rogerdnixon
Members-
Posts
667 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rogerdnixon
-
Fine here. If it's just onsite, then I'd suspect your content filtering is blocking one or more things that it should be allowing.
-
[sims] Capita is trying to sell off non-core businesses (SIMS is for sale)
rogerdnixon replied to psydii's topic in MIS Systems
I emailed James Leonard (Head of Google for Education UK) and told him to snap it up and give it a proper makeover..... They would not notice 500m. -
We use Securly across our Trust - works well with lots of cool features.
-
Pretty solid with 17k users on our Trusts domain. Mainly Chromebooks/Windows - not iOS. I have vaguely heard of issues with the iOS app - but never actually experienced any.
-
We do 1:1 Chromebooks and our approach to those questions is: 1) no - and we have the option to allow private accounts outside of school hours for devices that have been purchased (we have buy/loan options). 2) we use Securly - so they get the offsite policy at home and the guardians can control this with the Securly app (allow/block certain apps and allow/block website and even turn off the internet). 3) for each new Y7 cohort they get whatever Chromebook we can get at a decent price. So no choice. 4a) we have around 30 spare devices - so they would day-loan a device - but get a detention. Day-loan devices are set to only connect to managed networks - so useless offsite. Devices not returned are disabled at the end of the day. 4b) repairs are done at cost. So if it needs a new part - the cost goes on Parentmail and the guardian pays and we then fix. In the meantime - they day-loan. We have this 7-13. It takes a bit of management, can be transformative if implemented correctly. We went 1:1 Chromebooks with staff first. Having all users on the same platform is important and things like Classroom and the use of G Suite embedded is key.
-
You manage them in the G Suite admin and apply device and user policies a bit like you would in group policy. You need management licences which are around £17 per device - a one-off payment. These get added to your admin console. Documentation: https://support.google.com/chrome/a/answer/1289314?hl=en Watch out, once you find out how easy ChromeOS management is - you might wonder why you have been messing with all that MS stuff!
-
Should I have Secure transport (TLS) enabled for our emails?
rogerdnixon replied to TwistedHelixis's topic in Cloud Services
For sending mail you can specify your domain. If you want to force TLS 1.2 or above you need to enable MTS-STS https://support.google.com/a/answer/9261504?hl=en This takes a bit more setup - but not too hard and we have had it enforced for a while with few issues. It worth noting that TLS is enabled by default and the setting you are looking at simply causes mail to fail if the other end does not support it. The vast majority do now (CPOMS being a slightly ironic exception...). -
Safeguarding school owned devices away from network
rogerdnixon replied to timbo343's topic in How do you do....it?
We use Securly on managed Chromebooks and PCs. Chromebook they get the extension forced and PCs/Macs the Securly SmartPAC file. This is in MAT setup. Each school has its own policies and safeguarding teams. The safeguarding teams get email alerts for sites, searches, email content and Google Docs content. the can also login and just see their schools stuff - run reports and so on. Dead easy to setup and use. Can sync users from G Suite or Azure AD. -
G Suite uses email encryption by default. What you can do is enable high levels of security: https://support.google.com/a/answer/2520500?hl=en - we do this (the default now: https://gsuiteupdates.googleblog.com/2020/04/improve-email-security-in-gmail-with-TLS.html) https://support.google.com/a/answer/9261504?hl=en&ref_topic=9261406&visit_id=637240931547676880-58329043&rd=1 - and this, and https://support.google.com/a/answer/7280976?hl=en - but S/MIME required paid for certificates so we don't do this -and really needs the other end to use it for full functionality + a pain to setup. What it sounds like you are asking for is an additional layer of authentication - in case someone hacks the recipient's mailbox or you just don't trust their security. In that case, we use confidential mode - so either has self-destructing emails (time-driven) or require authentication delivered via a phone message (so hopefully the person who has nicked your laptop has not also nicked your phone or sitting at your desk). But in most cases, these things are remotely compromised - not people sitting at your desk. Never quite saw the point of "encrypted" emails in O365 as when ever I got them I just clicked on the link and they opened - not additional authentication needed at all.
-
I'll try to answer the questions. We have been using Meet/Hangouts for a long time in our Trust without any issues. Generally enabled fully for Secondary and for Primary - they can only join Meets/Hangout not make them. Question 1 For online teaching, the best approach is to use the Meet link in Classroom. This has a lot more restrictions built into it than a regular Meet link. So for example, when a Class Teacher leaves the kids are booted out. You can also hide or change the Meet link at any time and if you change it the old Meet link becomes inactive. I use this in my out teaching and it works well. Beyond Classroom - if you want a Meet link to be inaccessible after the event - use the live stream option and its only accessible for the event. Otherwise, they do persist. However, its never been an issue - probably because we have handouts enabled and its normal for students to collaborate that way. Question 2 Not put it to the test - but they last indefinitely I think. Not sure why this is an issue as external people cannot join without an invite and people just first up a hangout if they want a chat - why would anyone go back through their calendar and find a Meet link when they can just message someone normally? It's worth noting that we restrict students to the Trust for Hangouts. Question 3 I normally just share the recording with my classes on Classroom if I've done them. The recording ends up in your Drive if you started it and you can share as you want. You have total control over permissions. Question 4 Recording via the Classroom meet ends up in the teacher's Drive. I normally then post the video in an announcement to the students - then Classroom takes care of the sharing. I normally start a lesson by posting an announcement like "Hi Folk, see you in a few minutes - click on the Meet link" - we are sticking to normal times tables as much as possible - works fine - and really nice to have the contact with students and a bit of banter - especially around pets, mugs of tea and hats. Question 5 Take a look at this: https://groups.google.com/forum/#!topic/google-apps-manager/23ptQaKFNLo A GAM based Meet reporting system (you can look in the audit logs but thats tedious) - this emails to organise the attendance of the Meet. Looks pretty cool - but in a big org - might incure a cost (I've got 15000 users on 22 sites - so 100's of Meets a day - so I'm a bit nervous about my Trust credit card!) Question 6 It ends up in the organisers in Drive and they share as appropriate. I'd say its great - use it. We have done assemblies, lessons, staff meetings, Trust live streams and the only issues are the occasional dodgy home internet connections and really bad headgear. IT works because it's dead easy for people to use and requires almost no explaining.
