Jump to content

Recommended Posts

Posted
Is there a way to lock proxy in, though? We use Apple Configurator to manage our iPads and the kids can easily head to settings, disconnect from the wireless, remove the proxy info, etc. Hardly foolproof, no?

 

 

So you haven't bothered to password protect your profiles in Configurator so they can't be deleted???????

Posted
Of course, I completely agree with you there, actually. But whilst the device is still legally the schools, the fact that it goes off-site is going to really mess with managing it. I'm not advocating not managing the device in any way, I'm just asking questions.

 

 

Unless you can lock a proxy to a specific connection, that won't work, as it would try and contact the proxy server whilst it was at home, too, wouldn't it?

 

In some configurator and AirWatch, maybe other MDMs too you can lock a global proxy which spams all connections. You can get a hosted mdm and filter or make these accessible externally and force the devices through the proxy. I know it's possible because i do it.

 

We try not to for access at home from iPads and instead have a strong focus on educating both students and parents on the potential dangers of the Internet. Even going so far as to put on evenings with instructions on how they themselves can filter their home connections.

 

AirWatch can also blacklist applications from being installed.

 

There are ways and means, but education really is the best solution, otherwise they leave school completely unprepared for the real world.

 

Sorry, joined this thread really late!

Posted
Except she was using Skype. I can understand that the teacher should have been aware of what was going on, but if Skype was installed then it was obviously needed for something - there's no way to limit what you do on Skype. She wasn't accessing any adult websites or dodgy things in school, she went on the adult websites at home and then added him on Skype at school. It's partly the School's fault, yes - but I don't believe there is any real remote access/management system that lets you view iDevices in real time (except for Impero, but their iDevice integration is quite new).

 

Impero only allows tall time access to see what's on screen while the Impero app is open. It can be closed and they can't stop that. The better way to do this is with a layer 7 firewall that can detect and block things like Skype, Facebook, etc.

 

If you're going to go one 2 one or byod you need a strong mdm, layer 7 firewall and filter. All backup up with good safeguarding policies and education.

 

A recurring theme i see throughout education is that teachers want a solution from it to stop students 'messing around' but that issue has always been present since playing hangman on pieces of paper.

Posted
You can monitor ipads though - Impero has this ability, as does ABTutor I believe. So a teacher could have the screens displayed as thumbnails on their PC...

 

Making groups from a one 2 one point of view is difficult at the moment. I'm trialing this next month and giving some feedback to devs. Hopefully to allow sims integration to pick up time based groups. (that's my dream anyway)

Posted
Been discussing this with my colleagues and one of them just raised a valid point.. Schemes like this are usually contributed to by the parents.. With that in mind, can the school lock down the devices if they parents have contributed towards the cost? The device isn't 100% theirs. Tricky situation. Probably one for writing a policy about before they start going round with the collection bucket.

 

This can be worked around. We have an elearning scheme which parents contribute to. They are not paying towards the cost of an iPad, donate towards the scheme so that all students regardless of their financial situation can have access to the same level of technology. The iPad ate bought and owned by the school. The parents have the option to buy them at the end of the scheme at a very low price, if they like.

Posted

This thread is an interesting one and a lot of the points raised so far have merit, and @Ephelyon has covered a lot of historic conversations about the risk of BYOD.

 

As investigations are also still going on it is hard to make cast iron statements about what did or didn't go wrong.

 

A few things to cover though ...

 

1 - these devices were provided by the school so there is a responsibility even when the devices are outside of school. This has been core to some lengthy discussions between a number of esafety and legal folk, so please take it as fact rather than spending a lot of effort arguing about it.

 

2 - there are lots of technical options for heavy lockdown and I already know of two MDM providers who will be using this as an example whilst at BETT, including how you can keep control when outside of school. The issue is that for each element you lock down you lose engagement with the students. We cannot collectively comment on this school, but many of us know that the view of a number of schools (even after legal advice) is that they will take a risk on it as there is good research showing that where children take ownership of risk that learn to handle it better and take less risks as a result.

 

3 - different children will take risks in a different way, and it varies from school to school. Some area will be constant but the approach in a school with a large number of noted issues on risk affecting health and education will differ from another school where there are few and limited cases. One example used is whether you give certain classes access to craft knives due to certain children being a risk of causing damage to equipment or injury to others. One size does not fit all.

 

4 - the child is a victim, even if they have also broken rules. It is possible to be both.

 

5 - no matter if you have mobile devices, BYOD or just desktops, are we sure that everyone who has responded to this thread has a fully documented risk assessment of their own systems and have recommendations etc that have been followed, risks reduced or documented where accepted (with a name against who accepted it)? I know some of you have ... but has everyone? I know mine was never fully written down in the end but we had a good amount of it covered. I would definitely do it differently now.

 

Do I think that there is a perfect answer for all this? No ... And any supplier or consultant who says they have the perfect solution for your school when they haven't discussed your school's needs ... well I would steer clear of them. Do I think that locking down everything g would solve things? No ... it would just make a different set of problems. Most school become risk adverse to protect the school rather than protect the child. That is the difference that a lot of folk forget.

