ordeology
Members-
Posts
65 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by ordeology
-
We did an in-place upgrade from 2008R2 on 5 of our SIMS servers a few years ago we initially cloned the VM's then tested in-place upgrades just did some sanity checks. We went 08R2 - 12R2 - 16 - 19... or we may have stopped at 16 I can't remember. It was a long process as it involved upgrading SQL as well. We did all this over the summer and basically said to everyone SIMS will be out for critical maintenance during this week so we blocked all access to SIMS for that week. We did a full backup initially and also took a snapshot carried out one OS upgrade, checked it, then the next OS upgrade, checked it and so on. We deleted the snapshots when we were happy and kept the initial full backup for a few months I think. There was no issues just took a long time to do 5 servers.
-
Although I no longer work in education, handling our SIMS servers was always a job I tried to give to someone else to do. They were a nightmare. We did a really crude calculation once for how much it costs per year for maintenance and unplanned downtime spent dealing with SIMS issues, I think it came to about £60,000 per year. I can't quite remember how we got to that figure as it was few years ago since I did it. I did present it to our COO as part of a draft business case to move to a cloud based provider. However the CEO was happy with SIMS and wasn't going to budge or even consider looking at alternatives.
-
Running your servers - the cost of electricity vs cloud hosting
ordeology replied to localzuk's topic in General Chat
This an interesting point and something I never took in to consideration when I redesigned our new server infrastructure for a MAT about 3 years ago. However one thing I did was reduce the footprint of our server infrastructure because over 7 years we inevitably had to buy more servers and storage to keep pace with growth so the before was 19 physical servers, 2 tape libraries 2 SANs. Then the new kit came in we reduced all of that to 6 servers and 2 SAN's, I left the Trust shortly after it was all finalised to pastures new. Now thinking about it I do hope in reducing the footprint the replacement kit at least bought in some energy savings. -
I've had a similar problem, I found that the way Rufus creates the bootable ISO is not right for UEFI GPT so I used this method https://www.hyper-v.io/create-bootable-usb-windows-server-2019-installation/
-
I went serverless for two sites, all they had a server for was DC, and file storage... so when it came to server refresh we ripped them out. File storage had already mostly moved to OneDrive and authentication was provided by the two main sites where the main server infrastructure sat. It did mean they were reliant on the WAN connections but we had failover connections in place and, the main connections the only time we had outages was planned maintenance which was once in a blue moon out of hours. As for the Aruba switches I can't help we were a Cisco house.
-
I implemented Foldr in my previous place
-
I put a Biostore Fastrak system in the Trust I worked in previously and the system works really well, install was easy and went really smooth considering the switch over was doing during term time. Also used it as an opportunity to tidy up our biostore servers and biometric registration process.
-
If you have O365 why not create an MS Team? The backend of them is basically a Team SharePoint site. https://support.office.com/en-us/teams https://docs.microsoft.com/en-us/microsoft-365/education/deploy/set-up-teams-for-education When I worked for a MAT we had a SharePoint but no one took ownership of it and it quickly fell in to a state, we shifted departments and schools over to Teams and made life a lot easier for us in IT Support.
-
Yeah so it was a managed print contract direct with the manufacturer as we went all in with Konica. It was a cost per copy charge which covered maintenance, and the toner was self ordering so never really had to think about that. Only had to do a bit of work when a member of staff said toner is empty... Yes which colour and which copier? I can't remember what the cost per copy was mind you as I moved on from that place nearly 6 months ago.
-
Lenovo ThinkPad L390 Yoga? I deployed an earlier variant the 260 across the Trust I used to work for and went down quite well with most of the staff. It was light, touchscreen, didn't look to bad and had performance. Only problem was staff kept forgetting they had put a pen or something while they working then closed the lid and crushed the screen against it... (they weren't used to having laptops)
-
I had similar arguments before I left the trust for pastures new... I always put a stopper on new desktop laserjet printer requests only to get a message a couple of days later from C level saying can we order a desktop laserjet for this person. I did however make sure any new desktop laserjets were purchased through our print provider and if possible the lease length was adjusted to coincide with our main fleet.
-
Set the scene we were a trust and the school I worked at back then as a L1 technician had around 100 printers we then moved to a new BSF school and put in 8 Ricoh 45ppm MFP's purchased outright and had them for around 6 years. We then re-tendered as a trust and moved to Konica Minolta on a lease with 45ppm MFP's and then later asked them to put in PaperCut for us as well. We also defaulted everyone to mono and duplex.
