-
Posts
599 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Sephiroth
-
I would advise a repeater for this purpose if your radios are used for any form of critical communication, be it evac comms; safeguarding; medical... We have our radios programmed to use a repeater on 2 channels for day-to-day use for best coverage, with back-to-back channels for "private" comms or building emergency (for example, if the repeater is on fire). As others have said, I wouldn't want to rely on wireless or cellular networks for this level. There's too much complexity where it can go wrong.
-
I'm not sure that there's a general requirement for augmented reality, but we are providing a computer science course that has it as a module. We used to have a DB module that needed Access but I don't believe that's part of our course now. Either that, or they finally don't need support with it!
-
Currently have 7 dailys on site; 4 weeklys on a storage box on another site; 3 monthly and 4 quarterly on a seperate box on the main site; latest daily on a daily rotated USB. We're in the process of migrating to cloud backup where we would have 1 local copy, 1 cloud copy, and 1 obfuscated copy. I've not used an LTO tape since 2012...
-
Correct. 4 Merits for @DalekSec!
-
Funny you should say that... They were the last ones to transition, and even now, 7 years later, are relying on MS Office far more than they should. Unfortunately they were the first department to get teacher desktops, so have window machines rather than chrome desktops. We don't fancy the tantrums that taking Windows away completely will cause. Even though they still use Windows desktops, lessons are still delivered through Google Classroom. There are probably not that many applications keeping them on Windows these days, though art use Photoshop, and music use Cubase and Sibelius, which are the most difficult ones. Now that the requirements for AR in ICT have been relaxed significantly, that is potentially one to look at first.
-
Single LA secondary. Administration and specialist subjects (ICT, DT, Photography, Music, Art) use Windows and MS Office; everyone else is on Google Workspace. Teachers all have chromebooks and all classrooms have chrome desktops. Email is in Google and almost all document storage is Google Drive. Back-end is mostly MS servers with an on-prem AD structure synced to Google for authentication. There are some quirks, but for the most part this setup works well for us. the majority of the issues we have are because Google works in a very different way to traditional administration methods.
-
We use both OUs and groups for different user types. I can confirm that OU searching is recursive as that's our primary use case. Staff and student OUs are selected in PaperCut, but "Staff/Teaching", "Staff/Support", "Students/26Entry", etc are all populated.
-
Personally recommend ICT-Direct. According to their Stock List they have 1000 HP Chromebook 11 G9 EE devices from £115, or below £100, you can get the G8s, which are supported until 2029. If you're happy with 'C' grade, it looks like you can get them for £30 each!
-
Without wanting to sound like an extreme conspiracy theorist, this kind of thing is one of a great many reasons I don't use Windows at home. Application installation security has always been a sore point there, this is just a company being caught using one of Microsoft's flaws for their own gain. It'll be interesting to see if this affects cyber security guidelines gooing forward.
-
Glad its working. Until MS kill off Group Policy in favour of Intune, at least. Can't wait for that one... 😒
-
Eveyone seems to hide the goodies away now. I know that a lot of stands were complaining that the children that were let loose just took handfulls of sweets that seemed to be abundant this year. @Rob_D the little ICT-Direct box is a screen cleaner spray with cloth Most of what I got this year was bags and sweets. The highlights were a Verkada Yeti mug, an ICT-Direct thermal mug, and a beautiful 43 piece precision toolkit. I neglected to get any photos, so if I remember, I'll get some when I get home tonight (of course it didn't get to the office, thats what the paperwork is for!).
-
It should only apply to objects that match the security filter. I assume your security filter on the 'Scope' setting has only the object that you want affected? The screenshots I listed are from a fully functional GPO in my domain, as that's how we primarily do device specific software installation. We used to have the same settings in production for users, but don't any more. What does Group Policy Results show for that GPO against your users, both that you're expecting it to apply to and not?
-
I've put some examples in here. This is from an object applied to computers for software installation depending on group membership, but the premise is the same.
-
The security filter should have the 'Authenticated Users' removed, but that also removes it from the security settings, meaning that Windows won't be able to read the policy to apply it. You need to add 'Authenticated Users' back into the security settings with read permissions for it to apply.
-
I've found myself gravitating to old favourites recently. Project Zombiod - Fantasticly realistic zombie apocalypse survival game that's brutally challenging. Factorio Space Age - Top down, complex factory builder. Dying Light - Zombie apocalypse FPS parkour. 7 Days to Die - Zombie apocolypse FPS survival crafting game. Ostranauts - Rogue-like top down ship breaking/building game. Most of those are multiplayer, but i mostly play alone. Factorio is great with friends, and thats how I started, but mostly I play singleplayer. 7D2D is another one that is great multiplayer and I've run a few servers for a small group of friends, but I've logged nearly 8k hours since ~2018
-
I'm looking at the way we do secure accounts for technicians/domain admins and have started to go full circle driving myself barmy! Would you be willing to share how you manage the security and group policy for techs in your domains so I can see how others do it? For reference we are a secondary with ~2000 users and 2 sites supported by 3 staff. As it stands we have LAPS set up and technicians have 3 accounts: test user; technician; and domain admin. The test user is exactly the same as a staff account. The Domain admin account is a named but standalone account, not restricted by group policy. The technician user is a standard staff account but with a few overrides in group policy; for example, to enable CMD, PowerShell, and MMC and to allow access to the local disk. We still have to escalate to the DA account if something needs administrator access. I suppose my slightly rambly question is: Is this secure/effective/efficient, or is there a better way to do it? Thanks!