 

If folk want to contribute to a discussion about how a school could look at options to do things more safely, but still keep flexibility, then I think that would be the best thing to do next. @localzuk has already provided a large number of good comments and options. Shall we go from there?

Posted
So you haven't bothered to password protect your profiles in Configurator so they can't be deleted???????

I don't know, I wasn't the one to set them up, all I know is the kids can delete the proxy details or disconnect from the WiFi if they want to, I personally haven't had any experience with Apple Configurator so I don't know what its capabilities are.

Posted (edited)

We're right at the start of our BYOD journey so this is a very interesting thread.

 

I'd be interested in seeing how other schools force IPads (or other tablets) to connect back to your proxy once they have left the school premises and also what MDM you use. The free version of Meraki seem useful but also somewhat limited.

Edited by Tall_Paul
Posted
My understanding is that all MDM's all have to work off the same Apple Framework, so i don't think it's much more limited than any other. Correct me if I'm misinformed.
Posted
We're right at the start of our BYOD journey so this is a very interesting thread.

 

I'd be interested in seeing how other schools force IPads (or other tablets) to connect back to your proxy once they have left the school premises and also what MDM you use. The free version of Meraki seem useful but also somewhat limited.

 

There is a big difference in what you can do to a BYOD device. Especially when it comes to Apple devices.

 

You can lock to a proxy or even an always on VPN. However this requires the device to be supervised, something that requires the iPad to be wiped.

This is therefore not normally done to BYODs as the user would lose all their settings and files/photos.

 

Now if the devices are school owned, and you're looking at 1to1 rather than BYOD then you can pre-supervise them all before handing them out.

 

I've taken the following from an AirWatch Q&A document.

 

The following features are only available if a device is in supervised mode:

 

Single App Mode: Locks a device into a single app (often seen in retail and check in/check out scenarios)

Global Proxy: Allows you to force all Internet communications through a single proxy server

Enable or disable AirDrop: Allows for the transfer of files wirelessly

Enable or disable iMessage use: Messages sent through Apple’s Internet-based messaging system

Enable or disable data usage for apps: Applications can be prevented from using cellular data

Enable or disable manual profile installations: Allow users to set up their own profiles

Enable or disable account modification: Allows changes such as altering a user’s Apple ID, mail, contacts and calendar

Note: Enabling supervised mode will initiate a factory reset on the device. For this reason, supervision is not recommended for personally-owned devices.

Posted (edited)
There is a big difference in what you can do to a BYOD device. Especially when it comes to Apple devices.

 

You can lock to a proxy or even an always on VPN. However this requires the device to be supervised, something that requires the iPad to be wiped.

This is therefore not normally done to BYODs as the user would lose all their settings and files/photos.

 

Now if the devices are school owned, and you're looking at 1to1 rather than BYOD then you can pre-supervise them all before handing them out.

 

I've taken the following from an AirWatch Q&A document.

 

I thought that might be the case.

 

Our trial (set up in conjuction with an Apple reseller and their Apple certified engineer) essentially gives the students ownership of the device.

 

I can install apps onto there and see what they have installed (through Meraki) but that is about it. I cannot enforce an application blacklist (though I can enforce age restrictions on apps and other downloads) and cannot uninstall apps from their devices.

 

It has certainly been an interesting trial and, possibly, it may turn out that supervised devices may be a better fit.

Edited by Tall_Paul
Duplicate post made. Are there problems with the site?
Posted (edited)
My understanding is that all MDM's all have to work off the same Apple Framework, so i don't think it's much more limited than any other. Correct me if I'm misinformed.

 

You are right, Apple dictate to others that the MDM Protocol is to be and they follow it. All features are available for all companies its up to the company if they wish to implement them. MDMs are generally limited anyway as Apple only releases a handful of new settings and payload restrictions in each major iOS update.

 

Upon reading all the thread everyone has noticed the limitations in the 3 major deployment models from Apple. They are:

 

Institution-owned one-to-one

Student-owned

Shared use

 

If you are giving each of your students an iPad each, I wouldn't even attempt at going for Student-owned or Institution as it allows students to install apps. If the devices belong to the school or are to be used in school you want to still go for Shared, where you control the environment.

 

http://www.apple.com/education/docs/EDU_deployment_overview_en_sept14.pdf

 

People literally jump into deploying iPads to their environment as they get handed 30 by a member of SLT who saw 'shiny shiny' - iPad deployment is pretty complex when you look at the bigger picture. You need to get infrastructure sorted and a plan in place before handing them out. They need to be supervised using Apple Configurator and need to be enrolled in a MDM solution.

 

The reality of the situation is, Apple has not given us as administrators enough MDM controls - I would love to remove the settings icon or at least stop kids placing a passcode on them or turning off the WiFi but that will never happen because Apple knows where the money is - consumers.

Edited by SovietRussia

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...