Frazer
Members-
Posts
149 -
Joined
-
Last visited
-
I have just been through this process, however we are using Microsoft's InTune as the MDM rather than Google's MDM - the process should be adaptable for Google's MDM. You will probably want to go through the "zero touch" solution as this gives you a fairly automated setup from factory reset and a fully managed device. Similar to Apple's school manager solution. 1. Zero Touch Setup If this is your first purchase/registration, ask your reseller to create a Android zero-touch account and add the recently purchases devices to this account - this is a free service that lets you allocate the devices to your chosen paid MDM. You can use a personalised (non-shared) G Suite/Workspace accounts to manage this portal in the future, however they must have the 'Partner Dash' service enabled for their OU or security group in the Google admin portal. https://partner.android.com/zerotouch - only available for you to access after the reseller as created your account. 2. Zero Touch Deployment Part of the InTune setup documentation takes you through creating a new zero touch configuration profile (on the zero touch portal) depending on the type of device you will use and which MDM you want to assign them to. You then assign this configuration profile to each device - corporate owned shared use, corporate owned single user, personal owned with corporate apps etc. 3. App management For InTune MDM to manage apps from Google Play Work you have to create a user that is not attached to Google Workspace. Some MDM's are able to bypass this restriction using service accounts, Google's own MDM may integrate better. We use Office 365 for email and have @school.county.sch.uk and @school.onmicrosoft.com available for email addresses. @school.county.sch.uk is used with Workspace, so we created a [email protected] shared mailbox and added it to our mailboxes. At the InTune Android enrollment page, I clicked the link to connect to Google Play Work store and as part of the connection process, created a new Google account using the shared mailbox email address. This becomes the account that will approve free apps in the Google Play Work store and also be used to synchronise those free apps into InTune. Currently, Paid apps need to be obtained from the developer and uploaded as a custom app.
-
What steps did you have to take to migrate from OVS with KMS to A3 activation? Presumably you have to remove the KMS key from AD/KMS? Does Windows 10 remain on KMS activation until the existing 180 days expires and then switches to user based cloud license? Are you still able to deploy your OS via MDT/SCCM/FOG/Other? Or do you make use of the original OEM Windows installation? Does the Volume Licence Service Centre still provide you with a KMS key when you are licensed with M365 A3? If so, why not use that to avoid the activation changing per user?
-
I'm having difficulty getting concrete answers (shocker!) regarding the switch from OVS to EES + M365 A3. We currently licence via OVS (desktop core bundle + office) and deploy as follows: 1. Receive OEM device with windows 10 home/pro/academic pro including OEM's installation of Windows 10 + their apps. 2. Wipe the device using MS SCCM and deploy our own Windows 10 Education image (using the ISO from volume licence deployment center) and our applications. 3. Activation is handled by Active Directory or KMS (not reliant on cloud licences) and both Windows and Office remain activated no matter what user logs in. 4. Office is currently a mix of 2016 and 2019, this also stays activated no matter what user logs in. 5. The device is set up by us, ready to use, _before_ handing over to any users. With EES M365 A3 we can be allocated Office 365 Device licences, which gets around any issues with user based licence tokens or exam accounts (who aren't licenced in the cloud) and other such users. Can we deploy Windows 10 with M365 A3 using the same method above? From what I've read, they assume you retain the OEM installation of Windows with their original home/pro/academic pro licence and the first Azure AD user to log in assigns a Windows 10 Education licence to the device against their username, this then triggers an upgrade to Education - not helpful in a heavily shared environment who require the device be ready at deployment, not wait for an additional set up process to complete. What happens to the device's Windows 10 Education licence when that user has logged into 5 or 10 different PCs? What happens when they log out? At the point of deployment, surely Windows 10 needs to be running Education to receive various computer based polices/features before the user logs in and not after?
-
We recently started looking into YouTube with G Suite. One of the minor irritations was the lack of youtube.google.com/a/domain/ URL for SSO. I have discovered this URL which appears to work for us (ADFS 5.0/2019)- replace the domain after /a/ with your school federated domain https://www.google.com/a/your.domain.sch.uk/ServiceLogin?service=wise&passive=1209600&continue=https://www.youtube.com&followup=https://www.youtube.com/&faa=1 Hope that helps EDIT: how do you deal with students making use of 'create channel' 'go live' 'upload video' etc? Do you encourage? block at the firewall?
