-
Posts
5,084 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Koldov
-
Cisco VPN LGfL AnyConnect uninstalling and not completing an update.
Koldov replied to Koldov's topic in Cloud Services
Thanks, but I had a quick response from LGfL support and it seems that in certain circumstances there is a problem with the installer for the update and it wrecks the installation... They've done a restart and it hasn't kicked in to fix itself and it can't be fixed by a standard user, so not a lot I can do. I've had the update myself, but obviously as I'm admin on my machine there was no issue. -
Not really sure where to put this... but I have recently had 2 remote workers now raise this issue (with a few others that I am just waiting for that email to drop). It appears that once they log-on, AnyConnect starts an update but fails and leaves the software in an unusable state (users are standard and cannot install software, install initially done by GPO whilst on-site and I have no way to remote into their laptops). Can anyone tell me if they have experienced this recently?
-
Without knowing your full set-up and what services/roles your servers provide and what devices your staff have connected to them, only you are going to be able to narrow this down any further, but some more suggestions here: https://community.spiceworks.com/topic/2213500-domain-user-account-lockout https://www.reddit.com/r/activedirectory/comments/7ko0fa/account_lockouts_source_workstation/ I think those 'lockout' tools just read from the logs, so might not actually give you any more information than you already have (just makes it easier to view it all rather than manually searching)?
-
Staff Subject Access Request - Deleted mails?
Koldov replied to mikes's topic in Data Protection & Information Handling
I was quite interested in this as a cross-thread to: http://www.edugeek.net/forums/cloud-services/227010-m365-email-auto-deletion-policies.html about auto-deletion/retention policies. -
Prevent Users Going to C: and or AppData from Start Menu
Koldov replied to jamwatn's topic in Windows 10
Sorry I meant to post this on Friday, but it seems like I didn't hit the button... This is a strange one and I don't envy your task. I am surprised this post hasn't attracted more 'it's all permissions, what harm can they do?' responses... I have found myself in this situation and unfortunately never got anywhere. As you found out, I deployed the above GPO and found that it creates some issues. We also used 'Hide these drives' but it didn't seem to work if they could just type in C: and it would open... This creates some errors including for us, using a 'local' version of Office when saving files it still looks for local folders and produces 2 error messages that need to be clicked through which can be confusing. We don't use OneDrive or Teams but with that GPO you pretty much seem to need all local user folders accessed by the user redirected as no local folders can be used such as Documents etc. (and redirecting Appdata is apparently a world of pain).... I tried various other ways to disable the search function instead, SRP, Applocker (neither of which worked in our set-up for some reason), the only thing that blocked it entirely was renaming the Cortana folder, however this produces a Start Menu anomaly that means you have to click it twice or it is dulled and not able to be clicked on (although it has been mentioned that it is not controlled by Cortana in recent Windows 10 versions, so that might not help you but we're on LTSC). -
In mine the Account Name was the person's name, not the DC. Could be that it is just posting the lockout (if PDC) as it was passed on from another DC, if you have any others can you check those? Also, what do you mean by \\WORKSTATION...? Is that what appears or is it blank? What shows up when you lock out a test account? A quick internet search suggest this list of various other reasons for no Caller Computer Name: Check for services, scheduled tasks or software on lockout source machine There could be outdated stored credentials an application making an LDAP call saved passwords in the credential manager. You can open up the credential manager on the system to verify there are no saved passwords on the system Also check if any 3rd party device has a network drive or something connected to the server using wrong credentials etc DNS and NetBIOS reverse lookup issue or computer/device not on domain Or this... https://www.reddit.com/r/sysadmin/wiki/lockouts#wiki_no_caller_computer_listed
-
And 443, but it seems they are quite open about using ports that are less likely to be filtered. Also it seems that it may have been using 993 as it failed to communicate on its 'primary port' (as we are in school and that is possibly blocked) and it also depends on what services are configured: "This list changes dynamically depending on the devices and services added on the dashboard." https://documentation.meraki.com/General_Administration/Other_Topics/Upstream_Firewall_Rules_for_Cloud_Connectivity Looks like a lot of work potentially... We don't get any connection in school for our Windows devices, but I'm not concerned as we don't 'manage' them through Meraki, so no need to have extra network bandwidth being used constantly.
