Jump to content

Recommended Posts

Posted

In most organisation the general trend is to have locked down network clients.

The problem comes with what to do with laptops given to teachers and students with special needs.

 

They can reasonably argue that they need to install ISP software or drivers drivers for home hardware e.g. printers. Teachers may say they also need to 'try out' new software.

 

What to do? How to strike the balance between enabling students and teachers to get full benefit of 'their' machines and the need to protect the school network from sleep walking malware vectors.

Posted
We are needing to review this really, as we have had a couple come and say, they want to install there home printer on them, currently the local user account they use on the laptop is just a member of Users / Standard User on the laptop, and thats it, so I am interested in seeing what others do.
Posted

Yes please can everyone add to this.

 

At the moment our laptops are members of the domain so the teacher logs on as a domain user wether they are plugged in or not and their H: drive is available offline. But I presume that with the restrictions we have in GPO etc... that their domain user is a normal user as far as the laptop is concerned therefore they can't install software/hardware etc....

 

As far as I am concerned as long as the apps installed on it that the school own works and they can access the school network and Internet via it then thats good enough. But there is always someone that wants the other side of things too.

 

There have been some other threads on this I know but it would be nice to have a long list for some ammo.

 

Ben

Posted

I've been thinking about this.

 

My users have a domain account and a local account. Some users have access to a local admin account for installing software, but run under a normal user account for everything else. They're currently not allowed to connect their laptop to any network but ours.

 

My general (and definitely unwritten) policy is as follows:

 

1) Can I trust this user to do the sensible thing?

2) Does the benefit outweigh the hassle?

3) If user has admin access, we will only restore the ghost - no troubleshooting of additional software.

4) Any software must have a valid licence (GPL, commercial, free for edu)

5) How much have you annoyed me in the last month(s)?

Posted

I have about 20 teachers with wireless laptops. The laptops and staff are subject to their normal group policies. However, I've applied a loopback GPO to the laptops which 'undoes' some of the security in their normal GPO to give them more freedom when using the laptops.

 

I allow them to install their own software and set up home dial-up/broadband - as well as lot of other things. I originally thought that this would cause me a lot of hassle, but it hasn't.

Posted

I setup the laptops as workgroup rather than domain clients. I then create a local laptop admin account that matches their domain account.

 

Install any shared drives / printers ect. Then use local Group Polices to lock down any features, eg offline files.

 

Seems to work a treat at the 4 schools I look after.

Posted
I have about 20 teachers with wireless laptops. The laptops and staff are subject to their normal group policies. However, I've applied a loopback GPO to the laptops which 'undoes' some of the security in their normal GPO to give them more freedom when using the laptops.

 

I allow them to install their own software and set up home dial-up/broadband - as well as lot of other things. I originally thought that this would cause me a lot of hassle, but it hasn't.

 

 

So you're not really over worked :D

Posted

We run a Laptops for Students scheme here and we give the students 2 accounts, a domain account (locked down via GPOs) and a local account (with local admin rights)

 

We give local admin rights so that they can stick their own software on at home, their own printers, internet connection, etc.

 

If they bugger it up we say "you have buggered it up and now it doesn't work on the school network. We will fix it this time but if we find software x or you have done y or z and stopped things from working, then we will remove it from our network!" and send a letter home saying the exact same.

 

The students and parent learn very quickly that we mean it.

 

We also give them local admin access because it means that they have a large responsibility ... and they learn the consequences of buggering about with things when they have been told not to ... see ... even support teams can tick boxes in the "Every Child Matters" stuff ... we are teaching the kids things that also come up in citizenship.

Posted

What's to stop them installling hacking software and connecting to the network as local admins a wreaking havok?

 

Sounds like deep freeze on the laptops would be a good idea too - tho' the lesson in responsibility is sorta lost :p

Posted

When they log in we now have a script that writes what software they have installed to a database (a bit clunky but Stephen has got it nearly sorted) and we can see aht they are up to to a certain degree.

 

We also run a software restriction list (deny .exe, etc) to cover other things ...

 

It isn't perfect. We know some of them will try stupid things. However, they cannot connect to the network to talk to anything when a logged on as the local account, only as a domain user ... and this is when the GPOs and scripts kick in.

 

Ideally we would have all the APs in a seperate VLAN with access controlled by a Blue Socket box (or Vernier) ... but we don't have the extra several thousand pounds a year for it yet ... and we won't for some time. That way users would have limited access to most things ... and they couldn't really do much damage.

 

This is one of the few times when I would say the educational benefits far outway the risks of sheer stupidity on the part of users ... at the moment. YMMV!

Posted

Couldn't they connect to the shares they normally have access to from the local admin account? They just need to know the path \\server\share and/or \\server\home folder then log in with thier network credentials.

How do you lock out programs outside of GPO control BTW? [just interested :)]

Posted

All our laptops are due to be fully networked in the next couple of months so that the staff use them with the interactive whiteboards, etc.

 

I will also be installing a very basic virtual machine using the VMWare player. This will have NO applications installed in it but the user will have full admin rights so can use it for testing programs and using their home hardware.

 

There is a new policy that states what is permissable within the virtual machine and all staff have a clause in their contracts which state that this must be adheared to.

Posted

@Ric_

 

Interesting solution, but do you need separate licenses for each Windows installation... or could I install all our windows servers onto one uber powerfull 16 processor box and never buy a windows license again hehe.

Posted
I will also be installing a very basic virtual machine using the VMWare player. This will have NO applications installed in it but the user will have full admin rights so can use it for testing programs and using their home hardware.

 

ISTR reading something similar about Uni's doing this for student apps (though was a paid, tailored product from VMWare), possibly in El Reg. Students could only use university supplied apps running in the vm, which disabled usual means of copying software (removable disks etc) when vm was running. IIRC they had an expiry date on the vm as well for licensing considerations.

