Jump to content

DGardiner

Members
  • Posts

    1,544
  • Joined

  • Last visited

Everything posted by DGardiner

  1. Did you ever sort this? You can now enable cloud print on the mobility server and then use google admin to deploy that to the end users - Limited testing seem to suggest it gets around the discovery issues, though it enables cloud printing :0
  2. We have alot of stuff being bough centrally and moving around - We just kept them seperate at the start and its stuck.
  3. We have -main domain OU -ChromebookOU -SCH1 -SCH2 -ETC -Staff OU -SCH1 -SCH2 -ETC -Students OU -SCH -Cohort -ETC All settings are applied at the root and overridden as required in the child OU's General trust policies/restrictions are trust wide - Very little changes school to school except some Services/bookmarks/wallpapers this lets us do that.
  4. Yep that sounds the plan. all user settings will come from the Users UO's inherited settings. Hardware from whatever the inherited settings are for the devices OU
  5. With google theres usually not much overlap where user/devive settings will mishmash like on GPO theyre usually a different subset of options. Ive got our device settings deployed at the root because its pretty static (possibly the custom walpaper is per OU) but the policies can be overridden in the OU's as ou require differences. As for users, Again the overarching trust policy is applied at the root OU and then we override individual settings as schools require differences Probably worth mentioning Deice settings only apply to hardware in the OU's below, User settings apply only to user accounts
  6. Ensure you have enterprise enrolled the devices. at this point you can forget about them. Go into google admin > devices chome > settings > user or device Scroll throuhg the list and tick till youre happy. Id suggest: Forced reenrolment on Restrict logins to your schools domain/s set update policy set downloads to save to drive by default the rest will be preferences
  7. Any app that connects to the api has an appID, if you go to the page above and press the "third party apps" you can add app id's to the list and set them as trusted. this will allow them to connect to those high riskscopes - anything not on the list will get an app not authorised error
  8. While our instance didnt seem to be affected... 3 days is pretty piss poor... try explaining that to the higher ups, ipads are here no they cant be setup
  9. https://admin.google.com/ac/owl click manage google services Change Drive/Email, press restricted and then tick the high risk scopes only This will allow them to use basic oauth stuff that will share name/email but will stop things hooking in and reading their drive/emails for example unless on the whitelist
  10. Ours was them complaining that they had been restricted since they could no longer use them for facebook/etc
  11. When ours initially went out we hadnt restricted the "allowed logins" to our domains, Quite a few parents rang up complaining after that was rectified...
  12. Id love to hear how they even justified this
  13. id recommend setting all high risk api scopes to whitelist only.. then you get to control what they plug in. Were considering setting chrome extensions to whitelist only to
  14. Thats how they work since theyre user assigned not device, they shouldnt download the apps every time if you encourage the same user on the same chromebook.
  15. i means its almost like a MSP can make bank for no effort managing a fleet of laptops from a web based admin panel, yet push back
  16. Chromebooks are great, manage expectations... for a school who uses gsuite and the majority of tools are web based theyre a good choice and enable more equipment to get in front of the kids. "Gsuite subscription" you mean the free thing you just have to fill out a form to attain? for the equivalent you would have to have to run a windows network(azure/ad) or ipads(MDM)? I think you miss the point, Education does not revolve around a smart board or any application. when every child has a device available at their desk with colaborative tools the paradigm changes and a board is no longer the central focus in the lesson. Teach tansferable skills... not software packages We have a device agnostic approach and let our schools follow their own path and supported them in it, our traditional windows estate has been shrinking. Our iOS/Chrome estate has been growing steadily in a pretty even split until last year when in the first lockdowns when our google equipment was ready to go home without any prep. it has within the last 12 months Quadrupled in size and our 1:1 ios schools are now looking like ipads are going to be phased out... and this off their own backs.
  17. Check your smoothwall, IOS stopped accepting certain certs a while back, you may need to recreate your SW CA. though if you have ssl inspection turned off no idea
  18. Thats the point, you apply the restrited mode to lock it down when not logged in. then it uses whatever settings you have configured in gsutie for logged in accounts. set your teachers OU to be able to whitelist and kids to whichever restriction level you want oops same as above.
  19. Run a mail log search, it will show the send and why it was blocked - usually helps with tracking things down. If you know the IP of your helpdesk you can also setup SMTP relay to accept mail from it with no auth/etc
  20. Dont you need to enable less secure apps for that? IMO it should be disabled anyway along with pop3
  21. 9am email: BUBBLES MUST NOT MIX FOR ANY REASON 9:15: CAKE IN THE STAFF ROOM!
  22. How have you contacted them? can send some contact details for my account manager if you like? might help move things forward quicker?
  23. Like i said, more versatile. Chromebooks are great and have theire place, but if someones having to ask for hardware recommendations its pretty likely they dont understand the limitations theyre getting themselves in for... for the tidy price of £600
  24. Just a quick flick about the usual retailers: https://www.currys.co.uk/gbuk/computing/laptops/laptops/lenovo-ideapad-flex-5-14-2-in-1-laptop-amd-ryzen-5-256-gb-ssd-teal-10208569-pdt.html Ram looks to be soldered though, but has a removable ssd should that need swapped in the future. current circumstances probably wont help prices if the touch stuff is just a gimmik id personaly rather something like these, all seem fair: https://www.argos.co.uk/product/9396461 https://www.argos.co.uk/product/7296415 https://www.argos.co.uk/product/8181756
×
×
  • Create New...