TJ-Diggers Posted October 7, 2019 Posted October 7, 2019 Our SLT have ordered some Surface Pro's for themselves. I am looking at the best way to set them up. Naturally domain joined would be best but they will be taking them offsite to use at meetings etc. I have thought about vpn always on and then they can just connect to wifi at any location at the login screen.... and then just log in as normal. Only issue I have come across so far is that if the guest wifi redirects you to a webpage portal like a hotel or my cloud wifi etc, this wont work at the login screen due to having no web browser. My second thought was to just give them a standalone laptop and get them to use their OneDrive and Office 365 but they still want access to our on site shared area when they are not on site. I could just setup a script to connect using their ad credentials but this task will be seen as unnecessary work and they want it to just work!! Got to love school staff I know there are many ways to do this but a good one to fit our school needs is tricky.] Any ideas would be great! Thank Terry
LeMarchand Posted October 7, 2019 Posted October 7, 2019 Sign on with cached credentials, connect to hotel after logon and schedule/script VPN to start once the laptop can ping (say) Google? 1
forkies Posted October 7, 2019 Posted October 7, 2019 Nice that they spent school money (I am assuming without consulting based on the statement) without consulting the IT department to see if these are the best devices to suite their needs. Bitlocker encrypt, cached credentials, offline sync docs drive, user can connect to VPN when required for any network drives they need access to or Sims etc. If you use 365/GSuite then options for accessing files that way. Others may suggest Azure remote apps instead of VPN too if you have it. 1
mrcrazy04 Posted October 8, 2019 Posted October 8, 2019 If these are single-user devices, some of the guidance from NCSC might be of use. Recent versions of Windows 10 allow you to configure an always-on VPN for both the user and the device (with it transitioning when users login), so GPO updates and so on will deploy even if the device is not connected to the internal network. IPSec with IKEv2 and elliptic curve ciphers and certificates is recommended. NCSC have released a Captive Portal helper application, which should allow users to access any captive portals and login to those before the VPN is brought up. You can find details in their guidance - https://www.ncsc.gov.uk/collection/end-user-device-security/platform-specific-guidance/eud-security-guidance-windows-10-1809 - I haven't tried it though, so am not entirely sure how effective it is. BitLocker is also recommended, with TPM+PIN required to authenticate to BitLocker (providing the security of the TPM, but also requiring the users to authenticate). I think Surface Pros support Windows Hello facial recognition, so if you're happy with the risks of that, that could be an option to make authentication to the devices easier for SLT. They can then just login to their domain account by looking at the device. However, it's worth enabling the additional security option for facial recognition if you decide to go with that (we could bypass it with specially crafted photos otherwise). 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now