Jump to content

jmak

Members
  • Posts

    5,567
  • Joined

  • Last visited

Everything posted by jmak

  1. Microsoft's own guidance is now that security updates should be installed within three days, so weekly sounds better than monthly.
  2. I didn't have to win that argument - our 40 year old boiler packed up and the radiator and pipework needed replacing because they were equally old and it was 8mm microbore, but.... The heat pump installation including 20 new radiators, all plumbing and electrical work was done in 5 days (team of four plumbers). It was chaos for a week, but then over. I've evangelised about our ashp on here before and it was a great improvement on our oil fired CH, but I'd do something different if I was starting now. I wouldn't install a system that doesn't also cool my house. The model of ashp I have has a different spec in Australia and can run in cooling mode, but the UK variant doesn't. Otherwise I'd be swapping out some radiators for these: https://theheatpumps.co.uk/products/chilled-water-fan-coil-units.html Alternatively I'd be seriously looking at air-to-air to completely replace my wet heating system.
  3. You want to put a whole year group in detention at the same time 😲 What did they do!? /sarcasm
  4. I have: Goretex with zip-in fleece for all occasions Goretex with zip-in fleece for all occasions with additional ventilation from where OH's cats expressed their views on being captured and put in cat carrier Goretex with zip-in fleece for all occasions with additional ventilation from when I fell off my bike Hi-viz Goretex inherited from someone who carried it on a DofE expedition as hi-viz was mandatory, but they were too cool to wear it.
  5. Three of us received it simultaneously during dinner. We all grabbed our phones and tapped on it, at which point it disappeared before any of us read it. It's not stored anywhere on my phone (Pixel 9, Android 17). I did discover that you can access messages at gov.uk/alerts but the only one published there at the time was in Welsh. I'm not convinced the subject justified it. "There's a fire five miles away; be ready to evacuate" seems like a good reason to alert everyone. "It's come to our attention that the population is so stupid they need to be told not to set the whole place on fire" seems like ultimately a bigger problem, but less immediately urgent. Related: do people put their phones on silent or turn them off during concerts/theatre/cinema?
  6. This is my draft user guide Passkey_Setup_Guide.pdf
  7. Most people use laptops and for the last four years I've specified fingerprint readers and most of the new ones have Windows Hello capable cameras, so for convenience I think most people will have a passkey on their main device. I have one on my phone in the MS Authenticator app which I find works well. The user experience with a hardware token on the machine you're logged in on is much better than even simple passwords. I'm sure it'll be broken at some point but I think they're a genuine upgrade for users and admins.
  8. I'm aiming to push our users towards passkeys as quickly as we can. We've had multiple successful phishing attacks despite authenticator based MFA. Issues for us (not a school): 1) A mostly universal solution for an alternative second factor when they lose/change/forget/drown their phone 2) An option for people who want to login to desktop computers that they haven't used before, e.g. presenting at a venue that has a PC as part of the hosts AV setup. There's a third internal issue for us: the team that runs the tenancy is not the team that runs active directory. I haven't yet persuaded them to talk to each other and run the command that will allow it as authentication for logins to domain PCs.
  9. If you have OVS or should be free. You have to place an order and "buy" licences, but it should be zero cost.
  10. Do you mean they used shared device activation for the OS? We don't have the complication of CertiPort, but we use device based activation for Office 365. The machine has to be in a specific M365/Entra group and Office then activates based on the DBA licence being applied to that group.
  11. Referring back to previous comments, Teams has a Speaker Recognition feature. You do need a Teams Room Pro licence (around £40/year/room for Edu) and a decent (ideally Teams certified) mic.
  12. I haven't faced that specific requirement, but conditional access policies should allow you to restrict login to domain/Intune joined Windows devices for a specific M365 user group.
  13. The answer isn't to block security updates. From your own description, you can run iPad OS 18. My suggestion is that you compromise on the number of installed apps - that's how you can keep the devices functional. Cyber security is a basic requirement that *does* come ahead of teaching and learning. Without it you can't keep your legal obligations for KCSIE and is essential to ensure your school doesn't become the next victim to a cyber attack. It's equivalent to decommissioning PE equipment that doesn't pass safety tests or DT tools that are worn out. They probably still work and there's a high likelihood that no one will come to harm before the summer holidays and withdrawing them from service will impact teaching and learning. No responsible leadership team would take that risk and they should have the same attitude to cyber security.
  14. It's an often asked question in this forum and I think you might be about to become the expert! When I worked in a school, I went for Unifi. It was an easy decision - it was a massive upgrade on the home grade unmanaged access points we had and the total spend was around £600 Vs about £9.5k for Aruba. That included three years licensing but I knew I wouldn't be able to afford the ongoing costs and the Unifi had zero ongoing costs. In the non-school setting I work in now, I don't have any influence on the decision, but the network team are very keen on the Aruba platform. They get a lot of value from the management platform. If you can afford it and you'll use it the Aruba might be worth it.
  15. Seems like a warning from the future - the only step missing is having AI sit the exams. At which point the participation of a human in that process becomes futile. That's the future I think we need to prepare for: work out what we can do that people don't want to be done by AI. I was speaking to a friend who recruits for a graduate training scheme - the skill they want is understanding of and ability to use AI tools and they're finding that students have minimal exposure. The focus has been on preventing them from using it at school and university.
