Jump to content

psydii

Members
  • Posts

    5,195
  • Joined

  • Last visited

Everything posted by psydii

  1. Given you have gone splunking with ADSI Edit, this train of though probably wont lead anywhere, but is the spooler service enabled on your DCs and do you have "allow pruning of published printers enabled"??
  2. Remote Help: £3.50 per end user per month, and you can't buy per month any more, it needs to be purchased in 12 month blocks.
  3. ...however it may be pertinent to the subject's legal complaint, which is where the legal team need to cast their eye over it and get to call the shots, because in a bun-fight, there are other mechanisms by which a complainant can get access to the emails. BTW I'm pretty sure in your example the $pupilForeName is actually $StudentTeacherForename, which may make this email highly relevant if (say) the complaint is about how the school handled supporting them as the Student Teacher lead...
  4. This is a pain. However, can it not be pushed to the clients via EndPoint Manager or side-loaded? Actually I can see some sense in this change... Quick Assist is a bit of a security weakness (easy-ish to socially engineer remote access)... so by blocking it by default and requiring admin rights to install enterprises have that problem removed.
  5. If they are persuing legal action, I would very much recommend that you run the whole thing past your legal team as well as the DPO. The DPO will ensure you disclose what you are required to and make sure you do not disclose what you must not. There is a wide area between those two positions where the legal team may have a view. Ultimately this is between your DPO and your legal team, and it should be made clear who has ultimate authority in signing off the release of the SAR. I would say that emails between individuals are only within scope of an SAR if they //edit// contain information //edit// *about* the subject.
  6. Interested to know what workloads you’ve moved to azure? Did you go native, or are you running VMs? How much do they cost, and how does this compare to running on-site?
  7. Yes that is what I meant.... was the email sent to that email address or was it sent to an alias? My understanding is that if a domain exists attached to a tenant and the user exists then it should just work. Its only if the user/tenant does not exist then some sort of self-service provisioning needs to happen, and this is what most admins block (if they were made aware of that option when they last configured that bit of their tenant).. Which is to say, if the documents were shared with the Head's email address which is the same as their 365 UPN, it should just work? Perhaps the act of attempting to access these files requires some additional licence? Do they have an A1 or better licence assigned?
  8. Is the Head's 365 account UPN the same as the email address to which the link to the files was sent?
  9. 'works fine for us' As long as its got 64Gb storage 4Gb RAM and 4 cores, and the Shared Device profile, it's fast enough.
  10. I'd add an archive.org link into the mix too. I don't trust google not to purge abandoned videos at some point in the future, or even pivot away from user uploaded content completely. https://archive.org/create/ As for physical media, having multiple media, and on each media having multiple copies, with some checksum files to counter bit-rot, and then have multiple encoding options. https://www.dpconline.org/handbook/technical-solutions-and-tools/fixity-and-checksums#:~:text=A%20checksum%20on%20a%20file%20is%20a%20%E2%80%98digital,range%20of%20readily%20available%20and%20open%20source%20tools.
  11. I find doing a favour for a head teacher and other schools improves my clout.
  12. I suspect our problems originate because we went USB-C before the Thinkpad/Intel USB-C disaster happened (https://www.tomsguide.com/news/nearly-all-thinkpads-have-defective-usb-c-ports-what-to-do-now) , and some damage to devices seems to be communicable. But on multiple displays, there are limitations on how many displays are supported. The docks may have two DisplayPort, an HDMI and a VGA, but with our laptop/dock combos you can usually only have two displays at a time. It gets very complicated: https://support.lenovo.com/us/zh/solutions/pd029622#USB-C%20dock We did get the advice that higher powered AC Adapter may solve the problems. Our devices are quite low-end in power needs, so we didn't find any appreciable improvement testing a few rooms moving from the 90W to 135W adapters. (Given the laptops were supplied with 60W adapters, 30W ought to be enough to drive the dock and displays). One strangeness we did discover though was that while most HDMI-VGA adapters on most of our laptops/rooms were fine... some combinations would not work unless the HDMI-VGA adapter was supplied with additional power via is USB port. When we wired in usb power from the dock to the adapter everything was fine. So that's what we did in all rooms. Advice on power adapters for the docks is now up on the lenovo support site: https://support.lenovo.com/gb/en/accessories/pd500519-thinkpad-universal-usb-c-dock-overview-and-service-parts
