Jump to content

Recommended Posts

Posted

If you have a TPM device it auto unlocks and you get to the normal login screen, then you need a password. The reason for bitlocker is so you can't take the drive out and put it in another computer to just read the files without needing the user's password.

 

So you 1. want bitlocker enabled with a TPM chip. and 2. need to make sure everyone's password is good, so set min length to 8 and require complexity for staff, then force them to expire and need changing, and 3. check current passwords against the hash list online.

 

There's posts about all 3 of these things on here

Posted (edited)
If you have a TPM device it auto unlocks and you get to the normal login screen, then you need a password. The reason for bitlocker is so you can't take the drive out and put it in another computer to just read the files without needing the user's password.

 

I might be misunderstanding what you are saying so sorry, but we use the pin number during boot up option, so the hard drive cant be booted even with a TPM chip in the original laptop, unless the correct number has been entered.

 

EDIT - after the correct pin has been entered the laptop boots up and the user needs to enter a normal windows login password

Edited by TwistedHelixis
Posted
Its a bit like a poor mans 2 factor authentication, if some steals a laptop they have no way of booting it up and we don't need such crazy windows passwords, so the staff don't need to write them down and stick them on the laptop cover.
Posted
So bursars are not interested in saving money as you pay less than the capital equipment cost with an operating lease, plus it gives them the ability to plan finances for 3-4 years ahead?

 

It's rare laptop or desktop leases save money in state schools in my experience

 

You pay less than the capital cost by usually 10%, but you are then obliged to lease again in a shorter time frame than most school's purchasing cycle.

Posted
Our last batch of laptops lasted 7 years. Don't buy cheap and they last longer

 

I wish ours lasted 7 years, if only they weren’t dropped, carried by the corner of the screen and things closed inside the screen, etc. Then maybe they would.

 

We aim for 5 years but probably have 5-7 laptops needing replacement due to damage each year

Posted
I think it is important to set some ground rules such as fair use policy for the laptops, the staff also need to be made responsible for them and sign for them, etc. I don't think that is unreasonable.
Posted
I think it is important to set some ground rules such as fair use policy for the laptops, the staff also need to be made responsible for them and sign for them, etc. I don't think that is unreasonable.

 

Ours have a laptop loan agreement which they must sign when receiving the laptop, however when they eventually come back to me saying it is broken and they "don't know how it happened" but it has been like it for weeks, I go to the BM and say and they tell me to just replace it. We have only once charged a member of staff for a laptop when it was significantly damaged just before they "left" the school.

 

I usually try to give them a worse (older, hand me down) laptop when they break their laptop. Then they whine about the fact it is super slow and old, usually resolves the issue of them not looking after their laptops. Doesn't help with a certain member of LT who has been through 4 laptops in 3 years and about to have another one!

Posted
Its a bit like a poor mans 2 factor authentication, if some steals a laptop they have no way of booting it up and we don't need such crazy windows passwords, so the staff don't need to write them down and stick them on the laptop cover.

 

Problem with a shared password is you never know who knows it, only takes one kid watching a teacher type it, or one teacher shouting it to another.

 

Plus when you sync AD passwords to online now you need them to be complex anyway because your attack surface is now 510.1 million km²

Posted
Doesn't help with a certain member of LT who has been through 4 laptops in 3 years and about to have another one!

What bugs me about this is that it is a waste public money. I'd love a finance audit to discover this and have the governing body investigate. There is a duty of care for all in schools and it should extend to all staff and pupils. If the same level and expense of damage occurred, to say classroom desks or the school minibus, it would lead to questions being asked. It should be no different for laptops.

Posted

So you 1. want bitlocker enabled with a TPM chip. and 2. need to make sure everyone's password is good, so set min length to 8 and require complexity for staff, then force them to expire and need changing, and 3. check current passwords against the hash list online.

 

There's posts about all 3 of these things on here

 

There are posts about password security, yes. The most recent ones say that enforcing password expiration actually reduces the effectiveness of your security, not increases it. As Microsoft themselves say here:

 

By default, passwords are set to expire in 90 days. Current research strongly indicates that mandated password changes do more harm than good. They drive users to choose weaker passwords, re-use passwords, or update old passwords in ways that are easily guessed by hackers.

 

A more detailed best practices document is here

  • Thanks 1
Posted
There are posts about password security, yes. The most recent ones say that enforcing password expiration actually reduces the effectiveness of your security, not increases it. As Microsoft themselves say here:

 

Yeah, I just mean once so the new min standards are enforced, not all the time. No point setting a password policy if people keep their old 3 letter password.

 

Really we need to get rid of passwords and log in with our phones

  • 1 month later...
Posted
Hi all. Just to say thanks for the posts and to provide an update in case anyone is interested. We finally opted to go with the HP ProBook 440 G7 in the end as we thought this provided the best balance of cost and feel of quality. Only time will tell of course so fingers crossed! They will purely be for non-teaching use to begin with but we will then trial using them for teaching with sometime in the new academic year, the laptops have USB C charging capability so have tested with a USB C dock and in principle seems to work well....
Posted
I wish ours lasted 7 years, if only they weren’t dropped, carried by the corner of the screen and things closed inside the screen, etc. Then maybe they would.

 

We aim for 5 years but probably have 5-7 laptops needing replacement due to damage each year

 

AT my last school I sometimes found 20 ish laptops all in a neat pile on top of the laptop trolley

 

how none of the screens broke is a mystery!

Posted

This topic is very much on my mind also, and with end-of-year budget deadlines looming the topic is getting more rushed..

In turn the SLT are just suggesting 'just buy laptops', but as we can all agree it isn't as simple as that - there are many considerations to be made.

 

Quick query though - say these laptops are domain joined (of course), and a second wave comes around (ie. staff aren't onsite for a long time), do we just bank on the users being able to login with their locally-cached domain credentials? Or is there a smarter way of laptops being able to authenticate your AD credentials from their home network?

 

Thanks,

Fraser

Posted
Quick query though - say these laptops are domain joined (of course), and a second wave comes around (ie. staff aren't onsite for a long time), do we just bank on the users being able to login with their locally-cached domain credentials? Or is there a smarter way of laptops being able to authenticate your AD credentials from their home network?

 

Chromebooks would be good in this situation.

  • Thanks 1
Posted
Quick query though - say these laptops are domain joined (of course), and a second wave comes around (ie. staff aren't onsite for a long time), do we just bank on the users being able to login with their locally-cached domain credentials? Or is there a smarter way of laptops being able to authenticate your AD credentials from their home network?

 

There are many ways, but it depends on how your network is setup to support these devices. One solution would be a always on vpn setup.

  • Thanks 1
Posted

We are planning to have them domain joined with cached credentials. They will be hybrid joined so will be SSO for Microsoft services and using a User AlwaysOnVPN with 2FA to access network resources.

Tested using a device based AlwaysOnVPN which worked really well but I wasn’t happy to give access to the network with just a username and password.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...