psydii
Members-
Posts
5,194 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psydii
-
Yeah we're seeing this too. Though only about 5-10% total failure. Most have some policy failure but we're pushing them out of the door anyway. They are running ProfessionalEducation
-
We had that in our portal, but ten it disappeared. I assumed because it was considered to have been fixed. Not had any reports of problems from our users. I was using a GA account.
-
Per year. I mean its not cheap, but it is it is in the same ball park as the old site licence going back to the macromedia suite days, but you get automatic updates and some cloud storage and the ability for kids to use it during a pandemic (if they have computers powerful enough)
-
Coronavirus: General discussion (see opening post for rules)
psydii replied to Dos_Box's topic in General Chat
OMG Helpdesk is going nuts with password reset request from students/parents, and Teams administrative requests from teachers. Seems the IT helpdesk has been listed as the first point of contact for problems. (TBF the pastoral safeguarding and admin team addresses are also in the most recent letter home - but the IT Helpdesk once again takes centre stage) -
Some teachers would dispute that.
-
TBF site specific browsers with a 3rd party supported release of Flash is actually Adobe's recommended transition strategy for LoB apps that are uneconomic to migrate to modern technologies. As long as the browser is locked to their sites, and cannot be called via other browsers or OS api's it's a reasonable stop-gap. https://www.adobe.com/products/flashplayer/enterprise-end-of-life.html "For enterprise customers that need help transitioning their Flash content to other supported technologies or require Flash Player licensing support after the EOL Date, please contact our official distribution licensing partner, HARMAN, for more information about their commercial support offerings. ... Potential services provided by HARMAN may include, but are not limited to: ... Creating custom downloadable applications that will load specified Flash content for end user distribution. ..."
-
We're gradually getting all staff personal mobiles into system for password resets. Politically difficult to mandate. We are going via the "user risk policy " and "sign-in risk policy" mechanisms in Azure (hey, Azure blocked your sign in due to suspicious activity - please prove its you!) Staff at that point are usually pretty willing to have us copy their personal mobile from SIMS into Azure AD. We've recently had to extend this to kids too. For this we contact parents for permission to add either their child's mobile or their mobile for the purposes of account recovery. We do have most of these on record already in SIMS, but no-one has the stomach for justifying the bulk import with all the stakeholders. Once we hit a critical mass we'll revisit engaging staff and parent/students to complete bulk enrolment.
-
Remember in the weeks before Spectre and Meltdown became public all the cloud providers scheduled reboots of their infrastructure using cover stories. Both the MS and Google outages have been given reasons that can be interpreted as "the authentication system got overloaded" Smells to me like they were rolling over all the authentication tokens because so many government orgs may have had them compromised via the recent Solarwinds Orion hack.
-
Hey. Never let reasonably likely explanations get in the way of a good global conspiracy.
-
It could be. The hackers may have had persistence since mid 2019. FireEye has an arsenal of tools that were stolen, and a huge amount of knowledge of some of the biggest private and governmental IT systems. SolarWinds Orion is in many sensitive networks. Any network with Orion will likely have had DA, and SSO authentication tokens stolen. I do wonder if the MS and Google outages are in fact due to rotating certificates/tokens, done today because un-nameable orgs had enough time over the weekend to re-secure their networks and were ready to reset accounts and passwords again. (If your DA gets compromised (golden ticket) you have to change your KTGT password *twice* in order to prevent the hackers regaining persistence, I have very little idea how you recover if global administrator tokens are got.) https://cyber.dhs.gov/ed/21-01/
-
An ex colleague of mine would advocate for not doing any 'migration', and just build the whole thing new, import nothing. Normally I would push back on this, but, given the previous problem, now would be a good time to start again - as you are already with the Domain. However, that its a customer's system does make this a bit of a harder sell. Perhaps map out the work-hours required? Also ping well crafted tweet @ djammer (Director of Engineering MECM/SCCM) on Twitter, he can probably point you to the resources, and given his position it may carry some weight with you customer (He's already sold the customer SCCM - now he just wants them to have the best experience).
-
Night mobile phone contact for building - signal boost...?
psydii replied to BJG's topic in How do you do....it?
This article might be helpful if you have a large network where the firewall team and the wifi team and the phones team are not necessarily the same people: https://www.networkcomputing.com/networking/your-network-optimized-wifi-calling -
If we've got the attention of @PaperCut , they need to make it work properly with FQDN and transiently connected devices.
-
TBH Thinkpads, Latitudes Macbooks and the B1 all tend to survive that sort of behaviour.
-
This is a generalisation that I would have stood behind pre-covid. However the B1 is more rugged that most desktops, and at £185, incredible value. What that doesn't consider though it the reliability of the wireless network. If it wasn't designed to take 30 laptops in any or multiple simultaneous classrooms, you are probably going to have a bad time.
