Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Michael

Edu Supporters
  • Posts

    12,849
  • Joined

Everything posted by Michael

  1. It works on a Normal > Incremental basis, then Incremental indefinitely in line with your retention policy. Performing Normal backups indefinitely doesn't make sense and will eat up your data in no time (even if it were possible).
  2. There are several ways to tackle this - Single Domain, Single Forest (as above) or Parent Domain, Child Domain (Single Forest) or separate Domains, separate Forests connected with Trusts. That's with regards to how Active Directory is configured. As to how you connect them all up, there are numerous options. Curious why did you backtrack on MPLS and multiple Domains in a Forest? Yes you have to start fresh, but at least then everything's consistent in your organisation.
  3. Windows 10 has a concurrent limit of 20 connections, so bearing in mind a class typically has 30 pupils, this will never work well. Even if permissions are correct, Windows will know how many active sessions are connecting/connected. This is why Windows Server makes sense and will make your life much easier. Even if you just installed it but maintain a Workgroup set up. Of course I would recommend you look at creating a Domain as it makes user authentication straight forward.
  4. In what way were they faulty out of curiosity?
  5. I've just bought 2 x Unifi AC1750 (connected via Cisco PoE Switch) for home use and these are the speeds I'm getting - This is connecting at 400Mb using an Intel Wireless-AC 7265 adapter and exhausting my 100Mb VM broadband connection!
  6. Sounds like it's linking to Azure, however the same rule applies (best to my knowledge), as O365 and Azure are heavily integrated. From what you're saying, a new domain would be the best route. Unfortunately I fear that some Local Authorities implement such configurations as to 'lock' the school, making it more difficult to move to another solution.
  7. As above, it needs to be a public domain with the relevant DNS and MX records and anything else it needs. To make it internal, you'd just apply Mail Rules afterwards to block anything external. If you think about it, this does make some sense given that O365 is an external service also. Even if you applied Mail Rules, mail would still leave site and then come back again, unless you have an Exchange Server.
  8. I'm a bit confused by your question - of course when setting up Azure Connect, you're prompted for local AD credentials, as well as credentials of your new tenant. The sync then begins. If you're trying to create users in Tennant B instead of Tennant A, you'd need a new/different domain extension, whatever that will be, as of course domains can only be registered to one tenant at a time.
  9. It's one of these that's the issue. HP iLO firmware is up-to-date (version 2.50) and not sure if the firmware on this unit is even upgradeable!
  10. Thanks for this, but I didn't require it in the end. For some unknown reason, it's the KVM that affects all HP Servers in the same way, but not older Servers. It's not the keyboard or mouse, as unplugging these from the KVM still displays the problem. When completely disconnecting the USB cable from KVM > Server, the problem goes away. It's not a massive problem as I can now manage Servers using iLO (Integrated Lights Out), but still, somewhat of a mystery.
  11. The following Powershell script works for me adding ProxyAddresses for all users: $users=import-csv C:\tools\SMTP.csv foreach($user in $users){ $u = Get-ADUser $user.name -Properties mail,department,ProxyAddresses $u.ProxyAddresses = $user.ProxyAddress -split ';' Set-ADUser -instance $u } PAUSE SMTP.csv should read: Name ProxyAddress User1 SMTP:[email protected];smtp:[email protected];smtp:[email protected] User2 SMTP:[email protected];smtp:[email protected];smtp:[email protected] SMTP (CAPS) meaning Primary and smtp (lower), optional alias.
  12. Hi all, I have a HP Gen9 server setup using HP's Intelligent Provisioning, running Server 2016. Sometimes (but not always) the server gets 'stuck' on the Windows Boot Loader between Windows Server 2016 (default) and Win PE or RAM Disk Options as it's listed as (see illustration): Any idea(s) why the server sometimes gets stuck on the Boot Loader? And what is the RAM Disk Option or Windows PE boot option required for? When it gets stuck, I have to hold down Escape and then eventually it takes me to the UEFI BIOS whereby I can boot Server 2016 as normal. Not seen this behaviour before and Googling the issue is revealing little results, hence me posting here. Thanks!
  13. Confirmed here also. A lot of Admins all complaining about the same issue. Unbelievable really!
  14. Even if you change Azure AD policies so Staff can self-change passwords using a phone number, security questions or alternative e-mail, it makes no difference. The cost isn't justifiable at all in my opinion.
  15. I agree, direct joining isn't a good idea due to the different types of fibre in use. Of course one possibility is a fibre switch, fed by a 10Gb link from A to B, then from B to end points. In this scenario all of the mixed types should work without issue.
  16. Taken from here At no point during Azure AD Connect does it mention that it's a Premium Feature...
  17. Some websites are stating this is an 'Azure AD Premium feature', but not sure what that actually means? I'm using Free Student/Faculty O365 licensing, whatever it's called these days.
  18. Yes they can - for example (by default) I create the user either manually or automated and prompt them to change their password. I was under the impression that could do this from O365 or AD first and that the changes replicate in both directions, but evidently they don't appear to do so. I just receive the message 'Your organisation doesn't allow you to update your password on this site....' as I wrote above.
  19. Right the latest is - If I set a static password to a user in AD, this syncs to Azure within 30 mins and then works as required. So does this mean for definite that users need to reset their passwords from Active Directory only?
  20. Hi all, I'm having a few 'snags' getting Azure AD Connect to work as I require. The latest version is installed on Windows Server 2016 and users are being synced correctly. For the time being, pupils have a static password and this works absolutely fine in AD and O365. Staff however, I want them to be able to change their password from the default set. The AD side of things looks fine. When a test Staff user first logs into O365, they're prompted to change their password, but then I receive a message 'Your organisation doesn't allow you to update your password on this site. Please update it using the method recommended by your organisation, or ask your admin if you need help.' I have Password Writeback enabled and I've even explored the option of allowing users to reset their own passwords and still no go. I must be overlooking something really obvious!? Some articles I've found online state the end user can only reset password within AD and not O365, but this cannot be right surely?
  21. If users have an older version, Office 2016 setup will remove it automatically is the default behaviour. If users already have home agreements, the onus is on them to cancel it after it expires. That's not really your issue. As you say, make them aware it's there and it's legal, but you offer no support. It's what I do.
  22. Remove Everyone: Full Control, then type/search: Authenticated Users, and specify Read/execute rights. Then click Advanced > Change Permissions > Replace all child objects...
  23. The desktop will (or should normally), be a redirected folder/share somewhere on your server. If you look at Group Policies you'll know for sure (Folder Redirection > Desktop). Simply give Pupils read only access to the share, just as you would other folders on your network. Pupils will then be unable to save or rename shortcuts. They'll just see an Access Denied message.
  24. I look forward to it; I just worry a lot of companies could spend a lot of time/money developing something, only for Apple not to publish it on the App Store.
  25. A quick Google reveals Quest Password Manager, but at nearly £5 a user, it's just laughable.
×
×
  • Create New...