Jump to content

dylanm

Members
  • Posts

    34
  • Joined

  • Last visited

Everything posted by dylanm

  1. We set up 2x SSIDs (one for staff and one for students) with a 64-character WPA2/WPA3 pre-shared key. It's certainly not as secure as a radius solution but as long as you are able to lock that password down (eg. Applocker to block netsh for all users, not sharing the password with users, etc) it should do the job. The time it would take to crack a 64-character password from a de-authentication attack is effectively astronomical (as long as it's totally random with numbers, symbols etc). This is not the best way from a security preservative though - If you're able to, go with the radius/PKI solution! You can build a "cloud radius" like solution using software/solutions such as freeRadius and a Windows Server CA with the Intune Certificate Connector and a Windows NDES server. Microsoft has recently released a Microsoft Cloud PKI within Intune as a paid add-on so this could replace the Windows Server CA with the Intune Certificate Connector & NDES part. You're not going to be able to use a Windows RADIUS server though as it requires AD accounts for each device so solutions such as Aruba Clearpass/Cisco ISE/freeRadius would need to be used instead. Hope this helps!
  2. Yes - Usually have an OpenVPN client installed on the server/vm to set up the connection back to their data centre and then a funky bit of software to install the sims client. I haven't had that much experience with it but seems to be a very bouched-together solution...
  3. Hi, We currently have around 6 schools with individual SIMS Connected Third-Party Connectors in place at each of the schools. We are looking to decommission the servers at each of the schools however the third-party connectors are still running on these servers. We would like to consolidate all of these third-party connectors into one virtual machine/server that we can host centrally at the Trust. Does anyone know if this is supported? Thanks in advanced!
  4. Give this box a tick within Intune and it should enable the Proactive Remediation (if I remember correctly).
  5. Give this a try: https://github.com/dylanmccrimmon/IntuneProactiveRemediations/tree/main/Repository/DigitalLicense Download the two scripts and import them/create a proactive remediation within Intune.
  6. I'm sure it will be okay however would do testing first. Should be fine as your devices have come with the license already (you paid for the license when you bought your device) however I'm not the best when it comes to Microsoft licensing & the fine print so I would say to speak to your Microsoft licensing reseller/supplier (if you have one).
  7. So the way the A3 Win 10/11 licensing works is that it "upgrades" the device to either Education or Enterprise depending on the embedded device license. A few examples below + diagram: Scenario: The device comes with an embedded Windows 10 for Education Pro license and a user with an A3 license user logs in. Outcome: The device will upgrade itself to Windows 10 for Education. Scenario: The device comes with an embedded Windows 10 Pro license and a user with an A3 license user logs in. Outcome: The device will upgrade itself to Windows 10 for Enterprise. Scenario: The device comes with an embedded Windows 10 for Education license and a user with an A3 license user logs in. Outcome: The device will stay on Windows 10 for Education. Scenario: The device comes with an embedded Windows 10 Home license and a user with an A3 license user logs in. Outcome: The device will stay on Windows 10 Home. Scenario: The device doesn't come with an embedded license and a user with an A3 license user logs in. Outcome: The device will remain unactivated until activated with a product key. Note, if the device has come with an embedded license but Windows is showing as unactivated, the A3 license will not take effect. You will need to extract the embedded license key and then activate Windows. I have a proactive remediation (that you can import into Intune) that will do this for you, all it does is extract the key and activate Windows + report the status based on a 1 or 0 return value (IntuneProactiveRemediations/Repository/DigitalLicense/). Microsoft has further guidance on subscription activation here that goes into a bit more detail. Hope this helps!
  8. As foofihhterjim mentioned, it relies on the device having a product key in the TPM chip/main board. For the A3 license to work, you will also need to use/have Windows 10 Education Pro installed on the devices. The A3 license upgrades the OS to then use Windows 10 Education. Here is a good article on the A3 license: https://learn.microsoft.com/en-us/windows/deployment/windows-10-subscription-activation You can also push out a script/proactive remediation in Intune to check for the product key and then activate windows if one is installed.
  9. From the sounds of it, you have 4 cores (2 pairs). Using the light trick works nicely to see if there is a physical break in the fibre-optic cable. Side note, there is a great tool on Amazon for visually checking fiber cores: https://amzn.eu/d/4KSIBrv What you could do is check how many of the cores are broken. As long as you have a minimum of two cores working from either pair of fibres you can get away with taking a core from each fiber if that make sense? This will get you up and running on the fiber temporary. If you only have one core working out of the all of the cores then unfortunately, I think your out of luck. We have a awesome cabling team that does our fiber and cable installations that I can get you in touch with (they are based in Essex but are pretty much national). They can run you a new fibers or re-splice the cable (if it is possible). PM me if you want more details.
