Jump to content

Recommended Posts

Posted

Morning!

So I've been presented with the most difficult (but simple in my head) question to answer this morning from the HT.

A member of staff has complained regarding the amount the network is locked down and insists it 'affects the students learning'...

 

I've now been asked why she can't have an Administrator account to be able to change these things in my absence etc.

 

 

There are 101 thousand reasons why you don't give Administrator accounts out left right and centre and the same as to why we lock things down with GPO's!

Could anyone help me put it into words (less-technical) as to why we as NM's do these things...?

 

 

TEACHERS!!!:mad:

Posted

Personally I'd throw it back and ask "what's affecting students learning" :p

 

As if it's something silly like password resets, you can easily delegate that out without admin rights etc.

 

Steve

Posted
On shared computers you lock it down to maintain a consistent user state so it does NOT effect teaching and learning. If its a 1:1 allocated machine you could argue to make sure unlicensed software is not put onto school owned machines and remind the head that its them facing jail time for unlicensed software on work machines.
  • Thanks 1
Posted

Slows lessons down having to wait for me etc. apparently!

 

It's things at the minute like Task Manager and Regional Settings.

For some reason some account are getting US keyboard layouts, not sure why. Which is fair enough, but then other students change it to Chinese meaning I have to re-image the machine.

With the Task Manager I don't think they realise the process which can be stopped by students to bypass things. IMO students account should be locked down to the max and staff should only have the rights they need.

 

Staff with Admin accounts wouldn't be able to fix user related problems anyway so...!

Posted

What processes do you stop task manager for? Most things like take Securus etc you can't kill as normal user anyway.

 

Keyboard layout, maybe consider GPO that resets it to normal? But you could just unlock that in a user profile individually in control panel

 

Steve

Posted

A teacher should never be looking to do any aspect of your job, such as installing software, as it's outside of their job description. Their union will not support them on that one. No amount of locking down will affect their ability to change passwords, as that's not available even with full admin access.

 

The full list is crazy though, and includes:

 

Safeguarding (in many forms, including protecting data from unauthorised access)

Maintenance (looking after the network and protecting it from malicious software which can easily be installed without safeguards)

Licensing (I wouldn't trust anyone who doesn't hold the licensing records to be able to install anything, especially as they never read Ts&Cs)

Work to rule (most teaching staff are under union instructions to follow their JDs strictly, that doesn't include doing your job! Remind them of this)

Professional courtesy. You are employed to do a job, if a member of staff has an issue with how you do it that should be handled appropriately.

...plus many more I'm too tired to think of.

Posted

Don't mess about with the pupils this the pupils that. Lay down what it actually means for the headteacher personally.

 

"It is extremely bad practice to give non IT Administrators full access to the network. I can give her administrator access if you instruct me, but please be aware that this will give her FULL ACCESS to the secure Documents area for all members of staff including School Councillor, SENCO, Senior Leadership members and yourself. Due to that lack of security, we would be in breech of the data protection act. The headteacher is legally responsible in this area, and the maximum fine for data breeches within this school is £0.5million. If you still wish me to do this please instruct me in a written, signed document."

  • Thanks 4
Posted
Glad to hear this went well, just my 2 cents. When I worked at a University, we had a script that would give a user local admin access to any PC on the network. Maybe this is something that could be considered. The idea was that if a user requires something specific they could install etc on their own workstation and access would be removed after a specified time automatically. This also meant that they never needed network admin access.
Posted
Glad to hear this went well, just my 2 cents. When I worked at a University, we had a script that would give a user local admin access to any PC on the network. Maybe this is something that could be considered. The idea was that if a user requires something specific they could install etc on their own workstation and access would be removed after a specified time automatically. This also meant that they never needed network admin access.

 

Still a bit dodgy. Could be just enough time for crytolocker to do its work. And who has to clean up afterwards? Yep, you.

Posted
Still a bit dodgy. Could be just enough time for crytolocker to do its work. And who has to clean up afterwards? Yep, you.

 

True it still has its downsides and ocasionally we did have a few problems. It was mostly about making the users feel that they had partial control and IT would just facilitate their needs. I found that backup solutions such as Crashplan Enterprise are quite good for recovering from Ransomware... but again... depends on Budget, Time & Resources etc.

  • 3 months later...
Posted

*Thread resurrection time*

 

I'm back faced with the task manager argument.

My argument of them being able to disable services/end processes etc. apparently isn't strong enough.

Any help?

