Jump to content

smarties11

Members
  • Posts

    645
  • Joined

  • Last visited

Everything posted by smarties11

  1. We had a demo of it earlier this year and didn't like it. It's not Android compatible as already mentioned and critically [for us anyway] it doesn't support the Profiles module in SIMS for doing annual reports! Have you had a look at EduLink One? (https://www.overnetdata.com/edulinkone) It offers parental engagement too but works out cheaper than SIMS Teacher App + SIMS Parent App. This is the route we went down after looking at various offerings from 3rd parties.
  2. You can use the built in iOS/Android mail app instead or GMail? No reason to specifically use Outlook!
  3. Yes I'm sure it would help in terms of the storage space required. I might try zipping one too. I've done some more digging today and this is 100% an Outlook mobile app issue. On Saturday (our log file was 5GB), we had 3,300,517 IIS hits on our Exchange server. 3,102,193 (94%) of these came from the user-agent Outlook-iOS-Android/1.0. 2,917,697 (88%) of these came from the 5 worst offenders! I think we're going to have to block Outlook-iOS-Android/1.0 for now unless someone can suggest the best way to throttle these server side? We've got 121 users using the Outlook App so it won't be a popular decision if we block it!
  4. It's not the security I am concerned about. It's the fact that our logs have increased in size by 100x with no apparent reason. Clearly this will have a performance implication and cost for our server and out clients! I'm sorry but the answer to this is not 'just feed it some cloud storage'...
  5. Hi All, We migrated to Exchange 2016 from Exchange 2010 over the summer. I've noticed recently that the daily IIS logs are HUGE! They started at around 120MB per day (Exchange 2010 was about 60MB per day) - they've been increasing steadily in size and are now 2-3GB per day, the largest one being 5GB! I've looked at the logs and we have some ActiveSync devices (we allow all staff and Y11-13 students to use ActiveSync) that are creating ~300,000 lines per day in the log file! The vast majority of these are using the iOS/Android Outlook app, so this seems to be a factor at play. I've called 4 of the worst offending devices into the office and on three of them I've removed the Outlook profile and recreated it, and on the fourth I have removed the Outlook profile and set up the e-mail account in the native e-mail app. In all cases, the log file entries per day have decreased down to 3,000ish; although this is still much higher than the average device which is around 300 entries. I've looked at the iOS and Android Outlook app options and there appears to be no way of controlling the frequency of sync. I thought about blocking the Outlook app using a device access rule in Exchange, but then I wondered if it was possible to throttle the connection at the Exchange server instead. I've done some research on throttling policies but there are literally hundreds of options and I'm not sure which ones I need. I don't want to negatively impact on the user performance nor affect other clients e.g. Outlook desktop on our domain machines. Can anyone point me in the right direction with the relevant commands and best practices? I like to keep IIS logs for 1 year so that we are able to look back in time in the event of a breach, but there's no way we can afford the ~1TB of storage this would require! Thanks!
  6. Hi All, We're having some ongoing issues with our HiPath 3800, which is running OpenScape. Our current support provided have tried all sorts of things to fix it (including most recently replacing one of the cards and completely wiping the config and building from scratch), however our issues still persist. The latest issues today are issues with some phones intermittently powering on and off. And some phones appear to be "delay calling" where you'll dial a number and nothing happens. So you put the handset down. A minute or two later, the call is made, so the persons phone you were calling rings and when they answer they can hear you in the background (presumably via the loudspeaker microphone as the handset is still down). The support company downloaded diagnostic data from the system (which took a couple of hours!) and they say they are sending it to Siemens in Germany. They've the rebooted the system, but it didn't come back on. This is where I was asked to help, we were able to get it back online by doing a hard power reset, but it took 2 attempts. I think the support company are probably out of their depth. I was wondering if anyone a) had any ideas what might be causing these strange issues and b) could recommend a company who's engineers are more experience with these systems? Thanks!
  7. Thanks for clarifying your position @lwalshaw, it is appreciated. The message that came back from support was "Be aware that feature requests only get reviewed should other schools request the same feature", hence my post! I hope you do not see my post as negative; as I said we're really impressed with the system and we are excited to launch to staff and our first batch of parents next week.
  8. Yes, I'm not saying that what they have is insecure by any means, I just don't feel it would stand up to ICO scrutiny in the event of a breach. It's an accepted standard these days that when you are dealing with sensitive information a security check takes place. In the event of siblings, the system could ask for the DOB of the eldest child on roll? If one of our administrators mistypes parent [email protected] as [email protected] and we send the registration link out, we've then opened up a student record to a stranger and breached data protection legislation. I appreciate the fault here lies with the person making the typo, but then isn't this what validation checks are designed to do, to add an additional layer of security to help avoid human and criminal errors [which are always going to be inevitable]? We use ParentMail for parental communication / payments (although hope to retire this once EduLink have their payment module up and running), and they do a security check based on student DOB. This works well. It's a piece of information that the parent has already provided to the school in a separate exchange and would stand up to ICO scrutiny.
  9. Hmmm, that is interesting because it was change #2 (calendar) where they specifically responded "Be aware that feature requests only get reviewed should other schools request the same feature.", but we now know that at least 2 schools have requested it.... Your #6 is also a good one. I will add it to my list! It's #1 that is most concerning for me. I'm quite surprised a verification check wasn't considered as part of the original spec :-/
