Jump to content

Roberto

Members
  • Posts

    2,735
  • Joined

  • Last visited

Everything posted by Roberto

  1. I’d echo what FN-GM said - what process would they follow if the parents concerned didn’t allegedly “work at a school”. Great, now do that process.
  2. I think Microsoft would rather you use VDI or dare I say, Windows 365, rather than RDS.
  3. Yes. Though if you want to use M365 services, you might want to check the M365 service connectivity date on your LTSC office. Word should keep working on your device for the duration of the LTSC support period but that’s not the same as connecting to M365 online services.
  4. Not in education any more but I have been heavily involved in the adoption and development of AI solutions where I work. Below is my summary of a few rules we’ve developed (and which at least one high street bank you’d all recognise also apply to their AI use): AI output should be reviewed by a human before being shared with others or used to make decisions. AI tools should be evaluated prior to use to ensure that they meet our standards; for example, that sensitive data is not being used to train the vendor’s AI; that data is not being taken out of region (e.g. customer data that we’ve pledged to only store or process in the EU isn’t being taken outside the EU by the AI process) AI tools should respect the RBAC/access level of the user and data; e.g. my use of an AI tool like copilot shouldn’t expose data to me that my role and permissions should prevent me from seeing. That the AI tool adds value rather than being turned on just because it’s there.
  5. Indeed. I WFH a fair bit these days and haven’t noticed any difference day-to-day in performance. I’m in a London commuter town and there’s a massive difference in how busy the station is on Fridays from the rest of the week…
  6. I feel like they're trying to copy Apple somewhat, except of course that Apple only ever carry a few SKUs of each product so its easier to figure out what is going on.
  7. Precisely my point. So reducing the number of usernames and passwords they're expected to remember to interact with their school about little Johnny is a good thing. Doubly so if they have multiple students in the same school - one login to manage little Johnny and little Jessica's lunch in one place is a very good thing. Not just for them but for whoever has to support all this at the school...
  8. Will you be offering single sign-on options? E.g. integration with Google and Microsoft’s authentication services? I’d say that was essential these days, asking anyone to remember another username/password in their lives is unreasonable.
  9. Does Windows Server 2022 only support DFS-R by any chance and your old DCs haven't been migrated yet?
  10. Watched this the other day. We enjoyed it but does require you to put your brain in low-power mode as you say.
  11. They should have the roles necessary to carry out their job, no lore or less. So you might determine that a help desk operator needs to be able to unlock accounts and reset passwords, then assign them roles that allow them to do just this and nothing else. If you have the resources to manage this kind of thing, you might setup a ‘just-in-time’ system using tools like Microsoft’s PIM, which allows you to only assign roles to an admin temporarily to allow them to complete specific tasks - so my employer has previously agreed that I can be a global admin on our O365/EntraID tenant, but that role is only active when I request it to carry out a task that requires that level of privilege. [quote=Space_Munkey;2060696 If this isn't the case, then is it more common industry practice to simply have all roles delegated to a role admin account i.e: [email protected] [email protected] [email protected] [email protected] [email protected] And each IT Admin then follows a process to gain access to the password for the service admin account, which is then changed after use etc? No. Dear me, no. The problem with this approach is that it violates the integrity principle of the security ’CIA triad’- it breaks non-repudiation. If ‘anyone’ can log on with a generic role account like these then ‘anyone’ can make a change, steal or corrupt data, and you’ll never know for sure who did it or what exactly they did.
  12. Global admin is more than simply a handy way to group lots of access together, it allows you to change the tenant itself, and is a huge risk. It should only be used when necessary and not assigned otherwise.
  13. We used to use IP addresses/ trusted networks for conditional access, but I’d no longer consider that ‘safe’. Not to mention it’s difficult to manage if you have a large number of sites. Right now we trigger conditional access based on device and user state/risk, the ‘zero trust’ model mentioned above. This is both an improvement in security posture and frankly, easier to manage.
  14. Oh my friend, how I’ve missed you… I think we changed it after you left. Someone complained about looking at the same goat picture all the time…
