Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

David44

Members
  • Posts

    456
  • Joined

  • Last visited

Everything posted by David44

  1. Everyone accessing YouTube from a UK IP address will be blocked by default. There are steps one can take to circumnavigate the block, VPN, age verification, signing in to a Google account etc. but if you don't take any of those steps, you will be blocked, whatever age you are.
  2. Everyone that goes to youtube.com in the UK will be effected. There is no way they can't be. At best, they will need to sign in where they didn't before, at worst they will need to jump through hoops to prove their age. There will no longer be a frictionless method to visit YouTube to watch a video or have a YouTube video embedded in a post on a site such as edugeek.
  3. It isn't clear at the moment but it seems that they will have to ban YouTube for everyone in the UK until each person proves their age. Whether being signed in to a Google Workspace account that the school has marked as over 18 (or not under 18) counts as robust age verification, we don't know yet.
  4. Do users see the message when they download a file or when they try to open the downloaded file? For what it's worth, I'm using 149.0.7827.54 and I can download files and open them from chrome://downloads/. We enforce the downloads directory, users don't get to choose where to download files, and that path is on a Windows network share. It shows as h:\downloads rather than a UNC path though.
  5. Do you have a sign in for https://criticogroup.com/login/ (was PageOne) That should help determine if the text messages are getting to them for further distribution. It should also show any text messages you have received that haven't been passed to SIMS yet.
  6. Could you post the SQL query here?
  7. Is a misbehaving browser extension doing this? Do they have the same extensions in both browsers?
  8. Slightly off-topic, what was your workaround for the codes? We have a Powershell script that matches students from iPayImpact to their contacts (parents) in SIMS and then sends the student code to their their contacts (assuming no court order etc.). We use a Google Sheets "frontend" to select the student(s) we want codes to be sent for. We still have to periodically manually sign in to iPayImpact to download the CSV file of codes though. I wonder if you have found a way of avoiding that.
  9. We don't use Schoolcomms but for what it is worth, we get the same error message when browsing to https://app.schoolcomms.com/ We are similar to you, we use Chromebooks and some PCs. The error appears on both. If I use an unmanaged browser (still Chrome), I can get to the site. I'm not sure what that tells you, other than it isn't just you.
  10. We have resolved/worked around this. Here are my notes on what worked for us. You may not need to enable HTTPS inspection (step 1) if you have already done so for students. 1. Create a new HTTPS Inspection Policy... Who: SCHOOL Students, Unauthenticated IPs What: Google Sites (this category already existed) Where: Everywhere When: Always Action: Decrypt and inspect Enabled: True and move it to the top of the HTTPS Inspection Policies This is done here... http://smoothwall.ip:81/modules/guardian3/cgi-bin/guardian/https.cgi The above allows Smoothwall to see that students are going to https://sites.google.com/schoolname.sch.uk/student-site/ rather than just https://sites.google.com/ 2. Create a new category called 'SCHOOL Google Sites' and add 'sites.google.com/schoolname.sch.uk' as the only URL. This is done here...http://smoothwall.ip:81/modules/guardian3/cgi-bin/guardian/customcategory.cgi 3. Create a new Web Filter Policy Who: Default Users, SCHOOL Students, Unauthenticated IPs What: SCHOOL Google Sites Where: Everywhere When: Always Action: Allow Enabled: True and move it to the top of the Web Filter Policies This is done here... http://smoothwall.ip:81/modules/guardian3/cgi-bin/guardian/policies.cgi The above allows Students to access all sites under https://sites.google.com/schoolname.sch.uk/ We can reverse these changes when/if Smoothwall remove Google Sites from the File Sharing Category.
  11. Yes. Looking in to this now. It looks like it is just sites.google.com that is blocked under 'File Sharing' for us on both of our onsite Smoothwall boxes but as the student homepage with a load of links is hosted there, students are reporting that they are blocked from the internet.
  12. Do you use Sophos? There is currently an issue with the SIMS installation .exe files (SIMSApplicationSetup.exe, SIMSManualSetup.exe, SIMSAmparkSetup.exe) hanging when run silently on a machine running Sophos. This might explain why you are seeing slow deployments. It doesn't matter if they are called by Intune, MCM, Action1 or even Solus. There is a thread on it here with some workarounds...
  13. Where is SIMSApplicationSetup.exe running from? It sounds like the paths that @TooOld4This has given you are for Solus, but if you are deploying SIMS using another method, you'd need to apply similar exceptions to those path(s) instead.
  14. And it is back, seconds after posting.
  15. In absence of a service status page for EduLink One, can anyone confirm that there is an issue this morning? Their phone line is going unanswered, which isn't like them, so I suspect there is. We see an error that mentions VPN when we try to sign in to with Google. If you use EduLink One with 'Sign-in with Google' and it IS working, that would also be useful to know.
