Jump to content

Koldov

Members
  • Posts

    5,084
  • Joined

  • Last visited

Everything posted by Koldov

  1. Thanks! What edition of Google Workspace are you guys on? Yeah, it's the second link where it starts to go funky... It seems to redirect me to a different URL than the first (where it 'should' actually go). Also, it gets stranger... when I hover over the link in the Google search page it resolves to: https://support.google.com/a/thread/38689646/implement-account-lockout-for-g-suite-accounts?hl=en When I'm signed on as my standard account it takes me to that URL and I can see the help article. When I use my Super Admin account it takes me to: https://apps.google.com/supportwidget/articlehome?hl=en&article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fthread%2F38689646%2Fimplement-account-lockout-for-g-suite-accounts%3Fhl%3Den&assistant_id=generic-unu&product_context=38689646&product_name=UnuFlow&trigger_context=a It's like it is trying to do something special with that URL because it acknowledges I'm signed on as an admin maybe, but fails to do anything with it (because maybe I'm supposed to have a 'Support Widget' installed?)... I can't upload screenshots either... maybe it's a Friday afternoon thing and it's telling me to forget about it until Monday!
  2. Just researching something on the internet and came across a search result from 'Google Workspace Help', on the search page it seems to point to: https://support.google.com but clicking on the link takes me to a different URL https://apps.google.com/supportwidget/articlehome?hl=en&article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fthread%2F38689646%2Fimplement-account-lockout-for-g-suite-accounts%3Fhl%3Den&assistant_id=generic-unu&product_context=38689646&product_name=UnuFlow&trigger_context=a However the title is there and the rest of the page is blank. If I cut the URL down to: https://apps.google.com It takes me to: https://workspace.google.com/ If I cut the original URL down to: https://apps.google.com/supportwidget It takes me to a page that says: "You don't have access to this service. To request access, contact the administrator for your organisation’s Google services. If you’re a Google services administrator, you can turn on services. Learn more" Not very helpful, what 'service' am I supposed to turn on...? If I try the main URL with Edge and not signed in it prompts for sign-in. But the user I'm signed on with in Chrome is a Super Admin, with 76 of 76 Google Services on and the OU has all additional Google services on... what am I missing? Is it to do with being on Education Fundamentals? I wonder if this is tied in to one of my previous posts about not being able to see any info in the 'About this result' box when clicking the 3 dots next to a search item...
  3. This? https://www.amazon.co.uk/blink-sync-module-2/dp/B08BJ9ZCZC Seems to only support motion 'clips'...? "Record and store motion clips when you insert a USB flash drive (up to 256 GB – sold separately) into the Blink Sync Module 2. Does not support live view recording."
  4. A camera attached to a non-networked NVR seems a little overkill for one room (unless you can get something very cheap and cheerful - which would probably bring its own problems), might as well have a spare laptop, tablet, iPod, or mini PC with a webcam. As the school has no site-wide CCTV and obviously for some reason has never felt the need to have any installed... I presume this is only to be for safeguarding of the child and some sort of protection for the staff member (and not to view in real-time or keep the area monitored 24/7 for break ins etc.) would some sort of consumer grade stand-alone device work that only records to a memory card and mounted out of reach (I'm thinking 'spy cam' style but obviously not an actual 'spy cam').... Obviously, this has the downside that it is much easier to 'tamper' with, or 'forget' to turn on but that's got to be part of the process of weighing up the pros and cons.
  5. Just signed up, tried to watch a film and was immediately location blocked (QR code to scan). I'm guessing that's got to be par for the course? Cisco Meraki SM does the same because our devices are only ever on Wi-Fi (although I've entered in our public IP to be the 'home' location). What would be the way of determining someone's location if the network node (ours is LGfL) shows London and we're in Bedfordshire? @Jawloms did you just send a message to their support?
  6. We've always had all our domains with Heart Internet registrar. They had no problem taking on our .sch.uk domain.
  7. Tough crowd... but then I'm not sure what response was expected. Especially as this 'advertisement' (even though it fell flat) post does not belong in the Technical forum (MIS Systems Thread), I'd hoped a mod would move it somewhere more appropriate.... answers on a postcard please...
  8. Could have been something else going on here as it was an advert on Facebook (sometimes as I'm scrolling through there will be an advert post with a selection from a retailer where you swipe along to see the products). Only a phone screenshot though and it was a long time ago, so I can't remember if I actually visited the site to corroborate (as always good practise is not to click on these sorts of things). Not sure what the point of the vinegar is... maybe it makes the guitar sound more acid-house..? Left a bitter taste in mouth, that's for sure...
