-
Posts
2,734 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Roberto
-
Guy I work with, a contractor with his own limited company, has his company logo on the inside pocket of his suits, then claims tax relief for the company uniform. I think you and your staff ought to be fine if my colleague can make that one fly.
-
I presume you have a DPIA signed off that justifies this, that you have warning notices pinned up, that you’re exercising strict controls on who can access the CCTV + Audio data, and for what reasons.
-
Entra ID Connect just syncs. It doesn't look at account licences. If you can (can't remember what the version numbers are for this) export config prior to your upgrade. Also check if you have any custom AD Connect/EntraID Connect rules in place before upgrading as those can occasionally be problematic. Also take a note of any errors in the sync metaverse beforehand so you can see if things are the same afterwards - or ideally better!
-
Fortinet wireless woes
Roberto replied to gerardsweeney's topic in Internet Related/Filtering/Firewall
This seems like a fairly fundamental thing for them to have missed if it really is that the Fortinet box is undersized. Is it also acting as a firewall? DPI absolutely killed performance on the Fortinet box I got annoyed with back in the day. -
Fortinet wireless woes
Roberto replied to gerardsweeney's topic in Internet Related/Filtering/Firewall
I've had... mixed experiences shall we say... and therefore mixed opinions of Fortinet. That said, this does not sound anything like normal expected behaviour. Is this a 'Windows-only' problem? Can other devices connect ok? Are there any clues in the event logs on the workstations? Issues with contacting authentication servers? If you're authenticating users with RADIUS, any errors on the radius server logs? Where is the support from the installers in all this? Surely this was tested during the install and handover process? -
Do you have an Office 365 admin accout as well a normal user?
Roberto replied to nicholab's topic in Cloud Services
I think I have at least 3 accounts. One for daily driver, one for cloud admin, one for on-prem admin. I do admin work in a private browser session. Or a different browser. Not sure how many portals need you to have a licence. Off the top of my head, I think Intune did at one point but there's ways around that now. -
They want to put Windows 10 to bed, clearly.
-
Rate may vary for edu, but I've seen hints of £61/device/year to continue Win 10 support.
-
Remember that a Team is a group, a M365 group. If you can add users directly to the group associated with the team with a script or whatever then you're golden.
-
^ bet that’s it. Can you paste the first two lines of the csv file here?
-
I’d listen to Martin Lewis ahead of Ramsey, if only because Martin is a Brit, offer advice centered on British economic and financial planning, but it’s good to be planning ahead for your future. I’ve done a bit of work on my retirement planning of late and have a few pensions spread around, including about 25 years LGPS which should do ok for me, current employer has a really good pension plan alongside company shares that are doing well… right now at least. I think it’s important to be interested in the future!
-
There's quite a lot of criticism of Dave Ramsey's stuff out there if you look. The general consensus is that he might have great ideas for people truly at the bottom of the financial hole, but as a design for life, not so much.
-
I think you might have one or two OUs excluded for local accounts, leavers, or whatever, but by and large AD connect should be scoped to most or even all OUs. AD Connect Delta syncs should run every 30 mins or so on a normal basis and while you can manually trigger a sync more frequently if you need to do so, you shouldn't need to do that too often. I think you can change the scheduled sync but 30 mins is the most frequent option. Password sync should happen more frequently, every 2 mins as has been said elsewhere. It might be worth looking in Entra ID at the Entra ID Connect setting in there to see what it thinks is going on with sync server health, etc. I'd paste a screen shot to show you what I mean, but unfortunately one of my colleagues has nuked my dev environment and I can't share anything from prod.
-
Ok. When you create (or change settings on) an AD Connect connection, the first sync that runs on that server, the "initial" sync if you will, will be a full sync. Additional syncs on that server are Delta syncs. I've seen passwords take a while to sync in exactly the way you describe when a full sync was in progress. So, is a full sync in progress? With regards to logs, when you attempt to change a password, there should be logs in the event log on the AD connect server pertaining to the password change. Can you see them? So the password sync is taking place, but slowly. How familiar with AD Connect are you? Are you familiar with the Synchronization Service Manager? That should show the sync progress, errors, etc. I really feel like the solution, or the beginning of one at least, might be there.