-
Depends what you want to do on them, but I a super happy with the Acer B1 mentioned here: https://www.microsoft.com/en-gb/education/devices/default.aspx We run them as pure InTune shared, managed devices. Battery life and Logon times are good, there is a light on the lid that lets the teacher see the state of the battery. They are moderately rugged. They support USB-C PD and DP. They are cheap as chips. Our other laptops for courses needing the adobe suite are Ryzen 7's with 16Gb RAM. Which I am also super happy with, though we got an amazing deal on those. List price is now eye watering
-
What is your remote learning platform? Go with what ever device supports that the best. Based purely on the information you have provided above - ChromeBooks seem to be the better choice for you. We have Microsoft 365 E5, which gets us Intune and a basic (but adequate) content filter, so we went with Windows devices (iPads weren't even offered at the time). Needing a filter makes Unsecured Windows the obvious choice for us. iPads have poor filtering options (basically you can only do it at the network level - off device). I do not know what options are available for Chromebooks - I would lean into the LGfL offer to secure these. E5 also gives us a huge amount of telemetry from the machines and Office 365 so we can really see what people are getting up to, and trigger alerts on certain events and conditions. When running previous 1:1 programmes we generally engage with parents to raise their awareness of internet content risks, and get them to accept responsibility for the use of the devices outside of school.
-
Regarding docks: teachers still unplug them and walk off with bits and pieces.
-
Are the computers supposed to be members of a group?
-
Upgrading Windows 10 in certain scenarios causes the MDM certificate to be lost, breaking Intune based management. These scenarios strike me as being quite common in education, if you are building out from a legacy environment. Its not clear whether other certificates are impacted - I suspect they may be - so watch out if you have code-signing or 802.1x certificate based authentication. "Devices will only be impacted if they have already installed any Latest cumulative update (LCU) released September 16, 2020 or later and then proceed to update to a later version of Windows 10 from media or an installation source which does not have an LCU released October 13, 2020 or later integrated. This primarily happens when managed devices are updated using outdated bundles or media through an update management tool such as Windows Server Update Services (WSUS) or Microsoft Endpoint Configuration Manager. This might also happen when using outdated physical media or ISO images that do not have the latest updates integrated. " My reading of this is if you have (for example): A fleet of Windows 10 1909 (or earlier) fully up to date as of October 2020, a pilot deployment from SCCM/MECM which you have been running since the summer made from a more recent release and then you widen the scope for that deployment to your existing machines in production you will hit this bug. If you were instead to refresh/re-download the later version before widely deploying, you will be safe. https://docs.microsoft.com/en-gb/windows/release-information/status-windows-10-2004#1513msgdesc https://admin.microsoft.com/AdminPortal/Home?ref=MessageCenter&id=MC228536
-
Don't think that is possible. Do you have SCCM/ MECM? Query based collections are built using with the data from WMI on the clients - so if you built the equivalent query for an appropriately scoped collection, you would hit the same devices with an appropriately scoped GPO WMI filter.
-
Yeah. No. Our analogue Motorola's have lasted 10-15 years and we are only now phasing them out with Motorola's modern digital version. They have a function as part of the various emergency procedures and so need operational independence from other communication and power systems. We have a UPS backed wifi network. But various things have occasionally taken it offline over the last ten years. The 2-way radios *ALWAYS* work.
-
"For voice deployments, it is recommended that the cell edge should be at -67 dBm with 20 percent overlap" We built for voice several years ago, because Teams seemed like it might be important in the future. Turns out we were right . Go for 4x4 APs (I think all ax APs are?). They allow for higher density of devices. Depending on the vendor implementation of channel management, you, at school-grade densities, can also have 80Mhz channels as the channel stacking allows fall-back to 40 or 20Mhz if the rest of the channel is busy. If you have too-high a density of APs you are less likely to feel the benefit of 80Mhz, but you get more power per channel, which in turn increases the chances of achieving 256+ QAM You do need higher power to hit 256+QAM, so there is a delicate balance between density and bandwidth. In practice for us this roughly means one AP in every other classroom. Most offices are near classrooms so are covered. But for blocks of offices in some areas, one AP per two rooms also is a good 'guestimate'. Don't forget to think in 3D - if the floor is relatively transparent, try not to put APs directly above/below each other. I really would recommend getting an independent wireless survey and design done, they save a lot of stress and give you something to fall back on with certainty when a random problem occurs ("the RF design is good - it has to be something else - look I have the paperwork to prove it") EDIT: You also need -20db clearance between devices on the same channel but different APs - otherwise you get co-channel interference. So if you pack APs at too higher a density you risk some stations shouting over the top of neighbours on other APs - producing errors and actually reducing your operational throughput.
-
Instant messaging as the main port of communication
psydii replied to JoeRogue's topic in Cloud Services
I have found that calls still ring even if your calendar says you are busy.
