Jump to content

psydii

Members
  • Posts

    5,195
  • Joined

  • Last visited

Everything posted by psydii

  1. That's why I ask about AV - its the one thing that hooks deep into the network stack and updates regularly - so just because it was fine yesterday, it might not be today. Also who knows what changes actually get rolled into monthly updates these days, so rolling a machine back to an older Windows build and testing that might also help eliminate variables. I mean it is most likely some sort of bug in ESS's code... but it is very difficult to get them to investigate properly.
  2. I've just been given the nod to stand up full remote teaching/learning capabilities for Monday.
  3. What AV do you have? Does it do network inspection? Try testing with it fully disabled, or with network inspection turned off. On both server and client. Also try with a clean LTSB Windows 10 build and see if the problem is replicable there. Final thing (and quite the long-shot) is everything configured to connect to sims via hostname, if not try updating things so that they do.
  4. If you have E3/E5 or EMS you should be eligible for FastTrack Support who should be able to help/guide you through the options and capabilities available to you. https://www.microsoft.com/en-gb/fasttrack/faqs#coreui-collapsibledrawer-5r2a3zq-collapsible-drawer1 Personally, we just have annual training, and termly refreshers on what is and isn't acceptable. FWIW Cloud MIS's are accessible from anywhere so making 365 harder to use than that seems unnecessary. However, if your organisation considers preventing data escaping onto private devices essential, then supply all staff with organization-owned-and-managed device, and use Conditional Access to restrict access to those only. If only a subset of data needs to be strongly protected, use Labels/AutoLabels to encrypt those documents. Set the label to allow the group 'all staff' so that you block unauthenticated 'home' access, but provide a transparent experience to authenticated users. So now even if they do end up on private HDDs, they are unreadable. Protect everything with MFA/Authenticator.
  5. Also Wireshark - I've found several errant devices with static IPs on the wrong VLAN/Subnet by just looking for unexpected IPs* in a Wireshark capture. *by filtering out the expected.
  6. The devil is in the detail, and that recent post by MS and highlighted by @HPlum78 shows there is a lot more detail to worry about since 2012. What is the business case for the migration? I wonder if an alternative solution might be a better fit? The alternative I would consider would be to go hybrid into a overarching tenant and then pivot the old domain to Intune/365 only. This would avoid the need to migrate all the ancillary services up to the central Trust AD, which is itself legacy at this point. You still have to do all the work, but you end up with a modern solution, rather than one based on the 1999 design documents. (FWIW I'm still heavily AD centric because the business case for pushing to 100% cloud, for us, is not compelling enough; integrating another site would definitely change this balance)
  7. This is for Macs. I am wondering whether I am thinking about Group Policy Drive Mapping, but I have a feeling there was a similar capability through Workgroup Manager for Macs and hoping that there is a modern equivalent.
  8. Hi, I seem to recall some voodoo from the 10.5-9 era whereby one could mount a share at logon, but have its name as it appears on the desktop be friendly i.e. arbitrary text rather than the rather tech-centric systematic name of the underlying share. e.g. actual share name might be \\serverx1.deepcuts.rmnetlm.local\Private$ but as it appears on the desktop "Work Files" Caveat: we use a script and JAMF to connect to shared these days, because startup items etc. don't seem to work. (I am not the "mac guy" any more, so JAMF is uncharted territory to me!)
  9. ^this Several very successful school leaders I have worked with make a point of identifying these people very early on in the change management process. The other thing I would look at is *why* this culture is there. We have recently broken out of it by leaning into it. (and spending money) The teacher facing tech was a mess, funds were made available to sort it out. Along side that, we (*SLT) announced *only* problems related to that could queue jump. Reports were to be by email to the service desk, and they would have a 15 minute break-fix SLA. It was a really rough few weeks as this settled in, but the new tech and the fast response to these limited set of problems made a huge difference. We got to what mattered, and the SLA on these matters meant anything else reported to the service desk also got a fast response unless a critical ticket appeared, (because the helpdesk techs were watching the queue like hawks). These critical tickets were identified by a keyword that had to be used by the teacher when reporting, and the system would also forward them to the Deputy Head to allow them to have visibility of the critical work load. After a couple of months, staff had learned how to fix their problems by watching what we did when we came to their rooms (win+p FTW) - because they knew that when they reported a problem it *also* landed at at Deputy Head's inbox and to them a 15 second self-service fix, is better than a daft email that interrupts a DH followed by a 5 to 15 minute wait for the helpdesk. 15 minutes was about the time it would take to get a response even in person with a large site and that they are not allowed to leave a class unattended. People learned that tickets raised on the helpdesk got the fastest responses, and service improved. Win-Win. Clearly though SLT had to buy in and support the addressing of the underlying service problem. We now have time for CPD and more general Service improvements and project work.
  10. Minimize dependencies on the availability of the network, particularly during the boot / logon phase. Don't use roaming profiles at all. With Windows 10 they are depreciated, and last time I checked, they are not supported at all if you are using OneDrive. Minimize the sorts of restrictions you put on laptops via GPOs, much of the accepted wisdom for securing devices in education is based on myths from 1998. Ensure the laptops can get updates when offsite - Windows Updates / Anti virus / Adobe etc. cache commonly used documents and folders - works best if using OneDrive / SharePoint. If using traditional folder redirection then Offilne Files should kick in automatically - but be very wary of syncing busy network shares. As an advocate of the CSC /Offline files feature since it was called IntelliSync, OneDrive/Sharepoint is superior in almost all ways that matter.
