-
Posts
150 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by HCC
-
Hi, We are looking to replace our Hikvision NVR, and thought it would be useful to ask how other schools are recording and accessing CCTV. There are 30 5MP cameras, and I need an easy to use web portal for the head and pastoral staff to access and use themselves, which is very much not the case with iVMS. I'm currently considering: The Windows route, with Luxriot, Milestone or BlueIris etc Unfi protect but I don't like the online activation\portal aspect, and although it says third party cameras are supported I'm not 100% on compatibility. Replacement NVR like Cortex etc but not sure if such a system can use onvif or only works with matching manufacturer cameras. Thanks,
-
The latest is that it appears to be caused by a conflict between Senso.cloud and Smoothwall. If Senso is uninstalled the issue goes away. Smoothwall support theorised that it might be because Senso is trying TLS 1.3, but Smoothwall only supports TLS 1.2 the only solution I can find ATM is to add site exceptions to the Senso logging policy, or turn off Senso web logging.
-
Hi, I have this logged with smoothwall support but I'm not getting anywhere with that at the moment, their support has been a bit lacking recently. So maybe someone else has had a similar issue and already solved it? The issue I have is that sometimes users of youtube, myconcern, code.org, typing club, methodmaths etc (could be any site but those are the commonly reported ones) get a too_many_redirects error, and Edge gives up on loading the site. I'm guessing that this is because smoothwall is treating the tab as unauthenticated and trying to redirect to the web SSL page, but failing to do so. The Wscript is running on the computers, and sometimes auth works as expected but not all the time. Sometimes its OK on one tab, and not another. There is a transparent policy to try various auth methods (AD, Azure, idex), and then fall back to SSL redirect if that fails. Its worked without issue with the current settings for years, the only thing that's changed is the version of Edge now on 124, and we are now on the latest version of Smoothwall. So it looks like the auth must be failing sometimes?; is Edge now running every tab as a separate process, and is more fussy to redirects? Anyone seen, and solved anything similar?
-
Hi, We have had similar to this a few times and it was because they had somehow managed to set the logon keyboard as Slovakian or similar rather than UK. Had to go into the depths of the keyboard settings in control panel or settings and remove all random extra keyboard layouts so that only the UK one remains, then it worked again.
- 12 replies
-
- alt+112
- lock screen
-
(and 1 more)
Tagged with:
-
Hi, I just noticed there is a cert trust change mentioned in the notes of Edge 109 https://learn.microsoft.com/en-us/deployedge/microsoft-edge-security-cert-verification. In future versions of Microsoft Edge, both the certificate trust list and the certificate verifier will be provided by and shipped with the browser. This will decouple the list and verifier from the host operating system’s root store. Not sure if the smoothwall cert that we currently deploy by group policy to the OS 'Trusted Root Certification Authorities' won't be trusted by Edge in version 110 unless we disable the microsoftrootstoreenabled setting. But if so that setting will only work until Edge v111 when they then remove it. Might also need to update the instructions soon for students installing the SW cert for guest devices, that use our intercepted guest wireless? It does say In addition to trusting the built-in roots that ship with Microsoft Edge, the browser will also query the underlying platform for—and trust—locally installed roots that users and/or enterprises installed. So I'm not sure if this change is a huge concern or not, but maybe something to be aware of, if like us you use Edge with an filter SSL interception cert on most school devices.
