jadzea
Members-
Posts
38 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by jadzea
-
Intune app config - Smoothwall browser iPad
jadzea replied to steveg's topic in Mobile Devices & Tablets
Hi Tom, we don’t have the issue now with one to one assigned devices. could I feedback though, that while we do have the iPad platform web filter extension installed for apps other than the smoothwall web browser, it would be soooo much better if this extension did the proper filtering thus negating the need for the smoothwall browser…. Like lightspeed can do. -
Intune app config - Smoothwall browser iPad
jadzea replied to steveg's topic in Mobile Devices & Tablets
yes that’s correct. we have used shared iPads in areas before we went full one to one. We federated our AppleIDs with Office365 so it worked very well (same email and password they’re used to). not sure how a shared iPad would fair as effectively the payload is generated on intune and pushed to the device with all the information configured (ie their username rather than the wildcard) and it picks this up from the primary user field for the device in intune. Perhaps in shared iPad mode that primary user changes? I guess issue is sync frequency then, as I tune I think is every 6 hours..! -
Intune app config - Smoothwall browser iPad
jadzea replied to steveg's topic in Mobile Devices & Tablets
Thanks for this - very helpful. We've gone back to the start somewhat to the enrolment profile and switched to enrolling with user affinity (these are 1 to 1 devices assigned to the individual students) so during enrolment they authenticate as themselves (the student, or we do it on their behalf using their credentials) and then use dynamic security group based on enrolment profile used to then assign settings and apps. We've started to use the Microsoft authenticator app and are working on the SSO for this. We get company portal installed, but just hide this as not sure we really need it. We've found though, without even setting up the Microsoft Authenticator app (need for the SSO extensions) Smoothwall now works correctly as the primary user for the device is now set in inTune and thusly pushed to the device. I think I just made the mistake/assumption that it read the userprinciaplname variable from the device somehow, when in actual fact the app config is pushed onto the device from InTune with this value configured. We also didn't use the XML, and just set the values using the configuration designer (as shown on the screenshot attached). Smoothwall Browser works with it straight away and to be fair quite nicely. Next bit we need to sort is the general filter extension for the device so in-app browsers have some level of filtering to them too (disappointing that it isn't the same user level filtering, but at least it's something). -
Intune app config - Smoothwall browser iPad
jadzea replied to steveg's topic in Mobile Devices & Tablets
We’ve got the same issue - did you find a resolution to this? -
Ok, so we no longer use SIMS and haven't done for sometime. We now need to get into it to recover some old data however everyone that had a login to the particular SIMS instance has left..! Does anyone know how to reset the SYSMAN password so we can gain access? We know the SA password and can view the SQL database using SQL studio and logging in using the SA password. Help!! Thanks!
-
Don't suppose you could share your script could you? Thanks!
- 12 replies
-
- group policy
- pip
-
(and 1 more)
Tagged with:
-
That’s fantastic - thank you! I completely agree with your comments on time servers - I’ve experienced hyper-v time drift before where virtual machines are supplying the time to the hosts and start to drift further and further. Appreciate your help with this
-
Brilliant - thanks for your reply and guidance. Do you know of any articles where I could read more about this? Keen to learn more about this topic. Thanks again for your advice - I’ll certainly implement two now.
-
Just built a new Server 2022 2 node failover cluster with S2D and thinking about what’s the recommendation when creating a virtual disk on the storage pool to be used as cluster shared volume. Question is, create one virtual disk for the CSV that is maximum space available in the pool, or create several smaller ones to store each virtual machines resources and VHDXs? Coming to this from a dedicated SAN where we would have had volumes related to the LUNs on the SAN (ie faster disks as a LUN and slower disks as a LUN), so wondering what’s the best practice with this? I’m tempted just to create one single virtual disk that occupies the whole storage pool and is set for CSV and then store all our VMs in this, but wondered if this is the optimal use of the disks in S2D? Ie is there some sort of overhead that uses more space with multiple virtual disks as CSV, or is there a speed or other benefit? Any thoughts anyone??
-
You might want to look at Lightspeed for MDM and filtering.
-
I’m also assuming you’ve added them to nebula? We find using the iPhone app and scanning the QR code on the AP the quickest way of doing this.
- 5 replies
-
- networking
- nwa210ax
-
(and 1 more)
Tagged with:
-
We’ve experienced this with Zyxel APs and it’s almost every time the network time server it’s trying to reach. You can probably test this theory by whitelisting the IP address of the AP to give it a totally unfiltered route out and see if this works.
