-
Posts
5,084 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Koldov
-
We had IRIS (basically 2 iPods, tracking swivel mount, web interface for upload iirc), which we hardly ever used... Then the SLT decided to get Lesson Box instead, I have no idea why they thought that was any better, but it was new and shiny, probably quite expensive and came with 2 x cameras, laptop, lapel mic, all in a nice case etc. Actually it was a nice bit of kit.... that got used about 3 times...
-
Probably a really basic question (but therefore hopefully a quick and simple, unified answer).... We have a domain (sch.uk), we have an O365 tenant that uses this domain but we don't actually use it in anger as such (long story). The domain is registered to us, with our registrar (not NOMINET) and I have pointed the www DNS (A) record to the school website (different domain). There are MX records currently, but I don't see them pointing to O365, it seems that it is indicating that the registrar is processing mail (?) does that even make sense? Although we don't use it, it is dormant for if we ever do and I'd like to keep an eye on what's happening to it so have forwarded the admin email to one I do monitor (does anyone know if all global admins are notified of changes or only the built-in postmaster or admin - onmicrosoft - accounts?). Given all the above do I need to do anything with MX records, or can O365 sort itself out? EDIT: Apparently not as I am getting 'undeliverable' on test emails to a user on that tenant!
-
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
Koldov replied to Koldov's topic in Cloud Services
Yeah, that's pretty much the plan! No, it's totally random and made up, but I think they were based around the school name/county/sch/uk type address (our town is our county if you see what I mean) and close enough to get through any NOMINET checks though. Plus created and registered by ex-council I.T. dept. employee (then I.T. support for schools consultant) which must have given it some legitimacy (?). -
[ms office - o365] Microsoft word permissions bug.
Koldov replied to Mrpower's topic in Office Software
In my research iirc I did see various mentions of it happening with SMB and possibly not with AFP, however I think it wasn't seen as the answer, because AFP was being deprecated... Not sure if that's still the case? I don't think there are any massive 'light bulb' moments in those threads (still worth a read) but also in my research there were a few mentions of giving the specific Mac user (not sure how that works with multiple users) full NTFS permissions on the ROOT of the drive! I think there were two actual issues and they've got a bit mixed up in my mind, because one was definitely that the edited file was no longer able to be edited, even by the creator. Once that was sorted, I think the other issue was the creation of multiple folders every time the document was edited by the owner, creating multiple random folders (temp files/folders the OS should clean up once the document is closed), but both I think were caused by lack of permissions. -
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
Koldov replied to Koldov's topic in Cloud Services
I doubt that we would be able to in all good faith, although the registrars were very sympathetic and offered to do just that for us! At least 10 other schools have Headteacher or Admin (or both) email accounts within this O365 tenant on this domain publicised. How many are 'live' and actually being used, I don't know (but I guess I'll find out when I email them all and let them know the situation). Plus although it is registered and that gives it a certain amount of legitimacy, the domain isn't really a 'school' domain and is very generic in terms of its descriptiveness (council.town.sch.uk) so no real use to us once we have transferred those two mail boxes out and into our own. -
I decided that I should bite the bullet and update our servers last night (I'd done a couple of the less important VMs last week with no issues), so I logged on from home but it appeared that the servers had decided to update themselves, however I tried to RDP into one of the VMs and couldn't connect. So I logged into the host and went through VM manager only to find the VM had no network... After trying various troubleshooting (and checking the other VM) I remembered that a long time ago, I had done an in-place upgrade to Server 2019 on the host. This had the unfortunate effect of installing different NIC drivers and also renaming them... very unhelpful as it messed up the VMs networking. I got it sorted, but as usual in a panic seeing as these are production servers, so it wasn't documented as well as I'd like it to have been and it kind of got forgotten about as I moved onto the other issues... it seems that the restart had prompted a change in the Virtual Switch connection (which it hasn't done in previous months). So here is what my host sees as its network adapters in the Network Control Panel and Device Manager: Seems simple enough, but here is what Hyper-V (virtual Switch Manager) sees: This is the old name for the NIC adapters (#38), but as you can see only one of those old names appear (possibly the one that was in use by Hyper-V at the time of the HOST upgrade)... and the 'new' one, but annoyingly the 'new' name of the other adapter doesn't even signify which #no. it is (#39 or #40)! Anyway, it appeared that the the switch manager had somehow lost the connection and the VMs weren't connected anymore because it had changed to 'Public' or something and I need to switch it back to external (trying to make sure I selected the correct adapter), so I also ticked 'Allow Management OS to share adapter' as I was remote and have cut myself off before, but it isn't usually ticked as I have two adapters, one is dedicated to the HOST and the other is dedicated to the VMs. I know it sounds stupid, but I can't really work out from the screenshots which NIC is being used by which... What I'd like to accomplish ideally is to find out why this happens, but also that the Hyper-V Switch Manager sees the correct and full names of the NIC adapters in the HOST, so I can be certain in future which one to choose as even when I try to create a new virtual switch those are the only two options I'm given...
