smarties11
Members-
Posts
645 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by smarties11
-
This is certainly possibly the case with your other devices, however I'm not so sure with the GEOs. They have confirmed to me in email that the GE114 doesn't support PXE boot, and they are awaiting a BIOS update from the motherboard manufacturer. The older GE109 revision works. I suspect there's something missing in terms of the range of devices supported. I've three or four different types of USB ethernet here that I've used loads of times to PXE boot various non-ethernet-equipped devices that won't work on the GE114! We have tried using a USB hub, all of the various BIOS options etc to no avail, except with the StarTech
-
Hi, I concur! I ordered a couple of different branded USB ethernets on Thursday out of desperation, including the StarTech. I'm back on-site today and the GE114 does indeed PXE boot from the StarTech. It also recognises it immediately at boot unlike the Realtek chipset based ones which don't appear until they are re-plugged, even with the latest driver which is meant to prevent this. So for anyone else imaging these - you need the StarTech USB31000SW if you want to PXE boot them (or likely any other adapter based on the ASIX AX88179 chipset). I've tried two types of Realtek based ones, a TP-LINK one and this is the only one that works so far.
-
Really? If that's the case I'd really appreciate if you could share your settings. GEO have told me that the GE114 won't PXE boot without a BIOS update, and they won't commit to a timescale on releasing it!
-
I'm guessing you must have the GE109 rather than the GE114? As the 114 doesn't support PXE boot and that's what we have 😕
-
Did you have success imaging with SCCM? I'm finding it an absolute nightmare. We're booting from a USB boot stick due to the lack of PXE boot, but the problem is most of them won't see a USB ethernet dongle at boot, you have to unplug and replug it. This means the task sequence fails because at every reboot step unless you are there to unplug/replug there is no network connection. I've got one or two so far that have been successful but most not. I've tried all the options in the BIOS relating to USB, disabled fast boot etc. Tried two different types of dongle. Injected the latest USB ethernet drivers into the WinPE boot image and the driver package deployed to the laptop during TS. We've used these same USBs on other laptops no problem. I'm going to have to build an offline task sequence on a USB HDD at this rate then just add to domain at the end? I've never ever come across such an awkward machine to image in my entire IT career spanning 20 years!
-
Has anyone seen or heard anything yet about a BIOS update for the GE114 to fix the forgetting admin password and PXE boot issue?
-
We do similar here; a tip with regard to the installer that comes with O365 - it's never bang up to date (unless you are on current channel and deploy O365 updates every month perhaps), so new users will get a Teams install that's a few revisions old and then have to wait for an in-app update. What I do is download the latest installer from MS every couple of weeks then use a GPP to copy this to C:\Program Files (x86)\Teams Installer\Teams.exe
-
Thanks all! I've discovered even on my own machine a couple of issues today related to IE11 being uninstalled (I removed it yesterday). First is the .url shortcuts need re-associating to Edge, second is that the Office Customisation Tool stops working in SCCM. The main reason for disabling is that to use Smoothwall Cloud Filter you have to install a Chome/Edgium extension, and then disable IE11. But I'll just use AppLocker to block it on those machines I need to for now. We already have Edge set as the default browser, have done for the last couple of years and I've also removed all shortcuts to IE11 now. Seems odd for Microsoft to take it out of standard support and still rely on it so heavily?!
-
Hi All, We've deployed out the latest Chromium based version of Edge, and most users have been using old-Edge or Chrome for years anyhow. I figure we should be disabling IE11 now, we do have the odd user that still uses it because the IE11 icon is 'the Internet'. Is there an easy way to accomplish this site wide? I know it can be removed through Windows Features, but can this be done centrally through a GPO or any other way? I guess I could block it in AppLocker. Or script the removal in PowerShell. But just wondering if there was any more straightforward way! I was quite surprised to see that it is still turned on by default even in 20H2 despite being out of general support since October. Thanks!
