psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
If you are a pure WSUS user, following up on this tweet might be in your interests:
-
Because they are required to by policy, they have annual GDPR refresher training, and they are reminded twice during the year and like you, finance check in with me. Also nothing can authenticate through 365/Google without Global Admin consent and we have Sophos / Defender looking out for data exfiltration - we occasionally catch student data trying to leave via email, so we have technological tools in place too. Is it 100%? I doubt it, but it the DPO feels its a good enough effort. We even review our DPIAs.
-
ALl new software and services are reviewed through a GDPR lens here before any technical review takes place. If the software or service has a privacy notice, start there. If it does not, yet has a cloud component, then don't use it as you already know that they will not have built it to comply with GDPR. If there is not a privacy notice and the software appears to run local only, reach out to the developer. If you still have concerns that it *might* exfiltrate data without permission - deny the request - or fire up the monitoring tools (Fiddler/Wireshark and Procmon) in a test environment and see what it really does. I wear the onsite Data Protection hat and the IT Manager hat - so all new software and services cross my desk before being approved for use / install, all new applications get a DPIA. Often I have to give a hard "no" before i get very far into reviewing, but equally often I can bounce my concern to the DPO (outsourced) who will do the heavy lifting regarding reviewing policies and talking with the developer. DPIA's are signed off by the DPO (or sometimes get sent back for more work/denied.) It is all about managing risk. Generally these days its not much about local apps, and much more about 3rd party services that want to connect to 365 or Workplace. These all have privacy notices that can be reviewed. But generally if they want to connect and maintain access to OneDrive/ Google Drive/email, they get declined either by me or the DPO, even the ones based in the EU/UK, unless they have additional protections around staffing/safeguarding or preventing their staff from viewing our personal data.
-
Here's blog about deploying it per machine with Intune. https://mrshannon.wordpress.com/2022/06/06/get-updated-quick-assist-and-webview2-for-standard-users/
-
Applications are becoming suspended for one member of staff
psydii replied to cheaptonersucks's topic in Windows 10
This is strange because the received wisdom is that Win32 Apps don't support the 'suspended' state. I did see a note about Chrome sometimes getting in the state due to a corrupted profile. This lends further weight to deleting the user's local profile and allowing it to rebuild, but you have already tried that. My guess at a root cause though would be some anti-malware / Remote administration tool fouling something up*, perhaps with a transient update, but once broken the problem persists. If deleting the user profile doesn't work, then a wipe/reload of the machine is perhaps in order? *a dependency on a disconnected network share, slightly faulty hardware, or a dodgy driver can all also put unexpected blocks on applications, that then in turn trigger the same sorts of bugs that blocks cased by anti-malware software do. -
It may be because we also license through a CSP, but anything that we still have on OVS-ES that we'd traditionally get from the VLSC is currently available via educationstore.microsoft.com manage->products and services
-
Isn't there a web version that works just as well now? "No app or add-ins to download. With new HTML browser clients, leverage almost all capabilities with a single click, right from the browser. Never miss the audience whose IT policy may prohibit web downloads. Host, share, collaborate, and train anywhere, anytime, with the Adobe Connect mobile app for Android and iOS. Download Now "
-
Adobe Creative Cloud - without Azure
psydii replied to gerardsweeney's topic in How do you do....it?
Other than deploying the licence, I think its the same as for Named User Licences packages: 1) use the adobe console to create packages with the 'enable remote update manager" option selected. 2) Use SCCM/MEMCM to deploy those packages 3) Then use the Remote Update Manager to update the installs for the next year, until you are ready to update the packages and redeploy (which is typically a summer-break sort of job) RUM can have proxy username and password added. https://helpx.adobe.com/enterprise/using/using-remote-update-manager.html If you don't want to use RUM, then you can just use the admin console to update packages monthly and have sccm deploy those - though this can put a strain on the server/client disks depending on how big your installation packages are and how many computers you are deploying to. -
Problem With Firewall Service on Windows 10 with lots of users login
psydii replied to mc303's topic in Windows 10
If you upgrade a workstation to 21H2 does the performance issue persist? -
Recommended Network Replacement Installers
psydii replied to gwendes's topic in How do you do....it?
