Jump to content

CHiLL

Members
  • Posts

    2,809
  • Joined

  • Last visited

Everything posted by CHiLL

  1. I don't think I could in a million years get that by our bursar, for what is effectively a desk and a PC case, even if we did offer eSports (which we don't).
  2. We separate our different types of devices or systems into different VLANs, including: Staff desktops (Dot1x) Student desktops (Dot1x) Staff laptops (Dot1x) Student laptops (Dot1x) Servers Server management (ILOs, vSphere, etc) Network management CCTV Cashless catering BYOD Wi-Fi Guest Wi-Fi Telephony
  3. Windows 10 will receive support until October 14, 2025, so you have until then to use Windows 10 without worry of not being updated. In terms of viruses, you should always ensure you have some software installed, such as Windows Defender/Security.
  4. Yeah, these are just quirks I'm working through atm. There's only two of us here and I'm the guinea pig at the moment. My colleague will likely make the switch soon. That's how we ran it for years, but if your machine gets infected by something and you're logged on with account that can do everything, no amount of MFA or conditional access will help and it could wreak havoc on your network.
  5. It's also worth noting that not all Xbox 360 games are backwards compatible on the Xbox One (full list here: https://www.xbox.com/en-GB/games/backward-compatibility). For those games that still need a Xbox 360 to play them and they stop the ability to download them, you'd need to get a physical copy of the game. This all ties in with the fact that we don't truly own our purchased online games via store fronts, we are at the mercy of the platforms as to how long we can use them.
  6. I started running two accounts earlier this year, a standard user account for my main day-to-day at my desk and a domain admin account for specific tasks. I've changed my shortcuts to require admin privilages to run, so if I load ADUC, SCCM, Server Manager, etc...it prompts to to authenticate with my domain admin account. The biggest issue I had was related to folder permissions on shares. We had specified domain admins to have full control over all folders and we could make folder changes. Now as a non-domain admin, I can't make those changes without logging onto the server as my domain admin account. Instead, I created a new group for IT Admins and added myself and domain admins as members, then added IT Admins with full control to the shares. That way, I can make changes without being logged in as an admin. I have a question about the non-admin account for those that use one - do you make it a power user/local admin of your workstation? I find it gets very annoying when I'm installing/testing stuff.
  7. Our printers are managed by Papercut, including some follow-me queues for most staff, plus direct printing for classrooms/students and some office/admin staff. We use user Group Policy Preferences (User Configuration > Preferences > Control Panel Settings > Printers). We can use item-level targetting to add printers based on certain criteria, such as user, user group or machine OU. We have found that printers do not get added if it's the first time the user has logged onto the machine (or first time after their profile has been removed). If they log off and on again, the printers will get added. I never figured out a resolution to this.
  8. This is my take on it, based on what I've read/believe to be the case: KCSIE and PREVENT cover the school's reasons for monitoring and collecting Internet activity. MITM/certificates on personal devices is at the discretion of the individual. They choose to use their personal device on the network and therefore must adhere to the company's requirements. MITM certificates also enable the monitoring/collecting of secure website data/HTTPS, to also comply with KCSIE and PREVENT. I'm pretty certain that schools are not allowed to sell personal information, otherwise legal action could be taken against the school. It is the school's responsibility to ensure that data that is being shared with external companies is being kept under the GDPR regulations and that the company has a policy stating it will not sell/share the data. If that is broken, then the school can take legal action against the company. If the company is breached and data is stolen, then that ties in with the above point that the customer (the school) will have to take action against the company. Students are pusished if they breach the school's policies/rules on computer use, which the student or parent should have signed in order to use the computers. Such policies would include fordidding the student to access certain types of content, such as: Restricted/Age-inappropriate, dangerous, social media, extremism, weapons, etc.
  9. This is how we get the maths toolkit and other licensed features like transparency mode to work. All the maths options are missing in v23 despite the license being active, but show and work when opened when you do View > Open in SMART Notebook 22.
