Jump to content

Recommended Posts

Posted

Hello, I wonder if people could advise.

 

A member of staff is wanting to buy himself a Windows Surface Pro, his own property, it won't be part of the domain. But he wants to be able bring the surface into school log into the staff drive and use printers, effectively as if it was part of the domain. I have concerns, obviously it won't be manged for Updates or AV. This member of staff is senior. Although not Head or DH. Being his property , I am not sure if I have any responsibility towards it, but he thinks I should. Do others have this issue in their schools. How do they address it ? Do others think it good practice ? I do plan to speak with the head about it, but it would be good to gather advice beforehand. If anyone has suggestions as to how I can deliver what he wants ? I am the only network person, and it is a small special school, so I am hoping someone with greater knowledge can assist.

 

Thanks in advance

Posted

Two ways of doing this:

 

  1. He hands it over, and it becomes part of the domain - managed and maintained by you. He has effectively donated it, though he could take it back at any time (with it then being returned to a workgroup machine)
  2. It follows your normal BYOD policy. That may mean no SIMS, separate VLAN with no drive access, limited printing etc. This would have limited support from you. Perhaps utilises a remote access solution

 

IMO there is no third option. Having a personal device that can access all of your services but under his control has got to be a no - the potential for your network to be compromised, for Data Protection to be breached, and for you to be permanently hassled with a workaround for one user is too great. If he wants to buy his own device to go on the domain that's fine IMO - but he accepts that it will act like any other domain joined machine. Otherwise, it's BYOD and the limitations that brings.

  • Thanks 1
Posted
I can see a 3rd option; treat it exactly the same as it would be at home. Do you have remote access to those files, SIMS etc? If he can therefore bring it in, connect to the wireless and use those same systems, covered by the same policies for remote access then surely that'd tick all the boxes?
  • Thanks 1
Posted
I agree. If it's a personal device, then it shouldn't be added to the domain. Here, we would allow it to connect via wifi to our BYOD VLAN, separate from the rest of the LAN and giving internet access only. In addition, we don't provide support for personal devices but aim to assist where possible. It's a can of worms, accepting responsibility for the myriad of different personal devices that staff might have. If you have an acceptable use/BYOD policy that covers this, I'd refer him to that. If not, then maybe you should think about creating one.
  • Thanks 1
Posted
Thanks for replies....good stuff. We do not have a seperate VLAN for BYOD, just the one flat subnet, wireless that is used by domain, I know...but we are only a very small special school.
Posted
How about workplace join as a 4th option. This will give a level of control and let you map printers etc. You could then do sims as a terminal server or remote app as mentioned above.
  • Thanks 2
Posted
Thanks for replies....good stuff. We do not have a seperate VLAN for BYOD, just the one flat subnet, wireless that is used by domain, I know...but we are only a very small special school.

 

Sounds like now is a good time to set up some segregation. One vulnerable BYOD device is all it takes to infect your trusted network.

  • Thanks 1
Posted

Sorry to be a party pooper but if you haven't got a policy for this, or anything to accommodate this currently setup, then I would say it is a part of a future project to be looked at. The issue I could see is if you accommodate them then the next person will use that as an allowance to do the same. You then could end up in a sorry state of affairs, suddenly supporting twice as many devices as before and troubles doing anything as everyone expects it as part of the usual service. If you try and then tighten it up people will scream blue murder that you are preventing them from working and won't somebody think of the children.

 

Head this way very slowly, carefully and with great thought. Don't just jump into VLANs to help this case, build a case for the whole school.

  • Thanks 1
Posted
None school device = not on school network. Could be used on BYOD if you have one. Weather senior or not all users to be treated the same, once he has his own connected everyone will want their own!
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...