-
Posts
1,272 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by steve
-
It could be a little bit more than that, it might be a interface into something like Azures AI Foundry and use MS private OpenAI GPT models. Nothing on their website though to confirm / deny. I'm working on an AI implementation at my org, and there are a lot of questions to ask around these types of systems, a few of them below: Are you (reseller) hosting the models or someone else? Are the models fully private - read only, with no use of prompts / RAG to feed models? If a model is provided by a 3rd party (an API from Anthropic for example) what are privacy conditions, Ts&Cs etc. who agrees to these? Are the models in the UK / EU or globally provisioned? Where's my data being stored / processed? Many models are globally hosted, so you need to understand if that's acceptable to your institute from a GDPR perspective. Might be OK for teaching, but maybe not so much for student data analytics. e.g. using Anthropic via a 3rd party agreement could mean your data is processed in the USA under Ts&Cs you have not confirmed / seen.
-
Not tried it, but get a lot of adds in my feeds for it. But I am working on a project to deliver a similar platform: nebulaONE® - Secure, Affordable, Microsoft-based AI Gateway Would be interesting to see where they overlap and any unique selling points. Cost control and data security are 2 biggest risks we are working to minimise.
-
Its the SSO tax: The SSO Wall of Shame | A list of vendors that treat single sign-on as a luxury feature, not a core security requirement. We ditched Atlassian a few months ago (sso and confluence) due to cost.
-
I think my org now have some reasonably comprehensive guidance for all our users: Generative AI | Guidance, policies and information about using Generative AI for staff and students. This policy page might help in creation of your own: Guidance to Staff on the use of Artificial Intelligence | Governance and Compliance We also have mandatory training now too on AI use - basically co-pilot for anything sensitive is a must. I'm currently working on a project to deliver most other AI models securely via Azure AI Foundry to try prevent (limit) data exfiltration. The uptake stats and cost of this will hopefully come from a good pilot scheme. But its a tricky one no matter the org size and funding available.
-
Comtrya! Time to dust off the box set and watch for the nth time
-
Azure for Students - Anyone use this in their schools?
steve replied to Tefters's topic in Cloud Services
Yeah, shame about Azure Labs. We've been looking at DaaS with Virtual Desktops: Simple, Secure, and Affordable | Apporto Still early days though so no feedback on the service yet. -
Azure for Students - Anyone use this in their schools?
steve replied to Tefters's topic in Cloud Services
If I recall correctly, you'll need an Azure enterprise tenant for your org. This will need Entra ID and a subscription associated to it. There's a process you have to go through to get you org recognised as an educational institute to be able to access the offer. Students need an institutional email address to sign up. So you'll probably need Entra ID account for all student users (might have this already if you use M365). Azure for Students for University IT Admins | IT Should Just Work Microsoft Learn for Educators Program Overview | Microsoft Learn -
Azure for Students - Anyone use this in their schools?
steve replied to Tefters's topic in Cloud Services
Not a school, but we use it with Computer Science students at the uni. I don't think we pre-deploy anything for the students, just give it to them to test / build. In effect each student gets a student subscription, you can view / access them all as a global admin, and might be possible to setup policy to grant a teacher access to them all - but the student will be the subscription owner and may be able to block policy. You might be able to automate the creation of resources for students, but it would be a bit of a steep learning curve if you aren't into infrastructure as code and Azure already. -
Monopoly 50p coin released by Royal Mint for 90th anniversary
steve replied to 6Foot2's topic in General Chat
Having just done the Monopoly board pub crawl in London this weekend for my 50th Birthday, I might just treat myself 😀 -
TP-Link Omada & Cambridge University Selwyn Colleges
steve replied to TP-Link_Joe's topic in Wired Networks
I've been looking at Omada and others for an upgrade to my home / office setup. Is there any commitment from TP-Link of lifecycle of devices and supply of firmware updates? -
I've recently started to have a play around with proxmox. Great so far easy deployment of VMs, containers etc. I bought a couple of cheap Lenovo mini Pcs off ebay. Lots of pre-created scripts that will let you quickly deploy a big array of options: Proxmox VE Helper-Scripts For cloud I'd have a look at developing your IaC skills. Look at something like terraform or OpenTofu with Git / GitLabs. Once you abstract yourself from the GUIs for deployment it doesn't really matter to an extent which cloud provider you're working with. For managing and maintaining VM configuration most things have moved to the cloud for clients (Intune / JAMF / etc). Ansible / chef are potentially things to look at for Linux. For non specific OS management and security have a look at STIGs: Security Technical Implementation Guides These are definitely what we are starting to move towards - using published security baselines for hardening of systems. And it doesn't really matter to us how we get the baselines on, we want to know they are applied and that they continue to be applied - be that in Intune, group policy, ansible, Azure Machine Configuration or any other management tool. Other than that in general I've not really found any vendor agnostic training out there for free. It tends to be geared towards certs or use of a particular cloud provider. Maybe have a look at the various cloud well architected frameworks, these can be a bit more generic about how to design, build and manage cloud services - I've used ChatGPT at times to pull these together and make it a bit more vendor agnostic or look at the differences between them.