  16. It's a major risk, but you can control it. We have multiple vendors supplying third party support who use a remote access platform to access machines on our network. It's not unreasonable for a tech company to have a system of tools to do their job. However, you do not need to leave it there as a backdoor for someone to access whenever they want. I have seen users allow that and support companies install it while they've got access to the machine. The executable mentioned above that doesn't install is plenty. Attackers pretending to be IT support is one of the most successful ways of getting remote access to a managed network. You need a process to ensure the person accessing machines on your network has a legitimate reason and is who they say they are.
  17. Just get a guest Wi-Fi network running and tell people to use Wi-Fi calling. Although there's a lot more flexibility in the law now, it's still strictly regulated and not straightforward to implement.
  18. We're using Jira Service Management - the AI agent is the built in Rovo.
  19. Your original post mentions crafting your own AI agent. That is achievable but non-trivial and introduces significant risk. The Hannah Fry YouTube video is a very good demonstration of that. If you mean using a commercial agentic AI product on your environment, then that's an entirely different prospect - but still significant and potentially consequential. I don't work in a school any more, but our team is making extensive use of Claude - often for "traditional" AI tasks like analysing and summarising documents, producing user guides and knowledgeable articles. The recent change for me is using the agentic features. Yesterday I used the Claude browser plugin running on a tab where I was signed in to Jamf with a prompt along the lines of "create a configuration profile which sets an iPad to run in single app mode to launch x webpage and some it to this group of iPads". It then worked it's easy round the Jamf console clicking buttons and produced the profile, applied it to a group, pushed it out and the iPad on my desk restarted and launched the webpage. I did similar with Jira last week: create a form to gather these details and apply it to a new request type called "request service a" and add it to the portal in x space. That needed a bit more tweaking and I wouldn't have released that to general availability before proper testing, but it did work. I'm finding it genuinely useful, but one of our key purposes in using it is to try to get ahead of our users to find out what gates and guardrails we might need to put in place. Web based learning just became (even more) pointless. As an experiment I opened one of our learning packages in a browser and gave the prompt "watch the videos and complete the course. Then take the quiz". Ten minutes later a certificate of completion popped into my (and my manager's) inbox without me viewing any of the content or any further interaction. I mentioned the browser extension - that's because I run an ARM based windows machine so the Claude Cowork application won't install. On other Windows clients, MacBooks and Linux clients the installed version will operate on any application or setting you ask it to, so much more powerful - I'm thinking "add a registry key" or "create a PowerShell script to do x and run it". Quite a step on from "Gemini, please tell me the steps to edit the registry" or "create a PowerShell script to do x". You may have your environments locked down, but most users who'd asked an AI how to achieve something would get a fairly good set of instructions on the standard way to do things which you've probably got blocked. With agentic AI, it'll just keep searching until it finds a way through, which is a different risk profile. We've set up an autonomous AI agent in our help desk. It only runs out of hours and one of the first tasks in the morning is to review the tickets it's answered - not because it gets a lot wrong, but because we (currently) want our users to feel they're getting a personal service. It looks at our knowledgeable and previous ticket responses to attempt to answer the queries and the agent got its first five star review last month. Some users will hate it, others value a solution to their problem out of hours - the alternative is no answer at all until the help desk opens. Our team's paid subscription to Claude is the only group pro licence registered. Anyone else signing up to Claude as an individual with their work domain email address gets a prompt asking them if they want to join our team. We've received hundreds of requests to join in the last month - to me that indicates there's a real appetite for it and that we need to be ready for our users to have access to it whether we want it or not. All they have to do is sign up to a service with a personal email address and then they can run it in a browser to access any of your systems they have a login for.
  20. Does anyone have any experience of Hexnode? We currently use Jamf to manage Some devices and the free tier of Manage Engine MDM for Android, but we're outgrowing that. I'm therefore revisiting device management and the cross platform capability of Hexnode appeals.
  21. I presume when you're talking about £400 plus a week's work, you mean a week of an employee's time - which is fine as long as they're not taken away from doing something they're paid to do and their time is less expensive than a contractor.
  22. Only based on who I have used rather than any bad experiences: Currently Phoenix although decision is way above my pay grade and find them responsive and helpful. I had the same experience when I did choose the supplier in a previous job. Softcat were great when I used then for licensing in a previous place and are very competitive on the items I buy from them now. John Levis at Very PC has been very generous with advice on this forum. I haven't used then for software, not have made other purchases over the years and always had a good experience. All of them a good shout for your three quotes 😎
  23. Signal offers WhatsApp like features with privacy for users and from what I can tell better security and privacy for the organisation. You need your phone number to sign up but it doesn't need to be made visible to other users. It's our backup option to use if we lose access to our tenancy and anything that's SSO with it.
  24. But seriously - you need to ditch WSUS and move to WUfB. WSUS was always a necessary evil - it needed a lot of love to keep it reliable. With WUfB you remove one more pain point. Also, once per half term is not nearly often enough to run updates. We run them every day. Shared machines get force rebooted every night. Single user machines get a forced reboot once a week ) users get a notification when there's an update waiting to be installed. If they fail to choose a time convenient to them, they lose control and it's forced on them over the weekend. There were moans when we first implemented it, but users soon learned that it's better to choose a time than be unexpectedly forced into it.
  25. I personally wouldn't take the reasonably foreseeable risk of buying a brand that I might be mandated to remove. BT has had to remove Huawei kit from their network at their expense. It's a bigger scale, but maybe that makes it more worrying.
×
×
  • Create New...