Jump to content

Planehazza

Members
  • Posts

    325
  • Joined

  • Last visited

Everything posted by Planehazza

  1. Yep I questioned this too. Favourite dog and fruit encapsulating/acting as their username/pw is not MFA...
  2. Anyone having problems with RollCall iOS app? Can't sign in. Type in users email, check the privacy policy agreement then tap send secure access link and it just errors with "sign in details incorrect. Please check and try again". It never even asks for PIN or password, I really hope Inventry start loosing custom so they sort their s**t out. I'm so done with them and, infact, we will be done with them from December.
  3. Wish us luck, send flower to my funeral... We've turned a blind eye to iPad student internet tracking for too long. Yes, they've been filtered and tied to 1:1 pseudo accounts, but after I reminded them we were averaging 1.5 alerts per day across the trust and we had no way of tracking who was using any of the 600 iPads, our hand was forced and I've implemented Shared iPad mode, federated against Google. Some staff are very unhappy that it's too hard, but we just have to use Safeguarding to quieten them again. Anyone else been in this position? Teachers spouting safeguarding left, right, and centre, but heaven forbid they have to teach kids IT skills in an IT lesson, using a very simple user guide I created for them...
  4. I guess another way to think of it is you're more likely to get backing from money people to ditch them now.
  5. Oh I don't know real pain. I thought I did, but we're rolling out shared iPad mode across the whole trust, including KS1. Wish me luck. Drinking at work in schools is generally frowned upon, right? Just checking... 😂
  6. Another bump to this but cloudwise are no more I believe, or were bought out or something. I'm in the process of implement Clever at our trust, employing the SSO feature for QR badge logins for KS1 and KS2, which is all free now. It's the MFA you now pay for and it's actually not too pricey.
  7. Honestly it depends on who installs it. We've got it in 8 schools and every install is different. Good luck getting them all consistent, especially if you have more than one domain. Their product was all the rage 5 years ago, but now it's overly complicated and their support is abysmal.
  8. We're going through procurement process in Q4 so I can ask, but I suspect you'll have an answer by then.
  9. Thanks Ben, and for just validating how I feel with this. It's nuts. I'm already a but miffed with these iPads, as we're rolling out Shared iPad for ALL devices, including KS1. It was my idea as we've no other way of keeping them compliant with KCSIE without relying on teachers to keep track etc. They're going to hate them and me, but we've reminded them how dangerous these are when I've showed them we've averaged an alert a day on the current system, and we don't know who uses which device currently... I'm anxious, but content in my choice. OK, so if you'd be so kind, please hear me out... I can have a single default policy that applies to all the names them say iPad-{{serialnumber}} then add the devices to the Site1-iPad All/Site 2 - iPad Students etc groups to which another policy is set with a different template? Them having Site1 etc in the name isn't crucial; what's crucial is easy, quick software to hardware identification for group assignment. Being shared mode, I can't simply enter a pin to go to Settings > General > about and the serial on the back is tiny. Of course this begs the question of asset management - why don't they have tags on them etc. That's another resource/time question...
  10. Yep, ipads. I wonder if I've just misunderstood these enrolment policies then. I thought they applied at enrolment and only then? Surely I don't need to have multiple policies for each batch? It's going to be a lot overhead. I have got 600 devices linked in Intune to ASM. Really don't fancy manually assigning a policy one by one. Ans if these policies override names every time ASM and Intune sync, what is the point in a device rename feature MDM side? Or is there a way to remove enrolled devices from the scope of the enrollment profile once they're on boarded? Sorry I'm either just not understanding something here or this is pure madness?
  11. Yep, we're not currently enrolling any devices and yet the number is now 25 devices. Why is the naming template on the enrolment profile renaming previously enrolled devices? This is madness, and is going to make it mental to manage the devices. I wonder if I need to set up separate sites per school in ASM then have a token for each so I can have different enrolment polices per site. What a nightmare this is, total garbage
  12. Feel like I'm going crazy, but i'm 99% sure the enrolment polict that sets the device name at enrolment is renaming previously enroled devices. I thought I saw it happen at the last school and figured I'd bulk renamed the wrong group. Now at the second site, different site prefix and I'm seeing 20 devices checked in with the new prefix. We've only enrolled 14! Why's it doing this?
