PyROm
Members-
Posts
661 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PyROm
-
Doh! Found a way around it. By removing the students stream licenses they cant look at videos on stream. When a video is auto posted to a team, the students can see the thumbmail, but when they click to view it they get the loading cicle going around forever.
-
Starting the meeting through calendar is slightly better, still not usable for us though. This time when you stop recording it saves the file to stream, gives all attendees view permission (although not owner this time) and puts a link to the video into meeting chat.
-
Our headteacher wishes all lessons taking place with students to be recorded (this has to be started manually by the presenter from what I understand), however they do not want the students having access to the recording. The problem is that by default meeting recordings are saved to Stream and the permissions are set to allow anyone that was in the meeting to view it (it seems to actually set them as owners as well) and it posts the video to the Teams channel. I know teachers can go in and change it afterwards, however they wont consider racing to change the permissions on a video secure. Does anyone know a way to change this?
-
Could you send a command to them to change setting in registry? I know our antivirus for example can be used to run a command remotely and even when external pc's still check in with av server.
-
We have wsus set to not cache files locally meaning updates are still controlled by wsus but download from microsofts servers. We added the dns name of our wsus server to our external dns and opened up the wsus port to the internet.
-
I think you are creating local mailboxes first, then moving them to the cloud because they dont properly link with your AD accounts if you dont? The way around this is to set the remote routing address in AD, this way your create the AD user, set the remote routing address to your tenants mail address e.g. [email protected] (we use powershell) and assign licenses. When the user logs into exchange online it creates their mailbox for them and it is properly tied to their ad account.
-
If you have no on premises mailboxes you can use exchange server 2016 for free without licensing (it auto licenses itself when setting up hybrid). Exchange 2019 is not free though.
-
I just installed it locally on my machine, then copied the installed files to a network share and put a shortcut on the desktop, you could also just create a bat to copy it to their program files I believe.
-
Assuming that the user has access to certificates manager on both their domain account and local laptop account, and the certificate is marked as exportable on the CA, run certmgr.msc, find the certificate under personal->Certificates, right click, all tasks, export... follow the wizard. To import, just double click the file and follow the wizard. This is assuming that you are using Always on VPN in user mode and not machine tunnels. If the end user can do all this, then I see no reason why they couldn't also add their own personal IT kit to your VPN, might be something to watch out for.
-
Ive seen it before where user certificates just disappear. Normally I would tell them to bring their laptop into school and reboot it/login so that it grabs new certificate. Obviously this isnt really ideal at the moment. If the dc with the CA as a valid fqdn you can make external.... you could update you domains external dns to contain your dc (so somputers on the internet can find it) and allow access to incoming traffic to your dc's certificate services, that way the laptop should be able to grab a new certificate. I dont know how secure this method is, but being a ca I would hope ms made it secure, of course oncevthe laptop had certificate you could close the firewall again.
-
as another thought, if your adding it to the machine rather then the user, you need to run the script as service. Grab psexec from sysinternals and prefix your command to run your script with psexec -i -s
-
As your adding the vpn to the users profile, doing it in an elevated command prompt will install it for administrator. Have a look at https://www.google.com/amp/s/directaccess.richardhicks.com/2018/03/12/deleting-an-always-on-vpn-device-tunnel/amp/ to delete existing connection before readding it. As another thought, if you use certificates to authenticate do you all vpn users have access to your certificate server when at home (ie. Over vpn) so it can auto renew? If not it could be an expired certificate.
-
Classic shell got taken up by another group when development stopped. Open shell is current and maintained.
-
You can turn local storage off on wsus, so that it lets you control updates but the machines grab them from Microsoft update directly, its on the wsus mmc, update files and languages page.
-
I am looking at this again using Microsoft update servers (so wufb) is there any way to permanently block feature updates? ie. I roll out an image with 1909 on, which should be good for 3 years, I dont want it to auto update itself to 2004 (or whatever the new number is) when that comes out. I have seen the defer for 365 days, but this is not much use if it is 3 years.
-
Am I right in thinking device health is now part of Desktop Analytics, so needs A3 license or above to use?
-
\\\sysvol\\Policies\PolicyDefinitions
- 33 replies
-
- 1
-
-
- default apps
- photo viewer
-
(and 2 more)
Tagged with:
-
I believe the v1910 switch was a re-branded 3com switch form when HP brought them out.
-
We have smoothwall route our wifi guest network here. You do not need IP helpers setup if your aim is to keep your networks seperate. On your zone director set it so your ssid is tagged to a vlan, set that vlan as tagged on all your switches (and relevent ports) back to smoothwall. On your smoothwall, on the network interface the traffic is coming in on, create a new vlan interface (Network->Interfaces). You will need to use a different subnet for your guest network so that smoothwall (or any other network kit) knows what network you are talking to, for example if your main network is 192.168.0.0/255.255.255.0 you could use 192.168.1.0/255.255.255.0 as your guest network subnet. I would use the smoothwalls dhcp and dns servers to provide those functions on your subnet (you have to enable them for the vlan and set them up).
-
We used to run with only linux servers here back in the windows 98 days, when XP came out we setup a server 2003 (I think) machine to handle AD and GPO as Samba hadn't got that functionality yet, however everything else remained linux (fileserver/dhcp/dns/printing etc). We carried on like this until 5 years ago when we got a new head. The new head wanted all windows machines as she said they were easier to use as everything had a checkbox (I find it ironic now the shift to server core and powershell) so we switched everything over. We do have a couple of small linux servers for running the library system, VPN, unifi video and wifi. I would not want to try and put linux on the desktop for student use though, very hard to make it so they cant mess up their profiles.
-
We originally took the view it was fine to show registers, however the school signed up for counties DPO/GDPR service and when they came round we were told it is not ok to show registers on the board in case it reveals pre-populated absence information or any other student information such as SEN and PP. Also we were told we had to run all displays in extended mode rather then duplicate mode to prevent anything such as emails appearing on the whiteboard by accident. Their view was that every child has a camera in their pocket (phone) and it only takes them a second to photograph the board and share it on facebook/instagram etc.
-
We use PTC ProDesktop 8.0 for 3D stuff (replaced with proengineer now but too complicated) and 2D Design. We have just updated to TS Design v3 which has a lot of improvements (eg. multiple undo`s). For laser cutting we design in 2D Design then export as dxf and import into laser cut/easy cut (same program different logos). We ran solidworks for a while but the teachers found it too complicated.
-
windows 10 1909 internet detection
PyROm replied to maark's topic in Internet Related/Filtering/Firewall
Just came across this today as rolling out 1909. We use smoothwall and although msftconnecttest.com is whitelisted it needed exempting from authentication as well. -
Thanks for the replies, I will switch to allowing WSUS through the VPN. I dont really want to allow them to connect to MU for downloads, as when in school I could have 60 laptops simultaneously trying to download updates over the internet. At least very few will use them at home so less people trying to grab updates.
-
I was wondering if people allow school owned laptops, which connect over VPN, to grab updates off their WSUS server. I`m in two minds, blocking them from getting updates over VPN saves a lot of bandwidth (were stuck on 100mb internet connection at the moment) and they should be bringing their laptop in every day, at which point it will get updates. However over the 6 weeks holiday they wont get any updates for 6 weeks, so might be better allowing them access and suffering the slower connection.