Posted

Seems a long winded workaround Ric. Sorta like the sound of it tho'.

 

If I were the teachers I wouldn't be happy with the reduced performance and certain types would be demanding something more powerful from the Head Teacher and stressing the investment in the horsepower wasted. These sorts of argument carry weight at my place.

Posted

From my research, I found that you are OK to run 2 copies of XP on one physical box for this kind of environment which is more for testing than a production environment. I also use a fully paid up copy of VMWare Workstation to make the VMs.

 

If you go for some of the upper-end VMWare products, you can do all kind of funky things to the VMs - check out the presentation on the website.

 

This fullfils our requirement and the VMs will probably hardly get touched - especially since there is no software provided. I doubt some people will even run the thing to see what it is!

 

I want all the laptops networked so that I can manage updates and I refuse to allow staff to be able to destroy what I've done to the machine. This seems like a good stop-gap and our recent influx of interactive whiteboards and bluetooth tablets means that it is a perfect time to force it on people.

Posted
I want all the laptops networked so that I can manage updates and I refuse to allow staff to be able to destroy what I've done to the machine. This seems like a good stop-gap and our recent influx of interactive whiteboards and bluetooth tablets means that it is a perfect time to force it on people.

Can't fault you there!

Posted

I had a severe run-in with my Systems Manager about this yesterday! Thanks for posting this one.

 

Anyway, what I prefer to do for staff laptops is give them a local account with at least Power Users membership. That way (other than things that change system files) they can generally do *enough*. For some that hasn't been enough, and so with trepidation I gave out local admin accounts to several (they *all* have stuff they need to do on the machines at home) with encumbent warning that if they mess it up they cannot come crying to me. Well, Systems Manager does not like this at all. He doesn't want them being local admins on laptops, period. And I caught the rough end of this yesterday.

 

I think I'll stick to Power User and pass on the others to "the boss". Even so, having a domain account and a local account seems sensible to me if the laptops are (obviously?) going off site and in some cases simply being used at home as a com-puter.

 

Still got a bit of ass left....

 

:-(

Posted

This thread on TES forums may be of interest as to the feeling in schools about admin access on laptops

 

http://www.tes.co.uk/section/staffroom/thread.aspx?story_id=2186329&path=/ICT/&threadPage=&messagePage=1

 

The general feeling is that a goodly number of teachers think that they know how to operate a computer at administrator level and a goodly number of NMs / Techies think that the few that can are not worth the hassle created by the majority that will only bugger things up.

 

And then there is the usual "we are better than you" slanging match from both sides ... and then a range of emails between people which results in finding that there is actually a general concensus of "use a bit of common sense and trust those that have proven that they can be trusted!"

  • 1 month later...
Posted

Thought I'd revive this topic as we've just got a load [12] of new Fujitsu laptops and I'm wondering how to get the GP for laptops to be nigh-on perfect hehe

 

Is there any way to turn off Offline Files completely - except for the Home directory?

 

The other snag with this - although I dont believe it will be that big of a problem - is that when I logged on, it started syncronising my home folder. I've used a rediculous amount of space [tho I'm guessing in *most* cases it will be ok] so it started copying all the files across onto the laptop.

 

Am I right that this syncronisation is only a differential syncronisation i.e. that once it has done it once, only the changed/new files will be copied during logon/logoff?

 

Another thought is, do you use Offline files? If yes, how have you got it setup? If no, then why not and how have you prevented it?

 

I'm using a unattended CD which works fine for me - as it automatically joins them onto the domain and stops to ask the computer name and carries on [i thought it easier this way that messing around with the random name afterwards hehe].

 

Any thoughts asap [as always] as I need to get the most of them installed and running by the end of today ;)

 

Cheers

Nath

Posted

The best way to turn off offline files is to just disable it on the share. This is something I wanted to desperately find out as file synchronisation was the bane of my life until I turned it off entirely. It was a real PITA and I was glad to see the back of it.

 

To disable it on the share, right click on the folder, press sharing. Press Caching and uncheck "Allow caching of files in this shared folder".

 

Alternatively turn it off in a GPO. Its a computer setting, its under CC\admin templates\network. The option is "Offline Files", disable it to turn it off.

Posted

@tarquel: The default is to automatically cache any redirected folders (handy since these will include the home drive, start menu and desktop). Alternatively, you can use a GPO to turn this feature off and use 'Administratively Assigned Offline Files' - it's in the GPO - and bang the stuff in there.

 

Your assumption that it only copies the changes is correct.

Posted

All our Teaching staff and a good number of other support staff have laptops.

 

I started out with restricted access but found that staff would go on training programs when they needed to install software and could not and this caused some bother.

 

We came up with a 'contract' that staff had to sign re software, home access etc.. and then opened up the gates to local admin rights.

 

They know that we will ask for a laptop and check it for liceneced software, dodgy files and stuff.

 

Touch wood but in the three years of staff freedome we have not had any major break of the trust. Just one learning mentor who always needed to format his hard drive prior to us collecting them for upgrades and a teacher who had a large amount of pop up porn.

 

When they login to the admin domain we enforce microsoft updates and anti virus so are covered from that angle. Not had many virus attacks.

 

The major problem i have with teachers is getting them to backup their data. Our head of Technology has just had his laptop stolen from home and quess what? he hasn't backed up any of his data to the network, CD or pen drive in months.

Posted
@e_g_r: That is exactly why I have started using VMWare on the laptops... bang a basic install of XP in VMWare Player and the staff can trial the software as much as they like. You still have the benefit of backing up their files using offline files too.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...