  10. I know this thread is a couple of months old, but it is related to laptop deployments - can anyone recommend a dock that would support 2x HDMI 1080p monitors, USB C PD and USB C DP Alt, Ethernet and USB ports?
  11. While our implementation is different (using a SAN for the drives, connected via fibre to the VM hosts), we do separate our our OS and data drives. We have two pools of drives, 15k SAS drives or 7.2K MDL drives, with both sets using RAID5 (I think). Typically, all our OS drives are stored on the SAS drives, with the slower storage for data (or even the OS of our low-end VMs).
  12. We have Smoothwall Monitor (rebranded after aquiring Visigo and Policy Central) and we were told that it can capture that. However, with the amount of languages spoken at our school...we are not entirely sure if this is accurate, as it appears all the captures we deal with are in English.
  13. Wave9 supply our Internet connection (basically a 1Gb Virgin FTTP line), our firewall, filtering and we also have support with them. While we've had some issues with our supplied Sophos XG unit, we cannot fault them on their support, they've been excellent. We have a cloud 3CX host and they've configured our firewall for that too. We don't have DDOS protection though.
  14. I have ours deployed via SCCM. There are two applications I have deployed "Agent" then also "Agent and Console" (for those who want access to the console to write and send messages). Files in the source folders Note 1: Config.dat should contain the server gateway key Note 2: NSN.LIC is your license from NetSupport SCCM installation command: msiexec /i "NetSupport Notify.msi" /q /norestart SCCM uninstall command: msiexec /x {15E5AAF5-953E-4F4C-827D-F47076744C59} /q /norestart Detection method: Windows installer product code detection: {15E5AAF5-953E-4F4C-827D-F47076744C59} The only difference between the source files is in NSN.ini, specifically this line: Console=0 For Agent only, you want to set that as 0 For Agent and Console, you want to set that as 1 Because they both use NSN.ini, that's why I have separate deployments for the agent and also the agent+console.
  15. I've only been to a handful of BETT shows over the past 10 years, but I've noticed they've been getting worse in terms of visitor experience, with 2023 being particularly poor. We do not publish our full staff list online and I don't want to share my personal LinkedIn with them, so I doubt I'll be going to the 2024 show. I also can't be bothered with the hassle of registering, the spam/requirements from them leading up to the event and then the constant spam after the event from exhibitors.
  16. Would you mind sharing that script? I've been thinking of the same, just haven't had the time to look at it.
  17. Neither the GPO or Delprof2 work for me. Only thing I can do at the moment is clear off profiles manually with DelProf2 when I get complaints.
  18. I never got a care package with my order over summer, so I can't taste them to comment
  19. We've had an email every evening last week and early this week from Bromcom about SSO issues. In general, it has been quite slow. It's not been as bad as it was this time last year though, which is an improvement at least.
  20. The keys could also be stored as XML files in C:\ProgramData\Microsoft\Wlansvc\Profiles\Interfaces\. At least according to a Microsoft forum post: https://answers.microsoft.com/en-us/windows/forum/all/where-are-the-passwords-of-my-wi-fi-networks-saved/5170ec32-92f9-4187-813f-478e7d6dba76?page=1
  21. The RPM on our old Smoothwall box sounded like it was constantly fluctuating between 75%-100%.
  22. On that note, we do have a newer Zioxi smart trolley on-site, with their onView software. Once connected to the Wi-Fi, you can control the charging schedules and profiles of the trolley. But no, they aren't cheap.
  23. We use these Loxit 10 Port USB A Charging Stations (they also do USB C ones too). We also use these Really Useful Storage boxes (specifically the 9L) to store the iPads as they charge and for transporting around the building. We just have the iPads stood up, but upside down in the box, so we can easily plug the chargers in and the charging station is on the shelf next to the box. We found that not only do we prefer this over a trolley, but so do the departments that have their own department set of iPads.
  24. https://monitorhelp.smoothwall.com/hc/en-gb/articles/6815284366492 Smoothwall Monitor is an application that will monitor a user's device against websites visited, keywords typed, etc and report any suspicious activity to your designated staff. This can include things like self-harm, racism, terrorism, etc. It is not a firewall or any sort of network security or filtering.
  25. No worries. With that in mind, they'll just have to accept that if they log in with their work account, they'll see their work stuff. It is an employment benefit afterall.
×
×
  • Create New...