-
The change to Capita support wasn't something I was heavily involved in - it was done prior to our 'leaving One Connect' project so I couldn't comment on the price. Best thing to do is contact them and get a quote. Dont forget to twist their arm :-)
-
Moving away. We have already done the following: SIMS - direct to Capita Moodle - on-site now Email - Office 365 (free) Remote desktop - Microsoft Remote Desktop Gateway (included in existing licencing/hardware) Left to do: Website - on-site (relatively quick, just need to re-sync the copy I have on-site and change the external DNS) Antivirus - Waiting for quotes (also a quick one, probably staying with sophos, will require a change on our server to get the updates directly from sophos, but everything else should continue to work as normal) Broadband & Filtering - Last thing to move, waiting for quotes. The final decision to cancel/move will go to governors next month. After that its down to installation dates from the new broadband supplier - Dates will overlap with One Connect so that we get ~1 month change over period.
-
Times should be 11am - 1pm (email received today from One Connnect with correct times)
-
Looks like they are changing their filtering system. Although its probably too late for us (too many nails in the coffin) I hope they have looked into providing a self-managed connection if needed by schools (real ip, setting your own firewall rules). Perhaps we will find out. Title: ICT Network Managers and Technicians Meeting Description: At the School's ICT Focus group it was agreed that regular meetings between School ICT Network Managers and One Connect Limited should be scheduled. The first of these was on 22 May 2013 and covered a wide range of topics. The second will be on the 25 November at 11am and will be focused on the new products from Lightspeed that will form part of your Connect2Education bundle next year. This session will be delivered as a webinar that you can log on to from school. Topics covered will include: • Lightspeed Filtering • Mobile Device Manager • My Big Campus Virtual Learning Environment Conferencing details and a finalised agenda will be provided closer to the date. If you work in an ICT role in a supported school and would like to participate in this meeting please visit https://schoolsportal.lancsngfl.ac.uk/delegate/index.asp to reserve a place.
-
For Windows Server and Client OS activation, you only register ONE KMS key with your KMS host, the highest level OS you are licenced for. Example, if you have licences for Windows 7, Windows 8, Windows 8.1, Server 2008 R2 and Server 2013 R2: 1. Login to the MS Volume Licence Service Centre: https://www.microsoft.com/Licensing/servicecenter/default.aspx 2.a Get your highest level OS KMS Key - in this example, it would be 2012 R2 2.b If you didnt have any Server OS KMS keys, you would register your highest level Client OS (Windows 8.1 for example) 3.a Install the following update if your KMS server is not 2012 R2 - Update adds support for Windows 8.1 and Windows Server 2012 R2 clients to Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 KMS hosts 3.b Register your 2012 R2 key (from Microsoft licencing) with your KMS server - Installing KMS Hosts 4. When installing Windows 7 / 8 / 8.1 / 2008 / 2012 to be activated, use the following KMS keys during their installation procedure: Appendix A: KMS Client Setup Keys (Server OS's and Enterprise client OS's should have these keys embedded by default. You can use this page to input them again if youre unsure) Server OS's (2003/2008/2012) wont activate until the KMS server has 5 requests Client OS's (7 / 8 / 8.1) - 25 requests Office - 10 requests Be aware that if you setup two KMS servers for redundancy, each server will require the minimum requests before they will start activating. Office 2010 and 2013 require separate KMS keys to be added to your server, you also need to install ONE key per version (1 for 2010 1 for 2013) There are also separate installation files to support Office activation. In total you would end up with 3 keys registered with your KMS server (your highest level OS that you have a KMS key for, office 2010, office 2013) If your installation image isnt rearmed via sysprep then you will get problems with your activation count not going up. They need to be rearmed to generate their own unique ID - this is used when requesting activation, when the same ID is used for each PC, the KMS server will only see one request (from the same ID multiple times).
-
Update: Transferred the following from LancsNGFL to our server on site 1. Moodle data (200GB tar file) 2. SQL database 3. School Themes Extract the Moodle data to the relevant directory (as specified in config.php). Import the SQL database to a new database (dont overwrite the default moodle one as it causes problems) - http://docs.moodle.org/19/en/Site_restore Remove the entry in 'alternativeloginurl' from the imported SQL database, under the 'config' table Make sure the all the relevant entries in config.php are set correctly. Passwordsaltmain should be sent to you as part of your export. Table prefix needs blanking as the SQL database I got didnt have mdl_ prefixed on all of them as per default install. If your site is behind MS TMG, you may need to look at this for a quiz related problem: https://tracker.moodle.org/browse/MDL-11061 Extracted the themes and copied them to your /www/moodle/themes/ directory Check Moodle > Server > Environment for dependencies Check Moodle > Server > System Paths for dependencies / file locations You may need to convert the database to UTF-8, Converting your MySQL database to UTF8 - MoodleDocs Next on the list is how to back it up efficiently.
