Jump to content

Recommended Posts

Posted
we brought 10 here for SLT members, after a month or so of arguing with an SLT member that an un-managed device was going no where near the schools network she eventually backed down. So all our ipads are restricted. no apps, no personal accounts etc.

Its worth noting, i did offer the hands off approch, as in they could be given to the SLT member vanilla, but in this case i was refusing to let the Ipad access the schools data/network (Emerge(sims), Exchange etc).

So it became a choice, for SLT which did they prefer? being able to go on facebook using an app, or being able to access student DATA. I was not going to back down over data, can you imagine the uproar of one of these slt members had "lost" their pad with potentially access to all that data?... No, we as a school must have had control over the data that device is accessing.

 

Some of our SLT have ipads that have their gmail and google drive on them, we simply enforced a password/pin lock on them to secure them - in the same way we insist laptops are encrypted or use bitlocker.

Posted

iPads are encrypted by default, so I see no problem with accessing school data on them so long as you lock various settings down. We're a firm believer that school provided equipment should meet the needs of the school first and that home use is an added bonus.

 

This means that we get staff to ask us to install Apps via Meraki and VPP (we haven't ever declined an app, so they're OK with this, particularly as it means we'll often pay for the apps out of our budget) and that we lock down various account settings so that they can't be sending school data all over the place.

Posted

We have close to 500 iPads deployed both student and teacher.

 

MDM is a must, as is having the devices supervised, preferably with DEP as that adds even more advantages such as being able to push iOS updates via the MDM on mass. Also if the devices is activation locked with an Apple ID by the staff member when they leave the MDM will have a code you can pop in the password box to vipass and remove Apples activation lock.

 

Staff are free to install what ever apps they want off the App Store and we allow reasonable personal use within the confines of our AUP, so we would not expect say Grindr to be installed, but if they want Facebook and Candy Crush thats fine. We don't lock the staff iPads down at all in terms on restrictions, the MDM for us in regards to Staff iPads is purely there so we can regain ownership of the device, push out paid Apps from the App Store and some default configurations we want.

Posted
the MDM for us in regards to Staff iPads is purely there so we can regain ownership of the device

That's my concern with our set-up, as we can't wipe AppleIDs off the devices. Staff are told to reset the iPad before returning it, and we check it has been done. Still a risk, though, but I suspect Personnel could deduct the cost from final salary if it came to it.

Posted
I'm sorry but I think that's overkill. I understand not allowing unmanaged devices full access to the school network, but you could put them on a locked-down SSID which can access the Internet and nothing more (our staff SSID is a bit more open as we want to allow AirPlay)

 

Your SLT and all staff are already taking "all that data" off site, they're just doing it on memory sticks and paper. By denying them access to a password-protected encrypted iPad, you're arguably making the data more vulnerable not less...

 

you're presuming 3 things, firstly, that we allow un-encrypted USB devices, or usb storage devices at all. we are in-fact already phasing out the use of such a device for both students and staff.

 

Secondarily we are also limiting what data staff need to take off site, onto their laptops, as we offer full remote apps (with the obvious clipboard/usb/device forwarding disabled). Using their primary domain credentials, and secondary credentials as authorization, they have to access the data remotely. Yes this can be open to attack from a third party, but as long as the system is monitored this can be negated to an extent.

 

Thirdly at the time of the implementation, we had no way of offering "net only" access to devices, due to the way our managed service provider had implemented the infrastructure, it was a case of all or nothing, this could now be revisited.

 

you are however correct in saying I/we cannot close the "analog" hole, even though our bursar would love the idea of a paper free school.

 

Additionally, as i think was mentioned a few minutes ago, we never (yet) turned down requested applications all of the restrictions where put in place to protect the data that device might get access to. School comes first, rest after.

 

Additionally as i read my previous post i do see it might come across as a bit arsey, this wasn't my intention and i apologize if it came across as such.

