ryanplym
Members-
Posts
103 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ryanplym
-
Thats Ollie, I already have a VM in place just for this. the IT teacher has full access to this VM, it already has XAMPP and all the fun stuff installed and also a outbound firewall rule for port 80 to this vm so students can show their work off to whoever at home. I feel have done everything correct from my side but I dont think installing XAMPP on all pcs is a wise move but who am I - just the IT guy
-
i have a folder with email print offs, people would laugh at what they have asked us to do, unfiltered, unmonitored access to SLT ipads, they are able to log into their own personal accounts, not have it linked to their school email just as a start. I do have email filtering put in place for teaching staff that pick up on "gift cards" and scams etc this has stopped alot of issues but give it time and they will ask for unfiltered access for all :-)
-
Thanks I agree. I have spoken to SLT multiple times and had long chats with them but they say that he is the teacher and I am not in charge of student behavior. If the students access something they are not supposed to then that is their choice. It is down to the teacher to manage their behaviour. SLT love this teacher so I have no chance. I am just concerned about installing XAMPP and getting it in the neck that the PCs are slow.
-
That reply msde me laugh. We really have gone out of our way to provide. Even as far as seperating his IT room, giving him a dedicated IP range and his own special smoothwall filtering (Everything off except adult). I dont know any other schools that would go this far
-
Thanks, he knows about the web server, has access to it but really wants every pc to have xampp installed. Teachers always get what they want
-
Hi Our IT teacher wants me to install XAMPP Visual Studio Code and FileZilla on all the PCs. Personally I think its a silly idea as we already have a dedicated web server for the students to use to test their websites. Do other schools do this or am I being too soft on our IT teacher? Any thoughts about this would be useful or ideas that you have put in place for key stage 4 / 5 for their coursework Thanks
-
Thanks 2097, I have checked all enforced GPOs and cant see anything obvious. I also used the policy analyser tool. I am using pass-through authentication with SSO enabled. I will keep trying
-
Thank you thimon DavR thanks that's a good shout. I did check the domain and it is matching with what I have in azure. The students have their full email address in the email field although I will check the attributes in the morning.
-
HI thimon Thankyou, would you mind screenshotting your group policy settings if thats OK. This is the group policy we have enabled for computer configuration and user configuration: Computer Configuration (Enabled Policies) Administrative Templates - Microsoft Office 2016 (Machine)/Licensing Settings Enable EDU Org ID Sign In in Office from Windows Store: Enabled Use shared computer activation: Enabled Administrative Templates - OneDrive Always use the user's Windows display language when provisioning known folders in OneDrive: Enabled Prevent users from moving their Windows known folders to OneDrive: Enabled Prevent users from redirecting their Windows known folders to their PC: Enabled Set the sync app update ring: Deferred Silently move Windows known folders to OneDrive: Enabled Tenant ID: xxxxx Folder Options: Desktop, Documents, Pictures Silently sign in users to the OneDrive sync app with their Windows credentials: Enabled Specify the OneDrive location in a hybrid environment: Enabled Authenticate first against: SharePoint Online Use OneDrive Files On-Demand: Enabled Administrative Templates - Windows Components/Device Registration Register domain joined computers as devices: Enabled Administrative Templates - Windows Components/Internet Explorer/Internet Control Panel/Security Page Site to Zone Assignment List: Enabled Zone Assignments: https://device.login.microsoftonline.com (1) https://login.microsoftonline.com (1) https://aadg.windows.net.nsatc.net (1) Administrative Templates - Windows Components/OOBE Don't launch privacy settings experience on user logon: Enabled User Configuration (Enabled Policies) Administrative Templates - Microsoft Office 2016/Miscellaneous Suppress recommended settings dialog: Enabled Administrative Templates - Microsoft Office 2016/Privacy/Trust Center Allow Microsoft to follow up on feedback submitted by users: Disabled Allow the use of connected experiences in Office that analyze content: Disabled Allow users to submit feedback to Microsoft: Disabled Disable Opt-in Wizard on first run: Enabled Enable Customer Experience Improvement Program: Disabled Send personal information: Disabled Administrative Templates - Microsoft Office 2016/Subscription Activation Automatically activate Office with federated organization credentials: Enabled Administrative Templates - OneDrive Allow users to choose how to handle Office file sync conflicts: Enabled Always use the user's Windows display language when provisioning known folders in OneDrive: Enabled Coauthor and share in Office desktop apps: Enabled Continue syncing on metered networks: Enabled Continue syncing when devices have battery saver mode turned on: Enabled Disable the tutorial that appears at the end of OneDrive Setup: Enabled Prevent users from syncing personal OneDrive accounts: Disabled Administrative Templates - Windows Components/Internet Explorer/Internet Control Panel/Security Page Site to Zone Assignment List: Enabled Zone Assignments: https://autologon.microsoftazuread-sso.com (1) *.sharepoint.com (1) *.onedrive.com (1) Administrative Templates - Windows Components/Windows Hello for Business Use Windows Hello for Business: Enabled Do not start Windows Hello provisioning after sign-in: Enabled
