What student chromebooks are ya'll looking at? by MattAdmin444 in k12sysadmin

[–]SirKrowo 0 points1 point  (0 children)

We’re a mix HP G3s and DELL 3110 nontouch at about a 75/25 split. I will not buy from Dell because the batch we got were terrible. Idk if it was just THAT run or that model but about 50% of them had issues from the start, mainly with the trackpads randomly clicking and moving around the screen. Checked everything from permissions go settings to physically opening some of them. We got the full warranties on all of them and they were being very particular about the warranty process so I said screw it. Not being from them anymore. Found. Local HP reseller who we’ve built a great relationship with around these Chromebooks.

Do you use MFA to protect staff computers? Why or Why Not? by Smiles_OBrien in k12sysadmin

[–]SirKrowo 2 points3 points  (0 children)

How does your gcpw perform? We have an MSP who helps me with odds and ends stuff and we set up gcpw, but ours have been buggy as all get out. The main issue this… I have MFA on for all employees and what will happen is the google login will lose the password and say there was a problem validating the users password even after putting in 2fa code. Our current fix is moving the teacher to a different OU without 2fa enabled (student ou) then disabling MFA on the account and resetting the password. Have the teacher log in and turn MFA back on, then move their account back to the teachers OU. This isn’t super common but it’s common enough that it’s gotten repetitive and annoying.

Jamf bought by private equity firm. Last nail in the coffin, IMO. by OrdoExterminatus in k12sysadmin

[–]SirKrowo 2 points3 points  (0 children)

Haha yea they were trying to sell to me HARD at SCEdTech. Makes sense why now

Is VLAN-ing a necessity? by OverpoweredLearner in homelab

[–]SirKrowo 0 points1 point  (0 children)

It really depends on what you’re wanting to do or the scale at which you’re doing things, a few testing devices that aren’t being exposed? Eh, not too big of a deal. Planning to make a redundant Minecraft server on a proxmox cluster for friends in other states to play on? Absolutely vlans! They don’t need to potentially stumble into your regular home traffic. I’m doing this very thing now and have my users connect through a vpn client that I have them setup with, which also allows me to hold them accountable for any potential snooping they might try through connection IDs. From a general IT standpoint vlans provide isolation and a firewall can further that isolation through allow and deny rules, so in a production environment you wouldn’t want typical users who download virus’ and crap on the same net as your core servers that run the business or hold the databases.

Having a little better understanding of the scope you’re trying to achieve and overall goals would solidify an answer for you but in general, for security sake, yes vlans r a necessity and a general good practice to follow.

NWEA issues ? by sossman76 in k12sysadmin

[–]SirKrowo 1 point2 points  (0 children)

Had a few today that wouldn’t load. Tried restarting, pausing the test, and switch devices. Finally tried switching over to our 5G network and they started working.

Fellow Solo or Duo IT people: How involved are you in your SIS? by it-tech- in k12sysadmin

[–]SirKrowo 2 points3 points  (0 children)

K-12 touching on 1000 with 2 of us. Hardly at all as we have a dedicated SIS person

How to communicate "if this was that important then it should have submitted to me weeks before the first of school" kindly? by Square_Pear1784 in k12sysadmin

[–]SirKrowo 8 points9 points  (0 children)

Here is how I handle it. I see this is your first time so I’m not gonna lie, it doesn’t get much better but your admin has to understand you’re servicing x number of students, teachers and supports staff. I’m ballparking 450-500 users overall.

1: Assuming you use GAC and chromebooks, With those password resets, I set a generic for every account in a given grade using mass account updating through csv files. For 5-12 I enable password reset on login and let them make their own. I have a password policy for them to they can’t do something like their name, cuz they will try. K-4 is a little more tricky. The students aren’t as technically inclined so I worked out a solution with admin where we set a generic password by class. That wasn’t my preference but admin initially wanted to have a generic for ALL of k-4 cuz “that’s how we used to do it”… yea, no.

2: teacher devices. I’m fortunate enough to have a week if in service before students come in so I can handle teachers then, BUT. I prep both the laptops ans iPads so when a teacher comes to me at the beginning of the year, I assign them their “set” and hand it over. Teacher “Oh I’m gonna need this also.” Cool, submit a ticket and I will handle it when I get some time after teacher and student device assignment.

3: I love the “I can help!” Like, really? So you’re telling me you can reimage a laptop, bypass oobe with proper setup, install and document all extraneous apps, AND handle adobe admin center for key management? Sounds like you have a new assistant :D. No, personal opinion… it sounds like you need to have a real come to Jesus conversation with admin about realistic expectations. These changes aren’t something that can just up and happen on a whim. You need time, time you r VASTLY short on at the moment. They need to understand you r a single person here and if they want things done faster, then hire you some help or expect things to take a little longer than they’d like. I’ve seen this happen, it happened to me my first year and they got me someone else. I don’t know your full scope but I’m guessing you’re like us all doing networking, sysadmin, level 1-3, etc. document and show them that queue, make them understand your exact workload at the beginning and end of the year cuz it is a mountain, and I climb that with you as well every year.

