-
Posts
910 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Alis_Klar
-
CTRL + ALT + DEL > change password will open Edge at the reset URL. Might help some students.
-
Dear Google ChromeOS for Education administrator, Ensuring the security and integrity of your devices and users is paramount. We are writing to inform you about two potential scenarios where users could bypass forced re-enrollment on ChromeOS devices, and what you can do to prevent these scenarios. Please review the details below, as you can effectively address both scenarios with the following recommendations. What this means for your organization Understanding how these scenarios can occur can help you protect your devices and maintain a fully managed, secure environment for your users. Scenario / Setting Potential risk Mitigation status and Required action Sensitive Chrome URLs Users access sensitive device management tokens via internal URLs (such as chrome://policy/logs or chrome://net-export). You should not need to take action. Google has updated the default setting for the Block sensitive internal Chrome URLs policy to Enabled at the top-level Organizational Unit (OUs) to automatically protect your fleet. User-initiated enrollment Users utilize device enrollment permissions to bypass forced re-enrollment protections. We advise you to take action. Restrict manual username/password device enrollment specifically for student-facing Organizational Units (OUs). What you need to do Action required: We recommend that you restrict user-initiated enrollment, specifically for Organizational Units (OUs) containing students or users who might attempt to bypass enrollment policies. Navigate to Devices > Chrome > Settings > Users & browsers Select the Organizational Unit(s) containing the students or users you want to prevent from removing devices from management Locate the User-Initiated Enrollment setting Set it to "Do not allow users to enroll new or re-enroll existing devices" Click Save Note: You should not apply this restriction to OUs containing staff or administrators who still need the ability to manually enroll new devices. Additionally, you may choose to configure Chromebooks used by these users to automatically re-enroll after wiping, without user credentials. Navigate to Devices > Chrome > Settings > Device settings Select the Organizational Unit(s) with devices that need to re-enroll after wipe Locate the Forced re-enrollment setting Set it to "Force device to automatically re-enroll after wiping" Click Save Important: Unless you have previously disabled this setting, you do not need to take further action for the Block sensitive internal Chrome URLs policy, as Google has updated the default to Enabled at the top-level OU to ensure your fleet remains protected. You can still choose to update this policy for specific OUs by navigating to Devices > Chrome > Settings > Users & browsers and locating the Block sensitive internal Chrome URLs policy. We are here to help Please review the following resources for more information on managing ChromeOS device settings: Manage ChromeOS device settings Block access to websites Block sensitive internal Chrome URLs Force wiped ChromeOS devices to re-enroll
-
Looking at this Community thread https://community.bromcomcloud.com/archive-1kfacyh7/post/push-notifications-sending-instead-of-sms-N8MzxvfVgyAJ6Tn How does the system deem an MCAS account as active and not fall back to SMS/e-mail if you ticked the push notification box? Also while i'm here it's highly confusing that the push notification option disappears if HTML is selected. This should generate a popup error not just hide the tiny tickbox as it could easily be missed. Is the Announcement option a better bet as this never consumes SMS/e-mail credit and if a parent fails to get the message it's simpler to troubleshoot as it mainly caused by notifications not being enabled on their smartphone.
-
This is one of the Worst examples of Bromcom making something which should be simple an annoying maze of options that hardly work. If i was being helpful I think announcements generate a push notification in the app also. Although it's not obvious as with anything in Bromcom.
-
Wow! I had no idea that you could almost invisibly disable a playback device in Windows as a non-admin user! Right click over speaker > Sounds > Playback tab See all playback devices e.g. headphones and HDMI screen. Disable HDMI device. From that point onwards only the headphones will appear in the usual selector above the volume level and you would need to reverse the above procedure to fix. No way to lock it down AFAIK.
-
Worrying news. What vendor are your drivers for? Directprint.io would solve your problems as it uses driverless IP based printing. This site had some great info about Printing from ARM windows devices. https://whizz-tech.com/support/printers/printing-on-windows-arm-no-x64-drivers/
-
shared computer activation - anyone using it?
Alis_Klar replied to Alis_Klar's topic in Office Software
Some of our devices are stuck on Windows 10. What version of office should we put of them. They're already activated with OVS MAK key on Office 2016 or 2019. Will Office de-activate after OVS is ceased immediately? Do you know the refresh period if there is one? Would we have to install Office Apps 365 version to use out CSP A3 based entitlement? -
How does shared computer activation work? Once enabled by Reg key can an admin simply activate using their own A3 like the old days and forget about it? https://learn.microsoft.com/en-us/microsoft-365-apps/licensing-activation/overview-shared-computer-activation We are migrating from OVS to CSP (A3 etc) and don't want a cliff edge where suddenly everyone has to sign in. We don't use SSO with Entra yet or AD sync with Entra. Staff have a M365 e-mail so can sign into office but our students don't have M365 identities yet as we don't have MIS provisioning yet. How quickly do Office 2016 and 2019 installations activated previously stop working after OVS agreement is terminated usually? Any real world experience?
-
I've had a report from the one school in our Trust that uses it.
