maxrebo Posted January 4, 2022 Posted January 4, 2022 Just had a teacher in the office telling us his USB memory stick corrupted over the Christmas break, no backup and he had his entire careers work on there. Despite numerous emails to staff asking them not do this, or at least take a regular backup, this still happens. Any advice on how to force staff into not using memory sticks to run their life? We have Onedrive setup, syncing using the desktop app. One idea is to ban use of USB drives through a GPO? but I don't imagine that would go down well with staff?! Thanks
3s-gtech Posted January 4, 2022 Posted January 4, 2022 When we moved to Windows 10 20H2 and staff issued laptops connecting over the VPN, I used this as the cutoff to disable USB write access (we need read for cameras etc). The operational need for the sticks is gone (we did have remote access before, but many struggled to let go), and staff were only supposed to use encrypted sticks before then. There was no feedback at all received beforehand, until some staff actually tried to carry on as they had before - at which point there was some fair whinging. I showed them the alternatives that we offer, and asked them not to bring in USB sticks or hard drives. I haven't changed the policy, and they've got on with things. Try to give lots of notice, and fit it in around an operational change - like the shift to Windows 11. 4
djm968 Posted January 4, 2022 Posted January 4, 2022 I have often found that persuasive discussion with your DPO around the dangers of USB stick use and the potential for GDPR breaches is usually enough to discourage the use of these, especially if they are not encrypted! If that fails to produce a satisfactory outcome, go above them to the HT and finance officer, if there is a data breach, the school could be liable for a large fine! 1
Ratcliffepg Posted January 4, 2022 Posted January 4, 2022 We blocked them a few years ago, do this via our Anti Virus product, a few moans at the start.... we then showed them the advantages of cloud storage...... 1
jthompson Posted January 4, 2022 Posted January 4, 2022 Any advice on how to force staff into not using memory sticks to run their life? We have Onedrive setup, syncing using the desktop app. One idea is to ban use of USB drives through a GPO? but I don't imagine that would go down well with staff?! Having OneDrive desktop sync set up means that you're in a good position to be able to proceed with phasing out USB drives, since that ought to address the vast majority of complaints that you might get. Use Group Policy to set removable media to read-only on your domain computers, rather than outright disabling them. IMHO you don't need to disable outright*, and it's far less jarring for staff who have stuff on USB currently. That allows staff who do have things on USB to still be able to access them to transfer that data into your domain, or for new staff to be able to bring resources in when they join the organisation. I'd also recommend having a policy set up that you can apply to specific machines that will override that and allow write access to non-BitLocker-protected volumes, so as to quickly allow for any unforeseen circumstances where an existing workflow gets broken. For example, Languages staff working with dictaphone recordings. You can then work out longer term solutions for those workflows without having to allow writeable USB more generally for everyone else. *Slightly different but related issue, you should also be preventing any execution from removable drives, if not already. The read-only aspect covers the data protection side of things, whilst the blocking of execution covers the security side of things. 1
Guest Guest Posted January 4, 2022 Posted January 4, 2022 We blocked writing to usb drives when the GDPR can into force. Initially we just provided RDS we now issue laptops with aovpn
computer_expert Posted January 4, 2022 Posted January 4, 2022 We had OneDrive sync set up and forced staff/students to use it as well as blocking read/write access to USB media. There were very limited exceptions to this policy mainly for photography where read only access was allowed. Plenty of warning was given to staff that this was going to happen and there were only a few stragglers who refused. 1
Sonic007 Posted January 4, 2022 Posted January 4, 2022 (edited) Are your staff well informed about cloud storage and the advtatages (accesible from anywhere, always backed up, etc)? Might be worth running a session to convince them. Also highlight the trouble they can get into with lost USB sticks and GDPR, data breaches etc. Scare them! Edited January 4, 2022 by Sonic007 1
jthompson Posted January 4, 2022 Posted January 4, 2022 I tend to avoid the scaring method: it's likely to make less confident users feel even less confident. More "this is how things will work from now on" than "you're doing it wrong". 1
MatthewL Posted January 4, 2022 Posted January 4, 2022 Clearly they are still using them as something is in the way of an alternative method or they don't know what they method is, maybe some training is needed. If you put an obstacle in the way they will use the easiest way. Maybe you need to find some key staff and get them using a cloud method and get them to sing its praises to the rest. We banned write access to USB years ago, only read access for staff then went down the route of total ban on system unless approved and then it had to be an encrypted one, too much risk trusting users as an organisation put alternative things in place that negated the use of USB. Even just advise they can email themselves that is enough for some staff and they didn't even know they could email theirselves! 1
FragglePete Posted January 4, 2022 Posted January 4, 2022 We forced encryption on any USB stick people wanted to write too (bitlocker to go). This soon dissuaded a lot of people using solely USB sticks, and as we now have the OneDrive client that sets up and syncs automatically I find most users once they see what they can do with it has moved these types of users over. I have no sympathy, especially when they present a USB drive that they got free in a packet of corn flakes, or some other cheap and nasty device and wonder why it doesn't work anymore. Pete 1