-
Hii I hope I have posted this in the correct section as all our clients are Windows 11 Our IT Teacher wants single sign on for OneDrive. - I have followed the procces step by step from Microsoft here https://learn.microsoft.com/en-us/sharepoint/use-group-policy#SilentAccountConfig - Added the registry keys though group policy and tried adding manually - I have joined the PC to Azure AD using the hybrid configuration When a student logs in, it prompts them to setup onedrive, asking for a email address. When they type their email address, it logs them straight in not even asking for a password and will remain logged in if the student revisits the same PC but when they use another PC, it prompts them to login which frustrates the IT teacher. SSO works fine with edge, office applications, Teams but onedrive is the only application that prompts for a email. I know I am missing something, I just dont know what. Any help is appreciated - Thankyou :-)
-
Do you have this policy enabled in your computers OU or users OU? I have mine enabled in both. I wonder if this might be the cause?
-
-
Hi We are having a strange issue, in our computer labs, when a student signs into windows and clicks on, for example, Microsoft Word, it prompts them to sign in although Teams logs in automatically, edge/chrome logs them in but none of the installed apps. OneDrive is also prompting them to sign in. I have changed the following: Administrative Templates/Microsoft Office 2016/Subscription Activation/Automatically activate Office with federated organization credentials Enabled User Configuration\Preferences\Windows Settings\Registry Key Path: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\microsoftazuread-sso.com\autologon Value Name: https Value Type: REG_DWORD Value Data: 0x1 (1) Key Path: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\windows.net.nsatc.net\aadg Value Name: https Value Type: REG_DWORD Value Data: 0x1 (1) User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow updates to status bar via script Enabled One of the IT teachers had a observation this morning which did not go down well at all. I am not sure what else to do. I have used delprof to remove any profiles on the machine, did gpupdate /force, ensured the policy was enabled Any help or support is very much appreciated Thanks
-
We had exactly the same issue. I noticed it was to do with our smoothwall system. On smoothwall I added a rule (and placed it on top within guardian --> Https inspection) the following: Everyone Microsoft Office 365 Everywhere Always Validate certificate only About 20 minutes later, emails started coming through
-
Sorry for not messaging sooner The copy link works perfectly, except out staff wont do that as they only send the email directly to that shared mailbox. I am trying to find a way that we can convert the permissons from the shared mailbox to the invidiual user account, they can see the shared mailbox in outlook, when they click on inbox they see the file that has been shared although when they click to open the file, it requests pemission. Its causing a issue for the department. Thanks for all your help so far, I thought it was me just being stupid
-
Thanks, The group creation idea might be better for our staff, using teams will create more work and will be too complicated for them. Another issue that management has just picked up on is if I directly share a file to staff 1 and staff 1 forwards that email to staff 2, staff 2 has to request permission from me to open it. Is there a way to prevent this? Senior mangememnt are getting fed up with all the alerts although they want full network access but thats a story for another time :-)
-
Hey I am not sure if this is possible but I am looking to seek some advice on a challenge we're encountering with our shared mailbox setup. We're currently using Office 365 and SharePoint, and have a shared mailbox that two of our staff members access through Outlook. Here's the situation: whenever a file is shared directly with the shared mailbox, the two associated staff members are unable to access it without requesting permission. Interestingly, sharing a link to the file works perfectly, as I've configured the default sharing policy to "Only people in your organization." I'm curious if anyone has found a workaround or solution that allows staff members to directly share a folder with the shared mailbox in such a way that those with access to the mailbox are automatically granted access to the file. Any insights or guidance on this matter would be greatly appreciated. Thank you :-)
-
ooo thankyou!!! I have just clicked on replit and this looks perfect. Better than the VM idea i guess
-
The IT teacher is completely against the virtual machine idea. "Please do not go down the Virtual machine route. This will severely affect performance issues on machines. Virtual machines can be exposed to network drives, but I don't think this is an appropriate solution. I'd be happy to sit down with yourself, et al to discuss plans going forward for the college network before any segregation etc takes place. " I agree, the sercurity comes first, but here, the teachers get what they want
