Jump to content

AngryITGuy

Members
  • Posts

    411
  • Joined

  • Last visited

Everything posted by AngryITGuy

  1. I've just been sent the link to their report and remember completing the FOI request last year. If anyone else is interested in seeing the report it's here https://www.bigbrotherwatch.org.uk/wp-content/uploads/2016/11/Classroom-Management-Software-Another-Brick-in-the-Wall.pdf
  2. I was in the same boat recently while testing out our new RDS Farm. We have a REMOTE-ACCESS-ALLOW group which the collection was assigned to and policies setup to only allow remote access for that group. But as pointed out by sted we found that any domain user could login to the Web Access Portal but they wouldn't see any published apps. After a bit of hunting around online I came across and implemented this so only users in the allow group can authenticate http://www.vkernel.ro/blog/restrict-users-from-login-to-remote-desktop-web-access
  3. There's no argument that it saves time but we also see it as a security risk to have such data on personal devices. As mentioned in my original post we allow ActiveSync for a handful of users who have school issues devices and for everyone else it's blocked. But I have since found that despite having ActiveSync disabled users could still get mail to their personal devices using the Outlook app so we have had to put some rules in place to block that too as there a few alarming articles regarding the security of the app and I'm pretty sure during testing the app also ignored the ActiveSync policies passcode enforcement. I've spoken to Microsoft and there is no way to disable it across the tenant so we are as suggested running some scheduled PowerShell commands to get around it for now.
  4. Apooogies for resurrecting an old thread but did you get anywhere with restrictions Outlook? I'm in the same boat as I too am looking to lock down access to Office 365 mail via Outlook on personal computers. I've come across the same searches on Google for Client Access Policies but none of the ones listed seemed to fit my requirements. Did you have to create your own policy or merge two of the example scenarios?
  5. So I've had no joy with disabling Exchange ActiveSync by default for the tenant but I have had some success with bulk importing words in to Mail Flow Rules. After some digging around on the net I figured out how to do it and just wanted to post the instructions on here for anyone else in the same boat. You need to create a csv file, in my case it was full of file extensions i wanted to block and words I wanted to filter. After that that you need to connect to exchange online and run the following command New-TransportRule "NAME OF NEW RULE" -SubjectOrBodyContainsWords (Get-Content LOCAL LOCATION OF CSV) -RejectMessageReasonText "REJECTION MESSAGE"
  6. So we have finally migrated our on-premise mailboxes to Exchange online. At present it's just staff users whilst we iron out any issues . I kinda have it set up how I want it now thanks to the help I've found on here and online but I am struggling with a couple of aspects of it. I want to disable Exchange ActiveSync by default for the Tenant and only enable it for a handful of users on demand. The only place I have seen a setting for Exchange Active Sync in the Exchange Admin Centre is in Permissions and then Outlook Web App Policies turning it off here doesn't seem to do anything as new mailboxes sill have it enabled. I have ran a PowerShell command to disable it for all the current mailboxes but this won't work once I start adding students to Exchange. So how is everyone else managing this and is there a global setting I can set either in the Admin Centre or via PowerShell? Secondly I have configured some Mail Flow Rules one to block file extensions and the other for profanity. Using the Exchange Admin Centre you can only add the extensions or words one at a time and i haven't really been able to find and guides online on either how to import multiple items using the Admin Centre or PowerShell. And since i don't fancy typing all the words in one at time as suggested by Microsoft Support I was just wondering how everyone else has tackled this. Thanks
  7. We've recently started to use https://www.classcharts.com Linked to MIS and shows data such as SEN, PP as well dynamically changing seating plans based on ability and behavioural incidents.
  8. I've been wrestling with our hybrid configuration within Office 365 as I am planning to migrate mailboxes from our on-premise Exchange 2010 server to Exchange online. Not been having much luck as every time I try to do a remote move migration the process fails because the migration service can't find the migration endpoint. There were no issues running through the hybrid configuration wizard when it was all setup and I can see the mail connectors in the Exchange Admin Portal Online. We don't have access to the on-premise Exchange and despite errors when checking things with the Microsoft Remote Connectivity Analyzer I'm told the on-premise Exchange is setup correctly. So I am now going down the route of manual migration with PST files instead. I will need to remove the hybrid configuration and wanted to know if anyone has gone through this process. Adding the hybrid configuration was pretty straightforward so I'm hoping the reverse procedure is just as simple as I don't want to break anything with DirSync or ADFS.
  9. Thanks Richard I knew I wasn't going crazy! Guess I didn't drill down far enough through the menus.
  10. We use Class Charts and from memory it's about £2.00ish a pupil a year.
  11. Thanks for the replies guys. You're right @jslate1980 you can add permissions one at a time via the Portal but it was obviously easier just ticking the box and adding the permissions for everyone. I'm 100% sure that option existed a few months ago just can't find it now at all and it's driving me crazy! Guess I'll just have to run the powershell scripts instead.
