Jump to content

Is it feasible to lock a Google account to a single Chromebook device? Options???


Recommended Posts

Posted

Just had the following email from a primary school and would like options...

 

Is there any way that children can only access their school google account from the school chrome book? This is because today we discovered a child was able to access the school account from his home chromebook with inappropriate work.
Posted
Just had the following email from a primary school and would like options...

 

I think last time we checked this you can limit an OU to accept your domain accounts only, so you can stop anyone other than your pupils / staff logging in to Chromebooks. I think you could also set individuals to be allowed access, but again only at the OU level, so if you wanted a particular pupil to be limited to one specific Chromebook that Chromebook would need to be in a separate OU. That would be fiddly to maintain for a whole school (should be scriptable easily enough - create a sub-OU per pupil - but it's always a problem keeping such things up-to-date), but for a few specific pupils it should be quite do-able.

  • Thanks 1
Posted
I think you could also set individuals to be allowed access, but again only at the OU level, so if you wanted a particular pupil to be limited to one specific Chromebook

Ill have to do a hunt for that feature as I have never seen it.

 

Also, they don't take the chromebooks home with them, so this pupil would no longer be able to do any homework etc.

Posted
Also, they don't take the chromebooks home with them, so this pupil would no longer be able to do any homework etc.

 

You're looking for the setting in the OU your Chromebooks are assigned to, not users - your users should be able to log on to any (non-school) device (Chromebook or browser).

Posted (edited)
I think last time we checked this you can limit an OU to accept your domain accounts only, so you can stop anyone other than your pupils / staff logging in to Chromebooks. I think you could also set individuals to be allowed access, but again only at the OU level, so if you wanted a particular pupil to be limited to one specific Chromebook that Chromebook would need to be in a separate OU. That would be fiddly to maintain for a whole school (should be scriptable easily enough - create a sub-OU per pupil - but it's always a problem keeping such things up-to-date), but for a few specific pupils it should be quite do-able.

 

That wouldn't solve the issue would it? The child is logging in at home on their personal device.

 

 

One way would be to use your identity provider (if it has that facility). For example in ADFS and Azure Conditional Access you could limit logins for a particular OS to be only allowed in a particular IP range. We did this when I was in education for younger children so that weak passwords wouldn't be vulnerable to external logins.

Edited by FN-GM
  • Thanks 1
Posted

So instead of being able to identify the issue because they've used a school account, you'd prefer to push them to a Google account that isn't monitored so that it isn't the school's problem?

I don't think this has been thought through properly.

  • Thanks 1
Posted
So instead of being able to identify the issue because they've used a school account, you'd prefer to push them to a Google account that isn't monitored so that it isn't the school's problem?I don't think this has been thought through properly.

 

No, I am still waiting to findout what actually happened, so in the meantime I am getting all my options together ready. It's my belief that they will not need to lock the account down, but if I am instructed to do this, this is what I will do.

Posted
I have a similar issue, in that a student's work is (probably) being deleted by another student. It would be extremely useful to be able to restrict a students login to one particular device if possible.
Posted
I have a similar issue, in that a student's work is (probably) being deleted by another student. It would be extremely useful to be able to restrict a students login to one particular device if possible.

 

Surely this one requires password change?

  • Thanks 2
Posted
I have a similar issue, in that a student's work is (probably) being deleted by another student. It would be extremely useful to be able to restrict a students login to one particular device if possible.

This is one of two things:

  • Student repeatedly fails to log out
  • Student keeps telling other student their password

  • Thanks 2
Posted
This is one of two things:

  • Student repeatedly fails to log out
  • Student keeps telling other student their password

 

Sadly you are probably right. We've changed the password twice, and the student insists that they haven't told anyone. We have a 1:1 device scheme, but it's possible they leave their Chromebook unattended long enough for work to be deleted. Because it's ClassNotebooks and whole sections are being deleted, there is no way to back up the work either.

 

I think I'm at risk of derailing this thread, so I'll leave it there!

Posted
I think I'm at risk of derailing this thread, so I'll leave it there!

no problem at all, and our issue might also turn out to be similar to your issue.

 

So, just found out what the actually issue is. Back in December when a pupil was off sick a Google doc was created with a couple of unwanted words. The pupil said they didn't create the document.

Options are....

Someone else has their password

Someone else opened the lid on the pupils Chromebook (we are 1-2-1) and it was already logged in, although I think I have it set to 'logout on lid close' - will double check.

The pupil did create this file while at home.

 

I have looked at the doc in audit and the IP listed is for SKY broadband, so it does look like it was created from a home system. Looking at the time it was created it was just after school started, which eliminates anyone in school that day.

If I had to guess, the pupil probably created the doc while at home.

Posted

You can set a school-owned Chromebook to only accept logins from an individual account, but I don't think this is what the OP is asking for. You'd probably also want to avoid that for a device that's being taken home anyway, since it's likely to encourage account sharing at home when another member of the household wants to use the device.

 

In terms of preventing an account from signing into anything other than a school-owned device, you may be able to do that using Context Aware Access (Admin > Security > Access and data control > Context Aware Access). Not something I've played with, and I don't know if it requires a certain tier of Google Workspace and MDM level (probably), but that's where you can create an access level rule specifying that the device must be a company owned device.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...