Jump to content

rogerdnixon

Members
  • Posts

    667
  • Joined

  • Last visited

Everything posted by rogerdnixon

  1. Got access to this today - brief video of what it looks like Seems to work pretty well - I have >200Gb and loads of folders in my Drive and several Team Drive - all were picked up without any delay. Will be trialing with some Office users over the next week or so.
  2. For the default camera app - you can push it via user settings, its hfhhnacclhffhdffklopdkcgdhifgngh - so force install/pin or whatever. Other options include Screencastify, which is very good. webcamera.io , clipchamp (delkpojpfkkfgmknffmblbhmlamkjioi), nimbus screenshot and loom (liecbddmkiiihnedobmlmillhodjkdmb).
  3. I'm not sure about wildcards as such - but you can match any string or part string that appears in a specific part of the message or anywhere - see: https://support.google.com/a/answer/1346934?hl=en When you setup a content compliance rule there is an option at the bottom for an message if you are rejecting the message.
  4. Then just add an additional rule for those additional internal domains. So one rule to block emailing outside the global G Suite domain and another to block emailing to sub-domains you don't want specific users to email. We do this to prevent secondary students emailing primary ones on another of our sub-domains.
  5. I'm probably being thick - but why? You can block outgoing mail for a specific sub-OU(s) with one content compliance rule without impacting on internal mail between your sub-domains at all. Just tried this with a test user in an test OU (its not something we do) - worked fine.
  6. If they are all on the same G Suite setup - i.e. all sub-domains under one primary domain - then they are classed as internal mail not external and won't be affected - unless you want them to be.
  7. You can block sending to all external domains with a content compliance for outbound mail only which contains the text "@" - ie all email addresses. For class groups (we have about 600), we do it by group settings - so students are members who cannot post and teachers are owners who can. The groups are created this way - so when membership changes it does not matter as the group settings are static. We only use group settings not content compliance for control of groups. We have very few groups that anyone can post to - mainly public collaborative inboxes.
  8. Restricted Delivery applies to both sending and receiving - you list the domains to allow. Everything else is blocked. You use Content Compliance rules to do anything fancier. So you can restrict delivery to a group there. So to block delivery to a group, use "Advanced Content Match", "Any envelope recipient", "Contains text", Content = group name. Alternatively, don not allow group members to post - only owners - which is what we do for most student groups - they can view but not post. You change in the individual group settings or via GAM if you have lots.
  9. Our primary schools we look after are sub-domains of our domain (Wheatley Park) . You can edit group permissions in bulk using GAM - you just need a list of your groups in a csv file: https://github.com/jay0lee/GAM/wiki/GAM3GroupSettings
  10. To block sending to other domains and only allow ones you list, use "Restricted Delivery" under Compliance in mail settings. You can then list domains you allow and block all others - this is what we use for our primary schools students. To allow all - but block sending to specific domains, use a "Content compliance" rule in mail settings. So create a rule that blocks "any envelope recipient" that contains the domain you want to block. You can use a compliance rule to block pretty much anything you want e.g. emails containing the work "dog" if you wanted. We use this setting to prevent our secondary students from emailing primary accounts. You can also use compliance rules to block students from emailing groups. However, I'd normally use group permissions to allow members of a group to post or not. So for example we have a group called "students" - students are members who can view but not post and Leadership Group are owners and can post. Group permissions are very granular.
  11. I'd second Google sites + Google Drive. Dead easy to make cool looking sites really quick + unlimited storage + free.
  12. See this: https://bugs.chromium.org/p/chromium/issues/detail?id=700595&desc=2#c20 We had this on the beta and dev channel a while back until Securly updated things their end prior to the stable release of 58.
  13. You might want to consider running a few devices on the beta/dev channel and then you get a month or so notice of these changes and issues. I spotted this about 4 weeks ago and reported it to Securly and it was fixed (certificate update their end) before the stable release yesterday. However, you would have thought Sophos and the likes would be doing this anyways.
  14. If the schools are on totally separate G Suite domains - so not on the same management console, then they will not see each other. If the schools are sub-domains of a G Suite setup, then they will. So we have one main domain and a number of primaries as sub-domains. While users can see users in other sub-domains, you can restrict delivery to those domains with a content compliance rule in GMail User settings. So I've got it set that our secondary students cannot email primary domains and primary students can only email within their domain. However, the only way to "hide" a user is to turn off contact sharing for that user. You can do this in bulk using GAM. More granular settings for Sub-OUs have been requested - but no harm doing it again.
  15. We use Hue cameras https://huehd.com/ - relatively cheap and robust. Plugin and play on most devices. Most classrooms have them now and they are widely used in teaching.
  16. You need to set it as the default browser with a preference file - see: https://support.google.com/chrome/a/answer/7009292
  17. Current list: https://sites.google.com/a/chromium.org/dev/chromium-os/chrome-os-systems-supporting-android-apps?visit_id=1-636264771759545033-2846747554&rd=1 You may need to move to the beta or dev channel depending on the device.
  18. This is the thing I did on Education on Air about it: It sounds like you have done it all. Enable for the Domain, enable for the specific OU, Add an app via the Play for Work store, Allow the installation of the App for the OU. Once you have done that, you should see the Play Store icon appear on the shelf of the Chromebook. You then need to sign in to the Play Store and wait a few minutes while it sets up. Once done you should be able to access the Play Store App. Now apps you have deployed may takea few minutes to actually appear in the store. We have found its sometime blank the first time a user fires it up - but after that its fine. Hope this helps a bit.
  19. We use Securly - this provides our onsite filtering for all devices and offsite for Chromebooks. Works well and have quite a lot of nice features. GoGuardian is the other big player - we used them but found Securly a more cost effective option as it was cheaper and did all of our filtering. Both authenticate against the users G Suite account.
  20. You set a YouTube policy in the G Suite admin console by Sub-OU. So set one policy for a staff OU and another for students. We have staff on unrestricted and can approve videos and students on restricted.
  21. Do you mean its slow connecting offsite? A little while back I had an issue where remote access (via Ericom Secure Gateway) was slow at home - but bizarrely fine if I tethered my laptop to my phone. Turned out to be QOS on my Asus router - turned it off and it was fine.
  22. We block all mail other than domain gmail for all users. At work they use their work account.
  23. Its about £40-£45 per concurrent user - one off payment. You just need to know the maximum number of users you are likely to have on at any time.
  24. We use Ericom AccessNow and Secure Gateway for this - my demo: This is how most people access SIMS here as we are mainly ChromeOS. Chrome rdp also works fine - but you have to buy per user. You can manage the Android apps on ChromeOS now (assuming you have supported devices) - brief demo: MS rdp app works fine.
  25. Our 1:1 chromebooks are bought by use and parents have the option to buy them (we get about 60% buy rate). However, we make it clear that while the devices are at school they are managed by us. Once they leave school, we remove the management and they become consumer devices. We foot the bill for the licences.
×
×
  • Create New...