smarties11
Members-
Posts
645 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by smarties11
-
Have you looked at VeriCool? We've had it for over 10 years, and I'll be honest in the early days we had lots of issues but it got better with time. More recently we've upgrade to their latest SwiftQ platform, with new tills and cashless vending and it's been fantastic so far. Tills are super quick and has made a huge difference to our queuing times. Support has been great too and they've even made tweaks to how the vending system works based on our feedback. Worth a look, and you'll likely find it cheaper than the options mentioned here so far.
-
Yes, we are using the desktop client. If you use a recent build of the Office 365 Pro Plus on your clients, it gets installed by default on user logon. We used to block it from installing with AppLocker but now we are using it we've removed this rule. If you use AppLocker too, in whitelist mode as you should be doing, then you need a bunch of rules in place to allow it to install and run, as it installs and runs from user's AppData. Why they didn't make it install to Program Files I don't know?! Presumably to make automatic updates run without any IT input? I can share our rules if you need them. Also when it auto-updates, it downloads the .nupkg file to the users download folder. So if you have Staff who take laptops home, you need to ensure you are NOT redirecting the downloads folder to the network, as that prevents Teams updating and borks the Teams install when users are at home. Downloads must be redirected to the local user profile. Found that out the hard way!
-
Air Con for Server Room : Recommendations?
smarties11 replied to fiza's topic in How do you do....it?
Agree with ITGURU, get two for redundancy, wired into a controller on redundancy so that the units alternate each day (and the second unit kicks in if first unit fails or can't maintain temperature). You can try and justify the cost by explaining to your HT that two units running only 50% of the time *should* last as long as a single unit running 100% of the time. I think we paid about £6k for two units and a controller, this was after our previous unit failed when we were in Nottingham spending time with my FIL who had just had a major operation for terminal cancer, to extend his life. I had to remotely shut everything down, and then arrange a hire company to deliver a decent portable unit ready for 6am on the Monday morning so I could start everything back up again. Trust me, you don't want your aircon failing - it could be at the worst possible time as I discovered! -
Hi All, We're in the process of deploying Teams for live lessons. We're doing this with two year groups in July as a proof of concept for a whole School rollout in September, should it be necessary. So far it's going really well. We've done several live lessons as part of our internal testing with our key worker pupils. We've applied policy packages and tweaked these to our requirements, and I'm 90% happy with it, however there's a few bits I would like to get nailed if possible. Can anyone help with the following? 1. Is it possible for the meeting recording to start automatically, rather than teachers having to initiate this process? We'd only want this within our class teams, not in normal calls or non-class teams 2. Is it possible to get students to join as attendees by default, rather than the teacher having to set the meeting presenter preferences to 'me only' on each lesson 3. I've changed the policy package so that chat is off within meetings for students, but this has no effect? The only way it seems I can achieve this is to change the channel settings in each team so that only owners can post. This is fine for now but we might want students to post in the channel in future, but not chat in the meetings 4. Is there a Powershell command available to set channel settings so that only owners can post? Or is this only a GUI setting? Hoping for a speedy alternative to doing this manually on several hundred Teams! 5. Is it possible for background blur to be turned on by default for all meetings initiated by a Teacher? 6. Is it possible to stop students creating their own teams? I can't see anything in the policy packages for this. Can it be done with a normal policy, and if so can I use normal policies and packages in tandem? 7. Does anyone else find the raise hand feature isn't always available? I've never had it appear yet for a student, and it will sometimes appear for staff We could happily launch in our current state, but I'd like it to be as slick as possible. You can probably guess that for most of these points, what I'm trying to do is reduce the amount of steps Teachers have to remember for every meeting! Any help from Teams experts on here would be greatly appreciated!
-
[sims] Capita is trying to sell off non-core businesses (SIMS is for sale)
smarties11 replied to psydii's topic in MIS Systems
Anyone got a spare 500 mil? Capita SIMS for Sale: Capita looks to sell its education software solutions (ESS) unit as the board prepares to approve an auction - Finnemore Consulting -
Yeah absolutely! The tricky bit was getting through the first line support and convincing them it wasn't an issue our end. The support engineer initially tagged it against another Teams issue which was quite clearly unrelated to our troubles. Once they had established it was affecting more customers and created a full blown incident, it was dealt with within 24 hours, which is awesome.
-
This has now been resolved. Woohoo!
-
Yayy! Finally we have recognition of this issue by Microsoft! Expected resolution tonight at midnight :-D
-
[ms office - o365] Microsoft Teams meetings without Exchange
smarties11 replied to mrssevage's topic in Office Software
I wasn't able to find a way to do so. But it's pretty straightforward to connect it to your on site Exchange server, if that's what you have, by setting up oAuth and enabling sync of exchange hybrid in AD Connect. -
How are you achieving this? Is it a case of presenter invites you into the meeting then they share desktop and you request control? Or can you access all ongoing meetings from the admin Centre? Our admin Centre is borked at the moment and awaiting a fix from MS. Is there then away to temporarily stop broadcasting the desktop to the audience whilst you work on it so students can't see what you are doing? We are telling out staff not to share desktop, only application windows to avoid accidental projection of sensitive material.