-
Sounds like you need to work out strategic locations for MFP's and remove all the little printers and the inkjet multi functional devices. Yes staff will probably complain they have to walk down the corridor to release a print job so it will mean a culture change. It is so much easier to manage a few strategically placed MFP's than a wide range of inkjet multi functional devices, not to mention probably more cost effective. I was part of a project in on of my previous jobs which saw the cutting of a large number of little printers and replace them with MFP's in key locations. This worked well coupled together with a print management solution.
-
Hi We migrated to a new 2016 VM a few months ago back in Paxton were saying Net2 is unsupported on 2016 but they assisted us anyway and we can confirm it is all working fine. You can download the Paxton Net2 software from their website the only thing you will probably need support from them is transferring the license key over if you are using the pro version.
- 11 replies
-
- paxton net2
- server 2012 r2
-
(and 1 more)
Tagged with:
-
Fixed it... https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc816624(v=ws.10) needed to enlist the RODC's in to the partition and all works as it shoud.
-
Hi We have a single forest domain which we will call contoso.local with two child domains which we will call abc.contoso.local and xyz.contoso.local we currently have two forest level DCs running DNS and two DCs running DNS per child domain. These domain controllers run Windows Server 2016 domain functional level 2016. We have taken on another school and need to throw in a server with RODC's for the child domains as they cannot afford to put in a decent WAN connection so we have to go over a 20mb internet line with IPSec. To carry out the initial install I have set up a VLAN at one of our current sites for the new RODC's to sit on so that when I'm ready to throw the server into the new site I can just throw it in with out any IP changes needed. I'm using Windows Server 2016 to create the new RODC's, when creating either of the new child RODC's it does not allow me to install the DNS server part when going through the AD promo gui as it says "DNS cannot be installed on this domain controller because this domain does not host DNS". This happens on both abc and xyz. I ran dcdiag as per this link https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/troubleshoot/verify-dns-functionality-to-support-directory-replication and on both abc and xyz domains I get the following at the end just change abc1-dc to xyz1-dc below The A host record(s) for this DC was found The SOA record for the Active Directory zone was not found Warning: The Active Directory zone on this DC/DNS server was not found (probably a misconfiguration) Root zone on this DC/DNS server was not found Summary of test results for DNS servers used by the above domain controllers: DNS server: XXX.XXX.XXX.XXX (abc1-DC) All tests passed on this DNS server Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered DNS server: XXX.XXX.XXX.XXX (abc2-DC) All tests passed on this DNS server Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered Summary of DNS test results:Auth Basc Forw Del Dyn RReg Ext _________________________________________________________________ Domain: abc.contoso.local abc1-dc PASS WARN n/a n/a n/a n/a n/a ......................... contoso.local passed test DNS On the forest level I see this The A host record(s) for this DC was found The SOA record for the Active Directory zone was found The Active Directory zone on this DC/DNS server was found primary Root zone on this DC/DNS server was not found Summary of test results for DNS servers used by the above domain controllers: DNS server: XXX.XXX.XXX.XXX (forest2-dc) All tests passed on this DNS server Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered DNS server: XXX.XXX.XXX.XXX (forest1-dc) All tests passed on this DNS server Name resolution is functional._ldap._tcp SRV record for the forest root domain is registered Summary of DNS test results:Auth Basc Forw Del Dyn RReg Ext _________________________________________________________________ Domain: contoso.local forest1-DC PASS PASS n/a n/a n/a n/a n/a ......................... contoso.local passed test DNS Any help would be great... I'm struggling a bit here even with scouring the internet for similar issues.
-
We had an outsource DPO service that cost an arm and a leg mainly because I refused to take on the DPO role as I had enough to do as it was. However I still ended up doing 95% of the leg work as the DPO just checked my documents over, and gave plenty of advice when we had data protection queries and breaches. We haven't renewed the contract with them, as our compliance director is now taking a larger role in this and it seems my workload is now falling in the realm of data protection thankfully.
