Jump to content

TechMonkey

Members
  • Posts

    7,550
  • Joined

Everything posted by TechMonkey

  1. Find it simpler to keep everything off. Less support calls. When someone accidentally turns it on we need to know to turn it all off again.
  2. We are very lucky in that we have a fair space, with enough benching (though enough is never enough!). So rectangular office with desks coming off a short side out almost the length of the room. What we don't have is decent network connections or power so we are working with Estates to refurb and put a partition in-between the desks where we can mount trunking for power and data. We modelled a lot of options, but unfortunately the layout of the room precluded anything else really. Other important features are: - some big racking to store the odds and ends we have - sink/kettle/coffee machine - guard dog on top of racking that barks as people enter. - monitoring screen to let us know when things are up - non desk benching along sides of room to allow fiddling/fixing/ignoring hardware. Future blue sky plan is a to get a mezzanine in. We need a meeting area for less public discussions, plus our ceilings are so stupidly high it makes sense to claim the space. (Never going to happen but I can dream)
  3. Not reported them but reported the breach.
  4. Found the issue. MS documentation and reality do not match. Specific remote domains should override the default remote domain settings or less specific entries, as stated here. It doesn't. Currently turned off the forwarding block, but put a ticket into MS. We shall see.
  5. Yep, created a new outbound spam policy applied to only that mailbox and get the same. Really frustrating!
  6. DM me where you would like it sent and I'll get it across.
  7. Think you just have to gauge the reaction from the thread at the time (/forums/mis-systems/236405-classcharts-gdpr-security-issue.html) to get an idea what the hive mind here thinks. You are not alone in your thoughts of the incident. EDIT: I do find the paragraph where they say: Interesting. The incident was serious so we can't comment but not so serious as to count it as a data breach. I hope the ICO respond.
  8. Made my own based on the issues we were seeing and a bit of the NCSC presentation. I'm happy to send it across but it is based on my own special sense of humour! And it does include specific school email examples we recieved.
  9. Hi all, having fun with email forwarding. We have auto-forwarding blocked generally and now trying to get one mailbox able to forward to an external address. I have set the auto-forward on the mailbox and added a remote domain that allows auto-forwarding. I still get a drop response with the code: Reason: [{LED=250 2.1.5 RESOLVER.FWD.Forwarded; recipient forwarded};{MSG=};{FQDN=};{IP=};{LRT=}] Everything I can find says to fix that error I need to setup a Remote Domain. But I have! Any ideas what I am missing?
  10. Just had a look. Last blog post was in July saying late '23/early '24. You experience has been the same as mine for the 5 years, always just coming. Can't tell if it is vapourware, project issues or just feature creep/dealing with MS moving targets.
  11. Going OT a bit but I was just thinking about this. What questions should we be asking to find the real AI (I know, non of it is real AI but you know what I mean!) products and the "I used an IF statement" products? Should we be asking about what Machine Learning models they used, or ask them where AI is providing value? We have a member of staff that is going loopy over AI, wants to buy a system that will support our pupils with their learning through AI, and as far as I can tell it is just a conditional processor, you pass a test you get sent to the next one passed on the score, with a over inflated price tag.
  12. Used IAMCloud in a previous life. Although at the time it seemed to solve a problem, it did prevent people changing their mindset and locked them into the old one. It also had a lot of issues using WebDAV, such as being hit with throttling with no warning or resolution. This could cut the school off from using drives completely. The new version was always on the way, which would solve all the issues, but that has been for the past 5+ years. No idea if that ever got delivered. I'm almost certain the logout sync issue is now solved as that was one reason we moved away from native client originally. Not had any issues with that now. Also, with the native client you get shortcuts, which are game changing, though I wish you could have more than one per location. Shortcuts will follow users on any device as they are created in your OneDrive, so another benefit. I've not looked at DriveMapper in the past 2 years, so no idea what else it adds, beyond convenience. The downside of the native client is that you need to teach your users how to click the shortcut button, but it does mean they get to choose what they have quick access to, and Teams is a good front end to access most things anyway.
