Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Boredguy

Members
  • Posts

    4,103
  • Joined

  • Last visited

Everything posted by Boredguy

  1. 1 - adding a suffix rarely breaks anything 2 - With the new suffix, users still logon as normal, or they can choose to use their e-mail address 3 - Depending on how you configure your browsers for SSO, your users may be prompted to enter their e-mail address to login to 365 web services (but not their password). Logging into the workstations is not affected in any way
  2. We're providing our MAT's finance staff with 24" monitors, with the finance manager at each school getting dual, and the assistant/clerk just having the 1 for now.
  3. That command will turn the mailtip "This is an external recipient" on for all users (and is a good idea in it's own) For just a specific mail group, you can add a mail tip to just that item. If is an AD sync'd group it's a little bit harder, otherwise you can add it via the Exchange Admin page You can not turn on the external recipient mailtip to just a subset of users though.
  4. Our firewall changes via RM is normally within 24 hours, so turn around isn't that bad
  5. If you are on SWGfL, just log a dns record request via the ESI portal. Having a default dmarc record created automatically wouldn't be ideal as how would they know which address you want the rua and ruf messages to go to?
  6. @charlie13561 what do you mean that RM will not add the DNS record for you? They must have done so already to setup DKIM and SPF when you setup your 365 tenancy? If you are using RM via the SWGfL, you can request self service DNS from them to do the DMARC and other records without having to raise service calls all the time.
  7. What type of SQL licence on the server are you currently using? We are using a Per Core licence for SQL, which just covers the server and we do not need to licence the clients. There is the Server + CAL option as well which is what your supplier as quoted you for.
  8. Yep. Depending on the address sent to, it will either ask to login with a Microsoft account, google account or request a pin code to the recipient e-mail address. The encrypted e-mail itself never leaves your tenancy.
  9. You mean adding a rule to turn on the OMEv2 encryption? Yep we have that enabled as an alternative to pressing a button based on a subject content
  10. We use SCCM to deploy out Solus as an application and not as part of the Task Sequence, but the same would work. In SCCM, the package calls our SolusInstall.cmd script. It in turn calls a VBS script that checks a CSV file in the same folder for the workstation name. If it finds the name, it passes the stored GUID to the install string. If the name does not exist, it generates a GUID, updates the CSV file and calls the Installer. We originally exported a list of station names and GUID's from the agent table in the Solus3 database. We also export the Solus 3 Agent to our install folder. Install.cmd wscript.exe "\\server\applications$\Solus\SolusInstall.vbs" SolusInstall,vbs Const ForReading = 1, ForWriting = 2, ForAppending = 8 Set wshShell = WScript.CreateObject("WScript.Shell") Set TypeLib = CreateObject("Scriptlet.TypeLib") Set wshNetwork = WScript.CreateObject( "WScript.Network" ) Set fso = CreateObject("Scripting.FileSystemObject") Filename = "\\SERVER\Applications$\Solus\guids.csv" Found = false strComputer = wshNetwork.ComputerName strOSArch = GetObject("winmgmts:root\cimv2:Win32_OperatingSystem=@").OSArchitecture Set MyFile = fso.OpenTextFile(FileName, ForReading) Do While MyFile.AtEndOfStream <> True temp = MyFile.Readline if instr(temp,strComputer) > 0 then GUID = Left(temp,instr(temp,",")-1) found = true End if Loop MyFile.Close If found = false then GUID = left(TypeLib.Guid,37) GUID = Right(Guid,36) Set MyFile = fso.OpenTextFile(FileName, ForAppending, True, TristateTrue) MyFile.WriteLine GUID & "," & strComputer MyFile.Close end if If strOSArch = "32-bit" then 'msgbox "32 Bit install" wshShell.Run "msiexec.exe /i " & chr(34) & "\\SERVER\Applications$\Solus\SOLUS3AgentInstaller_x86.msi" & chr(34) & " AGENTSERVICEADDRESS=" & chr(34) & "net.tcp://localhost:52966" & chr(34) & " AGENTID=" & chr(34) & "{" + GUID + "}" & chr(34) & " DEPLOYMENTSERVERADDRESS=" & chr(34) & "net.tcp://SIMSSERVER:52965" & chr(34) & " RSAKEYPATH=" & chr(34) & "\\SERVER\Applications$\Solus" & chr(34) & " /qn /l*v C:\solus.log", 1, true end if If strOSArch = "64-bit" then 'msgbox "64 Bit install" wshShell.Run "msiexec.exe /i " & chr(34) & "\\SERVER\Applications$\Solus\SOLUS3AgentInstaller_x64.msi" & chr(34) & " AGENTSERVICEADDRESS=" & chr(34) & "net.tcp://localhost:52966" & chr(34) & " AGENTID=" & chr(34) & "{" + GUID + "}" & chr(34) & " DEPLOYMENTSERVERADDRESS=" & chr(34) & "net.tcp://SIMSSERVER:52965" & chr(34) & " RSAKEYPATH=" & chr(34) & "\\SERVER\Applications$\Solus" & chr(34) & " /qn /l*v C:\solus.log", 1, true end if
  11. MDT might have the drivers, but did you regenerate the boot media to include the PXE drivers for it?
  12. If you have less than 1000 FTE, then you are on OVS-ES. EES is only for 1000+
