Jump to content

mjhardisty

Members
  • Posts

    150
  • Joined

  • Last visited

Everything posted by mjhardisty

  1. Does your firewall support URL rewriting? If so, if you rewrite Google URLs and append &udm=14 to the end it should remove the AI elements from the searches. Sophos or another firewall might be able to do this. You can try it by going to http://google.com/?&udm=14 and then any resultant search adding &utm=14 to the end and refreshing. Otherwise, I did some work on Chrome policies so I've included those below. You should be able to target these in Edge too and muck about in GPO too. Google AI Disabled. Under Devices > Chrome > Settings > Users & Browsers. URLs Blocked: google.com/search?udm=50 lens.google.com Omnisearch Provider settings: Name: Google Keyword: Google Search URL: https://www.google.com/search?q={searchTerms}&udm=14&safe=active&ssui=on Icon URL: https://www.google.com/favicon.ico The following settings have been changed to be disabled: https://chromeenterprise.google/policies/#LensCameraAssistedSearchEnabled https://chromeenterprise.google/policies/#LensRegionSearchEnabled https://chromeenterprise.google/policies/#LensOnGalleryEnabled https://chromeenterprise.google/policies/#LensOverlaySettings https://chromeenterprise.google/policies/#LensDesktopNTPSearchEnabled https://chromeenterprise.google/policies/#AIModeSettings https://chromeenterprise.google/policies/#GenAiDefaultSettings https://chromeenterprise.google/policies/#ShowAiIntroScreenEnabled https://chromeenterprise.google/policies/#GenAIPhotoEditingSettings This will stop the majority of AI requests, but users can still get around by navigating directly to search engine pages. If this isn’t sufficient, there is also an extension to rewrite any Google URL with &udm=14 https://chromewebstore.google.com/detail/google-udm14/ackpmepblmioeoofggbipphdaooogjga?pli=1
  2. I've implemented Clever at several primay schools. SSO into Google Accounts works exceptionally well.
  3. The "where possible" is referred in the DfE FIltering and Monitoring Standards. https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/filtering-and-monitoring-core-standard Your responsibility would be to discuss both options with the DSL, discuss the pragmatics of each option for teaching and learning delivery (i.e. waiting/capability for pupils to sign in and out, etc) and then for the DSL to assess the risk and solution.
  4. I agree with Tom, shared iPads would be the best route, plus it then would ensure the previous user signs out - rather than leaving an iPad on a single session with an authenticated firewall token from previous users. Device serial might also work if you have 1:1 devices. KCSIE still says "where possible" for identifying the individual on the device, and its exceptionally difficult on tablets. At least it does allow you to individually identify the device and time using that method.
  5. Try this config in the .plist for the Smoothwall Browser application in Mosyle before you try the Shared Mode. <dict> <key>SmoothwallSerialNumber</key> <string>SmoothwallSerial</string> <key>UserID</key> <string>%SerialNumber%@youremaildomain</string> <key>HomePageURL</key> <string>https://www.google.com</string> </dict> See if that works? In the Smoothwall Cloud Filter you should then see alerts for a user of the devices serial number in the log? You can then create the according user in AD/Entra and then map it to the appropriate policies/reporting in Smoothwall. As least when responding to alerts then you'll know the specific iPad in question. For individual users it'll have to be Shared Mode.
  6. OK, so you want the iPads to use one or the other and not both then. If your iPads stay on prem, then they won't need the Smoothwall Browser, they can use any browser and configure those to redirect to the Smoothwall On-Prem SSL Login page. The issue with that is that they'll retain the login from the previous user unless configured to used Shared Device. Otherwise install the Smoothwall Browser, configure it with your MDM to use the UserID string. In our Cloud-First setup we have the UserID string as device_serial@schooemailaddress. Smoothwall will use the UserID string for policy access/reporting. You can then make sure the on-prem policies allow for those iPad users (a user for each serial number) to access the internet. If that makes sense?
  7. Are you using on-prem or Cloud Filter?
  8. It's always useful to ensure that Intune, Entra, Microsoft, etc endpoints are excluded from any filtering/inspection to ensure service delivery. https://learn.microsoft.com/en-us/intune/fundamentals/endpoints?tabs=north-america
  9. Afternoon all, I'm currently working with a developer on a new product designed for education called Filter Sentinel. It stress-tests your school's filtering against the risk mandated by KCSIE 2026 safely simulating real-world vectors and goes above the tool mentioned above by running against recommended education baselines rather than just illegal content. I did a short presentation at the ANME a little while ago, but it's about ready for a closed beta launch, so if you fancy being included please complete the form: Filter Sentinel - Closed Beta Application – Fill in form It asks a few questions about your security stack, etc, as it's important that IT teams also understand how this can affect filtering results and is important to ensure various levels of protection are working as expected.
  10. There's a remediation script for Intune here: https://www.systemcenterdudes.com/remove-intune-onedrive-photo-app/ I'm sure it could be customised for all environments to remove the app - even a GPO file remove or script run.
  11. We have mail rules to disallow student to student and student to external communications. Students are allowed to receive emails from external senders that on an allowed domain list (UCAS for example).
  12. @Tefters does Lightspeed audit the user, does it show a load of that URL?
  13. What product is this? After doing some stack work with filtering each tool seems to do something differently.
  14. Got around 520 devices - haven't had any reports of these issues. If you have an X account, the Intune Support Team usually respond pretty quickly - run it past them:
  15. We have an overarching AI Guidance Policy, supported with an AI checklist for implementation in schools. For each AI platform the guidance stiuplates that a DPIA is undertaken to evaluate risk.
  16. Good morning, we are suffering from the same issue with PDFs opening in Edge and being blocked due to the URL. Is this reoccuring for anyone @tom_newton
  17. Had lots of issues with this with EXA filtering.
  18. I would sign up for an Edu 365 tenent with A1 licences, and purchase A3 licencing for FTE staff. Use Intune to manage the devices once A3 is in place. Action1 is a great supplement to Intune to be able to deploy apps/update/patch instantly rather than wait for a sedatary Intune application. A1 licence for staff would cover 365 apps online. A3 licence for staff comes with 1:40 student use benefit and would alllow the full 365 desktop/mobile apps to be used.
  19. There is a range of endpoints required for Intune. It's best to fully exclude this from inspection and allow them through Sophos and Smoothwall. It'll ensure correct deployment of policies and apps. https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/intune-endpoints?tabs=north-america
  20. Good work!
  21. I think Microsoft are recommending Power Automation as the replacement for alerts. https://support.microsoft.com/en-us/office/sharepoint-alerts-retirement-813a90c7-3ff1-47a9-8a2f-152f48b2486f
  22. Yep, disconnect them see what happens. Then check with configuration policies are assigned in Intune. Try and reconnect to the internet and move a test device out of any configuration policy and see if it boots.
  23. Do the machines boot every time without the network connected? Are you running AD on prem still? Could they still be registered in AD in a hybrid setup and some GPOs preventing a boot?
  24. Perhaps remove one from Intune MDM, flatten the drives and partitions and rebuild it with a vanilla Windows ISO making sure UEFI/Secure Boot is enabled and no legacy ROMS, etc. See if they boot without issue.
  25. Ports and IP addresses document attached from British eSports for the popular games including Rocket League. Might help with your filtering and firewall configurations. PORT-IP-24-25.pdf
×
×
  • Create New...