, but I did see defender and something in the senso client folder having a fight for about 20 minutes today. One machine, running an older version of the senso client, it made the machine extremely slow, to the point task manager felt like it was about to lock up. Since we've had about 50% of machines on the newer version, and for the teachers that use it (and those machines) I've not heard any of the reliability complaints that I used to get weekly, but its a strange time of year so that might just be because people are busy / using the IT Suites less.
-
…except there are guidelines on data retention. It would be reasonable to expect a org to have not lost access because they simply didn’t want to pay. It’s also bonkers that to maintain archival access would require a full licence. When I last migrated an MIS (a very long time ago) I negotiated a perpetual single user/seat licence to cover this sort of thing. I am stunned that the DfE / Cabinet Office hasn’t pushed this type of clause into framework contracts.
-
Secure boot certificates expire in june 2026
psydii replied to TwistedHelixis's topic in How do you do....it?
Anyone got any tips on persuading Thinkpad/ThinkCenter machines to auto update their BIOS's? We're mostly ok on staff machines, as most teachers do click OK on the bios update nag screen at least once a year, but for the rest they just wont take, and almost none have reported to intune/wufb/autopatch that they need bios updates! (lots of random drivers recommended though). We've got Lenovo system update on most machines, prior to that we used the Lenovo's 3rd Party Catalog for WSUS/SCCM (which would do bios updates), but we moved from that a couple of years ago. LSU seems to hold off forcing a bios update, requiring user interaction to confirm, even when all other updates just install silently. Delivery via Intune/WUFB/AutoPatch would be preferred.. but incantations to get LSU to work would be welcomed too! -
Ahh, yeah, having an admin person on the team does open up for some options that don't usually sit in the IT Office. That does make sense, until all the "and... and... and...and-ing" starts impacting on your ability to support the IT team in a timely fashion. Unlikely with "just" this additional responsibility, but things have a habit of snowballing. Also with this one who picks up the work if you are off sick? But to answer your question (or rather, specifically *not* answer...) Services that offer menus to depts so they can request and then an admin can process, can (depending on how finance/ops want to account for time/value) to cost more, and the lack of flexibility ultimately frustrates people unnecessarily. Here teachers just email a link to the admin for what they want, and the admin does the leg-work through today's "preferred" suppliers to ensure best value. The work is generally bundled / front loaded at predictable times, but obviously there's still a lot of ad-hoc purchasing gong on. In terms of authorisation, the admin team are able to raise POs against dept budgets, but the HoD/Budget holder has to authorise them before the order can be placed. For things that need to go against a central budget, I'm actually considered the budget holder, so get to sign off on things. In fact, my somewhat facetious post (above) was inspired by an actual conversation with our SBM!
-
How would a maglock hold a double gate? They usually work by fixing one half of the maglock to the frame (that doesn't move). The turning force from a reaspnable shove on a double gate would likely easily overcome a basic maglock.
-
Not an IT job. LOL. I am disappointed by people's lack of vision here. Managing stationary is the original IT job. Pen and paper is a lower cost backup plan than replacing a keyboards or repairing devices. Infinitely quicker to deploy and requires no user training from you since reading and writing is literally the teacher's job. It's so reliable that people will actually *want* the new toys you have in preference to those complex and hard to manage "computers" you've been pushing for the last 25 years; and it aligns pay of the IT staff to the skill level required! It's thinking outside the box. Its saving money. Its solving the long term IT problems*. It's a win for everybody*. *opinions may vary. But I'm sure your Leadership believe it.
-
No PO, not order. POs can only be raised against approved suppliers. If a staff member can do the due diligence and demonstrate a new supplier would be advantageous to have approved, then they get approved. If they can't then quite frankly the extra work wasn't worth the potential benefit. We do have a healthy churn of suppliers available on the system. Generally the admin team do ordering of these things through a small selection of approved portals. The admin team understand each departments needs and preferences and the current procurement/budgetary environment, and work to keep everyone as happy as reasonably possible given the constraints. Sometimes orders are in bulk, sometimes the are somewhat more add hoc based on emerging needs of a department or team.
-
Interesting. I had need to reanimate and old (ish) Windows 10 laptop (returning long term absence), instead of updating to 11 automatically overnight, it stuck. Reason? “Incompatible intel wifi driver”
-
“18 years later…” hurts my soul. But to your question, I wouldn’t worry about it as long as it’s just internal, and you’re not big enough to have a dedicated compliance/legal officer. If you are big enough, it isn’t your problem. However, if it is external then the risk changes and you should have a quiet word, either with them or whomsoever has the compliance/legal officer role.