-
Redstor say they have no access to encryption keys and you need the old key to change the keys AFAIK. So perhaps the old MSP had lost the keys? https://helpdesk.redstor.com/support/solutions/articles/4000220057-999-how-to-check-if-an-encryption-key-is-valid
-
Where does this thread appear in the Google ranking when you search for Bromcom I wonder!!
-
I wonder if the lack of activity on the bank holiday Monday messed with the load balancers which dialled down resources and got surprised by the Tuesday peak when everyone returned.
-
Ditto. Thanks for tip regarding registers @TheRobins
-
Every app needs to follow what Canva did and support thin provisioning fed from Google or Microsoft SSO. Autodesk TinkerCAD is also really good at this. MyLogin SSO works great for apps that pay Wonde to provision them from your MIS. MyLogin have a 2nd best option for apps that don't pay Wonde for provisioning called "saved password" where you have to download and match the usernames manually yourself and then remember to keep up to date with new children arriving. This also requires a Chrome Add-on to transparently inject the password. The apps supporting full SSO don't require the add-on. Just to be annoying the TT Rockstars iOS app does not support login via MyLogin but the website does. Mathletics only supports Microsoft psudo SSO as it asks for the username and password at first sign in and matches the records that way. J2E is great and supports every SSO method going PurpleMash is also very good as supporting SSO
-
There are several advantages to using the same domain for Google and M365. The users don't have to remember 2 domains or get the 2 mixed up. Any share notification e-mails will come from Google through most 3rd party e-mail providers such as Microsoft totally fine. Its kind of a good side effect that Google don't promote as they want you to use Gmail.
-
Chrome Education Upgrade Licence change
Alis_Klar replied to d13373d's topic in ChromeOS & Cloud Based OS
Does this affect migrating Chromebooks from one Workspace domain to another? Can't find the edugeek thread about this which had a clear order of events. Do you de-provision to free up licences before you contact Google Support? -
Also password.ninja is great for kids passwords in bulk without resorting to an API.
-
Not rolling out to Primary Modules yet.
-
Anyone using Wonde MyLogin solution? We're primary. This will work with Google and EntraID for authentication, will also provision those from your MIS using their other product EduSync. Is useful for Primary Schools where you can log into the Entra Enrolled Windows or Google Chrome OS device using a QR code or Emoji password. Coverage by apps is patchy tho. Mathletics and Pearson ActivLearn refuse to interoperate with any MIS sync tool. They have made their in-built tool a bit less confusing recently. TTRS and PurpleMash and Just2Easy are very good at interoperability.
-
I've heard conflicting reports of the best route to use to Sync a SharePoint Document Library with Windows. Older (?) method Use the Sync button. Heard this has lower performance due to the fact that the OneDrive Client steps through each library in sequence and if one fails it can affects the others? Newer method, Use add a Shortcut to OneDrive option which apparently has better performance. However heard this can lead to duplicate files as people can get confused more easily as to where thing were saved. I don't really need offline access, just fast access to files from applications without having to find the right SharePoint in a browser for my users. Would I be better off using something like Cloud Drive Mapper? With drive mapper how easy is it to add new SharePoint sites? We're still inventing new sites we need as we're just moving to centralising our storage as a Trust. Once the formation of new Sites settles I envisage Cloud Drive Mapper could cope but then not sure if there are limits on the number of libraries it can connect to for a single user?
-
Hard Disagree. Their product is NOT amazing. Its a usability and UI nightmare. Tries to do too much stuff and isn't a replacement for every 3rd party product invented ever as claimed by their marketing. Jack of all trades master of none. E.G. Why does it, have 2 different interfaces to taking a register depending on which route you take? You need a PhD to create a report. Their documentation is full of grammatical and even spelling errors.
-
Alternatives to mandatory profiles windows 10/11
Alis_Klar replied to sledpath's topic in Windows 10
Has Microsoft updated its advice regarding multi user PCs where there may be hundreds of local profiles stored. First login times with modern apps being installed is still a big issue on slower machines. With LTSC being not recommended what are people doing as work arounds? Chrome OS handles this much better as it automatically clears the local user cache when local storage is low. Also first logins are much faster. -
This must be costing them a small fortune in Azure credits? Their code needs performance tuning badly. If their primarily having issues with the massive leap in demand during registration can't they laser focus on streamlining the register page and all the database calls it calls. Once they've done that, focus on common office staff tasks like calling up pupil profiles for phone calls home and managing attendance. All these operation spike between 8:30 and 9:00 in most schools. Then implement API fair use and trottleing as @Marci was alluding to.
-
Just try installing Chrome OS Flex on any old wheezing Intel machine and you'll realise just how bad Windows has got. Microsoft is plainly consumer hostile these days. I think Chromebook plus devices with Arm processors will be a competitor to the MacBook Neo and will soon be running an Android based OS. Really if your doing 90% of stuff in a browser the manageability of Chrome OS in Education blows MacOS and a messy MDM setup out of the water. A 2016 Intel Macbook Air (can't be updated to latest MacOS) makes a superb Chrome OS Flex machine.
-
Great idea! This link has expired. Is this still a thing?
