gaz350b
Members-
Posts
439 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by gaz350b
-
Not free and requires p1 level licensing. Although once you take all the benefits of p1 it’s cheap.
-
Smoothwall Slowdown ? Especially in the morning.
gaz350b replied to 2097's topic in Internet Related/Filtering/Firewall
See if there are any domains in the top 10 on the homepage with a massive amount of hits. We had a Microsoft domain being blocked 1 million times a day…. -
Could be anything from ssl interception to domains being blocked. It could also be failing authentication to Smoothwall. Get m365 domains added to white lists, allow unauthenticated users and finally add it them to the bypass ssl interception. Mix and match to find if any helps.
-
Look at configuring a connector in There you should be able to whitelist your network.
-
Aim to get baseline data on how they find the service don’t try and get try and get “I need x y z” type answers. Simple grid how do you rate the following with regards to the it provision. Issue resolution Quality of advice Promptness of answering phone Overall quality of issue handling Professionalism Helpfulness Ease of contacting IT Support Promptness of email response We base ours around the ofsted rating system. Feel free to leave a box for open comments. Sometimes people won’t raise their gripes with the system in person and other people won’t via digital methods. So hit it with face to face meetings too. And schedule it every year for summer. Use it as per of your Performance review.
-
It really depends on finances. If you go all new kit how do you plan on replacing it! I would try and bring a small amount of legacy as long as there is a strategy to replace it. As long as all pcs and servers have the required standards for windows 11 maybe latest gen i5 m.2 they should be good for years to come imo. You can always increase ram as you go. Start replacing at year 5. But keep anything that is serviceable as spares. Keep number of specs differences down to a minimum makes supporting longer term easier. If anyone is still on a full 5 year replacement strategy now, you are either speccing too low to begin with or you have a magic money tree some where.
-
Simply take the waste toner out, get a bag open the slide slot on the toner (roll you sleeves up)…. And shake the toner into the bag. Do it outside! (It uses gravity from the weight of the tube to press a button I think)
-
Reason we are saying don’t use the on-site version. It’s not being developed, doesn’t support office 365 modern auth and support will eventually be fully pulled. The cloud version is a total rewrite and we found it rubbish and I can’t even remember if it supported modern auth. So basically all those saying use the on-site version and get it working are suggesting to use something that is a potential security issue going forward especially as you would need to turn on legacy authentication (insecure) to get the on-site version working. Spice works has a weird authentication method to login. Not even sure if it’s local even in the local version! What if they disable this… you now have to migrate to another help desk.don’t do work twice when their are better alternatives out there now.
-
As someone has already said Spice works doesn’t work with modern auth. On-site is also end of life. Their cloud version doesn’t cut it imo. I would move to something that does support modern auth. We migrated to fresh desk for this very reason (from spice works).
-
We deploy all the required drivers to every machine (Version 3) as Microsoft guidance suggests. Printers map just fine when you do this.
- 1 reply
-
- 1
-
-
There is also a hardware reset which often fixes keyboard issues for us.
-
Azure MFA Causing Outlook Desktop App Password Issue
gaz350b replied to Gongalong's topic in Cloud Services
The main issue is basic auth can be used to do spray attacks and work out passwords. So You should work towards disabling them all. Exchange power shell has a modern auth module but I can’t stress enough monitor logs, migrate users/processes to modern auth and to an acceptable level you won’t catch everyone then turn it off. We did a “change” email advertising what they needed to do and then targeted emails “our logs show that you use mail app on iOS follow these instructions to delete/add again using our new authentication and read failure to complete will result in no email at xxx date on your device” After desktop app switched which should be easssssy. Checkout the other thread on turning off basic auth too. I would focus on EAS, imap/pop 1st If you have any internal applications using authenticated snmp migrate them to at least to your “o365 connector” (research how to connect a printer to o365 without auth) We also migrated things like our help desk to fresh desk because our old one didn’t support modern auth. So it’s not just end users you need to think about. -
Top half of this page should cover most of your query. https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/enable-or-disable-modern-authentication-in-exchange-online Modern authentication is basically a webpage so OWA uses it by default. When users get a OS type login this is basic auth. Outlook should prompt but doesn’t always. Now modern authentication is turned on start monitoring AzureAd sign in logs. This page outlines most of the Outlook client. https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-auth-and-exchange-online-february-2020-update/ba-p/1191282 I believe outlook app on iOS acts the same as outlook and should present the new modern auth login. Non-outlook clients such as mail app will need to be deleted and recreated for modern auth to work otherwise when it’s disabled you will get constant password prompts. Monitor the azure ad legacy auth logins using filters and migrate users as needed.
-
Azure MFA Causing Outlook Desktop App Password Issue
gaz350b replied to Gongalong's topic in Cloud Services
We actually configure admin accounts to 2fa every 24hrs as we are really bad for leaving sessions open in our browsers so conditional access boots us out. -
Azure MFA Causing Outlook Desktop App Password Issue
gaz350b replied to Gongalong's topic in Cloud Services
As a part of moving to 2fa I would also make sure you are disabling basic authentication. Otherwise 2fa can be bypassed. Verify who is still using “Legacy authentication” because all your users with non-outlook Clients like iOS and Google users will need to delete and add their email. Use the sign in logs in azureAd to see how ready you are. It took us a good month to move everyone off legacy auth. We eventually just turned it off because the last few people were impossible and would never reply to emails or make themselves available. (They turned up that day after disabling) -
The password protection has nothing to do with mfa. You can also use it on your local AD servers to apply additional rules.
-
If you really want to cover yourself. I would get the exams officer to send you the official guidance from exam boards on how they expect IT to be setup. Then Respond quoting how you are meeting each requirement. If they still don’t agree with your stance then start involving senior school leaders to give guidance. Then setup the system as agreed with those senior leaders not the exams office/senco
-
Just let the kids use their normal accounts on the laptops? We use chrome books and then when it gets closer to exams introduce them to using the windows laptops and the exam write (pro?) software. When it comes to the exams itself we then use a locked down account with no internet etc. What ever is agreed this has to be all concerned working together and as a school if they have shown they have a need we should try and provide it even if on the day they never use it.
-
If your school runs catering, ours is ran cost neutral including staff. But now we have limited income so losing money from that.
-
We use this tool great for remotely monitoring deployments so you know when to go back to a room. Also gives you error messages 95% of the time, but there are some instances where it doesn’t give you feedback on the error. But that might be a limitation of other factors such as steps being ran or software etc. https://gallery.technet.microsoft.com/ConfigMgr-Task-Sequence-fefdc532
-
We pretty much deploy all year round now. Test - pilot - non critical teaching devices such as open resource areas - teaching devices - mop up the last few mainly staff laptops . 1709 is in the mop up phases now and Skipping 1803 due to certificate issues. 1809 testing/pilots start term 2 with a select group of users covered at least every area of the organisation. We only deploy what we know is stable over the summer for the reason we don’t want too much trouble to happened come September.
-
I think there are some pre-reqs for wsus before you will get feature updates for windows 10.