  13. To play devil's advocate, maybe schools and trusts need to get better at procurement and tendering? A company can't sue if there is nothing to sue about. & @gsztech you may want to edit your initial post as you have the word "threat" in it, and I presume you mean "thread". Accidentally saying a company who is known to use the legal system is using threats wouldn't be where I would want to be
  14. It kinda is a massive hole. It is how ransomware and malware coordinate attacks, by using their own DNS servers to connect to the command structure. Generally, nothing should need external DNS access except your own DNS servers. Exceptions should be allowed specifically. Also, unless you have your network fully locked down, so no one can just plug into a network port, anyone can attach a device and bypass your filtering. New KCSIE is dead against that. I'd always try and lock down your network with the worst case scenario (within reason) as someone will try something you don't expect and if you are only counting on how you allow people to connect, you will be wide open.
  15. Is your SPF record OK? We had an issue with Google accounts, and a couple of other ISPs, who had tightened their mail checks. Investigating we found that SendGrid (bulk mailer used by iSAMS) had gotten confused so our SPF, although it appeared all happy, wasn't fully correct so mails were being bounced. One check you could do is use https://www.mail-tester.com/. You send an email to an address it generates and it will look at the headers and tell you any issues. It is geared towards newsletters so ignore recommendations about images or no text. If the bounceback gives you headers you can run them through MXToolbox Header Analyser . Are you signed up to the NSCS mailcheck service and reporting? That way you can have a look in there at problems. You won't be able to analyse a specific email but it will show you areas that are causing issues.
  16. Yes, Smoothwall do not let you see the sites in the category, only user added ones.
  17. All working for us. Have you allowed the M365 category to not be HTTPS inspected?
  18. I can't say I know definitely but I think intent would go a long way, here. If the Parents have only emailed you then there is only the intent to inform not be malicious. There is also the fact that the parents haven't done anything to get access, they have been given access by ClassCharts. I think any company that pursue a Computer Misuse Act against a school and parents when their system was spewing out data would be looked upon dimly. I know we would drop them in an instant if that happened.
  19. This is part of the issue, we can't tell unless someone contacts the school to let us know they have seen our data or ClassCharts lets us know. I have less than full confidence we will be told anything, so we will never know if our data was kept secure or our data was left open and we just haven't been told about it. Having been shafted by one company already in this fashion I am getting a bit fed up with Education companies playing fast and loose with GDPR, and data security. Our SLT currently do not want to open ClassCharts back up to our parents, and I agree with them but also realise that actually this does nothing to protect them.
  20. We may need to split this out to a separate thread but, funnily I was thinking about this today as I was looking at an infrastructure refresh and what we will have on site. I think school techs will pivot to network/infrastructure and cloud specialists. We have to have the platform rock solid with everything in cloud so we have to know the network inside and out, especially resilience and internet connectivity. We will have to keep some infrastructure on site, so know what we need (and probably how to cobble it together from 8 year old hardware, some chewing gum and crisp packet!) and how to run minimal setups. & then we will know how to manage and run cloud infrastructure, SSO and administration, as well as the governance behind it all. So, it isn't hopeless or a dead end, we will just have different skills. Or we will continue to run on-site setups and then when the worm turns and everything comes back on site we will be in demand!
  21. How many bets nothing appears until next week? Would surely be a coincidence.
  22. Depends on how serious you are. We spoke to Cradlepoint a while back and their system looked seriously good. @Net-Ctrl work with them now so you could speak to them and see what is what. Can't remember prices, but they seemed pretty reasonable. The other option is StarLink business.
  23. Just realised, their advice on locking out parents is utterly useless as all that does is stop our parents seeing any information, doesn't stop our pupils data being shared!
  24. Are you a MAT/Trust and the School 1,2 & 3 in your group or are the schools completely separate?
  25. I would count them as the same task, so a sync server doing all those. I tend to go VM per task, not service. I guess the next level would be to containerise each service and run in some sort of Docker implementation?
×
×
  • Create New...