  16. I've finally got this to work, don't get too exited through, we don't use Solus here so I don't know a fix for that. In Sophos, I just needed to exclude the paths \\SIMSServer\Capita\SIMS\Setups\SIMSApplicationSetup.exe \\SIMSServer\Capita\SIMS\Setups\SIMSManualSetup.exe \\SIMSServer\Capita\SIMS\Setups\SIMSAMParkSetup.exe from 'Exploit Mitigation And Activity Monitoring (Windows)' (and turned off all Mitigations) in Sophos Central. Of course, I could have also made a single entry of \\SIMSServer\Capita\SIMS\Setups\** but the three entries seemed slightly safer. This means that users can run SIMSLoad.exe once again (which we will now put back as part of the standard SIMS shortcut) and it is able to update the three components. To test, make the above change, update Sophos on the client (About, Update), delete c:\program files (x86)\SIMS\SIMS .net\simsload.ini and then run SIMSLoad.exe, watch as it installs the three SIMS components and creates/updates SIMSLoad.ini and be glad that you never got involved with Solus. Of course, this doesn't resolve the issue when we use MCM to deploy SIMS because it isn't being deployed from the SIMSServer. It makes me think that perhaps we could deploy it from there though. I will look in to that. A luxury that I assume Solus users don't have.
  17. Do you mean you did sort it or that it's still your problem to sort?
  18. I have been told by our SSU that "this is a known issue with Office 2024 which is under investigation by Parent Pay". They have apparently logged a case with ParentPay about three weeks ago and are still waiting on a reply. @SIMS_Customer_Support Can you confirm that this is now a known issue that is being investigated by Parent Pay? @chazzy2501 Did you ever get anywhere with this? Find any workarounds? For what it's worth, it seems this issue has been around for at least a year...
  19. These appear to relate to Solus, which we don't use, so I didn't add those paths. We don't have a Capita folder within ProgramData anyway so we don't have anything attempting to run from there.
  20. Is SIMS now installing without the exe file hanging for everyone else or have you just learned to live with it? We have been deploying SIMS by launching SIMSApplicationSetup.exe (and the other exe files) and then forcing it to close after 5 minutes to get around the issue but I'd like to sort this out properly, especially for SIMS updates. Did the Sophos exceptions work for anyone in the end? We want our users to be able to run SIMSLoad.exe to update SIMS. Currently when they do this, they see the same issue as is being reported with SOLUS, SIMSApplicationSetup.exe will launch (and get to 100%, before disappearing from the Windows task tray) but it will remain running and SIMSLoad will never move on to the next exe. We don't use SOLUS so the only exceptions I have added to Sophos, under Endpoint Protection - Global Exclusions are the following... C:\Program Files (x86)\SIMS\SIMS .net\ S:\SIMS\Setups\SIMSApplicationSetup.exe S:\SIMS\Setups\SIMSManualSetup.exe S:\SIMS\Setups\SIMSAMPARKSetup.exe I also tried adding \\servername\capita\SIMS\Setups\SIMSApplicationSetup.exe These changes don't seem to have made any difference, the .exe files still run successfully and then hang when they are run silently from the command line or called by SIMSLoad.exe Is everyone running SIMS and Sophos still seeing this issue?
  21. @Davit2005 What is wrong with the effs in that text message? I assume some kind of encoding issue but why would it only happen with effs? Do your other text messages show the same issue?
  22. Were they links created by the sender or had your email client made them in to links? If I was sending an email about registering a .co.uk domain. I might ask "What is a good company to register a premium.co.uk name with?" The email client of the person receiving the email might then make 'premium.co.uk' a link even though I, the sender, didn't intend it to be. Still the senders fault for not putting spaces before referring to the gov.uk domain though. Don't even try sending an email about sims.net though.
  23. https://www.papercut.com/help/manuals/ng-mf/applicationserver/printer-add-remove-printer/
  24. I don't think it's the sharing of the email address that is the potential data breach. It's an internal job so it was probably their school email address anyway. The data that was shared is the fact that they had applied for the job. Nothing was breached, the data was shared willingly by the member of the admin team by the sounds of it. Should it be reported to the ICO, I don't know.
  25. Thanks for the update. We seem to be experiencing the copy/pasting image issue but hadn't linked it to Senso yet. We've just added googleusercontent.com gstatic.com fonts.googleapis.com apis.google.com accounts.google.com as web exceptions to web filtering as parts of the Google Site that is set as our student homepage wasn't loading. It's been a pretty shoddy role out. They weren't going to migrate anything from the old system for us until we made a complaint via our reseller. It's still not possible to get a list of all console users either (it is, but it involes going in to Developer Tools and finding and downloading a JSON file rather than it being a simple button on the GUI).
×
×
  • Create New...