Jump to content

psynegy

Members
  • Posts

    132
  • Joined

  • Last visited

Everything posted by psynegy

  1. I'm not sure how typical this is, but our estate is large and sprawling, many separate buildings have been added over the years. We have 33 switches total, 8 of which are long overdue replacement have been marked EOL by the manufacturer. Our most recent purchase of 3 switches, only maybe barely meet the DfE standards and was already an eyewatering purchase to say the least (a mixture of the Aruba 6200M and F series for those interested). It's a tough sell to say we need to replace something that cost £300 15 years ago, with something that costs £3000 now, and will bring no immediately tangible end-user benefits. (Beyond feeling all safe and secure from those mean EOL switch firmware hackers...!) Centralised management is not attainable in our budget, nor do we really see it as being necessary given the lack of changes we regularly push out. Unfortunately the centralised option for our Aruba 2930F's which make up 20 of our switches was not fit for purpose anyway. Luckily a few powershell scripts here and there makes bulk updates fairly trivial. DfE standards have been helpful in convincing SLT that spending £1k now, will only mean we still have to spend an additional £3k later when say we want to update the wireless access points. Also helpful has been the CyberEssentials framework which by it's very name implies it's the minimum standards we should be meeting. I would love to entertain the idea of the new enterprise Ubiquiti switching, but because of the number of cabs we have up on walls, they're just physically too deep to fit in the majority of locations, and the smaller switches aren't even close to DfE standards compliant.
  2. Applocker perhaps? Can't think of other reasons why it would only work for Administrators. Check the AppLocker event logs. Also, I know there were some changes in I think W11 22H2 to the DisplaySwitch executable; it no longer accepts the sensibly named command line parameters, so if your shortcuts used parameters you will need to update them accordingly: 1 = /internal 2 = /clone 3 = /extend 4 = /external Example to clone: DisplaySwitch 2 I'm sure there was a very good reason for this entirely unnecessary and un-documented obfuscation...
  3. I'm not sure about the vulnerability bit, you seem to get *most* of the vulnerability management stuff in P1: Compare Microsoft Defender Vulnerability Management plans and capabilities - Microsoft Defender Vulnerability Management | Microsoft Learn If you assume your GPO applies evenly across the estate, then the security baseline assessment need only be on one machine I suppose...
  4. We're looking at ditching a few 3rd party systems (phishing, AV, vuln scanning) and supplementing our A3 licences with A5 Security. That gives us P2 defender for endpoint for staff, and then add some device licences and we've got Defender P2 for students too - great! What I'm not so clear on, is the server licencing. We're told that if we want P2 for server, we have to buy that through Azure, which it looks like you have to Arc the server first, which is fine, but the costs then seem to be eye-watering... Defender P2 for Server: £11 per server per month. Even if we whittled down a server or two, we're still looking at minimum 12, so £1,584 per year... Do we just settle for P1 for servers, and P2 the "important ones" (hosts & DCs), is P2 necessary at all? Or have we missed something blindly obvious? Thanks!
  5. Whilst I agree this is to the letter of the DfE standards (is it guidance or …?) there is a practical consideration that instead they just turn off WiFi and use 5G. Where students are concerned there’s a parental consent/control element that comes into play, but what if the kid stands outside of Costa on the way home and uses their WiFi? I do wonder if parental consent for “Costa” style WiFi access is going to be the only sane way forward here. Any reports of abuse or credential sharing and they receive a ban. Simple, cheap and parents can choose. You could still make best efforts on filtering and monitoring, but honestly, unless you’re inspecting, you’re never going to stop a well disguised HTTPS tunnelled VPN. When 5G, VPNs or WiFi from next door render the whole thing meaningless, beyond a yes/no from parents, I don’t see the point in making everyone’s lives way harder than they need to be.
  6. Will the stripping of ECH from DNS be a packet modification type affair or require us to use Smoothwall as a DNS relay? What do you do in those scenarios? "Sorry kids - no vaccinations today!" ?
  7. We've been looking on and off for months now at replacing our MSCHAPv2/PEAP/802.1x wireless network security with something like Cloudpath MPSK/DPSK enrolment. We do not currently HTTPS inspect our BYOD network. We had decided to put it to bed for now due to the eyewatering licencing costs and rumoured potential merging of Ruckus One and Cloudpath, but the recent ECH (Encrypted Client Hello) email from Smoothwall has brought it back to the front of the queue. Paraphrasing slightly, but our interpretation of the information from Smoothwall was that unless you are doing HTTPS inspection - you're either going to lose access chunks of the internet (by blocking ECH) - or you're not going to be filtering/monitoring appropriately (by allowing ECH traffic). So as far as we can tell, we have a few options: Bye bye BYOD - very unpopular with our staff and sixth form - we have terrible phone signal here Cloudpath enrolment SSID with certificate based enrolment, and bundle in our Smoothwall decryption cert - expensive and cumbersome to use - and impossible to use for visitors without administrative access to device(?). Lots of support calls. Continue with PEAP, but tell people they must install the certificate from /getmitm - continued loss of access for newer devices due to MSCHAPv2/PEAP deprecation - same issues as option 2, but free. Lots of support calls. Our only totally radical idea thus far has been to provide basic DNS filtering (if that's even a thing any more with DNS over TLS/HTTPS??) but only provide access with parental consent. We don't think this is a go-er due to incompatibility with DfE requirements however: Which brings up another question - how can we satisfy the filtering requirement for visitors who turn up with laptops that they don't have administrative access to install root certificates? I have to say - the thought of installing root certificates on peoples personal devices gives me the heebie-jeebies. Think of how much money root certification authorities put into securing their private keys... there's a reason for that! I certainly don't want to have to tell parents that their children's devices all have compromised security because we got ransomwared and they took our certificate keys! Is anyone using Intune for BYOD? It would certainly make deploying Wi-Fi configuration and the inspection certificates easier - does raise other concerns around privacy and security of course. I don't give it long before something like this comes along and we're back to square one... What are your plans for meeting these DfE and technical requirements that are seemingly at odds?
  8. psynegy

