Jump to content

Recommended Posts

Posted

Hi,

 

I have enrolled a couple of our new DfE HP Chromebooks and it all seems OK. I followed the guide on the gov.uk website but apart from saying "enrol them" there doesn't seem to be much info on whether there are any configuration changes I need to make in my GSuite Admin - Device settings.

 

We haven't used Chromebooks up until now - so not sure if there is a best practice guide as to what settings we should configure for these school-managed devices. At the moment, I guess everything is still setup as it would have been on Day One.

 

When our GSuite was setup by a partner (using the DfE funding) I know there were some DfE guidelines that they followed to configure settings for our Users - but I'm not sure if there are similar guidelines to follow for Devices.

 

Out Windows network has GPOs for student computers and I wondered if there is a similar set of lockdown configs for Chromebooks. Does anyone have a guide/list of GSuite settings for Devices suitable for Chromebooks used in Primary they would be happy to share?

 

Thanks in advance

Posted

Ensure you have enterprise enrolled the devices. at this point you can forget about them.

 

 

Go into google admin > devices chome > settings > user or device

 

Scroll throuhg the list and tick till youre happy.

 

Id suggest:

 

 

Forced reenrolment on

Restrict logins to your schools domain/s

set update policy

set downloads to save to drive by default

 

the rest will be preferences

  • Thanks 1
Posted

All of what DGardiner said.

 

Also useful to choose which apps to force install and 'pin' to the shelf (taskbar) by going to Devices > Chrome > Apps & Extensions

  • Thanks 1
Posted

That's great - thanks.

 

I have configured the settings inside the OU where my dfe Chromebook devices are (they are the only things inside this OU) - however as the settings are divided into the tabs of "User & Browser Settings" and "Device Settings" - should I only be configuring Device Settings at this level and then rely on the "User & Browser settings" that are applied to my Student OU to take care of that side of things? Or should I configure both types of settings in the OU where my devices reside?

 

If I do that however, am I in danger of contradicting some User & Browser settings that have already applied to my Student OU?

 

Or should I move my DfE Device OU to be a child OU of my Student User OU - and then just set Device Settings and let the existing User & Browser settings filter down to it?

 

Hmmm .. I feel I may have confused myself now!

Posted (edited)
That's great - thanks.

 

I have configured the settings inside the OU where my dfe Chromebook devices are (they are the only things inside this OU) - however as the settings are divided into the tabs of "User & Browser Settings" and "Device Settings" - should I only be configuring Device Settings at this level and then rely on the "User & Browser settings" that are applied to my Student OU to take care of that side of things? Or should I configure both types of settings in the OU where my devices reside?

 

If I do that however, am I in danger of contradicting some User & Browser settings that have already applied to my Student OU?

 

Or should I move my DfE Device OU to be a child OU of my Student User OU - and then just set Device Settings and let the existing User & Browser settings filter down to it?

 

Hmmm .. I feel I may have confused myself now!

 

With google theres usually not much overlap where user/devive settings will mishmash like on GPO theyre usually a different subset of options.

 

Ive got our device settings deployed at the root because its pretty static (possibly the custom walpaper is per OU) but the policies can be overridden in the OU's as ou require differences.

 

As for users, Again the overarching trust policy is applied at the root OU and then we override individual settings as schools require differences

 

 

Probably worth mentioning Deice settings only apply to hardware in the OU's below, User settings apply only to user accounts

Edited by DGardiner
  • Thanks 1
Posted
With google theres usually not much overlap where user/devive settings will mishmash like on GPO theyre usually a different subset of options.

 

Ive got our device settings deployed at the root because its pretty static (possibly the custom walpaper is per OU) but the policies can be overridden in the OU's as ou require differences.

 

As for users, Again the overarching trust policy is applied at the root OU and then we override individual settings as schools require differences

Probably worth mentioning Deice settings only apply to hardware in the OU's below, User settings apply only to user accounts

 

 

OK, I think my confusion is around a policy I have set on my Device OU - inside which I have configured some of the settings in the "User & Browser" section not just the "Device" settings. I think my best bet would be to revert any of the user settings I have changed back to being inherited from my top level and then relying on the ones inside my Student OU to do the user side of things. Is that the best approach?

