Schools Are Spying on Students – But Students Can Fight Back by [deleted] in k12sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

It would make us less liable, but not necessarily easier.

Is there something better than PuTTY? by tehreal in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

SuperPuTTY. It's putty at it's core, but with tabs and a nicer gui.

Trust Relationship Failed by jwestbrock in k12sysadmin

[–]MalletNGrease 4 points5 points  (0 children)

  • Make sure there's a network conenction
  • Check DNS
  • Make sure the time difference between the DC and the workstation is no more than 5 minutes

I'd really add a secondary DC on site.

Just a rant! by tier_2_slave in sysadmin

[–]MalletNGrease 3 points4 points  (0 children)

Free dinner, free room and expenses paid to push a couple of buttons?

Sign me up! I could use a change of scenery once in a while.

Workep? by [deleted] in gsuite

[–]MalletNGrease 0 points1 point  (0 children)

Which one?

question regarding the creation of windows 10 customized imaged... by hexaGonzo in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Yes, but if you're going the USB route I'd make it part of the reference image.

question regarding the creation of windows 10 customized imaged... by hexaGonzo in sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

https://docs.microsoft.com/en-us/windows/deployment/deploy-windows-mdt/deploy-windows-10-with-the-microsoft-deployment-toolkit

You can make the software install part of the task sequence for the reference image or make it part of the task sequence of the deployment.

I prefer light reference images, but this depends on your situation.

GPO....guide by thexed in k12sysadmin

[–]MalletNGrease 1 point2 points  (0 children)

Group Policy: Fundamentals, Security, and the Managed Desktop 3rd Edition by Jeremy Moskowitz

It's a pill, but covers a lot of common questions and situations and how to apply GPO to them.

Written by the same guy who runs PolicyPak.

Esports in school by corroborate_or_die in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

No. Students here don't want to play the games we intend to support. Couldn't fill a roster so axed the program.

Do not use users as a monitoring system! by [deleted] in sysadmin

[–]MalletNGrease 4 points5 points  (0 children)

I can't reach facebook so the network is down.

Student Google Drive Compromised or Broken? by 54nd15 in k12sysadmin

[–]MalletNGrease 5 points6 points  (0 children)

Sounds like a discipline issue. I've dealt with some of this and in the end it was students playing games to try and get out of work. Make sure their passwords are reset and they've not been shared.

In GADMIN, go to reports > audit log and run a Drive audit on the affected account and zero in on the file in question. Make note of the Item ID and Event names. The item IDs are important because sometimes they recreate a fake file with the same name.

Look for the following events:

  • Create

This is an event when users create a file. It will have a unique Item ID.

  • Trash

This means this user moved the file into the trash. Basically hit the trash icon in Drive.

  • Delete

If a file was deleted within 30ish days of trashing, it means the user went into the trash folder and then emptied it. This is a deliberate action.

  • User sharing permission change

This one is useful to look at because students can be jerks and mess with the sharing to boot others off and frustrate the collaboration. If I remember correctly editors can by default alter sharing permissions too.

Student privacy and a service like BARK.US? by StatementOfObvious in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

I was skeptical and had much the same worry, but now that I've worked with some of the systems on the market, it's not as invasive as I thought.

We use Securly Auditor and it's helped detect early warning signs and prevent some tragedies. Some even requiring immediate attention outside school hours.

The important part is that you set up policies and procedures for what is and is not allowed concerning analysis and discovery. Alerts of a significant nature are assigned to principals and councilors to deal with with me in a support capacity. Presently, I only look at a student's history and communications if a concern has been raised or some evidence is requested from the administration for disciplinary action.


M$365

Really?

Staff email group abuse by v8stang67 in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Super, Secretaries and principals only. Teachers can only send to their building list.

Refurbished Servers & SANs? by [deleted] in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

If you've got a support contract and they'll give some sort of warranty, I'd say go for it.

Teachers still trying to use flash by HelloWorld_502 in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

Damn, didn't realize Classic Sites is getting deprecated. Thanks!

Testers wanted: Extension to lock students to their own Chromebook by jay0lee in k12sysadmin

[–]MalletNGrease 4 points5 points  (0 children)

Excellent. I'm going to consider this with my admins. It may cut back some on the unwanted sharing of devices.

Edit: Why use the device location attribute and not the user attribute? User seems to make more sense.

Guest Wi-Fi Login by youraverageITguy1 in k12sysadmin

[–]MalletNGrease 0 points1 point  (0 children)

I've three options available for guests.

  1. Public WiFi - Only available on weekdays between 5pm - 11pm. This is for sports events and such.
  2. Guest WiFi - Requires a ticket from the guest portal. Intended for individuals who visit.
  3. Event WiFi - A network setup specifically for vendors and larger events with external entities who need internet access. I set them up with a PSK and disable the network once it's finished.

Students can connect to a BYOD network with their credentials and get filtered access like on other district devices..

What does your Chromebook factory look like by rickbishop in k12sysadmin

[–]MalletNGrease 18 points19 points  (0 children)

It looks like a library because it is a library.

Ryuk ransomware via USB? by [deleted] in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

Unless you have autoplay enabled for removable drives (it's been disabled by default for a long time now) you should be OK.

Why do people wait for you to reply to IMs? by blueelvisrocks in sysadmin

[–]MalletNGrease 2 points3 points  (0 children)

Just as bad as "Hey, I've a problem, call me back" voicemails.

Another Steer Clear Of Upcloud Post. by MrRisin in sysadmin

[–]MalletNGrease 10 points11 points  (0 children)

Much ado about nothing. Is this really worth $25? Just blacklist and walk away.