mavhc Posted June 2, 2020 Posted June 2, 2020 If you have a TPM device it auto unlocks and you get to the normal login screen, then you need a password. The reason for bitlocker is so you can't take the drive out and put it in another computer to just read the files without needing the user's password. So you 1. want bitlocker enabled with a TPM chip. and 2. need to make sure everyone's password is good, so set min length to 8 and require complexity for staff, then force them to expire and need changing, and 3. check current passwords against the hash list online. There's posts about all 3 of these things on here
TwistedHelixis Posted June 2, 2020 Posted June 2, 2020 (edited) If you have a TPM device it auto unlocks and you get to the normal login screen, then you need a password. The reason for bitlocker is so you can't take the drive out and put it in another computer to just read the files without needing the user's password. I might be misunderstanding what you are saying so sorry, but we use the pin number during boot up option, so the hard drive cant be booted even with a TPM chip in the original laptop, unless the correct number has been entered. EDIT - after the correct pin has been entered the laptop boots up and the user needs to enter a normal windows login password Edited June 2, 2020 by TwistedHelixis
TwistedHelixis Posted June 2, 2020 Posted June 2, 2020 Its a bit like a poor mans 2 factor authentication, if some steals a laptop they have no way of booting it up and we don't need such crazy windows passwords, so the staff don't need to write them down and stick them on the laptop cover.
Zammo Posted June 2, 2020 Posted June 2, 2020 So bursars are not interested in saving money as you pay less than the capital equipment cost with an operating lease, plus it gives them the ability to plan finances for 3-4 years ahead? It's rare laptop or desktop leases save money in state schools in my experience You pay less than the capital cost by usually 10%, but you are then obliged to lease again in a shorter time frame than most school's purchasing cycle.
TwistedHelixis Posted June 3, 2020 Posted June 3, 2020 Our last batch of laptops lasted 7 years. Don't buy cheap and they last longer 2
forkies Posted June 3, 2020 Posted June 3, 2020 Our last batch of laptops lasted 7 years. Don't buy cheap and they last longer I wish ours lasted 7 years, if only they weren’t dropped, carried by the corner of the screen and things closed inside the screen, etc. Then maybe they would. We aim for 5 years but probably have 5-7 laptops needing replacement due to damage each year
Davit2005 Posted June 3, 2020 Posted June 3, 2020 I think it is important to set some ground rules such as fair use policy for the laptops, the staff also need to be made responsible for them and sign for them, etc. I don't think that is unreasonable.
forkies Posted June 3, 2020 Posted June 3, 2020 I think it is important to set some ground rules such as fair use policy for the laptops, the staff also need to be made responsible for them and sign for them, etc. I don't think that is unreasonable. Ours have a laptop loan agreement which they must sign when receiving the laptop, however when they eventually come back to me saying it is broken and they "don't know how it happened" but it has been like it for weeks, I go to the BM and say and they tell me to just replace it. We have only once charged a member of staff for a laptop when it was significantly damaged just before they "left" the school. I usually try to give them a worse (older, hand me down) laptop when they break their laptop. Then they whine about the fact it is super slow and old, usually resolves the issue of them not looking after their laptops. Doesn't help with a certain member of LT who has been through 4 laptops in 3 years and about to have another one!
mavhc Posted June 3, 2020 Posted June 3, 2020 Its a bit like a poor mans 2 factor authentication, if some steals a laptop they have no way of booting it up and we don't need such crazy windows passwords, so the staff don't need to write them down and stick them on the laptop cover. Problem with a shared password is you never know who knows it, only takes one kid watching a teacher type it, or one teacher shouting it to another. Plus when you sync AD passwords to online now you need them to be complex anyway because your attack surface is now 510.1 million km²
Ditto Posted June 3, 2020 Posted June 3, 2020 Doesn't help with a certain member of LT who has been through 4 laptops in 3 years and about to have another one! What bugs me about this is that it is a waste public money. I'd love a finance audit to discover this and have the governing body investigate. There is a duty of care for all in schools and it should extend to all staff and pupils. If the same level and expense of damage occurred, to say classroom desks or the school minibus, it would lead to questions being asked. It should be no different for laptops.
