psydii
Members-
Posts
5,194 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
The Shared Device profile in Microsoft Endpoint Manager (formerly InTune) is pretty good. It makes them work quite a lot like a ChromeBook, but with the ability to run win32apps. With a bit of jiggery-pokery you can get them integrated with legacy services over smb (GPO, File and Print Shares)... however DO NO DO THIS*. Just accept them for what they are, and build out alternatives - that you will likely have already pivoted to to provide services during the pandemic. While we haven't finished getting it right just yet, PaperCut seems to be the key 3rd party product one needs. *You may need domain joined with a GPO for 802.1x device based authentication. Some WiFi systems have a suitable alternative deployment, but typical out of the box solutions from the big vendors do not (Aruba, Cisco etc). If you go down this route keep the GPO to the bare set minimum, and where ever possible deploy settings via MEM.
-
Can you replicate the problem when you hop on to the student computer with Quick Assist?
-
No idea but that's not good, they'll probably be able to walk right past onprem filters.
-
Not formally, opened:closed ratios (per week, per month, per term, etc - should be close to 1:1) Tickets open per technician. Time to close (physical repairs) - ideally the initial incident is closed within minute/hours using a suitable workaround - but the time to repair the fault device is important for setting suitable levels of spares stock. Rate of tickets per device type - For providing evidence that the replacement device schedule we agreed on four years ago remains valid, and no we can't skip the refresh this year. Total number of Incidents per period Total number of Change Request per period Total number of Problems per period
-
If not proxy, see what happens if you dial the MTU on a client down to 1280.
-
Sharp (who also own SmartBoard and make iPhone components) bought them and revived the DynaBook brand. Really impressed how they also made the driver and support docs back catalogue available. The Dynabooks we've recieved as part of the scheme are suitably basic - but I have much more confidence in them than the post financial scandle/Fukashima Toshibas.
-
If you are taking on the load previously carried by external companies, your pay should reflect the uplift in responsibility and skills. You should definitely be looking to move on. Right now you can spin the additional work you have taken on as a positive on your CV. It may soon become a burden on you personally. With the reduction in hours, the work cannot get less (unless they reduce their expectations in a documented and measurable way). It is time to move. As for how many techs per student, it really depends on what the school is doing. How many computers, what the internal SLA's (or expectations) are, how embedded IT is in the delivery of the curriculum and how involved it is in 'new things'. A static, locked down network, with known apps, and uniform classroom deployments, conceivably might be manageable by a single person for a few years (until upgrades require more time/manpower/skills). I would suggest that two well trained people managed by a technically sympathetic Deputy Head or Head would be sufficient to keep things ticking over, and leave capacity for improvements should budgets ever allow it. (The techs should almost be peers rather than senior/junior or NM/Tech).
-
Yes they are. Raise a ticket via the admin portal. This is clearly unintended behaviour. Don’t let them close the ticket, request escalation. If the direct you to a user voice post, go and vote on it. Be sympathetic to the people you speak to but do not accept being fobbed off. If you are on A3/5 speak to your account manager, get them to shout about it too. Disabling anonymous access stops the bypass. But that is not practical for many orgs that need to engage with members of the public.
-
I'd wait until MS Support cleared it up. YOu may have to be patient as the initial handler might not put you through to quite the right team at first. This problem is relatively niche.
-
urgh. sound like you are in second scenario from my initial reply. If you have a CSP (Microsoft partner reseller who 'owns' you relationship with Microsoft's cloud platforms) call them. If not, you'll need to open a ticket with MS Support via the portal (go into help and just work through the wizard).
-
Personal Device InTune Management + Azure AD Registered Devices
psydii replied to foofighterjim's topic in Cloud Services
If your DfE devices have shipped unmanaged then I suggest you AutoPiliot them: https://oofhours.com/?s=autopilot (this is the guy who, while he worked for MS, wrote the scripts that make this possible) https://docs.microsoft.com/en-us/mem/autopilot/ (official documentation) Microsoft filter the data you can see from personal devices, so even if they are taking policy (for example Defender) you don't get the deep telemetry from them that you get from "corporate" owned devices. -
Microsoft Teams - Anonymous Users and Guest Access settings...
psydii replied to networkmanager's topic in Cloud Services
I have been advised that Guest in the context of this configuration screen means an authenticated guest as appears on the azure active directory users->guest page. It may include Federated users (i.e. other orgs with 365 or GSuite), but that is slightly more unclear to me. So to clarify: Anonymous:No Guest:Yes is the current recommendation I have received. That said, I'm not sure any one support group, docs.microsoft.com author, or product team actually understand the full interaction between all thee available settings and clients. -
Microsoft Teams - Anonymous Users and Guest Access settings...