 

AND

They're wanting me to give the students back the ability to lock workstations. I removed this, because they'd lock the machine, walk out and never return.

Then after 4 logons like that, the system runs out of resources and prevents any further logons, meaning yet another pointless call out for me/my apprentice...

 

I know NYPA and all of that, but really need help in wording this to 'non-IT people'. Even though it's the IT teacher mainly in question... (IRONY!)

Posted

This makes me laugh.

 

We had IT staff that had administrative rights on their PC's at first school I worked in, one of them was always complaining about the slow internet. We found tons of Peer to Peer and bit torrent software on her PC.

 

I know this was probably rare.

 

But still you need to ask why it is effecting student learning and make aware that any changes made unknowingly or accidently could have not only have an effect on the user of the PC but the whole security of the network and it's data.

Posted
*Thread resurrection time*

 

I'm back faced with the task manager argument.

My argument of them being able to disable services/end processes etc. apparently isn't strong enough.

Any help?

 

AND

They're wanting me to give the students back the ability to lock workstations. I removed this, because they'd lock the machine, walk out and never return.

Then after 4 logons like that, the system runs out of resources and prevents any further logons, meaning yet another pointless call out for me/my apprentice...

 

I know NYPA and all of that, but really need help in wording this to 'non-IT people'. Even though it's the IT teacher mainly in question... (IRONY!)

 

What services/processes do they have permission to end with task manager?

 

Even with no locking of screens can they still switch user?

 

Why do you need to go out? Just remote reboot.

 

Offer them options anyway. Ask them how they're going to help you solve the problem of people not logging off. Should there be a list (ie AD group) of students who can't lock their screens because they keep leaving them logged in?

Posted
What services/processes do they have permission to end with task manager?

 

Even with no locking of screens can they still switch user?

 

Why do you need to go out? Just remote reboot.

 

Offer them options anyway. Ask them how they're going to help you solve the problem of people not logging off. Should there be a list (ie AD group) of students who can't lock their screens because they keep leaving them logged in?

you can switch users up to the point that you cant anymore at a certain point it just blocks new user sign ins though i believe you can reboot it at that point still to kick em off

Posted

Yeah, services/processes-wise it's AV/Impero monitoring etc.

@sted has it spot on with the blocking of new logons. Says 'system has run out of resources and cannot allow further logons'.

Yes, maybe we could remote restart, but that shouldn't be a problem in the first place. That's 5/10 minutes of learning time lost, because the student couldn't log in at the same time as their peers.

Posted
Yeah, services/processes-wise it's AV/Impero monitoring etc.

@sted has it spot on with the blocking of new logons. Says 'system has run out of resources and cannot allow further logons'.

Yes, maybe we could remote restart, but that shouldn't be a problem in the first place. That's 5/10 minutes of learning time lost, because the student couldn't log in at the same time as their peers.

the issue is you are trying to solve a person problem with tech. not logging off is classroom management really. I suppose you could script a forced reboot at every bell but then people could loose work

Posted
What services/processes do they have permission to end with task manager?

 

Even with no locking of screens can they still switch user?

 

Why do you need to go out? Just remote reboot.

 

Offer them options anyway. Ask them how they're going to help you solve the problem of people not logging off. Should there be a list (ie AD group) of students who can't lock their screens because they keep leaving them logged in?

 

Yeah, services/processes-wise it's AV/Impero monitoring etc.

@sted has it spot on with the blocking of new logons. Says 'system has run out of resources and cannot allow further logons'.

Yes, maybe we could remote restart, but that shouldn't be a problem in the first place. That's 5/10 minutes of learning time lost, because the student couldn't log in at the same time as their peers.

 

So disable multiple logins.

 

Impero and AV both runs as SYSTEM, so users can't kill those. Anything else?

Posted

Apparently so, I stand corrected.

 

I've disabled the multiple logons and that's worked.

 

 

I still don't like not having the peace of mind that they can't get on the task manager, but Impero etc. seems to give access is denied when you do try and stop it.

Posted

It's in the same area as disabling right click, or ctrl-r, or cmd prompt. By all means monitor those windows with Impero logs to see what people are doing, but if the network is secure it doesn't really matter if they're enabled, and if they're disabled then your computer science courses are going to be tricky to teach.

 

I've secured my house by painting the door to look like bricks, and putting it at the back of the house, or I could just, you know, lock it. In the end it's usually easy to find out who's been messing about and deal with them via human means

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...