Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I'm sure you're all having this issue

 

We had one earlier where an external user was attempting to join a meeting, the same user asked a student for access to a shared document from classroom

 

I assume this is a students alt - personal email address and I'm trying to track down who it was

 

I thought the Meet audit tool would provide me with info on denied entries which would give me an IP Address which I could probably match against a current student but it doesn't, and the doc access emails come from Google so that's a dead end too

 

Any of you having any luck tracking down this behaviour ?

Posted
We had one earlier where an external user was attempting to join a meeting, the same user asked a student for access to a shared document from classroom

 

We've had a couple of teachers reporting external users trying to join live Meet sessions. We're not quite sure how any external user is getting the session URL, my guess would be towards a pupil posting the URL to some freinds online to create a bit of disruption to a lesson. It's possible that a pupil / teacher has some kind of malware on a device that is leaking data somewhere. I've noticed we have rather a lot of Chrome extension "apps" installed on our domain, some I'm sifting through those at the moment and removing anything that looks questionable.

  • Thanks 1
Posted
I'm sure you're all having this issue

 

We had one earlier where an external user was attempting to join a meeting, the same user asked a student for access to a shared document from classroom

 

I assume this is a students alt - personal email address and I'm trying to track down who it was

 

I thought the Meet audit tool would provide me with info on denied entries which would give me an IP Address which I could probably match against a current student but it doesn't, and the doc access emails come from Google so that's a dead end too

 

Any of you having any luck tracking down this behaviour ?

We have been having the same issue - if the teacher denies the external from trying to join they don't appear in the logs. However if they accept them and then remove them from the meet or class they show in the logs so we have told teachers to grant access to anyone external then remove them. More hassle but at least you can track who they are

  • Thanks 2
Posted (edited)
Good idea, I'll pass that on in case it happens again, Google ideally need to add denied entries to the audit logs Edited by caffrey
Posted
we have told teachers to grant access to anyone external then remove them

 

I'm guessing you get an origin IP address logged if nothing else - are you then matching that up with known pupils? Are you finding the disruption is from your own pupils being silly or from external users?

Posted
More hassle but at least you can track who they are

 

Just checked - can't see any IP address or similar listed in the Meet Quality Tool for an external user, is it maybe recorded in some other logs somewhere?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...