psydii replied to networkmanager's topic in Cloud Services
I have been advised that Guest in the context of this configuration screen means an authenticated guest as appears on the azure active directory users->guest page. It may include Federated users (i.e. other orgs with 365 or GSuite), but that is slightly more unclear to me. That said, I'm not sure any one support group, docs.microsoft.com author, or product team actually understand the full interaction between all thee available settings. -
How can I stop students "turning in" empty work?
psydii replied to mandaroza's topic in Cloud Services
You tenant settings probably influence the terminology in Teams. Have a chat with your Office 365 Global Administrator. On students handing in blank work... at some point you check their work to provide feedback, I assume. This would be the time to deliver consequences for not actually handing in work, including returning the work to the student. -
Students using personal Chromebooks to access Google Classroom
psydii replied to rednight's topic in How do you do....it?
This probably isn't particularly helpful. We have a Chromebook use FamilyLink. Child#1 is signed in with his personal account. He is also able to sign into Classroom and other GSuite apps using his LGfL managed account. Seems to work 'just fine'. -
It depends on circumstance. But perhaps if one of the students is onside they could mute the other?
-
Open tickets with MS Support via admin.microsoft.com and aka.ms/edusupport There are a couple of ways they are able to do this. Support will eventually close this down as it is the behaviour of Teams as it ships. However it is not the *INTENDED* behaviour, and we need to get the product team's attention and for them to understand the serious nature of this flaw in part of their implementation. The real problem is that the only way to keep kids out of meetings when there isn't a teacher present is to require the lobby for a meeting. If we weren't fording people through the lobby, the only people in the lobby would be these uninvited guests, which would be more manageable. Currently the only way to stop it reliably is to disable anonymous access to your tenant. There are some medium term improvements in the pipeline that may obviate these hoops we are trying to jump through, but for now we need to be able to identify anonymous users in the lobby easily.
-
When you log on to your 365 tenant which domain name do you use? That's the one that is working and linked. The other onmicrosoft one is probably not verified - is there another DNS/Global Admin in your organistation? See also: https://www.michev.info/Blog/Post/3173/adding-multiple-onmicrosoft-com-domains-in-the-same-tenant which may help shed some light on what might be going on. Can you post a screen shot of your portal? (redacting the identifying features of the domain name)
-
@maxrebo Support tell me the product team are able to reproduce in the lab. Support just closed my ticket because 'that's the way that combination of things work'. Hopefully there is a UserVoice open for this. We need to all pile onto it, and if anyone has any relationship with the Teams or Edu Teams product team we need to put the pressure on.
-
Ghostbusters is terrifying to most <10 years olds. As for the others! You sir, have emotional fortitude that I lack. I'm traumatised just reading that list.
-
Microsoft and Google trust each others authentication services. So if the third part Office 365 Tennant admin has ticked the box, your Google users can sign into the third parties Office365 domain as trusted federated users. This is normal. We have LA/NHS/Uni guests in our teams all the time, some of them from a Google world and some from planet 365, and our users similarly are guests in other's tenants / instances. The only problems can occour if you *hadn't* signed up for an Office365 tenant, and the third part added some of your users as guests... some combination of actions can end up creating a shadow tenant for your domain that is a pain when/if you ever wanted to create your own.
-
Wolfwalkers
-
Not all EMMC is equal. We've found the recent Acer devices that shipped with Windows 10 Education Pro and 64Gb EMMC 5.1 HS400 storage to have great performance. (I mean absolutely fine, not screaming fast NVME speeds, but Windows updates and software installs and crucially Page File Swapping don't cripple it like they did on slower devices) https://www.sandisk.com/content/dam/sandisk-main/en_us/assets/oem/mobile/iNAND-7550-Prod-Brief_EN_US.pdf If you run this class of machine 1:1 or use the Shared Devices profile in InTune they are fine. Shared Devices profile block OneDrive client from installing, and you can't have the users installing the Teams client. But for internet and Office (and a bit of Python) they do the job. If you are ordering enough Acer (so a little birdie tells me) will allow you to customise them with NVME and more ram. For us cost was key, so we went with the base spec and never explored that option so YMMV.
-
Some (many?) schools do all of the above good practice, but also need anonymous access enabled for parental meetings etc. The expected behaviour is that a teacher can see easily differentiate "anonymous" users in the lobby because they have GUEST as a suffix to their chosen name. Without the suffix staff struggle to spot malicious external users (unless they are choosing vulgar names). There are a number of potential long term solutions (some have been linked to above). A quick win would be to ensure that all anonymous users are identified as such clearly to the meeting organiser. Now we can still see a risk there that vulgar names are chosen, but people will get bored doing that after a while. Personally I long for a default option of "no anonymous attendees", and a global option to allow members of certain security groups to override that setting on a meeting-by-meeting basis. I also long for delegation of meeting owner rights to both the exchange and the s4b sides of things.
-
The latter.
