Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

_techie_

Members
  • Posts

    434
  • Joined

  • Last visited

Everything posted by _techie_

  1. Hi Tom. This was my ticket ID: 438604 The issue seemed to affect Hybrid Azure Joined Devices (not intune managed in our case). The cloud filter wasn't mapping the AD On Premise groups correctly (all users ended up in the Default users group on the cloud filter status page), despite working before Leeds 66, so we ended up overblocking a bit too much really for Staff. Once the group policy setting for the smoothwall Unified Client: Enable Azure AD was set to be enabled, this resolved our issue. We were both before and after the incident mapping our Azure Directory on our Smoothwall S9 appliance. Supports recommendation was to setup the IDEx directory.... Hope this helps.
  2. Smoothwall's response was to use the IDex directory, but I don't really see why your using the cloud filter if your totally On-Premise? Unless your teacher laptops go offsite, and you don't want to mess around with providing ways of switching Proxy and and off.... The alternative for that would be transparent filtering tied to a VLAN/Location. If that's the case, I would seriously look at Intune Managed devices, sadly there is no real alternative to managing mobile devices if they leave the site (securely anyway). Thanks,
  3. Hi. If your totally on-prem, I would stick with a proxy setup, and push out proxy settings to the browsers using GPO for students, teachers, and office/support staff. I would agree with on you Leeds-66, something definitely changed without me making any internal changes. Don't forget you will need your HTTPS inspection certificate deployed via GPO too, as I think HTTPS inspection is on by default - might be worth checking your IP's here too, and putting any servers in a specific location on smoothwall for no HTTPS inspection too as well as auth through the filter as something more than Y7 students. Either that or setup some specific allowed categories for your whitelist for things like Windows Update etc for your servers. Hope this helps.
  4. Well we are syncing groups to Azure AD as well, so you will need to set this up in smoothwall >>> directories, and make sure any smoothwall filtering related groups in AD are being synced to Azure using Azure AD Connect. Also make sure any domain computer accounts that are being used are also synced to Azure if you are doing Seamless SSO for Office/OneDrive/Edge. In the group policy under Computer Config - Smoothwall, I set the Enable Azure Active Directory setting to be Enabled (default is disabled). This is for the unified client. This cured my issue without having to resort to the IDex Directory, which I would rather not use.
  5. Hi. Thanks for your help. I have now changed the setting on the group policy, that states "Enable Azure Active Directory" to be enabled on the Smoothwall Unified client. This seems to fix the issue in both Edge and Chrome. I will tidy up the remaining IDEX stuff in the hols.
  6. is it showing the correct username and AD group memberships but not applying the Smoothwall group assignments? Yes Moving to a proxy setup works too. I know we have around 6 servers with the Idex client on, and one DC with the Agent on, which we will be removing in the summer. I don't believe this is the issue however, as both our chromebooks and Intune PC's are working correctly with the groups!
  7. Hi. Today we have had reported that the smoothwall cloud filter extension that is applied via GPO is not mapping AD groups to on-premise groups correctly, instead placing them in Default Users! This means that a lot of content is being blocked incorrectly! I have put a workaround in place a the moment, to use no extension with a proxy applied, which seems to be working okay at present. Any ideas? I am obviously missing something as the directory settings on our on-premise smoothwall appliance are reporting as working correctly. Even tried a reboot of the smoothwall box to see if it resolves the issue, but no joy.
  8. If your using a browser based safeguarding extension, do you need to authenticate the user onto the WiFi? Just a consideration. Our Chromebooks use the Smoothwall extension, which picks up the Azure AD Groups.
  9. We tried using Edu 22H2 and on the old hardware we had combined with the shared computer suites AND the fact Store Apps install per user each time a student logged on gave a poor experience. This generated more tickets whilst students had to wait for apps to either update or install such as "snip & sketch" rather than the traditional snipping tool which is already available and ready to use. If your fully in with 1:1 devices for all users including students, and know exactly what store apps to remove as part of your build and not brick the OS all credit to you. I don't see a point in deploying an OS that's full of "stuff" that you then have to remove/turn off to keep students focused on work, but every school is different. I'm sticking with LTSC in my computer suites, but happily rolling out Intune laptops with Edu 22H2 to staff. LTSC in the computer suites frees up my time to focus on other projects that need my attention.
  10. Now sorted a move to another OU in AD where the rest of my servers were, gpupdate and long reboot, and now its started. Some more maintenance needed I think in the long run.
  11. So far the situation is thus: All drives installed in array, and formatted, so no can do with expanding storage. I might check disk manager to see if there is any free space on the array however - good shout. Really didn't want to have to rebuild this thing, but might be the only option... will let you all know. Thanks guys - something to go on with.
  12. No physical host sadly!
  13. Hi. Our Avigilon Centre Service won't start. I think its down to lack of disk space, but I cannot fiddle with the storage settings, until the service has started - catch 22! Any ideas on how to resolve this please? Thanks Mark Williamson - IT Support
  14. If you have access to the Google Admin console, you can set them up to use SAML sign in, and points to Azure/O365. Its under the security main tab on the LHS - you can set it there. you will need someway of provisioning users from AD to G-Suite (I found this best using the active directory GCDS Java tool best) although you can do it cloud to cloud, you just don't have the fine grained control over OU mapping (yet). 2 guides for you: https://blog.theserverlessschool.net/2018/04/sso-from-chromebooks-to-azure-ad.html https://support.google.com/chrome/a/answer/6060880?hl=en Hope this helps
  15. I'm getting the impression that Windows running in a virtual machine might be a better way to operate for students....certainly for things like Python and computing type stuff 😂. Maybe Azure hosted desktop is a solution here? Thoughts please?
