Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

jamesb

Members
  • Posts

    2,502
  • Joined

  • Last visited

Everything posted by jamesb

  1. I partly agree, although I'd give them the basics as a jumping off point. Research is all well and good, but if they've never heard of Active Directory it could be a long, frustrating and pointless search.
  2. No idea if this'll help you or not, but thought I'd answer from my own (non-school) perspective. Off-site warm room with fifty seats for 'essential' staff (definition of essential is somewhat controversial) in case of office incidents. For anything less than the building burning down our live network is provided by an MSP, mirrored between two data centers in different parts of the country. Bi-annually for security reviews on the live network, annually for our ISO 27001 audit. On the dev network (my area) security reviews are an ongoing process. Two, depending on which network you are on at the time. The live network policy is a lot more stringent than the dev network policy due to information sensitivity. They both essentially boil down to 'don't be a moron'. On dev we use Spiceworks to reduce the instances of iTunes and similar. On live no software can be installed, everything is provided by app streaming or browser so workstations are nothing more than terminals. Yup. We don't have it anywhere other than shared areas. Air conditioning breaking down in my case. Just recently I had a server burn out when the server room hit 90 degrees over the weekend. Less than 10%. It depends entirely on the role. Usually it's a case of hiring developers so generally the right experience on the CV. Speaking for myself if I were hiring an assistant I'd be more interested in general experience, adaptability and a demonstrated enthusiasm for the area. Me. Whatever's appropriate to their role and required by project, carried out by external training providers. No problem. I work with sensitive data, and I'm quite happy to tell people about any of our security practices (in fact twice a year I have to do so, as well as documenting them). If a little information about group policy is going to let someone break into my network I should really be looking for a new job rather than trying to keep them ignorant.
  3. On the DNS servers of each domain create a stub zone pointing to the other, with the start of authority as the corresponding DNS server. Other than that you'll need routing between the two. If you want to resolve the short name rather than fully qualified you'll also need to add the DNS suffices to the default search order on each machine (can be set through DHCP). Add a Stub Zone DHCP Search Options
  4. Easy to solve - just throw the waste onto a bonfire. Note: No one should ever do this. I miss my eyebrows.
  5. If you've got PowerShell then you could try this: Set up the 'root' folder with the permissions you want. Set up one subfolder manually with the permissions you want. Run the following in PowerShell: $acl = Get-Acl -Path C:\rootfolder\subfolder foreach ($subfolder in (Get-ChildItem -Path C:\rootfolder -Recurse | Where {$_.PSIsContainer})){ Set-Acl -Path $subfolder.FullName -AclObject $acl } That'll set all the subfolder permissions (for all subfolders, not just the first layer) to match the one you set manually. If you only want to affect the first layer, take out the -Recurse from Get-ChildItem.
  6. I can see from a personal matter exactly how much worse-off I am. Currently it's to the tune of about £400/month compared to last year, despite a reasonable pay rise through changing jobs. This is down to the wonderful tax policy changes. In fairness on the banquet front though, it was funded by a private company (the Corporation of London, possibly the oldest company in the world and almost certainly one of the richest) rather than the taxpayer. Not that a four-course banquet with gilded chairs is ever an appropriate place to talk about how we all need to tighten our belts. But hey, at least he didn't trash the place and do a runner.
  7. I'm confused. I'm sure I was using collaboration features in OWA on SharePoint a few years ago. Is this the O365 stuff instead?
  8. Absolutely no one. Unless you've paid out money to improve or repair the goods, in which case you may be able to get compensation from the owner for repairs. Actually that's not quite true - the person who sold the items to you (assuming you weren't aware they were stolen) would be the one who should compensate you. They've essentially fraudulently taken money from you, and would owe it back. Alternatively if you bought the goods with a credit card (and again, weren't aware of the theft) the card company should return the money to you. Citizens Advice - Stolen goods
  9. To give a different perspective (as in not education IT but development) we have: 1 network engineer (me), 24 workstations, 11 hypervisors, 20 client virtual machines and (currently, though it changes on a daily basis) 237 servers.
