-
Posts
16,316 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Garacesh
-
As with before, that's literally what appears, verbatim. I've had a quick play with Netwrix Account Lockout Examiner and that, too, picks up WORKSTATION as the device name. I have confirmed there is no computer named WORKSTATION in our AD. Edit: Going to steal a laptop after hours and lockout a test account
-
Yup, all the more reason the UK carriers need to get the VOIP number spoofing issues fixed. And whilst we're at it, is the whole thing where you hang up your landline but they keep the call open their end and then no matter who you dial, you get the same line, still a thing? I seem to recall people talking about something like that a good few years ago.
-
Coronavirus: General discussion (see opening post for rules)
Garacesh replied to Dos_Box's topic in General Chat
Yup, as expected. I considered it pretty much inevitable. There were bound to be people there who didn't know they had COVID. I'm still not 100% sure I would have gone, had I not just recovered from it a few weeks ago. I think maybe I still would've, but I would've been a lot more diligent about distancing, masks, sanitising, etc That being said, nobody bothered to ask me about vaccinations/covid pass/etc on the door. Quite a few others reported the same thing, there was no more red tape to get in than any other year.. Show your badge, scanner beep, in you go. -
Hmm... I'm seeing the lockout event now, which is good. But it's still not listing a device source properly. A user account was locked out. Subject: Security ID: SYSTEM Account Name: [color="#0000FF"]CurrentDC$[/color] Account Domain: [color="#0000FF"]Domain[/color] Logon ID: 0x3E7 Account That Was Locked Out: Security ID: [color="#0000FF"]Domain[/color]\[color="#0000FF"]SLTAccount[/color] Account Name: [color="#0000FF"]SLTAccount[/color] Additional Information: Caller Computer Name: [color="#FF0000"]\\WORKSTATION[/color] All the 4625 events are either just myself or my tech, for some reason, and I'm not seeing any 4768 / A Kerberos authentication ticket (TGT) was requested. events for his account in the 15 minutes prior to the member of staff telling me he'd been locked out again.
-
Isn't that against the exam board rules?
-
Valid, but a lot of the time we don't want pupils to know when they have special/nonstandard configuration, because usually they'll try to find a way around it. If you have Google Groups enabled for them, they'd be able to see that group. And probably leave it, too. Sure, you could make it AD-linked so GCDS would re-add them but anything between leaving the group and your sync wouldn't be covered. Edit: Yup, just checked, my test pupil can leave the all-students group. Edit2: That, and in my case, you can't monitor incoming email that way using group membership.
-
Thank you @Koldov, I'll try tweaking some of those settings and see if it makes a difference. Much appreciated
-
Perhaps, but there's a myriad of events all using different WIN- ID's. So I've no idea what's generating them. I'm trying to chase down a user being periodically locked out of their account, which would insinuate there should be a bunch of failed logon events with his user name. It happened again today, so I went to check the DC's event logs, but there's no 4625 events with his user at all. On any of the DC's
-
Well this is weird. I can now see 4625 events, but most of them aren't showing me a username. The ones that are? Me. Only me. Which I think is timed out sessions on a server I know I'm still logged in to doing the whole 'we need your creds again pls' thing. Everything else looks like this: An account failed to log on. Subject: Security ID: NULL SID Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 3 Account For Which Logon Failed: Security ID: NULL SID Account Name: [color="#FF0000"]WIN-[i]A user that doesn't exist in AD[/i][/color] Account Domain: [color="#FF0000"]OURDOMAIN[/color] Failure Information: Failure Reason: Unknown user name or bad password. Status: 0xC000006D Sub Status: 0xC0000064 Process Information: Caller Process ID: 0x0 Caller Process Name: - Network Information: Workstation Name: [color="#FF0000"]WIN-[i]The same username as above[/i][/color] Source Network Address: [color="#FF0000"]A.Valid.IP.Address[/color] Source Port: 49698 Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): - Key Length: 0 (Occasionally the Account Name and Workstation Name are genuine machines, but there's still no valid username in the information)
-
Apps - Google Workspace - Settings for GMail - Routing Add a new Routing rule Outbound, Internal - sending For the types of messages above, do the following: Reject the message Scroll down to the bottom before clicking Save, click Show Options B. Account types to affect: Users C: Envelope filter: Only affect specific envelope senders Single email address - [email protected] Edit: sorry, just seen "Some pupils", plural. You'll want Pattern match instead of single email (?i)(Pupil1|Pupil2|Pupil3|etcetera)(\@domain\.gtld)
-
We separate users based on year group, both in AD and on our file server. At the end of the academic year, we disable every account in $LeaverOU. Those get to sit there for a year, just in case any kid needs their coursework for college etc. Once they're disabled, G Suite and 365 disable the accounts on the next sync (Azure AD Connect does this automatically, Google uses an LDAP query that includes (!(userAccountControl:1.2.840.113556.1.4.803:=2)) so administratively disabled users don't match). GCDS doesn't delete non-matched users in G Suite because we've told it not to, so I also have to delete those manually, and as long as the user still exists in AD, Azure AD Connect won't delete them from 365. Next year, when we come to disable the leavers, we take the opportunity to delete last year's leavers, and remove all their files, which is simply just a case of 'delete the root folder' As for mid-year leavers, we disable the user account and slap information about them leaving (Off-roll xx/xx/xxxx, excluded xx/xx/xxxx, etcetera) into the Description field. There's so few and far between of these that we just let them sit there, and delete them and their user areas/etc when we come to delete the rest of the year group once they progress beyond Year 11. As for user profiles, we don't do roaming, so they're just stored locally on the machines they log in to. We generally don't bother doing anything with those. They'll disappear when the GPO profile age threshold kicks in. Well, that, and we do mass-reimaging every summer.