-
We use the supplied Education Teacher, Education Secondary Student and Higher Education Student policies and have these assigned to our students and staff. The policies are then tweaked for our requirements. For example we assign higher Ed to y11/12/13 and have student cameras enabled in these, but disabled in the secondary student policy which is assigned to Y7-10. We have Salamander Integration Suite, so this handles the automatic application of policies for student and staff, but you can do it in bulk either through PowerShell or using the tools in Teams Admin. There is a wizard now I think that you can use to assign policies by group or by license type.
-
We also ran into this issue last week, recording required to be deleted - not possible because the recording was within the Team. We opted in to OneDriveForBusiness recording mode as soon as it became available in November, following the instructions that were issued at the time (which I think are the same as those which Lionman linked). I've checked again today and RecordingStorageMode is still set correctly for OneDriveForBusiness as per the instructions. Then it dawned on me. This is the setting for the global policy, and of course we have Education_Teacher applied to our staff. So I checked that policy using 'get-csteamsmeetingpolicy -Identity Education_Teacher' and sure enough, RecordingStorageMode is set to Stream still. Doh! Bear this in mind - if you apply a meeting policy to your staff, the command will need to reflect that, e.g. Set-CsTeamsMeetingPolicy -Identity Education_Teacher -RecordingStorageMode "OneDriveForBusiness"
-
Many thanks for posting this, this has been on my to-do list for a while. I'd considered using publisher rules before however I wasn't sure how many different combinations would need to be on the allow list. Having this official confirmation from Microsoft is perfect. I've just put into place here and removed the path rules we had set up previously and test, works perfectly. Thank you!
-
Ah, I see. I hadn't considered from that perspective as we discounted scheduled lessons when we piloted Teams, for the reasons already mentioned! I can see why this would cause problems if you have gone down the scheduled lesson route. If this was my School, I'd be insisting that we disabled anonymous access. Talk to parents via student M365 account. And then externals with A another technology. Safeguarding trumps everything, afterall.
-
I don't really see what you mean. From what you've written it seems like you are over complicating things and blending two completely different scenarios (live lessons and external meetings). This is what we do for each of those scenarios. For live lessons.... - Anonymous access enabled, because as you say - it's required for external meetings - Students always access their live lessons by signing in first, using the School issued M365 credentials and therefore bypass the lobby - Staff know that they must never admit anyone in via the lobby - We use 'meet now' rather than schedule lessons which means students don't get the join link by e-mail, they can get it once they have joined the meeting but as long as staff don't admit anyone through the lobby that is irrelevant For other meetings... - Parent meetings we encourage that these are done via the student account wherever possible - then again, signed in via student M365 account - For others, staff create a schedule meeting and invite the external, they join via the lobby either as a guest using their own Teams account or anonymously if they have joined without signing in - Staff admit via the lobby - Much less likely to get a malicious user here as your external people are highly unlikely to forward the join link for giggles like the kids With the above in place, we've never had anyone yet join one of our lessons or meetings that shouldn't be there, and we've been running this setup since June, through various bubble closures (at one point we had 5 of 7 bubbles closed) and now through full lockdown, teaching a full timetable to our students every day.
-
I disagree. Any School that is allowing students to join a class without providing credentials, only asking them to type their name and taking their word for it, is asking for trouble. It's safeguarding basics. Likely these Schools have rushed into Teams / live lessons without a proper pilot and full evaluation. I mean, would you set all of your students AD password to their name? Or would you think "oh, hang on a minute, it won't take them long to realise that they can sign in to all their mates accounts too" The way to do it is to instruct students that they MUST sign in to Teams and join the meeting that way. Either via their calendar in the case of scheduled meetings, or via the Team itself if you are a 'meet now' School. And tell teachers not to admit ANYONE in via the lobby. Simples.