Posted
you're presuming 3 things, firstly, that we allow un-encrypted USB devices, or usb storage devices at all. we are in-fact already phasing out the use of such a device for both students and staff.

 

Secondarily we are also limiting what data staff need to take off site, onto their laptops, as we offer full remote apps (with the obvious clipboard/usb/device forwarding disabled). Using their primary domain credentials, and secondary credentials as authorization, they have to access the data remotely. Yes this can be open to attack from a third party, but as long as the system is monitored this can be negated to an extent.

 

You're right, that does make it more secure! Although I wonder how many staff are emailing files to their home accounts rather than lugging a laptop home each day...

 

we never (yet) turned down requested applications

Roughly how much time would you estimate you spend checking and then allocating apps for staff, both educational and recreational apps? Also, do you find that staff having to go through IT to get apps installed limits their desire to do so, or do you still get lots of requests? We took a conscious decision to allow staff free rein over app installation, as we wanted staff to "make the iPads their own" as we felt this would encourage the uptake and engagement, but I do see the merit of your "school first, personal second" approach.

 

My apologies if I also across a bit snappy/sarcastic in my response.

Posted

one of the things we did when we first implemented the ipads was go to the SLT member to determine their requirements (professional and personal). once the SLT had decided the list of apps they required, this was then checked for suitability in the corporate and education environment. this list was then used as a basis. (this list did include things like youtube, rail timetable apps, radio apps etc). we found the majority of new SLT members requirements where covered by this list.

We do not have a load of units, just units issued to out SLT team (about 15 members).

 

So in the cases of a new app needing to be added, i would say since the solution went in only about 4/5 apps have been added since. so the time consumed has been nominal.

 

I do agree that by limiting the installation of apps, could then limit their desire, to help combat this we allow use of the store/itunes so they can browse and select apps, using their laptops. If they see anything they like, they let us know the name/ID of the app, and we take it from there (they just cant install anything)

 

 

If we where to expand out Ipad estate, then i fully admit the solution will need another in-depth look.

Posted
If we where to expand out Ipad estate, then i fully admit the solution will need another in-depth look.

 

That could the difference between our schools - all our teaching staff plus a few others (Premises Team, family key support worker) have iPads, so over 60 in total.

Posted

I think the problem we're seeing with ipads is that staff are constantly being told about a 'new app' which is this weeks 'best thing ever for ' so they want to try it right now!

 

Next week the next best thing rolls along again etc....In the couple of years we've been supporting ipads the life expectancy of an app (free or paid) is very short apart from the core ones like Youtube etc.

Posted
I think the problem we're seeing with ipads is that staff are constantly being told about a 'new app' which is this weeks 'best thing ever for ' so they want to try it right now!

 

And I don't see anything wrong with that. Many of those apps will turn out to be garbage but some of them will be good, so why not allow the teachers to try them? I'd be concerned they might be reluctant to ask IT to install in fear IT would follow up in a few months and say "how are you getting on with XYZ app?". Plus, there's no way I'd be able to look at the app and judge whether it is garbage or whether it truly is the best thing ever for Physics.

Posted
And I don't see anything wrong with that. Many of those apps will turn out to be garbage but some of them will be good, so why not allow the teachers to try them? I'd be concerned they might be reluctant to ask IT to install in fear IT would follow up in a few months and say "how are you getting on with XYZ app?". Plus, there's no way I'd be able to look at the app and judge whether it is garbage or whether it truly is the best thing ever for Physics.

 

I don't disagree with that, it was more of an observation. However many ipads anyone deploys they way they are managed will have to be quite different to the desktop/laptop stock.

Posted
However many ipads anyone deploys they way they are managed will have to be quite different to the desktop/laptop stock.

 

Agreed. Saying "this is how we manage our desktop PCs, so it is how we will manage our iPads too" is missing some of the possibilities offered by new technologies. Equally of course, what works here might not suit you, and vice versa. If a school thinks about it and decides to manage them in a locked-down way, that's their choice for their school. As long as they've thought about it, I'm happy - much like all the people who vote the "wrong" way in elections... :-)

Posted (edited)
The problem with that is things like Youtube are 17+ - trying telling a teacher they can't install youtube and they will have a fit.