-
Thanks guys. Still broken for me. I have 6 working days to get Teams configured, policies applied etc and I can't do anything in TAC! 😬 Today's update from MS was that their senior engineers are working on it, but they won't commit to a timescale. They say others are affected, the guy I'm dealing with says he had 3 or 4 Schools with the same issue as us. Then he sent me a random article suggesting I needed to add Teams as a trusted site in Internet Explorer. FML!
-
Hi All, We're in the process of investigating Teams for live lessons. Today when I try to access Teams admin, it's littered with errors on each page - so I am unable to manage users or define Teams policies. It was working fine last week. Today I've run the HCW (full hybrid) on our Exchange 2016 server, it was successful except for the oAuth config - which I then did manually following the MS article and tested successfully. We now have Teams calendar integrated with Exchange 2016. I don't know if this is related or not? Logged a ticket with MS and got a call from a guy who said there was currently a live incident for this issue, however when I asked him to show me there were no incidents live for Teams. He pointed me to an issue from yesterday (MO216274) and is going to call me tomorrow - however I can't see how this incident has anything to do with our issues and think I'm being fobbed off. I've checked with a couple of other Schools and they can access Teams admin fine. I've now logged an incident too, hopefully this will reach a different tech team to my ticket. Does anyone else have issues today? Errors attached.
-
thenational.academy Vimeo Videos
smarties11 replied to robyholmes's topic in Internet Related/Filtering/Firewall
How do you mean it's flawed? It's quite a clever feature on SmoothWall I think - the URL patterns basically means it will only allow the main URLs (vimeocdn.com etc) IF the pattern matches, and as you are only putting individual IDs in the patterns this means you give access to ONLY the videos you want, not the whole of vimeo? The only thing you are doing for the whole of vimeo is turning on HTTPS inspection. You don't need to do that bit if you already decrypt and inspect everything. You can do the same with YouTube on SmoothWall too. -
thenational.academy Vimeo Videos
smarties11 replied to robyholmes's topic in Internet Related/Filtering/Firewall
@robyholmes - this is the article you need to follow for SmoothWall. We're not using Oak in School however we do use Hegarty maths which has hundreds and hundreds of Vimeo videos and this is the guide I followed for our SmoothWall which worked great. https://kb.smoothwall.com/hc/en-us/articles/360002033410-Allowing-Access-to-View-Embedded-Vimeo-Videos TIP: you can easily put together a spreadsheet in Excel that will create the right text for you to go into SmoothWall after entering a Vimeo ID. Create a new spreadsheet. In A1, type the vimeo ID. in B1, type ="player.vimeo.com/video/"&A1. In C1 type ="player.vimeo.com/video/"&A1. Then you can fill the formulas down and simply type in all the Vimeo IDs or copy and paste them if Oak provide a list like Hegarty do. Then in Smoothwall, you can switch to the full text editor in the rules and paste the whole lot in one go rather than creating each one individually. HTH -
Thanks for the input guys. Thankfully I've managed to solve the issue now so support won't be required. At least I know for the future though.
-
SOLVED IT! Checked the event logs to see the effect of deleting the old certificate, and saw an error from the transport service saying it couldn't find the old certificate, it would use the new one in the meantime but that I should restore the old from backup. So deleting the old certificate forced the required behaviour, but there was still an issue. Happened to see an event log message for our Anti Virus and that made me wonder.....and yes, our AV (McAfee Endpoint security) was preventing Exchange from changing the security on a private key. Good thing I suppose? Temporarily disabled the AV and then ran the PowerShell command to re-assign the services on the new cert and it works. I correctly got the prompt asking me whether I wanted to replace the old certificate with the new and now the errors in the event log have disappeared. Hope this helps someone in the future.
-
Yeah, that's pretty much it! I expected SMTP to fall back to non TLS but it's still running on TLS so I guess Exchange was like 'OK OK I'll use the bl00dy new certificate then' and got on with it! I reckon Exchange Online will be on the cards for us in the not too distant future, as well as Teams, Stream etc. My only bugbear is the backup; I know many Schools do just rely on Microsoft's resiliency for this but I still feel we need backups of our cloud data and I haven't yet found a product that does this anywhere near as affordable as maintaining our own internal backups. There have been cases of Schools 'losing' their cloud data in malicious attacks (including one School literally down the road from us who had to start their network again from scratch - although it's debatable what measures and competencies they have within their IT team but nevertheless, it happened) and our own backups is a non-negotiable for me.
-
Hi, Thanks, yes I'd be interested to see your scripts please! I had thought about going down the LetsEncrypt route this time around as our certificate renewal price was stupid, but managed to get them down to a sensible price in the end. We have a wildcard cert with SANs for Exchange and use it on quite a few services so didn't want the hassle on the 90 day renewal - especially when on things like Ruckus you can't automate it. I used ECP initially however when I ran into issues I switched to PowerShell and both give exactly the same error. In the end I bit the bullet and deleted the old certificate from the local store, hoping that would force Exchange onto the new cert for SMTP. That seems to have done the trick. And mail flow is still working as expected. I'm pretty sure it's just some sort of bug in Exchange. Fingers crossed...
