-
Posts
2,809 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by CHiLL
-
Why don't you want school/work files to appear when they're using their school/work account? I don't think it's possible to restrict it in the way you want, unless the user logs in with another account, such as a personal account? If it's not a 1:1 device, the Office apps aren't ideal because if a person forgets to sign out of the app (almost always), then the next person to use the iPad will have access to that person's account.
-
We use the Microsoft Authenticator app for most of our staff. Some are using SMS. We aren't using TOTP devices because of the cost, especially with replacements.
-
A1 will grant you access to the online services, such as Outlook, SharePoint, OneDrive, etc. You'll also need Microsoft 365 Apps to be able to use the Office applications. P1 will then allow you to enable conditional access in your tenant, so you can enable MFA prompts and specify IP address(es) to exclude. I don't know if you only need to purchase one P1 license to allow conditional access, or if you need to buy for each user. If you can do the former, then I'd maybe suggest that.
-
Thank you very much for this. Following this guide has allowed me to create and install a certificate that works! (I never knew that webpage for the CA existed!)
-
It's not showing me a SAN field (unless it's called something else). I'm specifically using the Create Domain Certificate option in IIS > Server Certificates. CN: website.school.sch.uk Organisation: school name Organisation unit: blank City/locality: Birmingham State/province: West Midlands Country/region: GB Specify Online Certification Authority: Internal CA Friendly name: website.school.sch.uk We have internal DNS records for website.school.sch.uk and I've also tried replacing website.school.sch.uk with website.domain.local, but that certificate shows the same error.
-
That's what I thought, but I've started to confuse myself. I've created a Domain Certificate within IIS on the web server and bound that to port 443. It's now complaining that the common name is invalid on both Edge and Chrome: NET::ERR_CERT_COMMON_NAME_INVALID.
-
I can see that our is already in all our client's Trusted Root Certification Authorities > Certificates. It isn't being pushed by GP, so I assume it's listed in the directory and added via auto-enrollment. However, that's been the case for many, many years and all our sites with self-signed certificates are still untrusted.
-
Does anyone know if it's possible to use an internal CA to create an SSL certificate for an internal website, so that our computers trust it and don't prompt an invalid certificate? If it is possible, can someone provide some basic info as to how?
-
Source: https://www.bbc.co.uk/news/uk-england-birmingham-66715441 Existing authorised payments and contracts will be honoured, but it looks like we'll not be able to purchase anything unless it's basically essential or safeguarding, etc. Interesting times for us LEA schools and other council services.
-
We are installing a new Aruba CX 6100 to go alongside our HP ProCurve 2530 switches. Since the config is going to be almost identical between the switches, aside from the name, IP address, etc...can I just import the 2530 config and then make the necessary changes?
-
This doesn't happen on Windows 10 clients, only on Windows 11. I was hoping this would be a generic Windows question, rather than an Impero specific query, hence why I put it in this section. If it needs moving, I guess a mod would need to move it to the Impero direct support forum (though I do have a case open with them regarding this issue).
-
This is a weird query - I am after the executable file that pushes the applocker blocked notification popup to the user. When a user launches an app that is restricted by AppLocker, how is the popup that is dusplayed pushed? The reason is because I'm finding that our Impero remote viewing is crashing/losing connection whenever the AppLocker "This app has been blocked by your system administrator" message is displayed, requiring me to close the remote window and reopen to view/control the machine. Impero's response is to add AppLocker to the Impero exclusion list of monitored applications, however I'm not sure this is how AppLocker works, I don't think there is an executable, as it's a set of rules against the machine. I have attempted to save the tasklist log of running processes on the machine, both while the popup is shown and while it's not, but unfortunately it doesn't show any difference.
-
Cost of living crisis 2022 - what have you cut back on?
CHiLL replied to Ditto's topic in General Chat
If gross pro-rata pay is £18,000 a year, then Nationwide's website says you could borrow up to £80,820. It's definately worth having a chat with them (or maybe another high street lender) to see what your options are. Note: I am not a financial advisor. The numbers are subject to change based on personal circumstances and other factors a lender may have, such as mortgage length, etc. -
Cost of living crisis 2022 - what have you cut back on?