 

Exactly. I just registered for this forum and frankly, the level of restriction it seems most people on here use on their staff is baffling. If I tried to tell a professor doing research programming they couldn't have admin rights on a computer, they'd never accept it. Much less telling someone they can't have YouTube/anything on an iPad. Also, I think it's very important that you be careful with talking about reporting someone. Our only job in IT is to monitor performance and operation of equipment. It isn't IT's job to report what is not "appropriate" much less what is not "relevant". The uni I work for actually makes this very clear in our policies, and clear that if we are investigating operational issues and stumble across a legal or HR issue, we're to immediately stop, report it up the chain, and get out of the situation. We're not law enforcement, or HR enforcement. We're IT.

 

I've stumbled across a lot of interesting things, including porn, at my last university. None of it reported, as no laws were being broken, no one was endanger, and I'm certainly not HR policy enforcement. Why would you want to take on that job?

 

To that end, I manage iPads the same way I manage computers - the goal is to restrict as little as possible to meet the goals of secure, supportable operation. If a staff member wants local admin rights, they get it after acknowledging the risks in writing. If they want firewall restrictions changed (some want SSH, etc), they get it, after filling out an information security form required by policy. And if they want YouTube or any other 17+ app they feel is relevant to their job, they certainly get it, with their own AppleID.

 

My interest is in preventing viruses, protecting data (enforcing encryption, secure passwords, etc), and supporting the academic mission of the university by providing repair and technical support. I'm not interested in what is "relevant" to someone's job or what is "appropriate". What do those words even mean? Even, at the extreme, the study of hardcore porn could have a relevant place in an anthropology course or similar.

 

P.S. This view is obviously shaped by the fact I'm the IT manager for a very research-heavy and technically-minded department at a university, and I provide technology for staff and mostly post-graduate students (with a small number of undergraduates with specific computing needs). Obviously, if I was supporting primary/secondary it'd be much different in terms of my argument that appropriateness doesn't matter. However, I'd still argue it's not an IT job - and I certainly would never want to work in IT if my boss was asking me to also play appropriateness cop. If I run across something, that's one thing. But I would never feel comfortable proactively looking for violations. I make computers work, I'm not a cop or a private investigator.

Edited by Allie
Posted
Exactly. I just registered for this forum and frankly, the level of restriction it seems most people on here use on their staff is baffling. If I tried to tell a professor doing research programming they couldn't have admin rights on a computer, they'd never accept it. Much less telling someone they can't have YouTube/anything on an iPad. Also, I think it's very important that you be careful with talking about reporting someone. Our only job in IT is to monitor performance and operation of equipment. It isn't IT's job to report what is not "appropriate" much less what is not "relevant". The uni I work for actually makes this very clear in our policies, and clear that if we are investigating operational issues and stumble across a legal or HR issue, we're to immediately stop, report it up the chain, and get out of the situation. We're not law enforcement, or HR enforcement. We're IT.

 

Unis and Schools are quiet different environments in many aspects. In schools there is still a large duty of care in everything you do as most children are underage.

Posted
Unis and Schools are quiet different environments in many aspects. In schools there is still a large duty of care in everything you do as most children are underage.

 

Fair point, as I noted at the end of my post. I still find it strange to apply the level of restriction one would apply to students, to staff.

Posted
Fair point, as I noted at the end of my post. I still find it strange to apply the level of restriction one would apply to students, to staff.

 

You're possibly overlooking the number of times students are using a staff member's device/logon. A teacher might lend a student their iPad because the student has forgotten theirs, and you wouldn't want that student to be able to access age-inappropriate websites. Similarly, the more tech-savvy student might take the opportunity to download a key-logger while using the teacher's classroom PC, hence not giving them local admin rights. You also need to protect against staff taking copies of licensed software and installing them at home or in their next school.

