Jump to content

KK20

Members
  • Posts

    969
  • Joined

Everything posted by KK20

  1. Training. We moved all of our onsite to offsite just before covid hit. Covid was a very very rapid set of training for us. We did two things, first we actually had office 2019 at the time and needed to move to 365 fairly quickly. The second was show people file versioning and file history. This led to branching and organising of "stuff". We were already dipping our toes in the teams water but covid catapulted this to the front. Our ethos is sharepoint for departmental "masters", teams for changing classwork, onedrive for personal stuff. However, items can be shared from any of them to staff (or pupils) as required. We moved our two main file storage areas into two main document libraries so the mentality was the same. For common resources people can file version their own branch if they wish or edit the master. Onedrive for personal stuff and share links with other people if they wish for collaboration. If staff leave I simply give the new person access to their onedrive, and move them to a "left staff" group. The new person gets a couple of months to sift through before they go in the bin. I do most of my work in onedrive and email links to my shared collaboration work, shutting off access when required. I have sharepoint external sharing disabled and onedrive external sharing enabled for staff. this stops someone sharing the root of a document library to the outside world. As for pupils, I have a scheduled task script that checks for new pupils and adds staff as site collectors thus staff have access to pupil onedrives. We still have a file server for our art and drama departments, moving and editing 500mb drama recordings offsite is still problematic for editing. Photoshop monsters are also an issue so pupils and staff edit using the onsite library and publish to sharepoint and onedrive. Get your administration office staff onboard quickly. Get minutes of meetings sent out as links, registration summaries as links, have collaboration spreadsheets for markbooks (if you dont use teams or firefly etc) as links. People will soon see the advantage of not searching emails for the correct version. Show the advantages of file versions, the recycle bin, being able to give a trusted pupil access to a pupil share for creating end of year leavers books, or 6th form prefects write access to the duty rotas etc. Show people how the versions can be checked for arsing around. It is better than onsite storage an far less of a task for you, one of the massive advantages for us was that staff could change who had access to their departmental areas without emailing us for NTFS permission changes. the other big sigh of relief was access requests. They used to take a lot longer with onsite storage, not quite as onerous with sharepoint and onedrive. Redacting still takes as long of course!
  2. We currently use conditional access for staff and pupils. Staff have conditional access for MFA in non trusted locations. Pupils do not (yet). Trusted locations are our school IPs only and this works fine for us. Pupils dont have enforced MFA, however we do have location conditional access limited to UK connections only. Its a crutch and not ideal but is better than nothing at the moment. However from what I can tell, conditional access kicks in AFTER a successful login. My idea is that some of our pupils are being absolutely hammered with external attempts from all over the world, this can cause a problem with account locking as these external attempts can happen at any point in the day. Ideally I would have liked the process to be: 1) attempt to login was made 2) conditional access checks location 3) conditional access fails location check 4) dont bother trying to check credentials, just send the usual username/password might not be correct - i.e. the phisher doesnt know if it was a correct u/n or p/w or conditional access What appears to be happening is: 1) attempt to login was made 2) credential check is made - this will increment the "x number of checks in y minutes" 3) conditional access checks location 4) response given to client. Obviously point (2) is the issue with this approach. MFA solves this because point (1) requires MFA to continue so you never get an account lock issue. But we cannot enforce MFA with pupils as not all will have capable phones and we cant afford to give everyone FIDO2 keys. How does everyone else deal with random login attempts and account locking?
  3. I know secondary schools who use 100/100 AND are on 365.... They might have had an upgrade as I havent been to an ANME meet for a while.
  4. depends on your setup really. Do you look after your own network DNS? If so then that is the forwarder part sorted. Can you add a certificate to all your clients easily using GPO, MDM etc? Thats another part done. Can you easily add a smartPAC to your MDM or GPO? Job done on the hardware side. Software is a case of linking your preferred logon sync, we use office 365 and that was easy enough. Guest networks depend on your own setups. It took me around 30 mins to set up the majority of my academic side and a couple of days for the guest as I needed to chat to an fro with technical support (I wasnt in a hurry else I could have pushed or rang).
