Jump to content

Roberto

Members
  • Posts

    2,735
  • Joined

  • Last visited

Everything posted by Roberto

  1. We've deployed it via SCCM/MSI here. Have you seen https://support.zoom.us/hc/en-us/articles/201362163-Mass-Installation-and-Configuration-for-Windows You can also do a lot to manage logins, etc. e.g. input your domains so that all accounts can be managed, integrate with Okta or Azure SSO/MFA, etc and then set policies as an admin for all users.
  2. I’ve always thought of Apple and Microsoft as “honest villains” in this respect. They’ve always been perfectly clear that they’re here to figure out what you want to buy then sell it to you. To me that makes them a substantial cut above the tech companies who tout slogans about not being evil while scraping every last bit of data they possibly can. But in either case, if you’ve consented, what’s the problem?
  3. I missed that. It doesn’t. Might need protection with things like MFA and DLP but that’s another story.
  4. Yep. I’m.. well not sure if fortunate is quite the right word because we’ve worked hard... able to live in a large house now, and my partner and I each have a room - her craft room, and my study. If we had school kids with us we *still* wouldn’t be able to accommodate the requirements for kids above, as we’re both WFH in our respective rooms and the rest of the house is bedrooms or shared areas.
  5. Almost all your parents must be minted then because you’re effectively saying that the pupil must have their own Study in their home. Can’t be a bedroom.. check. Bathrooms are obviously inappropriate too. No family member in room and must be quiet... so not the living room or kitchen as they are shared spaces. Not everyone has a dining room these days but I suppose that might work... Hope they don’t have more than one child!
  6. The benefit with Office 365's mail filtering itself, which isn't best of breed, and more about synergy with the other Microsoft cloud security products. None of them by themselves is a single "best of breed" product, but the whole suite of tools taken together are extremely formidable. Of course, if you really need to save that £4k and you're prepared to put the effort in, the filtering is probably adequate.
  7. I would certainly question putting RDWeb traffic inside a VPN, you're more or less effectively putting a VPN in a VPN at that point. I mean you do you and all that but it will probably just slow things down without providing a tangible security improvement. If you're concerned about better securing the RDP gateway I'd be ensuring it was protected with MFA.
  8. They’re the same thing really. Sharepoint online is a service that can host all kinds of resources, docs, media, etc in lots of sub-sites however you want (and this is the right place for shared resources). One of the types of site hosted in sharepoint is a personal space for each user to use as a cloud drive (and from where they can share content). This particular feature of sharepoint is known as a Onedrive... Hope that explains a little of what’s happening there!
  9. Teams sounds like a good option as you already support it internally, and you can share documents securely. You can connect externally as a guest to a teams meeting iirc, and you can implement any controls, ensure data management, etc. I’m using zoom to support my church’s online meetings/services and it’s been fine, but their privacy and security is complete and utter chaos and, well, clown shoes only in their boardroom I think... no way I’d trust it for anything you’re doing.
  10. Yes they need to think about how many people can work at home comfortably and safely, which is very different to how many people can manage in extraordinary times. I’m actually quite pleased with how our IT infrastructure has coped where I am. I was part of a project to deliver remote working for our worldwide group, doing things like handing out 1500 iPhone 11s in jan/feb/early March, but it’s working really well so far for our 5000-odd people, but a considerable number of those are ‘coping’ with wfh rather than enjoying it. I do think lots of businesses will be rethinking their plans for wfh, office space requirements, that kind of thing when the world returns to normal.
  11. Do the whole lot virtually, including building images. Have you considered powers requirements running all this at home? Are you taking user data off site?
  12. I think the first approach might be to identify exactly what your requirements are. You may decide you have different requirements based around people walking around quiet site during a quiet period when the (so effectively isolated to some degree but not entirely) vs. people working on site during the holidays by themselves. There should also be a risk assessment should there not? Aim to reduce/eliminate the occurrence of this happening at all and then reduce/eliminate the inherent risk in a task where possible. Decide on appropriate response to types of risk as part of this too, and ensure that's viable also. What if the one person nominated to call an ambulance is the person who is in difficulty? Then you can look to purchase an appropriate solution or solutions depending on precise need.
