Planehazza
Members-
Posts
325 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Planehazza
-
Got it working nicely, but Microsoft stipulate an "eight hour window" for load balancing. Does anyone know if it's possible anyway to speed this up? https://docs.microsoft.com/en-us/onedrive/use-group-policy I wonder if there's a reg key I can tweak if it's handled by the sync tool itself?
-
Disabling AADC Synced Distribution Groups
Planehazza replied to Planehazza's topic in Enterprise Software
That's what I thought too. I've obviously not tried hard enough with the cmdlets. -
Disabling AADC Synced Distribution Groups
Planehazza replied to Planehazza's topic in Enterprise Software
Slight diversion from the original question... I need to rename ~40 AD dist. groups, which involves editing about 6 attributes each. We started with exchange hybrid, but we decommissioned our exchange server about 18 months ago. I would have, otherwise, simply use EMC to change them via PowerShell, but without an exchange server I cannot do this that I'm aware of. Anyone got any ideas how I could do this with powershell without an on prem exchange server? -
Disabling AADC Synced Distribution Groups
Planehazza replied to Planehazza's topic in Enterprise Software
Interesting, never heard of this. EDIT: Handy to know, thanks! Office 365 - The (Previously) Undocumented AAD Connect Filter - Perficient Blogs -
Having a massive house clean of AD, and the current phase is dist. list groups. We have a LOT at one school and many are no longer needed. I don't want to just delete them in case we get the inevitable complaint (we're auditing them and are giving staff notice so they should know to mark them as 'keep'). What's the best way to remove them? Simply move them to non synced OU so that we can move them back to quickly restore them? The risk of deleting them and having a request for its recreation in a year's time is all but 0%. All email lists are currently 'xxxxEngDept' (xxxx being DFE number) etc., but all remaining groups are being renamed to a more neat and professional name, so once a an email list is deleted, there is 0% chance a group will ever have that name again. Having said that, never say never...
-
[ipad] Meraki MDM - Pushing bank of files
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
I guess then part of the problem is my not fulling understanding what it's used for. What is the best method to have a bank of shared iPads and have students log in to them and back out again easily and reliably, so we can track Internet usage and allow access to their 365 resources etc? Art has 6 iPads that a bunch of photography/graphics students use. Music has ~30 devices but they already use Seesaw etc. -
[ipad] Meraki MDM - Pushing bank of files
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
We use Azure, albeit via AADCSync from local AD. Would this not suffice? The problem with logins is you can guarantee that the students will not bother signing out before handing the device back. I do not want student A deleting all of Student B's work for sh!ts and giggles. -
[ipad] Meraki MDM - Pushing bank of files
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
Safeguarding. We need to know which students clicked on that porn advert etc, and relying on teachers to track it on paper or kids to sign out portals is not going to work. -
[ipad] Meraki MDM - Pushing bank of files
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
Yup, they're all ideal, but as it stands, the iPads are generic devices with no logins. We do not know from one minute to the next which student is using them as there are no Apple IDs or signing in involved. Teacher unlocks the device(s) via PIN and hands them out. If we put OneDrive on them for example, it relies on the user to sign out and that's just not going to happen. Realistically, as per the other [iPAD] thread about share logins, we're kind of stuck until we can set up federated logins so that each student 365 account provisions an Apple ID so they can sign into the iPad. We would have to start thinking carefully about device storage and be more proactive with having them back in each term for a wipe and reprovision etc. -
[ipad] Shared iPad - Logins
Planehazza replied to kidpressingbuttons's topic in Mobile Devices & Tablets
How will it affect the itunes accounts etc that we use to provision VPP etc? Like, the Apple ID we log into ASM/VPP/Secure Inbox etc. That's [email protected]. Our MDM solution spans ~6 years of continual development, built on a foundation of not fully understanding how it works. In other words, our ASM/Meraki accounts are all over the place for the two schools we manage. Considering I can prove ownership of a domain name, you'd think any matching email addresses using our domain name would not be any sort of data breach. Why can't/won't Apple show us so we can be confident it's not a problem? -
A teacher needs to be able to add a bunch of photos/image files to multiple devices because, at present, we block use of Safari on the shared devices (we're not using Apple IDs at all yet or SSO etc.). She's asked if we can install iTunes so she can sync photos but I've explained why that's not the best idea. So, I thought about having a repository somewhere they can link to? Or perhaps pushing them using backpack? The problem with the latter is that you'd need to define a backpack policy for each file, and these are going to be changing regularly. How have you tackled similar requests?
