Jump to content

Recommended Posts

Posted

We are implementing a compulsory BYOD policy for year 7 next year and I am currently trying to find a decent MDM. We are completely windows here and most of the main ones I have been suggested so far are designed for chrome books.

 

Have any of you already enforced this into your school and if so how is it going? SLT here want some kind of system similar to impero/netsupport where we can see what they are doing on their devices but when the devices are owned by them this becomes a lot more difficult and questionable weather we are even aloud!

 

Another big question mark here is YouTube access as well. We currently block YouTube for all students but some members of SLT or keen to open this up, what are your views and opinions on this?

 

Sorry I know there are a lot of questions so any feedback at all would be very much appreciated!

Posted (edited)

I think this is a massively ill-conceived scheme. If this is BYOD (not sure how you can make that compulsory unless you're in private education but lets set that aside for now) then the students or their parents own the devices but your scheme seems to be predecated on the idea that the devices are there for your school to do what it pleases with. I would suggest that mandating the install of a tool like impero or netsupport to "see what they are doing" is a massive overreach. I'm not sure what the legal basis for this is but I would absolutely refuse to allow you to do this if I were the parent of a child at your school.

 

Do you have a mechanism in place to support these devices? What if they want to upgrade their device to Windows 11 while your software will only work on Windows 10? What if the monitoring software captures information related to someone who is not a pupil, such as another child who doesn't attend your school or a parent? After all, this device could be a shared device within the home and you cannot stop that because it isn't your device. What you block one of these people from their own legitimate use of the device (you have no right to say that mum, dad or adult sibling can't watch whatever they want on youtube, for example). What if your control software causes someone in the family to lose data?

Edited by Roberto
  • Thanks 1
Posted (edited)

Could be asking for trouble there IMO. (definitely are)

 

BYOD is fine if all the devices are the same e.g. Chromebooks. I wouldn't like to take on a mixtures of devices.

 

Paid up Cisco Meraki is probably the most comprehensive platform out there.... i think the exception is Chromebooks. It'll certainly do Windows, Android, Ipad, Mac.

 

If it were me I'd settle on a hardware platform (Chromebooks, Windows laptops, Ipads, whatever), choose your management platform wisely, then implement a policy that either the school provides the device or families do for school use only where the student is the sole user of the device.

 

The user experience will vary so much for each student that it won't be worth doing... and there will be inequality issues... you see where I'm going.

 

SLT here want some kind of system similar to impero/netsupport where we can see what they are doing on their devices
---> Not legal. Not by a long long shot.

 

 

My 5p's worth.

Edited by mikkydoos
  • Thanks 1
Posted
of course we only want to monitor what they are doing in school and not a home but i understand the points you have made. I think our best option will be the lease the devices and they can then purchase them for a small fee when they leave. The entire BYOD is riddled with problems and trying to find the correct solution is extremely difficult. Thanks for your feedback.
Posted
Thanks for your feedback. We are in the very early stages and have not yet made an final decisions on how we are going to proceed with this but hearing peoples views and opinions is always very helpful and insightful. I think after several chats with companies the only real way to do this is leasing devices to parents as this allows us to have control and then they can purchase the device for a small fee as they leave.
Posted
of course we only want to monitor what they are doing in school and not a home but i understand the points you have made. I think our best option will be the lease the devices and they can then purchase them for a small fee when they leave. The entire BYOD is riddled with problems and trying to find the correct solution is extremely difficult. Thanks for your feedback.

 

 

I hear ya.

 

 

I think BYOD for students is totally unworkable. Staff?... maybe.

 

Your SLT need to wise up. It's not a sensible scenario and it will fail miserably.

 

If you lease, success depends on what cloud platforms you are using. Google? O365? None?

 

Google = Chromebooks for sure

O365 = kind of pretty much anything except Chromebooks

None = start doing some heavy research and trialling

Posted (edited)

Then Windows laptops or any tablet Android/IOS device really.

 

Office 365 -- you have Azure to cloud manage your AD and whatever policies you wish to deploy.

