Jump to content

TheHyperTechie

Members
  • Posts

    699
  • Joined

  • Last visited

Everything posted by TheHyperTechie

  1. Hi all, I have had a head scratcher today. I am trying to enable remote access on a sites cloud key, so I can manage everything through my phone/web browser instead of having to log onto it locally. I logged onto the cloudkey and tried to enable remote access, it asked me to log in with my UniFi SSO - no problems there! However, I received an error message stating to contact my ISP. I had a read online and asked my ISP to allow the correct ports for remote access (as listed on the Ubiquiti website) After I had confirmation they were unblocked, I tried again, still no luck! I restarted the cloud key to make sure but yet again no luck... Has anyone else come across an issue like this? TIA.
  2. Hi all, Just wondering how everyone else is managing 3rd party API access for their google domain/users. Are people just monitoring the "unconfigured" section and blocking access to that particular website/software. Are you giving 3rd party apps trusted access, or limited access? I feel like it is a bit of a rabbit hole. I do not want to limit access if staff/students are using that particular website. The only reason I am asking is mainly due to change google are implementing regarding 3rd party app access. If you have any OUs with an age label of < 18 they will not be able to access any of the "unconfigured" 3rd party apps (unless you configure the access e.g. trusted, limited, or restricted) TIA - I hope everyone has a lovely weekend.
  3. Hi Steve, This makes sense thank you. Just for reference, there will be about 30 handsets between both schools so not a huge number. I do believe that an 8sc license would be a safer option, As currently with the 4sc, if 4 people are on the phone at the larger school, no one would be able to make a call at the other... but upgrading to an 8sc would eliminate this issue. I think I will ask for a 8sc license!
  4. Hi all, I am looking at migrating our small MAT (2 schools) to a VOIP phone system. (I know I should have already haha!) I will be using a 3rd party MSP to host everything in 3cx, and each schools SBC will be built into the handsets. So this irons out any need for on-prem hosting etc. My main question is regarding SIP trunks and channels. I believe I know how this works, but please correct me if I am wrong.... 4sc license (between both schools) 1 SIP trunk with 4 channels for the larger school, and 2 for the smaller schools. If my knowledge is correct, the school will have the capability to have 6 concurrent calls between them? however, because they are on a 4sc license, they will be limited to 4 calls between them. This is what the MSP said anyway. He did mention, that if 4 calls is to little, you could upgrade to a 8sc license which will allow them to utilise the 6 channels, (6 concurrent calls) and then there is room to add two more channels to the sip trunk for them to be able to have 8 calls between them. Is this correct? Sorry if this post makes no sense! just wanted to confirm that this information is accurate. TIA.
  5. Thanks for your reply. So just to confirm, if the school didn't have Edusync, would they still be able to use Wonde SSO for their Chromebooks with magic badges etc... Or is Edusync needed in order to create the SSO for users?
  6. Hi all, not sure if this is the best forum to post this in. I have just taken on two schools that have a complete Arbor > Wonde synchronisation setup. They sync Arbor with Wonde for SSO magic badges and emoji passwords on their chromebooks. Edusync is used to sync users into Google and create their accounts. Essentially, I do not need to carry out any user provisioning, which is great. However, I just want to make sure I 100% know how the sync works... this is how I have worked in out (I think) 1. User/Employee is created in Arbor 2. Arbor syncs with Wonde and creates them a Wonde SSO log in. 3. Arbor syncs with Edusync to create their google account, and places them into the correct OU. Are Edusync and Wonde SSO two separate entities? I would love to know if any other schools are using this setup... Thanks!
  7. Hi all, I have just taken on two schools that have a complete Arbor > Wonde synchronisation setup. They sync Arbor with Wonde for SSO magic badges and emoji passwords on their chromebooks. Edusync is used to sync users into Google and create their accounts. Essentially, I do not need to carry out any user provisioning, which is great. However, I just want to make sure I 100% know how the sync works... this is how I have worked in out (I think) 1. User/Employee is created in Arbor 2. Arbor syncs with Wonde and creates them a Wonde SSO log in. 3. Arbor syncs with Edusync to create their google account, and places them into the correct OU. Are Edusync and Wonde SSO two separate entities? I would love to know if any other schools are using this setup... Thanks!
  8. Hi all, I am looking at demoting our domain controller, as users are no longer using it to authenticate against now. The domain controller currently hosts their DHCP and DNS (which I want to keep). I am hoping to move DHCP and DNS to a different host. Can anyone please explain the simplest way they might do this? or if you have done this what steps did you take? I am thinking exporting the old vm, and importing it to the host will do the trick. Would I demote the old DC first before exporting to the new host etc? TIA