  13. You can also use Intune (https://docs.microsoft.com/en-us/intune/apps/apps-add). Note that you’ll need App Store access on the devices for that to work however. I’m not convinced there will be a way around that; Microsoft, Google and Apple have spent a lot of resources on their store (and the underlying app distribution infrastructure) and using that infrastructure will always be the best way for any software management tool to deliver apps that are available in an App Store.
  14. Password protected PDF isn’t terrible in this day and age but I wanted to call out this account password fiasco. I’ll be kind to people who are stuck with a legacy system and not complain about those, but the only rational decision for implementing a new system like this in 2020 is that everyone involved in all the decisions here comes to work in clown shoes, a rainbow wig, and a red nose. I’d actually put it to them in those terms. Do 50 of them all come to work in the same shared fiat 500?
  15. As others have said, context is king here: Why do they need a personal email address? Could they mean one that is directly assigned to you at work as opposed to a shared mailbox? Other than that, I'm sure you can refuse no matter what the context - what are they going to do, send the local karate team round to beat you up? However, depending on the context (we keep coming back to that don't we?) this may not be a good course of action.
  16. Given the general squeeze on education spending/investment none of this is a surprise even if it remains a disappointment. When I left education my college was being forced to tighten up on all spending, not just IT. Luckily the campus is a fairly new build so it probably won’t fall down soon, but the lack of investment will tell in the end. Do your SLTs understand just how underfunded you are, and that compromises are already being made just to keep things turning already? For me that’s important. Managing expectations against the level of funding you have is very important. Make it clear that the current budget isn’t sustainable, that equipment is already well on is last legs.
  17. We have a regulatory requirement In some areas to ensure that all interactions between staff and customers are recorded. I don’t get involved with voice stuff especially (other than knowing it exists) but I have to consider potentially bottomless archival capacity for emails due to this. My feelings about turning on recording ‘just because it’s there’ is that this isn’t a good use of time, however having the facility easily available to enable recording if necessary may not be a bad thing. In any case, be clear with yourself and the organisation what problems are solved by doing this and which are not.
  18. In my experience cheaper APs scale less well and have management issues. That’s not to say that you should be buying the most expensive kit either, it may well be overkill to buy meraki or Aruba where ubiquiti are middle range and will do all you need, for example... but unless you’re working for free, cheap kit doesn’t save money when you add the cost of keeping it going on a sophisticated network.
  19. Several of them are connected with the releasing, or otherwise, of various kinds of hound. Also, global offices needing various things, bespoke app servers, highly redundant ‘scale out’ services...
  20. Think we've got about 5 times that in the cloud, alone. They're all quite busy.
  21. Adequate amounts of fan service for you? I liked it.
  22. You’ll want to look at rights delegation in Azure AD. https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/roles-concept-delegation
  23. ServiceNow is good, and if you're multi-site I'd think very favourably about cloud (or hosted) services that won't stop people on other sites working just because some clumsy fool in one building hoofed the wrong plug out of the wall or something equally absurd. Obviously I'd say an appropriate level of ITIL standardisation is a good idea for a large multi-site setup, whatever you choose.
  24. Not sure, you'd want to test this but you could try filling in the alternate email with their personal email and then using that to notify them? You can (and absolutely should!) configure self-service password reset and MFA to manage the password process for the future but getting the initial password into their hands is always going to be a pain in the neck unless you can give them a formula to follow (e.g. "your password is the name of the street you live on, plus your DOB in mmddyy format, e.g Washington082098"). I've had mixed success with that when I've worked in education in the past, with older students - senior high school age or thereabouts, but you will still need a service desk support setup to deal with those people who can't or won't figure out their proper password from the clues in this kind of system.
  25. It only seems simple to you because this is what you’re used to. Using Azure AD without on-prem AD is a perfectly valid scenario, and setting up AD from scratch if you don’t need it is hardly ‘simple’. Techno guy, have you seen the article on Azure AD csv account creation? You can set a password there for each account and do a fair bit there which is your best bet, then use a mailmerge of the data from that csv to notify the students as a bulk operation again. Might save you some stress. https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/users-bulk-add
×
×
  • Create New...