  13. I thought about those but the issue I'm having (compounded by the fact we're reluctantly enforcing shared iPad mode KS1 through KS4 and staff) is I'm struggling to find a way to name them in bulk quickly and easily. I'm hacving to go through 600 iPads to wipe and enrol to Intune and am doing it as methodically as I can to leverage enrolment policy naming templates, but it's hit and miss and something has gone and renamed previously enrolled devices too 🤦
  14. Deploying apps is tedious. We have 8 schools using ~600 ipads, and each school requests different apps, blah blah. I have the iPads in nest groups, ie Trust All iPads > School All iPads > School Student iPads > School KS1 iPads Trust All iPads > School All iPads > School Student iPads > School KS2 iPads etc## This way I can block Safari etc. and trust level, or ban settings at staff/student levels once. I've got quite nice targeting options. Deploying an app to KS1 iPads at school 1, then KS2 iPads and schools 2 and 3 etc, is going to take a lot of time especially if we have nearly 100 apps etc. Do you guys take a similar approach to SCCM? Have a group for each app then just add device groups into app groups? I'm just thinking out loud that this will be fast for subsequent deployments?
  15. Formal answer from Lightspeed is no.
  16. I think we're giving them notice they're getting binned. Dire product and support now. I'm praying I can convince the powers to choose SignIn App
  17. I should add that my current work around is an open wifi hotspot with the correct WiFi profile deployed, so I can get them online by selecting the SSID and not entering a password. Still quite slow though
  18. Lightspeed leverages a return to service tickbox which keeps a wifi profile on the device so you can hands off enrol it to the MDM assigned in ASM. VERY handy when dealing with one device. However, I need to remove erase 597 devices and push them across to Intune. Anyone know of a way, using Lightspeed or ASM to remotely wipe devices in bulk, whilst keeping them on WiFi for quick enrolment?
  19. Yep, works pretty well. As you say, at root level you create the layout, then at the OU/School/Group level you assign it. Works pretty quickly for me, but I find when dealing with many apps and many devices, instructions get lost and never arrive. Use the clear activities then trigger a resync. See if that helps?
  20. It really is. What age range was this with? We're trying to find a solutions for KS1 and it's a nightmare
  21. Having this same issue too. We've moved to (well I was planning to) Shared iPad mode in order to make students log into iPads to monitoring, but I can't seem to find a way of getting 'logged in' user or current manage apple ID to forward through to Smoothwall Browser. AppleId, userId, userprincipalname etc all fail. I can get SSO against Google to work, but then that defeats the purpose of shared ipad mode especially given that Smoothwall can only filter and monitor their browser - I might as well abandon shared iPad mode and have them sign into the browser. iPads for KS1 are an utter nightmare but we cannot get the schools to give them up...
  22. Hi all, thread bump. This topic is one that's been a concern of mine for a long time. Lack of funding and interest elsewhere has made progressing this impossible, but I've been given a potential go ahead to source solutions. It seems a lot of places are in the same boat, and I empathise with their concerns. KS1 kids are too young to log into devices with their individual accounts, yet I believe this is now mandated or at least set from DfE? Either way, teachers logging in Chromebooks with their accounts for kids is NOT a solution and we witness this daily with no consequence 😅🤷 Tomorrow I am tech demonstrating Shared iPad mode for student iPads and I expect this to go down like a lead balloon. I'm trying to sell it down the safeguarding path. especially given just how many lightspeed alerts we get daily. I've got a meeting today with Wonde to discuss MyLogin, and I want to speak again with Clever. Just wondering what you guys are doing with iPads and simple logins for KS1? I feel for the teachers, but we've got to keep students safe so I'm going to be pushing Shared iPad mode hard. We use Google so would be looking to federate either solution against that, but we are also looking to Federate Google against M365 down the line too for Intune etc. It's getting complicated quickly!
  23. Tried both. Can't tackle it retrospectively; every student and their dog will try once the knowledge spreads. We must get Edge blocked or extensions blocked at the very least. Thankfully our Meraki is stopping access to most dangerous things, but VPNs are a major risk if they can be installed as an extension
  24. Thread necro, but getting same issues. Kids installing VPNs. W11 is awful to manage. Can't get AppLocker to block Edge, and GPResult and edge://policy show the GPOs blocking extensions being applied, and yet extensions are installing.
  25. Thanks, will look into this! Much appreciated.
×
×
  • Create New...