-
Well, I have done a little more research on this and am hopefully going to be able to answer my own question (and help someone else - although it seems a unique set of circumstances judging by the lack of replies)... I will write a little bit about the testing and configuring of share permissions, but if that is a little TL;DR... Essentially I noticed one major difference between this folder and all the others on the share... in the NTFS/File/Security permissions there was an entry for 'SYSTEM' with 'Full Control' - once this was removed, the corrupt permission disappeared and the correct permissions were applied! I created a test document in a test folder and asked the Headteacher to edit it... they did and it disappeared, so I checked on the server and the permissions had been corrupted. I changed the folder to a share and changed the share permissions but it had no affect (going from everyone 'Full Control', to just modify, to adding 'Authenticated Users' and configuring those, to removing 'Everyone')... nothing changed. Which thinking about it, I'm not sure now why I thought it ever would, as share and file permissions are completely separate (not sure why it seems to have worked for others though)... However, in the NTFS/Security/File permissions I saw the 'SYSTEM' account having full control (I had just replicated the permissions from the original problem folder). It was created a long time ago and I'm not sure why this was present, but I had just recreated the test folder with the same properties. After a little research and checking no other folder on the share had this 'SYSTEM' account in the file permissions, I decided to remove it (as it was only a test folder)... and the test document file reappeared for me on my workstation under my log-in and a check on the server indicated that now the correct permissions were being applied! So the next step is to test that this has completely fixed the issue and apply it to the main problem folder (if I can work up the cojones)...
-
If it jams on every single tray (but not even picking the paper up) then there may be something else internally (sensor/roller). It might be more involved than you are 'trained or experienced' for, but unless you have a support company and the only other option is to skip it, you don't have very much to lose....? Also, how else will you get experience?
-
Can you take their phone from them during the school day?
-
General consensus is usually to hit it (no not with a hammer this time surprisingly)... a gentle (ish) tap to the rear of the device. http://www.edugeek.net/forums/netbooks-pda-phones/226680-ipad-blurring-ghost-screen.html Alternatively, if it comes and goes according to brightness, has the user got auto-brightness on? If so, can you turn that off and set it at a level where they don't appear (but is still useable)?
-
Sorry, that last edit was a lie... Event I.D. - 4740: The Account Name, Account Domain, Security ID (domain/user) and Computer Name were all valid and correct...
-
Hi @PaddyNewman Many thanks for the offer, but even though we can't get Meraki through the LGfL connection for Windows laptops (only iPads) at school, I thought I'd kind of ruled out any actual connection issues by taking it home (as my work laptop registers fine at home - as do all the teacher laptops, although I don't monitor them I can see in Meraki that they have been used off-site). From what I can see it appears to be using 993, so shouldn't be an issue from home...? Anyway, I took it home last night to test and it seems to have connected at last... I'll be annoyed if it just turns out to have been an issue on the Meraki end of things though... that would be typical, always wasting my time troubleshooting problems that you think are with the device only to find out it's the other side that has the issue!
-
OK, so I now know why I'm not seeing what I used to see... I think I remade my 'Advance Audit Policy Configuration' GPO for the Domain Controller at some point (I'm blaming Ping Castle)... It didn't include what I remember, so I had another look and this is what I have now: Advanced Audit Configuration [b]Account Logon[/b] [i]Policy Setting [/i] Audit Kerberos Authentication Service Success, Failure Audit Kerberos Service Ticket Operations Success, Failure [b]Account Management[/b] [i]Policy Setting [/i] Audit Computer Account Management Success, Failure Audit Security Group Management Success, Failure Audit User Account Management Success, Failure [b]Detailed Tracking[/b] [i]Policy Setting [/i] Audit DPAPI Activity Success, Failure Audit Process Creation Success, Failure [b]Logon/Logoff[/b] [i]Policy Setting [/i] Audit Account Lockout Success, Failure Audit Logoff Success, Failure Audit Logon Success, Failure Audit Special Logon Success, Failure [b]Policy Change[/b] [i]Policy Setting [/i] Audit Authentication Policy Change Success, Failure [b]Privilege Use[/b] [i]Policy Setting [/i] Audit Sensitive Privilege Use Success, Failure [b]System[/b] [i]Policy Setting [/i] Audit Security System Extension Success, Failure Just tried and here's what I see now: EVENT - 4768 A Kerberos authentication ticket (TGT) was requested. Account Information: Account Name: [color="#FF0000"][b]test = NOT A REAL DOMAIN ACCOUNT[/b][/color] Supplied Realm Name: [color="#FF0000"][b]DOMAIN[/b][/color] User ID: NULL SID Service Information: Service Name: krbtgt/[color="#FF0000"][b]DOMAIN[/b][/color] Service ID: NULL SID Network Information: Client Address: ::ffff:[color="#FF0000"][b]XX.XXX.XXX.XX = A VALID I.P[/b][/color] Client Port: 49914 Additional Information: Ticket Options: 0x40810010 Result Code: 0x6 Ticket Encryption Type: 0xFFFFFFFF Pre-Authentication Type: - Certificate Information: Certificate Issuer Name: Certificate Serial Number: Certificate Thumbprint: Certificate information is only provided if a certificate was used for pre-authentication. Pre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120. Or... EVENT 4771 Kerberos pre-authentication failed. Account Information: Security ID: [color="#FF0000"][b]DOMAIN\USER = A VAILD ACCOUNT[/b][/color] Account Name: [color="#FF0000"][b]USER[/b][/color] Service Information: Service Name: krbtgt/[color="#FF0000"][b]DOMAIN[/b][/color] Network Information: Client Address: ::ffff:[color="#FF0000"][b]XX.XXX.XXX.XX = A VALID I.P.[/b][/color] Client Port: 49908 Additional Information: Ticket Options: 0x40810010 Failure Code: 0x18 Pre-Authentication Type: 2 Certificate Information: Certificate Issuer Name: Certificate Serial Number: Certificate Thumbprint: Certificate information is only provided if a certificate was used for pre-authentication. Pre-authentication types, ticket options and failure codes are defined in RFC 4120. If the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present. EDIT: Just noticed that although I'm seeing these as Kerberos events, I'm not actually seeing any 4625, 4740 or any other Event I.D related to failed logon....