-
What's still syncing? How is password sync configured? If your initial sync is running still then, iirc, normal password sync won't work until that's completed. What do the event viewer logs related to password changes say on the AD Connect server?
-
Indeed - I was trying to say I think Microsoft have designed intune to solve my problems, not your problems. It's bad design tbh.
-
I'm not in edu IT any longer. I work for a global business. We're in... I can't even remember how many countries we have a presence in... and setting up SCCM DPs globally is possible but a massive pain in the backside and when you only have two or three people in a region, it's disproportionate to what we need... so at that point Intune + Autopilot starts to feel pretty groovy actually. I've set up autopilot processes to support people in every continent in the world. Well nearly every continent - not sure if the poles are continents or not!) I think we have a similar architecture to Microsoft themselves. So essentially they're designing their infra with an eye mostly on themselves and businesses like them these days.
-
I love intune. I'm in a use case where it does make significantly more sense than something like SCCM. However, it's painfully apparent that it lags far behind SCCM in terms of how many ways it allows you to solve problems. Reporting needs work. I think it's going to replace SCCM at some point and I wouldn't advocate for setting up a new SCCM org at some point... but to someone who has a well specified, well maintained SCCM infrastructure that meets their needs I wouldn't suggest going any further than co-management at this point. ... and that's before we even get on to it not being that well suited to schools because they more or less assume 1:1 user to device ratio... which is fine for me now but really not helpful for education.
-
Only a guess, but they're probably a crowdstrike customer. https://www.theregister.com/2024/07/19/crowdstrike_falcon_sensor_bsod_incident/
-
Is BitLocker encryption compulsory for schools?
Roberto replied to aia125's topic in Data Protection & Information Handling
I doubt any high level standard is going to say "You must use PRODUCT NAME", so you probably won't find a requirement for "bitlocker". Having said that, you probably will have requirements to keep the personal data pertaining to sdtudents and staff secure, and if data is stored on a end-user device such as a Windows laptop, bitlocker may well be the cheapest, easiest way to meet the requirement. So, unless your data is stored on Windows 365 devices so is never on the laptop, or unless your laptops are Chrome OS, MacOS or Linux, then as others have said "why not Bitlocker"? -
Isn't UE-V Deprecated? - I wouldn't be doing much new with it at this point...
-
Opinion - Whitelist local authority e-mail domain
Roberto replied to InspireICT's topic in Cloud Services
This alone would earn them a two line reply from me: lol. No. You have to consider the risks to your students if they’re a likely attack vector for malware and scammers. Obviously you can’t block or ignore them, but I’d be very unhappy at the idea that their emails don’t need proper scrutiny given what you’ve said! -
I think autopilot/Intune is fantastic for what we use it for where I am, but it’s clearly a design by Microsoft that assumes everyone is *like* Microsoft - a global org with 1:1 devices and hot and cold scripting ninjas on tap if necessary to do something clever. In many ways it’s better than SCCM from the architecture/strategy view, while still having loads of gaps at the sharp end where something that was trivial in SCCM is difficult or impossible right now in Intune. Its benefits revolve more around not having device updates fail in Myanmar because the local SCCM DP went wonky and there no techies in that region at the moment, or worrying about how your “standard” laptop model isn’t available in Belize. Those are real problems btw (my last two weeks have been insane) but probably not that common for most of their customer base. Bit like “one size fits all” clothing - technically possible, but it won’t fit anyone well.
-
I don't know if it will work but I think this makes sense if you consider that Leslie Nielsen had built a reputation as a serious actor before doing comedy in movies like Airplane. Part of the appeal I think was the cognotive dissonance of seeing Serious Drama Actors doing comedy like that.