- 10 replies
-
Hi, Come join our thriving 2-19 all-through college on its journey towards excellence! Our two-form entry primary phase opened in September 2019 and we have now completed our brand new state-of-the-art development on the secondary site. New facilities include a three-storey teaching block containing 22 classrooms and SEND hub, a fully refurbished Post 16 Learning Centre and a floodlit all-weather sports pitch to complement our already extensive sporting facilities. ICT Assistant Technician – Required to start ASAP Hours: 37 hours per week – Full Time 52 weeks per year – Monday to Thursday 8.30am to 16.00pm and Friday 08.30 to 16.00pm Salary: Single Status Grade 2 point 4 – £20,441 per annum Have a look at our website for further details
-
Hi, We use Sign in App running on some 9th gen iPads, and I get numerous heartbeat lost emails daily, and can see they have intermittent slow peak request time. The iPads usually resolve this themselves 10-20 mins later. I've had a look in the settings when an iPad goes offline, and it still appears connected to wifi, but can't get through to the internet. This has only happened since we upgraded to new Ruckus R650 802.11ax APs and a new controller over the summer. We have another connected site that uses Unifi, but otherwise uses the same network\filter etc and doesn't have this same loss of heartbeat issue, which makes me think its something that's changed in the config since moving to smartzone. I've tried a few settings changes like increasing the idle timeout, trying wifi5 compatibility etc but no change on this issue. We have had to update some laptop Wifi5 windows wireless drivers older than 2019 which went unstable on wireless, but I can't change as much on iPads. Anyone seen anything similar, and managed to resolve it on iPads since upgrading to Ruckus Wifi6? Thanks,
-
Android Photo Management on Primary School shared Tablets
HCC posted a topic in How do you do....it?
Hi, We have a set of 30 shared Android Samsung Tab A tablets, that Primary students use for Apps and internet. They want to use the camera on them instead of separate Digital Cameras. I can allow the camera app, but then it would just save locally, and the teacher would have to plug them in to their staff laptop with a USB lead to manage. We use Office 365 so I could setup the Onedrive App with a shared account that the teacher can access. The issue I see with this is that won't the photos then sync across all tablets, and how would the teacher know which student took which picture. I could use 30 Separate Onedrive accounts, then share them to the teachers? or do the same with Google Accounts and their photos app? Or is there a simple camera app, or web site that saves photos direct to an online photo service, the teacher can access and not to the device? - Needs to be simple enough for a 6 Year old child to do. -
https://www.hccat.net/job/ict-assistant-technician/ ICT Assistant Technician – required to start ASAP Hours: 37 hours per week, 52 weeks per year. Monday to Thursday 8.30am to 16.30pm Friday 08.30am to 16.00pm Salary: Single Status Grade 2 point 4 – £18,198 per annum We are looking for an enthusiastic, flexible, and committed person to join our ICT Support team. The desired candidate will provide effective technical and software support to a busy all-through academy. You will be responsible for: The upkeep and good order of the computer equipment Support teachers and students with the use of ICT Undertaking periodic computer checks Identifying and remedying software, hardware, and network faults. Excellent organisational, communication and interpersonal skills are essential. Previous experience in a similar role, and a good standard of education would be advantageous. We can offer: A school committed to consistency and sustained improvement A hardworking and dedicated team A friendly and supportive atmosphere A supportive Leadership Team Cycle to work Scheme The opportunity to join our Corporate Membership to Benenden Health Care, where the Academy pays for half the membership The opportunity to pay into the Local Government Pension Scheme which is one of the most generous pension schemes in the UK.
-
SharedPC - Powershell to check if provisioning package is installed
HCC posted a topic in Windows 10
Hey, I'm trying to enable SharedPC mode on the W10 student PCs to improve logon times. Does anyone have a powershell script that checks if a Provisioning package is installed, and installs if its missing? or another way I did think about is group policy and the MDM bridge, or via intune. Background: I've manually installed a PPKG on a few test PCs to enable SharedPC to try to improve logon times over the mandatory profile we have now. We have moved all student files to OneDrive so intend to use KFM with silent SSO (and I know SharedPC has a OneDrive sync client issue, but I think I've added an GP to override that to allow it to run). -
Hi, We have deployed out Edge 83 to school computers, and SSO always works for Office 365 via the new Office tab page etc. We use Firefly as our VLE, with Office 365 set as the logon method. Sometimes the SSO works with FF, and sometimes it doesn't When it fails, it quickly cycles through a few pages and returns to the sign in page with the error 'details you have entered are incorrect, please try again' I think this is specific to certain computers. The only way around this at the moment is to use browse as guest. I contacted Firefly support, but they said its an Edge issue. Contacted Office 365 support and they said it was a Firefly issue. Any ideas how to diagnose\fix this issue, so Firefly always auto signs in on Edge?
