Jump to content

jmak

Members
  • Posts

    5,569
  • Joined

  • Last visited

Everything posted by jmak

  1. I personally wouldn't take the reasonably foreseeable risk of buying a brand that I might be mandated to remove. BT has had to remove Huawei kit from their network at their expense. It's a bigger scale, but maybe that makes it more worrying.
  2. Isn't AI supposed to convince us it's human-like?
  3. The fleet I'm responsible for is still AD managed and authenticate against a DC, although they are hybrid joined. However we do have a fleet of around 7000 Intune managed Windows devices and they are Entra only managed. They tend to be in clusters as generally whole organisational groups move at the same time, and we haven't found any issues with high density.
  4. I've always thought of lifetime as "until I die" or possibly "until whoever takes over from me dies" which essentially means until the end of time. I've come to realise that's probably unrealistic and for IT/network kit I'm now satisfied with "until the date I was told security updates would be available when I bought it". If I think that's unreasonable short I won't buy the product and if it's not receiving security updates I'll remove it from my network anyway.
  5. Reasonable has changed - it's comparative. We have been a mostly Dell shop. We'd just made a decision to double the RAM of a standard build to 32GB as we expect five years life and the £35 cost was negligible over that period, but now it's a £150 upgrade we're considering halving to 8GB instead! Or maybe going for the MacBook Neo which will probably manage well on 8GB. We've also found that as well as quotes now only being valid for 14 days, we regularly find that the item we got a quote for is out of stock within a couple of days making process even more (upwardly) volatile.
  6. 👏🏻👏🏻👏🏻 Have a 🍺 Edit: The question is whether to add automation that plays it in the office when one of the team closes a ticket, or add it to the closure notification sent to users!
  7. Plenty of built in usage reports and you can set and manage print quotas in Hive. No option for a payment gateway, but charging departments shouldn't be a problem.
  8. If you want to move, you might have to consider a non-school job. If you don't fancy industry, you could look at higher education, NHS, County Council (they have quite a lot of IT unrelated to schools) or an MSP. All of them pay better than schools and often more scope for car development and a lot have local opportunities. Edit: More likely to get career development than car development
  9. I've quickly checked the horses, they're fully saddled up and heading for you. It's really bad form to interrupt when someone's in the middle of a crisis. There's lots wrong with trying - you're saying you believe talking to you is more important than getting their own school running again.
  10. https://www.linkict.co.uk/news/what-the-uks-new-cyber-security-and-resilience-bill-means-for-your-school-or-sme/
  11. You can do it without an enrolling as devices in an MDM for Cyber Essentials using Conditional Access policies with MAM-WE (catchy name). It's primarily intended for BYOD, but for CE assessment it meets the requirements. MAM-WE is mobile apps management without enrollment. The policy essentially specifies that you can only access corporate/school data through an approved app. You then use App Protection Policies to ensure that the devices are compliant before the app installs or opens. https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-windows-app-protection
  12. The Cyber Resilience Bill will become an Act of Parliament before the summer holidays this year. It mandates cyber security standards for all public bodies, which will include schools. The Cyber Assessment Framework specifies the standards. Clearly some (almost all?) public bodies will be unable to meet the standard by the summer, so there's bound to be a "working towards" period, but your governors will need to ensure the school complies with the law. Saying that you don't need to comply because it's not statutory is a slightly unusual stance for a governor to take.
  13. Does the desktop belong to you or the user? If it's yours, swap it. If it's hers, your best endeavours support has reached its limit. If twenty users have the same issue, you might need to investigate. For a single user, this has got unaffordable.
  14. The only acceptable answer. And if you can't afford to replace them, you can't have iPads. It's not complicated with Apple: they tell you what OS versions are still getting security updates and they tell you what models are supported. Note that this does vary by model. Models that support iPad OS or iOS 26 are not getting security updates for iPad OS or iOS 18. As mentioned above, the iasme Cyber Essentials page is a good source.
  15. Xibo and Yodeck are both good solutions. For an even simpler solution I've set up a slide show on Google Slides and then you can use any machine that'll display a web browser and anyone who can update a slideshow can add content.
  16. When I was a lone tech in a school I raised a lot of tickets on behalf of people - in some ways that was even more valuable as it was quicker than sending myself an email. I always had the best intention to remember everything I was asked in the corridor, but I had a much higher hit rate when there was a queue of jobs on my screen. In the larger organisation I work in now, it allows us to organise work and gives great visibility across the team. If a user comes to the office any of the team can quickly find out what's going on. It's taken a while, but we've made huge progress towards persuading people to fill in request forms. That way we get all of the information we need in the first contact so we waste a lot less time. Users who aren't at their PC can use their phone, a web browser on someone else's PC or phone, or come and use the Android tablet on our office. And pushed, I'd admit to raising tickets on users' behalf occasionally.
  17. I really truly, strongly recommend implementing a help desk. Use a free option - I happily used Spiceworks for years. If it's just you or a small team, most of the big players have a free option. Workload management, record keeping, incident analysis, structured data for help requests, reporting to SLT. And then your contribution to the handbook becomes "here is the link to the IT Support portal where your can find answers to all the common questions and raise a ticket for anything else. With the subtext that is they don't raise a ticket, they will be ignored.
  18. The only thing from your list that I'm aware had a limitation is charging. Accounting per user is fully integrated, but unless there's been a recent change, there's no option for a payment gateway to take card payments to buy credit. That wasn't an issue for us as internal accounting is important but we don't (yet!) charge employees to print. You will need to deploy the client, but we added the application to Intune.
  19. Proving that Edugeek is still the place to come for all sys admins, whether working in schools or otherwise. I have downloaded from the link here via the Way Back machine so that I know I have a copy of the installer. I did notice that was released on 15th July 2024, so it's the version we're already on, but useful to have a copy of the installer anyway.
  20. How old are the servers and what manufacturer? We normally buy Dell servers and on the configurator they come with three years standard as standard, upgradeable to 5 online, but seven years is available if you contact your account manager.
  21. I think what you need is MAM-WE: Mobile Application Management Without Enrollment. You then need linked Conditional access policies which allow access from your managed devices, but if it's not a managed device, then the school's data can only be accessed through one of the approved apps. You should then also apply Microsoft Defender for Endpoint policies to attest the security status of the Android device. The Conditional Access Policy forces use of approved apps The MAM-WE policy checks the status of the apps and calls the Defender policy The Defender policy attests the security level of the device This approach "registers" the apps rather than the device, so you're not entertaining the device in your MDM.
  22. As above, plus admin account for M365 cloud which is separate from the global admin account (standard use account is SSO with domain account).
  23. I am very wary about allowing this now. It's too easy to end up with access to work data on a home device. They have to sign in to their MS account, which makes it relatively difficult to prevent access to work data through the web browser.
  24. We're buying Dells and on most laptops we're adding five years accidental damage cover for around £40/unit. Only one claim so far, but dealt with just as painlessly as their normal NBD onsite repairs. And we've just decided to standardise on 32GB RAM as were expecting to keep them for five years.
×
×
  • Create New...