Jump to content

steve_forbes

Members
  • Posts

    89
  • Joined

  • Last visited

Everything posted by steve_forbes

  1. Hi everyone, Does anyone here work in a school within one of these areas? Or does anyone know if there is a large IT provider/Local Authority service in these areas that cover a lot of schools? Thanks Steve
  2. Apologies I've just seen the updates on this post - if I can be of any help (as a Nominet employee) then please do let me know and I'll be happy to try and sort it - although sounds more like a Microsoft issue from the mail perspective?
  3. Thank you - that's useful as I think that constitutes a pretty big security risk!
  4. Hi all, I'm doing some more research for the National Cyber Security Centre on secure cloud configurations with a focus on Google Workspace for Education and Office 365. I'm hoping the collective mind within Edugeek can help validate my statements below: The majority of schools now have one or both of these services but they may have been configured some time ago and not necessarily by an expert, therefore they may be insecure There are still cases where brand new cloud tenancies are created for migrations etc Even if setting up a new tenant today, the default configurations are not sufficient to ensure the school's data is secure Does anyone have any thoughts on the above statements, any additional information would be very useful. If there is a proven need then I am hoping to get some NCSC and Microsoft/Google approved configuration guidelines that include options for additional security if licences have been purchased. If there are areas that could be improved by changing default settings then we can also lobby the cloud provider to do so. Thanks Steve
  5. Hi, let me ask my colleagues here at Nominet and find out if there were any restrictions.
  6. Hi, Steve Forbes (RM) here, self-service firewall is currently in development for RM Broadband customers so you won't need to request changes - you will be able to make changes yourself using the same portal as RM SafetyNet. As you are an existing RM Broadband and RM Unify customer it might be worth just trying it out to see if it meets your needs - it won't cost you anything extra and could save a fair bit of money on replacing hardware. I won't get into the whole cloud vs local thing, ultimately it needs to be what is best for your school. Thanks Steve
  7. Hi there, I'm the Product Manager for RM SafetyNet (and RM Buzz). Thanks for your feedback, I'm going to investigate and will come back to you on the issues you raise here. If you have any specific support call numbers that might help then please let me know. Also really interested in my other feedback you have in general about either products.
  8. Yup, they've openly said that both G Suite and Apple have the same issues. Therefore leaving schools with little choice on OS or cloud suites!
  9. Hi, Steve Forbes here and I'm the Product Manager for SafetyNet. Apologies I'm late to the thread. As @Boredguy said, if you log a support call they can arrange for you to get the AD sync agent and enable User Based Filtering as long as your contract includes it. Transparent User Based filtering is now available to SWGfL customers and many others, again a support call can get this enabled for you - it will soon be self-enabled through the admin console. Lastly, we haven't just updated our support pages so if you login to the admin console and go to the support pages you will see all new articles to help you with the new features. There is also a home page where we are announcing new features etc. Hopefully that will mean no-one feels any new features are hidden from them again! Let me know if you have any questions or feedback.
  10. RM SafetyNet is now available to anyone, regardless of who provides the line, just in case you weren't aware of that.
  11. Hi, Here's the full list of proxys available on SWGfL: Default Proxy These proxy addresses provide filtering based on the schools default policy sslfilter.proxy.swgfl.org.uk:8080 - recommended standard proxy with ssl filtering proxy.swgfl.org.uk:8080 - standard proxy without ssl filtering proxy.[school domain name]:8080 - This is typically a CNAME which points to the standard proxy.swgfl.org.uk. These are no longer created but can continue to be used if SSL filtering is not required. User Based Proxy These proxy addresses provide customisable user based filtering based on active directory authentication sslfilter.userproxy.swgfl.org.uk:8080 - recommended user proxy with ssl filtering nosslfilter.userproxy.swgfl.org.uk:8080 - user proxy without ssl filtering Clearly you need to subscribe to User Based Filtering to be able to use this functionality. Coming soon: Over the next month we will be enabling new functionality to provide more flexible filtering for schools who cannot use user based filtering Custom Proxy Addresses These provide schools with the ability to provide differentiated filtering to different sets of devices using different proxy addresses sslfilter.policy1.proxy.swgfl.org.uk:8080 sslfilter.policy2.proxy.swgfl.org.uk:8080 sslfilter.policy3.proxy.swgfl.org.uk:8080 sslfilter.policy4.proxy.swgfl.org.uk:8080 "nosslfilter" versions of the above will also be available which use the same policy without ssl filtering IP Based Filtering Custom policies for specific IP addresses/ranges on your network, these will take precedence over the default policy when using the default proxy address. Legacy SWGfL Proxy Addresses These are historical proxy types whose functionality has been or is in the process of being replaced by the addresses listed above. These should no longer be required. Other proxies staffproxy.swgfl.org.uk is a legacy proxy type that allows unfiltered access for authenticated users. Users of this should consider using Safetynet User