  5. when we moved to isams we needed to format everything into specific CSVs. This was basically a huge set of report generation and a bit of faffing. We found the academic reporting side to be more cumbersome, we use a different third party for our academic reports (base data grabbed from isams). Everything in isams is modular, make sure you spec out what you want initially as extra report creation, modifications down the line will cost and the costs can easily rack up - even for relatively minor changes. Make sure you get a demo for what you actually want to do, if the sales person cannot show you, get a call scheduled for a demonstration. Take care if you are hosting onsite, you will need to keep up on your SQL and server upgrades as isams only support OS and SQL that are in mainstream support not extended support (certainly not for long). Our main gripe by admin staff is around census time, I cannot say why but apparently isams does not do something in particular. We havent had any issues with exams module. We dont use the parent module - we found the firefly parent module to be much better to work with. We do find isams easy to use overall though and it is pretty reliable. I havent used SIMS for some years now so cannot comment on what it is like now but it certainly works better!
  6. does it still list if you attempt to connect to a database engine, go to "server name" dropdown -> browse for more -> network servers and expand database engine? That is odd if it does as that means there is a pipe being broadcast. You could always install and run "microsoft assessment and planning tool" and run a search on your network for SQL servers, that will tell you definitively what is running (and is a good idea to pick up on those old SQL express installs from old programs such as Sophos etc that left those databases behind)
  7. I was a solid Windows person, MCSD qualified and been administering networks since NT4 citrix days. I was told to get a suite of ipads a few years ago now and didnt like the sound of it, we also have a few macs. They are easy to sort out, you simply need a good MDM and all will fall into place. Nowadays you even get office 365 SSO with the microsoft authenticator app. Visual basic is a fine language! Very forgiving to beginners and codes nicely as VB.NET. In fact we teach our younger students "small basic" as it is very easy to get into, can get results quickly and has a lot of resources. The concepts are easily transferable and still relevant to industry. IT is a tool, if the tool does not fit the curriculum and is not fit for purpose then it needs to be changed. Not on a whim but certainly for wahtever course/qualification/board requirement is needed. If the budget is there then why not? It isnt an onerous task to set up a room of Macs - not much more than setting up a new room of PCs. Intune and JAMF arent a million miles away from each other and once you get the strategy correct it is not hard to get working.
  8. KK20

    SIMS to iSAMS

    SSRS. If you arent proficient in SSRS then be prepared to pay a lot for support. isams is reasonable as an MIS and you can get an API so you can code your own bespoke apps to use the data but everything costs extra. Make sure you scope the entirety of what you want to do in isams so that you can get an idea of the true cost - each module costs more. We have quite a few .NET apps we have coded to do multiple tasks such as account creation for pupils, teams SDS sync, intranet updates etc. These are done when accounts are moved to "current" in isams and utilise the API in isams to get at the data.
  9. Mathletics works for us. We also geoblock, we use pfblocker on our pfsense firewall for our geoblocking. SNORT threw up a lot of hits from the usual suspect countries, it was worth geoblocking for these alone. The GeoIP lists come from MaxMind.com
  10. we use https://ecdluk.psionline.com/ in chrome - have done for years, we don't have java JRE installed on any of our machines so it cant use java client. Im sure it moved to HTML5 years ago. We use desktop 365 office. Anyway, for us we have a GPO that installs extension leneiifcmnfminekdbgbofkdddlkhcep;https://clients2.google.com/service/update2/crx this works for us and has been reliable for some time.
  11. It has evolved for us. Staff have moved away from the mentality of "staff drive/pupil drive" and more to "department area with permissions". We also use teams a lot so the two are meshed somewhat. Reluctance was high, hence the CDM as a halfway house. However once staff started to use the links, versions, hybrid working people shifted behaviour. I ran quite a few sessions on benefits of working with cloud documents, how to sync files and folders with the online equivalents, how to share working documents with other people plus classroom collaboration etc. It took time but we got there in the end.
