StephenPink
Members-
Posts
333 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by StephenPink
-
Yeahhh... post-summer brain is a thing! Turns out the Dell UD22 docks DON'T support PXE boot, so have ordered some new USB-C Ethernet adapters that definitely say they DO support PXE boot... Thanks!
-
Hey all, This one's got me stumped - got some new Dell 2-in-1 devices, connected to Dell Docks and they will not show the network PXE boot option... BIOS is all updated, reset to defaults and then the following settins applied: BIOS - Advanced Setup > On - Boot Configuration ○ Enable PXE Boot Priority: Enabled - Integrated Devices ○ USB/Thunderbolt Configuration: § Enable Thunderbolt Boot Support: On - Connection ○ Enable UEFI Network Stack: § IPv6 PXE Boot > Off ○ HTTP(s) Boot Features: HTTP(s) Boot > Off IPv4 PXE Boot is definitely on, but do not get any boot options appear other than the internal hard disk. Hopefully there's just a setting that's been missed? Cheers
-
Smoothwall - Unifi - VLAN - Captive Portal
StephenPink replied to DDR5's topic in Internet Related/Filtering/Firewall
Are you using/have you configured a separate interface on the Smoothwall, for the Guest VLAN? -
Sign-in Systems - InVentry Concerns - Alternatives?
StephenPink replied to interslice's topic in Hardware
Yep we're also moving away from Inventry for the reasons most have mentioned. They don't want you to domain join - yet as you say don't monitor/manage/update - and then aren't helpful when there are security policy conflicts. My other issues was cost - the hardware is very expensive, and the same cost each time for additional displays. Sign In App is one cost - 1 display or 20 (and we have an iPad school so plenty of slightly older iPads kicking around!) and so far so good with it. Cheers -
Just to add to the other reponse as well - not sure if you're using a public or an internal cert but here is what I do for internal cert (names/IPs changed); On your CA create a new template: NPS Server Authentication Template Configured based on Microsoft guidance here: https://docs.microsoft.com/en-us/windows-server/networking/core-network-guide/cncg/server-certs/configure-the-server-certificate-template and https://directaccess.richardhicks.com/tag/certificate-authority/ for the NPS specifics. Used for server certificates, that are then automatically enrolled and deployed to required servers (NPS) Certification Authority > CA Right-click Certificate Templates > Manage Select the "RAS and IAS Server Template > Right-click > Duplicate Template: Compatibility: Certification Authority: Windows Server 2016 Certificate Recipient: Windows 10/Windows Server 2016 General: Template display name: NPS Server Authentication Template name: NPSServerAuthentication Validity period: 5 years Renewal period: 6 weeks Publish certificate in Active Directory: No Subject Name: Supply in the request: Use subject information from existing certificates for autoenrollment renewal requests: Yes Cryptography: Provider Category: Key Storage Provider Algorithm name: RSA Minimum key size: 2048 Choose which cryptographic providers can be used for requests: Requests can use any provider available on the subject's computer Request hash: SHA256 Use alternate signature format: No Request Handling: Allow private key to be exported: Yes (all else on defaults) Security: Select "DOMAIN\RAS and IAS Servers" and remove Add > "DOMAIN\NPS Servers" and choose the following permissions: Read Enroll Autoenroll OK Close Certificate Templates Certification Authority > CA Right-click Certificate Templates > New > Certificate Template to Issue Select "NPS Server Authentication" > OK NPS Server Certificate Request Perform the following steps to request a certificate for the NPS server, that is usable on both NPS Servers. NPS SERVER 1 > Certificate Management Console (certlm.msc) > Personal Right-click Certificates > All Tasks > Request New Certificate. This launches the Certificate Enrollment Wizard: Before You Begin: Next Select Certificate Enrollment Policy: Active Directory Enrollment Policy Request Certificates: Select the "NPS Server Authentication" certificate template Click "More information is required to enroll for this