jmak Posted January 4, 2022 Posted January 4, 2022 I got them banned after our SENCo "lost" their USB with everything on it. When I asked which parents needed to be contacted and who would contact the ICO to report the breach, they looked harder and found it in the lining of their bag. Management was sufficiently scared to support my suggested policy. The other thing to do would be to try and find some people who use OneDrive (or Google Drive - pick your poison) and have them as advocates. There is usually a good number of users who actually like it and appreciate that it's better than having your life in a USB stick. I was told not to waste my time supporting staff who had caused trouble like this (losing work by using USB sticks when told not to and a practical alternative was provided) because they'd gone against instructions/school policy. Any solution will need SLT support. 2
DrBeaker Posted January 4, 2022 Posted January 4, 2022 Apart from Windows installs etc I rarely use them myself. Cloud or NAS nowadays. 1
3s-gtech Posted January 4, 2022 Posted January 4, 2022 Currently finding USB sticks fantastic for building individual vanilla builds of 10 Home that won’t be on the domain (so MDT would be a pain), and just used another for updating the firmware on a switch without needing to use a browser. They have no place for storing or moving anything important now IMO. A portable hard drive at home as offline backup isn’t a bad idea, but that’s about it. 1
free780 Posted January 4, 2022 Posted January 4, 2022 I think the fundamental issue is that some staff believe they are free lancers and that any content they have is owned by them regardless of how it was obtained. In reality the ownership of the data is the organisation they work for. This is why removable media is used for control of data and probably files copied from other organisations. If you don't prevent Dropbox or Google drive data will end up on personal accounts via policy or technical controls. Fundamentally the organisation needs to use Onedrive for Business or Google Drive and make it clear that you cannot take data with you when you leave the organisation. 3
Tom_P Posted January 5, 2022 Posted January 5, 2022 (edited) We tried the nice and non-scary approach which didnt work, then we tried the GDPR Data protection approach which worked better but some still didnt care. Then we were alerted to a potential malware infection - thankfully our antivirus did its job. Turned out it was from a teachers memory stick, which we later found out also killed her home PC and sons laptop. After this we took the take no prisoners approach and fully disabled the use of memory sticks and added the restriction to our IT acceptable use policy. Also in this time the school appointed a new data protection officer who also added the restriction as a potential GDPR and safeguarding issue. Basically what @free780 mentioned. All staff members were then forced to use onedrive, which was already being used by all students and some of the staff. There was some resistance in the beginning but with the USB option being disabled they had no choice. They've now said how brilliant it is. Especially when a file goes missing and we are able to recover it, unlike before. Edited January 5, 2022 by Tom_P 3
jthompson Posted January 5, 2022 Posted January 5, 2022 I sometimes wish I'd kept all of the broken, snapped, failed USB sticks that have landed on my desk over the years, and created some sort of wall art out of them all. It'd look crap, but might have helped bring about the end of the USB era quite a bit sooner. 2
Tom_P Posted January 5, 2022 Posted January 5, 2022 I sometimes wish I'd kept all of the broken, snapped, failed USB sticks that have landed on my desk over the years, and created some sort of wall art out of them all. It'd look crap, but might have helped bring about the end of the USB era quite a bit sooner. Thats a pretty neat idea. Could have how many files were fallen in each sticks eulogy 1
maxrebo Posted January 5, 2022 Author Posted January 5, 2022 Thanks everyone, for your feedback, really helpful for me to put a plan together. Cheers
Koldov Posted January 5, 2022 Posted January 5, 2022 I have tried to have this discussion with SLT a few times, but failed to really gather any support. With a few quotes from this thread I am going to make another effort, but can already see a few issues. What do you do with visitors, external educators, music/choir teachers, trainers etc. These all seem to have their documents/presentations on a USB stick... I'm sure some of you say tough luck to them, but that isn't going to help me sell this. It won't work in the real world scenario of being called to the hall in front of a whole assembly full of children and teachers to be faced with a visitor who nobody knew needed a USB to do the presentation (yes I know they could have emailed it or something, but I can practically guarantee that won't happen). Also, how is it best to do this GPO or Anti-Virus (we use Sophos), for if it needs to be reversed on individual machines on the fly. Which devices need to be allowed and how is it done, iPads, cameras, smartboards, visualisers, phones etc. Is any method granular enough to know which is which? It seems to me there are a few versions of this issue and I'm not sure what I'm trying to achieve in each scenario: Writing to USB - this is to stop resources (and potentially sensitive data) being saved to USB storage. Reading from USB - this is to stop resources being brought in on USB storage Executing from USB - potential virus/malware route. Then I would need to look into blocking all other forms of cloud storage (to stop personal accounts on Dropbox etc.) except those used by the school (Google Drive).
