Jump to content

Martin48

Members
  • Posts

    39
  • Joined

  • Last visited

Everything posted by Martin48

  1. Thank you foofigher and dav, atleast I'm not going that insane, seemed to be so many choices in joining, deploying, and managing was wondering if I was missing something glaring. Our places are heading towards chromebooks as-well bar a few IT suites, staff devices going 1 to 1 except supply, looks like hydrid+group policy is best for shared, and for those few user facing policies, although agreed its not that many. I have found filtering (yesterday) which I may try out basically creating a shared device group and filtering them out of the already setup staff 1to1 policies and apps I have... having the casting app install itself on my test student device when a teacher logged in wasn't much fun but all part of testing, ironically I had been switching app deploys to user groups for 1to1 which I like as if someone requests something and replaces the device in the future it fully configures itself back, but comes with these niggles. Eventually we would like no local AD, but we are not even close to that yet so will worry about it in a few years.
  2. Dear all, Sorry if this has been asked but my tests keep confusing me! Say I want desktop backgrounds / homepages to be different between staff and students... Now I have a shared device (in a computer lab, 99% of the time students login, 1% of the time staff) Testing intune shared device managed / not on the domain, logging on as a user gives the first login setup screen and gets stuck on apps, have to re-login, or I can hide that screen, but I'm noticing the home page/desktop stays as the previous user, until the next sync which can take an hour... I cannot have this, atleast login is fast. Could try and fix the app issue (seems to be an issue removing an app what isn't even on) but its still like a 15 minute login until I had the screen, not very good in a classroom. Due to the above I'm settling on hydrid and group policy, but my existing intune staff configuration policies and assigned apps end up eventually getting applied on my shared test pc, do I start re-assigning all this to device groups instead of user groups? How are people managing shared devices and intune? Really for anyone doing it fully azure and intune as this would be my end goal. Thanks for any help/hints or advice! Regards Martin
  3. Thank you, I found the script what sets the serial numbers, our installer configured it at 1 site then it was forgotten about, I did ask on my support ticket how do I set serials but unfortunately your support still hasn't replied to anything since 8th December.
  4. Thank you, I have done this, trouble is when their is no mapping on the first site i setup the user ends up in "default users" likely as that site is seeing the user as exists but isn't in a mapped group, the mappings on the other sites are there-for ineffective.
  5. I have seperate smoothwall boxes and cloud settings for each site, each site syncs to its own cloud. But I have only 1 azure tenant for all 3 sites. So when I try to push the edge extension which doesn't ask which site its for, it is treating my user as a default user now I have removed the group mapping and I am trying to map that group from the other site, as I would prefer each team to manage their own sites staff.
  6. As in all the users from azure are being handled by the first smoothwall box, as its the same azure tenant for all 3 boxes their needs to be a way to filter the users so 1 box doesn't end up getting all the users. From what I see the edge smoothwall extension doesn't have anything to say which smoothwall box its for, so it must be comparing the email to known users?
  7. Dear all, Wondering if anyone knows this one as smoothwall support is absolutely awful, ticket open over a week and just 1 person who escalated then radio silence. I have multiple smoothwall appliances which sync to their own cloud portals, unfortunately I have 1 azure tenant. The first box I setup seems to have stolen all the users from azure, so when I removed 1 schools teachers they just became default users instead of being picked up by the other smoothwall which is fair enough. When I check the azureAD directory in advanced it has user and group filter option but no help on what to put here I would assume this will be needed but no reply from their support. Regards Martin Sykes
  8. Hi thanks for your feedback it doesn't say "plenty off" but does ask for "experience in troubleshooting" so yeah ideally they should have at least played with tech (not all tech!) and tried to solve their own problems, but will see who we get.
  9. We have a new opportunity to join our existing expanding IT support team at Sheffield Park Academy, for anyone interested in the role and entering or re-entering the field of IT Support. Apprentice IT Technician (current-vacancies.com)