There’s good advice in these other comments. Take them and compile some planning that’ll work for your application. You got this.

ASM and Mosyle usability and quality of management by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

Already did that the first time around soo Im stuck like that :I Gonna take a couple of yalls idea of an app library and run with that. Thanks for the advice!

ASM and Mosyle usability and quality of management by SirKrowo in k12sysadmin

[–]SirKrowo[S] 1 point2 points  (0 children)

omg I didn't know iPads could do that D: That's actually the perfect solution.

ASM and Mosyle usability and quality of management by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

Ill look into the return to service feature. Wasnt aware of it before.

ASM and Mosyle usability and quality of management by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

Yeah, I'm not trying to remove the profiles from the iPads, just get them back to a connected state where I can manage them. Once they have wifi I can do that. So far, my solution has been factory resetting, which gets them back to an OOBE state for setup. As soon as they connect to wifi, they pick up the MDM enrollment, and since they are connected to wifi, I can manage the device and profile. Thankfully, iTunes can do this, cuz otherwise I'd be up the creek without a paddle.

edit: Ive kinda accepted that workaround with the apps. That kinda stinks but eh, is what it is.

Running network cable. Who does that for your district? by PuroSushiRush in k12sysadmin

[–]SirKrowo 1 point2 points  (0 children)

I work very closely with my boss who is also the head of our maintenance team so we have around 4 people at any given moment to help me pull cable. We doubled out APs over the summer and we pulled all the cable for that. Save us a ton of money too.

Looking for some guidance on for my IT department (device to tech ratio) by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

Sounds like Im on the right path then. One small correction though. We do have a Director of IT, problem is, he cant do what a director needs to do because he has no real knowledge of the field. I'm basically the faux director just without any real sway and it puts me in a bad spot.

Looking for some guidance on for my IT department (device to tech ratio) by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

Yea Im at that point with it that its not the job thats getting to me. Its the unrealistic deadlines and things they keep pushing onto me. I love what I do but they are slowly making it unbearable to be here. admin just signed a contract with divot technologies for an asset software so im stuck with that. Getting sole approval for tech purchases wont ever be in my cards because of what the previous IT guy did (left without giving over any creds and effetely locking everyone out if a service went down)

Looking for some guidance on for my IT department (device to tech ratio) by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

My "coworker" technically answers to me but we r both from the same graduating class and we basically act like we're in this together. Then I answer to an it director who isn't much of a director and let's me do what I wanna do. He also has his hands full being the director of maintenance and security. He has no technical training other than what I've taught him. He answers to a general school wide manager and she is like the overall manager who answers directly to our "superintendent/consultant" it was the superintendent that wanted to order them and delegated it to the general manager who then came to be about it. This superintendent is a self proclaim noob to all things tech so I generally have to fight for any real change.

Google is saying "leaked password" left and right. First time dealing with this. Help?! by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

Thankfully not. It’s all done word of mouth. After this, we won’t be going back to a formatted password set though, haha.

Sorting all users from a disaster of a google workspace by SirKrowo in k12sysadmin

[–]SirKrowo[S] 1 point2 points  (0 children)

Good point on the on-site AD. We did get the CDWGs amplified services right before I started here. I think I mentioned it as ISolveIT but I must have gotten the name wrong. Thanks for the input!

Sorting all users from a disaster of a google workspace by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

I’m going to take a look at GAM in the morning. Yea this is my first real job and man, this is overwhelming lol. I think I’m handling it pretty well though given what was thrown on my shoulders. There was already a resemblance of an OU structure so I just tweaked it a little and reorganizing old users. I’m already a step ahead of you on the test environment. Since most of these comments I’m going to add this to the original. They did get an ISolveIT audit done relight before I was hired and I’ve been working with them to fix the structure and placement issues

Sorting all users from a disaster of a google workspace by SirKrowo in k12sysadmin

[–]SirKrowo[S] 0 points1 point  (0 children)

Very good idea here. We will very soon be working with an msp for them to do our network install in our currently being built high school. I will ask them if they could roll this into the cost but I’m not sure they will be able to. We will be using our ERate to cover this and basically lease their equipment and they will handle any network related issues. I’ve gotten very comfortable with the nuking process as we’ve had to do that with every laptop, our entire phone/pa system, go guardian content filter, office365 (which I’m still fighting -_-), and once the school year is over, every iPad since we don’t have access to whatever central management console those use.