m0bov
Members-
Posts
146 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by m0bov
-
Hi all. We want to allow certain teachers to change student passwords using the admin center. I have used co pilot to help me set this up. I have created an AU, popped a test student in there, then added a test teacher account to the Password role for that AU. When the test teacher logs in, they can see the student account, they can change the password. But it only changes it for Azure. We already use SSRP, so the write back is turned on. I have tested it again my own account, going into the azure user page for that account and changing the password, it does write back. But for some reason, when you do an "admin" change of a password, like from Azure console, it does'nt. The passwords go out of sync. Any ideas? I don't want the students to have to register for SSRP, likewise I don't want to have to put AD tools and MMC console onto teachers machines to change the password on AD! Its just a simple process I want for a few teachers to be able to hit the admin webpage and change student passwords. Co Pilot says SSRP is a differant route, hence its working, but what I am doing is a sort of admin password reset. It suggests the below, is this correct? On the Students OU: Open Active Directory Users and Computers Right-click OU → Delegate Control Add: 👉 Azure AD Connect service account Grant: ✅ Reset user passwords ✅ Force password change ✅ Write lockoutTime Thanks.
-
A good exam setup meeting latest audit requirements
m0bov posted a topic in Learning Network Manager
Hi guys, we already use our filtering to block everything except Office when used with exam accounts. However I'm being asked for some other requirements now. So every student gets an exam account along side their own regular account, this account (we are an Microsoft School) is allowed to use Office365 only and the usual local access to apps as a standard user. The exams have A1 licences so online only. The laptops are intuned. We need to ensure spell check is blocked, predictive text is blocked, a standard font is used and there is no e-mail access. Also no calculator. How has everyone else approached this? Any suggestions? Is it better to use some sort of portal for this or can we tailor out environment for this? Thanks. -
Sure: Ticket ID: #542202
-
It appears when a website hosted by Juniper does'nt display correct. It normally says something along the lines of "our team has been notified"....etc...
-
Also to add, we have 4 other sites hosted by Juniper, they all work fine. Accessing the troubled website externally, is fine. Thanks.
-
Hi all. So suddenly we have been getting the Juniper Oops!! error when going via our Smoothwall onprem proxy. We have Cname in place and had this checked. Our website uses the same address as our AD If I add an exception for the url in GPO(where the proxy is specified) its fine. If we use the cloud filter on a laptop, on a hotspot, its fine. But as soon as you connect it to our network, or remove the exception, or use the auto config option (pac) it stops working. I tried using our ISP DNS, even 8.8.8.8, same issue. We use LGFL (very kindly have been helping us) Juniper said its an internal issue and can't help further Smoothwall say its not blocked, they have added exclusions, I ran a realtime log viewer and its not blocked, but still the issue remains. Any ideas? I have a test VM workstation I have been testing with. We also recently had a line upgrade with a new router and firewall. Thanks.
-
Can it pull photos from SIMS? Or is there another method? Thanks.
-
Hi all, what are other schools using for a badge printing system? This will be badges for staff and students, with their photo from MIS and coded with their UID from AD. Ideally, we just want a service were its all fully integrated (click and print). Some ad hoc printing during the year, otherwise bulk printing each September. Also "talks" to our Paxton and Inventry. Any suggestions? Cards then arrive in the post. Or, failing that, is an onprem printer a better solution? Ours is REALLY old! Thanks.
-
Hi, no error message if I try that.
-
Hi all, whilst troubleshooting something else, we noticed on our current and newly installed machines we are getting Netlogon 5719 errors when the PC is started up. We have tried the following: Restarting netlogon after log in, get the error pinging our two DCs, all ok nslookup of the FQDNs all ok Full windows up Used AI to troubleshoot, disabled the credential guard via the registry Ran test-computersecurechannel came up true Reset the channel, true Did verbose no errors klist, shows tickets Checked SPNs, no issues time sync ok Checked I had KB5055523 Took PC off domain and re attached, same error PC is getting GPOs and logging in ok No errors on the DCs. Enabled netlogon log, found but not sure if this is a real fault or not. I can ping the domain. Any ideas???? NlSessionSetup: Denied access as we could not authenticate with Kerberos 0xC002002E ... NlSessionSetup: Denied access as we could not authenticate with Kerberos (translated status) 0xC00000E5 ... Eventlog: 5719 (1) "**domain-name**" 0xc00000e5
-
Hi all, like many schools we are updating our general AUP to include AI in it. So far I am aware of some obvious things like... Don't share any photos of students or staff, personal details of school employees, students or any details of the school such as its name. Use Co-pilot, do not use Gemini and if using ChatGPT, select the option to not share data. Anything else I can use? I've not really used AI myself so on a learning curve with this one. Thanks. P.S I could use AI to help me?!