jthompson Posted January 5, 2022 Posted January 5, 2022 I have tried to have this discussion with SLT a few times, but failed to really gather any support. With a few quotes from this thread I am going to make another effort, but can already see a few issues. What do you do with visitors, external educators, music/choir teachers, trainers etc. These all seem to have their documents/presentations on a USB stick... I'm sure some of you say tough luck to them, but that isn't going to help me sell this. It won't work in the real world scenario of being called to the hall in front of a whole assembly full of children and teachers to be faced with a visitor who nobody knew needed a USB to do the presentation (yes I know they could have emailed it or something, but I can practically guarantee that won't happen). Also, how is it best to do this GPO or Anti-Virus (we use Sophos), for if it needs to be reversed on individual machines on the fly. Which devices need to be allowed and how is it done, iPads, cameras, smartboards, visualisers, phones etc. Is any method granular enough to know which is which? It seems to me there are a few versions of this issue and I'm not sure what I'm trying to achieve in each scenario: Writing to USB - this is to stop resources (and potentially sensitive data) being saved to USB storage. Reading from USB - this is to stop resources being brought in on USB storage Executing from USB - potential virus/malware route. Then I would need to look into blocking all other forms of cloud storage (to stop personal accounts on Dropbox etc.) except those used by the school (Google Drive). We allow reading from USB, so job candidates, etc. bringing in a presentation on a USB can still just use them. I'm not sure that there's too much of an issue associated with people bringing in resources from USB, particularly if you're at the point where it's largely dropped out of use amongst your users. We do this using GPO. For a quick workaround on specific machines, we'd just move the machine to a nested OU and apply a policy which specificially allows writing to non-encrypted removable media (i.e. overrides the general policy that sets them as read-only). iPads, cameras, SD cards, etc. should all be fine as read-only. 1
Koldov Posted January 5, 2022 Posted January 5, 2022 We allow reading from USB, so job candidates, etc. bringing in a presentation on a USB can still just use them. I'm not sure that there's too much of an issue associated with people bringing in resources from USB, particularly if you're at the point where it's largely dropped out of use amongst your users. We do this using GPO. For a quick workaround on specific machines, we'd just move the machine to a nested OU and apply a policy which specificially allows writing to non-encrypted removable media (i.e. overrides the general policy that sets them as read-only). iPads, cameras, SD cards, etc. should all be fine as read-only. Thanks, this is what I was getting at... If 'read' is allowed then there needs to be some sort of mechanism to ensure what is being read isn't potentially dangerous such as a script or program (and also a way to block the execution of files such as virus/malware)? Also, an SD card is just as able to have a dodgy file on it as a USB stick (I have used them as such in certain situations). Unfortunately the 'quick fix' of moving OU and rebooting/gpupdate won't be workable if I'm not on site or not contactable?
jthompson Posted January 5, 2022 Posted January 5, 2022 Thanks, this is what I was getting at... If 'read' is allowed then there needs to be some sort of mechanism to ensure what is being read isn't potentially dangerous such as a script or program (and also a way to block the execution of files such as virus/malware)? Also, an SD card is just as able to have a dodgy file on it as a USB stick (I have used them as such in certain situations). Unfortunately the 'quick fix' of moving OU and rebooting/gpupdate won't be workable if I'm not on site or not contactable? If allowing removable media as read-only, you'd definitely want to have AppLocker or equivalent application allowlisting in place, to prevent users from running portable apps or malware. In fact, you want application allowlisting in place regardless. That's a whole other topic, though. I don't think you'd want your readable/writeable workaround to be in the power of the users, so keeping it within the realm of sysadmins' tools is probably best.
mattpayne Posted January 5, 2022 Posted January 5, 2022 We tried using harsh words - didnt work We tried using Encrypted sticks, but at a glance a stick is a stick and its impossible to tell if the staff are using the correct one. Finally used Netsupport DNA to disable USB access. this blocks all USB devices, but has the ability to allow specific sticks for specific people/machines, its a bit clunky and expensive, but ticked all the boxes for keeping our DPO relatively happy! 1
Chris_Cook Posted January 5, 2022 Posted January 5, 2022 I'd definitely recommend applocker or similar to prevent running programs from random locations. Also helps stop games from student drives and random things from the downloads folder. For the staff who have most of the visitors, we've drilled it into them over the years to request a copy of slides so that we (they) can test them. It also helps with random file formats, missing fonts, poor layout and blocked videos. At least we then have a chance to deal with it before the kids get there. Doesn't work every time as some people don't like giving out their work for free, but people see the benefit when they don't look like idiots in front of students. Another option might be to let them plug in their own laptop to your projectors or screens. You might also have a visitor account with read access (and no access to confidential data). That could give an extra layer of security if something dodgy was on a memory stick.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now