Jump to content

Recommended Posts

Posted
Does anyone have a neat, quick solution to stopping students being able to login to staff machines? Despite reminders to staff that they should not be allowing this, they seem quite unable to help themselves so I'm really looking to give them a helping hand.
Posted

Make a GPO for teacher-only computers.

 

Add the pupil user group to:

 

Computer Config > Policies > Windows > Security > Local > User Rights > Deny Logon Locally

 

Force a gpupdate and Robert's your fathers brother.

  • Thanks 2
Posted
Easy one, set up a group in Active Directory (if you already have one set for pupil s use that) then add that group to the Deny Log on Locally section of the group policy object for the computers its under "Computer Configuration>Windows Settings>Security Settings>Local Policies>User Rights Assignments"
  • Thanks 1
Posted
We have the policy set as those above have mentioned. Staff know that if they allow students to use their logins they risk the wrath of SLT, we have their support on this.
  • Thanks 1
Posted
Student logon to a staff workstation, so what is the problem? Student using a staff logon big problem.

 

OP what is the reason for the restriction?

 

I agree with imullings. This sounds like you will create more of a headache for yourself over a problem which is not really a problem. I assume your Group policy is set up correctly restricting access to staff software and other network permissions are set up properly.

 

Lessons are engineered now that students use interactive features to aid learning from teaching workstations. By restricting that access you will be hindering modern teaching techniques in getting the students involved.

  • Thanks 1
Posted (edited)
OP what is the reason for the restriction?

1. It is not possible to force teachers to store documents in the places we make for them, so as well as the desktop, teachers may store confidential documents in local folders that are accessible to all users or the usb drive hanging off the side of the laptop.

 

2. Physical access to a machine opens up a number of exploits that would require good supervision and knowledge to recognise and prevent. Teachers are unlikely to be diligent enough in supervision (I'd be surprised if some even remove the post-it stuck to the screen with their password written on it).

 

3. The message, "Students must not use staff laptops" is simpler than "students may logon to staff laptops but only using their own login and must be closely supervised at all times". Forgetful staff will see students using another colleges laptop and will think it is OK without considering how they are doing that (so they will allow them to use their own login to print a document from a USB drive etc.

 

There are other ways to reduce some of the risks, I though stopping logins would be quite neat, simple and cheap (in terms of effort). @LeMarchand probably puts his finger on a huge downside. Also changing local policy as suggested would involve altering each laptop - which sounds like quite a bit of work required in the short term.

 

Lessons are engineered now that students use interactive features to aid learning from teaching workstations. By restricting that access you will be hindering modern teaching techniques in getting the students involved.

There has to be a balance between that and security. We provide plenty of means of access for students which teachers can avail themselves of in a classroom with a little thought and planning.

Edited by pcstru
Posted
1. It is not possible to force teachers to store documents in the places we make for them, so as well as the desktop, teachers may store confidential documents in local folders that are accessible to all users or the usb drive hanging off the side of the laptop.

 

While I agree that students shouldn't be logging onto staff machines, I'd query the above.

 

Why can't you stop them? Redirect the desktop etc, and restrict the C drive. Where else would they save but network drive? :)

 

Steve

Posted (edited)
While I agree that students shouldn't be logging onto staff machines, I'd query the above.

 

Why can't you stop them? Redirect the desktop etc, and restrict the C drive. Where else would they save but network drive? :)

It is certainly worth thinking about but not what we do at the moment and I suspect it is more effort than restricting logins which itself might be too much effort at the moment). I think if I proposed restricting USB drives, I'd have a huge fight on my hands (and in reality they are as much as or more of a risk).

Edited by pcstru
Posted
It is certainly worth thinking about but not what we do at the moment and I suspect it is more effort than restricting logins (which itself might be too much effort at the moment). I think if I proposed restricting USB drives, I'd have a huge fight on my hands.

 

Aye fair enough :) Just wondered.

 

In regards to the USB bit just restrict them (removable devices etc) on staff machines for students. Then even if Staff save to them, they wouldn't mount for students if they did log on a staff machine :)

 

Steve

  • Thanks 1
Posted
Also changing local policy as suggested would involve altering each laptop - which sounds like quite a bit of work required in the short term.

 

I should point out that even though it can be done with secpol.msc on the clients, this change can be made centrally based on OUs, WMI queries etc as it's accessible through Group Policy as well as Local Security Policy.

  • Thanks 1
Posted
I should point out that even though it can be done with secpol.msc on the clients, this change can be made centrally based on OUs, WMI queries etc as it's accessible through Group Policy as well as Local Security Policy.

 

Yup, I do it through GP.

 

So much easier.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...