Jump to content

free780

Members
  • Posts

    3,614
  • Joined

  • Last visited

Everything posted by free780

  1. I think the only way it would work would be. Exam board brings devices and servers in a closed wired network. No dependency on the BAU network devices. The equipment would have to be placed in exam halls for the duration of the exam season. Any reliance on cloud is bound to encounter issues. Using separate equipment would also ensure any advantage/cheating would be very difficult.
  2. Concurrent logins are possible but should you really? If it’s exam accounts etc you should just exclude them from FSLogix.
  3. I know that the auto desk installers do not like long paths. In PowerShell you can use the $PSScriptroot variable so that c:\windows\ccm\ etc is used.
  4. The other approach which will require a P1 licence to all staff is to deny access for students off site. Maybe restrict access only from the UK. Not perfect but reduces the risk. A compromised student account can be used for recon to try and phish staff. Restricting the Azure Management enterprise application to site and maybe allow users access with MFA setup would reduce the attack surface.
  5. Sounds like SSO isn’t configured correctly. Also if there are forced password changes NCSC recommends that passwords are not forced to change.
  6. I wouldn’t even proxy the traffic. Just allow the outbound ports for the VLAN. Keeping the games up to date is another challenge.
  7. free780

    Mac on Domain

    Also be aware if a users password is changed the Keychain password in the Mac will not be in sync. This is why nomad and jamf connect exist to use local accounts.
  8. If it still uses WebDAV the performance won’t be great. I think FSLogix is the way to go but not perfect.
  9. https://www.bbc.co.uk/news/technology-65746518
  10. Also extensions will not work when using User Profile disks in RDS in Chrome/Edge. I’m surprised anyone is using RUPs anymore.
  11. Is the failure that the setting is not defined. In an ideal world Restricted should be set for all scopes but unsure what would break.
  12. https://twitter.com/gossithedog/status/1660642497633058816?s=46&t=P6jzQLbwVcCTykF7n36lig
  13. Glad I was sitting down when I read that. Made me smile.
  14. Yep InfoSec twitter has been going nuts about .zip. Apparently officeupdate.zip has been purchased. What could possibly go wrong?
  15. Exam companies IT support is terrible. This needs to be installed on a 32 bit server OS that is physical (when MS had just EOL server 2008). Any drop in internet connectivity will mean you’ll have to reboot the server. The software uses Java. Users need administrator rights and a dedicated IT Suite. You need flash for SecureAssess to function. Should we keep it up to date? Uh not sure.
  16. It’s the same issue for governors (depends on organisation). It gets a lot worse with Cyber Essentials. E-Mail forwarding is a bad idea as is any account without MFA/Identity Protection.
  17. You need a compliance item in MECM constantly checking the changes had been done. Shame Microsoft couldn’t just supply that or a scheduled task that ran the command of needed.
  18. Appeared last week. Interestingly MDMs don’t support the ‘a’ for compliance checks yet.
  19. You will need a domain admin service account for backing up DCs but use it only for that purpose. Try and block interactive logins for the account etc.
  20. I never understand why these companies don’t just let you use SAML with your iDP(Google / AzureAD). It would be so much easier.
  21. I managed to register in Edge (iOS) but can’t login. But if an oversight on Microsoft’s part. Works fine in Safari (iOS).
  22. You can do SAML for https on Fortigate. https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-see-SAML-login-option-in-captive-portal/ta-p/253300
  23. C:\Program Files (x86)\Common Files\Adobe\OOBE\Configs\ServiceConfig.xml https://helpx.adobe.com/uk/enterprise/using/customize-creative-cloud-app.html You might have to create an app with the setting you wan't. Find the xml file and GPP the file out to clients.
  24. Kerberos I struggle with comes out as Kerbros. I also end up typing folder, fodler. Microsoft also gets typed as Microsft . SQL is it Squeel? Or Seek Queen ?
  25. Sounds like share permissions aren’t correct. I wouldn’t use a domain admin except for doing work on a domain controller.
×
×
  • Create New...