Jump to content

MartinT

Members
  • Posts

    2,324
  • Joined

Everything posted by MartinT

  1. That would be such an obvious breach of policy that the staff member should be instantly dismissed. The fact is, you can't legislate for every eventuality or for IT used by morons.
  2. https://www.sfia-online.org/en/sfia-6/skills/skills-home
  3. We haven't and don't intend to. We enforce encryption.
  4. We make SIMS available via MS RemoteApp, which works well. SSO using Trusted Authentication, too. Passwords require complexity and we enforce change every 180 days (shorter becomes self-defeating as they keep forgetting or use sticky notes). We publish minimum requirements for home PCs and also set RD limits, so XP or other old OS is not allowed to connect.
  5. Ouch! I've forwarded the news item to all staff - it's a good GDPR training refresher moment...
  6. Yes, all fair points. It's always going to be a balance between trusting the staff and being procedurally difficult (which inevitably means more support required from us). Our staff pretty much only encrypt USB drives that we provide, they don't like encrypting their own and some have Macs at home for which it's a non-starter. I don't want to be too anal about it as they could always take printouts home if they really wanted sensitive information for nefarious reasons.
  7. We did find recently that RDP stopped working after we applied the latest updates to our W10 1803 clients. It required Server 2012 R2 & 2016 to be fully updated to match before RDP would work again.
  8. Encryption of USB sticks was strongly recommended in two GDPR seminars I attended. We enforce BitLocker encryption for writing to USB sticks, but there is no need for reading from, so it shouldn't inconvenience staff using their own sticks who don't want to encrypt them. A pop-up asks if you want to encrypt when you insert one - if you answer 'no' then it's read-only. We've had very little issue with it and staff know they need an encrypted stick if they're going to write any document to it.
  9. Yes, folders setup at the root of their mailbox (not under inbox) by the user in Outlook or OWA. Exchange has root folders as a selection for retention purposes.
  10. I've setup Exchange retention as follows: Folders - 7 years (life of the student) Inbox - 1 year Sent items - 7 years Deleted items - 7 days It all happens automatically and the staff are well aware.
  11. Yes, we use intake2017 etc. for groups and it makes it a lot easier - change the group permissions (e.g. age-appropriate filtering) rather than the memberships.
  12. Lucid Exact is used by our SEN department and generates excellent reports. Y7-Y13 so may not be a good fit for sixth formers but a recommendation for Lucid, anyway.
  13. We use LANsweeper Helpdesk. Nice browser interface that we place on every desktop to allow problem reporting. Links with main LANsweeper so that users and assets are selectable. Keeps a good record of problems reported by user and asset.
  14. Thanks, I checked those permissions and it seems to be fine. I also reset the domain, giving it administrator authorisation. The AD structure shows, but no machines. It's no biggie, we've learned to work around it now.
  15. The two critical settings for the OS boot drive are: Computer Configuration, Policies, Administrative Templates, Windows Components, BitLocker Drive Encryption, Operating System Drives - Require additional authentication at startup (Enabled, all options set to Allow...) - Enable use of BitLocker authentication requiring preboot keyboard input on slates (Enabled - essential for Microsoft Surface or other tablets when without a keyboard) For USB drives: Computer Configuration, Policies, Administrative Templates, Windows Components, BitLocker Drive Encryption, Removable Data Drives - Deny write access to removable drives not protected by BitLocker (Enabled)
  16. We can do nothing about 3G/4G except educate the parents and insist on the teenage filter with contracts. Tethering we prevent by using the Meraki Air Marshall and repeatedly killing hotspots.
  17. We only turn it on for specific guests and change the password each time.
  18. We replicate all our servers in Hyper-V now, which gives me comfort that I can failover if I need to. All VMs are backed up to 8TB caddies kept in our cars on rotation, plus one in the fire safe.
  19. Get rid of RM CC4? We have BitLockered all our laptops and tablets. Where they have TPM, they just boot into Windows directly. Where they don't, they stop and ask for the password. It all works very smoothly and, since we record all BitLocker passwords and keep the recovery files, we have not lost a single machine build yet.
  20. Our domain is still the old school name because of that. However, we do still have Exchange (now 2016) on premises.
  21. It could be, we denied SMB1 via Group Policy across the whole network and removed the feature from servers. Why would SOLUS3 use SMB1?
  22. No DNS events. I should have said that we see the AD structure but no Computers in that root group.
  23. I should have explained. We use BYOD for our staff and students' own devices. Visitors can use the guest system which filters lightly and doesn't inspect.
  24. We've had this (no computers showing) in SOLUS3 for a while now. I either add existing machines by looking at Agents or I add using the IP address. Annoying but I never raised a support case for it.
×
×
  • Create New...