Jump to content

Recommended Posts

Posted

I just need a bit of a sanity check on the management / process of chromebooks that we (not IT Support) are looking to implement.

 

Parents have been advised to purchase a discounted Chromebook from a third party so the school does not get involved in parent payments and the chromebook is essentially the parent's / student's however at this point in time the SLT are not wanting them to be used onsite which is fine as students can use their school login details on the chromebooks at home.

 

The issue i have is when SLT decide that these chromebooks are to be used on site. Each device will need to be manually added to the wifi by us as we do not want student connecting their personal phones or other devices to the wifi networks. We would need to ensure that Smoothwall Monitor and Impero are used too however i cannot remember if these are installed via user or device.

 

Obviously having the chromebooks added to our GSuite Domain whilst we have them all onsite would be quicker and easier however i feel there are positive and negatives for both deployments.

Posted
I just need a bit of a sanity check on the management / process of chromebooks that we (not IT Support) are looking to implement.

 

Parents have been advised to purchase a discounted Chromebook from a third party so the school does not get involved in parent payments and the chromebook is essentially the parent's / student's however at this point in time the SLT are not wanting them to be used onsite which is fine as students can use their school login details on the chromebooks at home.

 

The issue i have is when SLT decide that these chromebooks are to be used on site. Each device will need to be manually added to the wifi by us as we do not want student connecting their personal phones or other devices to the wifi networks. We would need to ensure that Smoothwall Monitor and Impero are used too however i cannot remember if these are installed via user or device.

 

Obviously having the chromebooks added to our GSuite Domain whilst we have them all onsite would be quicker and easier however i feel there are positive and negatives for both deployments.

 

If you connect their personal Chromebook to your WiFi then they are likely going to be able to get the Chromebook to tell them the credentials and you will no longer be able to prevent them from connecting personal devices to your WiFi.

 

You will also struggle to filter them effectively as you will need to push an extension but if they can log on with a personal Google account which they could then the extension wouldn't be pushed out.

 

To properly use them in school you want them managed - you can designated hours and days when they can be unmanaged for use at home etc. It is a lot more complicated because parents have bought them rather than the school but you should be able to find something that works for everyone and allows you to manage them.

  • Thanks 1
Posted

You'd need to have them managed if you want to be able to push things to them and control their login.

Ultimately, if they're bringing their own unmanaged device onto site, nothing is stopping them logging into their personal Chrome accounts and having a big old Roblox session.

  • Thanks 1
Posted
If they are going to used onsite, then they need to be enrolled and managed - you can push everything automatically. You can also apply a device policy to allow timed access to private accounts. We do this - so they can use private accounts after 4pm and until 6am and at weekends (you can set whatever times you want).
  • Thanks 1
Posted
If you connect their personal Chromebook to your WiFi then they are likely going to be able to get the Chromebook to tell them the credentials and you will no longer be able to prevent them from connecting personal devices to your WiFi.

 

You will also struggle to filter them effectively as you will need to push an extension but if they can log on with a personal Google account which they could then the extension wouldn't be pushed out.

 

To properly use them in school you want them managed - you can designated hours and days when they can be unmanaged for use at home etc. It is a lot more complicated because parents have bought them rather than the school but you should be able to find something that works for everyone and allows you to manage them.

 

I don't understand the first sentence. If students brought in their own chromebooks, they would have to connect to an Open wifi (student wifi), login to the wifi with their AD username and password however they could use any device to connect to this wifi - this is what i don't want to happen. This wifi is filtered by the smoothwall based on the student username.

 

Would they have to install the certificate for filtering? Depends!

If students use their personal chrome accounts when using the chromebooks on the student wifi, then the certificate will have to be installed manually either by the student / IT Support.

If students use their school account on the chromebook, the certificate would still need to be installed however the chromebook / session would be double filtered as their school accounts are using the Smoothwall Cloud filter.

 

Might have to look at the "out of hours management" setting which i think i have already configured. I will need to review this as i configured this during the early part of lockdown v1.0

 

You'd need to have them managed if you want to be able to push things to them and control their login.

Ultimately, if they're bringing their own unmanaged device onto site, nothing is stopping them logging into their personal Chrome accounts and having a big old Roblox session.

 

Does it depend on what is allowed and not allowed via the smoothwall filtering policies? But i can see where you are coming from!

 

If they are going to used onsite, then they need to be enrolled and managed - you can push everything automatically. You can also apply a device policy to allow timed access to private accounts. We do this - so they can use private accounts after 4pm and until 6am and at weekends (you can set whatever times you want).

 

Will look into this! The issue is we don't own the device so can we enforce these restrictions?

 

Which requires you to have a license to do so...

