Jump to content

klop

Members
  • Posts

    230
  • Joined

  • Last visited

Everything posted by klop

  1. Thank you, new sponsors are suggesting to ditch the existing email accounts and just go with the new. We have agreed to keep them running for a little while and set them to forward to the new. I'm not comfortable with Powershell so guess its the forwarding option
  2. Hi, we are in the process of becoming taken over by a new sponsor. Our new sponsors are suggesting we cease using our current email accounts and be setup within their Ofiice 365 account so we all may use the same domain, ourschoolname.sponsor.academy - our existing accounts are ourschoolname.com I would like to know if there is an easy way to transfer our domain, complete with all mailboxes over to their O365 tenancy(?) and use their domain, perhaps keeping our existing as an alias? I have looked online and there appears to be third party companies that offer a migration service - has anyone used this? Cost will be an issue though. We are only a small school, around 100 members of staff. Pupils have had very limited use of emails so not worried about migrating them - just staff accounts. Thanks
  3. 1. It appears not 2. It appears yes 3. No idea!
  4. Thank you all - will phone around today and get some quotes.
  5. Hi, we are on our last year of a three year Microsoft OVS originally purchased through Misco. Loking for recommendations for a new supplier to quote for our final year. Thanks
  6. We use Bitlocker (though there may be some laptops still running truecrypt which we used before it ceased) We use an individual password for each laptop that the teacher chooses. Password must be min of 10 characters and contain lower & upper case, symbol and number(s) This password is different from their AD login. Staff have a little grumble at first, but I often help them come up with something memorable and it seems to have worked so far. I keep a log of all encryption passwords in case I need to use them. Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out!
  7. Hi all, We push our wifi settings to our iPad via apple configurator 2 We then use Meraki to manage However I cannot get the outlook app to work on the iPad due to our necessity to use the proxy settings for filtering I had to tether it to my phone to even get the app to install. Anyone know a fix please?? I can use the built in email app - that works ok but would prefer to use Outlook app. Thanks
  8. If we were do not force complexity into staff passwords I would prefer that we continued with the password expiry - at least something is then in place. Having read much professional guidance on using the expiry policy it states adding other options to secure - options that we do not have currently in place. However, it is hopefully under discussion. But if staff are unable to keep their passwords secure themselves, whether it is changed regularly or not it may be considered that they must be changed just to try to keep them from being known by others. If staff will not (and do not) choose complex passwords by choice and we choose not to force them - then other options need to be considered - what would you do? If you know that staff are sharing their passwords and never changing them then wouldn't you consider that to be unsecure? Additionally we have at least one member of staff who does have fixed passwords for other logins and does still write those passwords down in their special password book - not secure either really!? Basically - you cannot win - at least not in at place!
  9. It doesn't - that is the realisation... at least not without other factors included. What would make for a secure password is staff acceptance that a password should be secure. We were instructed to set the password change during an audit - and previous members of the SLT (who have now left) were insistent that we kept it. I am hoping to enforce complexity and perhaps retain the password life to 90 days (from 42 I believe) - however I am still waiting for a reply.
  10. I'm guessing you have faith and trust in your colleagues to use strong passwords... and to let you know if they feel it is compromised and needs to be changed. Unfortunately I do not have any faith or trust - complexity is not activated here at present and many of the passwords I see are very weak. One member of staff has our town name as a password (it's changed now) and couldn't see why this wasn't secure for O365. Others have their children's name or perhaps the month name maybe followed by a number and that is it. The school policy states passwords should be strong and gives examples - which is simply not followed. To be honest I'm tired of the moaning here relating to passwords - either resulting from me suggesting someone's isn't strong enough or the groan that they have to be changed - which was dictated to us during an audit sometime back. So.. once and for all I want a decision from the SLT and I will put that in place. Staff will still moan at me regardless - but maybe I'm past caring!
  11. Brilliant - thank you
  12. Oaktech - do you know if disabling historic passwords stops a user changing the number at the end? ie, P@ssword!1 would meet length and complexity but could they then use P@ssword!2 P@ssword!3 P@ssword!4 etc ?? Thanks
  13. O365 still sets a 90 day expiration as default though - can you point me to a Microsoft page suggesting to disable it please? I'd like to show it to our head / deputy head and maybe we'll stop the need for staff to change it. At the very least we'll change it from 40 days to 90 I think Thanks
  14. I believe if you set up accounts direct in O365 you have the option to remove password expiration? But that it is set as default to 90 days? Staff here would be very happy if we removed the need for them to change their password every 40ish days. I'm waiting on replies from our deputy & head to see what their initial thoughts are.
  15. Thanks everyone - had a look using the fine grained and it looks pretty straight forward and simple to do. I've sent an email to our head and deputy (who is also our ict coordinator) expressing my concerns re passwords and what I think we should do to make them secure. I await their replies! Thanks again :-)
  16. That's brilliant - thank you!