-
Yeah sorry it came back up sunday afternoon I think. Still cant tracert to the primary DNS server but it is working. H:\>tracert 212.219.82.4 Tracing route to ns0.lancsngfl.ac.uk [212.219.82.4] over a maximum of 30 hops: 1 <1 ms <1 ms <1 ms 10.74.20.1 2 1 ms 1 ms 1 ms 10.81.233.129 3 2 ms 2 ms 2 ms 10.78.192.138 4 2 ms 2 ms 2 ms 10.78.192.137 5 * * * Request timed out. 6 * * * Request timed out. 7 * * * Request timed out. 8 * * ^C H:\> H:\>tracert 212.219.83.4 Tracing route to mail.lancsngfl.ac.uk [212.219.83.4] over a maximum of 30 hops: 1 <1 ms <1 ms <1 ms 10.74.20.1 2 1 ms 1 ms 1 ms 10.81.233.129 3 2 ms 3 ms 3 ms 10.78.192.138 4 2 ms 2 ms 2 ms 10.78.192.137 5 2 ms 2 ms 2 ms mail.lancsngfl.ac.uk [212.219.83.4] Trace complete. H:\> H:\>nslookup Default Server: hadc01.hhdomain.local Address: 192.168.0.1 > server 212.219.82.4 Default Server: ns0.lancsngfl.ac.uk Address: 212.219.82.4 > www.google.com Server: ns0.lancsngfl.ac.uk Address: 212.219.82.4 Name: www.google.com Address: 216.239.32.20 > server 212.219.83.4 Default Server: mail.lancsngfl.ac.uk Address: 212.219.83.4 > www.bbc.co.uk Server: mail.lancsngfl.ac.uk Address: 212.219.83.4 Non-authoritative answer: Name: www.bbc.net.uk Addresses: 212.58.246.94, 212.58.246.95 Aliases: www.bbc.co.uk
-
Looks like DNS is down again for us. Z:\>tracert -d 212.219.82.4 Tracing route to 212.219.82.4 over a maximum of 30 hops 1 <1 ms <1 ms <1 ms 10.74.20.1 2 1 ms 1 ms 1 ms 10.81.233.129 3 2 ms 2 ms 3 ms 10.78.192.138 4 2 ms 2 ms 2 ms 10.78.192.137 5 * * * Request timed out. 6 * * * Request timed out. Hopefully someone from OCL will see this today and get it resolved.
-
a. Yes - make sure this is the very last thing you do. b. I imagine DNS management is tied in with the broadband contract so yes. You can get this hosted for free with CS New Media if you have a sch.uk domain. Carl, who runs it, posts on here from time to time. c. Email is tied in with the broadband contact, you need to migrate your email from OCL to Office 365/Google apps/other before cancelling. Once you're happy with the migration of your inboxes, you change the MX record to make sure new mail is delivered to the mail host. d. Once the MX record is changed, the email doesnt get delivered to county any more. Once your email is moved to your new provider, make sure the OCL mail team are aware of this - they need to make changes to allow other schools who use their mail service to be delivered to your new mail host. Otherwise stuff gets delivered to the old mailboxes or doesnt get delivered at all. Other things to keep in mind: Internet filtering Sophos licence School website Moodle Mahara These are all part of the same package. Dont forget to get appropriate replacements. Hope that helps!
-
Just for those following this thread: I've managed to get 1.9.18 working with the CLEO import tool. I've tested this with the reports from SIMS.net (classes + users) and uploaded them to the test site. Users and groups appear as they should. 1.9.18 from here Index of /stable19 CLEO MIS Tool from here: https://git.luns.net.uk/cleo_mis_tool.git/ (download the latest snapshot, I used 2009-02-03) 1. Install Moodle as per documentation 2. Extract CLEO MIS tool. 3. Rename the 'en_uf8' directory under \cleo_mis_tool\local\lang\ to 'en_utf8_local' 4. Move the 'lang' directory from \cleo_mis_tool\local\ to your Moodle directory 5. Move the 'local' directory from \cleo_mis_tool\ to your Moodle directory 6. Install the three CLEO patches as per documentation from the README.txt 7. Visit the Moodle admin page, example http://www.school.com/moodle/admin You should now have MIS Uploads under the Users section in Moodle. I've yet to test this with our Moodle data from One Connect, hopefully we will get this next week.