Norphy Posted June 3, 2020 Posted June 3, 2020 So you 1. want bitlocker enabled with a TPM chip. and 2. need to make sure everyone's password is good, so set min length to 8 and require complexity for staff, then force them to expire and need changing, and 3. check current passwords against the hash list online. There's posts about all 3 of these things on here There are posts about password security, yes. The most recent ones say that enforcing password expiration actually reduces the effectiveness of your security, not increases it. As Microsoft themselves say here: By default, passwords are set to expire in 90 days. Current research strongly indicates that mandated password changes do more harm than good. They drive users to choose weaker passwords, re-use passwords, or update old passwords in ways that are easily guessed by hackers. A more detailed best practices document is here 1
mavhc Posted June 6, 2020 Posted June 6, 2020 There are posts about password security, yes. The most recent ones say that enforcing password expiration actually reduces the effectiveness of your security, not increases it. As Microsoft themselves say here: Yeah, I just mean once so the new min standards are enforced, not all the time. No point setting a password policy if people keep their old 3 letter password. Really we need to get rid of passwords and log in with our phones
ajg Posted July 8, 2020 Author Posted July 8, 2020 Hi all. Just to say thanks for the posts and to provide an update in case anyone is interested. We finally opted to go with the HP ProBook 440 G7 in the end as we thought this provided the best balance of cost and feel of quality. Only time will tell of course so fingers crossed! They will purely be for non-teaching use to begin with but we will then trial using them for teaching with sometime in the new academic year, the laptops have USB C charging capability so have tested with a USB C dock and in principle seems to work well....
mikeprice Posted July 8, 2020 Posted July 8, 2020 I wish ours lasted 7 years, if only they weren’t dropped, carried by the corner of the screen and things closed inside the screen, etc. Then maybe they would. We aim for 5 years but probably have 5-7 laptops needing replacement due to damage each year AT my last school I sometimes found 20 ish laptops all in a neat pile on top of the laptop trolley how none of the screens broke is a mystery!
F_admin Posted July 9, 2020 Posted July 9, 2020 This topic is very much on my mind also, and with end-of-year budget deadlines looming the topic is getting more rushed.. In turn the SLT are just suggesting 'just buy laptops', but as we can all agree it isn't as simple as that - there are many considerations to be made. Quick query though - say these laptops are domain joined (of course), and a second wave comes around (ie. staff aren't onsite for a long time), do we just bank on the users being able to login with their locally-cached domain credentials? Or is there a smarter way of laptops being able to authenticate your AD credentials from their home network? Thanks, Fraser
TwistedHelixis Posted July 9, 2020 Posted July 9, 2020 Quick query though - say these laptops are domain joined (of course), and a second wave comes around (ie. staff aren't onsite for a long time), do we just bank on the users being able to login with their locally-cached domain credentials? Or is there a smarter way of laptops being able to authenticate your AD credentials from their home network? Chromebooks would be good in this situation. 1
p858snake Posted July 11, 2020 Posted July 11, 2020 Quick query though - say these laptops are domain joined (of course), and a second wave comes around (ie. staff aren't onsite for a long time), do we just bank on the users being able to login with their locally-cached domain credentials? Or is there a smarter way of laptops being able to authenticate your AD credentials from their home network? There are many ways, but it depends on how your network is setup to support these devices. One solution would be a always on vpn setup. 1
ajg Posted July 11, 2020 Author Posted July 11, 2020 We are planning to have them domain joined with cached credentials. They will be hybrid joined so will be SSO for Microsoft services and using a User AlwaysOnVPN with 2FA to access network resources. Tested using a device based AlwaysOnVPN which worked really well but I wasn’t happy to give access to the network with just a username and password. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now