CHiLL replied to Ditto's topic in General Chat
I assmume you're on a normal technician equivilant wage like a lot of us here? Are you full time or term time only? -
Talk to me about Broadband and Filtering!
CHiLL replied to Zammo's topic in Internet Related/Filtering/Firewall
We have 2x leased lines using different backbones. 1x Virgin 1Gb FTTP and 1x OpenReach 1Gb FTTP based solutions, configured for load-balancing. Sophos XG for firewall and on-site filtering, which has HTTPS filtering (requiring deployment of certificates to clients). For off-site safeguarding, we use Smoothwall Monitor (formerly Visigo), which takes captures and sends it off for human analysis, which are then forwarded to DSL if severe enough. Very severe ones also get a phone call. We also have a basic/cheap subscription with Senso.Cloud, which allows us to install a remote client on machines and block categories such as games, videos, etc. However, because we don't have the full package, we cannot granularly filter it...so blocking the videos category also blocks legitimate learning video sites like BBC Bitesize, MathsWatch, etc. I've consulted at another school, which is part of a MAC and they have some server space in a local data centre. They have their Sophos XG located in the data centre and the Internet for all the schools routes through that centre, so the filtering is all in-line. -
Cost of living crisis 2022 - what have you cut back on?
CHiLL replied to Ditto's topic in General Chat
You sound as though you have no option but to stay in that mortgage, like you're locked into it. Why do you think that, because I'm fairly confident that you could remortgage elsewhere. Have you actually had a chat with any mortgage advisors or brokers? -
Bromcom say it's now resolved and is unrelated to the SSO login issues from earlier this week. What a coincidence.
-
Three mornings this week we have been unable to get through the Microsoft SSO, it's utterly ridicuolous. Our main concern is that we can't access emergency contact details if we need to call a parent or next of kin in an emergency. We're going to have to resort to pulling a CSV containing that information and storing it in a secure folder on our server, for such an emergency. Edit: We're mainly after the details in the Emergency Contact field that gets handed over to paramedics.
-
Cost of living crisis 2022 - what have you cut back on?
CHiLL replied to Ditto's topic in General Chat
I remember you saying you had a £75k mortgage at that rate but wouldn't qualify for better deals/rates. You didn't expand on that, but earning approximately £20k (not pro-rata), you can get a solo mortgage of approximately £90k (according to Nationwide's online estimate calculator). Obviously I don't know what you personal circumstances are, such as income, credit rating, other existing debts, etc. -
It does have 4 SFP ports, though we don't have the free capacity in the 5406zl for them. We have spare bays for a new module, but that just seems excessive for what is something like a dozen clients, with more being connected only very infrequently (for imaging, etc).
-
Thanks for your quick reply. The 2530s we have are the J9854A, J9855A and J9733A models. The first two definitely take SFP+ 10Gb, though the library switch is a J9733A...which actually looks like it's only SFP, not SFP+. Well that puts a stopper to that idea. We often use the PCs in there (or rather their network sockets) as a place to imagine new machines, as it's the easiest place we can book/have access to to do multiple at a time. Thanks though!
-
I've noticed that a switch (HP ProCurve 2530) we have in the library (with multiple PC's) that has 1Gb SFP modules, with corresponding 1Gb modules in the core switch (HP ProCurve 5406zl). All our other switches, which are all the same models, use 10Gb SFP+ modules, so I know there's no compatibility issues. My question is; can I just hot swap them, or would I need to change the configuration on the library edge switch and the core switch to get it to run at 10Gb? Or would it automatically configure itself?
-
BlipparAR is the resource I was asked to look at this morning. It looks as though it's all in browser and you can use your Microsoft or Google SSO. But yes, the lack of thought that's gone into this by the exam board or whoever comes up with these courses is ridiculously poor.
-
We were asked to install this on our Windows desktops, but had trouble getting it working through our Sophos XG. Wave9 did a bunch of work, to no avail. We fed these issues back to our ICT lead and pointed out that it is still beta software, which isn't suitable for a curriculum. Once it's fully released, we can then truly be tested for use.
