Aldmi Posted March 25, 2022 Posted March 25, 2022 We are an 'iPad' school so every student as an iPad. The infant/Junior school have school bought iPads which are locked down through a device management software. The senior school and sixth for is BYOD so we don't have any control over them. We've always had a the usual problem with VPNs and block them through the firewall as best we can. However over the last month or so, more and more students are been caught using their mobiles to hotspot and therefore completely bypassing the firewall. At a recent parents forum there was a very mixed response, with some parents blaming parents for allowing their children to use the data on their phones and others who are the more vocal blaming the school and more specifically the IT department! I've explained to our management that from a technical point of view, there isn't much we can do to stop this. And emphasized that it is more a case of educating the students on why we have systems in place and also harsher punishment's if they are caught. All students sign an IT policy saying they won't use VPNs or hotspot. The sanctions are: 1st - Told to not do it again 2nd Offence - Lunch time detention 3rd offence - after school detention 4th offence - Letter to parents 5th offence - 1 day internal suspension I'm just wondering if anyone else has this issue and what your school do? We are a independent/private school so have a 'unique' set of parents should we say who have very strong views on what the school should be doing and what they pay for 2
Andycat Posted March 25, 2022 Posted March 25, 2022 We've had iPads for 8 years now. Always been an issue. It's a behaviour, not IT, issue. But we know where it ends up.... Equally, VPN's are an issue. We try and block them in Smoothwall, then get tutted at when the NHS or Council appear needing theirs to work.... 2
haci Posted March 25, 2022 Posted March 25, 2022 We are an 'iPad' school so every student as an iPad. The infant/Junior school have school bought iPads which are locked down through a device management software. The senior school and sixth for is BYOD so we don't have any control over them. We've always had a the usual problem with VPNs and block them through the firewall as best we can. However over the last month or so, more and more students are been caught using their mobiles to hotspot and therefore completely bypassing the firewall. At a recent parents forum there was a very mixed response, with some parents blaming parents for allowing their children to use the data on their phones and others who are the more vocal blaming the school and more specifically the IT department! I've explained to our management that from a technical point of view, there isn't much we can do to stop this. And emphasized that it is more a case of educating the students on why we have systems in place and also harsher punishment's if they are caught. All students sign an IT policy saying they won't use VPNs or hotspot. The sanctions are: 1st - Told to not do it again 2nd Offence - Lunch time detention 3rd offence - after school detention 4th offence - Letter to parents 5th offence - 1 day internal suspension I'm just wondering if anyone else has this issue and what your school do? We are a independent/private school so have a 'unique' set of parents should we say who have very strong views on what the school should be doing and what they pay for Ipads not really my area of knowledge but can you not lock them to a specific SSID via MDM? Fully expecting that you can't do this, because.... Apple. if parents and student cannot accept responsibility for deliberately bypassing the protections put in place, the only route forwards imo is to change the devices to something that can be controlled. 2
ITGuyNW Posted March 25, 2022 Posted March 25, 2022 From what I've seen in Meraki, you can specify it to always connect to a certain SSID, but it doesn't tie them down to one so you can easily pick and choose a different Wifi connection. Last time I checked, if you tried anything like hiding Settings app etc, it throws a wobbler.
kidpressingbuttons Posted March 25, 2022 Posted March 25, 2022 Could you not manage these devices in an mdm as a shared device then set a scheduled profile for wifi settings? Just checked and this is possible with Mosyle. So you could lock the wifi to school only from 8-5 then allow them to use their own connections when at home 1
Boredguy Posted March 25, 2022 Posted March 25, 2022 Could you not manage these devices in an mdm as a shared device then set a scheduled profile for wifi settings? Just checked and this is possible with Mosyle. So you could lock the wifi to school only from 8-5 then allow them to use their own connections when at home Just would have to remember to update restrictions for holidays etc using this method, but depends if the BYOD devices can be added to it since it's not the schools property so you can't force users to install the MDM 1
dmj Posted March 25, 2022 Posted March 25, 2022 Some WiFi systems (Meru , cisco do) have a function to block rogue wifi - it's usually to prevent devices connecting to the same SSID as your own. IIRC it works by sending disconnect packets to the device. We used it for a while, but it's a bit dangerous if your wifi extends beyond the site as you can end up preventing all your neighbours from using WiFi (that happened!)
Aldmi Posted March 25, 2022 Author Posted March 25, 2022 We have the added complication of overseas boarders whose parents see no issue in VPNs as they are the norm. We have previously looked at putting them on the MDM as a shared device and also pushing out a certificate from the firewall. However parents refused both of these requests, ranging from their daughters could be trusted, it was their own device and didn't want them connected to the school, to even that they didn't want the school 'spying' on their daughters then when they were at home
dmj Posted March 25, 2022 Posted March 25, 2022 We have the added complication of overseas boarders whose parents see no issue in VPNs as they are the norm. We have previously looked at putting them on the MDM as a shared device and also pushing out a certificate from the firewall. However parents refused both of these requests, ranging from their daughters could be trusted, it was their own device and didn't want them connected to the school, to even that they didn't want the school 'spying' on their daughters then when they were at home You're between a rock and a hard place. I think you're just going to have to write up all the options and let the school set a policy. 1
Brimstone Posted March 25, 2022 Posted March 25, 2022 Enforce management of any devices coming into school whether personally owned or not, using an MDM you can lock the device to a single SSID, however temporary or "timed" profiles do not work very well, my best suggestion is.... Don't run a BYOD program. 1
jmak Posted March 25, 2022 Posted March 25, 2022 Pretty sure if I owned an iPad and someone wanted to install an MDM on it I'd tell them where to go. I also think that in lessons they shouldn't be connecting them to personal hotspots - but that's classroom management. 3
Koldov Posted March 25, 2022 Posted March 25, 2022 Can you take their phone from them during the school day?
