Jump to content

Recommended Posts

Posted
To add to my previous comment, our IT technician explained we have a CISCO ASA which offers fail-over if one line goes down, provides additional security and manages all internal networking, including load balancing. We additionally have Smoothwall. The website is currently hosted by Google but we will split in the future to Google only for secure internal requirements and use a provider (GoDaddy) for the public site. So to summarise, our only need for a Windows server is to manage a small number of windows users, which we need to provide Office support and where we have dependencies on Windows software (or should I say apps nowadays!). For example, I'm told our interactive whiteboard needs a window box as the software for it only runs on that platform. So unfortunately it looks as we are stuck with having to bring our first server in to the school. If google can develop an MS Office killer with 100% compatibility, come up with a solution that is at least as good as Windows user management (I'm told) and have a competitive solution for every school application that is currently Windows only... well I'll let you decide...
Posted
So to summarise, our only need for a Windows server is to manage a small number of windows users, which we need to provide Office support and where we have dependencies on Windows software (or should I say apps nowadays!). For example, I'm told our interactive whiteboard needs a window box as the software for it only runs on that platform. So unfortunately it looks as we are stuck with having to bring our first server in to the school. If google can develop an MS Office killer with 100% compatibility, come up with a solution that is at least as good as Windows user management (I'm told) and have a competitive solution for every school application that is currently Windows only... well I'll let you decide...

 

You may have missed my post (previous page) about how you don't need windows server (and CALS) to manage windows logins anymore. 20 years ago it was the only option, but nowdays you can do it on OSX,Linux or unixes and bypass the CAL's. Keep a few windows machines by all means, but don't get sucked into an EES agreement for a few machines.

Posted
Do you have more detail you can add to the Mac server scenario. £14 would light up eyes, but surely that doesn't include hardware? I presume it also means we would be adding hardware on site. From other discussions, I'm keen to explore alternatives to keep the school entirely cloud based. One suggestion I wish to follow up on is a Azure AD cloud based solution - although as it's yet another MS offering, I will be researching further.
Posted
Do you have more detail you can add to the Mac server scenario. £14 would light up eyes, but surely that doesn't include hardware? I presume it also means we would be adding hardware on site. From other discussions, I'm keen to explore alternatives to keep the school entirely cloud based. One suggestion I wish to follow up on is a Azure AD cloud based solution - although as it's yet another MS offering, I will be researching further.

 

Having looked in more detail, you would still need to use SAMBA on OSX but the mac server may still be useful for DHCP and DNS.

For off site hardware there are many cloud providers such as Amazon, Microsoft, Google and others that would allow a full non-windows domain controller to run off site.

Posted
Do you have more detail you can add to the Mac server scenario. £14 would light up eyes, but surely that doesn't include hardware? I presume it also means we would be adding hardware on site. From other discussions, I'm keen to explore alternatives to keep the school entirely cloud based. One suggestion I wish to follow up on is a Azure AD cloud based solution - although as it's yet another MS offering, I will be researching further.

You'd need Apple hardware, but a basic Mac mini would do the job - £400 ex-vat new from Apple and I'm sure you could get a better price or go refurb.

Having looked in more detail, you would still need to use SAMBA on OSX but the mac server may still be useful for DHCP and DNS.

For off site hardware there are many cloud providers such as Amazon, Microsoft, Google and others that would allow a full non-windows domain controller to run off site.

Would you need SAMBA for user logon or only if you wanted to have network shares?

Posted
Would you need SAMBA for user logon or only if you wanted to have network shares?

Yes Samba can be used for Windows logons, windows shares and printing. I think it even does group policies these days too.

My suspicion is that this is one of the reasons that Microsoft want people to move to their cloud now, because it is getting easy to not need windows servers and pc's.

Posted

As @jmak said, a basic mac mini would do the job and is less of a physical footprint than a standard Windows PC.

The Azure AD solution could work, users would log in to Windows 10 devices (note must be Windows 10) with their O365 credentials. You can also use Microsoft Intune to manage the users and devices to a certain degree - nowhere near the level that you can with an on-site Windows domain with GPOs etc. but probably sufficient for admin staff. This SaaS model is certainly one that Microsoft are encouraging to use in the corporate space, it's just not quite there for general use in the educational environment with shared devices that are used by pupils.

I would avoid hosting a server in something like Azure/AWS/Google for this purpose - if the only requirement is to have a Microsoft device with Office and the user be authenticated then hosting a server for this would be overkill and could end up being quite costly if it is not configured correctly. Everything in those instances is pay as you go essentially so you won't know the real cost until you actually use it.

Posted
If everything is saved in Google / O365, do you actually need to log in to the PC? If it is just a few machines, could you set them up standalone and tell staff to log in to Google / O365 as themselves?
Posted
If everything is saved in Google / O365, do you actually need to log in to the PC? If it is just a few machines, could you set them up standalone and tell staff to log in to Google / O365 as themselves?