Based Filtering which allows AD authentication and custom policies to be configured for different users or user groups. updateproxy.swgfl.org.uk - Provides the same functionality as the standard proxy and will shortly be repointed to proxy.swgfl.org.uk smartcache.proxy.swgfl.org.uk / smoothwall.proxy.swgfl.org.uk - Upstream proxy for onsite filtering devices providing IWF and extremist filtering only. These will shortly be repointed to nosslfilter.policy4.proxy.swgfl.org.uk which will be preconfigured with a policy that mirrors this behaviour. unfiltered.proxy.swgfl.org.uk - IWF and extremist filtering only. This has to be enabled within the safetynet UI. This functionality will soon be removed. Users wishing to have access to proxy with a minimal filtering proxy will be able to use the new custom proxies to achieve this. A list of these proxies can also be found within the Safetynet administration interface. Hope that helps, Steve
  12. Thanks Nick, I will follow up and see what we can do.
  13. Hi, I'm the Product Manager for that product, have you raised a service call for the issue? Happy to get this looked at for you if I can get a few more details. Thanks Steve
  14. Just to jump in here (Product Manager at RM). We are currently developing self service firewall as well so changes can be made by the school instantly.
  15. Would love to hear your feedback on UBF, we are currently doing some work to make this easier to deploy so any additional feedback would really help. Thanks Steve (Product Manager)
  16. Clearly not the issue here but the issue involving users moving between devices that have different versions of Windows 10 is a known issue for all networks, not just RM networks.
  17. Hi there, Steve Forbes from RM here - glad to hear that things are performing well other than the issues you have described. It sounds like you may have an issue with the AD sync agent so it's probably worth you logging a support call for that so we can investigate further. The second one is a strange one, what kind of error do you get? Again, if you log a support call I will make sure both get looked at promptly. Edge is supported - I will get the article updated with this and SSL interception works with all the major search engines, not just Google so I will get that updated as well.
  18. Hi, I'm the product manager for Online Safety and Security at RM, just let me know what you need and happy to sort out a pro-rata contract for you or something that will meet your needs for that period of time. Also really interested in your feedback as to why it's naff :-)
  19. You could use Azure Information Protection to label documents based on their sensitivity and then use the DLP rules in Office 365 to block certain types of document from being sent externally or warn the user that they are doing something that they potentially don't want to do. It does have a licence cost though.
  20. As @FN-GM says, this is only for consumer accounts that don't have an Office 365 identity, Microsoft assume that if you have an Office 365 identity then they have enough information about you to verify your age. They are focussing on Yammer as that is seen as social media or "Information Society Service" to use the GDPR terms, where the providers now need to prove that they have an age verification process. I have verified with Microsoft that this is not applicable to Office 365 users.
  21. Hi, Steve Forbes here from RM and I product manage RM Safetynet - any feedback on what needs improving in the product would be most welcome.
  22. I think is quite commonly misunderstood, as @GrumbleDook says, it can't be used to cover the core activities of a Public Authority, but that's not to say it can't be used at all. The ICO have a good example on their website of a University that would be the same for schools: https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/ "There is no absolute ban on public authorities using consent or legitimate interests as their lawful basis, but the GDPR does restrict public authorities’ use of these two bases." Completely agree on the use of public interest for those things discussed, without absolute clarity it is down for each school to decide which lawful basis they are processing data under and as long as there is sound reasoning, it is transparent and fair then it is unlikely anyone is going to object to that processing for those reasons.
  23. Thanks for the feedback, there are a couple of areas that I can feedback on immediately: SSL interception (including Google search term filtering) is available for transparent filtering, this is an opt-in service that can be enabled by calling our service desk. This then needs the certificate to be deployed to all devices browsing transparently. There are a few exceptions around where this can be setup if you receive your SafetyNet filtering through a regional grid partner, in which case it would be worth checking with your grid support contact. We’re also in the process of releasing some improvements to RM SafetyNet which will allow transparent SSL filtering to be configured from within the administration interface based on IP range (for example, allowing transparent SSL filtering only on a specific IP range). This will be rolled out alongside the new support for IP based filtering policies and transparent user based filtering.
  24. You are correct @AlanD that UBF requires RM Unify for identity but we provide a basic version of the platform for this purpose and it is at no extra cost.
  25. Hi there, My name is Steve Forbes and I'm a Product Specialist at RM with responsibility for our Security, compliance and online safety products, it's great to see all your feedback and I will ensure it helps to shape our roadmap. If you have any other feedback, please keep it coming. Many thanks Steve
×
×
  • Create New...