Jump to content

Recommended Posts

Posted

I thought our school had turned a corner during covid allowing us to setup Edulink, moving to Google Workspace including email to Gmail and terminal server for home access

 

This week leadership is worried about people having access to Gmail and Edulink if a personal mobile got into the wrong hands.

I have already disabled the Google login button on Edulink so they have to type their username and password.

But on iOS there is no Face/Touch ID for Gmail, but there is on Google Drive. Android you can lock down the work profile so is a non-issue.

 

How does your school manage this or are you like me this is a non-issue everyone's phone already has a PIN, Pattern, fingerprint, or Face locks on their phones getting into the "wrong hands" is a teacher giving their phone to a child to watch youtube or game a game.

Posted
Here any personal device that gets used for work has to be checked by IT before its authorised for use. Part of that process is; making sure they have fingerprint, facelock or pin security (we do not allow pattern as i have heard examples of people tilting the phones to see the lines and guessing the patterns). We only allow the device to be used if its running the latest supported OS the manufacturer offers and staff are aware it must be updated regularly.
Posted

Basic Mobile Device Management

 

https://apps.google.com/supportwidget/articlehome?hl=en&article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fanswer%2F6328679%3Fhl%3Den&assistant_event=welcome&assistant_id=!2O7KaUcBF4U%3D&product_context=6328679&product_name=UnuFlow&trigger_context=a

 

No form of PIN/fingerprint/passcode protection, then no using your work account on the device and remote wipe account functionality. You'll probably find anything above that would be considered intrusive by your SLT, so they won't support Advanced MDM.

Posted
It's a yes, but we force enrollment in MDM (either GWorkspace or M365) so it can be wiped remotely and policies like minimum security can be enforced.
  • Thanks 1
Posted

So we issue staff with work phones were applicable and they are expected to use that but we cannot control our staff and what they do on personal phones for things like email. The policy does state no use but there is no control over it.

 

Some systems when they sign in for example with email force a PIN or some sort of authenticate and allows remote wipe. You need to be clear and cover it in your IT policy if they cannot, and if they do use certain things to ensure the phone is secure and that you could wipe for example if email is on it.

 

I can see the argument if you don't provide say a phone then they will use their phone so you need to cover your back with that.

Posted

Thanks for this but this still doesn't seem to do what the head wants for iOS, android does as you can force a user to authenticate work profiles app using MDM.

iOS just makes sure their main PIN is good I guess, or I'm I missing something?

Posted
It's a yes, but we force enrollment in MDM (either GWorkspace or M365) so it can be wiped remotely and policies like minimum security can be enforced.
I've always done this. Some staff complained about the idea of me having control over their phones. I told them that they weren't required to have school services on personal devices, but if they wanted it, that was the condition. My school was small enough that I knew all of the staff well. I was able to assure them that I wouldn't mess with their phone, but it could actually be useful for them if they lost their phone I would easily be able to wipe it for them.
Posted (edited)
I've always done this. Some staff complained about the idea of me having control over their phones. I told them that they weren't required to have school services on personal devices, but if they wanted it, that was the condition. My school was small enough that I knew all of the staff well. I was able to assure them that I wouldn't mess with their phone, but it could actually be useful for them if they lost their phone I would easily be able to wipe it for them.

 

I've always sold it to them that if they get p*ssed on a night out and lose their phone all they have to do is log into the Office365 portal or Email me and I can erase their phone for them, their data is secure, the schools data is secure everyone is happy.

Edited by Oaktech
  • Thanks 1
Posted
These days can't you just erase the work data without erasing the phone?

 

Yeah, you can, selective wipe is totally a thing, but the staff are unlikely to give a rat's ass about a scenario where this is important. We're selling the benefit of MDM to them so we get the benefit to the organisation as a happy little side effect.

Posted

I do think this is a whole area (See Cyber Essentials post about BYOD) where management need to make it clear what is allowed and if necessary use technical controls.

 

Rather than you can access organisational data on any device.

Either you can with MDM/MAM controls or you don't have access.

 

Equally there is the mental health, work/home life balance to strike. Worrying about issue x while reading work emails isn't helpful.

 

If your expected to be on call then a organisational device should be issued.

Posted
Yeah, you can, selective wipe is totally a thing, but the staff are unlikely to give a rat's ass about a scenario where this is important. We're selling the benefit of MDM to them so we get the benefit to the organisation as a happy little side effect.

 

Except that this is against the Data Protection Principles. You don't *have* to wipe everything that is not related to your organisation. You have no lawful basis for doing anything with data that is not yours. There are way too many scenarios to go into here, but wiping everything is just wrong.

 

As a general message to all on this thread, if you are looking at management of personal devices / BYOD, please make sure the school is covering your backside and doing a DPIA on it. You need to make sure that anything you do to mitigate/lower the risks are recorded and signed off. Then also make sure that it is unbelievably clear to staff what happens during a selective wipe process. Also remind staff about backing up personal devices, how they can remote wipe it themselves, etc.

  • Thanks 1
Posted
I think the idea was: when you lose your phone, we can wipe it for you if you ask us. Rather than: if you lose your phone, we will wipe it.
  • Thanks 1
Posted
Thanks for this but this still doesn't seem to do what the head wants for iOS, android does as you can force a user to authenticate work profiles app using MDM.

iOS just makes sure their main PIN is good I guess, or I'm I missing something?

Having a pin is must have whether the phone is school or personally owned.

 

But just a pin for security is not true for iOS, using Jamf Pro and account driven User Enrolment you can manage users own devices but only those enterprise/ school based apps and resources you give them access to, you force users to authtenticate on any variety of apps or their main work profile. It's effectively a single device but with 2 profiles, an enterprise MDM profile and a personal profile.

 

At all times user data and business data is separate and protected.

When a user leaves Jamf can wipe all the apps and data used in the school leaving the users own data intact.

 

https://www.jamf.com/blog/user-enrollment-service-discovery/

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...