Jump to content

itskdog

Members
  • Posts

    375
  • Joined

  • Last visited

Everything posted by itskdog

  1. I seem to be the only one here on LGfL's VoIP system (predates my time here, not worked at any other school yet so can't speak to anything else). If you're already with them for broadband, it's at least worth being aware of the option. Wavenet (formerly AdEPT, formerly Atomwide) manage it all for you with a custom web UI over the Cisco UC backend, no need to know all the complex PBX jargon. Anything you can't do in the web UI you can just log a ticket for. More complex configuration jobs they might charge ~£50 for, but basic settings like resetting a voicemail PIN, renaming/renumbering extensions, setting speed dials/BLF buttons, allowing/denying outbound calls, you can do yourself. The phones (with a variety available, from basic plain ones suitable for classrooms, to proper desk phones for offices with BLFs and speed dials) just plug into a dedicated PoE switch that goes to its own port on the firewall (we've put one on each rack as all our patch cables on each floor go to the same location), and they'll manage the switches & DHCP/TFTP settings themselves. Voicemail and extensions can be accessed remotely from the auto attendant (but you can block certain extensions from being accessed remotely to stop the kids messing around during break time), and the existing MIS integration used for creating USO accounts also lets the school office call parents with one click on their PC.
  2. Reporting false positives & false negatives is something that all staff should be encouraged to do anyway (as hard as it can be to train them when so much spam keeps coming in to any email address published on the school website), as they'll be able to tell if an email is legitimate more than IT can, if there is specific context in place that can affect that. Depending on how you have it set up, you can get a copy sent to a dedicated shared mailbox (either on its own so you can review for personal info before sending to Microsoft from Actions & Submissions if you're concerned about GDPR, or both to you and to MS together). Sending admin submissions as "I've confirmed this as clean" also lets you add an allow entry (and add your own opinion if Microsoft have clearly got it wrong with their first analysis from the user report), and the current default is "45 days after last used", so it will usually stay until Microsoft fix it on their end.
  3. Edge has an "IE Mode" for exactly this situation. It's IE11, but I think IE's compatibility mode is also available for if earlier versions are expected by the webpage.
  4. I think AutoSave in PowerPoint and Excel is only in the M365 versions, not the LTSC versions.
  5. We try to encourage using OneDrive (OneDrive is set to Anyone, but SharePoint/Teams is restricted to tenant-only) - Outlook already asks the question it if you try to attach something >20MB, and if someone needs to send something to us, we can demo use of the "Request Files" feature.
  6. 15 24-port Meraki switches + a spare in case one fails so we're not waiting for an RMA to bring the devices connected back online. Our (also Meraki) APs are connected to xGbE ports, clients to GbE ports, server to fibre cables via SFP with 2 per VM + 2 for the host, each one an aggregated link. Switch stacks are linked between floors by fibre/SFP, also.
  7. I called support today, they started walking me through going to the new user management page, then back to the old one, then when I said the tab isn't showing anymore, she said just to email the support email that's in the bottom of the new Cheat Sheet that was sent out this morning (not publishing in case there's a filter for it here) and they'll do it for you from their end. I'm sure the more work we create for them, the more the devs will be badgered into fixing it.
  8. Should be able to uninstall it with PowerShell Package name is "Microsoft.YourPhone"
  9. Do you have restrictions in place such as AppLocker that block access to certain applications?
  10. Good news, 25H2 is expected to have a group policy setting to uninstall various inbox apps, no more PowerShell scripts!
  11. When speaking to Support they apparently did send emails out about it like the previous upgrades to MFA. Maybe it's because I opted out of marketing emails when they sent out the one for VisitorSafe (along with all the really frequent ones aimed at DSLs) that for some reason actual service announcements also fall under marketing for them? Problem is, there's now no way to disable someone's 2FA because it's no longer in in the StudentSafe portal, and hasn't been added to the new Auth0 portal either. Also the fact that they have to say "make sure to select email instead of text as we'll be removing the phone number options" makes me think this was prematurely rolled out. Would have made much more sense to roll out everything in one go, rather than piece by piece which has caused so many issues for them as they're having to put temporary bits in place in the old portal when they're not even going to use it in the long-term plan.
  12. Following for my own info. Have used it at home, but 24H2 only came through for me in May, and still kept failing to install. I'm hoping all the issues they had when it first released last year are largely fixed by September. At least hotpatching is becoming a thing now on Ent/Edu editions managed through Intune, so nagging staff to restart might be less frequent.
  13. Ultimately it's a question for the DSL to take, as to whether they would accept the risk or back you with forcing use of the offline editor. They're in charge of the filtering now per KCSiE, and if you don't have their backing, it could cause more headaches for you.
  14. As we'd be We'd have no need for on-side DNS with no AD, so I believe the plan from RM was just to put LGfL's DNS servers in the DHCP config. Our firewall is managed by Wavenet (who acquired AdEPT Education, who acquired Atomwide) as part of our LGfL broadband, we don't have any control over it other than logging a service call with Wavenet to open ports as needed, and even then they can be a bit funky about it. Just had to get a firewall swap so they could open ports by FQDN for O365 HVE, and still it's not entirely reliable as I think they still just did it by IP address... 🤷‍♂️
