Mel_16 Posted February 1, 2017 Posted February 1, 2017 Our school is bringing in a laptop scheme, where our students buy the device, we set it up and then distribute it, however the device is essentially the students'. Obviously I can't add it to the school domain, but what GPO can I change to secure the devices when they come onto our site? They will mostly be using remote desktop connections to access the school's network. What do I need to look out for? What can I implement? To prepare the laptops to make them as secure as possible before distribution?
FN-GM Posted February 1, 2017 Posted February 1, 2017 You can't use any GPO if they not on the domain. Do you have the remote desktop setup already? They will be in effect un-managed devices so there is little you can do to secure them. Do you have a BYOD network setup already? Thanks
elsiegee40 Posted February 1, 2017 Posted February 1, 2017 It's usual to have a separate wifi network for BYOD devices
Mel_16 Posted February 1, 2017 Author Posted February 1, 2017 This is the first time we are running anything like this. We haven't done a BYOD before, so I'm pretty new to the whole setup.
kennysarmy Posted February 1, 2017 Posted February 1, 2017 Our school is bringing in a laptop scheme, where our students buy the device, we set it up and then distribute it, however the device is essentially the students'. Obviously I can't add it to the school domain, but what GPO can I change to secure the devices when they come onto our site? They will mostly be using remote desktop connections to access the school's network. What do I need to look out for? What can I implement? To prepare the laptops to make them as secure as possible before distribution? Your school is bringing in a scheme without having consulted with you about how it can be done securely?
caffrey Posted February 1, 2017 Posted February 1, 2017 (edited) Safeguarding to take into account too, Internet filtering etc. @kennysarmy Isn't that normal procedure ? Edited February 1, 2017 by caffrey 1
ThatBoringBloke Posted February 1, 2017 Posted February 1, 2017 You could take a look at Microsoft's Network Access Protection to make sure that the BYOD devices meet security requirements before being allowed access to network resources. I have never done this though, so have no idea if it is any good.
Katy Posted February 1, 2017 Posted February 1, 2017 I would have them on a separate wireless network and VLAN, with routing ACLs in place to stop them from going anywhere except the Internet (via the filter) and your Remote Desktop server. However you do need to make sure your RDS server(s) can cope with the load it is likely to get from potentially several hundred laptops trying to use it at once. If you can get Network Access Protection working then you can at least make sure they have up to date anti virus running before they can connect, don't forget to run AV on your RDS server as they will be able to directly copy files to/from the network via the remote desktop session. 1
Arthur Posted February 1, 2017 Posted February 1, 2017 What can I implement? Duo has access control policies that would block out-of-date and insecure devices from connecting to your network.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now