Jump to content

Koldov

Members
  • Posts

    5,084
  • Joined

  • Last visited

Everything posted by Koldov

  1. I'll take great pleasure showing the BM this post on Monday morning...
  2. Thing is, what is going to happen next year? Are prices just going to increase ad infinitum...? Due to my tariff ending soon my power company is asking if I'd like to renew now (obviously to a higher tariff) and lock in to 2023... which would be a good thing if prices are going to continue to rise... Or do I wait until January when prices might have dropped and a better deal is to be found (which seems unlikely)?
  3. Sadly my fixed rate tariff is up at the beginning of January (just in time for the really cold months when the OH will insist on the heating all day as she is working from home)! I'm dreading what the choices will be when I come to renew...
  4. Yes, I probably could if I'd been given the sign-on details.... I'll have a word with the BM on Monday as he's dragging his feet*. EDIT: *Very busy...
  5. Well, I did a little more research on it to get enough ammo to shoot it down (actually only needed one webpage and its linked articles).... https://www.commonsensemedia.org/blog/parents-ultimate-guide-to-youtube-kids ...and then took it to the SENCO who is also SLT (Deputy Head), luckily she has used it for her child and is of the same opinion. As it is just a front end for videos hosted on YouTube itself there are probably numerous holes in the algorithms that rate the videos 'for kids' and in the UI as pointed out above... Shame, its been around long enough to have matured into a useful product, but its just another afterthought/add-on/revenue stream for YouTube (and its owners)... Does anyone have any recommendations on something similar that is actually usable?
  6. We have been waiting for iPads too (as it's what we have had previously and what we have the infrastructure for rather than having to implement a whole new strategy, or have to deal with poor quality laptops/Chromebooks). Unfortunately it's all in the hands of the Business Manager and everyday I ask him, he "hasn't had time"... First day we got the email (Monday) he hadn't even checked, (Tuesday) he checked and there were none available, but subsequent days he's been out driving the minibus for a school trip (Wednesday), getting ready for a Governors meeting (Thursday) and today is his day off... When you think of the amount of schools who are getting in and checking first thing, it's no wonder any stock is snapped up immediately!
  7. Just had a teacher come and ask me to unblock this... she wants her SEN pupils (Primary age) to be able to use it on their iPads. Unfortunately YouTube is blocked for the children here via an IP range for their devices (teacher's have access to it from their devices), but it is set via our LGfL filtering to 'Strict Restricted'. Teachers can bypass this by signing in with their school Google account and having individual videos approved, but the YouTube service is turned off in Google for pupils. Anyway, I don't know if this YouTube Kids thing is completely safe, or if it is even possible to allow it through the filtering without unblocking all the YouTube domains (as presumably the actual videos are still hosted on the main YouTube servers). We can get to the YouTube Kids page but the videos won't play obviously... I don't really want to allow the normal YouTube for all the pupils, just to allow YouTube Kids for a handful of them. Although it is 'Strict Restricted' unblocking the main YouTube would allow them to see plenty of videos not suitable for their age range/school environment (regardless of what they see at home). Even though it would be a 'classroom management' issue, the iPads are also used for breakfast, lunch and afterschool clubs where the supervision may not always be 100%... I know I'm going to be asked why I can't do it, or why I'm blocking T&L, but honestly I can't see a way around it... anyone?
  8. It may well be a 'standard practise' given that the earlier posts mention that it is quite a powerful add-in and allows the user to be privy to 'all the data'...? But as you say, it should be understood that even an 'admin/power user' of the MIS* may not necessarily be an admin of the machine they are working on... Is it like SIMS where certain functions rely on the user having permissions on certain folders? *other software/platforms available (and equally culpable).
  9. Personally I would go for it... Once added to DEP and in ASM, get them into your MDM. We have Meraki here but I have a network with zero restrictions or profiles and the teacher ones are added to that. So, the iPads are 'managed', but not 'managed' if you see what I mean... EDIT: The teachers have no clue and it doesn't stop them using them as 'personal' devices, but I do have some control over them.
