-
Posts
4,144 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Sheridan
-
We've got Defender running on several Server 2016 VMs, one of them is generating errors whenever you use powershell to query the service/state etc - for example Get-MPComputerStatus returns this error: get-mpcomputerstatus : Provider load failureAt line:1 char:1+ get-mpcomputerstatus+ ~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : NotSpecified: (MSFT_MpComputerStatus:ROOT\Microsoft\...pComputerStatus) [Get-MpComputerS tatus], CimException + FullyQualifiedErrorId : HRESULT 0x80041013,Get-MpComputerStatus I've done all the usual, remove and reinstall defender, sfc, dism and so on and the end results is the same - defender is working OK, but obviously some component is missing/not registered? I'm at a loss as what to try next, apart from a repair install or upgrade to 2019/2022
-
Gmail stuck on loading for users
Sheridan replied to csmith0504's topic in Internet Related/Filtering/Firewall
I had this in my previous school job last year - I had to remove the most recent smoothwall update, although removing mail.google.com from https inspection also worked. Never did find out what happened as I left soon after that! -
We're having an issue trying to upgrade SCCM to 2111 - it constantly fails the prereqs saying the dotnet version isn't at 4.6.2 or higher. The three servers running SCCM are all 4.8 and the clients are all 4.7. I've checked with powershell, registry and in the SQL db - all show the correct version of dotnet, so I can't think of where the installer is getting the information that its below 4.6.2? Anyone seen this before?
-
Yeah I deleted those so they don't apply. I think its because the setting 'Allow users to connect remotely by using Remote Desktop Services' was enabled - which overrides everything, switch it off and no one can access. So it looks like that setting is too much of a global setting to user when you need firewall granularity
-
Got a weird issue with firewall rules on 2019 server. The server has a GPO that allows RDP from some specific IP addresses (separate range from normal network) but it still allows RDP from other subnets - in fact any routable subnets When I check the server firewall rules, the only rule allowing 3389 in is the one with the specific IPs, there isn't a whitelist rule to allow RDP for all, so I don't know how its not working. Running the RSOP shows that 3389 is only enabled by that GPO/rule, yet the firewall log shows an RDP attempt from an IP not in the list as ALLOWed to 3389 - where else can it whitelisted like this that I'm missing?
-
I've got a couple of 2019 servers that fail to install the Jan updates (error 0x800F0984) and this seems to point to component corruption - however running sfc and dism both fail to repair the system (dism also shows Error: 0x800f0954 DISM failed. No operation was performed) so no updates can be installed anymore Is there a way around this or am I looking at a new server, as I don't think there's a way to repair the server once its in this state?
-
I've got a random issue where certain W10 clients will request a device cert from the internal CA (for vpn use, using an intune config) - every so often a random PC will request this cert 7-10 times a minute the duration it is powered on! Then it stops and won't happen again, but another one will do it - there doesn't seem to be a pattern though. Of course the client ends up with 1000's of valid certs and the CA has 100s of 1000s of issued certs so something's not quite right? Clients are offsite so its tricky to diagnose but I can't see a reason why they would do this?
-
Ports/URLs for SCCM to download UI updates
Sheridan replied to Sheridan's topic in Enterprise Software
That looks like what I already have in place - mostly .microsoft.com over 80/443, but I might have to try and put a trace on it -
Does anyone know if theres a specific set of ports/urls for SCCM to download its own updates (rather than client updates?) Updates are downloading OK, but the latest updates to SCCM itself are timing out, which suggests a firewall issue
-
I've noticed a lot of Uni and colleges offer a service that show where computers are available in their 'study areas' or shared spaces I really like the idea of implementing something similar as we have desktops scattered all over the place in suites/pods etc and having a list of rooms with spare computer would be useful Something like this: Library - 20 free out of 50 Main Suite - 5 free out of 30 and so on. I'm assuming it will only show as free when logged out I can't find anything that seems to offer this, so does anyone know if these are custom systems, or all based on a similar api/codebase?
-
This is my sticking point - careless use in school! Of course they always set it remember their device anyway but 2FA at least mitigates some of this
-
I have to admit I'm still in two minds about it, part of me thinks that 2FA should apply all the time, in school or otherwise, part of me thinks I'll get less complaints about 2FA if its only used outside school Although if staff learned to lock their PCs it would be a start!