  13. anecdata, but I concur. Every time we've had a machine break after monthly updates recently, its because it hasn't taken a 21hx Feature update and is on a 20hx or 19xx build. Everything on 21hx has been absolutely fine.
  14. The answer is to bypass the usb-c dock and use HDMI for video and audio to the front of the classroom, and hope you don't hit the power management problem.
  15. We've had nothing but trouble with ThinkPad USB C docks. Latest firmware on laptops and docks has helped a huge amount, as has ensuring that cable is USB consortium branded "SS 10+" or "SS 20+" with power delivery. However what made the biggest difference was moving to connect video direct to the laptops via HDMI or HDMI adapter. 90% of tech problems in the classrooms were eliminated by simply not running the critical capability over USB-C. We keep some rooms/office as usb-c purists to monitor changes in reliability. A couple of weeks ago a new one happened. If a laptop was restarted while connected to the dock, the CPU would then throttle to 600Mhz-1.2Ghz. Removing the cable it would jump back to 1.8-2.8Ghz. Using a new cable would maintain the CPU performance. Using the old cable the poor performance returns. Rebooting the laptop and dock while disconnected from the cable, then restored capability to the original cable when it was reconnected. Once a laptop was in the slow state, the cable that was attached at that moment can no longer be used until a reboot. A new cable will work unitl it too is affected, and so on. USB-C with PD and Alt Mode is not reliable. Turns out the issue was documented by Tay, years ago, its just that things have been so janky for us, that this is the first time it has been the worst USB-C derived issue we were experiencing.
  16. Microsoft 365 E5 is absolutely the toolset you should be pushing for. It has all the technical tools you need to make this work well, without needing to go back and ask for more money to fix things later. You will get a lot of support form the FastTrack teams as you stand up each new element. If you can you really must ensure there are automated processes for sending HR and Student on-roll data into AzureAD/365. (https://docs.microsoft.com/en-us/schooldatasync/overview-of-school-data-sync). Getting the design of groups right and the processes for keeping them updated fundamental to success. One account per user, granting them the appropriate access to the appropriate resources, depending on the state of the device they are using at that time. Seamlessly, Secure. Your focus is devices, so Intune / autopilot and conditional access will be the right way to go in this scenario. Treat the legacy devices as BYOD, how you deal with new devices really depends on how the politics is navigated. If the Principle/Chancellor wants things centralised then you almost have a free hand to build out the perfect system, (new device purchased by IT as a service to faculties, and managed as such). Otherwise some level of compromise between what it right for the reliability of the service and security against what the end users *thinks* their need are will be required. Is there a modern equivalent of the 70-221 course material? I seem to recall it contained enough abstracted principals for it to still be useful, even if it technical content is based around on-prem AD. https://www.pearsonitcertification.com/articles/article.aspx?p=30481 This problem here is more about people and politics than technical details. The above link might give you useful pointers on what sorts of things you need to consider. Outline of chapter two of that book: It would be a good idea to get a solid grounding in 365 and Intune first though: https://docs.microsoft.com/en-us/learn/certifications/microsoft-365-fundamentals/ https://docs.microsoft.com/en-gb/learn/paths/manage-enterprise-deployment-m365/ https://docs.microsoft.com/en-gb/learn/paths/defender-endpoint-fundamentals/ https://docs.microsoft.com/en-gb/learn/paths/m365-information-protection/ While compiling that list (I need to update the training materials for my own team, so excuse me if I'm deep diving this a bit) I found this which, at a quick glance, appears to cover similar ground that old course: https://docs.microsoft.com/en-gb/learn/paths/m365-service-adoption/ As for a simple reciepe to success my gut feeling is that you should bring in old devices as BYOD and mostly "untrusted" you can run with that model for a year or two as you get expertise with intune and 365 and conditional access. While you are doing that, new computers for those that don't need admin can be centrally managed and secured (Intune/autopilot/defender). Once you are really good with conditional access and security, you can then offer fully managed devices (where users read and sign an AUP) *and* allow people local admin.