-
This is using the integrated scanning option within PaperCut, but also effects any notification messages and emailed reports from PaperCut as well. I have specified a 365 auth account in the PaperCut config but I'm not sure if this is used as we have it set up as Direct Send Option 2 described on this page. Why can't Papercut just use a specified send account using modern auth rather than from email sender impersonation? I'm not surprised the antispam doesn't like what it's doing. The other unknown is that the Public IP is used by other local schools, so it might not even be Papercut messages that are causing it to be blacklisted.
- 6 replies
-
- office 365
- papercut
-
(and 1 more)
Tagged with:
-
Hi, We use the PaperCut scan to email functions on a fleet of Sharp copiers, and its worked great for years. Recently scans and emails from PaperCut have started getting blocked by SpamHaus XBL list l can manually allow the external IP in this XBL list, but it then gets blocked again after a few days. I manually allowed to get it to work again, then looked at an sent email header. I think the cause is the HELO=printserver.domain.local rather than being the external Public IP that's being used. This is what is described as the issue in the XBL IP lookup. I've contacted PaperCut support but they suggested it's a network config problem. I've tried making a few changes to the PaperCut config - We use Office 365 and I remember it being a pain to set up in the first place but has been working for years. I have no access to the network config of the external IP addresses as that's at our ISP. I can't find any way of setting the HELO in the email config of PaperCut Does anyone have any ideas, how to permanently resolve so scanned emails work again without me often having to keep modifying a SpamHaus list?
- 6 replies
-
- office 365
- papercut
-
(and 1 more)
Tagged with:
-
I remember having to add several urls to smoothwall's Office 365 category that were missing, but if it works for some its unlikely to be that. Are they all on the same Office and Windows versions?
-
Hi, Sorry, don't know exactly what fixed it. Here are the things I remember changing: allowing the Office 365 category in smoothwall for all, and added a few allow urls I found in a Microsoft Office 365 firewall document that were missing from smoothwalls list. Switched from the normal 'Office 2016'; to Office 365 click to run with device based activation. Made changes to the internet settings as per https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso-quick-start We had directory provisioning on for azure connect to filter only user OUs. I had to tick Windows 10 Computer OUs as well https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering changed Office 365 to modern auth. Hope that helps.
-
Could this be to do with the GDPR that 'any information relating to an identified or identifiable individual' isn't kept longer than necessary? (Article 5(1)(e)) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed This would apply to lots of class\year group spreadsheets teachers create, and keep forever. I'm considering changing folders to a cohort\year folder structure, so we could easily archive\remove old data in line with data retention policies.
-
Hi, Does anyone know of a manufacturer of interactive displays that meets this spec: 65" wall mounted screen HD or 4K HDMI Multipoint touch that works natively in Windows 10 (i.e no driver needed for Windows 10) Freeze button Stylus Pen option No Android integrated - All of these seem to run an already old version of the OS. If we end up using any interactive display like we have the Promethean boards; I can see android integration being a problem in 10 years time if its not a replaceable part. Not interested in bundled software. I would like teachers to use the standard Windows 10\ Office inking tools or Classflow(if they must). Ideally around the £1500 per unit price point. Regards,
- 18 replies
-
- interactive screen
- iwb
-
(and 1 more)
Tagged with:
-
Hi, We have a similar but slightly different problem with Office 2016 on W10. It does auto sign in but there are no connected services, or file history. The odd thing is if you sign out, then in again to office, it works and doesn't prompt for password. OWA in IE or edge does SSO. We only have a few office policies Microsoft Office 2016/Miscellaneous Block signing into Office Enabled Block signing into Office Org ID only Microsoft Office 2016/Privacy/Trust Centerhide Disable Opt-in Wizard on first run Enabled
-
[ms office - 2016] Deploying Office 365 vs Office 2016
HCC replied to disk's topic in Office Software