-
Yeah - MS seem to have managed with 365 but I can understand why there's reasons why it hasn't been implemented with Google.
-
I'm not a big user of 365 but I'm aware that it allows you to enforce 2FA for users when they are offsite (i.e off school network) Does anyone know of a way (third party tool perhaps) that allows this with GSuite? We currently have it enabled but it applies regardless of the login location
-
Smoothwall firewall logs
Sheridan replied to Sheridan's topic in Internet Related/Filtering/Firewall
SIP Proxy isn't used, we did raise a ticket but to be honest we had a bigger problem last week and still haven't had a response on that ticket either, which meant I simply had to roll the most recent update back to fix our problem -
Smoothwall firewall logs
Sheridan replied to Sheridan's topic in Internet Related/Filtering/Firewall
Weird eh? But I do see traffic from the ip that handles the voice data, just not the main ip that handles the initial SIP connections - but the port forwards to this ip do get logged -
Smoothwall firewall logs
Sheridan replied to Sheridan's topic in Internet Related/Filtering/Firewall
I created a rule, and put it at the top of the list to allow all outbound traffic from that ip and also log it - still nothing shows in the logs. I know the ip is connecting because the phone engineer showed me the logs for their system showing a connection from the internal ip connecting out to their system. Very bizarre, but smoothwall logging has always been a bit unreliable in my opinion. -
Smoothwall firewall logs
Sheridan replied to Sheridan's topic in Internet Related/Filtering/Firewall
It weird, because even by port it doesn't appear in the log (apart from the Port Forward rule logs) - but the secondary address used for voice data does show correctly. Its got me baffled! -
I don't think Smoothwall actually respond to support requests these days, so hopefully someone here may be able to help! We have a port forward rule to an internal address, 10.x.x.x - this rule works fine and the service (SIP) is also working fine. However, when looking at the firewall logs, there is never an entry for the 10.x.x.x address outbound, even though there is an outbound rule allowing it, and also set to log traffic. Its odd because its working as expected and it must be going outbound, but I can't see the traffic in the firewall logs. I've checked the other rules and its the one rule it would hit a match on so I'm confused as to why it never appears?
-
No, our finance team just arrived to refund directly instead, by cheque I believe
-
This is what I suspected, its a shame as it means you can't have layered password reset support
-
Got an odd issue with user management in our Google domain. We have a few users who have the User Management Admin role to reset passwords of all accounts (staff and students) and also a more restricted 'Teachers' role that only allows those users to change passwords of users in a specific OU (i.e students) The issue is the members of the higher level User Management role cannot reset the passwords of those users who have the Teachers role. They can change everyone's password apart from the half dozen or so with the lower role, as the reset password shows up as greyed out Google support don't seem to be able to help, or aren't sure what I mean, but its almost like users who have any admin role cannot have their password reset by anyone other than those with the Super Admin role, which doesn't seem to match the settings when you look at the role permissions. Basically the built in User Management role should allow reset of anyones password even if they have an admin role as well, or is that just not the case and it is only the super admins who can reset other admins passwords?
-
Teams Meet Now starts and stops straight away
Sheridan replied to Sheridan's topic in Cloud Services
It actually seems be admin accounts when creating meetings with any teacher/student. Teacher > admin and teacher > student seems OK. Must be a setting somewhere I've missed! -
I'm mainly a GSuite user but we're also using 365 for various groups/externals etc and I've come across an issue with 'Meet Now' in teams A teacher clicks 'Meet' in a Team channel, the camera opens and 'Join Now' opens the meeting - and within a second or two it closes with the message 'This meeting is no longer available' It does this every time, regardless of who started the meeting. All Staff have the Meet Now function enabled in the policies as well - there's no error showing either, it just opens and then closes again. I'm more used to Google Meet so I can't see why the meeting would just close like this?
-
When are you planning to move your school(s) to Windows 11?
Sheridan replied to localzuk's topic in Windows 11
We were planning a high chrome OS with Windows 11 mix, but it depends what direction the mat sends us as they are pushing 365 as the platform
