Jump to content

Primary school individual logins and Web Filtering reporting


Recommended Posts

Posted

Hi All

 

Just looking into new web filtering solutions for a new primary school we have taken on and obviously for true reporting you need to know who is logged on or using the device, how do you guys handle this across all devices, ipad, android, chromebook, pc from all uses in all the years as this is a primary school. We all know how hard it is getting the younger years logged in etc so general generic accounts usually come into play but obviously then we dont know who was using what device when without some internal processes and logging from teachers.

 

Ive read this: http://www.edugeek.net/forums/e-safety/179717-individual-primary-school-logins.html

 

 

Is there any bang up to date advice or standards that we should be following along with any documents if possible that will help advise the school from an admins point of view, what do Ofsted say on the matter ? We dont primarily just do schools so hoping some of you guys who work in schools can help here. What systems do you ahve in place for say the Nursery Reception or earlier years, be interested to hear and updated view on this, as these things change all the time.

 

Many Thanks

 

S

Posted

I’ll kick off by suggesting you read the following written by Kent’s @esafety_officer who is nationally respected for her work.

 

She went through Keeping Children Safe In Education 2016 with a fine tooth comb drawing out all the online safety points

http://www.edugeek.net/forums/e-safety/171051-online-safety-within-keeping-children-safe-education-2016-published-26-5-16-a.html

 

Changes to this since are here

http://www.edugeek.net/forums/e-safety/196663-online-safety-within-keeping-children-safe-education-kcsie-2018-a.html

 

And Ofsted’s view is analysed here

http://www.edugeek.net/forums/e-safety/174069-online-safety-within-inspecting-safeguarding-education-2016-updated-sept-2016-a.html

 

For policy templates and guidance see here

http://www.edugeek.net/forums/e-safety/188272-online-safety-policy-template-guidance-updated-sept-2017-a.html

  • Thanks 1
Posted (edited)
Clever.com do QR type badges kids can wear, login via webcam

Wonde SSO supports QR code logins (a.k.a. Magic Badges), in addition to emoji passwords and regular email/password logins.

 

It's also extremely cheap (£180 + VAT per year for primary schools, £300 for secondary), can sync with popular UK MISs like SIMS and the company is based in the UK too.

 

Edit. willtech beat me to it. :)

Edited by Arthur
  • Thanks 2
Posted
Can I sync from AD/GSuite/O365?

 

You can use them as an identity provider for oauth, but I don't think you can sync from them.

There are 5 files I use for clever to associate all the details together.

There is a 6th one, admins.csv listed in the docs but I don't use it.

 

https://support.clever.com/hc/en-us/articles/203114867-SFTP-How-do-I-format-my-CSV-files-

 

https://support.clever.com/hc/en-us/articles/203166787-Which-identity-provider-should-I-use-

Posted

I just spoke to Wonde, they cant login all platforms via QR currently although a tech is contacting me back with more info. Seems its for logging into a predefined list of apps mainly. Possibility of logging into Chromebooks, but wasnt confirmed based on who i spoke to, hence the call back from a tech due.

 

We need to log on any device / platform (Not apps only) as easy as possible for the younger years and have that account associated with that one user. Have you guys done this? We need the web filter reporting to show the user that is using the device / internet.

 

Thanks

 

S

Posted
I just spoke to Wonde, they cant login all platforms via QR currently although a tech is contacting me back with more info. Seems its for logging into a predefined list of apps mainly. Possibility of logging into Chromebooks, but wasnt confirmed based on who i spoke to, hence the call back from a tech due.

 

We need to log on any device / platform (Not apps only) as easy as possible for the younger years and have that account associated with that one user. Have you guys done this? We need the web filter reporting to show the user that is using the device / internet.

 

Thanks

 

S

 

We have been speaking to them for about a year on Chromebook login via QR codes. You can do it but you have to federate with them. Our issue was that we use Azure AD and all ready link O365 logins to GSuite so their solution would have broken all that. But I am on a list so they will get back to me once they have developed further and maybe have a solution.

 

As for primary logins, we have individual logins down to Y1, albeit simplistic ones.

Posted
Clever.com do QR type badges kids can wear, login via webcam

 

know any software off hand that does that... our lower end of school are constantly on the whinge about logging on

Posted

Just Clever that I can see, Windows 10 does have Picture login, which is something different but might help, but it's Windows Hello, so it's local to the computer, would need 1:1

 

I'm setting up fingerprints for my students when they're assigned their own laptops.

  • 4 months later...
Posted
Does anybody know if there is a specific policy/legislation regarding this?

 

It recently came up on this thread: http://www.edugeek.net/forums/internet-related-filtering-firewall/207615-one-provider-rm-safetynet-how-not-do.html

 

There is no specific legislation (as far as I'm aware anyway) saying you have to identify users. Keeping Children Safe in Education says that schools should filter and monitor "appropriately", and what is "appropriate" should be driven by a risk assessment. However, KCSIE also signposts to the UK Safer Internet Centre's guidance as an example of what this might look like, and the UKSIC's guidance does specifically say your filtering should identify the users.

 

As you'll see from the linked thread, there were opinions on both sides, although the majority of people involved in the discussion were very much of the opinion that if your filtering system isn't providing regular safeguarding reports which identify individuals then you're missing some significant safeguarding opportunities.

 

My professional opinion is that if you don't at least meet the signposted UKSIC guidelines, you really need to have completed a risk assessment specifically addressing why you don't think you need to. There are plenty of filtering systems out there that support user identification, and in most cases it can be single-signon, so "we bought one that didn't" isn't going to be a good enough reason. There are occasionally reasons to avoid doing so in specific cases, but I don't think this should ever extend to the school's whole network.

 

From a risk perspective, I think you need to look at 2 scenarios:

1. Web filter reports may show some slightly concerning traffic which isn't serious enough to be a big deal. Reports that identify users allow you to keep an eye on low-level but recurring concerning behaviour. If the filter only gives you IP addresses and you have to go to some effort to figure out what user that is, you likely won't bother for this sort of low level behaviour and the safeguarding opportunities will be missed.

2. If something really serious happens, will you be able to figure out who the users are who were involved? The answer may well be "yes" even if the filtering system only logs IP addresses, but are you sure you can always do this? Responding to a really serious incident with "well we don't know who's involved" isn't great and may well put people at significant risk.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...