Jump to content

jthompson

Members
  • Posts

    5,685
  • Joined

  • Last visited

Everything posted by jthompson

  1. Basically, yeah. The key part there is... Note that with Search And Assistant turned ON for your users in Google Admin, you can still specify within that that Google Assistant is turned off for them. I'm working on the assumption that keeping Assistant turned off is good, because home smart speakers.
  2. My response was directed at @paulkerton, really. I'm pretty sure that you can't prohibit internal sharing, but I was just wanting to get confirmation. To answer your query about safeguarding, as an org you will always be able to use Google Vault to inspect anything that does come to light. That, I suppose, is the fallback, even if there's no technical means to prohibit uploads and sharing in the first place. It will seem like a bit of a weak answer, I'm sure, but perhaps better that any such material being shared around is at least being shared around on a platform that the school has oversight of, rather than on one which it doesn't?
  3. Can you prevent students from sharing items with other students? You can certainly prevent them from sharing outisde of the org, but I don't think there's a control for restricting internal sharing, is there?
  4. Yes, the film has a military plotline that feels like it was lifted from a Mega Drive game, but it's basically a cinematic air display served on a platter of cheese. Rubbery, orange-coloured American cheese.
  5. EduLink One is worth looking at. https://www.edulinkone.com/#!/demo As the name suggests, it tries to unify all those different aspects of school/parent comms in one app (parents' evenings, messaging, timetables, reports, homework, etc.). It does a good job of it. It's very modular and you can disable any modules that you're not currently wanting to use. In terms of messaging, it supports SMS, email and in-app messaging (any email messages sent to parents will be available to them as in-app messages. That's a good thing because other people can be crap about knowing whether their email account is full, etc. but they can always get those messages in the app). You need to come armed with details of an SMS provider (such as ClickSend or Gov.uk Notify) and an email relay to use. Edulink themselves don't send out the messages, but rather integrate with the service provider details that you plumb in.
  6. You'll need to make sure that the implications are considered and understood (by your end users). If these are messages where replies back and forth might be expected, conversations will fast become a complex mess if your headteacher is doing anything other than reading those messages that are being duplicated into their mailbox. As soon as they chip in a reply from one of those duplicated messages, the thread will become split and colleagues may begin to miss inmportant information. Avoid this kind of thing if at all possible, but if it can't be avoided, stress the importance of only replying from the shared mailbox.
  7. Veeam on-site backups and N-able (aka Cove) for backups to cloud.
  8. Helpdesk (for one of those people who is pointedly unhelpful to end users) Dreamcast (for one of those people who always seems to buy the 'wrong' games console) manpage (for someone with misplaced pride in "never reading the ******* manual")
  9. Maybe OneNote or WikiPedia for someone who always diligently updates their documentation.
  10. DropTable doesn't sound like someone I'd want as a wingman/wingwoman. Mind you, neither does Mass Outage :|
  11. As alluded to in the annoying things thread, I watched two Top Gun films last weekend and have had lines and songs from the movies stuck in my head all week. One of the fun things about those films is the cool callsigns that the pilots have (I can't decide whether the maverick protaganist being literally named Maverick is one of the best or one of the lamest bits of character-naming in all movie history). Names like Ice, Cyclone, Hangman, etc. all help to ramp up the cheesiness to a delicious level. Given that IT techs are just as cool if not cooler than best-of-the-best navy fighter pilots, what callsigns do you think would work well? I'm going to offer a few examples to start: Reboot Spacebar Firewall Cronjob Bluescreen
  12. Correct. IE mode in Edge uses the underlying DLLs, etc. that make up the Trident engine. That's not going anywhere yet, it's just the standalone IE application that's being phased out. With that GPO option set, launching iexplore.exe results in a message box saying "This action is restricted. For more information, please contact your system administrator". There's just an OK button for that, which when clicked launches Edge. If you don't have Edge, I guess it just won't launch Edge after not launching IE.
