jmak
Members-
Posts
5,569 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by jmak
-
People tidying up the loose cable from a phone with a pass through port is how I found out a network we'd recently taken over didn't have any loopback protection switched on You'll want to check that if you go ahead.
-
[pics] Biscuits with excess accents and apostrophes?
jmak replied to 6Foot2's topic in Jokes/Interweb Things
Doesn;t look like it;s Mike;s work [emoji3] -
ClassCharts - breach or not?
jmak replied to notalot's topic in Data Protection & Information Handling
I'd send a report to the ICO with a copy of the emails from Classcharts -
The OP is in a difficult position. When you want to buy something that wasn't in last year's budget, something else is going to have to get cancelled - £20k is almost enough to employ a full time IT tech,or heading on two term time only classroom TAs. (Obviously it's not, but it is a big lump of money.) TLDR: it's a lot of money, but actually good value. I got lucky when I introduced an OVS subscription. We had a set of teacher laptops with Office 2003 going out of support and a new set of 30 student laptops and no money to buy the perpetual licences the school had always bought. I demo'd libre office to SLT which they approved and I deployed it to all clients so that everyone had the same. The teachers hated it and there was uproar (although the students managed fine). I was asked to think again and proposed OVS. As they'd asked me, rather than the other way round, the money was found. It turned out to have lots of benefits - I could update and upgrade the windows editions to match across all PCs and go to Enterprise edition which allowed Bitlocker. All the PCs ran the same version of Office. I bought additional server licences so that I could virtualize. There are lots more advantages now as mentioned earlier in the thread. The other point I'd make is that at £5/month, it's less than half an hour of time costs for someone on minimum wage. If you have a Microsoft background, the amount of time you'd spend learning about and supporting another system also has a cost.
-
Pretty sure that wouldn't work, but this should: https://www.tp-link.com/uk/home-networking/powerline/tl-wpa4220-kit/with a unifi AP on the far end - presumably powered with a PoE injector. I had something similar at home years ago. Obviously anything peeling will depend on how your electrical supplies are wired, but I found them to be easier to connect than the instructions suggested.
-
Things that could have been improved before being approved...
jmak replied to 6Foot2's topic in Jokes/Interweb Things
DPD chat bot goes rogue: -
This ^^ I found this workaround for testing when I worked in schools and I was always slightly terrified - what if the child support agency found out that I had parental responsibility for 20 kids? What if.... something bad!? Document explicitly what roles you're giving yourself, with which individuals. Agree it in writing with the head teacher and remove all permissions/roles asap.
-
Surely you work in the IT department? As in the department for supporting IT which can exist in parallel to the department for teaching IT. And some IT departments only have one person in them...
-
Not a school, but we've done CE for a few priority groups. It looks like there's going to be an organisation wide programme with almost indistinguishable standards - I presume the driver is to reach the standard without spending the money. Most of it is what you already know should be happening already, but the requirement for CE accreditation gave us the leverage to implement things (mostly policies) that had previously been resisted. One thing that did get authorised and probably wouldn't have done if we weren't seeking accreditation was a centralised patch management system which I've been after for years. You will need full backing from SLT. We had lots of people who said it was impossible or too invasive and they went whinging to managers, but in fairness, SLT led by example and told everyone else to get on with it.
-
I had a 32" 4k at work, but I have it to someone else and got a 27" 4k. I like the space of the bigger monitor, but I find there's too much up and down head movement for comfort. Side to side is fine. I tried a 34" ultra wide and the format was good, but it was too small! Definitely at least 1440 and 27" was the sweet spot for me. Different sizes for the second screen don't bother me - as long as I can perfectly align either the top or bottom of the screens.