  10. There’s nothing stopping me now - I use port 443 on my vpn server to bypass the LGfL firewall and tunnel all my traffic. Works great to get round the filtering and port blocking issues that LGfL has. So by blocking all outbound ports on the LGfL network isn’t blocking the stuff you guys was trying to block in the first place... however I do understand why it's done but I think it is too aggressive. For example, LGfL blocks all Cisco Meraki ports even though it's one of LGfL's offerings... as well as educational software - SQUID, B Squared, Third Space Learning to name a few. Just wished that LGfL would keep up with these new technologies and not be a ISP that is restrictive to the point where we have to raise a ticket each time we want to use something new or allow software to work. Even if there was a button in the support site to allow the most common ports open, I would be happy. Apologies for the rant,
  11. Filtering? Do you mean web filtering?
  12. Sounds like you want to use the splash page login with sign-on. For that to work, you're going to need to open up some firewall ports (at your school) to enable Meraki's servers to communicate to your NPS server at your school. While you can do this and it will work, just be aware that there is no encryption or at least very poor encryption between Meraki and your NPS server - This RADIUS traffic/data travels across the internet and is not internal all internal... Meraki has a guide on how to set it up - See here
  13. See Attached - Our guest SSID uses sponsored login so the guest put's in their name & email address and then the email address of a member of staff at the school. An approval email gets sent to the member of staff at the school who approves access and job done. Just one thing to be careful of is that if students have a school email address that is using the same domain as the staff. You should block emails from Meraki for these students. This will stop students from being able to join their devices to the WiFi. Meraki - Guest Config.pdf
  14. No problem! - Happy to be able to help. We did use the slash page and the members of staff would have had to accept an agreement however it became very annoying for staff as they had to keep agreeing to it - there was no option for a “one off” splash page for each device and it had to have a frequency of days between each acceptance (from memory the maximum amount of days you could set was 90). Therefore we decided to just remove the splash page. There is also an option to have the authenticate users with active directory from the splash page instead of the usual 802.1X way in however we shyed away from this as there wasn’t any encryption (or at least very poor encryption) between Meraki’s servers and our NPS server meaning that all the RADIUS traffic would of been unencrypted / very poorly encrypted across the internet. We do we a splash page/splash page authentication for our guest network and I’m happy to send you the config for it if you want?
  15. I've attached the configs/screenshots for both Meraki and NPS. Just as a heads up - If you are running NPS on Windows server 2019 and above, you will need to run the below otherwise you will get some issues with NPS and the windows firewall 1. Run sc sidtype IAS unrestricted in terminal/cmd as an administrator on the NPS server. 2. Reboot the server. If you are using the config I have attached - All you gotta do is run copy it to your NPS server and the import it via PowerShell or the NPS interface. Then go in and change the following: 1. Change the IP address in the RADIUS clients to your schools IP range or IP range of the VLANs that the WAPS uses. 2. Change the shared secret to a random long string (you will need to add this to Cisco Meraki as well). 3. Change the windows group to a group in your active directory (I like creating a group just for BYOD and then adding the all staff group to that group; It give a little more control if students need to use it or if there was a guest account that isn't a staff member etc). 4. In the call station ID, enter the SSID name of your schools BYOD SSID after the : (for example our BYOD SSID is 'WBPS - BYOD' so the value should be '.*.:WBPS - BYOD'). 5. If you haven't already - register the NPS with active directory. Hope this helps you NPS.zip
  16. Yes - There is three ways that I can think of off the top of my head. 1. You can use the Google Cloud Directory Sync with the Google Password Sync to sync over the users from your existing Active Directory. This will automatically create accounts, disable accounts, groups, password sync (only when the user changes the password on a AD computer - Its a one way sync (AD -> Google)) etc. You can then set the policies for the Chromebooks to auto complete the domain for the students (see the below screenshot). 