Jump to content

Recommended Posts

Posted

Morning all

 

Over Summer we are introducing laptops to teachers to replace their ageing desktop classroom PC's. Given the device we've purchased I'm thinking Windows 10 will be the most suitable O/S to stick on them. With all that in mind I was looking for any helpful "best practice" suggestions on how to set them up to work seamlessly between home and school domain environments.

 

Many thanks

Posted

I hope you've got an IT Engineer just for the laptops as laptops take up a lot of time to manage and support.

 

With using Windows 10 you'll need 2012 Servers. Also, have you tested your wireless network to see if they can cope with the laptops. I recommend a VPN or proxy switcher. Also, have a policy to cover the laptops as well.

Posted

Couple of things. Don't let teachers have local admin permissions. We don't here, and it reduced the support time required for teacher laptops to a tenth of what it was before. If staff want drivers for their home printer or whatever, we will install them for them, and we have a library of software available for installation via SCCM's application catalog.

 

No-one has had any virus issues with it since the change here, for example, except for a couple of USB stick transmitted ones (which will be eliminated once our new WAN is up and running and we will disable USB stick use!)

  • Thanks 1
Posted

Direct Access is the way forward with a local Pac file and IIS configured on your server. Its abit tricky to setup but its worth it in the long run.

 

I have windows 10 laptops in most of my schools which I have set them up on the domain with a domain account with local profiles so they can still save stuff on there desktop etc.

 

Just set your GPs with giving staff access with there domain accounts to have local admin access on there staff laptops which they can have access to download resources,

 

Also I have created a directory on the server to copy icons to staff laptops on there accounts when they login, this copies the icon to the public folder profile which applies this to everyone who uses any laptop.

 

Mapping the Drives which you need can be done via GPs aswell for staff when they arrive in the school

Posted
If staff do not have remote access to your servers on site to access there work then local admins is the way forward, as someone mentioned said about restricting staff and making sure no virus are on staff laptops is good and keeps your IT department busy but its abit harsh to restrict them and coming to see you a lot of the time
Posted

I have laptops for all our teachers. We use One Drive because it is free with O365. I've insisted that everyone taking laptops home uses it.

 

I allow staff local admin rights, because I sure as hell aint putting a password in every time someone needs to update java. I have had minimum issues because staff know that this is a WORK laptop and they can't be installing games and letting their kids loose on it.

 

Staff here are pretty good though...

  • Thanks 1
Posted
I have laptops for all our teachers. We use One Drive because it is free with O365. I've insisted that everyone taking laptops home uses it.

 

I allow staff local admin rights, because I sure as hell aint putting a password in every time someone needs to update java. I have had minimum issues because staff know that this is a WORK laptop and they can't be installing games and letting their kids loose on it.

 

Staff here are pretty good though...

 

Same here, if they get a virus by installing something stupid its there own fault and they will lose their laptop and work stored on it. Our staff are pretty good too.

  • Thanks 1
Posted
I have laptops for all our teachers. We use One Drive because it is free with O365. I've insisted that everyone taking laptops home uses it.

 

I allow staff local admin rights, because I sure as hell aint putting a password in every time someone needs to update java. I have had minimum issues because staff know that this is a WORK laptop and they can't be installing games and letting their kids loose on it.

 

Staff here are pretty good though...

 

Ah, all updates and the like are handled by SCCM here, so there's no password entering for updates. I have had to put an admin password about once a week total for our fleet of 50 staff laptops here since the change.

Posted
I have laptops for all our teachers. We use One Drive because it is free with O365. I've insisted that everyone taking laptops home uses it.

 

I allow staff local admin rights, because I sure as hell aint putting a password in every time someone needs to update java. I have had minimum issues because staff know that this is a WORK laptop and they can't be installing games and letting their kids loose on it.

 

Staff here are pretty good though...

 

That's what we do.

A few broken screens, easy to replace at their cost if its caused by them, touch wood no viruses. Most of them treat them with respect, but the constant unplugging of the USB and VGA for use in class does sometimes mean the ports and cables get damaged.

Posted

No one has admin rights, no one has executable rights to anything I didn't install using SRP.

 

WPAD for proxy so automatically works at home and work.

 

Firewall set to lock down for public networks, auto set everything that's not work network to public.

 

Offline files for home drive.

 

Keep a super old dirty laptop around to lend to staff who break their laptop

 

If you can afford it, a usb3 docking station in each classroom is handy to connect projector, whiteboard, speakers etc with 1 cable.

 

Worth using software inventory to make sure they're being rebooted enough to install GPO software, and monitor WSUS to make sure they're getting updates.

 

Make sure AV updates can work from home too.