Posted
OK, I think my confusion is around a policy I have set on my Device OU - inside which I have configured some of the settings in the "User & Browser" section not just the "Device" settings. I think my best bet would be to revert any of the user settings I have changed back to being inherited from my top level and then relying on the ones inside my Student OU to do the user side of things. Is that the best approach?

 

Yep that sounds the plan.

 

all user settings will come from the Users UO's inherited settings. Hardware from whatever the inherited settings are for the devices OU

  • Thanks 1
Posted

We just have our main domain as the Parent OU and then Staff OU and Student OU as 'children' of that. So obviously anything we want blocked/unblocked for everyone, we would do at the top level and the child OUs inherit that. Then we can fine tune the student OU to block anything that we'd like staff still able to have.

 

For example, the students might have a different wallpaper applied to their devices. They also have different apps pinned.

  • Thanks 1
Posted
We just have our main domain as the Parent OU and then Staff OU and Student OU as 'children' of that. So obviously anything we want blocked/unblocked for everyone, we would do at the top level and the child OUs inherit that. Then we can fine tune the student OU to block anything that we'd like staff still able to have.

 

For example, the students might have a different wallpaper applied to their devices. They also have different apps pinned.

 

Ah, so would I bebetter off putting my Device OU as a child of my Student OU and setting all the policies at the Student Level so that all my Student users get the same settings - and the ones with DfE Chromebooks get their usual settings, plus a few extra device-specific ones (such as only allow users from our domain to login, guest mode disabled, auto-complete domain, etc)?

Posted

I kept it like you would with Active Directory

Created an OU in the root called chromebooks with Device OU's for staff etc. I apply device settings to that OU etc.

Posted

I think so... I'm trying to understand your setup.

 

We don't have a 'Device OU'. The OUs that you see when you go to the 'Users' section from the main admin dashboard are exactly the same as the OUs that you see when you go to 'Devices > Chrome > Devices'.

 

So when I enrol a new Chromebook, it appears in the devices list and then I assign it to either the Staff OU or Student OU, depending on who will be using it. It will then pick up the settings I've set for that particular OU.

Posted

You can easily create the OU, I just like to keep things separate for ease

 

I also have a user setup in each of the device OUs that I use for enrollment with "Place device in user organization set". So when I log in say with staffchromebook@ it automatically places the device in the Staff devices OU

Posted
I think I just had in my mind to create a separate device OU just to keep things "tidy"! I think I would prefer to keep it like that and would then change the Device Settings in the Device OU and the User/Browser settings in the Student OU. I think my GPO head might be taking over now as I have User Policies and Computer Policies and don't tend to mix the two!
Posted (edited)
I think I just had in my mind to create a separate device OU just to keep things "tidy"! I think I would prefer to keep it like that and would then change the Device Settings in the Device OU and the User/Browser settings in the Student OU. I think my GPO head might be taking over now as I have User Policies and Computer Policies and don't tend to mix the two!

 

I know what you're saying but I think it's over-complicating things. Windows GPO was always a nightmare. I'm glad we've moved away from that now. I was never sure whether to set something in device or user because there would be so many crossovers. Google feels a lot simpler to me.

 

We've got:

 

-main domain OU

-Staff OU

-Students OU

-Cohort 2017

-Cohort 2018

-Cohort 2019

-Cohort 2020

 

So we could have separate settings for each year group if we wanted.

 

Each OU has its own 'User & Browser settings' and 'Device Settings' that we can set. The children inherit the ones from the parents.

 

I can see no advantage of having another OU for devices to only set device settings.

Edited by j224
Posted
And I think I also had it in mind that I would need to have the DfE devices in a separate OU in order to get the Cisco Umbrella extension installed on just those devices ... but I've followed the guide on the gov.uk site and I'm not so sure that the apps are applied to Devices .. I think they are applied to Users ... so now I'm wondering if I need to put those children who are being allocated a DfE Chromebook into a separate OU under their Student/Intake OU (as I don't think I need to push it to all my students - just the ones we are supplying devices to)....?
Posted

Think I posted just before you so you might have missed my reply on the previous page.

