MatthewL Posted November 18, 2015 Posted November 18, 2015 Question for you all. Say you have 10 teachers all with their own laptop joined to your domain. How do you set them up? Do you give them a local login and get them to use that all the time or do they have both? If they have both what do you about accessing documents? Those that go down the full domain route how do you manage documents? In this example you have no VPN access from home and need to ensure their data is backed up to the network when they come back into school. Not out to catch anyone out just after some thoughts on the topic.
Kingstech Posted November 18, 2015 Posted November 18, 2015 You can use Direct Access for teachers to access school documents from home. Teachers would only need to logon with there domain username and password. 1
dblight Posted November 18, 2015 Posted November 18, 2015 If no access to network from anywhere offsite then Offline Files is an option. Any files created/deleted or amended whilst the laptop is off the network will get updated when the user connects back. Used to be a pain in the **** before but been ok since Win7. All can be configured via Group Policy. If allowing end users connection to the network offsite is an option as stated you can use Direct Access with Win 2012 or VPN. It depends on your security requirements if you roll that out to staff or not. We have it setup for a select few in the IT team for when we are at different sites but I don't envisage allowing teachers always connected access.
6Foot2 Posted November 18, 2015 Posted November 18, 2015 The default position we take is that we will supply laptops that are on the domain without a local user available. If the recipient of the laptop logs on while still in school this prepares the laptop for use off site away from the network. However, if the member of staff expresses a preference we will: Provide a local user on a laptop that is a member of the domain or: Provide a laptop that is not a member of the domain.
MatthewL Posted November 18, 2015 Author Posted November 18, 2015 dblight exactly what I am thinking. Another question related to the above, what reasons would you have for not having a VPN for staff (to use in above instance) on security grounds?
dblight Posted November 18, 2015 Posted November 18, 2015 (edited) dblight exactly what I am thinking. Another question related to the above, what reasons would you have for not having a VPN for staff (to use in above instance) on security grounds? I just mean it depends on your schools policy for remote access. If enabled your users would have what was available onsite at home. What if for example staff member has VPN connected, happily working away until door bell goes, they go answer it, someone else in the house sees everything displayed on laptop. Say it's a SEN action plan or statement or something sensitive? They forward it via email or something to someone else? That's just an example. The same could happen whilst onsite but the likelihood is the teacher will be doing such things in an office or staff room etc etc. What would happen if VPN was connected and user was on a train and laptop gets stolen? For a brief moment the thief has access to exactly what the user has access too. Albeit they may not realise what they have but the hole is still open. Again it's up to the school really about what's acceptable to be accessed offsite. Edited November 18, 2015 by dblight
MatthewL Posted November 18, 2015 Author Posted November 18, 2015 Know where you are coming from on that. PSN, CoCo and VPN does that make any difference?
FN-GM Posted November 18, 2015 Posted November 18, 2015 We have cached domain logins with offline files, really easy to setup and operate.
MatthewL Posted November 18, 2015 Author Posted November 18, 2015 Do the offline files cause many issues these days?
dblight Posted November 18, 2015 Posted November 18, 2015 Not really nowadays. It's used to be awful in XP. However since 7 it's been ok. At most I have only had to delete the local database and re-sync and it creates itself again.
LeMarchand Posted November 19, 2015 Posted November 19, 2015 Domain logins, offline files, HDD/SSD encryption, proxy.pac.
cpjitservices Posted November 19, 2015 Posted November 19, 2015 Domain Joined, Cached logons, If a user needs to access anything off site they can RDP into a remote server and access shares. As far as security is concerned, if a laptop was stolen or broken into somehow the logon to RDP is a desktop shortcut but with no saved credentials. You'd still need to authenticate to log on remotely. We also have a webdav offering, or will do very shortly - in the form of Alfresco.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now