Jump to content

Garacesh

Members
  • Posts

    16,316
  • Joined

  • Last visited

Everything posted by Garacesh

  1. One does not, because one is only 27 years old
  2. Can't say I'm keen on the new outfit. I get that high-waisted pants are a thing, and I get that pant-legs-cut-off-before-your-ankles is a thing, but combined it just looks like she's put on a regular pair of pants and pulled them up a bit too high. The coat's quite nice, though.
  3. Ooh-err.. That doesn't look like mine at all.
  4. That's implied, not expressly Tut, tut!
  5. Was that with expressly written permission from the broadcasting organisation?
  6. To be honest, with the incredibly lacklustre OnePlus 5, and all that invasive telemetry lark, I'm done with OnePlus now. I'll probably keep half an eye on the 5T, but I'm not expecting much. Bring on the Razer Phone!
  7. Garacesh

    Gaming Chat

    I'm not seeing a problem here OOH! Burn.
  8. Garacesh

    Gaming Chat

    Use PTT then ;D That applies for you too @bald_pig
  9. Might have to add that just to be safe. Did anyone ever find a way of removing the OneDrive link from the Start Menu? Even with a redirected start menu it shows up for us. Same with Settings (though with the 'deny access to control panel' GPO enabled, the Settings icon doesn't actually do anything)
  10. We combine that policy setting with the following registry keys: x64 HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} System.IsPinnedToNameSpaceTree [REG_DWORD] 0 x86 HKEY_CLASSES_ROOT\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6} System.IsPinnedToNameSpaceTree [REG_DWORD] 0 Those keys remove the OneDrive link from File Explorer's left-hand-menu.
  11. Well I think the answer there is "Well, tough." This is the internet. Whoever's handling the twitter account needs a thick skin and needs to understand how exactly the internet works (socially, not mechanically). Twitter has some ways to remove offensive content, but if someone decides to take a shot at you, there's not that much you can do if they're not being directly threatening or racist. There's really not a whole lot you can do in that situation, and if your deputy head isn't 'net savvy or thick-skinned, I could see that putting them off using it. If you do go down the Twitter route though, just remember it's considerably less popular than facebook. You can't run a school twitter if it's locked, because many people don't have twitter so won't be able to see your feed. Facebook is the safer bet in the grand scheme of things, because it's more likely that people will connect their communications with their 'real identity' (and be more civil because of this), and it's also more likely that a person has facebook than twitter, so your engagement % will be higher if that's what you're after. If you're not after either, and you just want an announcement platform, I'd say just use your school website.
  12. Probably. But you're gonna have to go with the disposable ones because hygiene. Sanding and filing are pretty hefty parts of RM though. Whenever you're making something, there's going to be sanding and filing as a minimum, as well as cutting/drilling/etc that's going to fill the air with fine particles you don't really wanna breathe in. So I guess it's either PPE, or can the syllabus
  13. You've trained him well, then?
  14. +1 for ipevo too. When BSF came and bought a tonne of stuff for us, they provided every classroom with an AverMedia/AverVision visualiser, which a lot of our staff have found suffers from the 'It can do too much' problem. The vast majority of our staff just want point-and-view. That's it. (Plus they have Promethean ActivInspire to do things like drawing/highlighting/etc) Science got themselves a few of the ones @mikeyw posted, they seem incredibly happy with them. Software is considerably simpler, but still has a few useful features like resolution, image rotation and screenshotting built-in. Also their software deals better with being pushed out via GPO than AverMedia's does.. Aver's often fails for no reason and you need to manually reinstall it but you need to be an admin, but you can't just run it as an admin. It's a pain in the backside. That being said, the build quality of the Ipevo ones feels a little lacking in comparison. And they'd be considerably easier to half-inch should a student be so inclined.