  13. We currently assign students licences for 15 out of the 18 apps available under the A1 Plus licence (Skype for Business, Yammer and Office Online being the 3 declined ones) Within the Azure Active Directory -> Licences -> Products, you can assign AD groups to the different licences to automatically assign them to your users (you can not use nested groups), and turn off specific apps licences for that group, so you don't have to do it per person. If you look in the Purchased Services in the 365 admin centre, and select Education, you might have access to some of the A1 licence plans which are free, and allow more features than the ProPlus one you mentioned. The best one currently, but can require a lot of hitting of MS, is the Office 365 A1 Plus for faculty/student. There is some global configuration you might want to do for 365 to aid restrictions, which include disabling the ability to update their contact image. All of which can be done via powershell
  14. When you did the trial, did you validate the schools official domain name and was it a .sch.uk?
  15. Our Heads PA has a few of those, but it is not something that is centrally maintained, but rather just a personal contact group in their own account (that way they can adjust any e-mail addresses without needing to pass them on to us) With the 365 Groups, you can add guests with their e-mail address, and they will be able to receive/send e-mails. You can also deligate rights to the Heads PA to keep the membership up to date (and it has the bonus of allowing new members to the group to see the previous e-mails)
  16. We moved all our governors onto our school 365 tenancy, and even the governors for the MAT are using their official trust domain, so that messages are not sent outside the organisation (especially in light of GDPR these days) The distrubution groups we do have, are universal security groups setup in AD that have the e-mail address required. We then add our "All Staff" CN value to the AD attribute "dLMemSubmitPerms" to stop students or external contacts from sending to them. We are looking to move our governors across to 365 Groups to better intergrate their documents and e-mails in a central location instead of having to switch between our website and 365 (plus makes it easier on tablets). Again this is something that works better with them within the tenancy and not an external contact.
  17. Why would you need to deploy SIMS's via the MSI? We still use my vbs script I created years ago ( http://www.edugeek.net/forums/mis-systems/149939-solus3-auto-reinstall.html#post1284151 ) to deploy Solus 3 out to stations
  18. Device Based Activation is a lot easier compared to Shared Computer Activation as long as a) you have SCCM available to deploy it and have it configured to do your updates so you get the monthly/semi annual updates for Office b) A1 Plus for Faculty/Student licences available to your tenancy
  19. We only use A1 Plus for our staff and students, as it provides all the functionality they need.
  20. That's not an issue if you have .local, you just have to create an alternative UPN suffix in your Active Directory (very simple) then assign that to your users instead of the .local. Our domain is a XXX.Internal, but we just added our fqdn as the suffix and the e-mail address the user would have and away it went. Some people find that using the proxyAddresses also gets round the issue of usernames not matching the same naming convention as the e-mail address
  21. Here is the example powershell to connect to Office 365 (you should already have the Microsoft Online Services Sign-in Assistant installed) Import-Module MSOnline $LiveCred = Get-Credential $Session = New-PSSession -ConfigurationName Microsoft.Exchange -ConnectionUri https://ps.outlook.com/powershell/ -Credential $LiveCred -Authentication Basic -AllowRedirection Import-PSSession $Session Set-MsolCompanySettings -AllowEmailVerifiedUsers $true
  22. Need a baseball bat to get it through their head at times, it's a different product line all together to ProPlus which is via the OVS-ES reseller.
  23. In our 365 admin panel, the "What is this" link next to our A1 Plus for Faculty goes to this site -> https://docs.microsoft.com/en-gb/office365/admin/misc/self-service-sign-up?redirectSourcePath=%252farticle%252f4f8712ff-9346-4c6c-bb63-a21ad7a62cbd&view=o365-worldwide That in turn suggests going to https://products.office.com/en-GB/student and entering a student e-mail for your tenancy. If you have not already tired the link above, give it a go and see if it does anything.
  24. The ProPlus is via your OVS reseller A1 Plus for Faculty/Students was automatic if you setup self signup (powershell command Set-MsolCompanySettings -AllowEmailVerifiedUsers $true) when it first came out, but seems these days you have to talk to 365 Support (sometimes repeatedly to get a correct person)
  25. Depending on your domain name, you might already have the Office 365 A1 Plus for Faculty/Student available. Some people have found if they are not using one of the established .sch.uk or .ac domains that they have to contact Office365 support to get their establishment flagged/registered as educational, at which time these licences should then become available (along with the Self Signup option) The A1 Plus for Fac/Stu would enable you to use the Office 365 Click to Run Device or User based deployment method on site, but you must have the OVS agreement to do this anyway. The normal Pro Plus one should be available via your OVS reseller as it's gets linked to your tenancy via the MS Volume Licence Centre
×
×
  • Create New...