-
Windows Server: Replacing Server What Best to Do
jmak replied to talksr's topic in Windows Server 2022
I haven't tried many different ways, but p2v made it really straightforward and low risk. You can be certain that everything will continue to work and have no downtime other than the equivalent of a server reboot - actually just while you move the network cables from one to the other. Then as others have suggested, create a new DC. Then create more VMs and gradually split roles across. (I actually put an extra DC on it in a separate VM which lots of people thought was mad, but I stand by - it meant that in effectively a single server school, I could carry out maintenance on the DC during working hours. I then put most of the other roles in one more VM, but depending on requirements and resources of the server I might split it out more now.) In a similar situation to you, I didn't put anything that would affect real-time service on the old server. I put an extra DC on it, an extra backup (we were using cloud backup, but I thought a local copy might be useful) and a WDS/MDT deployment server. -
The Microsoft way for BYOD accessing cloud services is "Conditional Access" which is fairly straightforward to implement. As an overview, the BYOD is registered on Intune on your tenancy - it's not a full member, just a lightweight registration - to allow basic checks like supported and updated OS. Once the user connects their organisational account on that machine, it creates an encrypted "container" on their device storage and any data belonging to the organisation is only stored within that container. The M365 admin can remotely delete the data from the BYOD machine. You can also set rules to prevent users downloading files. There are other data loss protection facilities in M365 that's fine more on the data side than the device side that might be worth looking at.
-
I get that this may be expected by parents as they constantly check where their own children are, but maybe they need to be told "no". It's not like it's a teenager walking home in the dark by themselves. Surely an update when the coach leaves with an ETA from the sat nav based on traffic information, an update if that ETA changes by more than 10 minutes and an update when the coach is 10 minutes from its destination and one when it arrives would be plenty? I also seem to remember that the coach company we used when I last worked in a school already had a system in place - might be worth checking that?
-
I'm assuming you've checked depth? I wanted to put a T410 in a cabinet that was mostly empty apart from a router and a few switches, but the door wouldn't close
-
GDPR - Tips and Tricks for staff
jmak replied to titch's topic in Data Protection & Information Handling
This answer is why it's worth posting questions on a specialist forum. A response from the experts on how to avoid making mistakes based on a real world example. It didn't come up near the top of a sensible Google search. -
I'm creating security policies for some users who I don't want to have access to cmd or powershell. I have them blocked in group policy for the required users, but they can still open Terminal. Is there any straightforward way to do that? At the minute I'm playing with deprovisioning the app for some users, but I haven't got my head around how I'll control who does it does not get it. Many thanks
-
I think this might be what people are referring to: /showthread.php?p=1696218 Ahem... the last version, just found a copy: SIMSBulkImport_2.5.0.0.zip Zip file contains: * SIMSBulkImport_2.5.0.0.msi * SHA-1: 63ec7c2af8886c34102a5a30a8e46690472e058a * VirusTotal scan result Manual_2.5.0.pdf * SHA-1: 37310406d772f716a69d3febbe69fc7cc3fe8aad * VirusTotal scan result For some reason the MSI is not digitally signed but it is the correct version:
- 4 replies
-
- applications
- bulk
-
(and 1 more)
Tagged with:
-
It depends what PII is in their school email account.
-
I'm sure it was exponentially better...
-
I thought if you configured active hours WUfB only installed updates outside of that, even if the PC is restarted. Maybe my users are more patient than I thought as no one has complained. As an alternative, you could remove the option for students to restart or shutdown the PC.
-
The browser based MFA that (caused controversy when) I mentioned in another thread works fine with MS. Not a recommendation for the browser based approach, but does suggest that other authenticator apps are compatible. I think they all use the time based approach rather than the notification and number confirmation that MS use.
-
Came across this last week - I haven't tried it yet https://hackaday.com/2023/11/29/converting-bluetooth-sensors-to-zigbee/
-
I'd use a free trial of one of the network inventory tools to run a report. Several of them offer a 30 day free trial. Manage Engine Endpoint Central or Tanium or Ninja One wind be a starting point
-
Presumably you could continue using it if someone was prepared to pay for it? I know site licences can get very expensive for these things, but I would have thought it should be manageable within the cost of supporting an individual student's needs.
-
I don't think it will help in the loft - as I understand it, the idea is that it brings drier air from the loft into the house. If you have condensation in the loft, you probably need more ventilation in the loft. There are different roof designs - the simplest problem to fix would be that the existing ventilation is blocked. A common cause is that loft insulation has been topped up and is more covering the vents in the eaves.
