Jump to content

dapaulio

Members
  • Posts

    1,459
  • Joined

  • Last visited

Everything posted by dapaulio

  1. the laptops are not domain joined. they were bought years ago (10years ago maybe) solely for the purpose to aid teachers who didn't have the facility to work on a computer at home were given a staff laptop. so happened that once they new they could get one they suddenly all wanted one
  2. I can understand their reluctance to advise as really the method is an option that would create a lot of work for something which is not directly supported. I can understand the easiest and more secure solution would be to recall and replace with TPM chipped laptops. something which schools do not have the budget to do.
  3. Whilst testing I have no other option but to use a usb. the pin option is grey out. the USB acts as the TPM chip and is required for devices with No TPM chip on the motherboard. I know I can set a HDD password but that is not encrypting the drive.
  4. Just to clarify. School issued laptops off the domain that staff use at home for personal/work use.
  5. What are people's opinion on this situation. We have staff laptops in our inventory that have no TPM chip running Windows 7 ent. Really Really old. Personally nowadays I really do not know how much staff use them and whether they use them for "work" purposes. Recent laptops that I have bought with a TPM chip integrated are already encrypted so not an issue as far as GDPR goes However the no TPM chip laptops, I am planning on recalling all laptops to ensure that all laptops have Bitlocker enabled and force staff to boot with USB and Pin. This is something that I know how to facilitate but concerned that teachers will see the extra step as a burden and no longer use the laptops as an asset. Also slightly concerned about the impact it will have on my support when they inevitably break/lose the usb device. Again I know how to support if the case happens but being on my own just concerned of the impact it will cause on an already stretched IT support, implementing bitlocker on all Non compatible TPM devices and then supporting it when it goes wrong. What have you all done? am I over thinking it? do I need to do it? or should I be recalling all laptops without TPM?
  6. As we have o365 account I went down this route, however if you don’t have either google or o365 I would encourage staff to sign in with a sims Id. Forward thinking It may integrate better if you chose to go sims hosted route. It be easier to manage also if there is a change in personel doing the role. Note (Options online does not disable the users account if you were to disable an account in sims self hosted). I assume it would if you already had sims online . In my case I’m hoping that disabling a user in ad would result in the o365 account being disable therefore options online would also become disabled. Parents would probably be ok using fb or twitter if that’s the route they want to take but feel social media for staff logins is a bit wrong.
  7. Not looking for anything which requires a lot of input. Needs to be the simplest of simples. . Just need a system that centrally catalogues jobs and staff log a job from their computers and the maintenance team action and close it.
  8. Sorry to hijack this thread. I’m looking for a basic easy to use interface to use with our maintenance team. Which one of the suggested would be best option.
  9. This is bugging me today I have a 2012 server with a mapped drive to a file server (2008r2). I have just deleted a load of stuff from the share on the 2012 server but the space has not been recovered on the file server. if I repeat the operation on my computer (win 10) with the same mapped drive, it deletes it to the recycle bin and recovers the space once I empty the recycle bin. when I do it on the server 2012, the recycle bin is already empty (doesn't fill up to empty) Scanned the Volume using folder size and confirms $recycler is empty is there something different on 2012 that I am missing? why wont anything I delete on the 2012 server recover disk space on the file server. Thanks
  10. I hope removal of leaver photos is necessary. Regardless I may just spout it around anyway. I would gain so much space back on my file server [emoji57] seems like a valid excuse that won’t get questioned
  11. Is the 2008 box a physical server with loads of hdd in. If so reinstall it with a 2012 or 2016 box. Add the wsus role. If you have gp targeting. Change the group policies to suit. Don’t give it the same name or ip. I would give it a new server name and IP address Relatively straight forward. Download (should say sync) all the updates and restart all the machines and let them check in.
  12. Probably been buying them for up to 2 years now maybe. As fn-gm comments never skipped a beat. I have 3 on my desk. One being a 24”touch. My only complaint having to remind other people I support not to touch my screen. I sound very possessive over them [emoji23]
  13. Not this specific model but have a number iiyama models around the site. I’m impressed with them all and have become my preferred monitor to buy atm