-
Can't say for sure, but is it possible that someone tried to log on with an account name that isn't valid...? Failure Reason: Unknown user name or bad password. The classic 'which is it'... wrong username or wrong password...? The only way you could know for sure is to maybe get a test account on a laptop and try logging in (or a random account that isn't real) and refresh the event log as you do it...? Not a very technical solution, but it's hard trying to track down past events and why they happened, at least you could possibly see a real-time event and what it relates to... EDIT: I'm not sure if it actually does log incorrect usernames... I'm sure I've seen them in the past, but haven't for a long time, might have to look into my auditing now... thanks...
-
I have been trying to get a Windows laptop to appear in the Meraki dashboard for a couple of days now with a little success, but it isn't really satisfactory. I have all our teacher laptops in Meraki and although I can't tell for sure, I do see ones that pop up regularly and they seem to be OK. Now I've got to set-up a laptop for a pupil's home use and this is the last sticking point before I can release it to them. I've done a little research but it's impossible as 99.9% of results are for iPads... I've reinstalled the agent and deleted from the dashboard a few times now, but on reinstalling it produces the same behaviour and I can't find out what the issue is... As you can see, it does register and some information is visible, but not enough to make it a viable option. I can also screenshot, power control, see public/private IP and storage capacity. But some of the information hasn't appeared (most importantly location) and it just sits on 'Client Synchronization is not yet complete' even when left for hours... I did notice that the Meraki team had "investigated and successfully mitigated the underlying issue affecting Dashboard connectivity for Meraki Devices in the European region." But it still wasn't playing ball when I took it home last night (we can't test at work because for Windows laptops, Meraki doesn't get through our LGfL connection - although iPads sail right through)! I just wondered if I'm jumping the gun and this had impacted anyone else and if it could still be the cause of the issue, or if there is something specific to this laptop's set-up...?
-
Yes, I do see your point, honestly though I don't touch any personal devices (not even staff - long story), but that's an individual choice and not something I really feel I'm being given here (if it is to be a 'personal' device), the Headmaster has told me to provide the laptop (due to the fact that we receive the funding - I'm still not getting any closer to the reason for that though)... As in the previous post, they wouldn't get even the service you provide if any other family bought it straight from the shop and it's not a condition of my employment (possibly different to an ethical responsibility) to do that for them...? Yes, I was aware of the Office 365 for student/teacher personal use scenario, we haven't looked into it here (since HUP for Office) as it seems that as it's therefore dependant on a school license it would only be valid for the term of employment/attendance at the school (?), the possibility of me then having to support it (and their devices) and the management of hundreds of staff and students outweighed the benefits. It therefore has never been advertised and I've only ever had one person ask about it in all the years I've worked here...
-
Yeah and I get that, at least that makes perfect sense to me and how it should be done if an LA gives the LAC a laptop (akin to a family buying their child a laptop) to be used as a 'personal' device, there's no issue. Unfortunately, somehow these devices are making their way to the child via funds provided to the school and so, I feel this changes the dynamic and the expectation of responsibility/liability...
-
Ultimately as all these answers prove, it all appears to very grey and with not even a scrap of at least guidance for the matter (which would also be subject to interpretation anyway), it seems there is no definitive answer as to 'right or wrong'... However, imho to me, the fact that you are touching it at all, does in fact imply some liability/responsibility and whilst you say you don't actually install software 'that is subject to a license agreement between a company and the school, I'd question if the O365 subscription isn't exactly that? So, technically provided by the school for educational purposes (whilst attending said school just like other software) and I'm wondering what the difference is (apart from being able to end the O365 subscription when necessary). Just a question, not an argument... Otherwise, just advise a suitable laptop and point them to Currys/Dixons and be done with it. However, somehow and for some unknown reason the money is funnelled through the school**, which also seem to infer that it is the school's responsibility to, a) provide the laptop and so, b) therefore to be a school laptop for education with all that entails... Also, I'm still wondering why they get laptops, Kindles, iPads at all? As noted in a previous post these are not specifically SEN children and from what I gather, for the most part are only LAC with no 'other' special needs to cater for. I know plenty of our children do not necessarily have these things at home... **Which begs the question... if they are being being given 'personal' devices purely as an effort to a achieve a certain perceived 'quality of life', why is the school involved at all (surely that is a local Gov. > local Gov. issue and not a matter for LEA if it is not purely for education)?