Posted

Our setup is as mavhc we just treat them as a desktop except encryption and offline files.

 

Usb storage is disabled.

 

We also had added a few lines in the Aup about checking condition of the device regularly particularly chargers.

 

We also added a bit about physical security ie not leaving it in your car etc.

 

Cost of ownership of laptops is more might be worth adding a few quid for replacement chargers / screens etc.

Posted

For setting up Windows 10 for staff, I highly recommend following the advice @Arthur gives here: http://www.edugeek.net/forums/windows-10/165029-how-get-rid-candy-crush-soda-saga-other-windows-10-start-menu-junk-good-2.html

 

I removed everything apart form the News App, gives a neater, more work like Start Menu.

 

Also trialling NOT giving local admin rights to staff this time around. The threat of Crypto viruses, combined with VPN access, has got me spooked enough that I don't want to come in Monday morning to find all files encrypted over the weekend by a mistake by a member of staff...

 

Otherwise, staff seem to like Windows 10. Helps that the laptops are very snappy! Also highly recommend docking stations as well if you can get them.

Posted

Thanks for all the feedback, guys. Helpful to find out from people who already provide laptops to staff.

 

Seems to be bit of consternation regarding local admin access.

Posted
You can have local admin, or you can have secure computers, tell them to pick one. Invoke the Data Protection Act, no security = no data protection
  • Thanks 1
Posted (edited)

We moved away from the staff laptops a while ago (apart from some SLT and HODs) and every classroom has a decent PC in it (all SSD based). Staff are expected to use their own laptop/home pc as they all have one and can remote in to the school via Citrix or simply access the VLE for resource whilst at home.

 

Keeps it simple and reliable for us - PCs are always online and ready for use, no cables to move around. In contrast in our primaries they all had laptops each and they were a nightmare, always missing power supplies, bent cables and broken ports from the constant movement. Most now have a PC in the classroom and they took the old laptops home!

 

I should mention those who do have laptops do not have local admin rights, they have an 'offline' login which has more relaxed restrictions but they still can't install whatever they want.

Edited by Sheridan
  • Thanks 1
Posted

We have laptops for virtually all staff and I have just upgraded them to Windows 10. No staff have local admin rights and havent for about 3 years, had some moaning to start with but now it is accepted, really cut down my work load. We have redirected documents and downloads and have them on sync (with a 6GB limit) so they can be used at home.

Decided against Direct access and stuck with VPN so the staff have to make the effort to connect to our network (i dont like the idea of them always being connected from a security point of view and we all know how interested in security some teachers are) I removed most of the windows 10 built in apps and then customised the start menu with common apps. The only user issues I had really was how to log off and how to find network drives.

Posted
We have laptops for virtually all staff and I have just upgraded them to Windows 10. No staff have local admin rights and havent for about 3 years, had some moaning to start with but now it is accepted, really cut down my work load. We have redirected documents and downloads and have them on sync (with a 6GB limit) so they can be used at home.

Decided against Direct access and stuck with VPN so the staff have to make the effort to connect to our network (i dont like the idea of them always being connected from a security point of view and we all know how interested in security some teachers are) I removed most of the windows 10 built in apps and then customised the start menu with common apps. The only user issues I had really was how to log off and how to find network drives.

 

Thanks for this. You raise an interesting point regarding DirectAccess.

 

This is a really basic question, but is there anything I need to consider regarding logons for staff? I have until this point assumed once they've logged on within the domain their profile will be cached and therefore they'd still be able to log on outside of our network.

Posted

All our staff have laptops, all on Windows 8.1 or 10 depending on when I last physically got my mits on it!

 

They all used their cached domain profile with folder redirection (so offline files takes care of sync issues), none of them have local admin rights, and they all have DirectAccess enabled so we can still update their machines etc over the summer period.

 

I would seriously look at deploying MDOP MBAM to forcefully manage BitLocker drive encryption though. We use MBAM so we can enforce BitLocker encryption on the OS drive with TPM and preboot PIN. This also makes key escrow easier on my end.

Posted
Im looking at the encryption side at the minute, been told it will be an ofsted requirement next year (but i think its might be a sales ploy) does bitlocker work well, ive not used it as yet
Posted (edited)
Im looking at the encryption side at the minute, been told it will be an ofsted requirement next year (but i think its might be a sales ploy) does bitlocker work well, ive not used it as yet

 

We've had 0 problems with BitLocker, but I wouldn't do it on a large scale without MBAM to manage it. Plus I can begin the encryption process before we even deploy our image with BitLocker pre-provisioning, so no waiting for hours :)

 

Bear in mind, a lot of encryption solutions (Sophos etc) are actually just frontends for BitLocker now.

Edited by Blue_Cookeh
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...