  12. I was told the exact opposite by my three providers - VeryPC looked into loads of hybrid ways to get around this by having a hybrid CSP solution, you lose the entire MVLS normally so no keys to download at all, you wont use MVLS for M365 admin, it will all be via the 365 logons. EDIT: I see you said EES, we arent big enough for EES, that was still 1000 licenses when we were renewing, we are less than 100
  13. The main caveat for us was the fact that hardware licensing will need either a BIOS windows 10 key or a visit to each machine and individually licenses and activated. It will no longer be a "paperwork keeping exercise to make sure each machine has a license", each machine will need to physically be licensed. We have a lot of W8 era machines that do not fit the bill, also we have a lot of W10 refurb licensed machines that did not have the BIOS key as they were not factory W10 licensed. In the end it was not a huge price difference to add Azure P1 to the "usual" desktop pack + free 365 desktop apps uplift as opposed to M365 The OS needs to be able to AD/AAD domain join so you need "pro" except W10, you can "free" upgrade W10home to W10pro for education https://docs.microsoft.com/en-us/partner-center/upgrade-windows-to-education
  14. do you use SSRS? We moved to a standalone 2017 SSRS and this made a massive difference for me. So much so our VM went from 32Gb down to 12Gb usage overall. Im not sure if it was 2016 SSRS implementation. There are loads of guides migrating, it was easy.
  15. firefly with isams here. The only issue we have is with "interesting family trees". isams will let you have various family/pupil links for parents, carers, pupils and these do not always migrate over to firefly for parent logins.
  16. I hate autodesk with a passion. This has been an annual nightmare for us ever since the current DT teachers started to use autodesk stuff. The 125 pupil to teacher licensing wasnt good, each teacher needed letter headed paper "I work here" annually, then they could get the pupils added, we needed the technicians to also do this because of the limits. It is a real faff in september each year for us. Ironically enough, Autocad (probably their flagship product) was a piece of cake to get licensed (and we only use it on a few PCs for the 6th formers) - we set up a licensing server (similar to a KMS server) and that was it! It came with all the relevent checks and applications in the installer.
  17. Do you mean an inplace upgrade of 2012 to 2016? There tends to be stubs left behind but ive never seen an inplace upgrade that has left significant binaries behind. If it is a parallel install and migration then I would say all of the 2012 can be removed (assuming you didnt use any other DB on there - WSUS etc). I think 2016 still has integrated reporting services so that should have moved with the installation if it is a parallel install. I cannot remember what happens to reporting services with an inplace upgrade (I moved to standalone reporting services)
  18. We used sharepoint migration tool to get stuff offsite initially. This gave staff the same-ish layout they had previously. We also used CloudDrive Mapper to map a drive letter. Phase two had the departmental areas created and staff moved their bits and pieces into their own areas that they controlled, had access to etc. Phase three removed the CDM drive share. This meant I wasnt making the decision on what to keep, what to use - staff did that as we went along. The area was self policing as departments had their own areas and set their own permissions. We have blocked universal sharing. Onedrive was similar, I didnt force a onedrive migration, we originally remapped "ununsed" home drive to onedrive. I then set the quota for onsite documents to be "very small". Staff and pupils could get their old stuff but had to re-save into their homedrive/onedrive. Once they deleted their old documents we ended up with a small quota for onsite storage. this is still useful for photograph manipulation, media use etc. However staff naturally started to mail links to documents and not the documents themselves, file version and history is loved by everyone, ease of manipulating the links to onedrive/sharepoint in our VLE was preferred etc. I would say it took 3 years from start to finish for a full and working migrated onsite to offsite.
  19. do you mean an internal map or a map of the grounds? I use digimaps to make an external map, then just zoom in. It was good enough to record our external assets. For the internal one, we paid a fire assessor company to create one as an addon to our fire alarm and extinguisher testing.
  20. we use a pfsense firewall with snort and pfblockerNG. This works will with Securly as our guest networks have a captive portal. The gotcha being our domain DNS server has a forward to Securly DNS but the guest network cannot simply DHCP the Securly DNS (or the captive portal wouldnt work, nor local web server etc). PFSense has a DNS forwarder (dnsmasq) capability which can be bound to the guest vlan - so now there are static hosts in the DNS forwarder with a DNS forward to Securly Guest DNS.
  21. Do you have 2x CPU? Try with 2x memory modules. I dont think those servers will boot with "odd" numbered memory modules. There is also an order to install the modules from what I remember (banks). I have a feeling that you can tell the BIOS to boot with an odd configuration - you might have had that set and a firmware update has reset it.
