-
Posts
602 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by MicrodigitUK
-
I'm interested by what this Kerberos script is? We don't have fast user switching enabled on our domain. Originally we used NTLM site for Domain PCs but this doesn't work well with Office 2013+ well. So we tried Kerberos but this the broke Java apps that don't support Kerberos. So switched back to NTLM and complained to smoothwall. Last summer they released the Negotiate authentication. Basically a mix of Kerberos and NTLM. That is what we use now on domain PCs. All working well. WiFi for BYOD is using 802.1x Radius authentication. That works well people's devices and tracking them on smoothwall. Apple Macs are using Kerberos authentication on a different port just because PCs where using Just NTLM until recently on our main proxy port. Shared iPads all use SSL page authentication with a 1hour timeout. So basically we are using almost all of the authentication methods on the smoothwall apart from Ident authentication. ident is the one with the little client service that publishes the current logged on user to the proxy, can easily be spoofed in ident protocol so never used it. But know other local schools that use it with other non smoothwall proxy setups.
-
Deploy Microsoft Visual C++ Redistributable via GPO
MicrodigitUK replied to mikkydoos's topic in Windows Server 2012
If you install the exe. This will extract the Msi to the c drive. Then to find it you can look up the product path in the registry bit that populates add remove programs. -
You can use the frog3 API to pull all of the folder structure and file names out of the frog database and rebuild the original file structure. All of the exports or backed up files are named by there database IDs that link back to the real names and file structure in the internal frog3 database. webfiles brick just shows the file name from DB and then links to the file ID to download. The files are only saved in the servers file system as IDs and all names are striped on upload and stored in the frog3 database. api.webfiles api.webfilesfolder Unfortunately for some reason the above webfiles api documentation has been removed from the following page: http://frog3fdp.frogcommunity.com/api think frog don't want people to export their files from their old system for some strange reason. I am willing to help people export the file names and structure but time is ££££
-
http://www.edutech.me.uk/administration/script-bulk-assign-users-to-saas-application-using-graph-api-adal/
-
I use a local company for my cable jobs. I will PM a mobile number for the main man. He should be able to pop over and do you a quote.
-
Yes, you can do it with configurator and some custom mobileconfig XML files. Examples of the new iOS 9 lockdown features as mobileconfig can be found on this site: https://www.groundctl.com/support/kb/1560
- 13 replies
-
- mdm
- mdm solutions
-
(and 3 more)
Tagged with:
-
Umm... Apple Ports all being opened
MicrodigitUK replied to Steve21's topic in South West Grid for Learning (SWGfL)
This is a joke. They should be asking if schools/sites want to opt into this change. What's the point in the SWGfL firewall if they are just going to punch holes in it without consulting the site first. Sorry but another reason to drop RM and the SWGfL at the next renewal. -
Is smoothwall connected to an upstream proxy? If so it will just proxy and pass all http/https tragic onto the upstream proxy regardless of the ip being a local address or not. You can add a list of IP address to bypass the smoothwall proxy and go direct. I can't remember off the top of my head where it is in the menus. But adding the IPs to this list will do exactly what you are looking for. Give me a bell on the phone tomorrow and I'll point you where to set it up.
-
You have 4 options for print release. Username and password (Long time at printer) User Code (faster than username and password but students need to remember there code, plus it is easy to remember others codes) RFID Card/Fob (Faster than above options and can be linked with cashless catering/library card) Biometrics (almost as fast as RFID but can slow down with sticky student fingers, but more secure than the RFID Cards) So without RFID or Biometrics, using codes is your fastest option with print release.
-
I will se if I have an old copy of the SDK for Live@EDU SSO. How long left on the Microsoft trusted cert? You can put a DC, ADFS and a ADFSproxy onto Azure or some other remote server deployment and that will solve the site going down issues. But it will cost you. We haven't had any issues with all the servers onsite yet touch wood.
-
Hi Steve, I looked into this about 2 years ago. If Microsoft do let you renew the cert you could move the code to a new IIS server running 2012. However it was deprecated a long time ago. So don't think MS will give you a new cert. Bite the bullet and go to ADFS, that's what we did. It's a pain to setup with needing 4 severs for load balancing etc. But dose work well. That or just stick with PW sync in DIRsync and they will just have to put up with logging on twice.