  15. Do they still have a desktop app? Might be worth reverting back to that so there's none of this social-network type stuff that might be useful for children using at home to practice their coding skills, but in the classroom where they're following instructions from the teacher and saving to the StudentShared drive, it's not as necessary IMO. I don't think we block the website, but we do have the app installed, and AFAIK the teachers use that in the ICT lessons.
  16. Hey everyone, We're in the process of preparing for a summer job of retiring our server almost entirely and move to Autopilot+Intune (we can't move printing to the cloud just yet as we're using RISO MFDs, and we want copying to impact credit balances, but the DirectPrint integration doesn't support that yet, so one more year of PaperCut MF it is), and considering how we're going to manage DHCP. We're torn between keeping our existing DHCP settings on Windows Server 2016 for the time being, or moving it onto our core switch stack via Meraki L3 routing, but with no routing, just a DHCP server. Naturally, third-party support contractors (RM in our case, who are also managing the cloud configuration for us) would be able to aid us with the server-based DHCP more, but Meraki do quote 24/7 phone support if there are issues. Does anyone have any experience using switch-based DHCP, on Meraki or anything else, and could advise on the pros & cons of that compared to a traditional setup?
  17. It's only slightly hinted at in the KB via this page: https://cdm.iamcloud.info/docs/Content/Overview/ThrottleHandling_Caching.htm, but you can change it in Iris under "Bandwidth" on the left-hand side. You can take it as low as 120 seconds, but obviously the lower you go the more likely you are to run into throttling issues.
  18. Not seeing any less info in that screenshot than we've had since Windows 8, just the addition of the driver that crashed that was added to Windows 10 a few years ago. As long as you don't turn off memory dumps, WinDbg's !analyse option should still work to identify the faulty driver.
  19. AFAIK, at least with InVentry, the touchscreen PC is considered your property, and is part of the upfront payment for the initial install. They come with a warranty for a few years, but after that you're paying for any replacements yourself. N.B. if you're on the V4 hardware, that came with Windows 10 LTSB 2015, you'll need to ask for a backup as part of a recovery process (free in your support contract, just need to post them a USB stick to put the LTSC 2021 image on, and agree a date to backup the database, followed by you installing their image, then they will take over the rest remotely via TeamViewer) if you want to keep getting Windows updates after October.
  20. OneDrive's sync client has what it calls "Files On Demand", where by default it just creates dummy files, and it doesn't download them until you first go to open them, then it stays offline until disk space is low or you manually free up space.
  21. For PCs/laptops etc., if you don't mind not getting the best deal and clearing cupboard space is more important, then CeX will usually take them (they don't have a maximum limit of how many devices you can sell to them, but you would be branded a bulk-sell customer and they will give themselves a bulk discount compared to what's published on their website). However, in that case, like with selling online on eBay/Amazon, etc., you are responsible for ensuring they are securely wiped under GDPR unlike a recycler who would give you a data destruction certificate.
  22. Check in the Windows settings -> Accounts -> Access work or school and remove your account there to stop the SSO. If you've attached your Entra ID account there, then it will keep you logged in to all Microsoft websites in Edge, in Chrome with the Microsoft Single Sign On extension, and in all Office apps. When signing in to a modern Microsoft program with your MSA or Entra ID, you will be prompted to sign in to "All apps" or "This app only" - clicking the former will configure the account in the Windows settings to keep you signed in across Edge, Office, etc. similar to if the PC was Entra-joined. You should be able to see all the PCs that people have attached in this way in the 365 Admin Centre -> Identity -> Devices, and they will show as "Entra registered" rather than "Entra joined".
  23. Don't know about you, but I was getting regular status updates via email every month or two during the migration process (including when the whole thing went down for all users), although the notification of accounts that haven't migrated 2FA from Meritec to Auth0 (and have just been clicking "Skip 2FA" as they don't need the elevated access most of the time) was sent the day before, but written as if it wouldn't be happening for a few days yet, but was sent to all users who hadn't migrated as well.
  24. I've seen this happen a couple of times. Often, it's because the user has logged in before a connection to AD has been made, and so is using the cached credentials (like you'd use when taking a laptop off-site) rather than checking with AD, or the off chance that someone has figured out that if your password has expired, you can enable airplane mode to disconnect form AD and still log in with your old password. Locking the PC and getting the user to unlock usually brings up the password expiry prompt.
  25. Just two of us here, one IT Manager and me, the technician. We used to have an MSP handling most things and the technician handled day-to-day repairs & password resets, but as the school grew and we now have 2 IT staff on-site, we went to a lower plan with them, initially just visiting once a month by the time I joined, then later we went to their lowest plan that is 20 hours a year, remote support only, and we use them as a 2nd-line support for issues we can't resolve with our own knowledge, or for things we don't do frequently to avoid risks of messing things up given we only have one physical server, no test environment.
×
×
  • Create New...