- 5 replies
-
- networking
- nwa210ax
-
(and 1 more)
Tagged with:
-
Hi, We're looking at some Chromebooks and also their performance on our wifi network - narrowed down to these two models, however I can't find out if either of them support 802.11R 802.11K 802.11V - we've found that devices that do have a much better time roaming from AP to AP etc as one might expect. It looks like the Intel Celeron versions of these Chromebooks do (think they have a REALTEK card) but I can't find any information regarding the 11A G8EE model or the 11MK G9EE model. Hoping someone out here might have come across this! Thanks,
-
Could anyone share a link to an announcement from Microsoft about this please? I can’t find where Microsoft have said they are forcing all users to have MFA enabled. Thanks
-
Have to remove hikvision from network - any alternatives?
jadzea replied to pooley's topic in Physical Security
We use Unifi cameras - decent quality and easy for staff to use via the web interface for the Unifi NVR. -
Xibo Embed Sky News not working on player
jadzea replied to mdrabble's topic in How do you do....it?
I think they removed the ability to embed as it has something to do with YouTube ads not appearing. I’ve been looking for another news stream to embed - anyone got any bright ideas? Is there a website that shows BBC news? IPlayer won’t work with Xibo I think? -
Chromebook Sign in Page and Smoothwall
jadzea replied to jadzea's topic in Internet Related/Filtering/Firewall
Ah ok so this might make a whole lot of sense about not being able to exclude a URL from HTTPS Inspection, just the domain, so even something like http://www.google.com/acs/ wouldn't be excluded unless the actual domain Google was... -
Chromebook Sign in Page and Smoothwall
jadzea replied to jadzea's topic in Internet Related/Filtering/Firewall
Thanks Tom, appreciate your help with this - so to clarify, At the login screen on the chromebook the chromebook doesn’t have our Google network policy so it won’t have our HTTPS Inspection CA Certificate, which is of course needed to HTTPS inspection. Once we're signed in this is installed and so inspection to google services works correctly? If we use a “raw” google account (i.e. one that has been setup in our google apps domain to not use the AzureAD SAML Sign in) to sign in things work correctly so I really do believe this is related to the ACS URL that is used - is it possible to get detailed requests from the chromebook via smoothwall to see exactly what URL is being called or causing the issue? Thanks -
Chromebook Sign in Page and Smoothwall
jadzea replied to jadzea's topic in Internet Related/Filtering/Firewall
Ok so to give a bit more context… We use Office365 to provide authentication for Google Apps using SAML - it works well on PCs, iPads and other web browsers. The issue is specifically related to when signing into Chromebooks and Smoothwall’s HTTPS Intercept is involved. If we join the Chromebook to a network where we’ve disabled SSL intercept the sign in works fine, but when we don’t the Office365 sign in performs as expected but it then pop up momentarily with the wifi network chooser on the Chromebook, and then rolls back to the login prompt. We’ve even joined the Chromebook to a RADIUS network that uses smoothwall RADIUS accounting so that we know the device is effectively being treated as a user who can access google services etc without issue, but the issue persists. I’ll try and raise with smoothwall again, but does anyone know if it’s possible to get a more detailed log from smoothwall to show all the urls going through it from a device - the IP audit trail doesn’t seem to show an issue… Thanks. And sorry, yes I’ve got Connect for Chromebook set for DO NOT FILTER for everyone as a web policy and also DO NOT INSPECT IN HTTPS policies. Thanks for the suggestion. -
Hi, Having a few issues getting a policy setup for some Chromebooks going through Smoothwall transparently. It seems there are a number of URLs that Chromebooks need access to and the biggest sticking point I've got is google.com To get them to sign in for some reason I see to have to set google.com to DO NOT INSPECT for unauthenticated users, which has the result of anyone being able to search for stuff without it being logged. Does anyone have any advice or sample policies and categories they've created to get Chromebooks signing in without messing about? I think I've been round and round with this so many times now I'm missing the obvious..! Thanks in advance,
-
I'm trying now as a parent and it's not doing it. Anybody had experience of the biometric login?
-
Hi, Does anyone know if the Arbor app should keep parents signed in? We've been doing some checks recently and it seems every time a parent comes to use it they need to sign in with their password - surely this isn't right??
-
[ms office - o365] Random issues with Shared Computer Activation!
jadzea replied to kennysarmy's topic in Office Software
Have you tried removing any AB TUTOR logging policies on the computers that have the issue? As soon as we did this it resolved the problem. It seems that AB tutor introduces a let’s say hidden proxy for the purposes of being able to log websites visited etc into the AB tutor log. Removing the policy (or at the very least removing the option in the an tutor monitoring policy for logging websites visited) solved the problem for users who logged on - we had to delete the local profiles for anyone who had been on previously. We use smoothwall too, but in transparent mode so we don’t have any proxy settings set at all - I wonder if it is fundamentally an issue with office365 activation going through a proxy full stop? -
[ms office - o365] Random issues with Shared Computer Activation!
jadzea replied to kennysarmy's topic in Office Software
Ok so I finally got to the bottom of this! We use AB TUTOR and we’d deployed a logging policy on some machines that was set to monitor websites visited. This meant AB TUTOR set up a local proxy service that it routed traffic through to log what was being visited but stopped activation working. As soon as it was removed things started working again!
