TheGoodGuy Posted January 15, 2014 Posted January 15, 2014 Hello all, I am just curious what methods others use to protect teachers laptops when they are at home, other than A/V. At school we have filtering to block malicious sites but at home there is no such protection. I am thinking of setting something up for the hosts file, but I wondered if anyone knew of anything that was more automatic? Cheers, Paul
free780 Posted January 15, 2014 Posted January 15, 2014 Smoothwall do a client so you can block certain sites with clients off the lan.
MatthewL Posted January 15, 2014 Posted January 15, 2014 Sophos have a similar thing with their web control built into AV if I am right in thinking.
Arthur Posted January 15, 2014 Posted January 15, 2014 other than A/V. Some of the things I have done... Enable AppLocker and setup rules to prevent executables/scripts from running. Install EMET to help protect against zero-day exploits (among other things). Block adverts in Google Chrome (using the URLBlacklist policy) so there is less chance of getting infected via malicious ads. Keep browser plug-ins like Flash Player and Java up-to-date. Install the latest Windows hotfixes as soon as possible after Patch Tuesday. All users have standard accounts. i.e. no teachers in the local admin group.
MatthewL Posted January 15, 2014 Posted January 15, 2014 Something basic don't make them administrators, cuts down on a lot of it I find.
free780 Posted January 16, 2014 Posted January 16, 2014 Have sccm installed with a outward facing software update/management point/distribution point. Then you can keep flash/reader/windows up to date.
Davit2005 Posted January 16, 2014 Posted January 16, 2014 (edited) As @MatthewL states, not making them administrators is a start. But also make sure the Stall Laptop AUP covers things like: The Laptop is to be used by the staff member only and not to be used by Siblings, etc. The Laptop cannot be used for any peer to peer sharing activities. I've personally found that most of the issues are caused by Siblings using the Laptop and visiting Joke sites, game hack sites, serial generators, or using Peer to Peer sharing sites. Just to add, having the Laptops back for Microsoft Updates and using Anti-Virus as others have said. But a lot can be said about the IT awareness of the end user . Edited January 16, 2014 by Davit2005
JonDaviesBourne Posted January 22, 2014 Posted January 22, 2014 Don't make them administrators on their own machines, and make sure that your Windows Lockdown GPO is properly configured. Any malware would require admin rights to install, and UAC should prompt the user for admin credentials when malware tries to install. If they bring the laptops into school each day, then having them back for Windows updates should be irrelevant as long as you have WSUS configured correctly. It could also be worthwhile pushing out a group policy that uninstalls Java as it's rarely needed and has myriad security holes.
free780 Posted January 22, 2014 Posted January 22, 2014 And if java is needed lock it down. Use deployment rulesets so it only works on trusted domains.
psydii Posted January 22, 2014 Posted January 22, 2014 Sophos also has "live protection" which reduces the need to keep its local malware signature database updated, great for roaming clients whose update server is behind the firewall. There are of course other ways of achieving this (publishing the update distribution point on a public facing server for example. I do have to say that with web protection and live update the number of infected staff machines I see is massively less than even three years ago.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now