  16. I've been doing some testing with office 365 in shared device deployments and the OneDrive Client seems to work more reliably at signing in... We do use Adobe Creative Cloud but we have advised that each student use/reuse the same laptop to try and alleviate these issues.
  17. Your facing similar dilemmas to most edu it teams now, where really you should be on 1:1 devices for staff rather than desktops and hotdesking... All this software is designed to work better if you use the same device, rather than roam across multiple desktops... Your fighting a losing battle here sadly. Will only get worse with Win11 and dreaded store apps....
  18. As per the title, it might be my age, but Windows seems to give me more and more daily headaches... Certainly in shared computer suites, and shared laptop trolley scenarios... Also the experiment that is Intune seems to be a bit of a backward step in a number of areas, such as speed and enforcement of restrictions needed for student use, as well as App installs not letting you see what you included in your package as a point of reference. Examples include: Store Apps that get stuck updating during a lesson including: Snip and Sketch and Photos which are useful/necessary for learning, are updating whilst a lesson is in progress. The apps then don't work as they are updating. OneDrive Client Sync...(where do I start) Fine for 1:1 user scenarios due to the nature of login process, and then just Delta file updates (I use my own USB-C laptop, and it does work well). With the fast paced use of computer suites and logging in and out, students don't often wait for their files to upload after saving work, and sometimes files get lost). Intune "speed" (or lack of) to apply settings plus the reporting of installed apps seems slow. We are slowly moving all our computer suites over to full domain join GPO enforced setup. I've even started looking at LTSC 2021 since it doesn't contain the store apps, and junk!! However, thinking ahead, Win11 doesn't include a junk free version like LTSC.. User installable apps (yes I know Applocker can block these, but Intune slowness means the settings aren't enforced immediately making it useless!) Some solutions we have put in that don't seem to have caused too many issues: Moving to Chromebooks for our laptop trolleys and using the browser versions of O365, autosave enabled by default and no syncing... We also do this for loan laptops for students safeguarding enforced with the Smoothwall filter extension, and Senso too. We did try a surface SE but the performance was dire... Sticking ChromeOS flex on and much more useable Is Microsoft listening to Education? I don't think Windows is suitable for much longer, certainly for student use...
  19. Hi. We have some Yealink Teams Voice Handsets, which work 'most' of the time. The software can be buggy at times, and we have done as much as we can do to resolve the issue. Current issue is surrounding transfer of calls, which puts the handset into hold... and is causing our receptionists some annoyance, the only workaround being to reboot the phone, which also only resolves the issue temporarily. There are two 'service'/anonymous accounts which are signed into the Teams handsets, as we have a number of staff that manage and run the reception desk throughout the day. The Ideally I would like for the reception staff to use the software version of Teams on the computer, but this currently logs the user into Teams using their own accounts. Has anyone achieved this? Our reception staff have other tasks throughout the day, so aren't on reception full time. Transfer of roles/reception roles or forwarding would need to be automatic, which I can imagine might be a nightmare to manage. Thanks Mark Williamson
  20. Hi, Not sure if I'm missing something, but our cloud filter doesn't seem to be working quite as expected, despite our smoothwall appliance working as expected inside school. I noticed a yesterday, that an interesting student had managed to download opera and installed it under his user profile, so was bypassing the filter, as the extension wasn't force installed. Having checked our web filter policies, I noticed that executable files were blocked. Testing on our RDS system, which doesn't use the extension, this worked as expected, and trying to download an executable file (I was trying putty.exe), which was blocked successfully. We have the cloud extension on both chromebooks and windows devices, and you can download exe files on both... Am I missing something? Or does the cloud filter extension not block executable files from being downloaded? Cheers Mark
  21. We seem to be experiencing a number of issues with ParentMail. This includes: Failed payments due to PM not supporting 2FA security. Inconsistencies in syncing parental data from SIMS with gaps in phone numbers from parent details. Incorrect recording of purchasing items yet or catering tills (Fastrax) it's recording purchases correctly. Currently reporting multiples of items being bought when only in one purchased in Fastrax. Just hope it's not just us.. Cheers
  22. We experienced similar issues to yourself, enforcement of policies takes a few moments to apply, by which time students have already done the damage! We eventually went to a hybrid domain join setup, where enforcement of policies applies via GPO still. Ti This seems to be a lot more reliable and speedy than Intune when hot-desking and sharing devices. When using 1:1 devices the issues seem less of a problem, as repeated logins just get enforced okay. Newer devices we have also seem to work better, probably due to better performance.
  23. Thanks both... We had some exceptions in our student emails section, which was stopping the emails being written back to SIMS. We uncovered this from our logs. All good now.
  24. Hi. We are using Locker in anger this year for our new Y7 intake, and everything looks good in terms of SIMS:- New Y7 students are 'current' in Sims and have a valid admission date of today. These 170+ students are not coming across into AD using Locker however. Oddly we have some new Y7 intake that are 'Future' status in SIMS, yet they were created today for us. We did follow the locker YouTube vid to deal with pre-admissions (they released over the summer holidays) so I'm wondering if accidentally we have banjaxed Locker from working as expected... Any ideas? We have run, and re-run the tool manually today with no joy. Or are we missing something in SIMS that's not picking them up or that I can check with our data manager?
  25. I'm aware that you can do this on SharePoint, but do you script this using powershell somehow? Cheers
×
×
  • Create New...