psydii
Members-
Posts
5,195 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
You can, but you have you stopped and considered whether you should? Your aggregation switch has an IP in each vlan that is configured to be the gateway/router address for all clients in that vlan. The aggregation switch has routing enabled. The router knows how to route packets to the appropriate subnet, not where the individual device is on that subnet, so into which vlan is it going to send it? It requires blurring of the logic between Layer 2 and Layer 3. You can of course legitimately have multiple subnets per vlan. But a subnet spanning multiple vlans is inviting chaos into what should be a relatively deterministic system.
-
We have a group that has permissions to 'all' users' OneDrives we used ideas described here: https://morgantechspace.com/2018/03/add-secondary-site-administrator-to-all-odfb-sites-powershell.html But almost exclusively teachers ask their students to share a folder rather than ever asking for full access. There are issues around safeguarding if staff have arbitrary access to all OneDrive's.
-
On Ryzen laptops - I think we have a few here in the hands of teachers... will have to check. On USB-C cables, we've had good luck with these: https://www.amazon.co.uk/gp/product/B094CCJMFV?th=1 The key seems to be the SuperSpeed logo which indicate they have passed certain tests. That said, we have pretty much abandoned USBC for DP delivery as our (intel 2016-2019 hardware) laptops and docks could never maintain connectivity.
-
Large secondary in an LA.
-
Access for the whole finance piece. Though we are a SIMS school for the foreseeable.
-
Recovery from ransomware is a feature of 365 https://support.microsoft.com/en-us/office/restore-a-shared-library-317791c3-8bd0-4dfd-8254-3ca90883d39a?ui=en-us&rs=en-us&ad=us
-
Aruba - Finding the Port a MAC Address Sits On?
psydii replied to JRA's topic in How do you do....it?
If you have nothing then doing it by hand works. start at the root bridge sh mac-address MACADDRESS gives you the port by which packets leave the core switch to head off to the AP. - probably at this point there is a switch on the other end of this cable. then sh lldp in re to confirm the details of what is on the port then ssh into the next device along and repeat until you find the device/port you are looking for. We have a NM tool that does it for us, but if I'm up to my eyeballs in cli, I'll often do it the long way to avoid breaking my flow. -
Counter-point for 365 specifically: https://docs.microsoft.com/en-us/compliance/assurance/assurance-customer-and-cloud-partner-ebcm-responsibilities In the context of the Azure responsibilities matrix, *Microsoft 365* is the customer. We are the customers of Microsoft 365. Of course you can shoot yourself in the foot, and getting Retention Policies etc correct may be more effort than just paying for cloud backup for smaller organisations that don't have dedicated roles/teams within their IT Service for this sort of thing. (VEEAM is way easier than getting my head around retention tags/policy and the changes that have come through over the last five years)
-
JThompson's response got me looking into this. Folder structure contains information and represents many days/weeks/years of work. It is not preserved by the holds/retention and cannot be recovered if deleted. A *possible* mitigation would be archive mailboxes, but those are also vulnerable to accidental/malicious deletion of items/folders (but there is a good chance you'd have the structure preserved in either the main mailbox or the archive mailbox, which could then be recreated by hand) Got to say (and tempting fate), in 20 years of managing exchange "recover my folder structure" hasn't ever come up, only ever recover a deleted mailbox, or a deleted mail, but I can see how it could be devastating.
-
These guys do this a lot. https://www.allabout365.com/2020/10/learn-about-new-tenant-to-tenant-migration-capabilities-in-the-latest-all-about-365-podcast/ I can't remember if I have listened to this specific episode, but they will often name check their employers or other trusted companies, as well as having ad-reads for services. For reference in case others find this thread when considering doing this themselves: There is a guide from Microsoft that covers things at https://docs.microsoft.com/en-us/microsoft-365/enterprise/microsoft-365-tenant-to-tenant-migrations?view=o365-worldwide and one specifically for mailboxes: https://docs.microsoft.com/en-us/microsoft-365/enterprise/cross-tenant-mailbox-migration?view=o365-worldwide SharePoint migration tools are here: https://stokenewingtonschool-admin.sharepoint.com/_layouts/15/online/AdminHome.aspx#/migration Guides for mover.io (Microsoft's public tool that can do SharePoint Tenant to Tenant migrations) are here: https://docs.microsoft.com/en-us/sharepointmigration/mover-o365
-
What is the case for needing a backup of the mailboxes? Would a retention policy suffice?
-
We don't have caps here, despite 1000 students on the network with their phones. AC wireless 1Gb/s internet line. No throttling and No performance issues seen. Might be different if we were a Uni, but we'd probably apply filtering/limits at the core/firewall level rather than at the APs From the Wifi perspective airtime management in the all the brands of APs we evaluated back in 2018 were perfectly capable of equitably carving up access to various classes of user with out us having to apply bandwidth management.
-
Just flagging this one up again, as the roll out is happening now and its ON BY DEFAULT. https://techcommunity.microsoft.com/t5/microsoft-teams-blog/microsoft-teams-users-can-now-chat-with-any-teams-user-outside/ba-p/3070832 https://docs.microsoft.com/en-us/microsoftteams/manage-external-access These capabilities also touch on the new Parent App, which while not yet full featured hold a lot of promise. https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=83593 https://docs.microsoft.com/en-us/microsoftteams/edu-parents-app https://docs.microsoft.com/en-us/powershell/module/skype/new-csexternalaccesspolicy?view=skype-ps https://docs.microsoft.com/en-us/MicrosoftTeams/batch-group-policy-assignment-edu
-
Switchshop might still have someone who knows their way around legacy meru kit.