-
[ms office - o365] Microsoft word permissions bug.
Koldov replied to Mrpower's topic in Office Software
I can't actually help you as I never really got to the bottom of it, why it happens or if there is an actual solution, as I can't really put the time or resources into it as unfortunately we only have one Mac user (also unfortunately it is the Headteacher) who is running an old version of Word for Mac... The thing is it only happens randomly and under a specific set of circumstances, but it had something to do with the permissions set on the file by the Mac and the server/storage not being able to translate that to a SID or a mismatch in the permissions it gives it. I did some research and it appear it is a known issue (and has been for a very long time), but obviously not large enough in scale to warrant a fix... I think there was also an issue with it creating a lot of random folders as well as the permission issue. The other Windows users couldn't even see the file that had been edited on the Mac though. Anyway it does appear to be similar to my issue (if not the same it might put you on the right track): http://www.edugeek.net/forums/mac/232284-office-mac-creating-random-folders-windows-server-share.html and this: http://www.edugeek.net/forums/mac/224946-microsoft-word-mac-producing-strange-folders.html Also, is this related to your previous post on a similar issue? http://www.edugeek.net/forums/office-software/232894-ms-office-365-mac-read-only-files.html -
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
Koldov replied to Koldov's topic in Cloud Services
Teachers are on a completely different tenant and domain, it's just these two legacy accounts that are on a tenant/domain that was created by the new '3rd party' I.T. support team (ex LA/LEA) back in the day when the council dropped in-house I.T. support for schools (including the council run email system). Yes, I might contact a few of the other schools and ruffle some feathers (after we have extricated ourselves from the mess, as we still need to remain on good terms with the person who holds the admin for it for now), as I had another thought over the weekend... During my investigation I found that the random (council.town.sch.uk - which shouldn't even exist) domain was created and registered by one of the ex LEA I.T. support team, who now no longer works for the council, the new '3rd party' I.T. support team and does not consult for them either. What powers does the registrant have? That was actually part of @steve_forbes original enquiry in his post wasn't it? -
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
Koldov replied to Koldov's topic in Cloud Services
Honestly? I have no idea... I can only really go on what I've been told unfortunately and the message I got was that it had been disabled. Here's a strange thing though... my BM went through the MFA process, downloaded the Authenticator app on their phone and gained access to the account... however, I can now log into the account without MFA! So, I believe yes, it HAS been turned off, however it just got stuck on the fact that it needed MFA to be set up before it allowed non MFA access... if that is even possible? The other thing is that if I try to do any thing else other than view emails, it actually DOES ask for MFA... For example: https://aka.ms/mysecurityinfo ...does require MFA, so I don't know if there are various levels? The thing that really irks me, is that in the last message where it was stated that the Security Defaults had been turned off, we got some push back... with the person stating that it wasn't 'best practise' etc. But they've obviously been happy with us using these email accounts that have never been ‘managed’ in regards to, non-MFA access, security settings/compliance/anti-spam or anti-malware policies (there was nobody checking the ‘postmaster@’ or ‘admin@’ account or dealing with any of the Azure back-end or reading any admin centre messages either), since 2014! Yes, it's a mess and we are going to remove ourselves from it ASAP now we know. However from my research I've found at least 10 other local schools that appear to have Admin/Headteacher accounts on this tenant, so I wonder if I should reach out to their IT support and ask if they're aware...? -
Unfortunately I didn't take any notice of what the logo said (if anything) before I downgraded... Can you actually use 'Activity Log' ? Also, I presume that (and I'm not sure how or why) our accounts were moved to a 'free trial' somehow, now this has expired we have been invoiced. Whether this was entirely without our permission I can't honestly say (I'm not on the communication email list from Wonde and I don't regularly check the admin portal) and if I'm blunt our BM is a little gung-ho and known to be a bit of a 'button pusher', so it's entirely possible they've agreed at some point (though not at all certain). Maybe either you've paid, or your accounts were never moved to a free trial? I can't see any other explanation, but as I don't know how or why our account was moved on to a free trial I couldn't even guess why yours wasn't...
