apearson Posted February 11, 2015 Posted February 11, 2015 Apologies if this has been covered elsewhere. I did a quick search but couldn't find anything. We had O365 set up over the summer and our staff have been using it and finding out some of its functionality. We haven't yet released it to our pupils. I have tried logged in as a pupil user to try and find out what they can and can't see/do, but was wondering if anyone has any suggestions about areas we need to look at and possibly block/restrict for pupils etc. We could just let our pupils loose on it and try to firefight afterwards as they discover things that we don't want them to be able to do, but it would be nice if we could configure it as much as possibly in advance. We are an academy trust of 4 schools - one secondary and 3 primaries all sharing the same network and O365 domain. We are not looking to block complete areas (eg. no access to email or onedrive etc) but just seeing if other schools have found things that we might not want pupils to be able to do. It is envisaged that all pupils will have access to email, onedrive, people, calendars, sites etc. Hopefully the above makes sense. Any suggestions gratefully received. Andy
StephenHardy Posted February 11, 2015 Posted February 11, 2015 Id remove the ability for Lync, share point & using email on anything other than OWA
Marshall_IT Posted February 11, 2015 Posted February 11, 2015 Lync and sharepoint can be restricted easily but just not assigning them the license for that part, you'll need to create a policy of some sort to restrict it to owa only although i don't see the rationale behind that for secondary pupils. They only other thing you might need to look at blocking is the ability to create groups. Not had a problem with that myself yet though so I've not blocked it.
StephenHardy Posted February 11, 2015 Posted February 11, 2015 Creating personal groups is ok, I restrict global groups
apearson Posted February 12, 2015 Author Posted February 12, 2015 Thanks for the ideas so far guys. Preventing the creation of groups is certainly something we will look at.
JRowley Posted February 12, 2015 Posted February 12, 2015 If you are having them share a tenant with the students you will want to consider staff display names, sharing via OneDrive and GALs.
Marshall_IT Posted February 12, 2015 Posted February 12, 2015 Also you might need to create different GALs for each school. I split staff and students so that staff don't appear in the address book, although it was quite tricky to setup.
apearce Posted February 12, 2015 Posted February 12, 2015 If you enable sharepoint - remove the ability to share mobile number and other personal stuff. Don't provision Yammer. Turn the creation of groups off. I did a blog post on this so hope it is useful. Disable Office 365 Group creations | BFC Networks 2
JRowley Posted February 13, 2015 Posted February 13, 2015 Why disable Yammer? Its basically enterprise facebook, surely you don't want to give the kids another distraction in the classroom? Even if it does have some benefits I'm not sure it would be advisable.
apearson Posted February 18, 2015 Author Posted February 18, 2015 I think yammer is already disabled, though I will check. Thinking about some of the comments has brought to light the fact that I think we might have to create policies for staff and students for each school. If we only make a 2 way split now - staff/students, then further down the line, as each school wants different things, it will be much more effort to create school based policies.
apearce Posted February 18, 2015 Posted February 18, 2015 problem with yammer is that you can change you own name and profile picture so Joe Bloggs is now Head Teacher with their profile picture. Yammer is not provisioned in you tenant unless you do it. 1
PeelyPie Posted February 20, 2015 Posted February 20, 2015 If you are having them share a tenant with the students you will want to consider staff display names, sharing via OneDrive and GALs. Hi JRowley, I'm in a similar position to this - Rolling out 365 to multiple schools within a single tenant - Do you know if there's a way to disable the lookup of display names when sharing through OneDrive? I'd like it so students don't see anybody within this lookup and can only share if they know the username/email address of the recipient in advance. Many thanks, Chris
JRowley Posted February 20, 2015 Posted February 20, 2015 Hi JRowley, I'm in a similar position to this - Rolling out 365 to multiple schools within a single tenant - Do you know if there's a way to disable the lookup of display names when sharing through OneDrive? I'd like it so students don't see anybody within this lookup and can only share if they know the username/email address of the recipient in advance. Many thanks, Chris To my knowledge there isn't a way to restrict the look up, it doesn't respect the GAL and just seems to search through the entire user base of that tenant which is not ideal to say the least. This is what made us take a look at display names for staff as previously they did not interact with students with their staff email accounts, sadly to migrate them to O365 we had to rename them to the format J Rowley rather than full names. Your idea would be an ideal solution, sadly I don't think it's possible, not even in powershell. However I will say that beyond the name issue I don't think having them able to see everyone is too much of a problem, if a child decided to be malicious and send something to a teacher that they shouldn't, it would be immediately obvious who shared it and what they shared. So the disciplinary system can handle it perfectly well. Though having multiple schools under one tenant does present a number of issues in that regard. 1