- 2 replies
-
- fortinet
- meru mc4200
-
(and 1 more)
Tagged with:
-
Bromcom support just said that it doesn't require admin permissions to run. Only admin permissions to install. Provided you are not using Roaming Profiles. Disabling Roaming Profiles for the timetabler is a lot less onerous matter than granting them local admin.
-
Not quite that command. I did them one at a time using their names rather than numbers. It was a couple of years ago, but thinking about it doesn't bring me out in a cold sweat, so... fine I guess?
-
GDPR - Students Doctors details
psydii replied to markberry's topic in Data Protection & Information Handling
While it may not be for the school to contact the GP, the GP is a Professional point of contact for the family, and in exceptional circumstances (such as the child has disappeared and the family is not responding to contact) should be contacted. While the LA may hold legal responsibility for making this contact, who has the most accurate contact information? Consider a scenario where a parent is medically vulnerable and this has not been disclosed to the school or LA. The GP likely knows. In the event a child has an unexplained absence and the primary and secondary (not that all students even have contactable secondary's) are not responding, is it not reasonable for the appropriate authority to contact the GP in case they have a) had recent contact, and b) are aware of medical issues with the primary carer that may warrant an immediate intervention (disclosable under Public Interest)? -
LOL. Universal groups all the way baby! I really can't remember why GG-DL group nesting was the recommended way of doing things in the training back in 2000, but I'm pretty sure unless you are running a multi-site with multiple domains in multiple forests there isn't any need to use global/domain local any more. I used to implement local groups on servers to control access to resources on that server (members being groups from the domain)... however it became relatively straightforward swap groups on ACLs in the middle of last decadefifteen or so years ago, so I haven't bothered since, and using Universal Groups in ACEs certainly made the migration to SharePoint Online very straight forward - the permissions just came straight across! FWIW we use "role" groups for each role their might be in school. A DH JD is a large collection of roles. Some roles nest inside of each other. access to resources are controlled via "resource" groups. Resource Groups only contain "role" groups as members. (print permissions, file/share access, mailbox access, certain bits of SharePoint/ Office 365, MS 365 Licences etc etc) Distribution groups also only contain "role" groups. When someone joins or changes or gains a role, we made one change in AD and everything else just flows. We prefix the groups so we know what type they are, and for each resource we might have three groups - _read, _write _fullcontrol. The terminology used matches the target resource nominclature. Each team (department etc) would have four role groups, _admin _leader _2ic/PostHoldeTitle, all nested in _member (because each of those roles is a member of the wider team role). Departmental _leader groups are members of the Head of Department distribution group, and the relevant budget group (for papercut reporting). _members groups are members of teh relevetn departmental budget group for print/photocopy charging. Since those in the _admin group have dotted line management to the Business Manager's team, they also are members of a support staff group. etc etc etc. It keep permission neat while allowing a great deal of flexibility, and thanks to a reasonable pro-active HR team, the whole thing is basically seamless to users.
- 1 reply
-
- 1
-
-
We have Microsoft A5 and use a lot of the features, particularly around what is now called Defender. It is a fully cross platform security system. It is very powerful, supporting us with safeguarding and GDPR compliance, Microsoft Information Protection, retention policies and Advanced eDiscovery is where I spend most of my time at the moment. We also use: Teams Conferencing, Booking, Phone System, PowerBI Pro, My Analytics (was Cortana, and is now Viva), AIP (now MIP), Advanced Auditing, ATA/Defender for Identity, Cloud App Security, Defender for Endpoint, and the Server CALS. Slightly out of date now I think, but here is a good start on the differences: https://docs.microsoft.com/en-us/office365/servicedescriptions/office-365-platform-service-description/microsoft-365-education GDPR, a near miss on ransomware and then the risk of a pandemic made the case for us. The Safeguarding team have been very happy with the level of detail we can drill into when needed.
-
Deleting user profiles via powershell at shutdown via GPO
psydii replied to IT_Man_Dan's topic in Windows 10
I can't say I have looked. The devices run without issue. -
Can anyone with a large SIMS server share their typical max IOPs*? We're seeing up to 1200 max, typically averaging around 18-90. I suspect that we are hitting the limit of of our aging HDD based SAN at the top end, and would be interested to see if those with Enterprise SSDs underneath SIMS see significantly higher. *For the purposes of this thread I'm really referring to the Windows Performance Monitor: Physical Disk"Disk Transfers per second" counter.
-
GDPR - Students Doctors details
psydii replied to markberry's topic in Data Protection & Information Handling
...quite possibly, but who holds the contact details? -
Do you have 2 way radios on site? Our Motorola radios have a panic button: https://www.radio-links.co.uk/two-way-radio-sales/motorola-digital-radio/health-safety-features https://learning.motorolasolutions.com/node/7408/download
-
GDPR - Students Doctors details
psydii replied to markberry's topic in Data Protection & Information Handling
Ok how about safeguarding? In cases of unexplained extended absence, when other avenues of contact have failed it would be appropriate to contact the GP to see if there were any potentially relevant concerns there given the circumstances. It may be that the school isn't the one to make contact (the an officer of LA might be more appropriate at this stage) but having multiple methods for reconnecting with absent students is essential.