  10. Barnsley Academy is seeking to appoint an IT Technician to join their established IT team. The academy is part of United Learning, a national group of schools and academies. IT Technician (dwp.gov.uk)
  11. We are delighted to advertise the post of Lead IT Technician to complement our Cluster IT Team which supports our United Learning academies across the South Yorkshire region. This vacancy will be based at Sheffield Springs Academy. Lead IT Technician - United Learning (current-vacancies.com)
  12. Teams client is single sign on with 1 extra click... luckily it remembers it, if the same machine is used again Mrbios technique works and saves about 500mb of ram, not that I'm saw what the client is a hog or anything.
  13. Yes if you are serious about going to teams and sharepoint yes... use office 365 Its alot faster saving directly online and crashes less. When working with onedrive client, office uploads first then lets the client download a copy, we found this important as the other way round files are saved locally but locked while office is open giving only a few seconds for onedrive to upload changes when people logoff, which ofcourse it fails to do.
  14. In fairness about the 72hours still applies don't not caring about your situation or holidays. Looking at the other end, neither do the perpertrators selling your data, and neither do the people whos leaked data is being exploited. GDPR is a pain in the ass but it is done for good reasons, hope the GPO/GPL roles are getting paid enough to get interupted in holidays.
  15. Confused by the question but suppliers wouldn't have to encrypt as the devices being supplied don't have any personal data on them at that time. (just os and apps) They would only have to encrypt if you asked them to as part of a service which they may charge for.
  16. We have them and they senior leadership are very strict about wearing them when ofted are in. Obviously cards confirm what everyone onsite is meant to be there and has been checked, visitors get different cards and different again if they don't have CRB. My pessimistic side would wonder, if you don't have them at all you can just say 'we dont use them' BUT if you start using them and someone is not wearing it, it could be a negative flag when inspected...
  17. I would worry about auto encrypting portable data drives, we force ours to read/only until encrypted as its vital what information leaving is encrypted, we get alot of users accidently encrypting then finding they cannot use on a mac then un-encrypting.
  18. I was horrified by the title, but then actually liked your project / idea and implementation well done, would probably be useful here and mroe secure then a generic supply account for example...
  19. I really hope he did a proper professional wipe and didn't just hit delete or quick format. Personally I prefer the drill but suppose can't sell that at 2p per gb.
  20. Flagged this up recently as something what needs looking at, currently we are insisting on password protected zip figuring that encrypts the data and is more universally readable then encrypted disk.
  21. You can actually block the powershell exe's with applocker and stop scripts from running just as you can with cscript and wscript, however yes I take your point as if you are worried about python you can also just use the vbscript within any office document.
  22. Originally I set python on a vm on virtual box, got a few issues with service not starting on boot, but worked for the year. Then we took another school what already had python in use, re-looked in to this and decided a computer program cannot do anymore then the user permissions it runs under (so setup security properly in the first place), that being said it can do it fast so it can do brute forcing, guesing passwords, and also network communication. For this reason we got our software firewall to specifically block python and pythonw, and we setup a security group "student programmers" and only allowed applocker to run that for all staff and students in that group, allowing us to block it for bored 6th formers not doing IT and any student who posses a risk for anything. We have notifications for the brute forcing.
  23. Most have 10 (or lifetime which is equivalent of 10) they come with 5 you can get them to quote for 10 but be prepared for a price shock. Edit: I think they are new to the education market they are very competitive and from the back-end infrastructure are probably not ready yet for education pots of money what come and go and the need to keep stuff going as long as possible and to not replace so regularly, they will probably revise this at some point..
  24. They compared good when we looked at them until we looked at support and warranty up until 10 years.
  25. Martin48

    SMB on 10.7.5

    fs side thank you wondered why scan to folder dropped on a new mfd, i bet this is same reason disabling smb1 this morning...
×
×
  • Create New...