Jump to content

VinceM

Members
  • Posts

    6
  • Joined

  • Last visited

Everything posted by VinceM

  1. The product type for us is shown on the home page of the SurfProtect panel, where is shows the setup instructions etc. On the right there is a panel with the ID and product details. Looking at the status details they have set it up based on a proxy port rather than group membership (I wasn't aware that was an option as all our profiles were set up using groups before I arrived here). I believe that will mean setting up a different proxy server address for each type of user then, and Intune is too slow half the time as you said. The way we do it is via groups which has a single proxy server address for everyone and SurfProtect deciding what profile to apply. Our way does require the user details being on the SurfProtect servers but once done it largely just works for us. Oddly the times it has a problem for us is when the users computer needs a reboot rather than an issue on SurfProtect itself, but even then they get the transparent proxy.
  2. A lot will depend on whether you have Quantum or Quantum+ versions of SurfProtect as there are different mechanisms involved for each. To get profiles to work you need some sort of LDAP integration. Quantum works via AD only (so would be no good with an Intune on environment) but Quantum+ can use Entra or Google too. There needs to be a periodic sync of user details from AD/Entra/Google to SurfProtect so the proxy server can do the lookup and assign the right policy. The profiles can be set up to look for group membership and/or specific users - so if all staff are in a staff LDAP group, add that to the staff profile etc. The proxy server address used is the same for all users so there is no worries about who logs in getting the wrong profile usually. Sometimes the lookup fails and those users will get the default transparent proxy profile (which should be at least as restrictive as the student profile). You can see what profile you are being assigned by checking https://status.surfprotect.co.uk/. I would suggest reaching out to Exa support for guidance on setting this up and so they can explain and caveats that could catch you out - the documentation isn't always as up to date as the product.
  3. It was something in the group policies. I recreated them all, removing a lot of old legacy stuff. My suspicion is it was a Google Chrome or Microsoft Edge policy but I was under pressure to resolve it so didn't go into too much depth once it was sorted.
  4. Thats where I am going now - takes time waiting to see what happens each change though. I've got a basic policy in place but need to tighten it before I can give it to a student to test. I am taking a positive that it will force the GPO to be 'cleaned up'.
  5. Thanks for the reply I have narrowed it down to something in our Student User GPO since once I take the student out that GPO they don't get logged out. At present I am recreating the GPO bit by bit until I find something that causes the logouts. Time consuming since the logouts are random unfortunately and don't affect every device at the same time. My current theory is possibly something in the browser configuration settings (Chrome, Edge and IE). I already have Veyon removed from a number of devices (was an easy one if it was the cause but alas it didn't help) and don't have it on my test devices. The HTML export will be a harder one as there is likely some sensitive settings in there unfortunately.
  6. Evening All, I am battling a confusing random user logout that is occurring for most students on many different devices (both Windows 10 and Windows 11). It doesn't seem to affect any admin or teacher accounts logged into the same devices. The device logs seem to to suggest the users initiated the logouts but I know from the test devices I have running that it just happens regardless of whether the devices are in use or have been idle for a while. I have gone through a range of ideas from app updates (Minecraft Edu), Classroom control software (Veyon and Sophos for AV) through to various power management settings and things like CEIP. I believe i have isolated it to our Student User GPO, which has evolved for years from well before I started. My thoughts now are to manually recreate the GPO a few settings at a time until I can find out any that seem to cause this. The downside is this will take for ever since there doesn't appear to be any way to force the logout. Some days we can have a couple of logouts in the morning and then nothing for the rest of the day and then you get days like today when it was non-stop all day. Does any of the collective knowledge here have any suggestions of areas I should concentrate on. My initial thoughts are Google Chrome and MS Edge policies since I have already removed all power management ones which I thought could be the reason. Nothing is immediately obvious in the rest of the policies but this MS afterall so anything is possible. A positive to this though is that I could get a much cleaner GPO. If it helps, the devices are all Intune hybrid joined too, so management is through both GPO and Intune. Thanks Vince
×
×
  • Create New...