  9. Hi @rogerdnixon, I have been in touch with Google this morning and they are going to apply some standard licenses as a trial for our domain. This will give me a chance to test it correctly, before making making the final purchase.
  10. Hi @rogerdnixon Brilliant, thanks for the explanation. So in simple terms you would set the main user settings such as updates, bitlocker, account type at the top level so the child OUs inherit them. Then you can be more granular with settings for other OUs such as the administrator user group who will need their user account permissions changing. It's good to know that the settings are applied to the OU -> User -> Device that they sign into. Thank you.
  11. Hi @rogerdnixon thanks for your reply. I think enhanced desktop security via Google will be the way to go... Quick question, do you apply the windows device management settings (such as update settings, access level, bitlocker etc) to user OUs groups, rather than device OUs? So if you apply these settings to a user OU they will apply to any device the user from the targeted OU signs into? Thanks... I hope the above makes sense.
  12. Hi @dhicks thanks for your response. Yes, that was the only issue I found with it too. In my case the windows devices I will be moving to GCPW are basically 1:1 (Teacher laptops). So I believe they would only need to sign into the drive client once and it will then stay signed in for the user if they log out (please correct me if I'm wrong though) I guess if I provided training to staff as well, they would understand the need to save to Google drive rather than locally... Hopefully haha! Action1 also seems very good. I almost can't believe it is free... In my experience and recent testing though, I honestly believe windows devices could be managed via GCPW and Action1. Quick question, as I only have education fundamentals, if I enable GCPW for my domain, does it make every user that signs in that way a standard user or an administrator? I think the answer is standard user, but wanted to confirm.
  13. Hi, thanks for your reply. 1. I will definitely look into back up options. I did make use of Synology Active Backup at my previous school, and this did work very well. I suppose the idea of a one off cost for a NAS is also appealing. 2. I was looking into upgrading their Google licensing, but just wasn't sure if it was needed. I have used Action1 for a while and it handles patch management very well, can deploy updates, run scripts, remote desktop, install/un-install apps. I wasn't sure if using something like this was a better choice. 3. I will take a look into this, as it sounds very interesting. 4. I am not 100% sure on what they use for door access, most probably is paxton, but I will double check. Thanks for your help!
  14. Hi all, I made a post a few weeks back about migrating schools to 100% Google and had some very good feedback... Since then, I have acquired a new job as ICT Network Manager at a very small MAT (2 schools). One school has around 500 students, and the other only has about 120. Both schools are VERY into Google with students and some staff using Chromebooks and using Google Drive etc. The larger primary school has one physical host running Hyper-V with two virtual machines. While the smaller schools server died a while ago, (and the current network manager didn't think it was worth replacing due to the amount they use Google Services). I will be looking to introduce GCPW over the summer for the remaining windows devices, to authenticate users without AD, and I will be managing these devices in something like Action1 rmm. Staff will be able to upload their remaining documents to Google via the drive client, and I will move any on-prem file shares into Google shared drives and reshare them out. The Chromebooks will obviously be managed through the admin console, so no issues there. They both use Arbor so SIMS doesn't need to be hosted anywhere. Our ISP can also host DNS/DHCP on the firewall. I am trying to work out any hidden costs this migration will cost for each school... Not sure if anyone can advise? So far the only immediate costs will be running Papercut mobility print on a desktop £150-£200? and backing up staff folders/shared drives in Google workspace, Cubebackup for example £2 per user a year. I am sure I will be missing some kind of cost out somewhere! TIA
  15. Hi all, I hope everyone is ok. Thought I would ask on here, as I am sure someone can provide some feedback etc. I have really been exploring GCPW at my school recently and.... I really like it. They are a google school with about 300+ 1:1 chromebooks for the students. The staff use windows devices but mainly use Google Drive for documents rather than saving anything on the server. I am looking to explore the options that Windows Device Management (G-suite console) could bring with managing these last few windows devices. On our fundamentals licensing we don't have access to any of this (Only GCPW) but long term, I would like to think I could manage these devices through GCPW and WDM too, all from the google admin console. This would allow us to remove on-prem hardware. I suppose my real question is pricing... would anyone mind sharing how much they paid for their upgraded licensing to either standard or plus? I have had a rough look around and it seems that for standard it is about £2 per student... but with every four licenses you get a free staff license. I'm not sure how much persuading our school would need to purchase this licensing, as currently they are on a free plan, and only pay for device upgrade licenses. But I do think the benefits it would bring to the school are worth it for the long run. TIA.