 

MDM - I'd look at Microsoft Intune or Cisco Meraki or a hybrid of both as a starter. (Not used Intune much but it's a bit flaky from my experience).

 

EDIT: Don't forget MDM solutions are an implementation of the OS manufacturers management platform.

 

e.g. Ipads have a much more limited MDM scope that say Windows does.

 

Depends on what you're trying to achieve.

Edited by mikkydoos
Posted (edited)

Beyond pushing their wifi connection through your web filtering there's no a lot of management you'd be able to do without getting into some pretty murky legal waters (IANAL), and you need to not be managing the students' personal devices outside of the school day. When we looked at this years ago, the potential work around was Lightspeed's geofencing (other companies may do this), so devices were only "managed" when in school.

There's a reason most 1:1 schemes seem to use a lease-to-buy model. While the student is at the school, the devices belongs to the school so you can manage it.

 

As for YouTube. We used to hard block it, but during lockdown and after we've been relaxing that. Now we've got it set up so students have YT access only during lesson time, which seems to be working pretty well.

 

(Eidt) sorry that moved on a bit while I was posting. We use Intune (or whatever Microsoft calls it now) to manage student loaned devices, so far it's working pretty well. It's not great for anything other than windows, but for windows devices it does what you need for basic management.

Edited by Rob_D
Posted
I agree and the BYOD will of course be going through our school level filtering system so most things are blocked anyway. I have requested a demo from light speed and still waiting to hear back but thanks for your feedback.
Posted
I agree and the BYOD will of course be going through our school level filtering system so most things are blocked anyway. I have requested a demo from light speed and still waiting to hear back but thanks for your feedback.

 

I think a lot of the issues with BYOD have been identified above but perhaps originally the terminology was confusing matters? I'd refer to BYOD as pupils bringing their own devices of any type into school, jumping on the wifi and using them to support their education - filtered and monitored when they traverse the school network, but otherwise IT hands are off the device. A device users can choose to use with permission.

I'd refer to compulsory devices as a one-to-one deployment. Schools owned or a shared lease device of a single type which can be managed, filtered and monitored and a written agreement between school, learner and guardian. Both have their merits and their issues.

 

You did ask originally about youtube. We allow youtube for all year groups in my secondary school. We use Youtube for Schools and can approve videos for our learner when we feel it is appropriate. Strict, Moderate and Unrestricted levels of access can be assigned in the Google Admin console if you choose to use Google Workspace. You can also add video approval permissions to particular uses if you like. The filter levels aren't perfect, but reasonable.

More info here: https://support.google.com/a/answer/6214622?product_name=UnuFlow&hl=en&visit_id=637734348547343883-54517424&rd=1&src=supportwidget0&hl=en

Posted (edited)
I agree and the BYOD will of course be going through our school level filtering system so most things are blocked anyway. I have requested a demo from light speed and still waiting to hear back but thanks for your feedback.

 

You're blocking "most things" on someone else's device? You know that's a huge overreach, and totally unjustifiable, right?

Edited by Roberto
Posted

Most things have been said - I definitely would not want to do BYOD (students bringing their own personal devices) and installing any form of software on there, especially not remote access software. I mean if you had a very robust policy that parents had to read and sign beforehand and run that past a legal team, then I'm sure it'd be fine... but no, way too much legal issues and I'm personally against it from a privacy point of view. In a BYOD deployment, the most that you can provide imo is a filtered internet connection and access to printing.

With youtube - we allow it in Strict Restricted mode and it's been enabled for all users. I don't see the issue, if there is any inappropriate usage then it's down to teachers to manage really.

Posted
I think a lot of the issues with BYOD have been identified above but perhaps originally the terminology was confusing matters? I'd refer to BYOD as pupils bringing their own devices of any type into school, jumping on the wifi and using them to support their education - filtered and monitored when they traverse the school network, but otherwise IT hands are off the device. A device users can choose to use with permission.

I'd refer to compulsory devices as a one-to-one deployment. Schools owned or a shared lease device of a single type which can be managed, filtered and monitored and a written agreement between school, learner and guardian. Both have their merits and their issues.