-
Yikes!
-
I've got the cert itself in 'personal'. The intermediate in 'intermediate certification authorities' and the root in 'trusted root certification authorities'. This is how I've always done it in the past, and is where the exiting certificate is located? EDIT: I've assigned services back to the old cert, removed the new and re-imported. Exchange itself places the cert in 'personal' (local computer). If I move it anywhere else, Exchange doesn't see it - so surely this is the correct place? I've never known them to be anywhere else since Exchange 2003. I'm starting to wonder whether this is a non-issue. I get the same error when assigning SMTP to any cert - whether it's the old one, new one, or the self-generate one. Hmmm. I also noticed that when I re-imported the new cert and assigned services, and then view certificates that SMTP is not assigned to it. As soon as I grant read access to the private key for 'NETWORK SERVICE' it shows as SMTP assigned. I don't even have to run the command to assign again. I'm *hoping* that the issue is that for whatever reason, Exchange doesn't have the rights to adjust private key permissions - and so adding them manually corrects that. However, I still can't remove the old certificate, I get an error saying that the internal transport certificate cannot be removed. So Exchange is still using the old cert for internal transport and I have no idea how to change that. I'm wondering if it will automatically use an alternative certificate (i.e. new one) once the old one expires on Friday? Really hoping that we don't have SMTP issues on Friday :-/
-
Hi All, I'm trying to contact Microsoft support regarding an Exchange issue we are having (I posted yesterday about this issue). I've phoned the support number and chosen Business (there was no option for education). I was then signposted to support.microsoft.com/oas Here, I've filled out the details and am then told we have no support contract (logged in with my MS account linked to our OVS agreement), and we have to pay $499 for a single incident 24x7 support plan. Is this right?! I've never needed to contact MS support before throughout my career. I thought as an education customer we'd get some support, or at least discounted prices?! Have I missed something?
-
Hi All, We use a public certificate to encrypt our Exchange traffic, and we have this assigned to IIS and SMTP services. It's a wildcard cert with SANs for autodiscover etc. The existing certificate expires on Friday, and I have just installed the replacement certificate. The certificate imports fine, however when I then attempt to assign the IIS and SMTP services, I get an error. This happens whether I use ECP or EMC. The error is below. Google research suggests that this is because the 'network service' account doesn't have full permissions to access the private key, however I've tried adding the network service account to the private key permissions (full control) in the certificates mmc and I still get the same error. When I view existing certificate in both ECP or EMC, it shows the new one installed and says it is assigned to both SMTP and IIS?? It presents the new certificate correctly when I try OWA but I'm not sure how I would test SMTP. Any ideas? A special Rpc error occurs on server S-XXXXXX: Could not grant Network Service access to the certificate with thumbprint xxxxxxxxxxxxxxxxxxxxxxxxxxxxx because a cryptographic exception was thrown. + CategoryInfo : NotSpecified: ( [Enable-ExchangeCertificate], InvalidOperationException + FullyQualifiedErrorId : [server=S-XXXXXX,RequestId=0ce68699-de3e-4ac4-9c7a-094b538d302d,TimeStamp=01/06/2020 13: 59:03] [FailureCategory=Cmdlet-InvalidOperationException] D9EA479C,Microsoft.Exchange.Management.SystemConfigurati onTasks.EnableExchangeCertificate + PSComputerName : s-XXXXXX.xxxxxxxx.co.uk
-
[ms office - 2013] Outlook Web App Profile pictures
smarties11 replied to thepridster's topic in Office Software
Just to add to this thread how to remove photos for all users as I needed to do this today. From Exchange PS run $users = Get-ADGroupMember -identity "#ad group name here#" -Recursive foreach ($user in $Users) {Remove-UserPhoto -Identity $user.SamAccountName -Confirm:$false} Just replace #ad group name here# with the name of a group that your users are a member of. I did it in two hits with our 'pupils' and 'staff' groups. Hope this helps! -
There's a couple of mentions here of people running SIMS and CMIS on Server 2008R2 etc and the work involved in migrating to a new server for what might be a short period of time. If your existing server is virtual then consider an in-place upgrade to Server 2012 - that's what I did here with our SIMS server last summer. It worked absolutely fine and Server 2012 is supported until October 2023. The only minor issue I had was that I had to re-install .NET framework. Not ideal by any stretch but migrating to a new server including all the MIS links to various external sources would have been a right PITA. If it had failed I'd have just rolled back the snapshot and planned a full migration, so there was nothing to lose in trying. Hopefully SIMS will have released SIMS8 by October 2023!
-
Hi, I'm setting up TinkerCAD for our DT department. There is an option to 'Sign in with Microsoft' however it won't accept any O365/Azure creds. It seems to need a personal Microsoft account rather than a work/school one. Is there any way to integrate it with O365/Azure authentication? I'm sure I've read somewhere that this is possible but now cannot find it! Thanks :-)