-
Wondered if anyone else can check this behaviour on their Azure tenant: You should be able to set "Encryption in transit" on an SQL server (PaaS) to TLS 1.3 - Connectivity settings - Azure SQL Database and SQL database in Fabric | Microsoft Learn I've tried on 2 different tenants (uni and personal) and 2 different regions. Tried the portal and cli. I only get the option for TLS 1.2. I could swear I've changed this before when testing connectivity to a new app. Can anyone else see TLS 1.3 as an option? Or am I loosing my mind and doing something crazy.
-
John Savill's YouTube stuff: https://www.youtube.com/@NTFAQGuy And others have said the MS learn stuff. Some of the modules you create a sandbox Azure setup giving some hands on experience.
-
I've recently upgrade our universities Body Worn Video System to Motorola equipment / software and you can have a pre and post record buffer, so when the button is pressed it stores the previous 2 mins of footage. When docked they automatically upload any captured footage to a central server and remove the local copy. Ours are used well by our campus patrol staff. But I agree there would need to be a significant management overhead if used by teachers who often have other things on their mind. Would be more cost effective to have better fixed CCTV and body worn cameras only used in specific circumstances such isolation units and high risk situations.
-
Personally I don't think the comms channel in itself is a bad choice, its they way in which its being used. I'd suggest that you look at how you might be able to make it more enterprise compliant - easy to search, easy to monitor, no single points of dependency (widen the pool of responders), ensure if the mobile is lost / mislaid you can continue to work and work securely. Those are some of the risks I'd highlight in using WhatsApp in the current way - how can the service continue if they are ill, the phones lost / broken. If its going to be used and valued, it should be adopted and de-risked. Having had a quick look at the options, you can use up to 4 "devices" on a business account for free - that includes MS and Mac store applications. I think that's where I'd start, get visibility on more systems, it would probably remove any personal use of it too if it was known others can monitor the use. Beyond the free 4 devices, there's an API version (free 1000 message per month) but for that you'd need an application to integrate with it, something like https://respond.io/ @$79 per month for 5 users. This would give a more enterprise style of management - data exports, MFA sign in, developed access and visibility.
-
Hi, It sounds like you're configuring Privileged Identity Management (PIM) in Entra ID. I'd recommend you have a look at this training video: and other John Savill videos on the subject. You can mix and match Eligible and Permanent Assignment in PIM, we do this a fair bit where a users is persistently needing a certain level of access but others only need it occasionally. Given the power of global admin access, we don't give any standard or admin users global admin rights permanently. Only our break glass accounts have this. Our senior admins have secondary admin accounts which are able to have the global admin role, but need to be elevated for up to 8 hours at a time. Some senior admins can elevate their own access via their daily driver account access (which have PIM approval roles), others that need global admin less frequently need approval from more senior admins. I appreciate being a persistent global admin can smooth the way in a busy resource limited team, but I'd suggest considering the principle of least privilege. Only have the access you need for the least amount of time necessary.