 

You did ask originally about youtube. We allow youtube for all year groups in my secondary school. We use Youtube for Schools and can approve videos for our learner when we feel it is appropriate. Strict, Moderate and Unrestricted levels of access can be assigned in the Google Admin console if you choose to use Google Workspace. You can also add video approval permissions to particular uses if you like. The filter levels aren't perfect, but reasonable.

More info here: https://support.google.com/a/answer/6214622?product_name=UnuFlow&hl=en&visit_id=637734348547343883-54517424&rd=1&src=supportwidget0&hl=en

 

 

 

Yep. Spot on.

 

Usual things to be aware of however.... Antivirus, app control, safeguarding, damage, theft, inappropriate files and on and on and on............

Posted
its web filtering so of course we have a right to block certain websites on our school WIFI.

 

On your WiFi, yes. So you're not applying filtering to these devices directly, just while they're on your network. That is ok. I think as someone else has suggested there is a terminology/lack of precision issue here.

Posted
Yep. Spot on.

 

Usual things to be aware of however.... Antivirus, app control, safeguarding, damage, theft, inappropriate files and on and on and on............

 

Thanks both for your helpful feedback!

Posted
You're blocking "most things" on someone else's device? You know that's a huge overreach, and totally unjustifiable, right?

No; you're blocking "most things" on your network. What they do on their home network is their parents problem.

 

That said, I'm unsure about snooping software being installed on someone else's device. Though I doubt that it is illegal if done right. Informed consent - removed when they leave - secure - etc

Posted

OK this will be fun for you. Here are a couple of thoughts (I was asked to look into this a few years ago).

* legality. You wont own the machine, they do. Whilst you can say "you must install this if you WANT to use our services" it will be very hard to get a sign off on "you must install this AND use our services". You will get pushback from parents. I (for one) would not let my kids have overreaching admin software installed on their devices by the school. On a school device sure, a home one? No.

* accidental damage. Your insurance may not cover this. ~Who pays for the machines if they are damaged on school property? It is one things swapping a 4 year old dell inspiron with a refurb. It is another when little joey has his ipad pro knocked out of his hands on the stairs.

*printing. This is fun for multi device on a network that needs to be authenticated but also open. I gave up on this aspect and told people to print from USB after logging into the printer.

*Virus outbreak. Your WIFI network will need to be set up accordingly so that interdevice communication is blocked (this should be a given anyway). One spod brings that unpatched XP machine into the school laden with malware (on purpose or otherwise) and you are going to have fun.

*Filtering. This depends on your system. Again, you are on shaky ground mandating that pupils install a root cert on their devices, it is one thing saying "you want to use our guest network? Install this cert if you do" against "you WILL install this". After that you are going to be down DNS filtering and block other DNS at the firewall etc. That wont stop DNS over 443 of course. Kids do know about this to get round crappy home filtering from ISP DNS (my kids learnt how to set private DNS on their phones to bypass adverts on their manga sites!)

* Software. Not everyone will have or want to install office - even if it is free. Not only that but you will get all sorts of personal vs business onedrive issues and syncing. Newer versions of 365 are better at supporting simultaneous business and home but older office is a bit of a nightmare. Mandating software installation will be problematic. Software in DT? Music? IT lessons?

*MDM, see the first point for mandating an MDM be added to a device. This is pretty much impossible with IOS as true MDM management (outside simple app changes) needs full ASM support and claiming the device. Otherwise you are locked out of a lot of settings. If you must have an MDM that supports windows, IOSthen ManageEngine and Intune do. Chromebooks are better using google own tools but again you need to claim the devices. All the above will need paid licensing of course, chromebooks will need an educational google license too.

*Monitoring software. I assume you run some sort of classroom management. See the above points on legality when mandating a device owned by someone else needs software installing.

*Admin rights. The home user will always have admin or root. Whatever you put on could well be bypassed.

*Maintenance and spares. Speaks for itself, you run WSUS, you run GPOS, you run scripts to make things work. Dont expect this from a home device.