-
Correct. Assuming you're using Azure AD Connect, if they log in to 365 and download and install Office, then that local install of Office is bound to their Office 365 account, which in turn is bound to your AD. Disable/delete them from AD? License invalid and (AFAIK) Office products will start haranguing them to purchase it. I can't say I've ever had an issue with management when I've explained why I don't want to support pupils' personal devices. I do usually support staff devices in a very minor capacity (again, usually this is debloating brand new devices, but we allow staff devices on our wifi so they often need the filter certificate for SSL inspection applying) but that's an entirely personal choice, not something I'm mandated to do, and I absolutely wouldn't begrudge anybody who chose not to, I can entirely sympathise with the reasoning behind it.
-
I always make it clear that what I'm offering, and the terms, and I usually express in no uncertain terms that once the laptop leaves my office, free of bloat, I will refuse to touch it, as would be the case with a pupil's personal laptop (because from that point, that's basically what it is, after all). The only reason I offer to debloat them is because I know they're fresh-from-factory and won't have any potential naughties on them. The only real exceptions to this has been when I've completely reset a device from the shift-reboot menu. Valid point, though perhaps just a scenario of bad wording than bad conduct. The vast majority of software licensed to the school is licensed to the school as a business entity, and is only installable on school devices etcetera. The Office 365 license does allow for users to install products on personal, non-school devices, so it's not in violation of any agreement (whereas giving them the Serif packages, or our SEN software, etc would be, which is why I give them instruction on how to do that, rather than dumping our copy of Office on with a MAK activated)
-
To my knowledge (although now I'm wondering if we were 'doing it wrong'), LAC laptops have never been school property and we've never accepted any liability for them. IT Support operates only in an advisory capacity ("We would recommend any of these laptops, they would be suitable for the use case.") and provides basic setup (debloating Windows, mostly) and support as a best-effort venture, carrying with it no guarantee, assurance or warranty, nor is it any indication of any contract or agreement of any future support being given. As for software licenses, etc, I've always tended to give the kids freeware (VLC, Audacity, Chrome, 7Zip, Foxit, Notepad++, Google Drive File Stream etc) and instructions on how to download and install Office via the school's Office 365 subscription. We do not install any software that the school has paid for, or that is subject to a license agreement between a company and the school. Whilst the child is in the building (e.g. under our duty of care) we encourage using school resources, which thanks to G Suite is reasonably pain-free most of the time. This way they're using a computer operating our safeguarding and security softwares, are filtered properly (traffic bound to an actual user rather than being anonymous), they're able to access specific software that would be unavailable to them on their LAC laptop (eg Adobe or Serif), and they have access to on-site file shares that aren't available externally.
-
Knew it would be something simple! Of course I hadn't set that to download the server stuff yet, I was testing deploying it to end-user devices first.
-
-
Bett 2022 - enter our biggest competition EVER!
Garacesh replied to VeryPC's topic in Our Advertisers
I cannot go back to <512x texture packs, no Optifine, and stock shaders, and you can't make me Vanilla minecraft is ruined, for I have experienced the future -
[b]Product:[/b] [color="#0000FF"][u]"Windows Server 2012" OR "Windows Server 2012 R2" OR "Windows Server 2016" OR "Windows Server 2016" Or "Windows Server 2019" OR "Windows Server 2019" OR "Windows Server, version 1903 and later" OR "Windows Server, version 1903 and later"[/u][/color] [b]Superseded[/b]: [color="#0000FF"][u]No[/u][/color] (Yes, some of those options appear twice. I have no idea if that's normal.) Preview.. Configuration Manager returned 2 updates. Windows Malicious Software Removal Tool x64 - v5.98 (KB89030) Windows Malicious Software Removal Tool x64 - v5.99 (KB89030) ... that's it. No other updates. Now I don't know about you, but I'd imagine that there have been a few server updates since Server 2012, y'know? Call me paranoid... Compare this to my end-user devices updates ADR: [b]Language:[/b] "[color="#0000FF"][u]English"[/u][/color] [b]Product:[/b] [color="#0000FF"][u]"Windows 10" OR "Windows 10, version 1903 and later" OR "Windows 10, version 1903 and later"[/u][/color] [b]Superseded:[/b] [color="#0000FF"][u]No[/u][/color] [b]Update Classification:[/b] [color="#0000FF"][u]"Critical Updates" OR "Definition Updates" OR "Security Updates" OR "Update Rollups" OR "Updates"[/u][/color] (Again we have some of the product options appearing twice, because.. reasons?) Preview.. Configuration Manager returned 238 updates. What on earth have I missed that means my MECM box doesn't see any Server updates?
-
Things that could have been improved before being approved...
Garacesh replied to 6Foot2's topic in Jokes/Interweb Things
Is there an accompanying 'First time bar dies'? -
Coronavirus: General discussion (see opening post for rules)
Garacesh replied to Dos_Box's topic in General Chat
Can we out-nutjob the nutjobs? "What, you think it's safe not to wear a mask? You think the government haven't engineered their own mind-control strain of the virus?!" -
Hehe I'm guessing PPE/Facemasks?
-
Way ahead of you. This little beauty will be arriving Monday. I will, of course, be bringing my legitimate badge for entry and for providing to people I do actually want to hear from, but for the drive-by scanning they'll get: The barcode is sufficiently scrambled and rendered unreadable, because I couldn't be bothered figuring out how to muck with that too much, and the QR is the classic