-
Not used Cloudnext but we are looking at https://wasabi.com/ for large volume data off-prem.
- 1 reply
-
- 1
-
-
Rare Steve phenomenon and Northern Lights dazzle in UK skies
steve replied to 6Foot2's topic in General Chat
I am a phenomenon- 4 replies
-
- 1
-
-
- aurora borealis
- bbc weather
-
(and 1 more)
Tagged with:
-
I've used a fair few at work and home. I have a very expensive one at work, use some hot desking around and I have a couple of others at home. Most recent purchase was one of these for home: https://www.amazon.co.uk/gp/product/B07K414CSX For the price £200, its actually really good, nice and sturdy, good range, programable.
-
Lots of memories around the old blank cassettes. The cling film with the red tab, the plastic cases - sometimes a nice smoky brown, the card inlay, stickers you put on yourself (often a bit skew-whiff). I'm sure that's why some people have gone back to the old formats, the tactile nature of them, the anticipation and act of making a purchase. It was much more that clicking on a virtual button on an app. But I've grown lazy and Spotify is just too easy. No going back for me
-
From what I can recall our Azure tenancy is tied to our Enterprise Agreement code, that in turn allows any subscriptions created under that to have the associated discount pricing - the discount is minimal btw. Where you can split your prod / non-prod workloads. Use a dedicated non-prod (Dev/Test) sub for non-prod stuff, they get lower pricing but have different SLAs. If you are starting from scratch, have a look at https://learn.microsoft.com/en-gb/azure/architecture/ The cloud adoption framework, well architected framework, enterprise scale stuff may be overkill but lots of good practice. See if you can get a good price under your MS licensing for a Visual Studio Enterprise license that includes the $150 per month credit for your dev/test work. I think ours are about $500 per year.
-
Azure Virtual Desktop - thoughts about how realistic it is
steve replied to Millgate_Victoria's topic in Hardware
Can you clarify? What are paying our staff on average or what are we paying for AVD per member of staff? If its staff salaries - we have a lot of IT staff at the uni, 350-400. Salaries range from apprentice minimum wage to CIO £100K (guessing). Finger in the air, about £40K average? AVD per person - well we have 10K staff, 40K students. We provision (expanding pool) typically up to 400 users concurrently. Worked out at about £167 per concurrent user per year. But AVD is only a part of the end user compute offering for us. We spend much more on other things like VPN, application virtualization (Apps Anywhere), hardware, etc, etc. Our Azure bill alone is probably more than double most primary schools yearly budgets. But the uni has a turnover of almost a billion a year. -
Azure Virtual Desktop - thoughts about how realistic it is
steve replied to Millgate_Victoria's topic in Hardware
Not looked at it in our uni for a little while, but over COVID we had one of the biggest implementations in Europe. Probably not any more as its been scaled back significantly as people have returned to the office / gone hybrid. Our use now is primarily for hybrid worker access to core systems where we don't want data leaving the organisation, for access to line of business applications from personal devices, and for student access to teaching and research related software they can't run themselves (e.g. Apple device owners). Microsoft are constantly improving the service and the supporting bits around it. We have found the main issues are around the quality of the applications you install on it - Windows multiuser isn't always happy with poorly written memory hogging software. And the cycle of updating the underpinning image(s) can be a pain - but that could probably be minimised using some good IaC automation. If you are considering retaining user configuration, you'll need fslogix to store profiles separately from the host pools. Other things to consider are what other services you have that you are expecting users to want to access? Are they all in Azure, do you need a link back to your on-prem systems? What's your wider end user compute strategy, where does this fit with VPNs, BYOD, etc. How will you configure and manage the underlying VMs - we still use AD and GPOs as Intune has its challenges around consistency between hosts. Cost wise its much more effective at large scale than DaaS like Windows 365. -
We tend to only have RACIs in our service definitions. And then we identify the team for each task (e.g. service desk responsible for first line support). But I guess it depends on your scale, how many teams / roles there are? What's the churn like for role descriptions / team structures? How well are you cross skilled?
-
I brie what you did there
