-
Posts
1,672 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by foofighterjim
-
Home working and emails to phones
foofighterjim replied to djrscally's topic in Data Protection & Information Handling
This is one of the things I am now looking at properly to get a resolution. Like you I was not entirely convinced by they built in (MDM) policies and I read these two articles last night: https://support.office.com/en-us/article/capabilities-of-built-in-mobile-device-management-for-office-365-a1da44e5-7475-4992-be91-9ccec25905b0 https://docs.microsoft.com/en-gb/intune/introduction-intune Just from reading these I was thinking that we may be forced into InTune to guarantee the level of security I would be happy with. Would you be able to divulge what you actually did with your mailbox policy? -
It is the usual chicken and egg scenario. Game developers don't want to risk making a game that nobody has the hardware to run, people won't buy hardware there's a limited number of games for.
-
If you haven't already used your free Xbox Game Pass trial then SoT will be on this from release.
-
Anyone getting Sea of Thieves? It would be good to have some edugeek groups sailing the seven seas. cdkeys have the digital version on sale for £42.99 at the moment (only £1 more than the disc version from Amazon and £8 less than from the Microsoft Store): https://www.cdkeys.com/xbox-live/games/sea-of-thieves-xbox-one
-
Interview questions for Computing/ICT Teacher
foofighterjim replied to Chipie's topic in How do you do....it?
I had to do this before Christmas, just do a little reading of the national curriculum to see what they need to achieve (it is surprisingly broad). I think I asked something like what would be your preferred languages to teach KS3 & KS4 and why? In this instance its not so much about what specific languages they pick (although some are much more appropriate than others) but the reasoning behind it. I also threw in a question about the OSI model (can't remember the specific question though). -
I would suspect that RM would have a tweaked GPO for an CC4 Access RDS server, not sure how dissimilar that would be to the standard workstation GPO on CC4. I would hesitate to recommend it but nothing to stop you from trying. If I were in your shoes I would be inclined to go with the CC4 Access solution though, at lest then you have the assurance that it will play nicely with CC4.
-
I think that is all CC4 Access is, a CC4 based RDS server (if I recall my conversation with them correctly). If you go this route just confirm that the options for mapping local resources are disabled (such as clipboard and printers), it could lead to a whole world of GDPR issues otherwise.
-
Smoothwall Authentication
foofighterjim replied to blu4's topic in Internet Related/Filtering/Firewall
Yes they do, their IDex agent: https://help.smoothwall.net/Latest/Content/idex/about.htm -
Me too, good chance of us moving away from RM this summer so any help I can get on the GPO front is appreciated.
-
GDPR and 365
foofighterjim replied to mikemcsharry's topic in Data Protection & Information Handling
Some of this can be mitigated with the O365 security centre but it is really basic. It looks to me; to really have control of the data you need InTune. -
Office 365 - Security and Compliance Center
foofighterjim replied to gsk's topic in Data Protection & Information Handling
I believe you need to "buy" a licence for Microsoft Azure Rights Management in order for it to work. We have it so it must free to education i.e. we definitely haven't paid for it. -
GDPR and 365
foofighterjim replied to mikemcsharry's topic in Data Protection & Information Handling
Have a look at: https://www.microsoft.com/en-us/trustcenter/privacy/where-your-data-is-located It should state (somewhere) in your global admin account what geo location your data is stored. -
Office 365 - Security and Compliance Center
foofighterjim replied to gsk's topic in Data Protection & Information Handling
Yup, my rule kicks in if the message is marked as confidential (seemed like a logical thing to do). -
Smoothwall VPN - Remote Desktop - Home Printers...?
foofighterjim replied to abillybob's topic in Windows Server 2012
In my eyes access to any local resource is dangerous as things can be printed, moved or copied by accidently or deliberately. You could justify that emailing documents is a deliberate act and the user is fully aware of what they are doing but you would be ruling the accidental angle. As far as data protection goes we have to mitigate the accidental element as much as possible, deliberate acts you can't always do much about but at least the onus is on the user at that point. -
Home working and emails to phones
foofighterjim replied to djrscally's topic in Data Protection & Information Handling
In O365 Security and compliance you can select basic options such as "Require data encryption on devices" before allowing it to sync, I know InTune provides a multitude of additional options such as location based 2FA and not allowing the storage of attachments on the local device. -
Smoothwall VPN - Remote Desktop - Home Printers...?
foofighterjim replied to abillybob's topic in Windows Server 2012
I would be actively discouraging this practice, it would be far too easy for something confidential to be printed at home and seen by people who shouldn't see it. You could make the argument that this could be covered by staff awareness / training but it is simply a hole that doesn't need to be there. As per the image @mikkydoos has put up printers and clipboard are definite no no's for a remote connection in my book. -
Same as @sllorep used them for leasing our Smoothwall, no complaints.