-
I have some neat tricks using some of the unpublished Frog3 File API's that might help you with the migration. However that will depend on you having a working Frog server to access the API's. P.S. All of the files stored on Frog3 system are actually blobs in the database and not stored on the actual file system. Have fun. You know where I am if you need me.
-
That looks like one dead Frog Server. Is the system still in support with Frog? Actually I take it isn't seeing as you are trying to fix it yourself. Good luck Steve, sorry I don't have any words of wisdom. At least if you can't restore it and the school wont pay for Frog support, you can put Frog3 into its grave.
-
Its not fine if you change the ADFS server settings to support all browsers for SSO (like we do for our Apple computers and PC' using Crome). Anyway, Hear is my solution. Change your DNS record to point to the ADFS proxy as it would do for off site devices. Then on all of the school managed PC's or Macs add a "hosts" file record pointing direct to the ADFS server. The host file override any DNS records. Thefor all school managed devices get the "hosts" file and can SSO with ADFS but all other devices get the web form login. my host file has: 10.4.208.85 adfs.*********.****.sch.uk my DNS record has: 10.4.208.86 adfs.*********.****.sch.uk On windows you will finde the file in: C:\Windows\System32\drivers\etc\hosts The host file can be deployed with GPO\GPP
-
We have 2 x 4096 addresse ranges with the SWGFL. One 4096 addresse range for main school network out of one port on the SWGfL router. And the second 4096 addresse range for BYOD network out of other port on the SWGfL router. We did once have an old 254 addresse range for OLD separate admin network but traded it in for our new BYOD 4096 range. Or just NAT 5 or 6 SWGfL IP aggresses in a pool over to a new privet IP address range for your BYOD. We do this with our catering network that is running on a privet 172.16.0.0 range. We use our own Cisco router to achieve this NAT setup on top of the SWGfL one.
-
Ruckus ZD3050 - Additional APs (or replacements)
MicrodigitUK replied to Steve21's topic in Wireless Networks
Hi Steve, Sounds familiar, took so long to upgrade the Extricom that the replacement Ruckus APs went EOL. LOL End of Life for the 7962 was announced March 1st, 2013. Per the EOL announcement, the 7962 will not be supported on software released after August 31st, 2014. So to keep the 10 APs running you can run 9.8 on the 3050 zone director (9.8 will continue to get patched until late 2015). But you can't run the latest 9.9 as you won't be able to control the 7962s. To keep it in budget you can stay on 9.8 however it might be better to get a new set of APs so you can run 9.9 features on the ZD3050. I don't think you will need 50APs to get full site coverage with the new Ruckus APs! At least you can re use the zone director. -
The 192.168.0.0 and the 10.0.0.0 range need to be routable from each other. Because the server only advertises one internal Ip via Apple. E.g. The client on 10.0.0.0 range will get a message from Apple that their is a local cashing server at 192.168.0.X and the 10.0.0.0 needs to be able to get to it through your router.
-
Office 365 - Outlook and ADFS SSO - Disapointment
MicrodigitUK replied to FN-GM's topic in Cloud Services
Just looking into ADFS and Outlook 2013. Did you get anymore updates from Microsoft about this issue? -
[sims] Report for printing AM/PM regisers for fire drill
MicrodigitUK replied to Pyroman's topic in MIS Systems
Yes, Reports>Lesson Monitor>Whole Groups Student Reports>Today's Register Report -
Yes, exactly that. Our staff shard accounts start with STAFF and we don't change the pin codes for them.
-
Don't know if this helps but we use a random code system excep everything is linked back to department Accounts, that the teacher or cover for that department issues. These codes are random and helps link printing to a subject for charg back if you whant to. http://www.edugeek.net/forums/enterprise-software/134343-papercut.html
-
Try setting your proxy to: fp02.swgfl.ifl.net
-
Set my proxy to: 213.18.249.46 and Google looks to be working on that SWGfL proxy.
-
Sorry, I presumed your users log onto your Macs with a Windows AD username. The Same user that you want to show as accessing the SMB print server. Kerberos is the Windows AD authentication. You need to tell the Mac to use that for each SMB printer, or it will randomly use the computer account or prompt for additional authentication.