-
We don't use a ticketing system (and I was actually going to mention that) but I thought I'd get too many 'use a ticketing system' posts. The thing is we are quite a small school and mostly things are done ad-hoc, by word of mouth. Not great, but I've been here quite a few years and never had any issues. Also, most of my 'other' jobs are self motivated/necessary by the nature of running a network/server infrastructure and not something requiring a ticket (although I could create one.... and square one). Unfortunately I'm on my own, so rarely need to tell anyone what I've been doing all day (thank $Deity)....
-
I'm not talking about the big things like DR or handover style stuff, but does anybody document the day to day...? I'm terrible at it and finding my advancing years aren't helping my recollection, but when I'm busy I can't seem to find the time (or will) to sit down and type it all out. I know if I don't do it right there and then, I will avoid it and it will get forgotten about (and I'll forget how I fixed it because I tried so many things and searched half the internet). Also that it takes as long (or longer) to record it than it does to fix the problem half the time.... But there have been a few occasions where an issue has arisen that really rings a bell, but for the life of me I can't remember the who, why, where, when or what.... Obviously there's the internet and in particular EDUGEEK can be great for solving the issue and mostly there is a permanent searchable record of the solution (if there was one), but that all takes time and isn't always fruitful. Does anyone take the time to record the minutiae of things like a small change to a GPO, or actually log if they've changed a port, a firewall rule, or an A/V policy (especially if you're a one man band and don't have to pass the information on to your team). If so, how have you achieved it so that it becomes a coherent/searchable database, easy to do in a timely manner and not a mess of incoherent babbling...? Case in point: I was told to rush out a laptop recently for home use (it's not something we've done before), so I spent a frantic couple of days working out how to achieve it and had to make a lot of changes to various things (as mentioned GPOs, Firewall, A/V). When (and if) I get the laptop back in say a years time and I try to get it back to working onsite, I'm almost certain things will not work and I'll have no clue why (although I would wipe it anyway, it's just an example).
-
Adobe Lighroom Classic Catalogue - Network Drives . . .
Koldov replied to PCope's topic in Educational Software
How many computers are we talking about? It's probably a logistical nightmare and I don't really know much about Adobe, so I'm probably talking out of my hat... but how about another local drive (similar to the USB option), either a separate partition, physical drive or internal USB that they can access? -
TL;DR - copy files/folder out and then back in without changing any permissions (Server 2012R2). The issue is I cannot lose any of these files or mess them up in any way, so although I have a backup, I wondered if there was anyway to copy these files out, do my change (on share permissions to the original folder) and then copy them back in without any permissions getting messed up along the way (as Windows does like to change them to the copy destination's permissions or even accumulate them). I have a problem with the Headmasters Mac (yes, but there's more), whilst accessing files on our server and editing them and copying them back it seems to mess with permissions. For details: http://www.edugeek.net/forums/mac/226838-mac-files-windows-server-not-inheriting-permissions-correctly.html It has been a long time since I've messed with this sort of thing... As the folder is not a 'share' but sits IN a 'share' (which is the whole staff drive) I can't really bring myself to mess with any share permissions on the root (unless anyone can cast-iron guarantee me changing share permissions on the root won't mess anything up). I have a cunning plan... . So, I am wondering if I create the 'share' on this particular folder and set the 'share' permissions on the folder to 'Everyone' = 'Modify' as indicated in my research... and hoping a share on a share, will behave OK? Will I affect anything at all in the folder? Unfortunately it is a very sensitive folder with a lot of information from teachers (including the Headteacher), on performance management/observations etc. There is a lot of work that cannot be recreated and they have just been told that pay rise (grade) depends on what is in these folders...
-
Replacement iPad not connecting to Mosyle
Koldov replied to Jobos's topic in Mobile Devices & Tablets
It might need wiping if you can't get right back to the beginning. The point before all that where you set it up as a new iPad? It has been a while but iirc it goes something like this... Hello > Language > Location > Set Up Manually > Wi-Fi > MDM should kick in here, tells you it's managed and continue... might take a while.... You 'shouldn't' need to do anything else (that's what the MDM is for) and I think what you're seeing comes way after that (which is probably why there isn't any other way past it)!
