Sheridan Posted November 25, 2015 Posted November 25, 2015 Ok I'm just after some general information here on staff bringing in their own devices and using the wireless. My point of view is a) the school provides computers in every classroom, staffroom, shared area and lots of ict suites (plus laptops and ipads as well) so they don't really need to and b) how can you control confidential data and what staff keep on their personal devices - ie their personal store of videos/photos etc! I'm also concerned (as we use a cloud vle) that staff will use their personal device to login to their vle account, and download data etc to their laptop - of which we have no control of security/encryption and disposal. I know some people will say a policy to enforce this may be enough but policies aren't enforced enough here for my liking. We're getting quite a few whining about 'why can't I connect my iphone/ipad/laptop/chromebook etc' (obviously because starbuck let them, we should to) and I'm probably going to be overuled eventually. So how do you fellow techs deal with this?
Steve21 Posted November 25, 2015 Posted November 25, 2015 We allow them to use them if they want, but it's not "supported" (e.g. anything that doesn't work properly on a random device isn't going to be changed for only one user) and not to be used with anything that needs unplugging. e.g. can't unplug a teacher machine/projector to use it. End of day in regards to the VLE part there's nothing that stops them doing the exact same at home, if they download it and use the data at home? We provide full RDS access for all staff, so should they need anything "confidential" etc it's done direct on that so no downloads needed Steve
pcstru Posted November 25, 2015 Posted November 25, 2015 We allow BYOD for teachers and 6th form. We impose some policy restrictions on their use if they want to connect to our exchange service. On security and them putting files on their personal devices; it is technically nearly impossible to stop this (anyone can email a file to themselves) so we have to rely on policy and educating users about the issues.
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 We also have remote access for staff for accessing MIS etc but I'm still dubious about the apparent 'need' to have our wifi to access their email on their phones. They all have classroom PCs and access to other equipment. When we replace our wifi I will be looking to incorporate BYOD anyway - who gets access has yet to be decided!
Steve21 Posted November 25, 2015 Posted November 25, 2015 We also have remote access for staff for accessing MIS etc but I'm still dubious about the apparent 'need' to have our wifi to access their email on their phones. They all have classroom PCs and access to other equipment. I guess to me it's they're gonna use it whether on wifi or 3/4g so what's the downside, as means you can filter out stuff you don't want them to have on internet too Facebook etc *cough* We have things like staff calendars/timetables syncing to phones too when they ask us to set it up so obviously that's useful to have too Steve
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 I guess to me it's they're gonna use it whether on wifi or 3/4g so what's the downside, as means you can filter out stuff you don't want them to have on internet too Facebook etc *cough* We have things like staff calendars/timetables syncing to phones too when they ask us to set it up so obviously that's useful to have too Steve This is where is gets a bit messy - staff are already using their phones to get their school emails, using their own 3g/4g but they now seem to think that the school should provide internet access on those devices as well!
tmoon-mint Posted November 25, 2015 Posted November 25, 2015 Regarding email on personal devices, do you use Office 365? You can implement an MDM solution that enforces certain security policies, e.g. force user to have a passcode, remote wipe and jailbreak/root detection. If this isnt an option I would look at making it school policy to secure all devices that access school data, including personal ones. Perhaps in a slightly amended AUP?
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 Regarding email on personal devices, do you use Office 365? You can implement an MDM solution that enforces certain security policies, e.g. force user to have a passcode, remote wipe and jailbreak/root detection. If this isnt an option I would look at making it school policy to secure all devices that access school data, including personal ones. Perhaps in a slightly amended AUP? No, we're using GAFE integrated into our VLE.
CyberNerd Posted November 25, 2015 Posted November 25, 2015 No, we're using GAFE integrated into our VLE. There is a mobile device MDM built into GAFE.
CyberNerd Posted November 25, 2015 Posted November 25, 2015 We have all staff and student BYOD allowed access to their email, calendars documents for the last 5yrs. The only real "issue" is providing documentation for so many different types of device.
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 There is a mobile device MDM built into GAFE. That would mean they have to enroll their personal devices though? Do you restrict the BYOD access just to email/calendars etc?
dry Posted November 25, 2015 Posted November 25, 2015 I've never really understood people's need for WiFi at the workplace, given that (in our case) they are provided with a laptop as it is. Yes it's nice to have, but what happens when you're away for the weekend somewhere that doesn't have WiFi? Does your life grind to a halt? Our internet connection is filtered heavily in any case, so even if we did open it up for all and sundry, we'd still get moans. I had one member of staff tell me that they need access to the WiFi and they need Whatsapp working straight away as a relative was at the hospital or something. I asked them if they have a data plan which they told me they'd used up already. Ughhhh. Buy some more data next month!
CyberNerd Posted November 25, 2015 Posted November 25, 2015 Do you restrict the BYOD access just to email/calendars etc? No, everything goes through a transparent proxy. The can do what they like as long as the filter allows it. That would mean they have to enroll their personal devices though? I'm pretty sure you can enforce it so they can't access work email without enrolment, so you can remote wipe them if you need to. Try here: https://support.google.com/a/answer/1753793?hl=en 1
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 Hmm I wonder if enrolment would be popular as staff would worry we'd be wiping their devices for the fun of it!