colly72 Posted March 25, 2022 Posted March 25, 2022 For me, this is a classroom management/acceptable use policy issue, as much as a technical one. I work in the independent sector too and although some parents can be demanding at times, we set clear expectations of how students use technology within school, so all parties are aware and have signed up to the agreed code of conduct. If the students use technology in a way that falls outside what they and their parents signed up to, they really have nowhere to go with any push back on to the school. We use web filtering, safeguarding and monitoring tools extensively wherever we can to protect and control but ultimately I believe it's a fundamentally a policy awareness/communication/enforcement exercise. 1
Ratcliffepg Posted March 25, 2022 Posted March 25, 2022 So they allow all senior school students to have a mobile phone in school with them......
Aldmi Posted March 28, 2022 Author Posted March 28, 2022 So they allow all senior school students to have a mobile phone in school with them...... Mobile phones are banned under the school policy, but what they do is just keep it in their bags so they can hotspot The next plan is to have them collected at the start of they day, but I'm staying well clear of getting involved in that 1
MatthewL Posted March 28, 2022 Posted March 28, 2022 We've had iPads for 8 years now. Always been an issue. It's a behaviour, not IT, issue. But we know where it ends up.... Equally, VPN's are an issue. We try and block them in Smoothwall, then get tutted at when the NHS or Council appear needing theirs to work.... You can block VPN but if there are regular ones i.e. Council & NHS that are needed but an exception in to allow access to that IP rather than allowing to all VPN's.
RLR Posted March 28, 2022 Posted March 28, 2022 Our schools iPads have a PAC file installed on them via our MDM which forces them to sign into our firewall to be filtered when not on our network. This means they get filtered where ever they go.
2ilent8cho Posted March 29, 2022 Posted March 29, 2022 Apple provide the option to specify 3rd party filters that then apply on the device not the firewall, so the content is filtered onsite or hotspotted. We use Lightspeed as they provide a Plug-in for iOS for this. You configure it under a Configuration Profile -> Content Filter and specify the Filter Type as Plug-in along with the settings provided by the filtering product maker. See if your existing filtering product supports this.
paulkerton Posted March 29, 2022 Posted March 29, 2022 Device level client for filtering on top of your network level one, surely?
jmak Posted March 29, 2022 Posted March 29, 2022 Thread's getting quite long now, so just a reminder that these are student owned devices. Lots of options for preventing use of VPN/locking to specified networks if they're school owned - not so much for devices the school doesn't own.
paulkerton Posted March 29, 2022 Posted March 29, 2022 so just a reminder that these are student owned devices. There are plenty of ways to manage BYOD. However, if BYOD is a problem a simple solution is not to allow BYOD. 1
Boredguy Posted March 29, 2022 Posted March 29, 2022 There are plenty of ways to manage BYOD. However, if BYOD is a problem a simple solution is not to allow BYOD. the OP stated they are an a independent/private school so not allowing BYOD might not be an option the same as it would be some of us
paulkerton Posted March 29, 2022 Posted March 29, 2022 the OP stated they are an a independent/private school so not allowing BYOD might not be an option the same as it would be some of us You can still put policies in place and standards of expectation, even if you're fee paying. After all, if someone misses a payment I'm sure the red headed letter isn't slow to appear! If have groups of parents who are diametrically opposed to each other, you can't please them all or have free-for-all either, can you? So you need to have some kinds of policies in place. Is there a behaviour free-for-all too?
free780 Posted March 29, 2022 Posted March 29, 2022 I actually heard someone from Smoothwall say. Eventually every young person will have to decide if they click that link or not. They can’t be filtered for their whole life. If students have mobile phones they should be treated like an employee with a phone. You should not be on it all the time. I believe it’s a policy control rather than a technical control here. There is also the role of parents to know what children are accessing. 2
Guest Guest Posted March 29, 2022 Posted March 29, 2022 (edited) I previously came from an independent day school and Students having mobile phones in their possession at all was a firm 'no'. However, Laptops were permitted and connected to the main school WiFi (no proper BYOD network back then). They installed the Smoothwall certificate and the filtering worked as if it was a 'normal' device on the Domain (every user bar Admins had the same filtering profile applied anyway) Ultimately, installing anything school related (e.g MDM) on a personal (i.e staff/student-owned) device would be a firm no from me; and if I was a Student/Parent I'd tell the school to "foxtrot oscar" if it was being deemed mandatory. If it's their device, they can do what they want on it providing the actions are sanctioned under the school's own policies. Heck, installing the Smoothwall certificate back then (and probably even now) does occasionally cause the less-technically minded people to wonder "what are you doing on my device" (aka "are you installing something "dodgy"?). IT can only be policed/locked down to a point and it'll always be a game of cat & mouse. I agree with many others that this is a behaviour policy/issue here rather than an IT one. Edited March 29, 2022 by Guest
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now