  17. I sort of knew that deep in my soul. But that is daft. We require executables to be correctly signed and in the right places (applocker). This stops most incidents of *END USERS* running stuff we don't want them to, including many many pieces of malware over the years. Of course there are/were bypass techniques (I've seen a Year 11 wrapping exe's as dll, and dynamically loading it via flash embedded in a pdf), but they should not be trivial. Just because you can run code on a box does not mean you be considered to have SYSTEM level of access, that is denying the entire design and purpose of the NT security model. Powershell should honour the instructions of the administrator, I mean if the user is admin, then sure let them bypass the policy (maybe?) but an end user? No. That said the horror show that having python on a computer opens your network up to is something I choose not to consider lest staring into the abys breaks my mind. (hint, Modern security tools basically don't look into what is going on in app-store python or WSL so chaos can be launched from there without leaving traces in the more well understood logs)
  18. 4 cores/ 4 gb ram / 64Gb storage (intune shared device config) or 4+ cores / 16Gb Ram / 512 Gb Storage (traditional AD, MEMCM) Anything in between (or below) those specs, for shared laptops, do not work well for us. Intune managed devices seem to manage to handle their updates overnight without problems. MEMCM devices are configured to hold off from updates until we take the set out of circulation and open up a maintenance window. Ownership of the devices is key. after 15 years departments have learned that there really will be no additional IT Suite offered instead of the trolleys so they have to make them work. It should be noted that before they learned this lesson, they also didn't manage to look after their IT Suites either, so we had hard data to support our assertion that it was staff apathy rather than a fundamental technical flaw that was the route cause of issues. (c.f. with other departments that instinctively looked after their IT Suites/Devices and comparatively had 'no' issues.). 1:1 is also reliant on ownership, personal responsibility, and collectively a culture that expects issues with devices to be reported and resolved promptly, but those values are easier to instil when the end user is paying for the device.
  19. We often buy five licences a year. I've seen it used well from time to time.
  20. In our setup code signing certs can only be requested by members of a particular security group. Members of this group are not DA or even Local Administrators. Each Desktop Support tech gets an account for doing admin work on end user devices. GPO makes these accounts admin on a subset of machines. These accounts are members of the Protected Users group. Devices cannot communicate laterally due to local firewall rules. (If I was going to be even more secure, we'd add the tech account to local admin on demand and only for the duration of the work they were doing.) They have to write and sign their scripts in their day to day non-administrative account. https://stackoverflow.com/questions/67270197/windows-powershell-policy-execution-bypass?msclkid=727f3d9ac70311ec86d8b7e14af1d8e5 echoes my understanding of the topic. If code signing is required by GPO a user cannot bypass it. That said there are several things I see regularly managing to launch with the -executionpolicy bypass flags (something to do with Defender I think).. so I am not at all sure whether being system offers a way for bypass to work. But at the end of the day if you are admin/system and a bad guy, you've won that box, and any others that share the same admin username/password.
  21. Worth noting who owns Dragon/Nuance these days....
  22. Here, people writing powershell scripts are issued code-signing certs from our enterprise CA.
  23. Definitely give Microsoft Translator a go, its an app available for Windows, iOS and Android.
  24. The scenario we have is that we currently need apps that are deployed via SCCM... can we have some apps deploying from Intune and others deploying from SCCM/MEMCM on to the same client machine? What I've read suggests that for each workload you either have Intune *or* MECM / SCCM with authority.
  25. While we do use Intune to manage our DfE laptops, we use AD and SCCM to manage our traditional fleet. We've been looking at what is happening around the Microsoft Store For Education/Business and winget etc. Absent any useful update from Microsoft at nearly half way through the final year of the MSfB, we are trying to figure out how we will install and update the 'Store' apps once the SfB/SfE is retired, on our SCCM managed fleet. I don't *think* we are in a position to move our app installation workload to InTune just yet - we have too many legacy apps, and the ever changing Creative Cloud Suite, and while great on a single machine, trying to use winget at scale reminds me of when I had to write update scripts before WSUS existed. Can we have apps deployed via Intune and SCCM on the same client? How hard is it to move app installation to Intune, when we are talking about tens of gigs of application data, and legacy (customised) install packages?
×
×
  • Create New...