-
Sorry to be pedantic, sfc /scannow needs to be run **after** the dism restore health command in order to be effective.
-
Basically what it does, but quicker and less work on our part. We only started to need it regularly hen we moved away from biannual feature updates (they were in effect re-installs). So from 1603-22h2 machines were in effect re-imaged every six months by the feature update installation, but now were still Windows 11 24h2/ Windows 10 22h2 ESU) and some of them are starting to feel their age. It really does fix a multitude of things. I have it as a script deployable from sccm, and a "four click fix" without even having to touch the device is dramatically less work than re-imaging. Whether it fixes @Giblets2 problem, we shall have to wait and see.
-
netcfg /d, then reboot. if that doesn't work, there's always the traditional "hail mary": DISM /Online /Cleanup-Image /RestoreHealth followed by sfc /scannow (not sure when that actually started fixing things, but prior to 2020 I'd never seen sfc /scannow do anything of note, but these days I feel like I run it at least once a week to put an unhappy machine back into a serviceable state. Not that I have any particular expectation it will fix your specific problem, but its worth a shot!)
-
How many SARs and FOI requests do you get?
psydii replied to enjay's topic in Data Protection & Information Handling
Fair. But practically speaking as I said, mostly "can you give me the info you have about..." is for data in the education record and we acknowledge and process as such. If they need it urgently, they usually say so, and we adjust accordingly, and if the scope is wider than that... its thrown over to the DPO and it likely becomes an SAR. Of course if they cite the DPA that does steer it somewhat. The fun happens when an estranged parent cites the DPA, so its a SAR, but consent is then withheld.... but if they'd sumbitted under the ERR then they'd get it (because the ERR gives parents the right of access). Thankfully our senco is pretty good at navigating the politics of that sort of thing while keeping us out of the firing line. -
How many SARs and FOI requests do you get?
psydii replied to enjay's topic in Data Protection & Information Handling
Internally we have policies on response times which are shorter than those of an SAR. Also most "informal" request for data/info (but still technically, potential SARs) are actually by parents for data that is covered under The Education (Pupil Records) Regulation 2005 and that has a **SHORTER** deadline that those for an SAR. We'd been handling those for over a decade before GDPR came along, so only when a request falls outside of the scope of that does it get thrown over to the DPO to manage. -
Advice needed on testing SIMS, Document Server and Discover restores
psydii replied to KeyData's topic in MIS Systems
A full bare-metal test? More often that we do, so I'd say at least once a year? However we are testing that we can restore the backup file generated by dbattach (i.e. extract it from the remote backup of the sims server) more frequently than that. Which is why I know our dbattach backup script has stopped working - the expected files were missing when I went to perform our most recent check! -
Just had a massive scare. Out nightly dbattach /backiup job was not doing what it was supposed to. The job puts the backup file into the MSSQL\BACKUP folder and then copies that to a safe location. Fine, except at some point dbattach seems to have started to return immediately, while the sqlserver plods on through with the backup. The script doesn't appear to be expecting this and is written so that the copy (and the other bits of house keeping) happen as soon as dbattach returns. This causes the copy to fail as sqlserver has the backup file locked (because it hasn't finished the backup!), and things get unglued from there. Anyone else seen this behaviour? or have I missed something?
-
Advice needed on testing SIMS, Document Server and Discover restores
psydii replied to KeyData's topic in MIS Systems
They way we've done it in the past is a full domain recovery + the sims server into an isolated environment. No need to dbattach, as the server comes back in full. -
How many SARs and FOI requests do you get?
psydii replied to enjay's topic in Data Protection & Information Handling
Yup. But informal requests received aurally or verbally are basically standard school - home communications and are either covered by the Education records act or the *intent* of the right to access of the GDPR, so mostly never cross into the realms of a formally logged and managed SAR. If they are more formally presented, or exceed the rights under ERR then they are (at least) forwarded internally to the dpo address. The "unlogged" stuff does of course generate an audit trail of its own, with all calls and emails needing to be logged in the communication record, and of course their are the technical logs and the actual emails etc providing evidence. These only matter if something has gone badly wrong, or somebody is very grumpy. -
How many SARs and FOI requests do you get?
