ITGuyWestMidlands Posted October 23, 2016 Posted October 23, 2016 The best answer to having in read only is ransomware
Tefters Posted October 23, 2016 Posted October 23, 2016 Teachers here are too dumb and still ask students to email work to them once complete instead of using a hand=in repository share I created them (One of the reasons i farmed off Exchange to Office 365, email box space and crap is no longer my concern!). For the slightly more savvy teachers I set them up OneNote Class Notebooks which has read/write access. If it wasn't for my teachers being idiots I would allow them read/write as stated previously, they can write in homework books.
PyROm Posted October 24, 2016 Posted October 24, 2016 We are a secondary school and have Read only access. The teachers normally get students to email in their work for marking. The reasons we don’t have full access is:- - Some teachers are bad with touchpads/mice and have a habit of dragging folders into each other (and they can never remember which one they dragged it into), which could be bad if they dragged one students folder into another students. - Ransomware wise, it stops a teachers laptop/BYOD device/login wiping out all your students My Documents, which although presumably could be restored, has a time implication that may affect GCSE work (ie. can’t work for a lesson or 2 while files are being restored). - We have had it where a student accused a teacher of deleting work out of their folder, the student claimed they had done the work but it was now not there and the teacher must have deleted it, the student threatened the teacher with a formal complaint from their parents if they didn’t "redo" the work for them. Luckily we were read only so the teacher couldn’t have done it and so any complaint they could make would be dismissed. - We havent had this one but, if a student guesses a teachers password or gets on a teachers pc/laptop that they left logged in and hasnt locked then they could put all sorts of nasty stuff in students home folders, or even just delete them all, and the evidence would all point to the teacher. They may have a specific reason though so would ask what the reason is (probably ask SLT from the point of view of trying to solve the teachers problem in a better way) so you could offer a workaround.
kathabell Posted October 25, 2016 Posted October 25, 2016 Staff have read only access to student areas; we also have a "collaborative" work area which is accessible by a yeargroup of students where staff and students can work together. For controlled assessment, students have a separate logon account/user area with no internet access and other restrictions. These accounts are unlocked when required for a CA "lesson" and locked again when the lesson is over. No access to the data contained within by staff or students in the meantime. I would point out to SLT that if they want to give extended write access across accounts, you should also implement active logging of file editing/deletion etc. - a huge demand on resources, but necessary in case of any charges regarding unauthorised access/deletion etc. It is our professional responsibility to point out the pitfalls of what they see as a simple requirement
Patrick Posted October 25, 2016 Posted October 25, 2016 (edited) This has got me a little worried actually. We are a small primary school, a teacher/SLT member recently requested re-working the pupils folder layout, whilst also requesting write access to her class folder where student data is stored, but requesting that other teachers cannot see/view her class folder. Not sure what to do, i might go to the deputy (head unavailable) and explain these changes just in case he/she's unaware. The particular class (Year 6) had poor results last year as well, if that means anything. Not sure if i'm over thinking this or not. What do you guys think? Edited October 25, 2016 by Patrick
kathabell Posted October 25, 2016 Posted October 25, 2016 CYA and everything else; we need to be transparent in our application of the access rights and rules. Security access is based on a job role/need to have not a personal "I want" basis - that can only lead to catastrophe.
Patrick Posted October 25, 2016 Posted October 25, 2016 I'll see the deputy tomorrow and explain that the teacher could delete, or modify childs work. Intentional or not. When SLT instruct me to do something i generally do it as long it's not a ridiculous request. I think i was naive to the think that teachers having write access could used for potentially malicious purposes. Asking for write access for your own class students data and no one else having having read access should have me thinking a little more cautiously.
pete Posted October 25, 2016 Posted October 25, 2016 (edited) ^ I could understand: "Bob and Fred can have read access to my class, but they click around like misguided woodpeckers, so don't let them change things" But: "I want write access and no-one else should be able to see the files" + poor results? = Yeah, need some due diligence here. The person's actions may be completely innocent (poorly phrased request) but if you implement it as requested, they've put themselves in a position where accusations can be made and they (unless you're auditing file access to user shares by default) won't have a good defense against said accusations. It's your job as a sysadmin to draw attention to and guide your users around such potential landmines where possible. Edited October 25, 2016 by pete
Patrick Posted October 26, 2016 Posted October 26, 2016 I haven't actually implemented it yet, so i'll have a chat with the head/deputy when i can.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now