Jump to content

Recommended Posts

Posted

Whilst rummaging around in the Google Admin console for other things, I happened to check the 'Devices' section.

 

For some reason I seem to have all the students personal devices listed there.

 

Is there any reason for this to be there?

 

We don't 'control' their devices do we?

 

Should we have this information?

Posted

Thanks!

 

But obviously I don't want to do any sort of control as these are the student's personal devices.

 

Well at least it doesn't look like any of the settings there are being applied?

 

Also looking at the link it seems to work from a user setting for a given OU, but even if I wanted to control the user's account on a work device, would it also give me control of their personal device if they signed-on to it?

 

Basic mobile management

 

Customize password requirements for managed mobile devices.

Set up managed apps for Android devices.

 

What else you can do

 

Wipe a user's account from a mobile device.

Posted

I think in theory, because you are exposing your corporate data to the device, as part of the BYOD trade-off, the user does grant you certain admin functions over their device (whether they realised they did so or not), Azure AD does much the same thing, as does Exchange. Be interesting to enroll your own device on there and see what controls you can use.

 

I mainly just ignore this page. When I'm going to Devices, I want to see my enterprise enrolled devices, it's kinda irritating that I'm presented with user devices each time and have to drill up then down to find them.

Posted
At the most basic, you can force them to use passcode/pin/fingerprint detection on the device they're adding their account too, and you can remotely remove the account from their device should you need to.
  • Thanks 1
Posted

What else you can do

Wipe a user's account from a mobile device.

 

A while back, in a previous job, one of our governors (don't ask!) switched on the option that led to a large number of staff mobile devices appearing. From memory, I think it ways all iPhones and not Android, but that may not be accurate. Anyway, I saw this ability to wipe devices and whilst tempted to test it (and make a point :evil_twisted:) I decided to back out the change. What really struck me is that not one member of staff realised. Clearly quite a few of them were logging in to their school G Suite accounts on personal devices, in spite of them all having access via managed Chromebooks.

Posted
I mainly just ignore this page. When I'm going to Devices, I want to see my enterprise enrolled devices, it's kinda irritating that I'm presented with user devices each time and have to drill up then down to find them.

 

You see the personal devices mixed in with the school ones?

 

I see the personal ones when I go to Devices > Mobile & endpoints and school ones when I go to Devices > Chrome > Devices

Posted
You see the personal devices mixed in with the school ones?

 

I see the personal ones when I go to Devices > Mobile & endpoints and school ones when I go to Devices > Chrome > Devices

 

Oh, no, they are separate. My comment was more that it's an irritation that it always defaults to personal devices at Devices > Mobile & endpoints, when I almost always want to see Devices > Chrome > Devices.

 

A minor irritation in the grand scheme of things, just seems an odd choice.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...