  22. dont get me wrong, it is working and since I have gotten in touch with Chris directly things progressed quickly, support did get back to me. I was very disappointed in the start though - I am technical and (given the time) like to get under the bonnet but others may just want a "just make it work for me" approach. I am surprised securly was more expensive than smoothwall for you though, smoothwall was literally twice the price of securly for us (even their "small school" option) and works "cloud based" so offsite. However, dont just trust the demonstration, one mistake I made was to not run a thorough trial, that one is on me as I would have been better prepared. Your mileage may vary as they say - there are a number of people who it went very smoothly for on here.
  23. I can tell you what I did and the pitfalls of what I wanted and tried to do. Firstly we run 4 servers in a stretch cluster with 2x SANS. SVR1 + SVR2 + SAN 1 is in "one location" and SVR3 + SVR4 + SAN 2 is in another location. I use 10gb as network interlink between them. The stretch cluster is set as synchronous with a separate server as a witness. The separate server is a cheap R430 and is a physical DC (with a virtual DC in the cluster). SVR3 and SVR4 do not get a vote in the cluster, that way if I have a failed interlink SVR3 and SVR4 will not "split brain". Originally I had SVR1 + SVR2 + SAN1 in a cluster, I added the stretch part "live", there was no downtime. I have had a failure in SAN1, the primary controller borked in a way that locked the SAN, the second controller did not take over. This produced a file lock in the cluster and "redirected" storage took over in SAN2 - in essence, it all worked. I also have had interlink failed (truck + fibre = fibre loses), split brain did not happen. The hardware is roughly similar, 1 and 2 are R630, 3 is an R630 but 4 is an R640. All my VMs can run on a single server if necessary. SAN1 is an svc2020 with a mix of flash and HDD. SAN2 is an aging DAS powervault 3220 with a mix of flash and HDD. SSD must be used for your cluster log. Now for the gotchas I found. Originally I had the powervault 3220 as the solo SAN. Originally I wanted to leverage S2D but hit a few snags. First, Microsoft is picky, really really picky as to the setup of the server running S2D, you will need a specialist to make sure your hardware supports the configuration. My "old R630" could not be made to S2D. Your mileage may vary but I had issues. Ideally I would have liked a pair of svc2020 with replication licenses and let the SANS replicate to each other thus I would have simply had a 2 or 3 way cluster and a pair of self replicating SANs. My budget wouldnt stretch to this and I would never have had the money to add a SAN plus some new servers. I also didnt have the budget to buy 2x fully capable S2D servers (thus "binning" our existing servers + SAN) so S2D was out for me. stretch cluster will not work with "presented" drive mixed cluster sizes - take this into account if you are using large capacity drives and small capacity SSD caches - the clusters might be different - look for 512e at least. The QNAP threw 4k as a presentation REGARDLESS of what drives were in the system. This meant you would not have been able to have the QNAP as a stretch cluster drive for a SAN presenting 512e. We have an 10Gb QNAP, it is a TS-1273U RP. It is a decent NAS with good performance. It is loaded with ironwolf drives and an SSD cache - great for iscsi backups. Bad for stretch cluster, the iscsi is just not reliable enough - the IOPS were decent enough, there were quite a few dropouts when I initially tried to set up a test cluster using the QNAP as a testbed. I would not have like to put our VM infrastructure on it! As it was, I could keep the infrastructure I had, "stretch it" with a pair of new servers plus new SAN and now I have resiliency. Not only that but I can have a fire in one building and not lose my infrastructure! If SVR1 + SVR2 were to permanently be out of commission, I would need to issue a powershell command to allow SVR3 + SVR4 a vote on the cluster, 1 + 2 would be evicted at this point and would need to be "re stretched" back. Stretching 7Tb of data makes very interesting task manager data and does look good when the network card is hitting 10gbs, it took all weekend and basically throttled the VMs right back. You can artificially throttle replication speed with a powershell command, otherwise your network interlink WILL be saturated, obviously more 10Gb cards and lines is the solution if you can afford this. Our interlink is a failover pair 10Gb link at the switch level, it is not LAGd - iscsi MPIO and LAG is not a good idea so I didnt want to try Microsoft stretch and LAG. Backup is done from the hypervisor using veeam. we used to have a "cheap" QNAP file backup to quickly backup and restore user files, this was conducted from a VM. We did this because VEEAM is p*ss slow restoring when all you require are a few files. The QNAP restore was much quicker for a "I deleted my file". The QNAP is pretty much redundant now we are in onedrive and