SwitchShop XMA https://www.itecgroup.co.uk/ -
My first thought here is that it might be a failed Optane drive? These are oddly structured and you need to follow slightly different steps to recover than for more traditional HDD/SDDs
-
Time to check your Azure AD Connect installation! If you are on v 1.x you *must* upgrade to version 2.x before the 31st August 2022. "I am not ready to upgrade yet – how much time do I have? You should upgrade to Azure AD Connect V2 as soon as you can. All Azure AD Connect V1 versions will be retired on 31 August, 2022. For the time being we will continue to support older versions of Azure AD Connect, but it may prove difficult to provide a good support experience if some of the components in Azure AD Connect have dropped out of support. This upgrade is particularly important for ADAL and TLS1.0/1.1 as these services might stop working unexpectedly after they are deprecated." https://docs.microsoft.com/en-us/azure/active-directory/hybrid/whatis-azure-ad-connect-v2
- 32 replies
-
- 13
-
-
Don't rely on USB C. Failure rates on USB-C connections (for various reasons) seems to run at about 2% of devices per week. Buy HDMI -> VGA adapters instead. Failure rates on these is around 10% per year.
-
You want to stop using 365 for email and start using Google. It sounds to me that you want (in MS parlance) a cut-over migration. You will need to add the domain to all your users in the Google administration console. https://support.google.com/a/answer/7502379?hl=en#:~:text=Add%20Domain%20Alias%20Gmail%201%20%20On%20your,Treat%20as%20an%20alias%20box.%20.%20See%20More. You will need to update your MX records to point to the google servers allowing inbound delivery of mail from the internet to their google accounts. Replace the ones that point to 365 servers. https://support.google.com/a/answer/174125?hl=en You will need to add/update your .sch.uk domain's SPF and DMARC records to authorise the google servers to be sending email for your domain. https://support.google.com/a/answer/2466580?hl=en This last step is very important. We often have to get emails from Google Schools out of quarantine because their admins have not correctly configured SPR/DKIM/DMARC. Migrate the old 365 mailboxes to Google. (though, perhaps not... If your data retention policies allow, now might be a good time to age-out all that unnecessary archived mail and save yourself a GPDR headache...) https://support.google.com/a/answer/9476255?hl=en#zippy=%2Cstep-set-up-the-data-migration-service%2Cstep-migrate-email-from-exchange
-
When I last had problems with an HP CP series https://www.ebm.co.uk/solutions/ were the only people who managed to help. At the time they had a team of engineers who really knew the products. We did pay them for the privilege, but they initially proved themselves with some highly effective advice provided pro bono. It was a few years ago, so I don't know if they've kept that team/service going.
-
10 year LastPass user here. They recently destroyed my certificates and ssh keys. Apparently they now only support certain file type as attachments, and if you had any already uploaded that were not of that type, then they are effectively lost.
-
Well for the next six months or so you should be able to link SCCM/MEMCM to the education store, and deploy them as Applications. https://katystech.blog/configmgr/deploying-apps-from-the-windows-store Apparently after that, it's back to the dark ages for a Debian c1999-like experience with scripting and winget. https://www.anoopcnair.com/install-app-windows-package-manager-winget-sccm/ Ooh this just popped up in my feed. Perhaps the future? (Powershell was designed by people who understood what system administrators need to do to)
-
The acer b3 line are surprisingly good and we’ve got ours running Windows 10 Education. I haven’t touched one of those Surfaces yet.
-
SAR Exchange Output Using Purview
psydii replied to MartinT's topic in Data Protection & Information Handling
Can you not redact inside Purview and then export to pdf direct from their? That said we tend to go the long way round. Export to flat files, individual emails becoming an .msg, convert these to PDF and then redact each one in turn. It allows us to break the job up between people and also track and review progress. Also we get a master list of unique identifiers for the emails if we ever need to revisit ones where a redaction was challenged. -
I believe they will supply the data in json format upon request.
-
Installing applications as an end user using admin login details
psydii replied to SJ98's topic in Windows 10
SCCM can deploy per user, and so can GPOs. However I suspect this particular software is some janky exam-proctor or e-marking app and manual install is the only way to get it to work? -
Old printers listed when searching for printers
psydii replied to Tom_P's topic in Windows Server 2019
Could they be being cached by mdns/llmnr or similar? Perhaps stick wireshark on and look at the network traffic during the discovery process to see where it is getting the information from? -
Setting a Group Manager for Security Groups in bulk
psydii replied to woollsr's topic in Windows Server 2019
FWIW, we have each group as CI in our CMDB/Service Desk. The ticket history gives us the information regarding who requested the group, its purpose and changes thus by inference its likely current owner/manager. This way when we review groups we have a better chance of working out who the owner is, than finding a 'link' to a long deleted user id. I have experimented with setting the manager field for groups but found this introduces odd user experiences where Office and Office 365 are expecting only people to have Managers.- 1 reply
-
- 1
-
-
- active directory (ad)
- managed by
-
(and 3 more)
Tagged with:
-
Old printers listed when searching for printers
psydii replied to Tom_P's topic in Windows Server 2019
Not relevant to your issue today, but you should probably disable the spooler on the DCs and only spin it up when you need/want it to prune, before shutting it down again.
