pcstru Posted December 8, 2015 Posted December 8, 2015 Does anyone have a neat, quick solution to stopping students being able to login to staff machines? Despite reminders to staff that they should not be allowing this, they seem quite unable to help themselves so I'm really looking to give them a helping hand.
X-13 Posted December 8, 2015 Posted December 8, 2015 Make a GPO for teacher-only computers. Add the pupil user group to: Computer Config > Policies > Windows > Security > Local > User Rights > Deny Logon Locally Force a gpupdate and Robert's your fathers brother. 2
glen_j Posted December 8, 2015 Posted December 8, 2015 Easy one, set up a group in Active Directory (if you already have one set for pupil s use that) then add that group to the Deny Log on Locally section of the group policy object for the computers its under "Computer Configuration>Windows Settings>Security Settings>Local Policies>User Rights Assignments" 1
LeMarchand Posted December 8, 2015 Posted December 8, 2015 I have gazed into my crystal ball and seen the future: the teachers will just let the children use the machines logged on as a teacher... 2
3s-gtech Posted December 8, 2015 Posted December 8, 2015 We have the policy set as those above have mentioned. Staff know that if they allow students to use their logins they risk the wrath of SLT, we have their support on this. 1
imullings Posted December 8, 2015 Posted December 8, 2015 Student logon to a staff workstation, so what is the problem? Student using a staff logon big problem. 1
3s-gtech Posted December 8, 2015 Posted December 8, 2015 Shouldn't be a security issue, but we found that teachers would get them to log on during a lesson; they'd then miss important alerts, emails etc. 1
dapaulio Posted December 8, 2015 Posted December 8, 2015 Student logon to a staff workstation, so what is the problem? Student using a staff logon big problem. OP what is the reason for the restriction? I agree with imullings. This sounds like you will create more of a headache for yourself over a problem which is not really a problem. I assume your Group policy is set up correctly restricting access to staff software and other network permissions are set up properly. Lessons are engineered now that students use interactive features to aid learning from teaching workstations. By restricting that access you will be hindering modern teaching techniques in getting the students involved. 1
pcstru Posted December 9, 2015 Author Posted December 9, 2015 (edited) OP what is the reason for the restriction? 1. It is not possible to force teachers to store documents in the places we make for them, so as well as the desktop, teachers may store confidential documents in local folders that are accessible to all users or the usb drive hanging off the side of the laptop. 2. Physical access to a machine opens up a number of exploits that would require good supervision and knowledge to recognise and prevent. Teachers are unlikely to be diligent enough in supervision (I'd be surprised if some even remove the post-it stuck to the screen with their password written on it). 3. The message, "Students must not use staff laptops" is simpler than "students may logon to staff laptops but only using their own login and must be closely supervised at all times". Forgetful staff will see students using another colleges laptop and will think it is OK without considering how they are doing that (so they will allow them to use their own login to print a document from a USB drive etc. There are other ways to reduce some of the risks, I though stopping logins would be quite neat, simple and cheap (in terms of effort). @LeMarchand probably puts his finger on a huge downside. Also changing local policy as suggested would involve altering each laptop - which sounds like quite a bit of work required in the short term. Lessons are engineered now that students use interactive features to aid learning from teaching workstations. By restricting that access you will be hindering modern teaching techniques in getting the students involved. There has to be a balance between that and security. We provide plenty of means of access for students which teachers can avail themselves of in a classroom with a little thought and planning. Edited December 9, 2015 by pcstru
Steve21 Posted December 9, 2015 Posted December 9, 2015 1. It is not possible to force teachers to store documents in the places we make for them, so as well as the desktop, teachers may store confidential documents in local folders that are accessible to all users or the usb drive hanging off the side of the laptop. While I agree that students shouldn't be logging onto staff machines, I'd query the above. Why can't you stop them? Redirect the desktop etc, and restrict the C drive. Where else would they save but network drive? Steve
pcstru Posted December 9, 2015 Author Posted December 9, 2015 (edited) While I agree that students shouldn't be logging onto staff machines, I'd query the above. Why can't you stop them? Redirect the desktop etc, and restrict the C drive. Where else would they save but network drive? It is certainly worth thinking about but not what we do at the moment and I suspect it is more effort than restricting logins which itself might be too much effort at the moment). I think if I proposed restricting USB drives, I'd have a huge fight on my hands (and in reality they are as much as or more of a risk). Edited December 9, 2015 by pcstru
Steve21 Posted December 9, 2015 Posted December 9, 2015 It is certainly worth thinking about but not what we do at the moment and I suspect it is more effort than restricting logins (which itself might be too much effort at the moment). I think if I proposed restricting USB drives, I'd have a huge fight on my hands. Aye fair enough Just wondered. In regards to the USB bit just restrict them (removable devices etc) on staff machines for students. Then even if Staff save to them, they wouldn't mount for students if they did log on a staff machine Steve 1
3s-gtech Posted December 9, 2015 Posted December 9, 2015 Also changing local policy as suggested would involve altering each laptop - which sounds like quite a bit of work required in the short term. I should point out that even though it can be done with secpol.msc on the clients, this change can be made centrally based on OUs, WMI queries etc as it's accessible through Group Policy as well as Local Security Policy. 1
X-13 Posted December 9, 2015 Posted December 9, 2015 I should point out that even though it can be done with secpol.msc on the clients, this change can be made centrally based on OUs, WMI queries etc as it's accessible through Group Policy as well as Local Security Policy. Yup, I do it through GP. So much easier.
TomHD Posted December 9, 2015 Posted December 9, 2015 I thanked your post just for this Robert's your fathers brother.
X-13 Posted December 9, 2015 Posted December 9, 2015 I thanked your post just for this Wait... have you never heard that before?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now