Jump to content

colly72

Members
  • Posts

    429
  • Joined

Everything posted by colly72

  1. No issues here - we have a/v and Intercept X on our SIMS server, with all recommended settings turned on.
  2. Here's the key part for me: I'd consider any 1:1 device to be a school device, so I'd say it's pretty clear that they should have some form of monitoring/filtering protection wherever they are being used.
  3. I'd agree that it's not specific or overly prescriptive but I take it to mean that the School should assess the risk when it comes to filtering and monitoring and take appropriate steps to protect children. My take on that is that the School has a responsibility to protect its students on any School device, wherever it is being used. It comes down to individual risk assessments for each School/circumstance.
  4. We use Senso here. It was an essential requirement for our 1:1 rollout that we could monitor in and out of school. You might want to refer to the DfE standards (https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/filtering-and-monitoring-standards-for-schools-and-colleges) for monitoring and filtering, when making a decision about mitigating any risk.
  5. Zoho ManageEngine also have an MDM, which you might want to consider. I can send you a link for 10 devices for free if you want to send me a private message.
  6. Moysle do a free version but it's missing some features. See the link in my earlier post for comparison of free vs paid.
  7. I'd look at a 3rd party MDM like Moysle (https://school.mosyle.com/pricing/) or Jamf (https://www.jamf.com/pricing/education-pricing/), rather than trying to use another Mac. I used Profile Manager years ago, which was part of Mac Server, but it's pretty much a legacy product now, as Apple have looked to kick Server into the long grass.
  8. We've started receiving MS email quarantine release requests, that have clearly not been requested by the user. Indeed, some of the user accounts that they originate from, are disabled. It started around a week ago and they seem to come in bursts. I'm reasonably confident that the accounts are not compromised but I'm at a loss to see what might be causing it. Has anyone else had this? I've seen a recent thread on Reddit from someone else who has the exact same problem:
  9. It's a while since I've used it but Wordpress multisite might be a good option, in terms of a HoD having oversight of all student websites.
  10. What sort of website is it (e.g. Wordpress etc). Perhaps there is some sort of caching plugin installed which might affect things. Try clearing that, if so.
  11. Thanks for this, it sounds like this is the best way forwards. The more I'm reading up on a PAW solution, the more complicated it gets. As a school we have limited budget and resources, so it's interesting to see how much others invested in a PAW solution and what is a reasonable solution that provides us with appropriate security, without over-complicating our system. Any input on how others have implemented this and how far into it they have got would be greatly received.
  12. Adding a non domain admin account to the local administrator group doesn't allow running things like ADUC, Hyper-V Manager, DNS, DHCP etc, with admin privileges as far as I can tell, which is what I am looking for.
  13. Good idea but that's hugely painful, assuming you can get in to ADUC in the first place to obtain the password (without being asked for elevated permissions), then requires writing down the password and manually typing it in (pasting the password is not allowed).
  14. Scrap that, my elevated admin account is in the local administrator group (its a domain admin) but as soon as I deny access to logging on locally, I can't use it as an elevated account
  15. Yeah, we have separate elevation accounts already but denying them the log on locally right on PCs stops them from being used when runas administrator is attempted. I guess I'm missing the bit that requires us to add them as a local admin.....
  16. As part of our security review, I'm trying to get to where our domain admin accounts are blocked to Log On Locally but can still be used for elevation/runas admin. Is there a way to achieve this in Group Policy or should I be looking to secure by using a different method?
  17. Its like the mass transit system for Leeds.........
  18. We use Sophos Firewall VPN here, with MFA. Works pretty flawlessly for those who want to use it.
  19. Yeah, it's not difficult but perhaps a bit time consuming, especially if you have a lot of faces to blur. From memory, this is the video that I watched to learn how to do it:
  20. Last time we ordered (just before Christmas), you could still get 300e Gen 3 Chromebooks but I believe that Lenovo are moving to Gen 4. Try https://www.getech.co.uk/schools/ to see what they can offer you.
  21. Adobe Premiere Pro can do this. Pretty easy but do it on a fast PC!
  22. Education Fundamentals (https://edu.google.com/workspace-for-education/editions/education-fundamentals/)
  23. Free on Education Standard, which isn't free. I take your overall point though, which is that Google also has its own conditional access feature, albeit in a paid subscription.
  24. That's how I see it. Conditional access is a must for us, so Azure SSO was the obvious way to go. We use the Schools IP as the 2nd factor when Senior School students are connected to the school network but require them to use the Authenticator app on their mobile device when at home.
  25. This might work with Google login but it doesn't when using Azure SSO.
×
×
  • Create New...