 

I'm not sure if the agreement between the parent and 3rd party supplier contains the license! I forgot about this - thank you

 

 

Thank you all to this and my thoughts were right, i think managed is the best way to go but the SLT think 20 mins per device to configure them on to the Google Domain is too long, especially when there are 200 of them to do.

Posted
I don't understand the first sentence. If students brought in their own chromebooks, they would have to connect to an Open wifi (student wifi), login to the wifi with their AD username and password however they could use any device to connect to this wifi - this is what i don't want to happen. This wifi is filtered by the smoothwall based on the student username.

 

Thank you all to this and my thoughts were right, i think managed is the best way to go but the SLT think 20 mins per device to configure them on to the Google Domain is too long, especially when there are 200 of them to do.

 

I'm not sure what you don't understand? If you're using RADIUS using their user credentials then yes they'd be able to connect with other devices. My point was that if you're managing them then you can control all of this. You said you don't want students to be able to connect any other devices but now you're saying they're going to connect to open wifi (hopefully you mean a RADIUS protected SSID) and authenticate using their username and password.

 

Eg. if you manage them they could all connect to an SSID dedicated to them using a PSK that only you know, or RADIUS creds that only you know. But if you don't manage them then they need to be able to join the WiFi and at this point you're going to struggle to prevent them joining other devices.

 

20 minutes per device? Takes us about 2 minutes per device to enrol them.

 

Long story short - if they're coming on site you need to manage them, the myriad of issues you'll have if you don't is huge - eg. they log on with a personal account and use a VPN extension which is hard to block to completely bypass filtering. If it was managed they wouldn't be able to do this.

  • Thanks 1
Posted
I'm not sure what you don't understand? If you're using RADIUS using their user credentials then yes they'd be able to connect with other devices. My point was that if you're managing them then you can control all of this. You said you don't want students to be able to connect any other devices but now you're saying they're going to connect to open wifi (hopefully you mean a RADIUS protected SSID) and authenticate using their username and password.

 

Eg. if you manage them they could all connect to an SSID dedicated to them using a PSK that only you know, or RADIUS creds that only you know. But if you don't manage them then they need to be able to join the WiFi and at this point you're going to struggle to prevent them joining other devices.

 

20 minutes per device? Takes us about 2 minutes per device to enrol them.

 

Long story short - if they're coming on site you need to manage them, the myriad of issues you'll have if you don't is huge - eg. they log on with a personal account and use a VPN extension which is hard to block to completely bypass filtering. If it was managed they wouldn't be able to do this.

 

Sorry, i've just re-read the sentence again this morning after having a decent nights kip - makes sense LOL!

 

Is there a way to find the WPA2 key on a chromebook? I googled it months ago and couldn't find out how to do it - but i'm sure there is a way.

 

I have tested Radius though it's not something that is high on my list of things at the moment - i seem to be doing more admin more than anything at the moment with no time to test - they won't pay me over time - anyway i don't want to get into that discussion.

 

When we got the Chromebooks from the DfE it took about 20 mins from start to finish (un-box, enroll, paperwork, move in GSuite, re-box)

Posted
Sorry, i've just re-read the sentence again this morning after having a decent nights kip - makes sense LOL!

 

Is there a way to find the WPA2 key on a chromebook? I googled it months ago and couldn't find out how to do it - but i'm sure there is a way.

 

I have tested Radius though it's not something that is high on my list of things at the moment - i seem to be doing more admin more than anything at the moment with no time to test - they won't pay me over time - anyway i don't want to get into that discussion.

 

When we got the Chromebooks from the DfE it took about 20 mins from start to finish (un-box, enroll, paperwork, move in GSuite, re-box)

 

Yes you can find the WPA2 key on a Chromebook - there's guides online on how to do it.

 

Yeah unboxing etc can be time consuming but if students are bringing their devices in you could quickly enroll them. You could actually get the class to do it for you if you put the creds on the board (change them before and after obviously) and stand at the front guiding them through it - boom class done in minutes :)

Posted
Yes you can find the WPA2 key on a Chromebook - there's guides online on how to do it.

 

Yeah unboxing etc can be time consuming but if students are bringing their devices in you could quickly enroll them. You could actually get the class to do it for you if you put the creds on the board (change them before and after obviously) and stand at the front guiding them through it - boom class done in minutes

 

 

Thanks for this! Great! *rolls eyes*

 

There are 2 different angles of looking at this deployment. All i know for certain (100%) is that if the Chromebooks are first used at home and brought in then added to the domain, the device will be factory reset.

 

I guess no matter which avenue we go down there are going to be pit falls which is why i wanted to try and find which avenue would work out best so i can put my opinions forward to the SLT. Obviously having chromebooks in our GSuite would be ideal!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...