  10. I'm presuming you've reached out to Bromcom support for advice? Can you share their response (or are they too busy with all their potential new customers and other pursuits)... I'm thinking this would be something that must have been brought to their attention a few times (given the length of time since this thread was started) and the fact that their user base is schools who more recently are trying to get a grip of security.... maybe they know of a way to do it.
  11. I made the mistake (I'd like to say it was in the early years of my career - but it wasn't so long ago) of trying to remove a screen that had adhesive tape along the bottom inside edge of the screen bezel... The screen was only flickering slightly so I though I would just reseat all the wires and test... Anyway, it wasn't fancy rubberised tape with tab removal, just seemed to be full on double sided tape and after trying to remove the bezel from the screen with a flat blade... we needed a new screen...
  12. Yes, it absolutely is! The link in my first post from the error in the event viewer log forwards to that link. What I am not understanding actually is what the errors really mean... or maybe I'm reading it incorrectly. I'm just trying to decipher it and failing, because to me it looks like DC1 (KDC) is unhappy with what DC2 is sending (the errors are part of the Deployment/Audit phase I think), but when the Enforcement phase kicks in (July 2022), does that mean it will block communication? And why doesn't DC2 have what DC1 needs (the correct Kerberos PAC)?
  13. As for the printer errors I'm ashamed to say I've left my clients on the September CU... Nothing in your link obviously relates to 2012R2 (as it's for 1607/2016) and clicking on the "Known issues in this update - Clip or tap to view the known issues" reveals a further clickable link under Workaround - "Windows release health." However, I'm sure I've mentioned in one of the other many printing threads that I can't understand the workarounds... "Print clients must have installed a Windows update released on or after January 2021 before the print server has installed" None of my clients are that far behind on updates... "Ensure that network security and VPN solutions allow print clients to establish RPC over TCP connections to print server over the following port range: Default start port: 49152 Default end port: 65535 Port Range: 16384 ports" Not sure where this is (as it doesn't explicitly state what service/program to enable these ports for - I can't find RPC over TCP), but on my print server the Firewall is off and if it wasn't the following rule is in the 'Firewall with Advanced Security': File and Printer Sharing (Spooler Service - RPC) Inbound rule for File and Printer Sharing to allow the Print Spooler Service to communicate via TCP/RPC. Program - %SystemRoot%\system32\spoolsv.exe Protocols and Ports TCP - RPC Dynamic Ports - All Ports That's a default for printer/file sharing, so doesn't that cover it? "You also benefit from using client side rendering for print jobs. The 'Render print jobs on client computers' option is available from the printer's device Properties, and it is recommended that its checkbox is selected on the print server. Note this step will not help if clients have overwrites which prevent the server setting from taking effect." This is the default for all our printers anyway... I just can't face the potential hoards of teachers knocking on my door crying that they can't print a new ream of paper for their class to colour on and stick in their workbooks...
  14. Yup, confusing as hell (as ever) from Microsoft... but 'do nothing' seems to be the general consensus... https://community.spiceworks.com/topic/2338789-event-id-35-and-37-kerberos-on-server-2019 https://docs.microsoft.com/en-us/answers/questions/630388/server-2012-r2-std-generates-event-id-37-microsoft.html Maybe it's just the wording of the error that seems to imply that when the enforcement phase kicks in, 'DC 2' is going to be blocked as it doesn't contain the PAC attributes field 'DC 1' is looking for... and I've no idea why not or how to fix it! Not helped by the search for Event ID 37 brings up "Event ID 37 is logged when the hardware platform determines that the OS can't use some frequency range that the processor supports. This Warning event notifies the user that the processor or CPU core can't support running at full speed." Only subsequent results in the search show the Kerberos issues linked.