- 7 replies
-
- 5
-
-
- google meet
-
(and 3 more)
Tagged with:
-
If you use G Suite and have Windows 10 devices, you might be interested in this https://gsuiteupdates.googleblog.com/2020/04/enhanced-security-windows-10-google-login.html We have been an alpha/beta tester and I've put some info into this blog post: https://wpsit.blogspot.com/2020/02/google-mdm-for-windows-10-devices-more.html We are now using this as our default way of managing Windows devices in our Trusts primaries. Its worth noting you do need some (we have 10), Enterprise licences for the accounts involved in managing devices - but regular users do not need them. So as a management solution its pretty cheap. We combine this with Papercuts (users sync from G Suite) print deploy for printer management. It's not perfect - but developing rapidly and great for an almost serverless school setup (we do have a print server...) and the built-in SSO is really good.
-
I'd say this is a job for the teacher (I am one). I judge engagement by the quality of work submitted and if it's been done. I'm not bothered if they have gone on Classroom - have they actually done and submitted assignments are what matters. As a teacher, this is easy to see in the overview page. We have a Google form on our staff site when you can highlight students who are not completing work and then the powers that be take action. However, I do run a GAM script daily that does dump all of the assignments into a Google Sheet - which then feeds other dashboards - basic details here: https://wpsit.blogspot.com/2019/02/import-domain-google-classroom.html on my blog. However, how often someone looks at or logs into Classroom tells you nothing about the level of engagement. Thats a teacher judgement.
-
Basic mobility Print is free - but its just a way of deploying printers to BYOD -there is no actual print management. Having said that there is little actual print management out of the box in Printix - its mainly print deployment. For a small school - Printix was around £300 for a year I think. Papercut - especially MF, is a lot more - but does a lot more.
-
We use it at one site and its OK - sort of Papercut light. You can push the docs to whatever cloud storage you want. However, PApercut Mobility print and Print Deploy are much better and thats what I'll be putting in the site in the summer.
-
As an IT Professional what laptop do you use?
rogerdnixon replied to flyinghaggis's topic in Hardware
HP X360 14 i3 Chromebook or when I want to be lighter weight HP G6A Chromebook. Fast, long battery life and just work. -
The Formmule addon is very good. Also Autocrat depending on exactly what you want to do.
-
We buy from C-Learning - speak to Ian ([email protected]). Cost depends on what bits you get - so things like Auditor+ are an option. It also depends on the number of licences - get cheaper the more you have. I'd say you might be looking at around £2.5-3k for 1000 users per year - depending on the bits you want. If you just want Chromebook filtering and no other devices (and no parent portal - our parents love this though - so well worth it), then its free. One of the killers for Chromebook and other things is rubbish content filtering. So while Securly is not the cheapest solution - it adds value in terms of its ease of deployment, use, reporting and parental engagement. It's definitely been a selling point for our 1:1 scheme.
-
Securly here as well - works well on all our devices across multiple sites - dead easy to use.
-
Personally I'd avoid Lenovo - their Chromebooks are not very durable in my experience. We tend to get HP devices which hold up (so x360's) pretty well. Acers have also been OK. However, touch flip devices have more to go wrong and do tend to need more fixing.
-
AeroHive AP121 Firmware
rogerdnixon replied to snagrat's topic in Internet Related/Filtering/Firewall
Ask for help on the Aerohive Community - they will supply the file: https://thehivecommunity.aerohive.com/s/topic/0TO0c000000g7rPGAQ/access-points?language=en_US The community support is pretty good. -
In the admin console - go to a user, click more, then restore data. This will restore anything they have deleted out of their bin within a specified time frame as long as its within 25 days. IF they have "lost" something, you can use Vault to find is as long as they give you something to search for. The reality is that I've not used the restore feature in a very long time as most users don't ever look in their bin (or know it exists), let alone every deletes it from their bin and we have 10000+ users. Finding things they have "lost" (i.e. forgotten what folder they put a file in) is a bit more common.
-
Authenticate Windows 10 devices with GSuite Enterprise
rogerdnixon replied to mavhc's topic in Windows 10
OK - just got clarification from the enterprise team - you only need enterprise licenses for the people doing the enrollment (so IT Support). So my quote for 10 users annually is £420 - so that the cost. So I might be using this in my new deployments - we shall see. -
Authenticate Windows 10 devices with GSuite Enterprise
rogerdnixon replied to mavhc's topic in Windows 10
I'm trying to establish how many licences you actually need. From my testing - the minimum of 10 a year seems to do it. That's around £480 per year. The testing I've done so far is with no licence - getting so trial ones this week - so will test a bit more once I have them. -
Authenticate Windows 10 devices with GSuite Enterprise
rogerdnixon replied to mavhc's topic in Windows 10
Had a quick play with the new release (I've been an alpha tester): You can actually sort of use it without enterprise licenses if all you want to do is sign in with a G Suite account. If you have enterprise licenses, then you get Windows Management in you G Suite management console. However, you can use this on AD joined and Azure joined PCs. Longer-term I'm hoping for just one management console so I don't need Azure/Intune for where we need PCs still. -
I'll be pontificating on the Google Stand at 11am on Wednesday.