CyberNerd Posted November 25, 2015 Posted November 25, 2015 Hmm I wonder if enrolment would be popular as staff would worry we'd be wiping their devices for the fun of it! It is tempting sometimes. 1
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 I like the idea of using mobile management to make sure they have a password/pin on their phone etc to make sure that confidential emails aren't easily read.
TechMonkey Posted November 25, 2015 Posted November 25, 2015 Hmm I wonder if enrolment would be popular as staff would worry we'd be wiping their devices for the fun of it! I have had this "scare" story here after a member of the IT team nonchalantly mentioned we could wipe their devices. I had to send out an email explaining what it actually meant, that we wouldn't use it unless they asked us, that yes they did agree to it when they set up the email, no I can't help it if they don't read messages and yes if they don't like it they can remove it from their devices and not receive work emails on their device. No we won't supply a work device for you to get your work emails was the only extra email I had to send out to a couple of chancers. 1
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 I've never really understood people's need for WiFi at the workplace, given that (in our case) they are provided with a laptop as it is. Yes it's nice to have, but what happens when you're away for the weekend somewhere that doesn't have WiFi? Does your life grind to a halt? Our internet connection is filtered heavily in any case, so even if we did open it up for all and sundry, we'd still get moans. I had one member of staff tell me that they need access to the WiFi and they need Whatsapp working straight away as a relative was at the hospital or something. I asked them if they have a data plan which they told me they'd used up already. Ughhhh. Buy some more data next month! This is sort of my point of view - they have access to equipment in school and can use any device at home for email - so why do they also need to be hooked onto our wifi?
CyberNerd Posted November 25, 2015 Posted November 25, 2015 This is sort of my point of view - they have access to equipment in school and can use any device at home for email - so why do they also need to be hooked onto our wifi? Why not though? It's pretty easy to do. I can understand if it's an old fashioned network where you have to setup a separate MDM, mess around with calendars and email servers but with GAFE you are halfway there.
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 Why not though? It's pretty easy to do. I can understand if it's an old fashioned network where you have to setup a separate MDM, mess around with calendars and email servers but with GAFE you are halfway there. True, I can put the restrictions onto mobile devices with GAFE without any further intervention. Once we upgrade our wifi to BYOD we may allow access as well - the issue we've had is when our primary schools bought wifi and used it for their ipads and laptops - but then every staff member and their dog hooked their phones to it as well, and it did impact the performance!
zag Posted November 25, 2015 Posted November 25, 2015 (edited) Try not to "overthink" this. Its an internet connection at the end of the day you are providing. As long as its filtered, logged via a transparent proxy and the BYOD devices are on a separate ip range or vlan then it should be absolutely fine to add as many as you want. All this talk of wiping devices, pin codes and MDM solutions, and control of BYOD really is missing the point of BYOD. Edited November 25, 2015 by zag 2
CyberNerd Posted November 25, 2015 Posted November 25, 2015 All this talk of wiping devices, pin codes and MDM solutions, and control of BYOD really is missing the point of BYOD. I can't help but agree. The problem is (with Edugeek) as soon as someone mentions Cloud/BYOD the world starts caving in with "think of the Children" and "What if X happens?"
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 Try not to "overthink" this. Its an internet connection at the end of the day you are providing. As long as its filtered, logged via a transparent proxy and the BYOD devices are on a separate ip range or vlan then it should be absolutely fine to add as many as you want. All this talk of wiping devices, pin codes and MDM solutions, and control of BYOD really is missing the point of BYOD. I went off topic there really - I think enforcing password/pin protection on personal devices that use school email is important, to protect against confidential emails being read by the wrong person! The original point was staff bringing in their own devices to use in school - like you say they would only have internet access that equates to what they would have on a networked computer.
Sheridan Posted November 25, 2015 Author Posted November 25, 2015 I can't help but agree. The problem is (with Edugeek) as soon as someone mentions Cloud/BYOD the world starts caving in with "think of the Children" and "What if X happens?" It is a valid point though - if staff were sent an email with confidential information about your child at school - and that email was left on a phone that was unlocked, you would be furious that this wasn't controlled in some way? Obviously using policies and staff's own common sense is 99% of the equation, but its nice to have a backup plan!
Oaktech Posted November 25, 2015 Posted November 25, 2015 I have had this "scare" story here after a member of the IT team nonchalantly mentioned we could wipe their devices. I had to send out an email explaining what it actually meant, that we wouldn't use it unless they asked us, that yes they did agree to it when they set up the email, no I can't help it if they don't read messages and yes if they don't like it they can remove it from their devices and not receive work emails on their device. No we won't supply a work device for you to get your work emails was the only extra email I had to send out to a couple of chancers. I always sell it to them in a positive light that I could be the saviour of their private life... If they lose their phone in a pub they can contact me and I can wipe all their personal details from the phone.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now