Jump to content

psydii

Members
  • Posts

    5,194
  • Joined

  • Last visited

Everything posted by psydii

  1. I recovered a school domain by going through nominet. I'm afraid I can't remember the details though.
  2. Pretty sure posting how to hack such-and-such service is the sort of thing that is frowned on by the mods here. *that sound more dramatic than necessary. The reason to raise the urgent tickets is to help MS get visibility of the issue, which is same reason I turned on full telemetry in Windows 7. This is just an identification (human to human) level bypass - social engineering if you will, that is made trivially easy by inconsistent behaviour of Teams.
  3. Regarding anonymous users appearing as legitimate users in classes/the lobby. I have reason to believe there is some understanding of how this is happening, and that it shouldn't be. There is some inconsistent behaviour in Teams and a use case that can be reliably used to produce the effect described. The desired behaviour can be seen in other use cases. For now the recommended way to keep anonymous users with arbitrary (and therefore potentially forged) names out of the Lobby or meeting is to disable anonymous access. I recommend that anyone experiencing anonymous users gaining entry to meetings by forging their identity raise an urgent ticket with Microsoft via the admin portal https://admin.microsoft.com/ *and* the edu support site: https://aka.ms/Edusupport
  4. Fastest thing to do is open the MEMCM (nee SCCM) DP to the internet. Advisable to make sure you've fully updated and have implemented best practice for the various accounts SCCM uses (hint: if any of them are domain admin, you have some work to do) Longer term, link them up with MEM (nee InTune). Longer term still, retire MEMCM.
  5. The csv will let you identify the group names. So you can iterate through: Foreach ($class in $classes) {Add-teamuser -groupid (Get-unifiedgroup -anr $class).externaldirectorygroupid -user [email protected] -role owner} The “best” was would be to have the people added to the course in the mid, perhaps as coteachers, or in some oversight capacity like Head of subject/head of faculty and have salamander do it all automatically.
  6. Ours too. We've had testing running since last week, staff can get done as often as they want (though at least once a week is required for on-site workers) and similar regime for on-site students. Biggest day was when we ran some exams with a few hundred kids. Such a stressful time for everyone, but the team is really delivering. Notable that a couple of the team running the process have lived through past national disaster level traumas elsewhere, and were the first to step up.
  7. No, by default this is blocked by default in tenants. Auto forward rules are one of the first things abused by hackers when they pop an account.
  8. This is concerning. He just announced a measure that is quite severe, before it is apparent to the wider population that it is required. I'm quite worried now.
  9. I'd trust the proposed design by the engineers. It certainly matches patterns I have encountered on both Paxton and other systems. In the long term, a design pattern that the field engineers recognise will be more important than swish locks on the doors.
  10. Has anyone else had reports from macbook using colleagues that access to sharepoint online is throwing certificate warnings? It seems as though something is causing fall back to TLS1.0. This is effecting both our JAMF managed devices and peoples personal macs. Its all very weird.
  11. If you are braver/have more time than I, the tricks in here might work: https://james-rankin.com/articles/microsoft-teams-on-citrix-virtual-apps-and-desktops-part-1-installing-the-damned-thing/
  12. Interesting. The only time we have had any support from GC for over a year has been when a third party customer of GC has raised a ticket from their side. Concerning if even this now isn't getting things resolved.
  13. Yup we've been seeing that the last few days since we started using the Lobby for everyone. Normally if you just have the link and are not signed in, you get to choose your display name BUT Teams then adds (GUEST) to the end so it is clear to the meeting organiser that you are not a local user. This safeguard seems to not be working, and unauthenticated users are appearing in the lobby with no visual clue that they are not actually the student they claim to be.
  14. Is Storage Sense disabled?
  15. Machine Wide installer, which puts a running copy into everyone's AppData folders. These auto-update. Then we ran out of space on the shared devices. So we removed local Teams entirely. Staff kept Teams on their laptops. Student/Shared machines then had to use the Web version. Now during lockdown 3 we are encouraging onsite students to download and install Team (into their AppData) as for the moment each student has a designated seat and therefore only one user per computer (well 1 user per 2 computers for social distancing). Longer term there is a method for forcing to run out of Program Files, but this would require us to deploy a new MSI every couple of weeks - a PITA. Why it can't work like Chrome/Edge I don't know.
  16. Do they hear it or just the other participants? I wonder if they are on a misbehaving server? I've had similar happen in Teams, which because of its heritage offers quite a lot of telemetry and we've seen problems disappear as a user is moved off one server/cluster and onto another. Not that we have any control, as is the way with cloud services.
  17. Have you considered that they maybe renegade Timelords?
  18. https://docs.microsoft.com/en-us/security/engineering/solving-tls1-problem
  19. https://docs.microsoft.com/en-us/answers/questions/31158/how-to-enable-the-qa-option-for-teams-live-events.html
  20. Is it expected behaviour? Well, we've come to expect it, but we don't believe that it should be happening Lots of little quirks and inconsistency's with the OOBE + Intune at the moment. Things seemed much more consistent back when this guy still worked at Microsoft. I wonder if they lost some talent in the dev/support team that has lead to a drop in service reliability.
  21. Monday and Tuesday Teams chat had a wobble around 9am. (see Service Health dashboard on admin.microsoft.com) Yesterday SharePoint and a lot of other bits of Office 365 wobbled around 3-5pm when a London Datacenter took an unauthorised leave of absence: "We've identified that the issue occurred in a datacenter located in London, and thus the majority of impact was for users located in the United Kingdom. Additionally, users in other European countries such as France and Spain may have been impacted if their connections were routed through the affected components in the London datacenter." To echo DaveTheTech, So far today I've not had any reports that were attributable to instability/overload in Office365. So they may have shaken things out and got used to the new normal patterns of load.
  22. We're seeing issues beyond that... camera icon missing from apps (across multiple meetings/users, but not consistent) Also reports of teachers unable to release students from the lobby - again not consistent, some kids get let in, others just get stuck.
  23. We've seen occasional reports of this. Never managed to get a coherent one with screen shots like the above. Hasn't made it to a complaint at the remote learning forum or into SLT meeting yet so I haven't allocated any time to follow up yet.
  24. Do you get an error code when it fails?
  25. I can't help there, we ordered them unmanaged. There are others here who have worked through the process to have a DfE Intune device released.
×
×
  • Create New...