certificate" Subject: Subject name: Type: Common name Value: BOTHNPSSERVERS.DOMAIN.LOCAL (to cover both NPS Servers, has to be FQDN) Add Alternative name: Type: DNS Value: BOTHNPSSERVERS.DOMAIN.LOCAL (to cover both NPS Servers, has to be FQDN) Add Type: DNS Value: NPSSERVER1.DOMAIN.LOCAL (to include NPSSERVER1 , has to be FQDN) Add Type: DNS Value: NPSSERVER2.DOMAIN.LOCAL (to include NPSSERVER2 , has to be FQDN) Add General: Friendly Name: NPS Servers Description: Certificate to secure both NPS Servers for failover purposes OK Enroll This newly requested certificate then needs exporting, and then importing on NPS SERVER 2 - this is super important; it has to be the exact same certificate with the same thumbprint or else devices will notice the change if there is a failover. NPS SERVER 1 > Certificate Management Console (certlm.msc) > Personal > Certificates Right-click the "BOTHNPSSERVERS.SFCF.LOCAL" certificate > All Tasks > Export: Export private key: Yes, export the private key Export file format: Personal Information Exchange - PKCS #12 (.PFX) Include all certificates in the certification path if possible: Yes Delete the private key if the export is successful: No Export all extended properties: No Enable certificate privacy: Yes Security: Password: PASSWORD Encryption: AES256-SHA256 File name: CERTIFICATE.pfx NPS SERVER 2 > Certificate Management Console (certlm.msc) > Personal Right-click Certificates > All Tasks > Import: File name: CERTIFICATE.pfx Private key security: Password: PASSWORD Mark this key as exportable: Yes Include all extended properties: Yes Certificate store: Personal Note: This will import the ROOT CA again as well - this extra entry in the Personal store can be removed to reduce confusion
-
It's on each Network Policy - when you configure the authentication methods. If you then select the auth method, and edit, you then get a drop down to select the certificate to use. I've seen this have issues sometimes when the server has already auto-renewed the certificate in use, but then still had to go into each Network Policy, select the (already selected) renewed certificate and then OK to save it again to "complete" the replacement of the certificate Cheers
-
Hi all, Hoping someone can help. For various reasons, I'm looking to purchase ESU's for some Windows Server OS's. However, my reseller is telling me that the only way these can be purchased and used is by also paying for Azure Arc and going through that. However, according to Microsoft (How to get Extended Security Updates (ESU) for Windows Server 2012, and 2012 R2 | Microsoft Learn) you can also activate the ESUs via MAK keys. My reseller says this isn't available for Edu - but that Microsoft article implies that it should be: Anyone been able to purchase and use the ESU on Servers, without Azure Arc? Cheers
-
Nice that's pretty cool if it does! Didn't know that Good luck and let us know how it all goes
-
I'm looking at Ruckus very closely now (and about to install some ICX7850s as a core) having always used HP Procurve/Aruba previously. Price factor - specifically the ongoing licensing costs - a big deciding factor
-
As others have said, would spin up new DCs and migrate roles - easy enough to do and so not worth any potential weirdness from trying to restore/convert. Also - when restoring from Veeam does that handle the conversion? E.g the vmdk to vhdx type stuff
-
Jumping on the back of this - I'm looking at a larger UPS, again tower as no rack space - however are APC still the go to/good value? Others I've heard mentioned but would appreciate feedback on are; - Riello - Dell (rebranded APC but seem slightly cheaper - and their versions include the NIC card, and the tower mounting stand, and the rack mount kit) - Certa Cheers
-
Thank you - touch screen laptops or non-touch screen? The ones with the detachable keyboards - do you also supply pens/stylus? Cheers
-
Hey all, If you were to decide upon Mobile Windows devices for staff (or have already done so) what would (or did) you go for and why? - Laptop - 2-in-1 Laptop - Tablet (with detachable keyboard) Also interested to know and hear real world feedback and experiences regarding makes/models used, and costs. Thanks!
