rogerdnixon
Members-
Posts
667 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rogerdnixon
-
Ofqual and DfE studying ‘feasibility’ of ‘fully digital’ exams
rogerdnixon replied to DrCheese's topic in General Chat
So we are 1:1 with Chromebooks across most of our secondaries now and use Trelson extensively for exams and it works really well with minimal fuss. However, if you don't have the devices and the required robust network connectivity - thats going to kill it dead. -
Microsoft Forms and Google Forms - Receipt Number
rogerdnixon replied to Bankesy's topic in Cloud Services
You could use the Sheets addon Formmule or Autocrat. The former can send out emails on form submit - which can contain whatever info you want. The later can merge the info into a Google Doc/PDF and share with someone and send the email. We use both extensively in automations and some of our own custom Sheets scripts as well. -
Prevent hotspotting on chromebooks in school
rogerdnixon replied to dgsmith's topic in How do you do....it?
You can restrict to managed wifi if in range - its in the wifi settings in the admin console. We use it and its kills the use of hotspots. You can also just restrict to managed networks if the device lives entirely onsite. If you use the first settings, be mindful of anyone who lives right next the the school and takes their device home. -
Just deploy the new SSID on the Google Admin console now. Devices that are online between now and the install will pick up the setting and just work.
-
We use Securly across our MAT (28 Schools). Depending on the device it extension, DNS or SMARTPac. Filtering works anywhere. One dashboard for the entire Trust and easy to deploy and scale. We tend to use UDM Pros for firewalls at primaries and PFSense+ at secondaries.
-
Google Workspace - prevent saving of .exe files
rogerdnixon replied to fiza's topic in Cloud Services
If you are on Plus you could use a Trust Rule to alert you if they try to share a particular type of fiel or a file with specific content and prevent them from doing so. You can also set the download policy on Chrome to prevent them downloading exe files. -
We do this the Google way but the basic idea is the same. Our schools typically have a firewall appliance (which does DNS/DHCP), cloud based filtering and MIS. All devices cloud managed. Other than the firewall all there is onsite are switches, access points, copiers and display kit. We do run little print appliances - so a little fanless NUC industrial PC that runs local Papercut - although if Papercut Hive might kill those off. We have a fairly well oiled migration plan for new schools coming into the Trust - but as its Google Workspace and not O365 - not really relevant to you.
-
Google Voice - Has anyone gone down this path?
rogerdnixon replied to TwistedHelixis's topic in Cloud Services
There isa feature about to be released to allow you to specify that users in a given OU get the caller id of the autoattendant number when they make a call. Q2 release - so anytime now - the option is already there - the policy is not yet. -
Google Voice - Has anyone gone down this path?
rogerdnixon replied to TwistedHelixis's topic in Cloud Services
Yep - you just do number porting via the Google admin console. Takes about a month to port numbers. Just make sure you are rock solid on all of the details on the port request and they are super picky! -
Google Voice - Has anyone gone down this path?
rogerdnixon replied to TwistedHelixis's topic in Cloud Services
You need to go to user settings > speeddials > untick the boxes and then you can edit them. Save when done and reboot. -
Just for info - API access on Google Workspace has recently been changed to Whitelist by default for Edu customer. I've worked with O365 and Google Workspace - both need careful setup. However, both also give detailed guidance on how to setup on how to set things up to be secure by default. But this does require whoever is setting it up to either know what they are doing or read the instructions.
-
To Windows - Papercut Print Deploy. Most other things Papercut Mobility Print.
-
Canva is free to Edu and gives you pretty powerful video editing on any platform. Works really well. The Photos app now supports video editing - so basic editing is built in now.
-
Removing Google Prompts as default 2FA option?
rogerdnixon replied to aydee's topic in Cloud Services
We typically pre add security keys for staff on the admin console and then there is nothing for them to do. They get their device + key when they start. -
Thats basically it. Do your own testing of course to check its behaving as expected. Good luck with it. btw - we push AnyDesk to our devices for remote support - works well.