sharepoint (it actually backs up FROM sharepoint and onedrive now using boxafe, but that is a different story) Advantages of stretch cluster over S2D - Hardware is less picky, you can have completely assymetrical hardware - I do have assymetrical servers!. if you are reusing old equipment and cannot do a complete swap then stretch cluster is better. You are relying on an older set of hardware for part of your resiliency though. that being said SANs have their own resiliency built in. Expanding an S2D cannot be done without downtime, I believe you shut the whole things down and bring back up with the new drives, I could be wrong on this though! I do know that symmetry has to be perfect and im not sure how mixing cluster sizes will work. SANS are at the mercy of whatever drives you can throw in them. IF I had the money I would go with a 3 way S2D identical hardware with SSD+HDD journal/storage. For 2 nodes I would definitely nest (reducing capacity further)
  24. we stuck with 2019 datacenter as our hypervisors and put 2022 on our domain controllers. VM wise, we migrated from 2016 to 2022 on our two fileservers. Our printer server was already on 2019 so ive not migrated that. Our web server and SQL server are 2019 so I havent migrated that. We still have a legacy exchange server with one mailbox to admin hybrid and act as a relay for our UPS (the printers have 365 A1 accounts for their scan to email, god bless those 1000000 licenses I have). We arent moving to pure Azure AD so will be running in hybrid for a while. I will be migrating to server 2022 and exchange 2019 in the summer.
  25. With the help from Chris I have managed to get a working solution. Tweaks needed to be made behind the scenes (the setting was not available in the GUI) 1) We now have Staff BYOD using the regular Securly guest DNS - this worked originally and we can set the "guest policy" in securly to be lightly filtered. 2) Pupil BYOD needed a little tweaking. I was mostly there with a separate "IP policy" and our Pupil BYOD egressing on a specific public IP. What Chris needed to do is manually disable authentication on this public IP. Now I can set a more stringent filtering on this custom IP policy. This uses the "regular" securly DNS but will also need the certificate installing (unfortunate but cannot be helped). At least the securly.com/ssl page doesnt put a https cert error. I am offering that to our pupils from the wifi landing page. Notes so far. As earlier, you cannot recategorise domains internally. this is now a pain. I am up to 8 policies and we are a small school (on account of needing the separate guest policies, "games" policy allowed at lunch, staff, young pupils, older pupils). If I wish to "allow" a website, that is 8 policies I need to go into rather than a simple "recategorise internally". NOTE! I am not talking false positives, this is a genuinely categorised website that we allow (these are usually gaming websites that we allow, some for ICT etc) You can only assign a single IP to an IP policy. We have internet failover and our smartDNS will failover at the same time. this gives two potential egress IPs for our pupil BYOD policy. I need to clone (and independently update) the pupil BYOD policy. It would have been nice to allow custom IP policies to have more than one IP. You have to go to support to selectively disable authentication on policies. Not sure why this cannot be in the GUI - especially for custom IP policies. This is also not mentioned in the documentation and would have saved a lot of time - as I said earlier, I cannot be the only person to have used 2 guest WIFI "tiers"? No user lookup when adding usernames etc. A small but annoying mention. Typing a full name rather than having a user lookup (similar to how 365 works) is annoying, especially when typing a list of email addresses or when searching for our Czech and Polish staff- my spelling is not the best and the 365 autopopup is a godsend (I am actually using outlook address book to copy and paste into securly!) You cannot rename a policy. You need to clone, remap to all the groups. It is hard to locate which policies are mapped to which groups (for example if you need to clone and rename). The policy page does not give a list of what it is mapped to and the mapping page will not let you filter by policy. Since our Azure AD has teams with all our sets, we have rather a few security groups to wade through. Obviously we only use the core pupil year groups but it would be nice to have at least a filter. Safeguarding groups cannot be assigned to policies. I.e. we have younger pupils and older pupils. Separate staff cover younger and older pupils, it would be nice to have triggers sent to appropriate groups depending on the policy that triggered it. Likewise guest "triggers" sent to a separate group. I understand that auditor is a separate package but this would seem a logical decision for safeguarding. Support got back to me quite quickly and was efficient (thank you Chris). I had forgotten about my failover IPs, they were added very quickly to our account.
×
×
  • Create New...