  10. Hi All, We've recently purchased EduLink One as a replacement to SLG. I have to say, the system is fantastic and we are very impressed. However, we've come across a few missing features (which we have raised with them) - but they will only action feature requests if they are reported by multiple customers. So, my post is basically to ask if any EduLink One customers here would benefit from my suggestions below, and if so would you please mind making a feature request to them? 1. Onboarding parents by e-mail - the system sends the initial logon credentials to parents by e-mail. My feature request is to add a security check (e.g. ask parent to enter child DOB) when they click the link. This would tighten security and avoid a breach if the e-mail was sniffed in transmit, the recipients mailbox was compromised, or there was a typo in the e-mail addressed recorded in SIMS which resolved to a valid third party recipient. We are going to use CSV export and mail merge manual letters (username in letter via student, password in letter by post) in the meantime as we don't feel the existing e-mail method would stand up to ICO scrutiny in the event of a breach. 2. Make the event titles in the calendar module populate from the SIMS 'description' field instead of the SIMS 'category' field as it does currently. We (as I am sure most schools do?) use SIMS calendar categories as ways of 'grouping' event types together, however this means what shows on the calendar in Edulink is pretty much pointless. The only way around this at present would be to create calendar categories in SIMS for every event e.g. 'New York Trip' or 'Y11 Parents Evening' which seems crazy. 3. Show a lesson number or time on the 'next lesson' widget at the bottom of the page. If it's currently lesson 2 and your next lesson isn't until lesson 4 (i.e. you are free lesson 3) then this can be ambiguous without an indication of time/lesson number. 4. Register tags - you can add a register tag for 'missing consent' i.e. consent requests which parents have not responded to. It would be useful to have 'declined consents' as an option too - this would give teachers visibility on who in the class cannot be photographed, for example. 5. Register flood fill - you can effectively disable this feature by adding all codes in the 'marks prevented from flood fill', but the button still remains. It would be useful to have an option to remove the button. We don't want our teachers to flood fill registers, but the button remaining gives them hope that they can! TIA 😎
  11. Nope, you've not misunderstood. E-mail received on the 23rd May says.... New T&Cs - https://smoothwall.com/uk-terms-and-conditions/ (I'm told that ONLY point 4.1 has changed)
  12. Seems crazy to me! If you're using it as a UTM as we do then that's a major piece of the network puzzle - I'd want to spend 2 or 3 months on a procurement exercise looking at alternatives, arranging trials, making sure it was fit for purpose etc - add on 3 months notice period and it means you're having to look at alternatives 6 months into your existing contract?! The SmoothWall line is that this is in the interests of their vulnerable users, as cutting off services when a customer doesn't make their renewal intentions known to them would leave them un-monitored. Which makes no sense at all - as in this scenario they would just renew the contract if 30 days notice isn't given, as per their previous T&Cs. I don't see how increasing this to 90 days from 30 is of any benefit to the customer at all - but SmoothWall say that they have made this change on the advice of their customers who prefer this model?
  13. Hi All, SmoothWall e-mailed customers on the 23rd May to notify them of an immediate change to their Terms and Conditions. Be aware if you have a contract with SmoothWall, that the notice period required for termination of the contract has moved from 30 days to 90 days. This will obviously need factoring in to any procurement exercises.
  14. Hi Tony, I can try! OK, for your mapped drive, create a shortcut in your redirected start menu called "Q Drive.lnk" and put C:\Windows\explorer.exe Q: as the shortcut target. Then make sure there is a line in your layout XML as follows....(obviously making sure the column/row reference is correct) For edge, make a shortcut called "Edge.lnk" in your redirected start menu and put %windir%\explorer.exe shell:Appsfolder\Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge as the shortcut target. Then make sure there is a line in your layout XML as follows....(obviously making sure the column/row reference is correct) Give this a try and if it doesn't work post your XML and I'll cast my eye over it!
  15. Thanks for this tip. Not a product I have seen, but it does look good! Are you using the free community version or have you paid for enterprise?
  16. There's a few ways to achieve this in SCCM. You can pre-create your computers in the SCCM console, or import them if you have details of their MAC addresses in an existing system. Then when you deploy an OS it will see the existing record in config manager and use that name. I find the easiest way is to create a variable called 'OSDComputerName' in your unknown computers collection. You literally add this as a variable on the 'collection variables' tab of the collection properties, leaving the value blank. Make sure the 'do not display this value in the CM console' setting is unchecked. Then, when your OSD task sequence runs, if the computer doesn't already exist in the database it will prompt for this variable and use whatever you input as the computer name. If you are re-imaging a PC and you want it to have a different name to the existing one, you just need to ensure that you delete the computer from the database first. For this to work you need to have enabled 'unknown computer support' on your distribution point. It's on the PXE tab of your distribution point properties in Administration -> Site Configuration -> Servers and Site System Roles. Hope this helps!
  17. Thanks @pete for your feedback, it is much appreciated!