 

How would you then monitor the internet for stuff outside of Office 365 and Google?

Posted
How would you then monitor the internet for stuff outside of Office 365 and Google?

 

Do you need to uniquely identify web traffic if it is just staff?

Posted
Do you need to uniquely identify web traffic if it is just staff?

 

According to prevent yes.

 

Anyway if you are using something like Chromebooks logging in takes just seconds.

Posted
If everything is saved in Google / O365, do you actually need to log in to the PC? If it is just a few machines, could you set them up standalone and tell staff to log in to Google / O365 as themselves?

 

The problem with this is whether the users can be trusted not to save anything locally, especially if there could be sensitive data. There is also no way then of managing the machine so any of the users can install whatever they want, whenever they want.... not great from a security perspective.

Posted
According to prevent yes.

Prevent only applies to students, doesn't it? Our Lightspeed monitors everyone and staff are informed we're doing this, but I don't think we have a legal obligation to uniquely trace staff internet use.

Posted
Prevent only applies to students, doesn't it? Our Lightspeed monitors everyone and staff are informed we're doing this, but I don't think we have a legal obligation to uniquely trace staff internet use.

 

It applies to anyone on site.

Posted
The problem with this is whether the users can be trusted not to save anything locally, especially if there could be sensitive data. There is also no way then of managing the machine so any of the users can install whatever they want, whenever they want.... not great from a security perspective.

 

Tell them not to save locally, and if they do, it's their responsibility/problem (just like we did with Laptops for Teachers or memory sticks, just like we do now with iPads). As for managing them, create two user accounts, one with admin rights and one for everyone else. Not a scalable solution, obviously, but if you're only talking a handful of admin PCs and want to save every penny you can, it might work. We do that with a few laptops which we keep for dedicated exams use.

Posted
Prevent only applies to students, doesn't it? Our Lightspeed monitors everyone and staff are informed we're doing this, but I don't think we have a legal obligation to uniquely trace staff internet use.

 

Also lightspeed will only look at Internet traffic. What if a student or staff member had made a word document with questionable content?

Posted
The problem with this is whether the users can be trusted not to save anything locally, especially if there could be sensitive data. There is also no way then of managing the machine so any of the users can install whatever they want, whenever they want.... not great from a security perspective.

 

With Chromebooks you don't need any servers onsite and everything saves to the cloud, yet you can still do per user content filter and restrict what is installed.

 

I think the issue is for those who really need/want to keep some windows computers but find the cost of having just a few windows machines is now massive for comparatively little benefit. At least that's the situation I am in and am looking towards those things like SAMBA for help.

Posted
Also lightspeed will only look at Internet traffic. What if a student or staff member had made a word document with questionable content?

 

There's no legal obligation to monitor like this is there? Force everyone to save to drive, you then can make use of Google Vault if need be.

Posted
Also lightspeed will only look at Internet traffic. What if a student or staff member had made a word document with questionable content?

 

Then we'd have to identify that by other means, just like we would do if they brought in a questionable book.

Posted
There's no legal obligation to monitor like this is there? Force everyone to save to drive, you then can make use of Google Vault if need be.

 

As the internet isn't the only way to distribute questionable content. What if you had a student creating a word document he then distributed to his mates. I don't think it's a requirement under Prevent but we decided to implement it anyway.

Posted
As the internet isn't the only way to distribute questionable content. What if you had a student creating a word document he then distributed to his mates. I don't think it's a requirement under Prevent but we decided to implement it anyway.

 

With reference to the article title: "Google schools" - they don't have word, and "disallow external storage" means that the internet is the only way to distribute content.

Posted
With reference to the article title: "Google schools" - they don't have word, and "disallow external storage" means that the internet is the only way to distribute content.

 

Still the potential to share questionable content via a shared Google Doc of course (we have students using shared Docs as unblockable chat clients!). This is where things like Securus come into their own, if you're rich enough. Otherwise, accept/admit technical monitoring only goes so far and make sure your other safeguarding policies are solid.

Posted
If everything is saved in Google / O365, do you actually need to log in to the PC? If it is just a few machines, could you set them up standalone and tell staff to log in to Google / O365 as themselves?

This is something we've considered, but as we grow to 1000+ pupils and number of staff that would lead to, we feel individually managed machines would be too much work. There are a number of circumstances where we need full desktop office software, and/or windows platforms machines, sometimes due to third party software dependencies. However, I believe we can keep the numbers to a low level.

Posted
I wouldn't dream of individually managing sufficient machines for 1000+ users! I got the impression (possibly incorrectly) we were talking about a handful for admin staff only.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...