I managed to fix my activation problem. Office 365 Device based activation doesn't work if shared computer licensing is on. I found this guide https://technet.microsoft.com/en-us/library/dn782859.aspx My activation status looked like screenshot A and I checked and shared computer activation was on in the registry. As soon as I set the reg key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\Configuration\SharedComputerLicensing key to 0, it then worked as expected. I still got the accept updates and openxml file formats prompts but hopefully I can fix that with a group policy. Now if only Microsoft updated Outlook to make SSO work, and allow WSUS to manage Office 365 updates that would be great -
[ms office - 2016] Deploying Office 365 vs Office 2016
HCC replied to disk's topic in Office Software
Hi, I am trying the Office 365 ProPlus device based activation on some new laptops. It installs OK using the OPPTransition program with our tenant and key. It also creates the device account in 365 user admin. The problem is that when a user logs on then loads any of the office programs it asks for an email to activate. We have SSO for windows 10 set up via Azure Connect, not ADFS. I can see that office has recognised the logged on user, because their name is in the top right corner. If a user puts in their email it works ok, if not they get a unlicensed nag bar. I could see this not being a big problem for staff, since they have an assigned device and could type in their address; but if we used it on student computers with mandatory profiles this would be a big problem. Is there any way I can stop this activation prompt happening? Has anyone else seen this and managed to stop it appearing? -
Hi, Not using ADFS (looks a bit complex to set up and maintain), so there is a lag before the SSO first works, based on when Azure connect syncs and the policy applies. As it says here https://azure.microsoft.com/en-gb/documentation/articles/active-directory-azureadjoin-devices-group-policy in the prerequisites Windows 10 build (build 10551 or newer) is needed. What is the LTSB build number? Yes you need to sync the 10 workstations, this is why it didn't work for me.
-
Hi, I managed to solve it. I had a look at how the system works by creating a certificate and uploading it to AD. This got me thinking about how Azure Connect then sends the computers details to Azure. I forgot that when I first set it up as dirsync years ago, I also set up OU filtering... The problem was that the Windows 10 computers were in a new OU that wasn't being uploaded to Azure. I set all the W10 Computer OUs to sync using the instructions here: https://azure.microsoft.com/en-gb/documentation/articles/active-directory-aadconnectsync-configure-filtering/#organizational-unitbased-filtering Then I had to force a full sync using the command "Start-ADSyncSyncCycle -PolicyType initial" in powershell on the Azure connect server. After a restart of a Windows 10 test computer, I can now SSO using IE or Edge for Office 365 and Firefly. yay Hope this helps anyone else who gets stuck.
-
OK, So I ran the powershell command Initialize-ADSyncDomainJoinedComputerSync detailed here https://azure.microsoft.com/en-gb/documentation/articles/active-directory-azureadjoin-devices-group-policy/ worked out the [connector account name] is the MSOL_guid Domain User from the domain users container. I've also set the GPO to enable the workplace join. This has created a scheduled domain join task on the Windows 10 computers, but it isn't working. There is an message which says: Task Scheduler successfully completed task "\Microsoft\Windows\Workplace Join\Automatic-Device-Join" , instance "guid" , action "%SystemRoot%\System32\dsregcmd.exe" with return code 2147942401. If I run the command dsregcmd.exe /status I can see the computer hasn't joined Azure. I'm not sure how to fix this. It could be something in the Azure Portal, since it says SSO 'Not Planned' on the domain page or do I need to run any other commands on the Azure AD connect server? I'm not using ADFS, so I can't run the 'claim rules' Has anyone else come across this problem and fixed it? I tried to log it with 365 support, but they said it was an azure issue, and you need premium azure to get assistance with that.
-
Hi, I am trying to do something similar. I would like it so that when saving from an Office 2016 application, the Sites view was more useful. At the moment it looks like this: I would like to get rid of the entire document libraries section. Then make it so that the Sites and Workspaces showed all the file libraries for the 365 Groups I'm a member of. The ones on there at the moment are only sharepoint sites, but I think groups are more useful and are more teacher proof. At the moment its easier for users to use the web pages to find the files, then click the edit in word if needed, but I would rather they create a document from scratch in full Word 2016 then save it into a group rather than their laptop documents folder. Thanks,
-
Hi, Looks like they updated the info on the page in March, Has anyone else tried this yet? Would it allow for the company store, and office 365 SSO without Federated AD, System Center, or Server 2016.
