Jump to content

jthompson

Members
  • Posts

    5,685
  • Joined

  • Last visited

Everything posted by jthompson

  1. My OH and I had different words today.
  2. One of my pet hates is clocks which are meant to automatically adjust, but don't, leaving you with no option to manually set it. My previous car was meant to pick up the correct time through DAB or whatever, but usually didn't. Maddening.
  3. Our school uses Facebook and Instagram. Responsibility for managing the accounts is formalised as part of somebody's role. Not left to IT, thankfully. Personally, I'm of the opinion that we shouldn't be touching these things with a bargepole, but then I'm not in posession of a 'normal' attitude to social media and big tech. The truth is that the people schools need to reach are already normalised to using those platforms and expecting organisations to have presence on them, so you kinda have to engage with it to some degree.
  4. That's what we do, too. That would also help to tidy up existing users on Google by sorting them into their respective OUs. Just make sure to remind yourself to add new search rules at the start of each academic year to account for new cohorts.
  5. That's what we do, yes. In the GCDS config, the groups search rule is just looking at the AD OU containing the groups we want synced to Google. All our other AD groups are going to be outside of that scope. If you have existing Google Groups that you don't want GCDS interfering with (i.e. you want to keep them, continue to manually manage them on Google and not sync them from AD at all), then you can specifiy exclusion rules for those in GCDS under 'Google Domain Configuration -> Exclusion Rules'. GCDS will delete any Google groups that aren't matched from AD and aren't covered by such an exclusion rule. The 'Classroom Teachers' Google group is a special case and won't get affected by GCDS in any case. You can just add suitable staff groups as members of that group and leave it be.
  6. Not sure about GMT all year round. Wouldnt that mean that the sun would come up stupidly early and summer evenings would be noticeably darker? Wouldn't having BST through winter be better than having GMT through summer? tbh the annoyance of adjusting clocks is probably trumped several times over by pragmatic arguments for safer roads and lower energy consumption when keeping DST. DST is less of a benefit at lower lattitudes, I suspect.
  7. 2) Our Google groups are primarily there are email groups. We therefore maintain a dedicated set of groups in AD specifically for syncing to Google. That is, those AD groups serve no other purpose in AD and are purely there for management of Google groups. We have them in a dedicated OU in AD, separate from all our other AD security groups that we use for Windows stuff. GCDS is then configured to just sync the groups that it finds in that OU. 3) If your 'extensionAttribute1' is where you have the email address that you want to use as a user's main Google address (i.e. what you're wanting to use to match AD accounts to Google accounts), then you can tell GCDS to use that instead of the 'mail' attribute from AD. In the 'User Accounts' section of your GCDS config, you'd change the 'Email Address Attribute' field from mail to extensionattribute1. GCDS also keeps account of objectGUID from AD as well. That's there so that GCDS can update primary addresses of Google accounts when the email address attribute of an AD object gets changed (e.g. when someone changes their name and needs their email address altering).
  8. I get why our oven has a clock on it, because you can set it to start or end cooking at a particular time of day, but I've no idea why they put clocks on microwaves. If I could make our microwave not display the time of day, I would: it drifts a lot and power cuts are a thing.
  9. For a backup option I would have thought a starting point would be a 4G/5G dongle with a suitable SIM. Something with a low monthly cost but with enough data allowance to cover the absolute essentials during an outage (e.g. MIS functions, phones, email). If you're wanting something to give redundancy for everyone's regular connectivity in a 1:1 environment, then that's obviously a different thing.
  10. The dog is undeniably lovely, but that owl is mesmerising.
  11. I seem to remember doing this at one stage by using AutoHotKey. A GPO that took care of deploying AHK to computers, and then another that runs an AHK script at user login. When running, the script would capture Win+Tab, Win+Ctrl+D, etc. keystrokes and just perform an Alt+Tab instead. IIRC you can configure it so that AHK runs silently without any visible systray icon. Don't have that in place at the moment, but I'm almost certain that it all worked well.
  12. Yep, cables ties. There's a bit of a dark art to judging just how much reach to allow on keyboard and mouse cables. Enough to avoid children feeling as though they have to pull on them at all, but not so much that they can be placed in front of neighbouring machines or hang off the front of the desk too much. Err on the side of longer, and remember to allow for left and right-handed use. We usually use one small cable tie each for the mouse an keyboard to bundle the excess, and then a beefier cable tie fed through those loops to secure them to the power lead and/or base. If it's an AIO, allow enough slack on the plug end to accomodate the full range of any height and angle adjustments. As ever with cable ties, take pains to not leave any lying around for children to do silly things with. Because they will.
  13. Education Standard would let you play with that.