-
How are people blocking software/apps in windows 11
Sephiroth replied to User3204's topic in Windows 11
The one that tripped me up when setting up AppLocker is getting the rules generated automatically adds the version currently installed on the device. For example, if I have Chrome version 138.0.7204.97, then it will pick that as the lowest version to allow. If that's the latest version then any machine that isn't bang up-to-date as of implementing the policy will have that application blocked. I got around this by removing the version (asterisk in the file version field, as pictured above) fixed most of the initial issues I was having. -
How frustrating. I was hoping to completely remove Read & Write this year in favor of EWP everywhere. We've been using EWP for the last 2 years on isolated exams laptops, having moved from Word/Wordpad + Read & Write. I would guess that it has come from a market share perspective; There's a competitor that is seeing a hefty chunk of sales, buy the product and slowly (or not-so-slowly in this case) bludgeon it to fit the marketing and costing of existing products.
-
I was at a small town middle school in the late 2000s and remember the death of this scheme. We had 600 students all come in with fistfulls of the wreched things and we'd count them up. We generally got a few keyboards and mice a year to replace dead or broken ones, so it wasn't all bad, but it would probably have been cheaper in staff time to just buy them new. With all the fervor that came with it, I can only assume that it did peak at some point earlier, where it was viable to get a few BBC Micros or something similar.
-
As above have commented, I would recommend looking to automate the installation and activation processes. If there's no SCCM server then MDT / WDS is quick to set up and very powerful for automation, especially if you utilise the database features in MDT. Does the school have a Microsoft 365 tennant? If so, InTune might be something to look at as an alternative to on-prem deployments. I can't recommend starting to look at it if it's not already at least half set up though. I also agree that you should get an MSP involved to assist. I would stress, however, that you ensure they are brought in to help you get things set up, rather than rely on them to sort it out. This will mean that you have the knowledge behind you and a second opinion if necessary, as well as a guiding hand specific to your situation. You may be able to rely on support on forums like this (and we will, of course, help you as much as we can), but sometimes it's impossible unless you get hands on. Does the school have Google Workspace access? If so, Google Chrome OS might be a viable alternative to windows on some hardware. Have you considered refurbished hardware from somewhere like ICT-Direct? This will enable you to get some hardware replaced for a decent price to meet Windows 11 hardware requirements. Windows 10 LTSC is technically not supported outside of specific use cases, so I wouldn't recommend going down that route. Similarly, I can't recommend installing the production OS on unsupported hardware, It's a ticking time-bomb for when Microsoft change something that kills it, either in a patch or update, or as part of it's processes. Another option is to look at desktop virtualisation with something like HiveIO. If you have the server capacity, this could smooth out some of the more problematic areas, buying you time to consider better options later on down the line. A single high power server is cheaper than 300 desktops, especially if you go down the refurb route. I know there's a lot to think about here, but hopefully this give you some options to go through. Welcome to the forums, good luck, and keep us posted!
-
Broadcom VMware cease or desist or be Audited
Sephiroth replied to loxford01's topic in Licensing Questions
Personally I think that Broadcom's policies have made VMWare a very hard sell and would recommend migrating away, especially with the current turbulence and sudden changes that are coming about. We moved to a Hyper-V Hyperconverged cluster 5 years ago which was the best move we've made, going from 3 hosts, a controller, and a SAN to 2 cluster nodes. Windows Server Datacenter is already in our licence so made financial sense. I would strongly recommend looking at Proxmox as an open source alternative though, especially if your Microsoft licencing isn't in your favour for Hyper-V. Out of interest, what is your current physical infrastructure setup? -
A friend was on Manjaro for a bit but stopped. It kind of worked but only in that they had so much stomach upset and pain that they couldn't possibly eat anything. The thing with these injections is that they are great to get you into the habit of smaller portions or less snacking, but if you don't change anything then the weight will just come straight back when you aren't taking it.
-
I've used variations of the same password system for as long as I've been using computers. I get around the complexity requirements by putting numbers and special characters between words. The only time I change mine (outside of nonsensical forced changes) is when they get compromised, which I check for regularly. Our password policy at school is linked to the policies of other systems like Go4Schools, making it easier to tell younger children what the requirements are. I'd love to just set it to length>16 though. Back on topic... Password manager depends on use case. We are a Google school so promote the use of Google's password manager in Chrome, but others exist. We use Zoho Vault in IT Services to share passwords and it's a powerful system with plugins for most modern browsers. The fix is exactly this is you are on a Windows exclusive platform:
-
Group Policy Objects Link Order - this has got me stumped
Sephiroth replied to kennysarmy's topic in Windows
If you can parse the licence key as a variable to MSIEXEC, them you should be able to create a transform for it, which can then be deployed by GPO or SCCM. If that's the only setting in the transform, you should be able to use it for all subsequent versions as well. -
Block specific HTML file (Eaglercraft)
Sephiroth replied to Undertoad's topic in How do you do....it?
We've just had this rear it's head here and I'm struggling to find a way of reliably stopping it without blocking file URLs, which is a last resort. How did you do this? Hopefully I can get this to work in both Edge and Chrome.
