Jump to content

Roberto

Members
  • Posts

    2,735
  • Joined

  • Last visited

Everything posted by Roberto

  1. Neat, you’ve incorporated the save icon. Obviously trying to send a message about saving people from IT problems?
  2. Good point, though iirc completing the AD Connect wizard that allows you to select new sync sources will kick off a full sync by default.
  3. This isn't a "I just need to script harder" situation. Microsoft isn't hiding a "-syncGroupsNoReallyBillGates -ImeanitThisTime" switch in the powershell to run an AD connect delta sync that we're all under a strict NDA that mentions you by name to keep secret. This is a "this should already be happening based on what you've said, so something isn't right and needs fixing" situation. So, are you sure the groups are in an OU you've configured to sync? Are you sure you've set groups to sync? Are your groups universal groups? (On-prem exchange lets you get away with mail-enabled global groups, O365/AAD is much more stringent in requiring groups to be set up correctly? Do they meet the other condtions in the link below(1) (e.g. correctly configured email address attribute of some kind? If all of these are correct and it's still not syncing, then are there errors in AD connect pertaining to the groups? Have you set AD Connect to target members of a particular group to sync, and this is why its excluding other objects? (2) What happens if you create a brand new, universal mail-enabled group in the OU where the current groups are? Does that work? What if you create a brand new, universal mail-enabled group in the OU your users are syncing from? Does that work? (1) See https://docs.microsoft.com/en-us/azure/active-directory/hybrid/concept-azure-ad-connect-sync-user-and-contacts#groups (2) https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-configure-filtering
  4. Yup. My Aruba experience is all with the traditional model so I didn’t think of the IAp model, but you’re quite right. These days I’m in a ‘meraki all the things’ kinda place, they are better imo but expensive ongoing costs.
  5. I would suggest you ask for a requirement that failure of the controller does not mean failure of the system. IMO, this means either a system like Unifii where the controller just pushes config and isn't required for functionality or a cloud service like Meraki. It's possible to get dual-controller systems where the failure of one controller doesn't mean the service fails (Aruba do this for example) but its not cheap.
  6. Why not just construct a Gui Interface using Visual Basic to track his IP? That should be easy to do. Then we can see where they're from, for example if the first number is 398 then they're in downtown...
  7. I can't say. If you've built other devices with no issue then maybe the issue is with the device - something not quite right there perhaps. I'm not speaking in riddles on purpose, I know that error is related to restriction policies whenever I've seen it before, but I can't say where or why in your case.
  8. There a device restriction policy in AAD or Intune somewhere preventing this from working, would be my guess.
  9. Just to be clear, this log isn't a log in the normal non-database way of things. Do not just delete it, whatever else you do. My first thought is that your database is in full recovery mode and you don't have the transaction log backups configured. Actually, the first question should be even more basic than that. How are you backing the server up, is it "SQL Aware" and is it correctly targetted to this database. I'm going to point you to this web page: https://dallasdbas.com/why-is-my-sql-log-file-huge/ - read the whole article and make sure you understand all of it before you do anything. Lastly, be careful. If my comment about the logs in the first line of this reply is news to you then, and I can't emphasise this enough, get help from someone who does understand MSSQL databases (whoever supports your SIMs install maybe?) and don't try fixing this on your own.
  10. Hope you threw them off site. That's appalling.
  11. Does seem to be a bit of a rash choice, yes.
  12. This was not specified in the post I originally replied to.
  13. On your WiFi, yes. So you're not applying filtering to these devices directly, just while they're on your network. That is ok. I think as someone else has suggested there is a terminology/lack of precision issue here.
  14. You're blocking "most things" on someone else's device? You know that's a huge overreach, and totally unjustifiable, right?
  15. I think this is a massively ill-conceived scheme. If this is BYOD (not sure how you can make that compulsory unless you're in private education but lets set that aside for now) then the students or their parents own the devices but your scheme seems to be predecated on the idea that the devices are there for your school to do what it pleases with. I would suggest that mandating the install of a tool like impero or netsupport to "see what they are doing" is a massive overreach. I'm not sure what the legal basis for this is but I would absolutely refuse to allow you to do this if I were the parent of a child at your school. Do you have a mechanism in place to support these devices? What if they want to upgrade their device to Windows 11 while your software will only work on Windows 10? What if the monitoring software captures information related to someone who is not a pupil, such as another child who doesn't attend your school or a parent? After all, this device could be a shared device within the home and you cannot stop that because it isn't your device. What you block one of these people from their own legitimate use of the device (you have no right to say that mum, dad or adult sibling can't watch whatever they want on youtube, for example). What if your control software causes someone in the family to lose data?