  15. Yeah, but then you'd miss out on so-bad-they're-good movies like The Adventures of Pluto Nash.
  16. Follow-up post to the earlier G-Suite/Android dump. Ignore if not relevant to you. So I fired up my old OPO and linked it to my test account. I created 2 files in Drive, one spreadsheet which was made Available Offline and one document that wasn't, but was downloaded locally. Despite the document not being available offline, I could still access it via the Docs app, presumably this is a cached copy. So what's the difference? I have no idea. I could edit both documents, and both were sat there 'Waiting for network'. Perhaps the Available Offline option effects actual computers more than the smartphone apps. Upon reconnecting to the wifi, changes were synced back upstream. So as expected, nothing will happen to a handset that is (for example) stolen and the Wi-Fi and Cellular signals are disabled. Obviously an account wipe cannot be initiated either. But the device will likely have cached files on that can be read. What I was able to do with the all wireless comms disabled is go into the phone settings, then Accounts, and turn off all syncing for the work account (App data, calendar, contacts, docs, drive, gmail, google fit data, people, sheets and slides). That said, if I were in a position to get disable this lot, I could just remove the Policy app from the Device Administrators list. I initiated the account wipe whilst all syncing was disabled on the phone and all wireless comms were off, re-enabling wireless comms after-the-fact. The account was still immediately blocked, then wiped, even with all syncing options turned off. So from this we can establish that syncing cannot be disabled in order to keep the account from being removed (syncing an account in-general can probably be disabled in some custom OS builds, or by using a firewall app but that's typically way beyond the capabilities of our users). I lost access to the spreadsheet that I had enabled offline availability. I did not lose access to the document I had downloaded to local storage. I was able to reconnect the same device to the same account without an issue. Handy for if a phone is found again, but worth remembering that if you remote-remove an account, you should enforce a password reset too! Once the account was reconnected I initiated a full device wipe. This immediately rebooted the phone and set it into 'Erasing...'. I held the power button in to force the phone off, then turned it back on again. It continued erasing. The full-device wipe also wiped the SD card. Additional: I was not able to remove the lockscreen security or revert to the insecure 'Swipe to unlock.' Both options displayed the message Disabled by administrator, encryption policy or credential storage. I was able to select Pattern, PIN or Password. Presumably phones with fingerprint and facial/iris recognition will have those options enabled still, too.
  17. Um. Perhaps? I didn't actually test that because my test account doesn't have much data on it (drive, etc), I really just tested emails. From the messages it gave, I'd assume it would remove the account from Drive/Keep/etc. My suspicion is, however, that anything that's been downloaded to the phones own internal storage will not be effected by this. I'll create a few bogus spreadsheets and stuff when I'm testing the full wipe with my OPO tonight and report back. (Or a bit earlier with my OP3, if I get a slowdown before 4pm) And I don't have any iOS devices to test this on. Sorry!
  18. Garacesh

