Theldron Posted February 21, 2018 Posted February 21, 2018 Hi all, The system that I inherited had staff laptops setup as standalone (with mapped drives) and staff with local admin rights on the laptop. With everything else including GDPR it is time to move away from that. How do other schools do that with regards to allowing accessing to drives remotely? I was looking at Offline files, but was recommended work folders. We do have Office365 so was also looking at mapping the users onedrive account? Any advice or recommendations would be brilliant Thanks
DSapseid Posted February 21, 2018 Posted February 21, 2018 I provide remote access using Remote Desktop Services and it works really well. I am moving to W10 in the summer and will be mapping users OneDrive using onedrivemapper powershell script from OneDriveMapper | Liebensraum ive seen it mentioned on here and seems to be a nicer way of doing it. Rather having to install onedrive on the machines and configuring them, it also then wont store a local copy of the files on the local computer! If there is a nice way of doing onedrive than this then im all up for new ideas!
dry Posted February 21, 2018 Posted February 21, 2018 Offline files for all staff users. DirectAccess as a trial for SLT and other non-teaching staff to access shared areas, as well as a third party VPN solution for some non-teaching staff whose ISP's default router firewall rules were preventing DirectAccess from connecting. Looking at transitioning to solely OneDrive because we're finding 'secret' DropBox shares still being used by teachers despite policy saying no. At least with OneDrive we'll have some control over the data.
TwistedHelixis Posted February 21, 2018 Posted February 21, 2018 All my primary schools have a remote access gateway but we are in the process of moving all data to Google Drive, So in your case it might be worth using onedrive.
jmak Posted February 21, 2018 Posted February 21, 2018 I provide remote access using Remote Desktop Services and it works really well. I am moving to W10 in the summer and will be mapping users OneDrive using onedrivemapper powershell script from OneDriveMapper | Liebensraum ive seen it mentioned on here and seems to be a nicer way of doing it. Rather having to install onedrive on the machines and configuring them, it also then wont store a local copy of the files on the local computer! If there is a nice way of doing onedrive than this then im all up for new ideas!Is that necessary now that Onedrive can use placeholders in Explorer? It only became available in 1709, but presumably you'll be rolling out at least that version by the summer.
mavhc Posted February 21, 2018 Posted February 21, 2018 I still use offline files, shared drives are the main issue. Bitlocker encryption works well if you have TPM 2.0, OK if you have TPM 1.2 (have to enable it via scripting bios, ie per manufacturer stuff, or per machine) Shared drives on Office365 still use sharepoint I think, and no one likes that, just test everything with a group of beta testers, people who can actually report bugs and will use it. Set up SRP to disallow a massive list of extensions from running from anywhere that's not c:\program files, (x86), and c:\windows, and your shared stuff, \\school.(oh yeah, there's still no internal tld)\netlogon, sysvol
MatthewL Posted February 22, 2018 Posted February 22, 2018 I would always use a VPN solution and then you can ensure everything is on the network and backed up.
KK20 Posted February 26, 2018 Posted February 26, 2018 (edited) VPN. Staff inset training on using the VPN and not using USB pens (GDPR tick-in-box). Laptops also have bitlocker enabled (TPM) (GDPR tick-in-the-box), the weakpoint will always be the staff password. Mandatory password changes have also been implemented (GDPR tick-in-box). I love GDPR, no really, if our department wasnt vilified enough to begin with, it is now. Edited February 26, 2018 by KK20
mavhc Posted February 26, 2018 Posted February 26, 2018 How should we implement 2 factor auth for everyone on their phones? Is it built into Windows 10 yet?
FishCustard Posted February 26, 2018 Posted February 26, 2018 Mandatory password changes have also been implemented (GDPR tick-in-box). I would seriously consider changing that... See here from the NCSC, and here from the US FTC. Short version is that they lead to people picking a simple password and shoving numbers on the end.
KK20 Posted February 26, 2018 Posted February 26, 2018 (edited) my concerns were minuted. The compliance officer said "do this", they are SMT, I did it. Box ticked, concern noted. With regards to phones, it is hard enough to get phone security in any shape. However, in order for staff to use our WIFI they need to install the school cert. In order to add a private cert you need authentication. That got around half of the problem at least. Edited February 26, 2018 by KK20
sparkeh Posted February 26, 2018 Posted February 26, 2018 VPN. The only way staff can access files remotely is via an encrypted school laptop over a secure connection.
adamsund Posted March 1, 2018 Posted March 1, 2018 DirectAccess for accessing shared areas. We also encourage anyone with a staff laptop to use OneDrive instead. With files on demand (available with 1709), this saves on drive space if it's a concern. Next step is moving shared drives on to SharePoint and find a way of connecting to these automatically........
Blue_Cookeh Posted March 1, 2018 Posted March 1, 2018 We use OneDrive (Office365) for user storage, SharePoint for 'shared drives', and DirectAccess so we can manage machines with SCCM etc.
mukz Posted March 3, 2018 Posted March 3, 2018 We use OneDrive (Office365) for user storage, SharePoint for 'shared drives', and DirectAccess so we can manage machines with SCCM etc. Do you map the sharepoint drive? If so, how do you do this please?
KevinB Posted March 5, 2018 Posted March 5, 2018 All remote access at the moment is done via DirectAccess but once we have it figured out we'll be moving to Always on VPN instead since DA has proved to be a bit of a sod for a lot of people.
Oaktech Posted March 5, 2018 Posted March 5, 2018 Generally speaking RDS. Although I have about 30 users across 2 sites who still have school laptops - those are now DirectAccess. I've had performance issues with DA recently but at the start of last week I made a config change to not force all browsing through the DA server and not had any further complaints over the 4 day weekend.
Theldron Posted March 7, 2018 Author Posted March 7, 2018 Would RDS be acceptable with GDPR? At the moment staff would enter their login twice, but I am sure I read somewhere that, that would make it 1 + 1 factor authentication rather than 2FA?
Oaktech Posted March 7, 2018 Posted March 7, 2018 Would RDS be acceptable with GDPR? At the moment staff would enter their login twice, but I am sure I read somewhere that, that would make it 1 + 1 factor authentication rather than 2FA? I've received no guidance from our MAT that RDP is not acceptable with GDPR. They've recently done audits with us and the question was asked and RDP seemed acceptable. You can easily make it such it that it would be one login for gateway and one log in for RDP server if that is better? What wasn't acceptable to them was the legacy VPN that a few people use at our other site, so we've decommissioned it.
sparkeh Posted March 7, 2018 Posted March 7, 2018 What wasn't acceptable to them was the legacy VPN that a few people use at our other site, so we've decommissioned it. Oh? do you know why?
Oaktech Posted March 7, 2018 Posted March 7, 2018 Oh? do you know why? Because people were able to set it up on their home machines thus exposing our network to whatever crapware/exploits might be on their machines. We disable all redirection of local resources by policy for RDP which seems to make the MAT happy too. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now