-
Posts
1,672 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by foofighterjim
-
Oh, now this is interesting. We've just had a new S10 appliance and I patched it to the latest release before putting it into production. We've had a couple of occasions in the last month where the BYOD authenticates in the morning but just seems to stop by the afternoon, everything returns to normal the following day. I've spent very little time investigating has it has only happened a couple of times and I've had a bit on my plate. Pretty much the same setup as you but with Aruba IAP; Smoothwall doing the RADIUS and DHCP.
-
Went with the pink, I'm in the minority as usual
-
Yes it is pretty good, coming from Aerohive there are a few plusses and a few negatives, for instance: + APs are relatively cheap, compared to most. + The IAP system if pretty robust and fault tolerant. + Regular and clear updates from Aruba over any known vulnerabilities. - Guest wireless unusable without a properly signed SSL cert (can't be wildcard). - Maintenance and configuration can get a little complicated if you mix multiple models of IAP into the same setup. - Interface (both versions) leaves a lot to be desired.
-
What MFA hardware tokens are you using with O365 / G Suite?
foofighterjim replied to pete's topic in Cloud Services
I've been looking at: https://deepnetsecurity.com/authenticators/one-time-password/safeid/hardware-mfa-tokens-office-365-azure-multi-factor-authentication/ The Diamond tokens can be used if you don't happen to have an Azure P1 or P2 subscription but do cost a couple of pounds more than the others. -
you can stop personal Windows devices from being enrolled into Intune by going to: Endpoint Manager> Devices> Enrol Devices> Enrolment Restrictions> Device Type Restrictions Click on All users and then go to Properties. Under Windows (MDM), change personally owned to block. Here are my settings, not reason to worry about iOS, Android or Mac in my testing so far. Users should get an error if they leave the box ticked to say the device couldn't be enrolled, but please test.
-
Coronavirus: General discussion (see opening post for rules)
foofighterjim replied to Dos_Box's topic in General Chat
I'll look into this, I wasn't given a date for the 2nd jab when I had my first. I was just told to book it when contacted by my GPs office. [emoji1745] -
Use their App Finder wizard to get the msi: https://appusers.pixl.org.uk/appfinder.php I created an mst to remove the desktop shortcut. My install was just: msiexec /i PiXLApps3.msi TRANSFORMS="PiXLApps3.mst" /q
-
Saw that Game and the MS Store had some availability this morning, I've ordered a Series X with an extra controller as the eldest has just started getting interested in games. I honestly wasn't fussed initially but a friend recently got one and it just made me envious. My OG Xbox One just runs so slowly now, constant popup in open world games, couldn't even play Ori and the Will of The Wisps properly due to lag in some of the environments (absolutely nothing to do with ability:)). Given the amount of time I actually have to play these days, I actually want to enjoy it when I do get the chance, not waiting 10 minutes to start the Xbox and actually load a game. As you can see, I'm rehearsing my explanations to Mrs foofighterjim this evening!
-
Just arrived, thank you very much. I really quite like the new sock design, could definitely see these in neon pink with electric blue for the heel and toes (go all out 80s).
-
Network drives:
-
Coronavirus: General discussion (see opening post for rules)
foofighterjim replied to Dos_Box's topic in General Chat
Don't forget that in the next few weeks, the very first groups to have their first jab will need their second, this will reduce the rate of first jabs and they may need to hold some vaccines back to ensure supply. -
Coronavirus: General discussion (see opening post for rules)
foofighterjim replied to Dos_Box's topic in General Chat
Had my first Oxford jab on Saturday, no side effects that I've noticed. Whole thing was very efficient, I was in and out within 5 minutes. -
I had the form submitted message like @DJ-1701 but not had a confirmation email.
-
Same, need to mitigate for a positive test and a bubble being sent home, especially whilst the testing is being done in school and is "verified". We have our Year 11 & 13 students scheduled to bring them back in early June, with the rest in mid July.
-
No, you don't keep access to the ISOs. It is not a Volume license agreement so you get nothing in VLSC under Windows 10. Nor can you get them from the Licensing and Billing section in O365. I thought it was a mistake initially, after speaking to MS they confirmed that this is the case because it is not a volume license. You can only get the ISO from: https://www.microsoft.com/en-gb/software-download/vlacademicwindows10iso and this is only the current release. You can't activate Windows on a M365 license away from Azure. The license is user based and must be authorised against Azure AD. You can actually use M365 Apps (Office) on a standard domain joined machine. Users just have to sign into it when they open an application for the first time. You can configure this with a roaming token, under shared device activation, to a share, so users can move computers without being prompted to sign in again.
-
Big thing to note about the Windows aspect of the M365 A3 license. You are only covered for Windows 10 if the devices are AAD or Hybrid AAD joined, at least 1903 (I think) and the device must have a Windows 10 pro license. Any pre existing activations with say, a KMS key are not technically valid, it must be activated with the digital license that the device has. So, for instance, if you have any older hardware that only has a Windows 7 or 8 licence, that you are now running Windows 10 on through OVS entitlement, these devices are not valid for the license. This aspect has recently caught me out, so don't let it happen to you.
-
I am just testing the Redstore solution but I've also heard good things about Barracuda.
-
I had seen them but dismissed them because of the Euros, how is their service / product quality?
-
Morning All Does anyone have a trusted supplier of OATH hardware tokens for Azure MFA, ideally one that quotes in Sterling (I've found plenty in $ or €)? So far the only one I have found is deepnetsecurity.com who have given me a quote. We are looking for ones that generate a code rather than ones that rely on an USB port being available. I've contacted all of my usual suppliers and none of them are able to source anything. Ta
-
As it is per user licensing, you need to license all staff who require a login to you Domain / Azure. Plus, in my experience, you'll need a handful more to cover things like maternity cover or creating accounts for new starters before being able to remove the license for the departing member of staff. It can be hard to get the balance right.
-
Sorry for bringing up an old-ish thread, having a similar issue with MFA during Autopilot and also with Students installing O365. Out of interest are you guys using A3 licenses? We've just realised that when installing O365 on Desktops our users are now being prompted to register their MFA details (and Windows Hello too!). Closing the prompt for MFA gets rid of it and the applications end up registered, but still. I believe I may have found the policy causing this, if you go to: Azure AD> Azure AD> Security> Identity Protection> MFA Registration Policy Ours is set to All Users for Require Azure AD MFA registration. The problem is, the whole section is greyed out and I can't see a way to change it, it appears that you need a P2 license in order to do so. No idea why Microsoft have set this as default and then hid the ability to change something so fundamental behind the P2 paywall