  18. Hi All, I was wondering if anyone had any opinions on the SmoothWall Monitor product, which they acquired from Future Digital last year (used to be Policy Central before that I think). We currently use Securus but have been offered discount on our SmoothWall filter if we take both. We've seen the demo and it looks quite basic against Securus (that isn't necessarily a bad thing - Securus is over complex for our safeguarding staff) but seems to tick most boxes. If you are using it I'd love to hear your real world feedback. Thanks!
  19. You are welcome! It's possible I guess but I think it's more likely to be errors with your shortcuts.
  20. YAY! Now just a case of putting them back one by one and working out which setting is causing the issue. What I did here when we started our Windows 10 deployment was to put Windows 7 WMI filters on all the existing GPOs, so that none of them applied to Windows 10. I then built new policies with a Windows 10 WMI filter. It took longer but starting from scratch meant I was able to review the group policy settings we had in place previously (which were inherited from Windows 7 and Windows XP prior!) In respect to the missing tiles you should be able to troubleshoot those individually - first thing to check is that the shortcut in the all programs list actually works. If the target doesn't exist then the tile doesn't appear. Once you've got it all working as you want it you should be able to put back your policy to hide the all programs list - though I don't know if this will break the tiles, I've never tried this approach. We keep the all programs list in place and remove all the junk apps from our source image. Have a good weekend :-)
  21. You definitely don't have a profile set for the user in the profile tab on AD? Can you browse to the path of your start menu OK when logged in as the user? If you disable your start layout file can you then see the all programs list? What version of Windows 10 are you using? The next thing I would suggest would be to put the user in their own OU, and block inheritance on that OU in group policy management console so that the user has no group policies applying. Then create a new policy to set only the folder direction to see if that works (in case some other GPO setting is interfering) This is one of those issues where there are lots of factors/errors at play. I think we've ironed most of it out now it's just a case of working out the last piece of the puzzle. The way I've described is exactly how we have it set up here with no issues on 400+ clients.
  22. Great! We're getting somewhere now. The issue is with your folder redirection. The shortcuts you have saved in \\server\icons\student\start menu are not showing in the start menu list. Unless you can get them to show in there, your tiles and XML won't work. As I mentioned earlier, the shortcuts must actually appear on the start menu all programs list if you want them to show as a tile. Next step to check is your event log. There will likely be an error explaining why the start menu redirection failed. Also check the NTFS permissions on the folder and also the share permissions too. The share should be set to 'full control' for the 'everyone' group as is standard practice with shares where you use NTFS to set the granular permissions. Make sure the NTFS permissions on your icons, student and start menu folders have permissions set for read access on a security group that encompasses your users. I just use the 'everyone' group again and have read & execute, list folder contents and read permissions set. You can easily test the permissions by logging in as your test user and then attempting to browse to \\server\icons\student\start menu - does it let you see the folder contents or do you get an access is denied message?
  23. Another vote for SCCM. We started using it last year for our Windows 10 roll-out, moving from fat images to zero-touch thin provisioning. It's a bit of a pain to set-up (especially the installation) but once you've done it you won't look back. All we do now is PXE boot a machine and the task sequence I have built does the rest. Installs the base WIM, injects the drivers for that particular model, provisions BitLocker for off-site devices, adds to domain if not a member, names the computer, installs all our core software include Office 365 client, AV etc, removes unnecessary printers, installs optional software based on task sequence parameters set, activates Office 365 using device based activation. Literally once the task sequence is complete all we do is test the machine and then put it in the classroom. Beyond that, we use it to manage Windows updates (you can also inject these into the base WIM so that newly deployed computers have the latest updates from the off), software deployment, remote control and reporting. There are built-in tools and reports to manage your Windows 10 servicing branches and the same for Office 365 client branches. If you have WOL enabled you can also incorporate this into your task sequences so you can remotely PXE boot a machine and start the deployment process. I'm a huge fan now and it's really streamlined the process of deploying a machine and keeping it up to date and means you don't have to mess around keeping images up to date every time you have a new driver, update or piece of software to manage. You just add a new step into your task sequence. I've also retrospectively installed the SCCM client on our Windows 7 machines (not many of those left now though) and am using that for patch management, application deployment and remote control on those machines which has replaced some legacy tools and systems. It's not expensive to add on to your EES/OVS agreement. The client licenses are already included in the desktop bundle, you just license your server(s). My only regret is that I didn't start using it sooner!
  24. Hi, Your folder redirection GPO is incorrect. The bit that you have set to 'create a folder for each user under the root path' should be set to 'redirect to the following location'. The way you have it set means that it is looking in \\server\icons\student\start menu\username for the shortcuts. Also make sure that 'grant the user exclusive rights...' and 'move the contents of the start menu...' check boxes on the settings menu are NOT checked. Hiding the start menu all programs list is making troubleshooting harder for you at this stage. The shortcuts need to be visible in this list for the tiles to work, and by hiding it you can't check this. I would make this list visible whilst you are testing and then hide it again once everything is working.
  25. Another point to add - it's worth deleting the user profile of your test user between each test, as the start layout is cached!
×
×
  • Create New...