m0bov Posted April 28, 2020 Posted April 28, 2020 Hi all, like many schools we have students who don't have access to device. We have funding for a number of laptops, I just wondered how everyone else is dealing with security of the device and ownership? I know it will need to be security marked, no local admin access, but other than a Meraki client, is there anything else I can do? They will have a 3G dongle with them. Cheers.
Chris_Cook Posted April 28, 2020 Posted April 28, 2020 Sounds like you've covered a lot of the basics. I'm assuming you are talking about windows laptops I'd add/consider: * Bit locker or other drive encryption - hopefully these devices have a TPM. * keeping a log of who gets what * Web filtering off network. * windows updates - both getting it up to date, and making sure it can stay up to date off network * Software licencing if there are any network apps on it, like sibelius, solid works, that sort of thing. * Testing it before it goes to the student - can the student login off network, especially if they haven't logged in on the school network. * Permissions to add printers/wifi networks. For many of our student facing laptops we are putting neverware on them, as windows is a load of work we don't need. We only do windows on mobile devices if there is a specific need.
synaesthesia Posted April 28, 2020 Posted April 28, 2020 We've just taken ours off the domain, created a local admin account and handed them over. There's no data on them anyway due to uev/mandatory profiles, already bitlockered from build and that's it. Filtering etc isn't our issue when off-site and in short notice it really isn't worth it. paperwork signed to say they're liable for damages, replacement etc and that's it. There's no point over-complicating something, especially if the majority is done on google/teams etc.
flyinghaggis Posted April 28, 2020 Posted April 28, 2020 We've just taken ours off the domain, created a local admin account and handed them over. There's no data on them anyway due to uev/mandatory profiles, already bitlockered from build and that's it. Filtering etc isn't our issue when off-site and in short notice it really isn't worth it. paperwork signed to say they're liable for damages, replacement etc and that's it. There's no point over-complicating something, especially if the majority is done on google/teams etc. That's pretty much what we did. Only had a couple of days notice to convert the laptops for offsite use so there wasn't really time to do anything beyond that.
m0bov Posted April 29, 2020 Author Posted April 29, 2020 Thanks guys, yes, pretty much thats everything, don't want to over complicate things. I am waiting on pricing from a company that do 4G dongles with web filtering, don't want students munching up data watching youtube....
FragglePete Posted April 29, 2020 Posted April 29, 2020 (edited) Essentially what we have done as well for Staff and Students. - Rebuilt the Device from our current WDS Image which installs Office365 ProPlus using DBA - Remove from Domain - Installed Foldr Client for Staff - Run Sysprep to do a OOBE and Shutdown - Hand Device to Staff / Student once they've signed for it. They then go through the Windows Setup and use their School credentials to join the device to Azure and they can do what they like with it. It's not on the school network, unless its the BYOD network which is segregated from the school network. They can access the school shares via Foldr and do everything else online as needed. Simple, quick and effective - would like to take it further in the future with Intune and stuff, but I don't fully understand all that just yet. Pete Edited April 29, 2020 by FragglePete
MicrodigitUK Posted May 3, 2020 Posted May 3, 2020 (edited) Simple, quick and effective - would like to take it further in the future with Intune and stuff, but I don't fully understand all that just yet. Pete Hi Pete, @FragglePete Recommend this book as a good introduction to all the Intune AzureAD joined concepts. If you are wanting to learn more build and what you have done. https://www.amazon.co.uk/MDM-Fundamentals-Security-Desktop-Autopilot/dp/1119564328 Edited May 3, 2020 by MicrodigitUK 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now