Jump to content

Recommended Posts

Posted

Here goes...

 

I'd be very interested to know how people are handling staff laptops that don't particularly come into school that often, if at all.

 

Main points of interest are:

  • Windows Updates - How are you managing them?
  • Volume Activation - MAK or ADBA / KMS
  • Remote Access - SIMS / network drives. Direct Access / Always on VPN? RDS over port 443?
  • Encryption - particularly older devices that don't have an onboard TPM chip.

 

I think that's a good starting point. If there are any other challenges I'd be interested to hear how you got around them.

Posted
IIRC you can set updates to look at MS if they can't contact your WSUS. I'd go KMS as then they have to bring 'em in from time to time. Don't do remote access (though many on here do) - wouldn't it help with the first two queries? You can set W7 ENT and (I think) >8 Pro/EDU/ENT to Bitlocker without TPM or there's always Veracrypt.
Posted

I guess I should have expanded on the updates, my main worry of directing updates directly to MS is that they may take on feature upgrades when I don't want them to. Or can I control what they receive directly from MS? We use SCCM for updates btw.

 

I think Bitlocker just requires a USB without TPM - just querying what others do here.

Posted

Re: Licensing of staff laptops: KMS. Always KMS. That way they HAVE to bring the laptops into school every so often to allow the laptop to see the network. It's an opportunity for SCCM to send new packages at the same time (if there are any)

 

:thumb:

Posted
I guess I should have expanded on the updates, my main worry of directing updates directly to MS is that they may take on feature upgrades when I don't want them to. Or can I control what they receive directly from MS? We use SCCM for updates btw.

 

I think Bitlocker just requires a USB without TPM - just querying what others do here.

If you get the Windows Update for Business policies correct you can delay a feature update for up to a year. I always test group policies against the latest feature update even if we don't deploy. I'd rather have laptops on 1803 etc and secure than not updated at all. You should strive for all laptops to have TPMs if not bitlocker can be configured with a password but must be unique to each laptop.
Posted
All laptops are Bitlockered, and USB devices have to be encrypted to be written to. Currently our SCCM cannot work off site. I've been trying to find on the web, is there a way to lock down a computer if it doesn't connect to the network within a certain time?
Posted
All laptops are Bitlockered, and USB devices have to be encrypted to be written to. Currently our SCCM cannot work off site. I've been trying to find on the web, is there a way to lock down a computer if it doesn't connect to the network within a certain time?
Microsoft InTune: https://docs.microsoft.com/en-us/intune/manage-windows-pcs-with-microsoft-intune

 

Some InTune functionality is included in the free to education version - not sure if this is part of it.

 

Otherwise..

 

 

 

 

 

 

Chromebooks? [emoji16]

Posted
I think Bitlocker just requires a USB without TPM - just querying what others do here.

 

We do this: USB with most staff laptops as they don't have TPM chips. Works fine.

Posted
we use unencrypted laptops here, we tell the staff to store no documents on the laptop and access all files over Direct Access, this will allow the laptop to behave like its here. All updates are downloaded directly but controlled from WSUS. We use KMS activation which seems to work over the DA link. Staff are told to use bitlocker for USB but we haven't enforced it, they've been told, if they ignore it thats on them.
Posted
we use unencrypted laptops here, we tell the staff to store no documents on the laptop and access all files over Direct Access, this will allow the laptop to behave like its here. All updates are downloaded directly but controlled from WSUS. We use KMS activation which seems to work over the DA link. Staff are told to use bitlocker for USB but we haven't enforced it, they've been told, if they ignore it thats on them.

 

If your member of staff loses a laptop or USB stick the ICO wont see it that way.

 

You should be encrypting your laptops. It's the easiest thing you can do nowadays, especially with BitLocker.

Posted
the laptop only has the os and office on it, what is there to loose? Bitlocker uses hardware encryption on the SSDs (by default) anyway and this is probably broken, it's been shown that drives (looked at Samsung evo 840 and crucial) can be made to self decrypt due too poor implementation. Best not to store the data on the device. And staff don't typically use USB sticks (as they are usually connected to the school via DA anyway) We have TPM on all our laptops but we decided to not store the data on personal use devices.
Posted
Re: Licensing of staff laptops: KMS. Always KMS. That way they HAVE to bring the laptops into school every so often to allow the laptop to see the network. It's an opportunity for SCCM to send new packages at the same time (if there are any)

 

:thumb:

 

I do exactly this for the same reasons.

Posted

RE: Windows updates, I'm guessing that it's possible to make WSUS reachable with an external URL. I've been thinking that if that were done, then the clients would be configured via GPO to check WUS on that external URL, rather than just an internal address, so that they'd receive updates regardless of whether they're on or off site.

 

Everything else on the list we'd configure on site first, and have them sign in before taking the laptop away. Any staff on maternity leave, for example, keep hold of their laptop at home, and updates are really the only thing I have an issue with on that front.

Posted

  • Windows Updates - We use onsite WSUS to manage windows updates. Our updates are set to deploy once a week, if people "choose" to keep their laptops at home they understand they are not getting security updates and could lead to GDPR breach.
  • Volume Activation - KMS - Every 60 days or so they have to bring the laptops on site to reactivate.
  • Remote Access - We use smoothwall VPN, not ideal but does the job.
  • Encryption - All of our staff laptops are encrypted with a password/TPM chip if its avilable as we have a lot of legacy laptops. This can be set via GPO and prompts the user for a password before the laptop even boots to windows. We keep a copy of the recovery key onsite incase there are any issues.
     
    All laptops are configured on site before staff take them away.

  • Thanks 1
Posted
RE: Windows updates, I'm guessing that it's possible to make WSUS reachable with an external URL. I've been thinking that if that were done, then the clients would be configured via GPO to check WUS on that external URL, rather than just an internal address, so that they'd receive updates regardless of whether they're on or off site.

 

Everything else on the list we'd configure on site first, and have them sign in before taking the laptop away. Any staff on maternity leave, for example, keep hold of their laptop at home, and updates are really the only thing I have an issue with on that front.

Yes you can setup a standalone WSUS over https and only your clients have a client auth cert. However it depends how much control you require. Most people just need a week delay in updates. If you need that level then an always on VPN may be easier.
  • Thanks 1
Posted
the laptop only has the os and office on it, what is there to loose? Bitlocker uses hardware encryption on the SSDs (by default) anyway and this is probably broken, it's been shown that drives (looked at Samsung evo 840 and crucial) can be made to self decrypt due too poor implementation.

Not true - only on certain models of SSD. Regardless of this it can be mitigated by not using the built in hardware encryption - use software encryption instead. Performance loss is no longer a valid complaint in 2018.

 

Best not to store the data on the device. And staff don't typically use USB sticks (as they are usually connected to the school via DA anyway) We have TPM on all our laptops but we decided to not store the data on personal use devices.

 

How do you stop staff storing data on there? What do you do when someone opens a document on there and it's copied into the various caches on the device?

 

Security is done in layers, and it sounds like you're missing a huge part of it.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...