  13. Disabled by GPO here (the "Disable Internet Explorer 11 as a standalone browser" option), with an enterprise mode site list set up for the one thing that we need that for (CCTV dash). The June CU doesn't do anything to IE, I don't think. You'd still be able to launch IE it's just that it's not supported any longer. It will get removed by an update later this year, I suspect, although the MS article about suggested that it wasn't going to be done via Windows Update, so ¯\_(ツ)_/¯
  14. I think people get sent a download link via email, as there is more than one flavour.
  15. Trying it on a couple of off-domain servers first. One hosts backups and the other is a Hyper-V server hosting one of our DCs away from the main cluster. Will check that Hyper-V is happy on there first before updating that DC. Then the cluster after that.
  16. I think the inetcpl dialogue exists separately from the IE desktop application. It's part of the Control Panel and governs the user's system proxy, as I understand it. Third-party browsers take their proxy settings from it. Firefox, for instance, when set to "Use system proxy settings", will use those in inetcpl. Chrome used to have similar options as Firefox back in the day, but now just seems to use the system proxy, without any option for the user to specify one manually within Chrome itself.
  17. Assuming we're talking about a website that requires TLS 1.2, as long as TLS 1.2. is enabled on the client (which I assume it is these days on Windows), Chrome will just use it.
  18. Step 4 of your instructions is meant to take you from Chrome to the "Internet Properties" Control Panel dialogue (same as just running inetcpl.cpl from your Start menu), such that step 5 is happening in inetcpl.cpl. These days, opening proxy settings from Chrome is probably going to take you to the new Windows Settings app instead, which I don't think gives you the protocol options you're after. You should therefore run inetcpl.cpl, go to the Advanced tab and scroll down to the bottom for the TLS tickboxes. I'd be somewhat surprised if don't already have TLS 1.2 enabled, though. Support for TLS 1.0 and 1.1 was depricated from Chrome a few years ago now, and disabling them both for Windows clients is recommended.
  19. Do the page-zoom keyboard shortcuts work? That might bring required page elements into view.
  20. One bugbear I've found with using Power Automate for an approval process is that a workflow will fail if left awaiting approval for too many days. I want to say 30 days? You might therefore want to design your workflow with that in mind, perhaps including a timer in it which will automatically cancel a request if not approved within 10 days or something. That way, if an approver allows something to lapse, there can be a notification back to the requester to have another go.
  21. We usually have fewer than half a dozen each year asking. They're nice enough about it and understand that it's done as a favour. I don't mind.
  22. I reckon that's HTTPS inspection upsetting the software's connection. If you're able to exempt the application/user from HTTPS inspection you'll probably find that it works. How/if you're going to do that would be an exercise for the reader, as it'll rub up against your environment and policies. Your Senso rules for that particular flavour of E-Marker 2 will be doing the same thing as the AppLocker rules I posted earlier, I suspect.
  23. Regarding having Google APIs operating on an allowlist basis, I'd previously assumed that that couldn't be applied to the basic sign-in scope, just the beefier API scopes covering apps, but I now see that the sign-in scope (i.e. the "Sign in with Google" mechanic that websites might offer) can actually be set to allowlist posture as well. I think I must have missed when that was updated. It's also annoying that new API scopes for Workspace apps default to unrestricted. The recent migration from Hangouts to Chat left the Chat API unrestricted, for instance. Had a similar thing with Classroom API in the past as well. It definitely seems like you have to review all these settings regularly to combat Google's penchant for very permissive defaults.
  24. Infinite loops spawning notepad, calc, etc. which then leads to host machines getting a hard reboot in order to become usable again. If that happens in a VM it doesn't bring the host down. That's the daft end of things, but then we also had kids bringing in and running whatever L334-HaXoR-looking python code they were finding on the web for things like chat apps, which we weren't keen on. Edit: the whole "sandbox or no sandbox" debate has been had before RE: Python, more than once, so I'll just end with a ¯\_(ツ)_/¯ on that point.
×
×
  • Create New...