  15. Look it another way - why do they need to bother to afford it when you’re affording it for them, so to speak. Absolutely not defending or excusing any bad behavior by your vendor here, quite the opposite, but you have removed any urgency to do better by you! I think y’all should probably develop a set of ‘supplier due diligence’ questions to ask of any supplier of pretty much anything more complex than a pack of pens, and consider how to work these sorts of questions in to that. I can’t share ours unfortunately but there’s an interesting blog on supplier DDQ here: https://www.bulletproof.co.uk/blog/supplier-due-diligence
  16. That was 'season 9' of scrubs and I think it failed because it was portrayed as season 9 of the old show and not season 1 of Scrubs TNG.
  17. I'm in two minds about this - I loved scrubs but perhaps some things are best left as they are.
  18. As others have said, I'd look at MTO. I think this will only become more useful as there are several business segments that Microsoft serve that run on acquisitions - my employer is one of those in fact - and there's a good roadmap for MTO last time I checked as Microsoft have finally accepted that there are good reasons for businesses to be related but not necessarily fully integrated. If you do want to do a full merge/integration then you need to decide which tenant is going to be the 'home' tenant. It might be one you already have for the MAT or if you don't have one for just the MAT. This needs a bit of thought - if all you have are schools with their own tenant at the moment, don't simply assume you can or should fold smaller schools into the bigger school's tenant as there may be technical limitations to that and there will almost certainly be political implications, right? And, without wishing to be rude, statements like the two below really make me think you will need help from an expereienced O365 consultant rather than trying to do this in-house - it feels like you have several fundamental misconceptions about how Entra ID and Office 365 work.
  19. If this is proper Teams or Zoom Meeting Rooms (and if it is not, I'd urge you to consider doing that), I'd look at https://www.yealink.com/en/product-detail/microsoft-teams-roompanel We have hundreds of meeting rooms deployed using either the above or Condeco (which is great but very expensive. The Yealink panels are cheap, easy to mount, robust (imo) and have great visibility of the room availability from a distance.
  20. Yeah. My first thought was about all this too. Luton has got a raw deal again.
  21. Yeah, this is exactly what power automate and sharepoint workflows were designed for.
  22. I don’t doubt your experience with Macs and HDMI to your projectors but this is the first I’ve heard of such an issue. They are using an 8 or 9 year old computer if it’s a 2015 vintage, and a 9 year old laptop of any sort might have idiosyncrasies. Logitech will have lots of Bluetooth keyboard and mouse options for a Mac. They’re all fine. They can be expensive but they don’t have to be.
  23. Hw are the devices getting updated? How was office installed and licenced? Do you have any plugins or anything that might modify office any other way?
  24. This is incredible testimony. Thank you for sharing and I hope you continue to improve. I think there's a lesson here for us all and I feel like the biggest gift we can all collectively give to you right now is to listen and learn from it. I've had a few rough years of my own - nothing like this but to share my own story about stress... my brother is a convicted child molester. He's a former teacher, scout leader and parent and before he was discovered and stopped he managed to violate the trust placed in him in all three of those areas. I had to testify twice to have him put away. He's done two rounds of jail so far. I took it very hard. I felt very guilty that there I was, fully trained up on (heck supporting) safeguarding in my edu job, yet there was my brother abusing his children and all others he could get his hands on. I blamed myself though I had done nothing wrong, and this caused me a great deal of guilt and stress to the point where I started to self-harm and ended up being treated for depression. Even after all that I have had years of unresolved anger and guilt to work through over the guilt (undeserved I know), the shame, the sadness at the impact on my nephew and niece. It took a lot to move past it but now I have. So please if anything in my story of self-harm or anything in Andrew's story of overwork and the detriment to his health sings to you, take action before its too late.
  25. I can't share our policy and I don't think it would be helpful to you anyway, but where we work you can use your personal mobile device to access our data only with full MDM profile install, and via mandatory software (e.g. Outlook for email, not whatever app they might personally prefer). For "desktop" type access, printing, etc, you can install the Citrix client if you want to and use a citrix desktop, or Windows 365 if you're lucky enough to have that, or you can forget about it. This absolutely needs to come from management. I'd be warming them up about the obvious security risk, also going to great pains to stress the data protection risks also of data being transferred to devices out of your control, and saying (not asking) to senior leadership that they are responsible for any issues that arise from their failure to act decisively on this.
×
×
  • Create New...