  17. Hi all, I work for a small SEN school. Ideally I would like to force passwords for complexity and minimum length but just for staff. Some of our pupils are only able to use single character passwords - but that is ok with us. Is there a way I can use a GPO to enforce staff policies without affecting pupils? Currently we have a password GPO that has complexity, length, 42 day change etc set with loopback within the staff OU - the 42 days change works but not the others. I understand really the password rules should be set in the Domain Default Policy but of course this would affect our pupils logins too. We have staff who have pretty much pointless passwords and in today's age this seems crazy. I have just spoken with a couple of members of staff who find it funny that I think their passwords should be secure. They simply will not change them. One even suggested if I force them to be secure he will stop using his laptop and complain to SLT that I am stopping his access!! We have Server 2016 & Windows 7 Pro clients. Only thing I can think is to try setting the password policy at the very least in the laptops OU that only staff use - would that work? Would be a step forward - but they'd only have to log into a pupils use PC to have an 'easy' password again! Thanks for any pointers!
  18. Doesn't that just backup a maximum of one VM?
  19. Thanks again - very helpful. I didn't know if Veeam was a complete backup or incremental - it's good to know it's incremental as it'll be a lot quicker. We couldn't afford to have fibre installed to the separate building so relying on cat 6. I appreciate we haven't a second server to restore to should we have a problem with our current server but we simply do not have the budget to purchase one. Our main physical server is new and a direct replacement for one that failed. Even had the replaced server been useable there is not anywhere in the separate building where it could be housed - the NAS was our only option due to weight and size - no space for a server at all. Also we're only licensed for the one server for Veeam - and you'll not be surprised to read we couldn't afford two! Should the main server fail we do have a second physical DC and it will be a case of using the backed up VM's to get the office up and running asap and then replace the server asap. Pupils and other staff would simply have to wait - the SLT are aware of this. Additionally all critical data is backed up to RBUSS so is available offsite - including SIMS.net. It is not ideal - but it is all we can do with the budget & existing hardware we have. Re, 2 CPUs and 4GB RAM - that's the plan to virtualise the SIMS server asap & then use the existing SIMS box for Veeam out the window - just found out it's a single CPU!! Oh well. Cheers :-)
  20. Hi mikkydoos, thanks for your reply. We only have the one server that is capable really except the possibility of using our physical DC - perhaps a VM added to is solely for Veeam but I've read you shouldn't run Hyper-V on the DC? Our second DC is a VM that will be backed up using Veeam. I'm not ceratain of we've enough RAM in the physical DC to run the extra VM though - and NO budget to purchase any! We are currently running SIMS on a physical server - not sure it would be capable of SIMS and a VM for Veeam. Plan is to virtualise the SIMS server one day and then I could make use of that physical server itself - but no idea when that will happen - far too many other things to do. I've not installed Veeam yet - but the plan is to backup all VM's to a NAS drive housed in a separate building every night. I'm not certain but hoping this is something we can do? I know replication would be better but without the hardware that's not an option for us. Admittedly it means should our 100% relied upon single server fail we have a bit of an issue - all our eggs are in one basket! Would the backups from Veeam require Veeam to be installed to a new PC or Server to be able to make use of the VM's backed-up, or could we simply install Hyper-V on something suitable and 'copy' them straight to it from the NAS? Thank again :-)
  21. Hi all, We have a single server with Server 2016 and running Hyper-V We have 5 VMs on this server. I have a licence for Veeam and wish to install it. Unfortunately we do not have much in the way of anything else to install Veeam onto so I am wondering how successful it will be to install Veeam to the host itself? I appreciate this is not ideal - but will it work fine? I realise should I lose my physical host I've lost Veeam as well and will need to reinstall - that is the one thing that worries me I guess. But not sure we have any other hardward that will meet the min spec. If I do install it onto the host would it be best on the physical OS running Hyper-V or onto a VM - ideally again I'd prefer it on the physical ? Thanks :-)
  22. Hi all - full of cold but trying to figure a best setup for our new server. I want to go VM using Hyper-V (we are currently all physical) I'm thinking; One VM for DC AD/DNS/DHCP One VM for Files One VM for Print These will be backed up to an 'offsite' NAS using Veeam. Critical files will continue to be backed-up offsite using RBUSS The above will release our current Print Server so I can use it as a secondary DC with AD/DNS/DHCP - this will be physical - I believe it's a good idea to have a redundant physicl DC too - of course this could be a VM too - but RAM maybe a factor. I understand it's best not to use a DC to host additional VMs? I'd liked to have put maybe one or two small VMs on this DC to run maybe our electronic doors, Spiceworks, Sophos. We will keep a legacy older (current DC) server and use that for WSUS, non-critical files, and anything else I think of! SIMS will stay on its current box and I'll be looking to VM that later - then run it back on it's current box as a VM I'd also like to look at the possibilities of SCCM & WDT as soon as I have all the above up and running nicely. We're a very small SEN school - hence quite a basic setup Thanks :-)
  23. We changed our wireless to wired in the end - much better. We're a very small school so very few doors but our front door is now wired direct to the fire alarm panel and a classroom door is wired to a fire alarm sounder for redundancy. great system, working really well. Even emails myself, the site manager and the head teacher if the fire alarm goes off - which is more than our fire alarm does!
  24. This is a shame, I wanted to setup just 6 computers for a group work but to have to buy it for all students that might to choose to come along and play it - well that's a no from us. Is it possible to purchase for just some pupils? We're SEN and do not use emails for our pupils - I'm guessing I'd need to setup O365 accounts for those pupils that might want to use Minecraft too? Thanks Edit... would the yearly charge be per academic year, calendar year or our ees agreement? Is the charge via ees or direct chargable to O365 - which we currently pay nothing for! Cheers :-)
  25. Sorry o dig up an old thread but did anyone get to the bottom of this? We are an SEN school and therefore have a high number of TA's - many of whom are part time. They all work in access of 200hrs per year though so all have historically been counted. Very few of our TA's though use the PCs. A handful have laptops or PCs for their use but most just access their emails from their personal phones (a separate issue!). If we do not have to include those TA's who do not use PCs frequently it would help us a lot! thanks.
×
×
  • Create New...