-
So, top left of that screen we have - wonde basic Upgrade Also, if we click on 'Activity Log, it tells us we need to 'Upgrade to use this feature'.
-
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
Koldov replied to Koldov's topic in Cloud Services
Yeah, this was discussed as soon as we realised we had email accounts for the main Admin and Headteacher were in an 'unmanaged' tenant on a domain we don't own (and shouldn't even exist)!! But in all honesty I didn't realise it was going to such a PITA to get sorted and I thought we would be in by today (but then I have thought that every day for the last two weeks - lessons learned I guess), so the 'new' accounts haven't finished being provisioned yet... Anyway, BM has installed the Authenticator app on their phone, so at least it's sorted for now. I mean don't get me wrong, I'm all for MFA and 'securing all the things' and in fact now they have to use it I may get less resistance from SLT, it's just that we hadn't been informed it was being switched on (as nobody was ever going to get the notification), so it took us a while to figure out what was even happening, then find out who the admin was, then get a response, then get them to action anything... And although we probably should have had a strategy for this already, a furious HT and BM who haven't had emails for 2 weeks aren't the best people to have an MFA discussion with! -
Just spoke to the BM and they had the invoice sitting in the 'pile of things to pay'... going on the knowledge that it is something we use (and the assumption that they needed to pay for it - which is I'm pretty sure is Wonde's plan)...
-
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
Koldov replied to Koldov's topic in Cloud Services
Yes, this tenant has been up since 2014. Unfortunately, although we have been informed that the Security Defaults have been disabled (I have no visibility of this, so can't confirm), we continue to see the MFA set-up prompt! So frustrating! My HT and BM are about to have an actual meltdown!!! -
I'm interested in why their support wasn't your first port of call...? Anyway... I have just heard the SLT are going to look into having an EntrySign demo at some point... This is the first I've heard about it (no surprise I.T. aren't involved, yet again)! I certainly hope they don't then dump this on my desk with immediate demands for network access/cabling/network point install, software/MIS integration/database/installation on the server, app installs on the workstations etc. My summer works schedule is pretty full on already...
-
Yup, just logged in and went to, Settings > Wonde Licence... and have the same as @psydii So, without any prior notice (although I wonder if an email has gone to someone who didn't take any action - wouldn't be the first time) Wonde had moved our plan onto a 'free trial' and now converted it into a 'paid' version (no invoice yet, but I'm sure it's on its way)!
-
Also a shame as they were starting to gain favour and being seen as the best of the bunch, given that the alternative is being 'bashed' on here regularly (not least by me).
-
O365 - MFA ENABLED - SECURITY DEFAULTS ENABLED (?) - OUTLOOK 2016
Koldov replied to Koldov's topic in Cloud Services
Yes, that's right. So you think this will stop it? Interesting, I know what you mean but I doubt it (this domain has been up since 2014) and I think it has more to do with the fact that (and forgive me if I'm wrong as I don't deal with email) Microsoft have just recently applied and enabled 'Security Defaults' (which enforces MFA) to the tenant (as iirc that is being rolled out this year)? -
New thread from: http://www.edugeek.net/forums/cloud-services/233648-email-security-challenge.html Due to to new information/new questions, but the saga continues... We have found someone who knows about these accounts! However they are an ex-council IT dept. employee, that was part of the move from the LEA in-house IT support for schools, to them all being made redundant when the council dissolved that support dept. and then they all went off and set up a support company, became consultants and were contracted by the council to provide IT support... to schools... Unfortunately, they are 'very busy'... but we have received a response! It turns out that despite my belief that these were 'official' council run email accounts from a sanctioned and managed O365 tenant on an official council owned domain... they are none of these things!!! These were in fact setup by the aforementioned ex-council IT dept. employees (now acting as 3rd party consultants) using a '.sch.uk' domain name (which I will mention, contrary to what I believe is .sch.uk policy, is NOT affiliated to a particular school) for the whole of the LEA. Therefore every individual school using these email accounts for their Headteacher and Admin are just 'users' all in the same tenant on the same domain... So, 'myheadteacher' & '[email protected]' is on the same tenant as 'yourheadteacher' & '[email protected]' The killer line in the response....? 'The @council.town.sch.uk is not managed. So, all this time I have believed these were 'managed' by the council, they have basically been left at the defaults in terms of security, compliance, etc. since about 2014.... And the footer "IMPORTANT: The content of e-mail sent and received is routinely monitored to ensure compliance with policies and procedures. " is a joke at best... Now, it would appear that (forgive me if I get this wrong as I don't deal with it) this means (and bear in mind we haven't been able to access the MAIN admin email account for the school in nearly 2 weeks so need this sorted, like, NOW): 1) Microsoft (not the council) have enabled MFA on this domain (as obviously nobody at the council has done anything on the accounts for years). Q1) Can we turn this off? Because this is the only option we are being given: 2) We can't turn MFA off. Q2) Can we do something else that means our BM can access the account on his computer through Outlook 2016, without having to have the Microsoft authenticator app on his personal phone as it's a generic 'Admin' account (obviously thinking about if they are, on holiday/off sick/leave)...?