  9. So just to clarify, if you are on an LGfL network, FSRM (which I believe uses port 25) will work when pointed to the LGfL mail relay, but when pointed anywhere else will fail. Yes, that makes sense, it just always got through on O365, so I've never needed to configure SPF on the sending domain .
  10. Thanks, yes I've always worked on the premise that if the setting was actually there then you could use it! Don't even know why I asked really, just got a lot on my mind and second guessing everything!
  11. Which setting actually worked, or did you need both? Just out of interest the first setting: Configure the color of the browser's theme "This policy allows admins to configure the color of Google Chrome's theme. The input string should be a valid hex color string matching the format "#RRGGBB". Setting the policy to a valid hex color causes a theme based on that color to be automatically generated and applied to the browser. Users won't be able to change the theme set by the policy. Leaving the policy unset lets users change their browser's theme as preferred. Example value: #FFFFFF" Did you set that, or did it not matter (and if you did what did you set it to?). I presume 'Allow users to customize the background on the New Tab page' is just set to 'disabled'? Edit: Also, are these OK to be set as 'Computer' Configurations and not 'User'?
  12. Good shout! I have resisted iOS 17 due to various issues that have been posted, I only saw the other day the latest GB requires it!
  13. Ok, so it was just the fact that if that is true, but @PaddyNewman says port 25 is blocked on the LGfL firewall, how does FSRM send OK when using the LGfL mailrelay...? It must mean that port 25 isn't blocked between us and LGfL (or at least the mailrelay - only to the outside world). Another thing is (and I seem to remember it was another reason I started looking at this) when I set my new GMail account to be the one receiving alerts from FSRM (using the LGfL mail relay), Google rejects it. I guess the LGfL mailrelay messes with the header? Or the sending account I'm using doesn't have something set-up correctly? "Messages missing a valid Message-ID header are not 550-5.7.1 accepted"
  14. Just a thought then... What if for some reason FSRM is trying to send on port 25...? The last couple of internet searches I've done for FSRM > SMTP have mentioned port 25! If it was sending on port 25 (although you say it's not allowed), could it go on that port to mailrelay.lgfl.org.uk (as the LGfL relay works with FSRM)? Because I just used telnet from my server to mailrelay.lgfl.org.uk 25 and it connected... and weirdly 465 & 587 failed... Or is there something else going on and I'm going to look stupid when you explain how it actually works...?
  15. Yup, you'd think so as this is exactly as I've set it up in GW (and I'm guessing @fiza has done the same)... In section one (1. Allowed senders - Only addresses in my domains) I presume it means you need a 'user' account to send from/as and I have created a user for this purpose, which I have entered in FSRM. In section two (2. Authentication - Only accept mail from the specified IP addresses) The IP address is the Public NAT address (this was also returned in the telnet query so I know it's correct). I just have no idea what else could be wrong... obviously the error message returned from FSRM isn't explicit enough for me to know 'why' it can't connect to the remote server!
  16. I can Telnet from the server to both smtp-relay.gmail.com and 74.125.133.28 which I found from an NSLOOKUP (but returns 28250 for some reason). Port 25 does not connect Port 465 gets me to a blank screen (so connected?) Port 587 gets me to a connected session and returns the EHLO details in the screenshot...
  17. Many thanks for your input as always @PaddyNewman - I will probably take you up on that offer when I get 5 minutes spare... I am also grateful for all the other suggestions, however I would really like to try and simplify things mainly for my own benefit (but for anyone who takes over). I do look at all the wonderful (and sometimes slightly left-field) workarounds to find ways to do what should be the simplest things... Sometimes it's just the workaround means setting up and learning a whole new process! Unfortunately even if documented somewhere, these are always the things that trip me up 3 years later when either the OS get an update, or I change a setting to do something else and bring everything to a grinding halt... The thing is I never seem to have the time or resources to ever actually get to the bottom of the real problem, just deploy the workaround and move on, without ever actually solving the problem... The message in event viewer is the same as @fiza had on another thread which says "A File Server Resource Manager Service email action could not be run. Error-specific details: Error: IFsrmEmailExternal::SendMail, 0x8004531c, Failure sending mail.: Unable to connect to the remote server" So that could mean firewall (possibly LGfLs as it never had a problem getting to the LGfL relay)? Unfortunately, I don't know the process or the ports FSRM is using to send the message as it's a very basic interface with no configuration options. Or something on the Google side rejecting it, which might return as being unable to contact the mail server? Again, I've read the Google help pages and set-up what it's telling me to do, but I don't really know if I've done it correctly.
  18. @fiza did you ever get this working?