psydii replied to enjay's topic in Data Protection & Information Handling
Similar numbers. There are of course potentially many more than this, but mostly they are just BAU school->parent communication - technically they could be SARs*, but nobody couches it in the legalize that gets it noticed and put on the SAR register. Only when the scope of the request (or where it was sent) raises a red flag or the language used makes it apparent the work needs to cross the desk of the DPO or SBM do we actually kick-off the formal SAR process. Our policy (and website) say that such requests need to be sent to a specific email address. This is monitored by the SBM, HT PA, and the DPO. Of course requests do arrive via generic email addresses, but these are monitored by the school office, who are well versed in forwarding emails to the correct location. Sometimes we just push a request back to the department that it should have gone to had it not been formally submitted to the DPO address to action, and the DPO just updates the register as it is completed. We get one or two really big ones every year, an the back and forth with the genAI that's writing them recently is frustrating. that said, we've had a couple of challenges to responses recently, and our process is sufficiently robust that our response to the challenge/query seems to have been found (by the genAI?) to be sufficient. *though one could argue they are actually Education Records requests. -
Can anyone recommend a reliable Microsoft Licence Reseller?
psydii replied to kwatt's topic in Licensing Questions
There are/used to be scenarios where the lowest cost way of licencing SQL Server (and the Windows Server (Datacentre) infrastructure to support it) is to have an OVS in place, and to do that you have to have Windows Client at a minimum level on the OVS. That you were already licenced for Windows Client via your CSP A3/A5 just makes it look painful, but the net cost was less than licencing SQL and Server any other way. Certainly a motivator to get off on-prem MIS. As an aside, I think Microsoft's internal KPI is "OVS number go down". I'm not convinced that MS care in the slightest about a school's server licensing arrangement if they are paying $$$ for Microsoft 365 A5. That said, the liability might quickly start to look like the sort of number that needs to appear on reports to the governors! -
How to properly export live settings in GPO applied to a machine
psydii replied to egoitzr's topic in Windows Server 2022
I had a big draft (which I managed to lose) where I'd dug into this via Win2k and 2k8 ResKit docs, and the old Windows 2000 Server help files, cross referencing the (slightly) updated info on the learn.microsoft.com site. Short short version: gpresult cannot do what is being asked here. what is being asked is how to compare the actual settings of the computer against what policy is saying they should be. One of the challenges is that with security policy "unsetting" a setting does not revert it to its previous state, so policy might say "unset" but what is actually applying is what was set previously. This is quite possible with in-box gui tools. But it is somewhat unclear whether this is possible to achieve with the command-line tools. -
Staff need to be able to log on via 365/Entra/Google ID accounts. I don't care what their back-end is doing. They also shouldn't need to have people log in with their back-end username and password. They have all the email addresses, just match on those. Also same for students just use 365/Google auth by default (though I accept a pin is easy and necessary in some cases). ..and they certainly shouldn't be breaking it so frequently.
-
Staff randomly unable to log in at home - local profile?
psydii replied to synaesthesia's topic in Windows 11
I wonder if it's maybe it's a by-product of some silent a/b testing in an update for "credential guard" that's bugging out and clearing/blocking access to the cached credentials. -
Staff randomly unable to log in at home - local profile?
psydii replied to synaesthesia's topic in Windows 11
I'm going to assume that you've checked GPOs for caching logon credentials settings or settings configuring the requiring line of site to the DCs? Don't forget to check Local Group Policy of the offending machine too in case there is somehow something there. (rmdir /s grouppolicy and rmdir /s grouppolicyuser is a handy trick for clearing out stuck/corrupt policy settings, I've found I've needed that a lot in the last 12 months, having never needing it in the previous 25 years) Also Is it possible that when they were on site, they were not actually connected to an ssid that allowed them line of site to the domain controllers? (i.e. creds aren't cached) or there is a dns/dhcp quirk that makes the device think it's got LoS to the DC (when at their house), and so then fails when the DC doesn't respond (because they are at their house). ..maybe they have a device on thier home network that has the same IP of one of your DCs? There are a few reports around the place for this sort of thing: Domain not available for single user while on different network - Software & Applications - Spiceworks Community (There's a link to a reddit thread at the bottom of that conversation that I can't follow right now, maybe there is some insight there.)