  10. That's the last thing I need. I like being away from the computer sometimes.
  11. Just want to say thanks again to everyone, and particularly to Dave. The volume is now rebuilding and I can drink my coffee in peace for a few minutes.
  12. Thanks to all. The crisis has now calmed down and thanks to Dave should be sorted early tomorrow morning. One week in and already suffering stress-related hair loss.
  13. Sadly, yes. Should have mentioned that first.
  14. Unfortunately not in this case, not compatible.
  15. Morning - had a slight problem with some of our older hardware and a failed SCSI disk. As this has some of our test machines, and we're in the middle of a test cycle I'm under a little pressure. Does anyone know somewhere in or near Croydon that I could pick up a 300GB (or bigger) 15000 rpm SCSI disk, or anywhere that would cover an urgent delivery (where urgent means as soon as possible so people stop shouting at me)?
  16. Excellent. Thank you.
  17. I'm giving myself a headache staring at license requirements and wondered if someone might have a nice, easy answer for me. My new job involves a complete revamp of the development platform, and the development network (currently all on the same hardware but that's about to change). As part of it I'd like to deploy System Center to manage both production servers, and development servers. Obviously it's fallen onto me to minimise license costs and this is where the headache starts. I'm planning to separate the current virtualisation cluster into two, one to run nothing but production VMs and the other to host all of the development labs. Since the dev labs are built and destroyed on demand, and are for development only, MSDN should cover them as far as I can tell. What I'd really like to know is how System Center interacts with MSDN licenses - i.e. if the hosts which the test labs sit on are purely for development purposes do I need a server management license for the underlying host or is this covered under MSDN? This makes quite a significant change to the bottom line, and if I need a management license for all of the processors being managed I'm going to need to revisit my design.
  18. Your best bet is to run a full profile sync, you can get to it via Central Admin. That should clear up any old details still in the profile store.
  19. Not so much just basic circuits - I'm still impressed by this one.
  20. I think the problem boils down to MPs giving equal weight to both sides in an argument. I'm reminded of talk shows where they deal with issues like 'Science vs Acupuncture', and representatives of both sides are allowed to talk equally - anecdotal evidence is equated with experimental evidence, and all in all it just validates woo. Scientific study is actually counter-intuitive - we've developed to believe anecdotes, and ascribe them weight, much more than to pore over reams of numbers. One good anecdote can completely destroy a scientific argument - a good example would be the anti-vaccination disgrace.
  21. This is what happens when politicians are liberal arts majors rather than actually learning something about science. The wealth of abused statistics that vomits forth from parliament is sickening, and this is just another demonstration of how little they actually understand.
  22. I'm going to go against the flow here, I know, but I like it. Since they started including a run box in the start menu I've never used the thing anyway - there's not a single program I can't access faster by typing it's name instead of hunting through menus. For the few where I want one-click access, I just pin them to the taskbar. As far as I'm concerned the new interface only got rid of an annoyance on the screen which I never used, and took up screen estate. The start screen on the other hand I can pin various useful tiles to (things I'm actually interested in) and get an at-a-glance check of my various e-mail accounts, media accounts, train schedules, latest news and so on. Not to mention being able to jump straight into playing a film on Netflix by starting to type the title and other useful little bits.
  23. I have no idea if this will work or not, but it might be worth a try. Go into AD and set to deny read access to the thumbnailPhoto attribute to the users you want it hidden from. I haven't got a setup to test this on these days, but in theory I think it should work as Outlook pulls the photo from AD under the current user's identity. Whether it'll have any strange side-effects I don't know.
  24. This gives details of how to delegate the Unlock Account right - How To Delegate the Unlock Account Right It's similar for all other delegation of rights over accounts. There are also various tools available which'll make it even easier for them. Setting minimum password age is detailed here, and means that a password cannot be changed until it has been used for the length of time set: Minimum password age: Security Configuration Editor; Security Services
×
×
  • Create New...