2. If users already have an Office 365 account and your school has Azure AD sync (not required by makes the whole SSO idea better and seamless), then you can do is single sign in into Google from Office 365. For example, if a user was to sign into Google Drive, they would be redirected to a Microsoft login page to login, then once logged in, they will be redirected back to the application.This also works for logging into Chromebooks. The only downside to this is that the user needs to type their username in twice, once for Google (to check if they need to be redirected to Microsoft to sign in) and once again for Microsoft. In theory, when students are logging into Chromebooks they will be authenticated with both Microsoft and Google so if the users was to browse to Outlook on a Chromebook, they will not be prompted to sign in again. Google has a great guide on how to set this up - https://cloud.google.com/architecture/identity/federating-gcp-with-azure-ad-configuring-provisioning-and-single-sign-on 3. You could opt for the Wonde to handle the sign in, students are issued with Emoji passwords and magic badges (QR codes) where they can scan their magic badge with the webcam on the Chromebook. More info here: https://www.wonde.com/single-sign-on We have implemented the Azure to Google (option 2) in a few schools and it works quite well, it has no reliance on local infrastructure (local syncs from on-prem AD) and it is cloud native. Given the way that technology is moving (Microsoft moving towards Intune), I would opt for this way of doing it. However, the Google Cloud Directory Sync with the Google Password Sync also works well and something that we have implemented in a few schools. The Wonde solution is okay (something that I have never used) but this is something that comes at a yearly cost and isn't free like the aforementioned. Hope this helps in some way
  17. Wonde are pretty good - They can provide you with a sandbox like environment / fake data. If I was building or using the product, I would prefer to use Wonde (both as a developer and school tech) as it allows the school to control what data is being sent to your application (eg. filter students where parents haven't consented to their kids data being used to other systems) and plus they have a unified API for multiple MIS's so you don't have to write a different code base for each MIS.
  18. To make it even easier, you should be able to import the Chrome ADMX templates directly into intune now. You can download Chromes ADMX template from: http:// https://chromeenterprise.google/intl/en_uk/browser/download/ (select the windows download and it will be in a folder called configurations. Google also has a nice handy guide on doing all of the above (adding ADMX to Intune etc). http:// https://support.google.com/chrome/a/answer/9102677?hl=en#zippy=
  19. Use Autopilot - Best way I have found. If you doing it manually you can do the below oversize MDT is my go to: - Create the Autopilot profile. - Download the json Autopilot profile via Powershell. - Re-Install Windows (This way you remove all the OEM crap from the OS). - The copy over the Autopilot profile (JSON file that has been exported via Powershell) to C:\Windows\Provisioning\Autopilot\AutopilotConfigurationFile.json - Make sure this step is completed before connecting the device to the network/internet. If your doing a mass deployment you can use this method with MDT or SCCM. More information on the above can be found here: https://docs.microsoft.com/en-us/mem/autopilot/existing-devices We've done this for quite a few schools now via MDT and it works quite well. Autopilot auto names the device for us in-which add's it to the correct group automatically and then applys relevant settings, apps and configs apply based off the group.
  20. Yeah, just add it in the task sequence, it didn't break anything for me and you can always change it back if need be. Microsoft did realise a hot fix that is supposed to fix this so I would recommend installing the hot fix first - https://support.microsoft.com/en-us/topic/windows-10-deployments-fail-with-microsoft-deployment-toolkit-on-computers-with-bios-type-firmware-70557b0b-6be3-81d2-556f-b313e29e2cb7
  21. I just deleted all of the partitions on the SSD and that done the trick of me Win 10 2004 ADK has the issue that I had - have a look at this guide as well (https://deploymentresearch.com/making-mdt-work-with-windows-adk-2004-for-bios-machines/). It talks about MDT but SCCM uses the MDT backend.
  22. Hmm, I encountered a similar issue when doing one of the Geo books thinking about it. The way I got round it was to format the disk using Hirens boot CD on a USB to clear any existing partitions and then imaged it via PXE. What ADK are you running in SCCM/MDT? I had a problem last year when reimagining a school and the ADK wasn't able to detect if the computer has a BIOS or UEFI firmware. https://deploymentresearch.com/making-mdt-work-with-windows-adk-2004-for-bios-machines/
  23. I've done this a few times in the past and I've used GoodSync to copy the data over to shared drives in Google Drive. Comes with a nice UI and also verifies that all of the data in each file has been copied over successfully. You can also copy over time stamps etc. If you have got a ton of folders it takes some time to create them but other then that I have no problems with it.
  24. I had to image about 50 of these Geobooks when the school ordered them from the DfE and none of them was PXE bootable. In the end, I created a few blank Windows 10 bootable USBs and then replaced the boot.wim with the bootable WIM image from WDS onto the USB. Boot the Geobooks from the bootable USB stick (with a USB network adapter plugged in), it then picks up your MDT/SCCM. Then removed the USB to stop MDT getting confused (MDT run in memory once booted). Not sure if this helps you but it worked for me PS - You may want to use DoubleDriver to export all of the drivers from one of the working Geobooks and putting these into MDT/SCCM or you could try downloading the drivers from GEO. I had tones of missing drivers when I imaged them.
  25. In the BIOS of the laptop, try changing the storage controller mode from RAID to ACHI mode. When I had RAID mode turned on, I had all sorts of issues including BitLocker and imaging them.
×
×
  • Create New...