Jump to content

Alis_Klar

Members
  • Posts

    910
  • Joined

  • Last visited

Reputation

555 Excellent

About Alis_Klar

Personal Information

  • Occupation
    School Network Manager
  • Location
    Birmingham

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

  1. CTRL + ALT + DEL > change password will open Edge at the reset URL. Might help some students.
  2. Dear Google ChromeOS for Education administrator, Ensuring the security and integrity of your devices and users is paramount. We are writing to inform you about two potential scenarios where users could bypass forced re-enrollment on ChromeOS devices, and what you can do to prevent these scenarios. Please review the details below, as you can effectively address both scenarios with the following recommendations. What this means for your organization Understanding how these scenarios can occur can help you protect your devices and maintain a fully managed, secure environment for your users. Scenario / Setting Potential risk Mitigation status and Required action Sensitive Chrome URLs Users access sensitive device management tokens via internal URLs (such as chrome://policy/logs or chrome://net-export). You should not need to take action. Google has updated the default setting for the Block sensitive internal Chrome URLs policy to Enabled at the top-level Organizational Unit (OUs) to automatically protect your fleet. User-initiated enrollment Users utilize device enrollment permissions to bypass forced re-enrollment protections. We advise you to take action. Restrict manual username/password device enrollment specifically for student-facing Organizational Units (OUs). What you need to do Action required: We recommend that you restrict user-initiated enrollment, specifically for Organizational Units (OUs) containing students or users who might attempt to bypass enrollment policies. Navigate to Devices > Chrome > Settings > Users & browsers Select the Organizational Unit(s) containing the students or users you want to prevent from removing devices from management Locate the User-Initiated Enrollment setting Set it to "Do not allow users to enroll new or re-enroll existing devices" Click Save Note: You should not apply this restriction to OUs containing staff or administrators who still need the ability to manually enroll new devices. Additionally, you may choose to configure Chromebooks used by these users to automatically re-enroll after wiping, without user credentials. Navigate to Devices > Chrome > Settings > Device settings Select the Organizational Unit(s) with devices that need to re-enroll after wipe Locate the Forced re-enrollment setting Set it to "Force device to automatically re-enroll after wiping" Click Save Important: Unless you have previously disabled this setting, you do not need to take further action for the Block sensitive internal Chrome URLs policy, as Google has updated the default to Enabled at the top-level OU to ensure your fleet remains protected. You can still choose to update this policy for specific OUs by navigating to Devices > Chrome > Settings > Users & browsers and locating the Block sensitive internal Chrome URLs policy. We are here to help Please review the following resources for more information on managing ChromeOS device settings: Manage ChromeOS device settings Block access to websites Block sensitive internal Chrome URLs Force wiped ChromeOS devices to re-enroll
  3. Looking at this Community thread https://community.bromcomcloud.com/archive-1kfacyh7/post/push-notifications-sending-instead-of-sms-N8MzxvfVgyAJ6Tn How does the system deem an MCAS account as active and not fall back to SMS/e-mail if you ticked the push notification box? Also while i'm here it's highly confusing that the push notification option disappears if HTML is selected. This should generate a popup error not just hide the tiny tickbox as it could easily be missed. Is the Announcement option a better bet as this never consumes SMS/e-mail credit and if a parent fails to get the message it's simpler to troubleshoot as it mainly caused by notifications not being enabled on their smartphone.
  4. This is one of the Worst examples of Bromcom making something which should be simple an annoying maze of options that hardly work. If i was being helpful I think announcements generate a push notification in the app also. Although it's not obvious as with anything in Bromcom.
  5. Wow! I had no idea that you could almost invisibly disable a playback device in Windows as a non-admin user! Right click over speaker > Sounds > Playback tab See all playback devices e.g. headphones and HDMI screen. Disable HDMI device. From that point onwards only the headphones will appear in the usual selector above the volume level and you would need to reverse the above procedure to fix. No way to lock it down AFAIK.
  6. Worrying news. What vendor are your drivers for? Directprint.io would solve your problems as it uses driverless IP based printing. This site had some great info about Printing from ARM windows devices. https://whizz-tech.com/support/printers/printing-on-windows-arm-no-x64-drivers/
  7. Some of our devices are stuck on Windows 10. What version of office should we put of them. They're already activated with OVS MAK key on Office 2016 or 2019. Will Office de-activate after OVS is ceased immediately? Do you know the refresh period if there is one? Would we have to install Office Apps 365 version to use out CSP A3 based entitlement?
  8. How does shared computer activation work? Once enabled by Reg key can an admin simply activate using their own A3 like the old days and forget about it? https://learn.microsoft.com/en-us/microsoft-365-apps/licensing-activation/overview-shared-computer-activation We are migrating from OVS to CSP (A3 etc) and don't want a cliff edge where suddenly everyone has to sign in. We don't use SSO with Entra yet or AD sync with Entra. Staff have a M365 e-mail so can sign into office but our students don't have M365 identities yet as we don't have MIS provisioning yet. How quickly do Office 2016 and 2019 installations activated previously stop working after OVS agreement is terminated usually? Any real world experience?
  9. I've had a report from the one school in our Trust that uses it.
  10. Redstor say they have no access to encryption keys and you need the old key to change the keys AFAIK. So perhaps the old MSP had lost the keys? https://helpdesk.redstor.com/support/solutions/articles/4000220057-999-how-to-check-if-an-encryption-key-is-valid
  11. Where does this thread appear in the Google ranking when you search for Bromcom I wonder!!
  12. I wonder if the lack of activity on the bank holiday Monday messed with the load balancers which dialled down resources and got surprised by the Tuesday peak when everyone returned.
  13. Ditto. Thanks for tip regarding registers @TheRobins
  14. Every app needs to follow what Canva did and support thin provisioning fed from Google or Microsoft SSO. Autodesk TinkerCAD is also really good at this. MyLogin SSO works great for apps that pay Wonde to provision them from your MIS. MyLogin have a 2nd best option for apps that don't pay Wonde for provisioning called "saved password" where you have to download and match the usernames manually yourself and then remember to keep up to date with new children arriving. This also requires a Chrome Add-on to transparently inject the password. The apps supporting full SSO don't require the add-on. Just to be annoying the TT Rockstars iOS app does not support login via MyLogin but the website does. Mathletics only supports Microsoft psudo SSO as it asks for the username and password at first sign in and matches the records that way. J2E is great and supports every SSO method going PurpleMash is also very good as supporting SSO
  15. There are several advantages to using the same domain for Google and M365. The users don't have to remember 2 domains or get the 2 mixed up. Any share notification e-mails will come from Google through most 3rd party e-mail providers such as Microsoft totally fine. Its kind of a good side effect that Google don't promote as they want you to use Gmail.
×
×
  • Create New...