-
Posts
2,734 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Roberto
-
New Staff Laptops - Windows 11 - Local Domain or Intune Managed?
Roberto replied to newpersn's topic in Cloud Services
Intune is a good bet, but I would suggest it needs a bit more planning than it sounds like you have done so far to get a good experience. -
You're asking if EntraID Connect can run in a cloud server in Azure or whatever? Yes this is absolutely fine. I'm syncing about 100,000 objects that way with no issues. Have you looked at Cloud Entra Connect, the new 'serverless' agent based sync? If you don't have anything that represents a hard requirement for Entra ID Connect server (hybrid exchange springs to mind) then this may fit your needs better? One thing to mention as you talk about migrations is that Microsoft will only support one Entra ID Connect server being the 'live' server so you cannot have multiple Entra ID Connect servers in multiple forests syncing to the same Entra ID tenant (well it will probably work if you don't do any writebacks to AD, but its absolutely not supported and microsoft support will point at you and laugh if you log a support call to say you've done this and banjaxed something). This sort of requirement is one thing that cloud connect will support that the traditional server will not. Again, with an eye to migrations as you mention it, I think its the default now for source anchor but make sure you're using MSDS-ConsistencyGuid as your source anchor for the sync.
- 2 replies
-
- 1
-
-
- azure
- cloud server
-
(and 3 more)
Tagged with:
-
Conditional Access? Probably not.
-
You have a requirement to protect the data in those emails, right? So with that in mind you probably have very little choice about this, you either block access to this data from personal devices or you require some kind of device (or app) management with your MDM or MAM solution of choice. As you mentioned O365, intune would be an obvious route for this as it supports both device and application management - you can require an approved and managed device and/or app to access the O365 services, use conditional access to block access from unmanaged sources, and go from there.
-
Azure AD, Fortinet Filtering
Roberto replied to Alawil's topic in Internet Related/Filtering/Firewall
Been a long time but I’ve used clearpass for user auth with radius on WiFi before. Perfectly possible. -
Sometimes the objective isn't to make it impossible, but to make it impossible to do easily or by "accident" - which would be useful if disciplinary action were taken. Or to increase the amount of effort necessary to deter the casual rulebreaker. This is similar to securing your home - if someone is determined to get in they will but you can do things to make the casual burglar decide to burgle the house two streets over instead of yours.
-
Copilot for M365 - I've found it quite good for taking notes in meetings, letting me knoww the action items after a meeting, etc. - Quite good at "tell me what I've missed" or "What's the status of Project X" after a few days off. - Not sure I'd trust it to rewrite content, though it is quite good at making some of my overly-wordy prose more readable on occasion but it needs to be carefully proof-read afterwards if you need technical precision. - There's a bit of sticker shock - $30/month/person which quickly adds up, though I think its easy to demonstrate more than $1.50 per person per day of value once you start using it.
-
A quick, er, Google search tells me they published a lot of mealy mouthed stuff about how good their program is but I didn't find anything on what would happen post EOL... though I'm inclined to ask what you thought would happen. 4 extra years of use post EOL for a device that's entirely online is hardly bad. No one should be buying devices without thinking of how they will be supported in the future, including things like replacement planning.
-
I'm feeling a little upset by the way you've phrased this like a challenge to me - like it's my fault it's difficult to do, or something. I'm not associated with any organisation mentioned in this post just to be clear. So... I can absolutely agree that its a difficult and expensive exercise for schools. We have a team of specialists that handle this where I work. I'm not one of those people though I do work closely with them on some things. These are resources your average school will not have, or even a small to medium MAT. Of course when LEAs were still a thing, then you'd have access to a specialist team in the council... In any case, it's absolutely on you (well, your org) to make your own determination based on your own needs and appetite for risk. I would suggest you should be doing something like a DPIA for every project or service you have that holds or processes data. Good vendors should have details on how they store and process data available either publically or as part of the proposed contract you sign with them. They may have things like a SOC 2 Type 2 report that detail some of their services and competencies. It's not easy. But it's doable.
-
Makes sense. My insurer added her to my insurance for the rest of the year, for free. Obviously the right choice.
-
As suggested by PotNoodleTech, Andrew and Davit, I'm going to see what it would cost to add her as a named driver to my current insurance. I was under the impression everyone had to live at the address the car was normally kept at but I guess not. thanks for everyone's replies.
-
Just a Kia Picanto, so nice and small. And while I say "Stepdaughter" - she's a woman in her 20s whose family needs two cars for about a month, not a teenager learning to drive - so temporary cover that was more than I pay for a year's cover surprised me when I went looking for myself.
-
Wonder if anyone has done this or has any ideas? My stepdaughter needs to borrow my car for a few weeks while I’m not using it. She lives elsewhere with her husband so I can’t add her as another driver who lives with me. So effectively I (well, she) need temporary, fully-comp car insurance for about a month. What’s the best way to do this?