-
Thats not a bad idea. Thanks for the suggestion. The IT teacher wants the students to upload the py files to OneDrive\teams so he can view the files himself. I was thinking about creating virtual machines with no internet access but the students wont be able to save their files to onedrive. I am baffled on how I can do this. If I allow internet access, students can use the virtual machine to play games and download scripts etc but this will also give them the ability to download the scripts to the school computer
-
Hey Happy Thursday. We had fun yesturday. One of our sixth form students decided it would be fun to run a python encription script on our server (They have been learning about python in their IT lesson.... about encyrption..) Lucky, they have limited access and was unable to encrpt anything. It looks like a pre-made script downloaded from the internet. The students are also accessing powershell to run things such as wget. ping, ipconfig etc. They have also uploaded shortcut scripts and random tools (such as a active directory browser) to their onedrive, download it on the school PC and run it. I found a text file with all the usernames. I was watching this student in realtime on Netsupport, so I blocked his account and logged him off. I have found he has uploaded portable games to his onedrive account. I was told by SMT to unlock his account as he needed it for his IT lesson.... Basically... I want to lock down access to powershell and harmful tools for the students, which I have done on group policy (looking into the onedrive upload restrictions) but the IT teacher is kicking off about allowing it in his IT room. So, I deneid the standard student group policy for his classroom, put a new policy in place, denying all other PCs other than his classroom. But he wants the students to access these tools in other unmonitored areas of the school, such as the sixth form centre. Back to square one. Has anyone else managed to successfully keep the IT teacher happy and put a policy in place that allows students to access python etc but without it causing harm / allowing students to play games etc?
-
Hi We have a teacher who insists on getting students to edit Word documents within Teams. We have Stone PCs with Windows 11 and Office 365. Every time they open a word document and attempt to edit a file, the Teams application will flicker when typing or moving the mouse. I have tried disabling hardware acceleration but still no luck. All other applications within teams works fine such as Excel and PowerPoint. I have reinstalled Windows and Office and attempted a online search for the issue. I have tried the application on my own machine (not Stone) and it works fine. Any help would be appreciated. Thanks Kindest Regards Ryan
-
From Google Support: Google Workspace Support, Kushal1:14 PM Thank you for contacting Google Workspace Support. My name is Kushal and I'll be working with you today. While I read over your message, is there anything else you'd like to add? Google Workspace Support, Kushal1:14 PM Hello, how are you doing? 1:17 PM Great thanks. We have a large number of students and staff that keep getting the "loading" message everytime they try and open a message. They are unable to load any messages Google Workspace Support, Kushal1:19 PM Please inform the students to clear cache and cookies in the browser, and use google chrome browser with an incognito window. Google Workspace Support, Kushal1:20 PM I am sure the problem will be resolved after doing this. 1:20 PM We have already tried clearing the cache and cookies and this does work for a single session then stops working again. Incognito mode is disabled for students for safeguarding reasons Google Workspace Support, Kushal1:21 PM Okay. Google Workspace Support, Kushal1:22 PM Are all the devices personal or from the institution? 1:23 PM These are all from the college. None of these devices are personal. Thanks Google Workspace Support, Kushal1:23 PM Okay, please uninstall the chrome app and try installing it again. Google Workspace Support, Kushal1:24 PM in all the devices. Google Workspace Support, Kushal1:24 PM Also please make sure that the internet connection is stable as well. 1:25 PM Thanks I will give it a try
-
Thanks for testing this at your end. We do not have any Chromebooks here only desktop PCs and a few windows laptops. Office 365 works with no issues. I tried using Google Chrome and Edge but none of these browsers work. I can only assume its something to do with the Google admin end? I will speak with Google support and keep you informed with any progress
-
Morning I just grabbed the IP address of the client and added it to: Guardian -> Web Filter --> Exceptions --> Source exception IP Addresses (http://smoothwall:81/modules/guardian3/cgi-bin/guardian/filteringexceptions.cgi) then press save at the bottom of the page Another way to check is to bypass the https inspection: 1. Create a new location and add the client IP Address: (http://smoothwall:81/modules/guardian3/cgi-bin/guardian/locations.cgi) 2. Go to https inspection --> Manage policies. At the very bottom of the page in small text, click on create a new policy (http://smoothwall:81/modules/guardian3/cgi-bin/guardian/https.cgi) 3. Select the following: Who: Everyone What: All https content and all https urls containing an IP Where: Add the location you have set from 1. When: Always Action: Do not inspect Don't forget to remove the IP address from the exception list otherwise students will have a good time :-)
