PlantHead
Members-
Posts
204 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by PlantHead
-
Fly-trap
-
Geneva
-
Can't view Administrative Templates in Group Policy Manager
PlantHead replied to Samm's topic in Windows Server 2012
https://support.microsoft.com/en-gb/help/2688272/wrong-error-message-for-missing-adml-files I had something similar a while ago with Chrome. I had copied the Chrome.admx with the en-GB folder to Policy definitions and then couldn't work with the policy. I ended up having to copy the en-US folder instead of the en-GB folder. -
I think the 3COM is only a layer 2 switch. If you have vlans and need to route between Vlans you are going to need a layer 3 switch which can do high speed routing at your core. I'm no expert so hopefully someone else can give you a bit more of definitive answer.
-
Use your AV (TrendMicro, Sophos, etc.) to block all removable storage devices and allow white listed USB devices - that is the easiest way.
-
You don't need to pay for it unless you want additional features, the free version is pretty much all we need to monitor server health and login to the console if there is an issue. If you don't have it setup you should, it is very useful.
-
I would also be interested in this We are largely WCBS at the moment and it is really a bad product.
-
You need to use conditional access which only comes with a P1 license if you want to have trusted IP's.
-
We have Ruckus and BYOD policy. Setup Radius for authentication and then forward all accounting information to your firewall so you can report on it and track potential VPNs, which are always a problem. We have 1 pupil SSID, with client isolation switched on. Deep packet inspection is the big problem - getting certificates onto each BYOD device is a real pain. We have a webpage handed out from our firewall for BYOD devices but it is far from a perfect solution. I would like to force intune or similar onto each client that attaches to our network but that is quite a step for the school to get its head around.
-
Parliament
-
Alan Turing
-
Scrotum
-
TrendMicro on the desktops and defender on the servers. Trendmicro was pretty cheap and the admin side over the last year has really improved, all cloud based too.
-
Just going through tenders for a new phone system now - we are edging towards a hosted VOIP system with a mirror in the cloud for DR purposes.
-
Setup the same VLAN as your Guest WIFI on your firewall and have the firewall hand out DHCP addresses and forward DNS requests externally for that subnet.
-
SSD's do fail though and they tend to fail instantly without any warning. If the data is important and you can't afford the downtime then it is still best to implement RAID. If it is the difference between rebuilding a server from backup or just changing a disk, I go with the disk change every time.
-
[sims] Can you safely shrink SIMS DB in SQL Manager
PlantHead replied to robjduk's topic in MIS Systems
Generally it is a bad idea to shrink SQL databases. If you use DBCC to shrink the DB you will end up with heavily fragmented tables which will effect performance. Why do you need to shrink the DB? Space on the server? -
2 Hyper- or Vmware host servers with enough RAM to be able to run all servers on 1 host for failover I would probably go for a physical SAN infrastructure but do your reading on VSAN's before you decide. I would virtualise 1 DC (HyperV or VMWare) and still keep a physical on an old box that I wouldn't worry about backing up. There isn't much point in having 2 virtual DC's if they both use the same shared hardware and you want to make sure you always have access to a DC if the virtual hosts go down. Virtualise the File Servers and maybe even cluster them across both virtual hosts - depends on how much downtime you can take. If you are mainly windows servers I would look at backing everything up to Azure to cover off-site backups - I would stage the backup to an onsite server first but probably not to my virtual environment because of performance.
-
You need to setup default associations. You can do it through GPO, Adobe give you some templates and examples to do what you want. https://www.adobe.com/devnet-docs/acrobatetk/tools/AdminGuide/pdfviewer.html#solution-2-gpo-policy
-
Still issues authenticating here. Phone authentication goes no where and the authentication app gave several wrong responses.
-
https://www.theregister.co.uk/2018/11/19/azure_down/ [h=1]Azure goes super-secure: Multi-factor authentication is borked in Europe and Asia[/h]
-
GFX heavy applications mainly - Photography, creative media and music are the main problem apps.
-
As already said, it is a mentality thing. If you switch to Chromebooks you need to promote it and encourage the teachers to use new applications. There is an alternative to pretty much any windows app available to be run with a Chromebook. If you think the teachers and school will be resistant to changing the way they work then don't go with Chromebooks. We are currently moving away from Chromebooks because the teachers couldn't get on with them.
-
It is a school requirement that all software conform to GDPR in that there should be a bulk user deletion tool or a user anoymisation tool. As a basic requirement it should be simple and quick to search for user data and be able to delete it, or produce a report on it. We are also looking for a hosted solution. Thanks for the reply though.
-
We're going through the same process of trying to identify a new helpdesk system for IT and for our estates team. The problem we have with OSticket is that they don't seem to be aware of GDPR or acknowledge any need to make their software compliant. Its a shame because when we trialed it we liked it. At the moment we are looking at Freshdesk/service, which is meeting most of our reqs.