-
Thanks for all the info guys. We have been mailing them all, but not a single company every replies, literary complete radio silence. Mailpace looked good, but no response from them at all!
-
We can go direct to them, yes. We don't really want to be running any onprem services. Thanks.
-
We use Twilio for our virtual parents evenings and I think sendgrid is part of it. I have tried contact them with no response as we need to pay in GBP and for a year. Is this how you pay?
-
Hi all, we have been using Office 365 for our outgoing e-mails from apps like Edulink. But as some might know, they limit the messages per minute and the size of the mailbox. Does anyone have any recommendations on a good SMTP provider? One that won't keep getting black listed??? Thanks.
-
Looking at Starwinds conversion tool, it looks like a no brainer to me. I can shutdown all the VMs expect the vcentre. I can flatten the second host, Hyper V it, then do a conversion from VMware to Hyper V. First up the servers on the Hyper V host, check and if happy, flatten the first host with Hyper V. Then "balance" everything out. The VMs are running file level backups from the Redstor client within the VM so I just let everything continue to run as normal. I will need Starwind to setup their VSan servers of course.
-
That's interesting, we do in fact, need to upgrade one of them anyway (still 2019), the others are 2022 but yes, we could do that!
-
No, the hosts would not be backed up, they are just purely a VM host.
-
Hi all, just trying to plan out a migration here. We have two hosts, running Starwind vSAN on ESXi. We want to switch to Hyper V on the hosts due to the crippling VMware costs. We use Redstor as a backup solution. Its been suggested we use Redstor to restore each VM back to the newly provisioned Hyper V host. Once they are all back on the Hyper V host, we can then wipe and reload the other host. My only concern is when it comes to Active Directory. The server needs to be running for the back, then we shut it down. Then we restore it to the other host but we need to make sure the other DCs are off. But if we power them up, the AD version will update? Or do we leave them running? I did look at creating a snapshot, cos you can do that when the server is powered off. Then convert it to Hyper V image??? A snapshot might be better than a file level backup/restore? Any suggestions? Thanks! James
-
Another thing, on the Intune device, I created a doc and called it test123, saved it. all ok. Then I noticed the autosave was then on. So it seems on a "on domain" device it will prompt for a filename before turning on autosave. But with Intune/cloud, it will only come on when the file is saved. My next question is, how can we prevent work being lost if they don't give it a filename or the machine crashes? The recovery location is still local storage (profile) which is not accessible. We do also use redirection for known folders to Onedrive. Thanks.
-
We just tested an "on domain" device, same user. We tried turning on auto save, it worked straight away. We can only assume the lack of auto save is why students are loosing work or struggling to find their work. Is there an issue with having Intune and locking out the local storage??
-
Hi all. We have a number of WIndows 11 laptops, they are intuned with device based policies, setup as shared devices with no local storage. These are setup with basic apps (inc Office 365). The issue we have is: When you log in, you have the built in Onedrive that works, you can go to word do open, save etc fine. But we noticed autosave is not on, it won't let you turn it on. There is no Onedrive icon in the system tray, students are use to looking in the system tray and double click on the blue cloud. Opening explorer, there is only downloads, no OneDrive in explorer, but it does in Word. They have A1Plus licenses When I log in as a student, if I turn on Autosave, it asks to log in with a button, it tries but hangs on loading accounts. When I log into Onedrive on the web, its asking for e-mail address, but the device should know the user. Its logging into our Azure. Any ideas?! How can we get auto save turned on and working? Thanks.
-
I think we sorted it, the login domains got changed back to the local AD, swapped them back their e-mail domain and seems to be all ok.
-
Hi, yes we have this as well. But its not set as the default username in Azure.
-
Hi all. We recently had to reinstalled our AADsync app and updated to the latest one with a clean install. I noticed at one of our domains (not the one the aadsync is running from) that although the user is created, their login name is the set to the tenant domain i.e. ommicrosoft.xxxxxx I'm having to go into Entra and change their username domain to match the local AD. I recall when we installed the old version of AADSYNC you "mapped" the local ad domain suffixes. It seemed to work ok, but now with the newer version its not. I found an option in Entra to log in with alternative email. Also in Entra ID there were some options, or is this something missing in the fresh AADSYNC installation? Thanks for any pointers!