*Licensing. A biggie, they are on your network and you have mandated that they should have a device. A very grey area of enforcement. They will be laden with ASK toolbars, DRIVERUPDATOR2021, Torrenting software, WAREZ AND GAMEZ. How are you going to check devices are licensed properly to be on your network? You have the burden of proving authentication on a device in school in a work environment and has been mandated. These are not "guests" in the true sense.

 

If you are a private school then the only way around this is putting something on the bill, owning the device and you controlling it not them. State school? Dont bother.

  • Thanks 1
Posted
---> Not legal. Not by a long long shot.

 

 

My 5p's worth.

 

It can be legal ... but it can also be morally dubious and an extremely expensive nightmare.

 

It all depends on what we mean by MDM and device management.

 

It is possible to have tools available but to restrict when they can access and do things. This is Privacy by Design and by Default (PbD2), and should be a significant part of any DPIA/Risk Assessment that is done. I'm presently going through all our tools and writing up about PbD2, and the first example can be found here - https://classroom.cloud/privacy-by-design/

Posted
We are implementing a compulsory BYOD policy for year 7 next year and I am currently trying to find a decent MDM. We are completely windows here and most of the main ones I have been suggested so far are designed for chrome books.

 

Have any of you already enforced this into your school and if so how is it going? SLT here want some kind of system similar to impero/netsupport where we can see what they are doing on their devices but when the devices are owned by them this becomes a lot more difficult and questionable weather we are even aloud!

 

Another big question mark here is YouTube access as well. We currently block YouTube for all students but some members of SLT or keen to open this up, what are your views and opinions on this?

 

Sorry I know there are a lot of questions so any feedback at all would be very much appreciated!

 

I know you have said that this is very early on in the conversation, and I would heartily recommend you keep in mind every so far, as well as continuing to talk to schools that have done similar. If any supplier offers you a chance to talk to another school as a reference, then take it ... even talking to a reference school to a supplier can give you a lot of insight of what went well and what didn't. Ages ago I used to be a reference for Dell and for the leasing firm ... and we were fairly open about the issues we had to learn to manage.

 

The other thing you need to do is really decide what you need and see what is the best fit.

 

Are you managing devices as in putting software on them, putting in place configurations, applying filters, setting limits on usage?

Is this location specific and/or time specific (inc. certain days/dates)?

What protections will be in place should remote teaching/learning start up again?

What sort of management do you want to do? Lesson based? All the time? Blocking things or monitoring things?

 

Once you have a full picture of what you would like then you can look at the options, including any compromises or where different solutions can provide slightly different approaches.

 

Then you *have* to do your risk assessment. I say you ... but I mean the project team working on this, drawingin in whichever stakeholders are needed. Work with your DPO on this to make sure it happens.

 

And, as always, if you want a direct chat, then let me know. Yes, we do have solutions that could help, but I'm more interested in helping you work out the right approach.

Posted

Some great points brought up - I tend to look at the practical side of things though.

 

BYOD/1-2-1 deployment can raise a lot of practical issues. Such as -

 

Updates - when a big Windows/software/AV update is issued when is that to be done? Imagine all your pupils sat there doing nothing because their devices are all updating first thing on a Wednesday morning?

WiFi - is your WiFi up to that many devices connecting at the same time? Or are you hoping to have LAN cables for every user (bearing in mind a lot of mobile devices don't have a LAN port now, so an adapter is required)

More infrastructure - think all your students are going to turn up with a fully charged device that will last all day? Think those batteries are going to last for the 5 years they're with you? You'll need charging points all over the place. Expect these to be used and abused with constant plugging and unplugging of PSU's and probably phone chargers too.

More support - "forgotten" devices, adapters, PSU's... Broken kit because the dog chewed it (my old pet rabbit loved Macbook chargers!), not to mention the debris that's going to end up in there "I was doing my homework while eating my breakfast and now there's coco-pops in the keyboard". And that's before a helpful member of the family tries to fix something to make the device work better....

 

I'm not against students having a school managed personal device. But it should supplement a standard, robust and sufficient wired network based PC offering to be used on school premises rather than replace it IMO.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...