- 47 replies
-
- 1
-
-
- cloud computing
- google admin
-
(and 2 more)
Tagged with:
-
The concept of users/device OUs does not exist like it does for ChromeOS. A device will pick up policies of the account you use to enrol the computer and then policies based on any additional policies that you apply to specific OUs. For primaries we just have an "enrol" account we use for setting up devices in the root of the schools OUs. For secondary typically a few in different OUs - mainly because different software is pushed to different devices. You can then set polices that apply to uses (e.g. default apps and start menu) on an OU basis. We set the majority of policies at the root of the trust - so applocker etc so you only need to do it once. Update settings/bitlocker we set at the root level as it generally the same across the Trust.
- 47 replies
-
- cloud computing
- google admin
-
(and 2 more)
Tagged with:
-
The majority of Windows devices are managed using Google Advanced Desktop Security now - both primary and secondary - so 1000's of devices. Works well and keeps the management of devices in one place - along with ChromeOS. As others have said, this requires either Plus or Standard licences. GCPW is the application that facilitates this and can be used without the device management and can be used alongside an AD setup as well. If you are using GCPW without the backend management, make sure you set the registry key not to enrol the device otherwise it will bug you about the lack of a licence. Users would be signed in as a standard user. If you use the management you can set admin permissions by OU. My Slides from my talk at Google about this - has links to many useful resources. To answer one of the other points - we do make it quite explicit that files must be opened/saved from Google Drive and this along with other stuff comes as a little instruction insert with all devices. We also backup Google Workspace using AFI backup and show users how to do self service restores of mail/drive. Any questions - let me know.
- 47 replies
-
- cloud computing
- google admin
-
(and 2 more)
Tagged with:
-
Cannot replicate that on our setup. So Chrome, VM leased line and Securly filtering.
-
Can you make an existing Google domain a subdomain of another?
rogerdnixon replied to fiza's topic in Cloud Services
You might want to just make them Trusted Domains and keep them separate. Also be aware that unless you ate on Plus licencing - each separate domain gets 100Tb storage - combine them you just get 100Tb. -
Can you make an existing Google domain a subdomain of another?
rogerdnixon replied to fiza's topic in Cloud Services
If you have two Google Workspace setups and you want to merge them into one there is no native way to do this. Its rather manual or you pay a third party to do this. Basic way I've done it: Add a suitable subdomain on the the one you are keeping. Recreate the accounts of the incoming domain on the one you are keeping on its new sub-domain - with appropriate polices, OU structure and so on Recreate Shared Drives on the one you are keeping. Add an account to the shared drives on the doamin you are not keep from the one you are keeping as an owner. You can then simply move the files from old to new shared drive. If its quite small you can give users instructions on how to use Google Takeout to make a copy of all of their stuff and target their new account - so that does Mail and Drive. You can use the built in migration tool to do Mail in bulk. Or use a third party migration tool if its bigger - used Systool Migrator when I did an incoming secondary. Its not pleasant and it not easy - but it is doable with some effort. -
I just pop on the SSL cert on servers and nothing else. Securly won't block updates and the like and of course you never browser on server. Yes - all filtering methods other than the guest prompt the user to auth (well not ChromeOS with the extension as it just knows who you are). Use the guest DNS settings if you don't have more than one external IP.
-
More or less. Smartpac proxy you push to any devices that support this - which is most - ipads, Windows and so on. DNS works on anything and will prompt for user login. You can have a separate guest network either on a different external IP that you tell Securly or you use the Guest DNS servers. The guest does not require signin.
-
Browser extension is for ChromeOS only. Other devices you would use either DNS filtering or SMARTPac or both. You could also point things to your guest filtering policy which is what we sometimes to things that just need internet access (e.g so tills at primaries). If something does not authenticate - it will be dumped onto the default policy which sounds like what's going on here.
-
Takes a couple of weeks to get a new Edu setup approved. You just have to wait.
-
I've not had any issues like that. We have Voice at a lot of our sites. The only time I've had issues are when I've had next to no mobile signal and then there is a bit of latency. I did have issues installing some handsets at two sites that had Exa and RM provided filtering. But they switched to VM leased lines + Securly filtering and have been fine since. Google did change the out bound ports required a few months ago - sent an email out last year about it. so you might want to check that.