  15. Luckily the server side of things (updates) no longer seem to affect printing, it's only client updates that mess it up. I was on another forum (shhhhhh)..... and noticed that some had said the recent out-of-band updates for Windows 10 clients (tested on 21H2) seem to have even fixed their printing issues. Even though the release notes don't mention anything about printing! Nothing for lower version yet though...
  16. Yes, exactly that (event logs), it does appear to be a DC to DC thing. Everything else (that I know of so far) is absolutely fine. EDIT: Just a little concerned about what it may be breaking between DCs (replication etc.)
  17. Well, OK... my 2p's worth. Previously our server room (glorified cupboard with A/C) had a lockable door and I pretty much had the only key. There was a spare but the Site Agent had it and there wasn't really any need for him (or anyone else) to actually go in there apart from the A/C engineer once a year. Now, I've moved the servers to the Plant Room (which is also the Switch Room and where the SA stores some other equipment) and although the door is lockable and it has AC, I am aware that there may be more 'traffic' in this room - the fact that the switch cab has a big bow in it from when the electricians stood on it (yes that's right) to reach the ceiling for cabling proves that regardless of who 'says' they will do (or not do) something is irrelevant (SA said he would keep an eye on them)... but I've taken those risks and assessed them and the servers being in there is for the greater good... But as others have said if the Site Team are mandated to check 'every' room on a fire evacuation, then they have to check every room... that's all there is to it. I would however get assurances from the SLT that access to said room is on the proviso that it is only for that purpose (if there is no other need for them to be in there) and a cheap motion detection cam (with alerts) for good measure.
  18. To be Frank...
  19. Last night I remoted in and bravely (?) did the November updates for our servers... I was expecting some sort of carnage this morning due to previous print nightmare updates (and a thread on here about SQL). After a reboot of the servers sure enough I couldn't print, but found that somehow it had set the Print Spooler service to 'Disabled'. Setting it back to automatic and restarting it brought all the printers back on-line... strange but at least it is working for now. Anyway, after checking through the event logs, I started seeing Kerberos Ticket errors: The Key Distribution Center (KDC) encountered a ticket-granting-ticket (TGT) from another KDC (SERVER-2) that did not contain a PAC attributes field. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more. and The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket. This prevented security checks from running and could open security vulnerabilities. See https://go.microsoft.com/fwlink/?linkid=2173051 to learn more. Ticket PAC constructed by: SERVER-2 Client: DOMAIN.COM\\SERVER-1$ Ticket for: krbtgt I left it overnight thinking it would sort itself out and settle down, but the error are still being produced this morning. Looking through the link I can't really see what the issue is as both DCs have had the November update... I haven't added the reg key suggested. Anyone else seeing this.
  20. What could possibly go wrong....?
  21. Send them to me, I love Bounty! The ones that gets left in our house are Quality Street toffee penny and finger (not good for my fillings)... but even they only last until the week after Christmas when we are desperately trying to find something to ease the sugar withdrawal symptoms.
  22. I'd say that was 'fair'...
  23. Possibly won't stop a school moving MIS. But it should absolutely stop them asking Bromcom for a quote/invite them to tender.
  24. Actually not empty folders... Looking like some kind of temp/autosave file...? Not sure why it has only just started happening though, the user hasn't mentioned any updates to either the Mac OS or Office...
  25. As the title says, just had the Head tell me he was working on a document yesterday and whilst editing and saving found that it was producing random empty folders. Unfortunately he isn't the most IT literate and couldn't really explain what he was doing when it was happening (other than editing a document) and presumably he didn't even realise until he'd finished anyway. I can't really get hold of the Mac to do any kind of troubleshooting, so I thought I'd ask on here if anyone has seen similar issues. First time he has noticed it doing this (and I can't find any other instances). File was on a Windows Server 2012R2 share which he regularly uses with no issues (and has done for a few years now).
×
×
  • Create New...