-
@Dos_Box; rough night or not a morning person??
-
Would love to go just for alexisonfire let alone Cancer Bats & Less Than Jake! Alas foofighterjim baby 2 is due in May so no chance this year (or the next 5).
-
(Another) CC4 to Vanilla thread
foofighterjim replied to foofighterjim's topic in Network and Classroom Management
I completely agree but playing devils advocate; Windows 7 EOL January 2020, Windows 10 1709 EOL March 2019 (not sure if CB and CBB use the same EOL date), this is one of my major frustrations with WaaS I'm sure I'm not alone in this. As much as I think long term I must also approach this one with a good deal of short term planning. I suppose that is the other question I have seen on here a few times; CB, CBB, or LTSB! My poor brain () -
(Another) CC4 to Vanilla thread
foofighterjim replied to foofighterjim's topic in Network and Classroom Management
By the way, I haven't had time to reply to everyone but thanks to those who have sent me PMs, a lot of helpful information in a good number of them. Just to bring the thread into line with where we are now up to. We are almost certainly going the Vanilla route, I am certain that RM will lower their prices to try and keep us but unfortunately it may all be too little too late. So I'm thinking Vanilla Server 2016 on Hyper-V (possibly SAN as I'm not convinced of S2D if we ever have / need disparate server hardware), Veeam to NAS and latest data replicated to the could (as its purely for DR). Not 100% sure on SCCM or InTune at this point but am keeping an eye on them, especially if a good number of Chromebook like devices start coming to the market with InTune licences included. The big question is Windows 10 and / or Windows 7. Some of our Netbooks will only run Windows 10 so we could never be completely Windows 7, so already we're juggling two sets of GPOs if we go Win 7, sounds like a less than ideal situation for a newbie vanilla team. Equally if we go Windows 10 we will be supporting an unfamiliar OS (from a GPO perspective) on an unfamiliar network the chances of us being anywhere near effective at identifying and resolving issues are remote. There is an abundance of documentation for us to dig into for Windows 7 problems, whereas Microsoft seem to introduce new issues & bizarre GPOs (or lack of, I'm looking at you Edge) with every release, there is also substantially less documentation to back it all up. I am still of the opinion that partnering with a 3rd party may be the way to go for us to give us a safety net but with us driving the design. What I am going to do this week is setup a new VLAN and spin up a 2016 DC and a Windows 10 client, I'm going to play and see how far I can get with GPOs, possibly Sysprep and WDS. Out of interest how do people document GPOs? Is it just we have xGPO and it is intended to be used for X, Y and Z it is applied to this OU and these individual objects? -
For those of us without a DPO yet...
foofighterjim replied to djrscally's topic in Data Protection & Information Handling
Exactly what we are doing. Staff here have recently had a data awareness meeting and I did a presentation this morning on where we currently are regarding staff USB devices and like likely courses of action available to us to ensure compliance. -
(Another) CC4 to Vanilla thread
foofighterjim replied to foofighterjim's topic in Network and Classroom Management
Let me know if those extensions come in at a favourable price, if so it could be possible for us to keep the hardware and just change to Vanilla this year and then do the hardware the year after. -
(Another) CC4 to Vanilla thread
foofighterjim replied to foofighterjim's topic in Network and Classroom Management
Now why hadn't this occurred to me! I could attach the server and a host or two the staging network, they wouldn't have internet access but I could at least try and play with the GPOs without interfering with the rest of the network. -
(Another) CC4 to Vanilla thread
foofighterjim replied to foofighterjim's topic in Network and Classroom Management
Thanks for the training recommendation, I will have a look at that over the weekend. As for the testing (this will sound utterly pathetic), the best we have going spare are computers with 10 year old AMD Athlon 2000+ processor with 2GB RAM and a 120GB 5400rpm SATA II disk. Budget until May is £0.00
