-
Posts
7,551 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by TechMonkey
-
Securly - Is it all that?
TechMonkey replied to TheRobins's topic in Internet Related/Filtering/Firewall
Sorry, was just checking you weren't using a different cloud based filtering system as you hadn't mentioned Securly specifically and we had moved the conversation on to more general cloud filtering usage. Sorry for annoyance. -
Securly - Is it all that?
TechMonkey replied to TheRobins's topic in Internet Related/Filtering/Firewall
Is that Securly or another? -
We created a Sharepoint Portal for governors and documents all go on there. They are then told when something that needs their attention is uploaded and they log in. The only issue we have found is when they use M365 for either their own work or another organisation, there is often a conflict and it tries accessing our portal with their other login. I knew getting them to log out of their other instance would lead to being told we had broken their computer so we showed them how to use incognito/inprivate.
-
Yes we did encounter the same issues, though not a MAT. We are keeping licenses to a minimum, so small group to test and then management so they can monitor dashboards. For sharing wider, the decision was to create PDF or PowerPoints, no need for interactive dashboards. It is annoying, that to just consume dashboards you need a license and everywhere seems to say that Free users can consume, but what they mean is open content, not receive shared content. You would have thought the content creator would need a license and anyone wanting to repackage content. Very annoying.
-
Securly - Is it all that?
TechMonkey replied to TheRobins's topic in Internet Related/Filtering/Firewall
Good point. We block all DNS bar ones we have nominated to stop ransomware and other malware phoning home. I guess it is just a change in mindset, as with most cloud systems. It just feels wrong to not have a filter on the main line, with it 'out there' it feels less secure and more easily bypassed. -
(Not stalking you honest!) Have you looked at SalamanderSoft? They tap into the iSAMS APIs to automatically provision users, M365 licenses, create mailboxes and definitely used to sync with Moodle. They can build really intricate rules and I haven't found anything they haven't been able to do yet. If you are iSAMS hosted, they are very touchy about you accessing the database directly, they really push you to use the API. You can get access, you will have to nominate an IP that will be allowed. We do it to create SSRS reports.
-
Securly - Is it all that?
TechMonkey replied to TheRobins's topic in Internet Related/Filtering/Firewall
So with the DNS based filtering you can guarantee someone will go through the filtering, even if a user sets their own DNS servers? -
Don't forget if you have any access control, for example Paxton. Downside I mentioned elsewhere is if you don't control the device then how do you enforce filtering on your pipe? At least with a device in between your core and the router you have complete confidence that you can apply filtering. You will still need a firewall so either a combined device or one extra box won't kill the serverless dream. Or look at some of the Hybrid filtering systems, so site(s) are protected and your devices off site are covered. I would still have VLANS to hive off any services you keep on site, VOIP, CCTV and access control as mentioned. Some thoughts on UPS for cabs, if the power goes will school continue? So do you need to keep all the services going? How long will you keep your core going so is their much point pumping traffic to it? Will your pupils be sitting in the dark still using their WiFi devices to learn? Most schools I know will shut if it is definite that power will not be brought back up in a couple of hours. Better to ship any essential admin staff off to WfH. Also print management is currently firmly stuck on site. Add to that things like copier management often have a helper service that needs to be installed on site. That is probably the biggest issues, 3rd party suppliers that expect you to have certain infrastructure. We have a managed radio system that we had to spin up a standalone PC as it had a USB dongle and didn't like server editions. Even with careful questioning those limitations never came up in pre-talks.
-
Securly - Is it all that?
TechMonkey replied to TheRobins's topic in Internet Related/Filtering/Firewall
Me too, but at least with onsite you control the gateway so can force all traffic through a filtering box. Interesting. Many thanks. -
That would be nice as we are the same, a range right across their history of models! What bugs are you seeing? We have started getting some boards having phantom touches that skip YouTube videos or PowerPoint presentations forward. Quite annoying.
-
Securly - Is it all that?
TechMonkey replied to TheRobins's topic in Internet Related/Filtering/Firewall
So fine for devices we control and can enforce, but anything else it can't be guaranteed? -
Securly - Is it all that?