-
Yeah, the clicking is indicative of a mechanical hardware fault. I’m guessing that if you had backups you would not need to ask. DMJ’s suggestion is a good one but if it’s a lot of data and you really need it then I’d be contacting a data recovery company
-
This hard drive is no more! It has ceased to be! it’s expired and gone to meet 'its maker! It’s an ex-hard drive…
-
You are always responsible for your users data when you are the data controller IIRC. You can have a contract that requires your data processors to enforce a very stringent set of processes and all kinds of penalites for breach but you can't abrogate responsibility for your users' data. The processor is responsible to you, you are responsible to your data subjects. They have the same responsibility to each individual school or other org to which they have a contract to be a data processor (I am making a lot of assumptions about their agreement with schools here but my assumptions being broadly correct would explain their attitude). Their level of responsibility, whatever it is, whatever you or I think it is, does not stack because they have more customers - they have an individual contract with each of their clients to do an individual job for each client. You say they are "trusted" - how are you making that determination? What does your contract say? What audit controls do you have in place to ensure that you can trust them? Have you got a SOC 2 Type 2 report for them? I'm not trying to have a go at you here, and speaking hypothetically rather than any particular vendor, I would take a dim view of anyone who I thought might be trying to baffle education customers, who may not have experienced DPOs to hand, with BS and legalese rather than being open and clear and would place the blame with them rather than with the schools for things like this... but that doesn't change the obligations on the schools as data controllers for their pupils, staff or parents' data.
-
What does your contract with Classcharts say about your data. If you are the data controller and they're merely processing your data for you, then one could well say that it's up to them to report an issue to you, then it's up to you to decide if there has been a breach, then it's your responsibility to report the breach to the ICO, not them. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/contracts-and-liabilities-between-controllers-and-processors-multi/responsibilities-and-liabilities-for-controllers-using-a-processor/
-
DHCP Server and WiFi password
Roberto replied to Supermanpunch786's topic in Learning Network Manager
Mine is ******* people will never work it out! -
welp, VMware is dead to me...£3920 per year! 5x the old cost!
Roberto replied to chazzy2501's topic in General Chat
IBM would like a word: https://en.wikipedia.org/wiki/VM_(operating_system) Totally agree with your comments on HyperV - @Norphy and I did this quite some time ago for our then employer, and while I think it was hard work and should not be taken for granted, I wouldn't say it wasn't a problem per-se. -
That's absolutely correct and is likely to remain so. However, as others have noted there is an Apple event today that is almost certainly going to change the iPad line-up, so while I would expect the gap between the basic model and the air to continue (after all, they're different tiers of product, not simply what Apple felt like calling stuff the year that thing came out), the details may very well be about to change for the spec at each tier.
-
Same. It’s either unbelievably bad or unbelievably good. No in between at all. I’ve had one call where I ended up speaking to the dev team for the feature I was having trouble with, and another where I might as well have been speaking to Cletus the slack-jawed yokel.
-
There are solutions to alerting out there that are resilient - https://www.everbridge.com/solutions/business-operations/ springs to mind. If the data needed for registers was stored natively (or possibly lists generated locally and saved to cloud after registration) then the data can be available online in the event of a local building fire/power issue, then you have access to the data via 4g/5g phone services for taking registrations electronically...
-
Someone at work discussed the housing association as an example of bad practice in general and ICO action, and I thought it might be of interest here as I think the ICO may see housing associations and schools trusts as similar in some ways. Reprimand: https://ico.org.uk/action-weve-taken/enforcement/clyde-valley-housing-association/ Press release: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/04/housing-association-reprimanded-for-exposing-personal-information-on-online-portal/ This is something I might wave at a service provider whose procedures seem lax or use to justify better training and procedures if I were responsible for data protection in a trust...
-
Help implement an efficient wireless structure
Roberto replied to Username101's topic in Wireless Networks
Fewer SSIDs. More than three is too many imo and I'm struggling to get above two for your use case. You can assign profiles for devices based on a number of factors and this below is roughly what my employer does with two SSIDs for about 8000 devices in our main building. Org-owned devices go on one SSID, everything else on the second SSID. Looking at your requirements, I'd go: SSID 1 / "Corporate" A main SSID for domain joined devices only, with access to multiple vlans for resources etc. SSID 1 / "Corporate" A SSID servicing staff iPads. SSID 1 / "Corporate" A SSID servicing pupil iPads and interactive screens (I'm not sure why you think these are different from Staff iPads, assuming in both cases you're referring to devices issued by the school...) SSID 2/ "Guests" A SSID for the non domain joined PC's where it can be secured off our main network through a VLAN SSID 2/"Guests" A Guest SSID where staff and guests can get 'unrestricted' (to a certain degree) access.