    Bypass Tray

    We're a Windows AD + PaperCut + Toshiba Copier environment, and we have a very annoying issue where sometimes documents are sent to print from the bypass tray. We haven't been able to narrow down how or why this happens, some documents in applications like photoshop seem to be defaulted to the bypass tray. What we find is that a student will send this job, it doesn't come out, they walk away and then the copier is effectively jammed until someone that knows how to delete a job comes along to save the day. We already use PaperCut to prevent non A4/A3 and non 'plain paper' jobs - but there's no way I've found to do anything with source tray as that's a driver level feature as I understand it. Our supplier has given us two options: do as we currently do, or have the copier delete jobs when papercut is logged out. We tried this option, but found this caused even more complaints from staff that were half way through jobs, and either they would log out, or the copier would time them out. Has anyone else had a similar issue and found a magical unicorn solution?
  9. What are people buying switch wise these days, how much are you spending per switch? Are you meeting DfE standards with these purchases? DfE standards:
  10. We get a number of requests from students and staff trying to use their Entra credentials to log into various websites. We've largely ignored them unless they're websites that the school has a relationship with, but it feels that we are possibly being unnecessarily restrictive. Take typing.com for example, it's a free website that helps students learn to type, sounds great! From our perspective, having students sign in with their Entra account is also great, it means we're automatically securing their account on that website with our policies and it means they don't come and ask us what their password they set 2 years ago for typing.com is. We also require them to click sign in with MS on all our school purchased systems, so you can see why they would be drawn to it. With everything we have to do regarding DPIA for companies that we send data to, would we need to complete some sort of assessment for sites like this? The permissions they request are fairly vague, and I can't reason from the terminology if I'm approving the application to read the data of all users, or just the ones that have ever used the website to sign in. It says "read the profile of signed-in users" and "maintain access to data you have given it", but also says "this app will get access to the specified resources for all users in your organisation... Assuming it does only provide the information for users that use the system, I would have thought that the data we would be providing would be no more than they would be required to enter themselves to sign up with a password? What do you do in this scenario? Do you have a policy to cover this sort of request?
  11. Expect to have some SOLUS pain - possibly forevermore... We did a domain rename (SHOCK HORROR!) and SOLUS was never quite the same again, having to select the domain each time. Support gave up trying to fix it... It was functional enough... to migrate to a different MIS. You'll need to push out updated ini's with new server addresses. Other than that, I don't think it was too bad.
  12. Moving to a new AD domain, or performing a domain rename?
  13. That sounds exactly like what we want! We'll persevere through them telling us it's not possible then! Yeah, we'll give you a shout if we get stuck! Thanks
  14. What's everyone using for wireless BYOD authentication these days? We're still on MSCHAPv2 with RADIUS accounting to Smoothwall. Obviously MSCHAPv2 has had it's day, and needs to be replaced. We've been looking at Ruckus CloudPath as an option, but we aren't crazy about having to ask staff/students/visitors to download apps/executables/profiles that install root certificate authorities on BYOD devices. There's the option of some sort of DPSK/MPSK assignment, but we've been led to believe that can't work with RADIUS accounting for Smoothwall(?) and that's obviously more management for IT to handle. Any ideas or thoughts appreciated!
  15. Can't deny print management without also denying print sadly... I suppose I could just remove permission from the group rather than explicitly deny... Sigh.
  16. One of our admins just logged into an MDM device that uses Print Deploy, and once again our printer shares have become unshared! So annoying! Has there been any progress on finding the cause of this?
  17. I've been assured an update to fix this will be released imminently.
  18. I've been contacting the IT departments at schools where we've received screenshots for, to hand over what evidence we have. Much more powerful ammunition in their hands than ours.
  19. My colleague was the one affected for a while, and what we did was put a deny permission on the printer share for their user, and that "resolved" the issue for the time being.
  20. We submitted a ticket, but they insisted on needing logs, and I haven't been able to reproduce the issue since. Hopefully the more people report this, the more likely they are to take it seriously. It may well be a Windows bug, but I think PaperCut have to be the people to determine that, and I'm certain they've got a red phone with "Microsoft" written on it somewhere.
  21. We've been experiencing this issue. Very frustrating. Will also report to PaperCut.
  22. I asked for explicit confirmation that they were not treating the issue as a data breach and received the following:
  23. I will be taking the same action. Truly appalling response from ClassCharts.
  24. I've had an email from CC stating "There is no evidence of a malicious attack or data breach." I cannot see how they can possibly treat this as anything other than a data breach.
  25. psynegy

    Car Wheel

    Did they put the wrong size tyre on? Only other thing I can think is that they put the balancing weight on in a place that interferes with the brake disk cover... It should be fairly obvious if that is the case as there will be a nice shiny metal line across the balancing weight on the inside of the rim.
×
×
  • Create New...