  14. We did use to prevent the Start menu search function from working by blocking it with AppLocker, but I'm not sure that's viable any longer. The Start menu search functionality used to just be handled by the Cortana app, so blocking that app with AppLocker was a slightly cludgy way to close this sort of thing off, but I believe the Start menu search functions are now handled directly by Explorer itself. Your next steps will probably depend on the specifics of what you're rrying to combat. If it's a problem with people running random software from within AppData, you should be able to cover that off with AppLocker, whilst still allowing for the likes of Teams which I believe need to be run from there as well.
  15. Have a look at https://apps.google.com/supportwidget/articlehome?hl=en&article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fanswer%2F9275380%3Fhl%3Den&product_context=9275380&product_name=UnuFlow&trigger_context=a You won't be able to do the time of day restriction. You'll be able to create rules to restrict to access from your school's IP (setting an IP subnet condition) and you'll be able to say that a company-owned device is required. I don't think you can go as granular as a specified subset of your company-owned devices, however.
  16. I guess it depends on how many pupils this would need to apply to, and how dynamic that list is going to be. If it's only a few and changing very rarely, then keeping it all within a single routing rule is probably the most KISS approach. RE: students removing themselves from groups, there is a way to make a group unleavable. I don't think it's presented in the Admin or Groups GUI, though, but it's in the API and available to set using GAM. That won't affect the ability of GCDS or groups admins to manage group memberships as normal, it just prevents vanilla members from removing themselves. gam update group [email protected] who_can_leave_group none_can_leave
  17. I'm wondering if the 'Group membership' option here might work. Create a Google Group specifically just to contain those pupils to which a sending ban would need to be applied, and specify that group here in the routing rule. Pupils would then just need to be added and removed from the group as needed, and the routing rule would not need to be edited each time a change is needed. If that works, it's easier for long-term management of pupils' bans. Also, if pupils have any aliases on their account that they can send from, that would probably be covered automatically as well, without having to account for any of those in a pattern match rule. I had wondered whether using an address list might work as well, but I think those match on senders for incoming mail, and recipients for outgoing mail, so wouldn't be of use in this case.
  18. Another take on it might be to have a QR code (or a friendly URL) on the wall that links them to a publicly available page containing your onboarding instructions, with directions to get a passcode from reception, or whatever.
  19. Yep, Edge or Chrome profiles are built for exactly this.
  20. This might be another useful one to bookmark - https://gamcheatsheet.com/GAM%20Cheat%20Sheet%20A3.pdf In terms of finding out the required course ID, if you have the security investigation tool in Google Admin (requires one of the paid-for tiers, iirc) then you can leverage that to get at a course id as well. Generally, though, I tend to do what @RLR has suggested with the gam command. If you're using gam in Google Cloud Shell, then gam print courses teacher [email][email protected][/email] > classesTheTeacher.csv followed by cat classesTheTeacher.csv to view the output. It's pretty ugly to read like that, so downloading the csv file from Cloud Shell (three pips -> download -> type name of file) and opening it in a spreadsheet app should make it easier to pick out the right id to use. Probably worth also deleting the csv from Cloud Shell as well, to avoid crap building up over time. rm classesTheTeacher.csv
  21. This thread has prompted me to update our admx templates for both Chrome and Edge. Quite a few new options appearing for Edge since I last did it. In particular New Tab Page 'content' (i.e. news) and MS rewards 'experience' cruft.
  22. Rename a Chrome browser window so that custom text is shown for it in the Windows taskbar, rather than the active page name - Three pips -> More tools -> Name window.... For example, a window that would ordinarily have a name of "Wordle - The New York Times" could be named as "Daily Tasks".
  23. Do you currently use GCDS and GSPS to sync Google users and passwords from Active Directory? If so, you'll be able to sync Azure AD with your AD, too, such that the same users accounts and passwords are then present in 365. You can have both your Google and 365 domains using the same domain name. Mail routing gets a bit complicated if you're wanting emails delivered to Google for some users but 365 for others, but it can all be done.
  24. That would be my suggestion, too. If you have existing GPOs for Chrome, just pick your way through and replicate as much as you need into the Edge templates. The templates are super similar - even things like extension whitelising are laid out in the same way. One thing I can't remember is whether you first need to install the admx templates for Edge like you would need to do with Chrome. I suspect you do, so once you've done that, just read through all the available settings and consider what you'll need to be configuring for either computers or users. Some settings that you probably want to ensure that have you set in Computer configuration/Policies/Administrative Templates/Microsoft Edge for all computers are: "Allow surf game", "Hide the First-run experience and splash screen" and "Send required and optional diagnostic data about browser usage". The surf game being the equivalent of Chrome's dinosaur game.
  25. I'm going to hypothesise that driving an executive German saloon car is a very strong predictor of poor observance of social distancing rules. I think an Ig Nobel is a nailed on cert for that.
×
×
  • Create New...