 

Re. Cisco Umbrella, what are the other students using? The ones that don't have the DfE Chromebooks allocated to them?

Posted (edited)
Think I posted just before you so you might have missed my reply on the previous page.

 

Just spotted that one! Must have passed in the ether! Yes, my structure is almost exactly the same .. with the exception of the nice shiny new OU I created for the DfE Devices just under the main domain OU! But the more I think about it, you are probably right in that I am over-complicating things!

 

Re. Cisco Umbrella, what are the other students using? The ones that don't have the DfE Chromebooks allocated to them?

 

All the other pupils will be using whatever devices they have at home - laptops, ipads, phones, etc - so these won't have anything "school managed" in the way of filtering. I was under the impression that it was just the DfE supplied devices that we needed to provide filtering for?

Edited by BlueSkies
Posted (edited)
All the other pupils will be using whatever devices they have at home - laptops, ipads, phones, etc - so these won't have anything "school managed" in the way of filtering. I was under the impression that it was just the DfE supplied devices that we needed to provide filtering for?

 

If you don't have any limitations regarding the amount of installations of Umbrella you can use, then I'd personally just get rid of your shiny new OU and apply the Umbrella app/extenstion to your Student OU in the 'Apps & Extensions' section.

 

EDIT: and assign your DfE Chromebooks to your Student OU too.

Edited by j224
Posted
If you don't have any limitations regarding the amount of installations of Umbrella you can use, then I'd personally just get rid of your shiny new OU and apply the Umbrella app/extenstion to your Student OU in the 'Apps & Extensions' section.

 

I'll need to check if there are any limitations - as it was part and parcel of the DfE Chromebook order, so not sure if it is something I can use for all my users or just those that get the DfE devices.

 

Shiny new OU now retired!

Posted
Even if there is a limitation, applying it to the Student OU won't matter, because the extension will only get installed on the Chromebooks which you assign to the Student OU (i.e. the DfE ones because it sounds like you don't own any other Chromebooks?)
Posted (edited)
I know what you're saying but I think it's over-complicating things. Windows GPO was always a nightmare. I'm glad we've moved away from that now. I was never sure whether to set something in device or user because there would be so many crossovers. Google feels a lot simpler to me.

 

We've got:

 

-main domain OU

-Staff OU

-Students OU

-Cohort 2017

-Cohort 2018

-Cohort 2019

-Cohort 2020

 

So we could have separate settings for each year group if we wanted.

 

Each OU has its own 'User & Browser settings' and 'Device Settings' that we can set. The children inherit the ones from the parents.

 

I can see no advantage of having another OU for devices to only set device settings.

 

 

We have

 

-main domain OU

-ChromebookOU

-SCH1

-SCH2

-ETC

-Staff OU

-SCH1

-SCH2

-ETC

-Students OU

-SCH

-Cohort

-ETC

 

 

All settings are applied at the root and overridden as required in the child OU's

 

General trust policies/restrictions are trust wide - Very little changes school to school except some Services/bookmarks/wallpapers this lets us do that.

Edited by DGardiner
Posted
I still don't see the use of 'ChromebookOU'. What policies are applied in there that wouldn't be in Staff OU or Students OU?
Posted
I still don't see the use of 'ChromebookOU'. What policies are applied in there that wouldn't be in Staff OU or Students OU?

 

We have alot of stuff being bough centrally and moving around - We just kept them seperate at the start and its stuck.

Posted
I still don't see the use of 'ChromebookOU'. What policies are applied in there that wouldn't be in Staff OU or Students OU?

 

Thought i had a reason (I dont), if a teacher was to login on their own chromebook at home, currently under your single OU for user & decvice, they would be getting the user policies but would they also get your school device policies applying?

 

Scratch that - if the device is not listed in the OU it should not get the policy. You are right there are no reasons to have a seperate devices OU.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...