-
[ipad] Shared iPad - Logins
Planehazza replied to kidpressingbuttons's topic in Mobile Devices & Tablets
Slight derail, though it is related (promise!)... I wanted set up the federated logon between our ASM and 365 so that we could provision accounts for students to login in to shared iPads so we could allow Internet access again. It seems ~70 people have created Apple IDs with their school accounts, meaning that when I try to set federation it warns me that I need to reclaim those IDs prompting them to change the email address they use. It doesn't seem to tell me which accounts are going to be affected? I'd like to sit through them first and query whether it's going to be a problem. -
Spring 2021 SIMS update has killed commandreporter
Planehazza replied to rogerdnixon's topic in MIS Systems
Came here after googling why a CommandReporter batch file of ours is sporadically failing and I found the irony in this post amazing -
Yeah we have it set up like that. Here is the policy for students: In Teams, you can see that Chat is missing (blocked) and searching for a user show the chat/call options greyed out. Correct. However, in OWA, you can click on the contact card of any user and see the call/chat buttons which allows them to flow through and call them via Teams. OWA mailbox policy settings: I've blocked various mailbox features in the EAC and assigned the policy to the student, verfied that it has applied via a powershell Get-CASMailbox -Identity | Format-List owamailboxpolicy No joy. Thought it might be a Delve feature, but can't see any way to manage these?
-
We have multiple Teams policies in place to prevent student access to chat and calls. However, when they go to OWA and click on the profile card of any user, the call and chat options are there allowing them to (ab)use the the features. I cannot see any Exchange functions etc that would allow me to turn this off. Would the Teams Chat role permissions affect this? Have you had to block this, and/or do you just rely on custom GALs to limit the ease of finding recipients to contact? As you can guess, students have worked out how to spam call teachers...
-
Exactly my point Same, though we do not manage it ourselves, and instead rely on the service from Cloud Design Box to provision it for us.
-
Yup, that's how I understand it. I can use chat role permissions to set students to Restricted and staff to Limited or Full Access, but this won't address this request. The request, IMO, is flawed; it's not the answer to this one issue, but it's not my decision to make. I'm meeting SLT about it soon so hopefully I can make the case of the importance of Teams chat within a class team for homework setting etc.
-
This 'behaviour issue' has cropped up a few times. There's no easy way to block it, as there are multiple avenues users can adjust their photo. We have changed numerous settings, but there are still some ways they can change it. It might be worth us electing to do the nightly change also (we have salamander and cloud design box), but alas it won't prevent students changing it. It might demotivate them to fiddle when they see it resetting every morning
-
Same here. Don't forget, teachers (as owners) can go the team settings and mute students, either as individuals or all, preventing them from chatting entirely. We've had an incident resulting in a request from SLT to block chat between staff and students entirely 🤦 Just seems like a kneejerk reaction.
-
We have multi group assigned policies set in Teams to prevent students using the chat 'app' in Teams. We still, however, allow chat within meetings or the class teams where they're in a 'safe' environment with a teacher that can monitor messages. Just wondering how you're handling said restrictions? Not necessarily the Teams settings/policies, more the school policy or what SLT have told you to do?
-
We have a Team for most departments and subjects through a third part syncing solution between SIMS and 365. If a teacher teachers Art, they're added to the Art group where the SharePoint resources are held and Team is there for meetings. They're then also added to a class team for every lesson they teach as on owner with the students in as members for assignments etc. Now, for anyone that has a similar implementation, how are you handling emails? I've elected to decommission legacy AD synced distribution groups in favour of using the Team group shared mailbox. We have the Exchange options enabled so that messages and and meeting invites etc. are also sent to the mailboxes of group members. This way, I see it that we have a singular central group for each department/subject. Easier to manage, shared calendar, Forms 'repository', Stream channels etc, and easier for staff to remember a single group name. Dist. lists mean that someone that teachers History once a month can be in "History Teacher" email list without needing to be in the Team. It's the one, small pro to using DLs over SMs I can think of... Where we don't have a need for a Team/SharePoint site etc, i.e. 'Year 07 Students', is where we'd fall back to 'legacy' dist. lists. Does any of this jump out at you as a "WTF are you doing that?!"? We also see it as a way of HoDs can prove they sent an email to their staff when the inevitable "oh, I didn't get that" response comes in - they just look at the read only group mailbox, and there it is. TL;DR: Shared mailbox belonging to a team enabled unified group, or 'legacy' distribution groups? Thanks!
-
Probably a silly question, but have you clicked the reprocess and refresh buttons? What if you manually tick the license in the portal so that in Azure, you see "Direct, Inherited from "?
-
We're in the process of A1 to A3 licensing. We went for it primarily for things like SSPR, Intune. Other features like Bookings look like they might be useful
-
I've taken the task of going through our AD and giving it a sort of rewrite. Non of our groups are set up in an obvious, easy to understand way for delegation and access, and very few of them use the correct best practice method of PC/User > Global Grp > Domain Local Grp > Permission/Access. GPO security filtering wise, does it matter what group scope I use? Many of our security filtered GPOs have groups on them, but they're all Global and work fine for policyscoping. I want to change them to DL groups for neatness and good habits, but is there a technical reason here too for things like replication? I would assume yes? Do many of you use things like PaperCut or other third part apps that tie in to AD? Would you use G or DL groups there? Thanks!