  16. I'm talking in Microsoft terms myself because I'm an O365 expert these days and its the language I speak. I'm assuming Google have their own equivilent to most or all of this functionality? I could also do all this stuff in Okta, for example, so I'd expect it from any decent featured IdP.
  17. Policy absolutely needs to be a part of whatever solution you work towards. I sympathise with people who don’t want controls on their personal phone, I’ve opted into a corporate one where I work precisely to maintain this separation myself. However (and this is where policy comes in), you’re not requiring them to have the controls on their personal device regardless, you’re simply mandating their use when people want to access your organisation’s data. If they don’t want one, that’s fine, but they cannot then have the other,
  18. Important to ensure that whoever you use can support and supply DEP registration for your devices.
  19. I've always been wary of that brand of products...
  20. Not concerned about cyber essentials but I have implemented this to meet other requirements. It's really not that onerous. If you're using Office 365, require Intune (conditional access can be set to require devices users connect from to be marked as compliant, for example), create a light-touch compliance and configuration policy for BYOD, go to lunch because you're done. Intune (or any other MDM these days) will then gather the data you need, as well as helping secure access to your data..
  21. Ok, so first things: What does ‘feel’ mean here? Presumably this “gold service” thing has a standard, ideally a SLA attached to it? You should be able to objectively measure the service you’re getting against the agreement and know, not ‘feel’ how well the service you’re getting corresponds to what you’re paying for. Whether you’re paying for, or getting, what you need is an entirely different conversation, incidentally. As for being asked to spend money whenever you ask them to resolve issues, again would need to qualify this; if your issue is that your laptop is always crashing and it’s a 6 year old clunker that you’re trying to run photoshop on then “buy a new laptop” is a reasonable response, and unlikely to be covered by a support contract. Similarly, ‘dead spots’ in the WiFi or a worn out/overtaxed server/NAS aren’t really support issues and wouldn’t normally be covered in a standard support contract. Again, spending more money based on your growth, if you’re growing you’re probably going to generate more requests for support, more issues to fix, etc. I could easily justify a price increase depending on how things are structured. Literally every point in that list would need substantial work to define where it is and where you need it to be, and the remedial actions necessary to get it there, before you could outsource it to a “support” company. There are MSPs (big ones like wavenet spring to mind) that can do a lot more than providing ’support’ who could give you an outsourced IT department to do this. Your last two points, “full data security”, DPA and Cyber Essentials are whole organisation issues, not really IT issues. This is a possibility, but keep in mind they may need to get help from an outsourced provider anyway. This could easily be an IT director/manager level bag of tasks, not a ‘technician’ role.
  22. The vast majority of people won’t understand how any of this works, and either will lose their ‘digital signature’ or will have to place it with an escrow service of some sort - I imagine solicitors companies would offer a service, for example, and those would be vulnerable to phishing (a would individuals who look after their own data, now I think about it) and we’re back to square one.
  23. All I know is that I've had mild symptoms last week and my partner's got a proper covid case. This despite both of us being double jabbed and at least fairly careful with masking. Given how much I didn't enjoy the mild symptoms and how much I can see my partner's feeling about 1000% worse than that, it boggles my mind that people don't appear to care anymore.
  24. Yes. I signed up to that on advice from my conveyancer when we moved last time. It’s a free service and as terrible cases like this Luton one show, while the odds may be small of this happening to you, the impact is devastating and it’s incredibly difficult to untangle.
  25. Roberto

    old iPads?

    Internet devices don’t need to be up to date? Are you a time traveller from 20 years ago? Because if you are, I hate to break it to you but out of date, unpatched devices are the last thing I’d be wanting my users to browse the internet on.
×
×
  • Create New...