  14. Are you approving all updates including the superseded? Right click on column header and tick supersede. Sort the update by the supersede column Only approve updates with no symbol and where the top box is highlighted. The rest should be superseded All superseded updates can be declined then cleaned up
  15. I was thinking more on the server it’s deployed from. But yes I agree
  16. Are you using the same answer (unattended) file. Quick google on status code points to permission of the user account supplied In your answer file are the credentials hashed? Try (as a test) sending them in clear text. If that works then you will need to regenerate your answer file.
  17. I get your point and completely agree, it isn't my problem if they cant do as they are directed to. but these are teachers and some really do need their hand holding from the point they leave their front door to the point they return home in the evening. It is mentioned in the AUP that users are not to download from youtube or any other copyrighted material and distribute it across the network but they do and they get away with it commenting that the network shouldn't facilitate them to break the law resulting in a managerial instruction to put better measures in place. I tend to choose my battles and cant see what measures we can improve on other than blocking all audio media file types from being saved. anyway I am digressing from the actually question.
  18. oh yes forgot to mention. we do include it in our AUP however because no one ever reads it (not IT problem I know) I send it every now and again just to make sure we are covered from that perspective. at least then any infringement staff and students have no leg to stand on for not reading my email and the small print of the AUP
  19. Morning all As I have been reading about the GDPR it got me thinking about HTTPS Inspection With HTTPS Inspection smoothwall has an disclaimer when you set the warning to never, about "local law blah blah must inform users blah " however as I have experienced if you let smoothwall inform users it doesn't half cause some problems therefore I usually send out an email every now and again but concerned now that these more stringent rules may mean that I am not doing it frequent enough and I want to fill my part of the survey out with confidence that it will not raise any questions. (we all like the quiet life ) How often does everyone inform their users that they inspect and decrypt secure traffic on their network? I usually do it once a year (or when I remember to do so) however with the turnover of staff increasing with part timers and supply I feel maybe more frequent message need to be sent. Also anyone got a more professional message I can steal of them. because I do it so infrequently I only quickly right one up which may not sound the best. I would appreciate if anyone could share their messages Thanks
  20. Yeah ours too. We Implemented specifically for lockdown purposes only. It’s only been implemented for a few weeks now and already messages have been banded about re be careful of the snow. Cancellation of an event. I have used it for technical announcements but that is justified. in my eyes that’s what it is good for [emoji57] and what I say, goes I can foresee before long it to be a replacement method of pointless all staff emails Eg such and such has lost car keys... etc
  21. Maybe this is something that netsupport could implement as a feature in to the next build
  22. @fiza net support techy have answered my questions in an email. Unfortunately you can not lock down the console but they suggested that I could deploy the console into iis and use a web front end rather than the console as this is a cut down version where you can only send messages. I’ve considered this as an option but not yet actioned it as there is only slt and myself who have access to it but already slt have asked now to give every admin member an operator account. As a result of this I have requested that rules are put in place before I create them. As when using this software, I can foresee a message been sent out from admin containing personal info of a child whilst the unsuspecting teacher is delivering her lesson with a projector You can contact them directly for help the only method of changing passwords is to delete and recreate the operator however it was suggested that you can use nt authentication in iis to do this.
  23. are you sure users are not manually switching using the shortcut windows + P. Just saying it may not be a fault. Our students and staff know how to switch views as a regularly email tips and training every now and again +1 on displayswitch.exe in logon script
  24. Hello community and @NetSupportTechSupport We have successfully deployed and happily using Notify, however I have a few questions to the administration of the console and giving permissions. Currently all users have access to the whole console including server setting and customization menu which I would like to lock down. I have noticed in the operators tab there is a permission button however it is always ghosted out regardless of the user I select. Second question I cant seem to find how to direct my users to change their password as they have all been issued a default password to log them all in. Any help would be much appreciated
×
×
  • Create New...