    Gaming Chat

    Yarp, that's Veronica. I always found it amusing that she'd happily run over and uppercut a Deathclaw, but when you trade with her she's all girly like "You have something for me? IS IT A DRESS?!"
  19. Garacesh

    Gaming Chat

    Ed-e + Boone = Constant "OHSH...!" moments from the spontaneous killcams as Ed-e sees an enemy 2km away and Boone potshots it in the face.
  20. Loooooong post, but hopefully contains enough info to be useful. Bit of a detail-dump though. I'd have uploaded screenshots but I don't have a USB-C cable at work. You can safely skip this post if using GMail/G-Suite doesn't apply to you. I've just tried to add one of my a test accounts as a second account on my phone in the GMail app and been given the message: This account requires mobile device management. To satisfy the security policies associated with the account, you have to install a newer version of the Google Apps Device Policy App. I'm given the option to skip this, but if I do, I'm not able to view the inbox. It just hangs on 'Getting your messages...' If I install the update I get: This application allows administrators to enforce policies on how your mobile device is used to access work information. If you are using Gmail or Google mobile apps for personal reasons, you don't need this app. To keep your data secure, it also allows the admin to remotely wipe data, while you can reset your screen lock code remotely or locate a lost device. Some device details will be shared with administrators. [VIEW DETAILS] Using this application is subject to the Google mobile terms of service and the applicable G Suite terms of service for your organisation. The 'View Details' button displays: Domain administrators can view these details about your device: Device Model: ONEPLUSA3003 Serial Number: REDACTED* Device ID: REDACTED* Operator: EE Device OS: Android 7.1.1 Build number: REDACTED* Kernel version: REDACTED* Baseband Version: REDACTED* Domain administrators may request a list of applications accessing domain data. * (actual data is shown, not the word REDACTED) Clicking 'Next' from the 'This application allows administrators....' page prompts up 'Allow Device Policy to make and manage phone calls?'. The Google Apps Device Policy app then requests to be activated as a device administrator, which allows it to: [list] [*]Erase all data [*]Change the screen lock [*]Set password rules [*]Monitor screen-unlock attempts [*]Lock the screen [*]Set the device global proxy [*]Set screen lock password expiry [*]Set storage encryption [*]Disable cameras [*]Dsiable some screen lock features [/list] If you click Activate this device administrator you are given the following: The following domain policy settings will be enforced: [list] [*]Device password must be set [*]Administrators will be able to remotely wipe the device [*]Administrators will be able to remotely remove account* from the device [*]Administrators will be able to remotely provision Wi-Fi networks [/list] You can do the following actions on your device: [list] [*]Locate device on a map [*]Ring your device at high volume [*]Reset your device password/PIN [*]Lock your device [/list] * sic erat scriptum Clicking 'Enforce' then finishes the setup, and my test account started getting calendar events and emails coming through. I am still (as a user of the phone) able to initiate a factory reset (at least, it asks for my PIN/fingerprint, I didn't complete the process.) So if I login to G Suite as my Superadmin account and make my way to that users' information page, there's a category under 'Account' labelled Mobile devices which gives me the option to wipe the account off device, or wipe the entire device. If I change the password on that account, my phone brings up an alert saying: ⚠ Google Play services Account Action Required email@domain and no longer delivers mail for that account to my phone. If I click on the alert, I get: email@domain You were signed out of your Google account. Sign in again to continue. and am prompted for the new password. Sign back in, emails again, standard stuff. It is worth noting here that I could still view emails already delivered to the phone whilst I was locked-out. Clicking the 'Wipe Account' button on the user information page returns This account will be remotely wiped during the next sync. Once this happens, my phone gets an alert reading: Device Policy Account wiped A domain administrator has wiped account email@domain from this device using Device Policy. This device is no longer being administered using Device Policy. As this alert implies, the 'Google Apps Device Policy' app has also removed itself from the device Administrators list. It has not been removed from the phone, though. I have an old OnePlus One I'll test the wiping with when I get home, but I can't see why that wouldn't work. TL;DR: To add a managed G Suite account to an Android phone, the user must download an app and have it set as a device administrator. That says it gives a tonne of permissions over the device (which it technically does), but the only options the G-Suite Admin actually gets are to remove the account from the device, or to wipe the entire device. HTH
  21. Subscribing to this thread. I suspect with the rollout of G Suite that some of our more engaged staff will want to have their Google accounts linked to their own personal phones. Most of them probably won't, but a few might. The main issue is that these are personal devices, so we won't be able to remote wipe the whole thing, but if there's some way we can at least wipe the GMail box/disassociate the account, that'd be good. Just in case. Note to self: Find out what happens with the GMail app if there's a change of password
  22. Bugger, yeah. Didn't think of that. RDP + iPad + AppleTV + Projector, then? What about VNC Viewer? There's Android/iOS apps for that too, which should satisfy the teacher requirement?
  23. If they just want to 'control their slides', a wireless presenter is more than sufficient. If they want full-on control (assuming you're Windows), Microsoft have an RDP app for both iOS and Android which they could download. Though this would require either faffing about with firewall rules (and murdering the teachers' mobile data allowance) or putting their phone on the WiFi.
  24. I don't know what any of these are, but I'll gladly do my usual play-for-a-few-months-and-lose-interest no matter which modpack gets picked
  25. So we're looking at deploying Chrome out and I've been introduced to the Set a default associations configuration file option and that's sorted getting Chrome working, it's the default application for my test users if they log on to the machine it's applied to.. But as always: there's a 'but'. I'm trying to test if I can have multiple default association configuration files. My reasoning on this is to say, for example, computers with Chrome want the default association to be Chrome. Easy enough, done that. But we also have users that do a lot of work with XML documents, which at current just open in IE which isn't exactly helpful to the end-user. Say I want them to open in Excel. But if the people opening those XML files don't have Chrome, I don't want to push a global file association file because obviously it'll muck them up. Problem is.. I can't find ProgID/ApplicationName info about other software, like Office, or even Notepad. Google is letting me down. Edit: 2 minutes after I post this, I stumble across a powershell function to pull ProgID's. Typical. Edit2: The results are in: You can not have multiple default file association configuration files set in Group Policy. Bugger
×
×
  • Create New...