-
So are you saying that you've had students able to gain access to meetings either - by bypassing imposed authentication or by forcibly getting through the lobby without a teacher admitting them (hacking) OR - that students are gaining access because a teacher allowed them in via the lobby and trusted they were who they said they were (not hacking) You need to be clear on this because if you're suggesting there's a security vulnerability in Teams, there's 1,000s of Schools up and down the country that need to know about it in order to consider the safeguarding implications.
-
This sounds very cryptic. Can you share more details?
-
You can achieve this fairly easily by creating the relevant address lists and global address lists, setting the permissions and then using address book policies to assign them to your mailboxes.
-
I'll check when I'm back at work but we've been able to do this lots of times with varies external people and agencies etc. I hadn't realised this, I've just checked and you are right. However, with meet now this still shouldn't matter - to get far enough to copy the link, your students are already signed in with their valid credentials. Therefore, teachers then just ignore anyone that comes in via the lobby.
-
You could still use meet now if you built new teams and channels to reflect your collapsed classes? Even if you had a really basic structure, e.g. A team for the whole year group (all year group students are members) and then a channel for each subject, or teacher etc. And then just tell the students where they need to be, and when. The other option is simply not to admit guests. Make sure students know that they will only get access to the lesson if they are logged in with the O365 credentials.
-
Yes, when we type an external email address with these settings, it turns into an invite link which we click. They then receive the invite. Again, IMO meet now wins on safeguarding too. The only possible way a student can connect to a meeting is by signing in with their valid O365 credentials, and being a member of the class team. Using scheduled meetings, the invite URL can be shared with anyone. Some randomer could join one of your lessons simply by entering a valid student name in the lobby, and then get admitted by the teacher. This actually happened in a local School, students shared the invite with their mates in other Schools, they then joined the lesson and starting taking the p!ss out of the teacher!
-
It works for us as long as they are invited using their external email address. We publish student timetables to mailbox calendars (which show in Teams too) using Salamander which tells the student where to be. With meet now, students can only join once a teacher has started the lesson, which makes the lobby redundant in my view. I can only speak from our own experiences. We tested both ways and using scheduled lessons we ran into all the issues you describe. With meet now, it has been very successful, plus it means your teachers / admin staff don't need to schedule the lessons. We've had fantastic engagement and attendance from pupils, far in excess of what other local Schools have managed. Ultimately its your choice but IMO teachers should be using the technology to teach, rather than the technology create the additional classroom and behaviour management burden you describe.
-
You don't need the lobby if you don't have guests. To meet now, students must have already logged in with their O365 credentials, so the lobby is bypassed. The only other setting they might want to change is to make themselves the only presenter. But you can change the default policy (via PowerShell) so that this is the default setting anyway, so that any meeting initiated by a Teacher will always start such that any students joining are attendees only.
-
You only need external access turned on to have meetings with externals. You don't need guest access on. That is for when you want externals to be actual members in your teams and see all the posts and files. I mentioned earlier in this thread but the way to avoid students joining random meetings etc is NOT to schedule the lesson. This creates an e-mail invitation with a link, and this link can be passed on to anyone (and allows them to join as guests). I know of lots of Schools locally using this method and it's creating an unnecessary classroom control burden on their teachers, who are facing the same issues as you. Instead, ask your teachers to 'meet now' within the relevant class team & channel 5 mins before the start of the lesson. Students then just browse to the team & channel at the correct time, see the meeting running, hit join. They are never in possession of the meeting join link so can't mess about. It makes it impossible for them to join meetings for which they are not a Team member. Scheduling the lesson also allows students to join it before (and after!) it has finished. With meet now, once the meeting is ended, it's gone. We've been using this method successfully since June throughout various bubble closures and now a full lockdown. We're teaching a full timetable to every student with over 90% attendance. It works!
-
SQL has fully supported TLS 1.2 since early 2016 so I would hope most people have run a service pack / CU since then! It's the app rewrite that is the issue as I suspect it won't be quick.