-
How do I delete an individual print job from the queue...?
Koldov replied to Koldov's topic in How do you do....it?
Thanks, I'll investigate this when it happens next. Thanks, unfortunately however the message isn't 'paused - spooling' it just says 'printing', we don't use windows 10 modern store apps, we DO have 'Client-Side rendering', there isn't built in authentication (although we do use the Job Accounting feature - but if this goes wrong it still goes to the printer and errors there) and lastly we don't use Papercut. -
A minor inconvenience/niggle, but something I've never got to the bottom of... Like a lot schools we print a fair bit and occasionally a job will get stuck for $deity knows what reason and almost every time I'm not told about it until much, much later when loads of other jobs have stacked up behind it (although to be fair that doesn't take long). It's not a daily occurrence which is why I've never put in much time/effort into sorting it out, but it's just happened and reminded me, so I thought I'd ask... They always seem to fail somewhere between the client and the server as they never appear on the actual printer, but if I go onto the server and try to delete the job from the queue, 99% of the time it just won't delete (it says it's deleting but never actually does). This means I have to do the nuclear option and restart the print spooler service and unfortunately everybody on site loses whatever they were printing or what was in the queue (most of it had probably been printed elsewhere or was to be collected later, but still)... I wonder if 'Print Directly to the Printer' and 'Render Print Jobs on the Client Computer' settings which although originally done to lighten the load on the small VM print server (and fix some other issues), might be hindering my attempts to manage the jobs in the queue...? I'm thinking of it mainly being an issue when the job has not been fully rendered (maybe they closed their laptop after pressing print), or some error in the transmission of a large print job over the Wi-Fi...?
-
This gets better and better... I have just found out 2 things: 1. This has all materialised due to the fact that the BM has forgotten the password... and he is the only one who knows it! 2. There is apparently nobody in the LEA anymore that knows who deals with these email accounts.... You know the little things, like is it hosted in an out of date Exchange server in a cupboard that someone at the council has forgotten about? Was it migrated to O365? Who owns the domain name? Who is dealing with the email security settings? I'm sure there's more, but it's Friday afternoon, so....
-
Just to elaborate, we have a few users who WFH and for some reason their machines will not connect to SOLUS over the VPN (possibly I.P. related or something), one of them is from the Finance Dept. (so uses FMS) and once an update is applied here, they are effectively locked out (database mismatch) until they can bring their laptop on to site. They are standard users, so can't expect anything to be run manually by them really, but I could get a start-up script to run and they can access the server file shares.
-
This is precisely what I was trying to ascertain... if these email demands are being sent to everyone who uses a Wonde client to sync data (data feed/data extraction to provide user details to an online learning platform etc.), or only to those who have had more in-depth interactions with Wonde, or taken further services or have been moved onto the free trial offer for some other service Wonde offer etc.
-
Hi @chrisgreenwood or @David44 (or anyone else that does this method of SIMS update). If you get the time, I would be grateful if you could share the method/scripts to accomplish this. I've only ever used SOLUS and never done a manual update for a client, so wouldn't even know where to start! I can only presume that somehow the update has to be extracted to a share and then the client instructed to install it, but how you'd script that is beyond me...
