Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Primus

Members
  • Posts

    2,232
  • Joined

Everything posted by Primus

  1. Interesting - so 1 site the update worked and caused no issues - I am seeing event ID 39 in the logs. At another site the update borked RADIUS as others are seeing and I see event ID 6273. I've temporarily removed the May update for now but need at least a medium term solution that allows the update to happen and then a longer term plan for what needs to be done to comply with their new enhanced requirements for certs.
  2. Ok, just checked we have the warnings in event viewer. The Key Distribution Center (KDC) encountered a user certificate that was valid but could not be mapped to a user in a secure way (such as via explicit mapping, key trust mapping, or a SID). Such certificates should either be replaced or mapped directly to the user via explicit mapping. See https://go.microsoft.com/fwlink/?linkid=2189925 to learn more.
  3. I've installed the May update on the DCs at one site and so far no issues with our RADIUS secured using smartcard or other cert, though I do need to check the logs for the identified events.
  4. We're in the North East so only posting in case you don't get any responses and need to cast your net further.
  5. Has anyone installed them and not had issues? - I'm wary of Microsoft's "may".
  6. Wouldn't that be a bit like disabling alt-tab?
  7. Please can we have an update this is honestly getting daft now - we should be a model of good practice - not using HTTPS in 2022 is ridiculous.
  8. Is there any update on this? @ZeroHour
  9. In my current case I'm fortunate to have leaders that will listen to experts - at least most of the time. But some of it's how you engage with them. Educating them, little and often. Sending them snippets of articles, referencing ransomware in conversations about hardware refresh: "This is why replacing these PCs before 2025 is so important so that we can move to Windows 11 so we still get security updates - if we get stuck on Windows 10 we'll get no further security updates making ransomware more likely." Gentle reminders about data protection requiring us to take "all reasonable steps" - when they propose something that isn't reasonable flagging it. Involving outside trusted opinions to back up what you're saying. Getting certifications and qualifications yourself to give yourself some weight behind your points (this is more difficult but there are some qualifications that sound good and are easy to get - eg. Microsoft Innovative Educator, Google Certified Educator/Trainer [a bit less easy but still not that tough] etc.)
  10. It's not like that everywhere...
  11. It does and it doesn't - LTSC is not intended for use with general purpose computers, all you're doing is prolonging the inevitable. Whilst I'm not thrilled about having to replace so much equipment before October 2025 I now see it as an opportunity and there is sufficient time to spread the cost to ease the financial burden somewhat. We've worked hard with our schools to teach them that one off spends on IT are unsustainable - everything requires replacement at some point so this has to be considered on purchase and then as part of annual budgets.
  12. I was just thinking about the original the other day, I can't wait for this.
  13. You'll need to resolve that.
  14. For what reason - can you see from the headers what's causing the junk filtering? Have you checked your SPF record is now compliant as when I did it for us I had to alter it as their default settings led to the SPF record becoming invalid.
  15. But it's being sent from your domain so it's following the settings you apply to that domain. If you haven't put in place DMARC then it won't be failing because of DMARC but you really should consider using it.
  16. Or just follow the helpdesk article - it's actually really easy to switch to iDex
  17. One or two might die randomly without any reason - when it's multiple I'd be looking into it as there must be a reason behind it. As I say, we've used it extensively for years now and it's been rock solid - that said we use both their APs and edge switches so that might account for some of it but for the first year we ran the APs off HP switches and it was still fine. We've had 1 AP die in that time and that was someone pouring water over the floor above (don't ask).
  18. Fair but at the moment it sounds like they're not (yet at least) and they have issues.
  19. If you're having issues with Unifi would it not be better to get someone in to look at it as many schools use it (we certainly do) with no issues. Would be more cost effective than spending £100k on a new WiFi setup - I've always thought I had expensive tastes when it came to equipment but £100k is steep!
  20. I've done multiple schools and it was always on the morning of upload day.
  21. You tend to get them on the morning of upload day.
  22. The issue we've found with an FTTC backup is the upload speed, we max it out so quickly the connection comes to a halt. We end up having to shape traffic very aggressively so that our SIP lines still work, our new tender doesn't allow for FTTC as a resilient connection in anything other than a primary and even then it's not ideal.
  23. The tender we've just put out for our MAT broadband has every school with a resilient connection - including the primaries.
  24. I think that's an interpretation some might take, I don't think it's an interpretation that DfE intended but that's my personal opinion.
  25. This is a bit of a nightmare for us, we use the old extension for staff only to prevent us filtering staff on their personal Chromebook offsite - yes I know they'd still have to log in with their school account to be filtered and we were going to address it at some point but sudden loss of functionality is a pain.
×
×
  • Create New...