-
Office 365 Spam Filter
ordeology replied to jamoritch's topic in Internet Related/Filtering/Firewall
We use O365 Advanced Threat Protection and it seems to be doing a pretty good job so far, it is catching a lot of stuff. -
Below is the scope that was sent by the auditors, which should give an idea of what they wanted to see. 1.1 Scope of the review The scope of the assignment has been agreed by management as follows: 1 Business processes and data discovery Based on the documentation and information provided inspection of the management control processes designed to identify and document all in scope data across the organisation. Related data inflows and outflows focussing in particular on: · the existence of process and data mapping; · processes to classify data; · identification of data flows to third parties; and · methods of data storage and transfer. 2 Third parties Based on the assessment set out at (1), we will carry out the following: · inspection of the methods used to identity third parties to whom the ‘in scope’ data is transferred. · identification of methods used to assess contractual data confidentiality existence and coverage. 3 Data ownership · Based on the documentation and information at 1 above, note the existence of processes used to identify/allocate data owners. 4 Data security system level controls · Test data security controls agreed by you over data inflow, data repository and data outflow and report results by reference to recognised good practice. 5 Data storage and retention · Based on documentation and information at 1 above, comment on the existence of data retention and storage policies. 6 Awareness · Based on the documentation and information at 1 above, comment on the existence of GDPR awareness processes. 7 Data policy, roles and responsibilities · Based on the documentation and information at 1 above, comment on the existence and scope of current data policies. · Based on the documentation and information at 1 above, comment on the existence and designation of data protection roles and responsibilities. · Comment on current roles by reference to recognised good practice. 8 Individuals’ rights · Based on the documentation and information at 1 above, comment on the existence of procedures for updating, deleting, and reporting personal data at department and organisation level. 9 Consent · Based on the documentation and information at 1 above, comment on the existence of processes in place to capture data consent. 10Data breaches · Based on the documentation and information at 1 above, comment on processes in place for the detection, reporting and investigation of personal data breaches 1.2 Limitation to the Scope of our work [TABLE=width: 699] [TR] [TD]· The assignment is delivered as ‘agreed upon procedures’ and therefore will not result in a formal assurance level or opinion. · We will not confirm compliance with GDPR and/or provide any legal or regulatory advice. · Our work does not provide absolute assurance that material errors, loss or fraud do not exist. Please note that the full scope of the GDPR assignment can only be completed within the budget if all the requested information is made available at the start of the assignment, and the necessary key staff are available when required. If the requested information and staff are not available, we may have to reduce the scope of our work and/or increase the budget. If this is necessary, we will agree this with the Chief Financial Officer during the assignment. [/TD] [/TR] [/TABLE] 1.3 Requested documents To enable us to commence our fieldwork on the agreed start date, we will require access to the following information or records in advance of the assignment start date: · Full listing of IT systems that manage data which falls under the scope of GDPR; · Documentation and evidence of data mapping including a listing of designated data owners mapped to the data for which they are responsible; · Documentation and evidence of third party contract data confidentiality assessment(s); · Documentation of processes used to capture data consent; · Key policies and procedures relating to data policies and procedures; · Data breach incident response procedures; · GDPR / data governance awareness programs; and · Data Protection/GDPR role job descriptions.
-
Really interesting post!
-
I forgot to mention they didn't look at any of the DPIA's we had done, we still have a few to do but we have the majority of our systems done.
-
Hi all, Sorry for the silence on this, been rather busy since I posted this. So the auditor in the end said we have every document you could need under the GDPR just they aren't quite finished or some of them don't contain the correct wording. The A30 record it has been recognised does need to go out to department heads really to be filled out in more detail so not to bad. As for the 3rd party stuff he didn't seem to impressed that all we had were the T&C's that came with the service as my thought process always has been we would agree with the 3rd party wording. He wanted us to have submitted our T&C's for data protection and even if they refused them then he would have been happier with it. Other than that I'm just trying to push GDPR up to our compliance director who is higher up the picking order than me and therefore will have more clout in the academies to get things done which is where I have struggled. Also working on re-wording policies so that the department responsible is the exec not the IT department.
-
Well I don't know what to think now... We have had an independent auditor in to review our data protection compliance and it isn't looking good. In the year I have worked on the project which I didn't want to do in the first place I have had several major IT projects running at the same time. My view we have come a long way in a year we have a breach procedure, assessment form and register, a subject rights request procedure, form and register. We have privacy notices a data protection policy, a very good draft of a retention schedule thanks to the IRMS toolkit and the DfE document. Staff are being trained in GDPR and information security and are starting to ask questions around data and whether they should send it or not. Two main points the auditor has a problem with is our data mapping isn't great so our article 30 record or whatever you want to refer to it as. And 3rd party agreements my thought was that the larger company always imposes their terms and conditions on us instead of us sending them our terms and conditions around data protection... I don't know what should we be doing with 3rd party processors such as Groupcall, Go 4 Schools etc? Any ideas.
-
SMTP Relay Issue Exchange 2013 to Office 365
ordeology replied to ordeology's topic in Enterprise Software
We did find that link useful as we have now started working on moving away from using our on prem exchange sever for SMTP.