PeelyPie Posted February 20, 2015 Posted February 20, 2015 To my knowledge there isn't a way to restrict the look up, it doesn't respect the GAL and just seems to search through the entire user base of that tenant which is not ideal to say the least. This is what made us take a look at display names for staff as previously they did not interact with students with their staff email accounts, sadly to migrate them to O365 we had to rename them to the format J Rowley rather than full names. Your idea would be an ideal solution, sadly I don't think it's possible, not even in powershell. However I will say that beyond the name issue I don't think having them able to see everyone is too much of a problem, if a child decided to be malicious and send something to a teacher that they shouldn't, it would be immediately obvious who shared it and what they shared. So the disciplinary system can handle it perfectly well. Though having multiple schools under one tenant does present a number of issues in that regard. Thanks for getting back to me so quickly - You're right about it pulling all active users within the tenant - Why you can't point it to the user's GAL (that we've got segmented) is beyond me. The frustrating thing is we had MS point us down the single tenant path ages ago for student email - Now we're ready to start rolling out OneDrive but this is a huge issue for us. How MS can push this as an educational tool with this flaw is beyond me - Even in a single tenant school, you can implement restrictions within your Exchange and Lync environments - none of which are carried over into O365. We have MS on-site next week so hopefully will get some clarity on the issue.
JRowley Posted February 20, 2015 Posted February 20, 2015 Thanks for getting back to me so quickly - You're right about it pulling all active users within the tenant - Why you can't point it to the user's GAL (that we've got segmented) is beyond me. The frustrating thing is we had MS point us down the single tenant path ages ago for student email - Now we're ready to start rolling out OneDrive but this is a huge issue for us. How MS can push this as an educational tool with this flaw is beyond me - Even in a single tenant school, you can implement restrictions within your Exchange and Lync environments - none of which are carried over into O365. We have MS on-site next week so hopefully will get some clarity on the issue. The problem with O365 is that it is formed from two distinct parts, Exchange and Sharepoint. Exchange handles Outlook, Calendar, People, Tasks, where as Sharepoint handles OneDrive, Sites, Projects (if you have it). Sharepoint doesn't respect GALs which is why the list isn't restricted. However I don't believe there is much in terms of separation for Sharepoint, you can do security groups and audiences but you still can't change where the sharing list is populated. Its good that MS are coming on-site for you, I would definitely press the matter, your best option is probably to push for the list to be able to have an audience or security group attached to it, its unlikely they will be able to get GAL support added in any reasonable amount of time due to the separation.
muppet Posted February 25, 2015 Posted February 25, 2015 @ PeelyPie, I'd be interested to know how you got on with MS as we are about to roll out student email accounts and will be in the same situation as you.
timbo343 Posted February 25, 2015 Posted February 25, 2015 Id be interested in this too. I have asked questions in the past but I wont be using OneDrive until sharing can be disabled. We have office365 for student email and I have locked it down so that they can only send to our staff emails which are hosted on our exchange server. It might be ring fencing but it cuts down on bullying and spam and it means I can control which domains students can receive emails from. They cannot send emails to each other nor can they send emails to Hotmail, gmail, yahoo etc, however they still have access to their personal emails in school. We have said that staff are not to communicate to students via their personal email addresses only via their school email address. I have tested the sharing and although ive got the sharing email invite disabled, the file still shows as being able to view.
PeelyPie Posted February 25, 2015 Posted February 25, 2015 We've now got a couple of feature requests in with MS to 1) Provide an option to disable OneDrive sharing entirely and 2) Introduce GAL segmentation (or similar) functionality to OneDrive. No word on if or when these will be implemented though. @ muppet, If you're sticking to Exchange Online only then you can do a certain level of separation and provide students with blank GALs for instance - Then they can't look up any users within the AD structure of 365. It's only when you move to any SharePoint based platforms (OneDrive, Sites, Delve, Video) that you'll hit similar issues. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now