-
Posts
411 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by AngryITGuy
-
I’ve tried creating a Team manually and have the same problem so I’m beginning to think it might be something to do with SharePoint. There seems to be others experiencing similar issues when searching Google but no one has a definitive fix!
-
Happens outside of school too as filtering was the first thing we checked as we weren’t whitelisting all the required URLs for Teams to work.
-
We’ve used Microsoft SDS along with Salamander to create Microsoft Teams for all of your school classes. With a bit of tweaking we’ve added additional owners to the groups so we can keep an eye on classes and how they’re being used and we’ve also managed to hide all those pesky emails from the GAL. However Teams doesn’t seem to be functioning correctly. We have a ticket open with Microsoft but I’m just being passed from Team to Team at the moment. When I browse to a Team the only thing working is the conversation tab. When I click on the tabs for Files, Notebook or Assignments I get the standard ‘we are just setting things up, please refresh the page after a few minutes’ message and that’s been like that since Monday. Is anyone using Teams and have you come across this before?
-
We’ve decided to ban the use of all USB devices unless they are the encrypted devices provided by school. We couldn’t enforce Bitlocker as we only have Windows Professional and denying write access to USB drives not encrypted with BitLocker sounded good but in reality it wasn’t ideal as non encrypted devices could still be read. So we have now whitelisted the school supplied encrypted USB devices and things like school digital cameras by device ID in group policy and whitelisted devices classes such as keyboards, mice, printers allowing the end user to install such things. Testing this allows most USB devices or peripherals to be installed by the end user and only allow the use of the school supplied usb pens and nothing else will work.
-
We are looking to enforce USB device encryption across the site and have been testing a couple of different solutions. I've tested the GPOs to lock down USB device installation to a specific brand which means staff can only use the Crypto Dual Encrypted Pens we supply them and this has worked well in testing. We've had requests from staff to be able to encrypt their own drives and again I've had success in testing the deny write access to removable drives not protected by BitLocker GPO. However looking online for assistance it looks like i can only have one of the above solutions implemented and I would prefer to have both. Is this possible? And how are others managing USB encryption?
-
Profile Manager is a PITA it works here but that was after much messing about. Even now we have restrictions applied to AD groups but when I go in to that group on Profile Manager to modify the restrictions the policy is empty ... yet it's still applying restrictions! I'm going to trash it and revert it back to default in the summer and start again but regarding your problem are the Macs bound to AD, OD or both? Might be worthwhile checking DNS entries ... but then again if you've bound them to the domain DNS won't be an issue! Usually when we have had issues with pushing out restrictions it's always been down to an issue with the firewall blocking ports but you've said that all the necessary ports are open! Is the profile Manager certificate installed on the Macs? How are you enrolling the Macs in Profile Manager, we had an issue with enrolment and I found that you have to install the Trust Profile and then the Enrollment Profile. As a temporary workaround you could try applying the restrictions to the device group instead of the AD group.
-
We have domain joined iMacs and don't have an issue with signing in to 365 with a federated domain. Only issue we had was with the iMacs signing in to Office apps and that was resolved by enabling form based authentication in ADFS. Are the Macs able to navigate to the IIS page of your ADFS proxy?
-
We use https://www.classcharts.com and the staff absolutely love it. Talks to SIMS to sync classes and also write data back. We also use the detention module for managing detentions here.
-
That's a good point but I shudder think about the size of the USB drives staff are currently using around the school and having to accommodate that capacity with an encrypted device. So how are you enforcing the no normal USB devices at your school?
-
The focus here is primarily on USB devices and trying to ensure compliance with the school policy on encryption and the use of sensitive data. We have laptops for the SLT that are taken offsite and they are all encrypted with bitlocker and a startup pin.
-
Thanks for that. We have a 2012 RDS farm as well as Office 365 but staff still insist on using USB devices.
-
I have been looking to update the staff AUP here for a while now and it just so happens I have been speaking to the Chair of Governors and the Head about it today. At the moment the policy has guidance on saving sensitive information to portable drives how it should be encrypted etc. The policy also informs staff that the school will issue them with an encrypted memory stick if they need carry sensitive data on a portable device. However the Head and the Chair of Governors are concerned that because staff still use personal USB drives they could still be saving sensitive data to that rather than an encrypted device. Stoping the use of non encrypted devices isn't an option as the encrypted devices we provide are only 4GB. They have asked me to find out if there is a way for the school to ensure the guidance in the policy about encrypting sensitive data on portable devices is actually being followed. It's all fine and well having it written in a policy but is it being followed was the question! Reading between the lines I think they might want to be able to do random spot checks on staff USB drives that are being used on the school network that are not encrypted to ensure compliance. I could be way off here but that's the vibe I was getting. We have impero here so I suppose we could run reports looking for window captions for portable devices. We use USBDLM here so I already know the drive letters that will be assigned the devices. I suppose thinking about it maybe the AV logs would also help out. I want to know if any one else is doing anything similar, has any suggestions as to what to do, or if in fact the school is even able to spot check a personal device.
-
I could be wrong but I'm sure Macs use the newer SMB3 and most of the advice here has been to disable SMB1. We had some lessons in our Mac Suite today and no one mentioned any issues with mapped shares.
-
The link posted by @Arthur suggests it's £1.50 per user.
-
We are using Glamis-3 on a S8 appliance with non-transparent NTLM authentication once SMB1 was disabled on the domain controllers it stopped working. And when I diagnosed the directory in SmoothWall there were red crosses against connection to domain controller, trusted domains and groups. Rebooting the appliance didn't fix the issue so we enabled SMB on the domain controllers to get this back working.
-
It's the same for our SmoothaWall appliance. Disabling SMB1 on our domain controllers broke the NTLM authentication.
-
I believe the settings are in the Default Role Assignment Policy. You need to make sure the MyDistributionGroups check box and the MyDistributionGroupMembership check box are untucked to stop users creating groups.
-
It's currently logged with our LEA MIS Team and as a temporary workaround I have enabled the Macros (actually not configured the GPO for Word) for the one member of staff running the reports.
-
The error message is 'the macro can't be found or has been disabled because of your Macro security settings' Enabling Macros fixes this issue but that's not ideal and like I've said it all worked fine prior to the Autumn 2016 update.
-
We have Macros for all Office applications set to 'Disable All except digitally signed macros' and with SIMS 7.168 we ran in to an issue with individual reports in assessment manager. This was eventually resolved by installing patch 21751. Since upgrading to 2016 Autumn Release 7.172 the issue has reoccurred but nothing has changed in group policy to alter the Office Security settings. I've tried to apply patch 21751 and it just sits in Solus with a status of in progress. Has anyone else come across this since installing the Autumn release, is there a different patch I need to apply? Couldn't find anything on Capitas website.
-
Might be worthwhile checking out https://msfreaks.wordpress.com/2013/12/09/windows-2012-r2-remote-desktop-services-part-1/ I used the guides on there to setup or solution.
-
Have you tried connecting to the published apps URL using the built-in windows 10 remote apps feature to see if the credentials are being passed to the RD Session host? What's your setup like, how many servers?
-
We had this issue with IE and Smart Ink too and found that selecting the option to 'hide smart ink' under the application settings resolved this. It essential stops the Smart Ink overlay running in IE until a pen is picked up and used to draw on the board and still allows the user to annotate over slides in Power Point.
-
Have you configured the certificate for the connection broker part of the deployment too? I believe you need a certificate to enable single sign on.