  11. The lack of reference to keys and the number 64 does not give me any hope that this is anything but reversable encryption.
  12. I think I saw someone just posted here about how they thought sims auth can have a better option, and then realised that the "better" option was actually way way worse To answer your second to last question first: Inertia. Though momentum for change has been building across the industry. To answer your questions about the lack of modern security practices: SIMS development has been relatively stagnant as market dominant cash-cows often become. The previous owner (Capita ESS) tried and failed to create a new web/cloud MIS over the last 10 years. Capita found itself in financial difficulty and has sold off the SIMS business unit, and the new owners are promising significant developments. While not meeting modern security best practices (or even best practice from a decade ago), last time I had a noodle around with wireshark on a SIMS Client->Server connection they were all protected by TLS. I have never heard of SIMS being breached through a technological hack. I'm sure there will have been kids who just figured out teacher passwords though. On Nova-T. The code for timetabling is as old as microcomputers. Nova-T is at least 25 years old, likely deep down older still. The major alternative (Timetabler) dates its core back to the 1970's!. If you think this is bonkers, go read up on what keeps the money flowing in banks. Finally on being able to do bad things if you have an unencrypted copy of the backup. Well, yes. Backups of the database should be well protected by NTFS permissions, and never be stored on removable media with out additional protections.
  13. Are you using Premium (formerly 'Advanced')? Steps if you are: Create a Case. (We name them against a helpdesk ticket number - and if particularly sensitive the helpdesk ticket only references a date code with the corrosponding DSL / HR's name) Case Format: NEW (this bit is important, almost everything that should have worked two years ago now works they way the documentation suggested they always should have.) Add the custodians (the student under investigation) I tend to keep both their their mailbox and OneDrive selected. Let the Hold and Index process complete, you can monitor this int the Jobs tab. Once the re-index has completed, create a "Collection", using date range as the search condition. I tend not to filter by message kind or any other aspects just yet. Add the collection to a new review set, give the review set a sensible name. TBH I tend to start with "Review Set 1" just for consistency. Let the collection process complete (monitor progress in Jobs tab) Now go into the Review set and with the analytics button/icon run "Document and E-Mail analytics" Let the Document and Email analytics process complete. Back in the review set add a filter -> Item Properties -> Message Kind. In the new message kind filter box, select you can now filter by "message kind" select "MicrosoftTeams, IM" (I feel like this option has changed in the last week?) You should now have a Results Set view of just team messages, threaded as best they can be. (threaded chat is a pain as it can branch and converge as people join and leave the chats.
  14. What's your internet line speed? If you enforce a seating plan, enable Storage Sense, and don't run apps that install per user (Teams, I'm looking at you), and disable Volume Shadow Copy we've found onedrive works well. We have a 1Gbit/s line and 256Gb storage on the desktops.
  15. Here the SEND team work with the teachers and the admin team. As far as I can tell, this results in teachers either putting in a special paper request for certain exams, or an SEND Team member taking a finished paper and duplicating it onto the correct paper for the student, depending on how busy/organised everybody is being. With Covid absences climbing, there are quite a few more last minute scrambles this year than previously. It probably helps that there is a healthy turnover of staff between the SEND and the Admin teams, and two HoD's started out as LSA's long ago so all involved understand each and the needs of the students well. Dispassionately I would say it is the SEND teams responsibility to check that access arrangements for the students under their watch are made correctly.
  16. Based on your last sentence: OneDrive on each device? It syncs document library to the local machine. Files On Demand (on by default) means that only files that have been accessed on that machine take up space. I wouldn't try to have a "server" running OneDrive and sharing out that folder over SMB, I imagine the reliability would be inconsistent at best.
  17. I am aware their documented position does not support this, but they'd never dare to enforce that particular clause, it would be suicide. It is probably there to make it completely clear that you need office installed locally to the sims client for sims to work as advertised, and its easier to say "Office 2019", than clarify the difference between Office 365 web apps and Microsoft 365 Apps. Also if a recent 365 Apps update on current or Monthly Enterprise Monthly does break something, you can always move to Monthly Enterprise and roll back to a previous version.
  18. I've seen this happen before. Solution? No idea. It just started to work again a day later. Try sticking wireshark in the middle and seeing what's happening on the wire. Tricky due to TLS but maybe some insight can be gleaned.
  19. The only reason @synaesthesia got his post in before me, honestly was because I removed the 'hell no' from my draft.
  20. Do not do this.
  21. Maybe this: https://support.microsoft.com/en-us/topic/kb5004442-manage-changes-for-windows-dcom-server-security-feature-bypass-cve-2021-26414-f1400b52-c141-43d2-941e-37ed901c769c Check Event Logs for the IDs mentioned in the article.
  22. No idea if it will work without the Store App being there, but you could try winget https://docs.microsoft.com/en-us/windows/package-manager/winget/ winget upgrade "Microsoft Photos"
  23. Would not a deny ace on the GPO work?
  24. There was a lot of spam coming from the 40.92.xxx.xxx servers, probably due to multiple tenant compromises. Possibly related: email from met.police.uk has be dropped into spam for us over the last 24hrs, even emails that were replies to messages originating in our domain... so given other threads here, I would say the email transport team over at Microsoft are having a bad month.
×
×
  • Create New...