  16. Hi @dhicks I have tested out GCPW today and I have to say it's seems really promising. I signed in with my Google account and obviously still have access to the software already on my laptop (which is a bonus). I also had a play around with the policy settings and most of these worked, however, I couldn't seem to get custom settings (gpos) to work. I would set them up (block camera for example) and assign it to an OU but it wouldn't show in the console as applied, or even show at all! I'm not sure if this is due to a licensing issue perhaps? But overall really good, I think if staff moved all of their data from the file server into Google drive and used this from now on, I could definitely remove the on-prem AD/file server in the future. Then it's just handling printing, DNS, DHCP etc but definitely doable. Thanks for your help!
  17. Hi @dhick, wow, it seems that you have the exact set up that I should be running haha! I have had a look over GCPW and looks really good. I think I am going to need to test this out. So do you not have an on-premise AD? In a sense, this basically seems like Google's version of Intune/Azure. Do find that the included restrictions for endpoints are more than enough? and also, what plan do you have? I currently have education fundamentals...
  18. Hi @southhamster thanks for your reply. Yes this seems to be the only thing holding them back at the moment. With everything moving to a web based service, I am sure they would manage, but I would want to confirm this with them first of course. As @dhicks mentioned earlier in the thread, I could use GCPW so the admin staff could sign into their windows devices with their google accounts, and I believe the device can then be managed through the console, but please correct me if I am wrong!
  19. Hi, thanks for your reply! Thanks for the link, that looks very interesting. Do you use this at the moment? Yes, if they have available funds, I will definitely be looking at an on-site (NAS) and possibly a cloud back up. For papercut I could use the current server (but just for that) or invest in a cheap desktop to run it.
  20. Hi thanks for your reply! Well, I would be issuing a chromebook to every staff member. So there would be no need for Intune, or Azure etc (at the moment). I would just manage the devices and users from the G-suite console. Of course the only issue I see with me doing this, is.... Legacy software! such as the office suite. I suppose in the future I could always buy some staff licensing so they can access the apps in a browser such as word, excel etc. And yes, resilience is definitely a key factor. It would need be planned correctly, and They would need to invest in a redundant line for sure.
  21. Hi, thanks for your reply! - Yes, a server will still be needed for Papercut forgot to mention that! I suppose it could be hosted on a desktop or I could look into a different printing method such as IPP or similar. - Users could either be created by myself, or by using something like salamander to link to Arbor (as you mentioned) - Yes, I could mix firewall with filtering. They use RMSafetynet at the moment. So I could set up an IP range for staff and student devices and apply the policies accordingly to each range (staff/student). Or I could assign a policy to the whole IP range and enable the staff proxy for staff to access certain sites etc.
  22. Hi All, I was wondering if anyone has fully migrated their schools to Google....? I work in a large primary school with a very "hybrid" set up. The students use Chromebooks, and some of the staff/teachers do to. However, there is still an on-prem DC (that is tired) managing a few windows laptops hosting services such, Active Directory, DNS, DHCP, Printing, and file shares too. My thoughts are to do the following... - Deploy the google drive client on remaining windows devices to sync users files to the workspace - Use papercut mobility print for printing services - Host DNS, and DHCP on firewall. - Use something like Synology Active Backup for workspace, pointing to a NAS off/on site. - They already use Arbor for their MIS so no issues there. - Invest in a redundant FTTC/5G connection in the event of a main line issue. - Senso.Cloud for safeguarding monitoring, and possibly Securly for extra filtering. - Licensing is perpetual, so would be looking at roughly £30 per device - Training provided to staff/students on how to use the Google Workspace apps Please let me know if I have missed anything, as I am sure I have! I am more interested to see if any schools have actually succeeded in migrating fully to Google? How have staff found it? Has there been any software issues? is it even possible? haha!
  23. Hi, I am located down in the South West and have used this company a couple of times https://www.greenitdisposal.co.uk/ Their service has been great. Although, you do need to have a certain amount of qualifying items such as switches, printers etc for a free collection!
×
×
  • Create New...