-
What network work was done? Depending switching/config may need to add the SCCM server IP to the DHCP/IP helper address list for the relevant VLANs
-
Not sure if the same thing, but we spotted something similar recently, for files that had been accessed through Google Classroom - according to our Google reseller, this is a Google issue. The issue is apparently that Google is now creating groups automatically for Classroom with a group that Google "manages" but it is being seen as external even though it is in our domain.
-
Google Context-Aware Access - Windows Version Control?
StephenPink replied to Shaun_Dark_Lord's topic in Cloud Services
Yeah it's very annoying - I've had to manually look up based on the info in the model field. Unfortunately, whilst our asset database is correct, this is the BYOD device information that is required for CE. Yup it's a real shame. There are some things Google does so much better than Microsoft - but Intune has come along so much recently that Google can't compete. -
Filtering and Blocking Chat AI
StephenPink replied to Berttielp's topic in AI in Education & Enterprise
Good, that's the stance I've been taking too - just wanted to check I hadn't missed A.N.Other product/technical solution that can somehow monitor AI chats.. -
Filtering and Blocking Chat AI
StephenPink replied to Berttielp's topic in AI in Education & Enterprise
I’d be interested to hear what others are using/how they are filtering and monitoring the various AI chat functionality tools out there. Especially given the recent proposed changes to KCSIE. As far as I can tell, none of the filtering products out there can do this? (Securly “cheats” and want you to redirect to their own AI chat) Cheers -
Google Context-Aware Access - Windows Version Control?
StephenPink replied to Shaun_Dark_Lord's topic in Cloud Services
I've been trying to play with this and the new Security Advisor but not super impressed so far. As far as I can tell as well for Windows devices, it will only work IF the user is signed into Chrome, with the endpoint verification extension forced OR the actual device is managed by Google Workspace. I also can't seem to export the required asset info for CE at the moment - as I need make and model, and most of the device information seems to be missing the make... -
Using Google Workspace App Access Protection - Security Advisor
StephenPink replied to StephenPink's topic in Cloud Services
Seems to be around 24 hours - however not 100% Additionally - this is being put in place as part of the BYOD technical controls required for Cyber Essentials (figured it worth mentioning for future searches). However, am definitely finding it harder to both set controls, and extract the required device information from Google Workspace, than Microsoft Intune. Would be interested to hear from anyone with CE certification, that is using Google Workspace. Cheers -
As in the title, anyone using Google Workspace App Access Protection - Security Advisor to limit BYOD access? I have a question - I've set outdated OS's to be blocked; user has then updated device, but still receives the block message. I can't seem to find information on how often Security Advisor checks for this data, and/or how to force it to be re-evaluated? Hoping someone here has been there and done that and knows! Cheers, Stephen
-
Currently trialling Action1. Been very impressed so far; as others have mentioned 200 endpoints free, forever - fully featured as well. I'm using it to meet Cyber Essentials compliance initially, and will likely then review further and potentially roll out across the college, then Trust. I looked at several others; most were similar sort of pricing (there were some outliers that were a lot more!) but the biggest thing with Action1 was the software repository - it had far more software in there that was relevant, than any others. Adobe Creative Cloud was hugely attractive. Cheers
-
Are users hitting the correct filtering policy? We've had an issue today (still waiting to hear the cause) were all our Policy Maps had disappeared - so staff were getting the Base/Default Policy instead of the Staff Policy - so e-commerce etc was blocked.
-
Helpdesk recommendations to replace Jira Service Management?
StephenPink replied to Shaun_Dark_Lord's topic in Cloud Services
We started using HaloITSM last year. Not cheap - but not expensive compared to other paid-for offerings either. We've barely scratched the surface of what it can do if I'm honest, need time to setup and deploy additional features. Pricing wise - can be per named agent, or once you reach a certain number there's a concurrent usage model that could be better value. As others mentioned - it's one price, everything included. I got so annoyed of all the others where every feature/integration suddenly was an extra cost. Also noticed a few MSPs using it - which as a MAT, seemed like a good fit (central MAT team probably operating similar to an MSP especially as the MAT grows) Cheers