  19. I hope it is! Not only for me, but I don't think FSRM allows any configuration/authentication at all (not sure about FMS at the moment).
  20. I'm so confused! We don't use this function much, so I've never really got to grips with how it actually works... Firstly we have FMS sending BACS, then we also have FSRM on the server sending notifications. Both currently use the LGfL mail relay. I can only currently see 2 options, so I'm looking for the easiest one obviously! 1. Change the LGfL relay settings to deliver to/from Google GMail accounts. 2. Somehow work out how to do this through Google Gmail setting and not use the LGfL mail relay at all. Of course I don't actually know how to do either of these things, in fact thinking about it now FMS BACS emails might have already started messing up with some of the other things that are happening around DNS and us losing the old email accounts that were being used. Anyway, if anyone can give me the ELI5 version of what should be happening that would be appreciated... If FMS sends an email to the LGfL mail relay, then that sends it on, using a 'from' email address (that we no longer have access to) that is listed in LGfL as one of our Domains... If FSRM sends an email to the LGfL mail relay, then that sends it on, using a 'from' email address (that actually doesn't exist)... I thought it was some sort of alias within the LGfL settings, but can't find anything there now! There does appear to be some sort of DNS TXT record on our Domain host for this, but I think this is only for mail going the other way as it seems to forward email to the domain on to an LGfL mail account. I really want to stop everything being so complicated and try to streamline this process to stop myself tripping over it further on down the line and really try to centralise it all onto one platform. So I guess do it all through Google?
  21. Just for completeness... and for future reference when I've forgotten all about it... I tried 'Any envelope recipients' and it didn't work**, so I chose 'Location: Recipients header' in the end and 'Contains text: olddomain.co.uk'. Anyway, it seems to have done the job! **Maybe because it's SMTP forwarding and not Inbox forwarding? Also I thought I'd seen the envelope and sender can be different, so maybe if I'd put the onmicrosoft address in as it's sent 'via' that, maybe that's what is in the envelope?
  22. It's been so long I seem to have forgotten how to do this... unless it has changed? We have just had a new set of iPads, which were added to ASM/DEP by the supplier, enrolled in Meraki nicely and got profiles and apps. As I've been going through things though I have noticed some discrepancies in the version number of apps that were installed. It 'may' have been set up incorrectly as when we started with it, nobody knew how to actually use it and it appears there a few ways to view 'apps' details (on device or in network). In every 'network' I have assigned the apps in the 'apps section' and then set 'Targets' with any of the following 'Tags' I went through all the apps in every network and pressed the 'Refresh Details' button, but at the bottom of the page it still shows the targets with the old version. I tried So, for example in Meraki SM, choose a 'Network' (Year 3 iPads) > System Manager > Manage > Apps Here I chose Garage Band and clicked 'Refresh Details' and it changed from version 2.3.14 to 2.3.15, then nothing! Keep app up to date is ticked... all certificate up to date... devices have checked in... enough licenses available... Whilst I was in the 'apps' section I scrolled down and selected a device to test and chose 'Push' 'Install or Upgrade'. Went to the device and 'Activity Log' which said it was Pending a Garage Band install. Refreshed it a few times and it said 'Success'... went to the apps section on the device... nope! Still 2.3.14... Chose 'Update' next to the app and confirmed... nope still 2.3.14... So it appears, 'Keep up to date' is not working, manually pushing the update from the 'app' page is not working and manually updating from the device page is not working! Also is there a way to do this en masse for all apps on all devices (or at least per network) as doing it manually/individually is going to be a right faff! One thing I did was change the 'Source - Type Store > App source to United Kingdom as they all said United States.
  23. No, although I get your logic, strangely enough by some magic it appears to only reply to the original sender...
  24. Ah, thank you that explains it then! No, we don't control the DNS of the domain for the O365 tenant, it was set-up by a 3rd party Learning Platform company (quite bizarrely in my opinion) that all local schools had a .schoolname.schooltypetown.co.uk address. So, for example I had [email protected] and someone else had a [email protected], there was also @schoolname.juniortown.co.uk, schoolname.infanttown.co.uk, domains so each school had a sub-domain of 'their school' and the TLD was 'schooltypetown.co.uk'. All very strange and glad to be out of it in some ways, but now it all the administration and management falls on me alone... I'd got quite proficient at O365 after badgering them for admin access to Entra/Azure (because their support dwindled off to being pretty dismal as most of the other schools had left), but now all of a sudden we're on Google... and I've got to learn everything from scratch and expected to be proficient from day one! Hooray?
×
×
  • Create New...