  12. I'm having a bit of a senior moment and I'm pretty sure I haven't made this up. A few months ago whilst configuring the various settings in Office 365 and SharePoint I came across a setting that allowed me to add an admin user to the Site Collection Administrators group of everyone's OneDrive folder within our tenant. I went to check a users OneDrive today and no longer had access. I've checked a handful of other users and it looks like my access has been removed right across our tenant. I've looked through all the settings online and can't for the life of me find the setting anywhere and was hoping someone could point me in the goth direction before I start pulling my hair out.
  13. Does anyone else use this service? We are having some access issues since the site moved to version 8 of the software. Very slow access, web pages not responding and nothing apparent showing up in SmoothWall as being blocked. Internet access is fine and I've also noticed that the site is no longer https either. I have contracted their support team but was hoping someone here as already experienced such issues.
  14. Prior to the recent changes it was indeed possible to add items for multiple children to one basket and then pay it as one amount. We don't use ParentPay as a school but I do as a parent and I can't for the life of me think why they would want to mess with a system that worked from an end user point of view. But I did get email notification about the impending changes to be fair.
  15. We looked in to this and initially used the Multi-Factor Authentication service built in to Office 365 for all admin accounts. We have since moved on to testing Azure Multi-Factor Authentication as we also wanted to protect our Windows Remote Desktop services too. There is an option within Azure MFA for Windows Authentication but I'm not sure if this covers logging in to a computer. There is a cost associated with Azure MFA. Can't really comment on Google as we don't use it.
  16. I might do the same too as it would be a very handy feature.
  17. Does anyone know if you can restrict the file types users can save to their One Drive folders? Google wasn't very helpful in my quest for an answer so I'm beginning to think it may not be possible.
  18. Looks like that's the case with us too. Can't believe I let that slip by without realising, guess I know have something to look in to during half term.
  19. I must be losing the plot as we use Meraki SM and have done for years and I can't see the options to stop the end user form changing the wallpaper.
  20. The functionality to stop wallpaper changes only works on supervised devices and is at present only available on Profile Manager. I'm guessing locking the devices out simply means setting a passcode which you can clear via Meraki and Profile Manager.
  21. We use School IP here and have done so for a while. The license is up for renewal this year and we are looking for an alternative as the licensing cost is something like £6,000 for 3 years. I'm also looking at the Personnel module for SIMS which for a secondary school has a one off cost of £500 according to Capita.
  22. I updated the school iMac Server to OS X El Capitan and I am looking to do the same with the iMacs. I am currently testing out the new OS X and I am hoping to enable the default profile. I've found a couple of guides online and after following them I have managed to setup a default user template. The default template works perfectly for any local user. However as soon as I bind the iMac to AD and OD and login with a network account the user doesn't get a profile using the default template. After some messing about I found that if I enable the tick box labelled 'Force local home directory on startup disk' in Directory Utility the network user gets a profile based on the default template when logging in. However doing this also maps a network share on the iMac that is the root folder of all user profiles. All our profiles are kept in \\servername\users$ we have folders for teaching and support staff and the students. By enabling the tick box in Directory Utility the \\servername\users$ folder is also mapped on the test iMac. Not sure why this is happening as there are no configuration profiles installed on the iMac yet from profile manager. Anyone able to shed some light on what could be happening here and if there is any other way that I can force the default template on network users without mapping that share?
  23. Thanks for the update guys. It is a major PITA with Profile Manager, not being able to deploy proxy settings for the Ethernet interface. I've decided to enable the auto proxy discovery and advertise the proxy settings via DHCP which now seems to be working.
  24. I'm hoping someone can shed some light on an issue we are having since upgrading to Yosemite. We have a Yosemite server and a suite of iMacs all running Yosemite. All the iMacs are bound to AD and OD and profile manager is configured on the server. I've have device, user and group based configuration profiles all working nicely on the iMacs yet I cannot figure out a way to deploy proxy settings. The proxy setting is available under the WiFi option in profile manager but not when using the Ethernet interface. I've read online that you can configure the proxy connection on a iMac as the local administration and then copy /Library/Preferences/SystemConfiguration/preferences.plist to the rest of the suite. When I've looked at the preferences.plist file the Ethernet interface is referenced via a GUID and I'm assuming each iMac will have a unique GUID so I can't see how copying that file to the computers will actually work. So before I give that a go an a handful of iMacs as a test I thought I'd check on here to see if anyone has any additional advice.
  25. Another vote for AirServer we have had it in now for about two years and haven't really had much bother with it. Had an issue with it last year because we implemented VLANs on the network but that was quickly sorted. A really good feature of AirServer is the ability to mirror multiple iPads to the same display.
×
×
  • Create New...