TechMonkey replied to TheRobins's topic in Internet Related/Filtering/Firewall
Sorry to go off topic but how does a cloud filtering system ensure all devices get passed through it? So if someone brings in a device and manages to get on to Wi-Fi or network with out putting the cloud system as the proxy, do they get unfiltered access? -
Are you backing up minute by minute? Hardly anyone isn't no-one. I'd be interested in a comparison of costs because if you are backing up enough for a mid day outage to not lose any data there must be a fair amount of storage, at which point does it actually save money? Also it sounds a very manual process, rather than being an automated process.
-
With local storage if a node goes down doesn't that just take all VMs out on that node? I thought the benefit of Hyperconverged was that you used local storage but the magic was the vms were spread about so if a node went down everything still carried on. So the benefits of a SAN without the cost? OR have I got confused along the way?
-
What is the format? Speak to alternative finance providers and see if they can provide this format. My understanding from the past was that the LA could advise what package and many schools took that advice as it made things easier, but it wasn't a mandate. Katy's idea is feasible, though I have heard some horror stories of SQL servers in the cloud racking up costs. Alternatively do the reverse, keep the SQL server onsite but VPN it out to your cloud. I would first push back and find out where they mandate what software package you can use. It may be an misunderstanding on either side. They may have taken that as the majority of schools take their advice it is 'must have'. It may be you buy services from the LA that will only work with FMS so they are saying you have to stay with that to make it work.
-
iSAMS - Attendance capture solution, what do you do?
TechMonkey replied to Bgmcderm's topic in MIS Systems
2FA can be set to not be necessary on site, you set your school IP as a trusted network. If staff are allowed to use mobile phones then there is a staff app that can take registers. We've not pushed it but I know some staff do use it. Data is kept within the app and so is secure. I can't remember if that is an extra cost though.- 6 replies
-
- 2
-
-
- attendance
- isams
-
(and 2 more)
Tagged with:
-
He seems to have given up and just be selling his name to movies. There was another one recently, small group against army, protecting the business man (Bruce Willis) with the golden idea that could save the world. He was barely in it and everything about it was bad, even Bruce didn't seem to be much in to it. EDIT: Hard Kill, that was it. Don't bother.
-
As far as I know it is just a total for the period that is reported on, three times a year. So the invoice produced by iSAMS has line items but SAGE only knows the total. Not sure if that is a conscious decision or a limitation of the SAGE plugin.
-
Does Developer Tools show anything? I'm not hopeful as it is an internal address but the console may show something?
-
Yes, we are. I don't have much to do with it but can answer any questions, or find the answers. I'd be interested to discuss why you are moving that way as we are looking at doing the reverse.
-
Securing our RD Web access Remote access
TechMonkey replied to maxrebo's topic in How do you do....it?
If you can, setup Azure Application Proxy. Stops a direct connection into your network, meaning no open ports. -
From what I remember a clash matrix is just a technique, not a specific piece of software. It would be part of a wider program, so TimeTabler has this option and this PDF from their timetabling book explains it a bit.
-
We had one done as part of a penetration test. No one was told before hand what was happening, not even the rest of the IT team and I didn't know when it was coming. The way we went about it was that it was part of a wider security training push. I did a online Safety inset for staff and incorporated it with that. No names were used but the numerical results were shown to give people an idea of how it went and how far people went. I then showed the emails and how they could have been spotted. A bit softly, softly but the intention was to take people along a learning path, not scare the pants off them. Sorry if this is harsh but if Mavis is too scared to open emails she needs training to help her or she needs to retire. What would be done if a receptionist said they were too scared to let anyone in through the door or too scared to answer the phone.
-
It's a good skit. I've seen a version where a guy helps someone into a tiny spot, lots of shunting back and forth, careful instruction, hand movements, a really great effort, to end with the same as above.
-
360 degree safe - technical or not?
TechMonkey replied to Koldov's topic in Internet Related/Filtering/Firewall
Not done it myself but a quick look on their website shows there is a technology element so I would imagine (hope?) they ask you to participate or comment. In fact it says: Technology - Aimed at: Technicians; network managers and those responsible for data security. Covers: Filtering, monitoring and security to keep all users safe. Defining practices when using technologies and meeting obligations on data protection
