Jump to content

Steve21

Members
  • Posts

    9,168
  • Joined

Everything posted by Steve21

  1. Updated list is live too if anyones interested (Shows on your current Tier if you're moving up), T4 for us! https://www.gov.uk/guidance/full-list-of-local-restriction-tiers-by-area Steve
  2. Out of curiosity is it actually an iPhone 4 she has? Most the stories that have come out recently list a huge amount of iPhones and then say actually they can all be upgraded to support it Steve
  3. Any "official" way of changing the local admin passwords were blocked years ago because it was so exploitable via GPP etc. Which is when LAPS was really brought in You "could" bodge it via NET USER to enable it and then change password using a start-up script or remote powershell etc but obviously more of a security risk How many machines are you talking if it's a primary school? Might just be quicker/safer to manually do it? (or even if you enable it via a bodge method, change them manually after ) Steve
  4. Take it nothing silly like you have it on another program that's taken control of it? We've had that kind of issue before where something like Teams was left open and holds control of the mic, so a browser etc can't use it while it's open Steve
  5. Yep an interesting bit is why there's a new company involved who's going to be running it, but with funds from Montagu Tiger UK Bidco Limited, a newly formed private limited company incorporated in England and Wales, ultimately owned by funds advised by Montagu Private Equity LLP (the “Purchaser”) (the “Disposal”). Class 1 circular below if anyone's interested in a nosy at the longer info: tiger-consent-letter-barclays.pdf Steve
  6. 2016/2019 base it on virtualTPM, so like USB passthrough from the host etc (again assuming you have TPM on the HOST), so storing of the keys separately isn't needed as it's within the TPM as a standard laptop etc Even silly things like how you RAID could affect your answer to this, it's always going to take a hit but depending on how much will depend more on the setup overall Steve
  7. I don't know if it's changed recently, but without using vTPM/shielded VMs it was never officially supported using bitlocker on the guests as the keys would be stored unencrypted as such on the host Any reason you say you can't use Shielded for what you're talking about? You can use it with a standalone host (althoughtobviously more are better) Otherwise you're going to run into problems with manually unlocking them every time you reboot etc In terms of your actual question, we don't use any of those. It's the same principle as paperwork that's stored locked away, could still be stolen, but you've implemented many security features before that stage etc, so you're still following all guidelines etc Steve
  8. What error are you getting? Steve
  9. This is the one that really should hit home for anyone who still thinks it's not spreading: Steve
  10. Today I learnt there's a number to forward junk too! And it spells out SPAM on your phone haha Steve
  11. To clarify, when you say BYOD laptops do you mean like a shared bank? Or are these their own devices? Just thinking in terms of how the client is being deployed out/run on said devices Steve
  12. I don't know if you know, but was that a "them" decision more than a Gov one? We had the opposite email just before Xmas hols, everyone must be in, even if teaching students remotely. Just wondering if it's changed in the latest guidance *fingers crossed* Steve
  13. The other one we use that's linked to Chromes version would be - "enable add person in user manager" and disabling it so they can't add another profile Steve
  14. The main one is called "Browser sign in settings" for Chrome it seems, Edge like to rename it all but it's the same regkeys it seems (BrowserSignIn) Steve
  15. Not checked on Chrome being an MS school, but when I was doing our Edge Chromium policy the other day there was an option to disable profile logins, and then auto login with Windows Auth Guessing Chrome "should" have a similar named one, seeing it's same browser? Steve
  16. That shouldn't affect it as that's their employee record, rather than login (You don't even need one for the other remember) Few things to check, mainly obvious stuff, but no harm in checking Leaving Date isn't set, and something like Salamander disabling? Username isn't set to work with AD auto login? User isn't still logged in somewhere? Checked the user access logs to see if somethings showing as logging in after you reset it? Steve
  17. Very nice! Thanks Steve
  18. Seemingly 85.92.188.117 you use currently based on your MX? Would that match up with your current range? Steve
  19. Tongue in cheek aside, what's your external IP for your transport server? As in you must have an external IP/port forward setup to route mail internal->external->internal etc Steve
  20. Lots of places https://www.montagu.com/news/montagu-to-acquire-capita-s-ess-business-and-invest-in-parentpay-group/ Steve
  21. You really don't need 12 VMs for SCCM, unless you're trying to make it complex or have 12 schools I've only ever run it on 1 VM and it can easily support 2k+ users/devices. In terms of your original question though, as others have said, I'd query more along the what are you missing. Whether it's inTune/SCCM/MDT/other, they each have their benefits/downsides, it's more weighing up what you're trying to do and what's most efficient for your own site. If you're heavy on mobile devices etc you can link these all into SCCM/Co-Management etc, something you couldn't do with MDT natively. It's a big change moving to SCCM with a large setup at the start, but once it's setup you're unlikely to want to move backwards Steve
  22. Yep, we cancelled our plans a few weeks back when it wasn’t coming down (we had some in case things did magically get better!) Back to just our own household, at least we have all the food bought ready, can imagine a lot of late night shopping in Tier 4! Steve
  23. Well seeing we now have a Wales, Scotland and England live briefing planned today, I'm gonna place a bet most Xmas plans are all changing! Steve
  24. Never tried it with MACs, but you can add alternative server names (or DNS redirects) so both server1 and server2 would resolve to the new server At least that way until you change over all the Server1 links should still work Steve
  25. We did similar as above, local account, Teams/365/Chrome/OneDrive etc pre-installed. Set a restore point, more for our laziness of fixing if required Seems to work well for them (at least in terms of the specs etc) as home devices Steve
×
×
  • Create New...