Posted (edited)
Exactly. I just registered for this forum and frankly, the level of restriction it seems most people on here use on their staff is baffling. If I tried to tell a professor doing research programming they couldn't have admin rights on a computer, they'd never accept it. Much less telling someone they can't have YouTube/anything on an iPad. Also, I think it's very important that you be careful with talking about reporting someone. Our only job in IT is to monitor performance and operation of equipment. It isn't IT's job to report what is not "appropriate" much less what is not "relevant". The uni I work for actually makes this very clear in our policies, and clear that if we are investigating operational issues and stumble across a legal or HR issue, we're to immediately stop, report it up the chain, and get out of the situation. We're not law enforcement, or HR enforcement. We're IT.

 

I've stumbled across a lot of interesting things, including porn, at my last university. None of it reported, as no laws were being broken, no one was endanger, and I'm certainly not HR policy enforcement. Why would you want to take on that job?

 

To that end, I manage iPads the same way I manage computers - the goal is to restrict as little as possible to meet the goals of secure, supportable operation. If a staff member wants local admin rights, they get it after acknowledging the risks in writing. If they want firewall restrictions changed (some want SSH, etc), they get it, after filling out an information security form required by policy. And if they want YouTube or any other 17+ app they feel is relevant to their job, they certainly get it, with their own AppleID.

 

My interest is in preventing viruses, protecting data (enforcing encryption, secure passwords, etc), and supporting the academic mission of the university by providing repair and technical support. I'm not interested in what is "relevant" to someone's job or what is "appropriate". What do those words even mean? Even, at the extreme, the study of hardcore porn could have a relevant place in an anthropology course or similar.

 

P.S. This view is obviously shaped by the fact I'm the IT manager for a very research-heavy and technically-minded department at a university, and I provide technology for staff and mostly post-graduate students (with a small number of undergraduates with specific computing needs). Obviously, if I was supporting primary/secondary it'd be much different in terms of my argument that appropriateness doesn't matter. However, I'd still argue it's not an IT job - and I certainly would never want to work in IT if my boss was asking me to also play appropriateness cop. If I run across something, that's one thing. But I would never feel comfortable proactively looking for violations. I make computers work, I'm not a cop or a private investigator.

 

I dont like to think I am law enforcement either, but staff are given these devices for work purposes and they do not belong to them. I allow them the freedom to pretty much do as they like but if things are installed on it that aren't relevant to work then this is a problem, since it breaches their AUP. I would of course handle things diplomatically, having a quiet word with the member of staff in question first however if this didn't resolve the problem it would be escalated further. Not sure about any of you but if I knew a device wasn't being used according to the AUP and I kept it quiet people would start asking questions.

 

- - - Updated - - -

 

You're possibly overlooking the number of times students are using a staff member's device/logon. A teacher might lend a student their iPad because the student has forgotten theirs, and you wouldn't want that student to be able to access age-inappropriate websites. Similarly, the more tech-savvy student might take the opportunity to download a key-logger while using the teacher's classroom PC, hence not giving them local admin rights. You also need to protect against staff taking copies of licensed software and installing them at home or in their next school.

This happens so often, especially in primaries.

 

EDIT: I dont go out of my way to find problems either. You are making it sound as if I sit at my desk all day checking peoples iPads to make sure they havent installed candy crush on it. If I see an app I mention it. Staff are usually very good with it as they are made aware beforehand that we can see what is installed on the device. I would also like to point out that in my post i put CAN be reported, not saying that I would. I am by no means a horrible person that likes to get others into trouble for the sake of it.

Edited by tmoon-mint
Posted

*sighs*

 

Firstly iPads need to be supervised that's both for staff and students and both need to be enrolled into the MDM you are using, why?

 

Because with Supervision you can do the following;

 

Remove the activation lock from an iPad if the teacher has left without giving you the Apple ID.

You are free to push school owned apps to the iPads and revoke those apps if the iPad breaks or goes missing, you would push these apps via device assignment.

 

If teachers want to either buy free or paid for apps then just give them the choice at their own expense..

 

Basically an Apple ID is not tied to a device, so if teachers have purchased content themselves they can still get access to this on either a personal or school owned device...without a war and peace statement having to be written about this policy

  • Thanks 2
Posted
Fair point, as I noted at the end of my post. I still find it strange to apply the level of restriction one would apply to students, to staff.

 

I've seen so many times the problems with staff letting students use their accounts.

 

First secondary school I worked in heaps of stuff was routinely deleted from shared area's and/or folders renamed

 

Requests for inapprorite web sites to be allowed, had an instance where a proxy avoidance site was asked for via a staff members account, it weren't till I verified the site and confronted and verified with the teacher what they asked for.

Posted (edited)

All teachers have one here, they can use their own Apple ID's though most choose to create a new one with their school email which we do encourage just in case overly personal photos end up on their school iPad via photostream or vice versa with pupil photos. No restriction on apps, if they want school ones purchased then I buy them with VPP and assign them to their Apple ID, taking them away if they leave of course.

 

To be honest, most staff already have a personal iPad and so rarely use the school ones for that, those that do it's just iPlayer and stuff from what I've seen. The level of risk is low and so I spend very little time administering or monitoring them

Edited by sidewinder
Posted
All teachers have one here, they can use their own Apple ID's though most choose to create a new one with their school email which we do encourage just in case overly personal photos end up on their school iPad via photostream or vice versa with pupil photos. No restriction on apps, if they want school ones purchased then I buy them with VPP and assign them to their Apple ID, taking them away if they leave of course.

 

To be honest, most staff already have a personal iPad and so rarely use the school ones for that, those that do it's just iPlayer and stuff from what I've seen. The level of risk is low and so I spend very little time administering or monitoring them

 

How I view it, but how can you revoke an app given to an Apple ID? I haven't tried, but I thought they could only be revoked if assigned to a device. I am absolutely not arguing against MDM, just against the level of restriction on staff. Maybe it's different in a university, but I can't imagine the revolt my staff would create if I gave them iPads with any restrictions on what they could install.

Posted (edited)
How I view it, but how can you revoke an app given to an Apple ID? I haven't tried, but I thought they could only be revoked if assigned to a device. I am absolutely not arguing against MDM, just against the level of restriction on staff. Maybe it's different in a university, but I can't imagine the revolt my staff would create if I gave them iPads with any restrictions on what they could install.

 

I use Meraki and when I 'retire' a user it says all assigned licences will be removed from their purchase history after a grace period of 30 days and reassigned to the school. Or you can revoke licences per app for a user. I'll be honest I've never kept an eye on whether the licence count does go up again but it must do or we would have run out of licences of apps we push to all staff iPads :)

 

Edit: also I agree with your views on restrictions (aside from local admin on PCs). There is no reason for me to be difficult or restrict staff unless it undermines the security of the network. They sign an AUP, it's not up to me to enforce they stick to that by imposing restrictions. Some views on this forum perplex me at times. I work at an independent school though and staff are generally given a fair amount of freedom and trust.

Edited by sidewinder
Posted
I'm curious as to what paid apps you guys are putting on iPads. In the two years we've been using iPads, I've only been approached once about a paid app, and even then we didn't install it because Google updated the Drive app so MP3s could be played through it meaning we no longer needed the play-your-MP3s-from-Google-Drive app.
Posted

*sighs again*

 

You have always been able to revoke an app purchased via VPP managed distribution and pushed via an MDM whether that app is assigned to the teachers Apple ID or the device.

Posted
I'm curious as to what paid apps you guys are putting on iPads. In the two years we've been using iPads, I've only been approached once about a paid app, and even then we didn't install it because Google updated the Drive app so MP3s could be played through it meaning we no longer needed the play-your-MP3s-from-Google-Drive app.

 

PE co-coordinators seem to purchase a fair few. Coaching apps and the like. Some dance things as well.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...