Jump to content

Recommended Posts

Posted
But what does it achieve apart from encouraging pupils not to log off properly, but to leave the PC and walk out of the room?

 

We are supposed to be teaching children good security practices but at the same time not giving them the tools to do so?

  • Like 1
Posted

We do not allow students to lock computers, but restart/shutdown is then available on the login screen.

 

Depending on your environment, switch user could cause performance issues over time in ever decreasing resources.

 

Our acceptable use policy is clear to students that they are responsible for their own logins and should log out when the PC is not in use.

Posted
We allow students to lock their PCs, we also advise them to do so if they get up to go to the MFDs for printouts. No issues for us. We have some pretty ancient PCs and they handle account switching ok.
  • 3 years later...
Posted

Sorry to bring up an old topic...

 

We currently allow fast user switching and locking screens, however apparently this affects authentication with IDex in Smoothwall.

 

Is anyone in a similar position, or was, and can share some tips please? Do you disallow lock screens because of this or have you got a workaround?

Posted

We've disabled switch user for multiple reasons, one of them was that the agent installed for identifying the logged in user so setting their filtering accordingly would get confused as to who is using the web if multiple people were logged in. We received push back when we first disabled switch user, just like when we blocked USB sticks, but a few months down the line everyone has stopped complaining and realised they can actually still do their job, just like when we blocked USB sticks.

 

We allow, and encourage, the locking of screens.

  • Like 1
Posted

I'd also suggest nightly shutdown tasks for the PCs then using WoL to start them up again the next day, this will clear any logged in users and also help prevent any lockouts due to password resets.

 

You will have to cater/deal with any filtering that uses IP address mapping to get user IDs.

 

 

  • Like 1
Posted

Yeah fast user switching shouldn't be a thing for students IMO - no real need for it. Locking actively encouraged for obvious reasons, but no issues with locking and IDEX here. I would expect fast user switching still has a paddy.

  • Like 1
Posted
17 minutes ago, ITGuyNW said:

Sorry to bring up an old topic...

 

We currently allow fast user switching and locking screens, however apparently this affects authentication with IDex in Smoothwall.

 

Is anyone in a similar position, or was, and can share some tips please? Do you disallow lock screens because of this or have you got a workaround?

We had this, for the reason you mention - disabled fast user switching to force log off and log in events to be recorded on the DCs event logs and I assume reported to the smoothwall via IDex and it solved the problem from our testing. Not sure if there are alternate options or settings that can be tweaked in the Smoothwall, but it seemed logical to why this was happening with user switching in place and why the problem disappears when removed, so we went with removal!

  • Like 2
Posted
13 minutes ago, synaesthesia said:

Yeah fast user switching shouldn't be a thing for students IMO - no real need for it. Locking actively encouraged for obvious reasons, but no issues with locking and IDEX here. I would expect fast user switching still has a paddy.

How do you handle locking screens and logging off the student when its been done at the end of a lesson and they walk away?

 

I've been testing using the Lithnet tool to force a log off after some activity.

Posted

Idle timeouts in Impero - if they're sat for over 10 minutes they log out - plus classroom control (naive but hopeful!) and teachers have impero too and are asked to double check.

Not perfect but the same goes for staff, and usually kids get the idea when others start messing around with their files.

  • Like 2
Posted

We had fast user switching disabled for a good long while, as it interfered with our Internet filtering. Users can, and were encouraged to, lock their workstations, but this left us with the only way you could change users was by restarting a logged on user.

 

When we upgraded the filtering to something that could cope with it, I re-enabled fast user switching. It was the single most popular thing I did that term for our SLT, who desk swap all the time 😂 

 

The difference with us is that our Windows network is almost exclusively staff, and we mitigate the fast user switching by having a forced shutdown at the end of the day. Students are all on Chromebooks.

Posted
1 minute ago, ITGuyNW said:

Who did you go with for filtering?

 

We're using the LGfL SchoolProtect filtering, it's their implementation of Netsweeper.

 

It used to use a login script to set the filtering group, which was no good if people were changing users without logging in or out fully. Now it uses a workstation agent which is clever enough to register when users are switching. 

  • Like 1
Posted

I've had some wild arguments about fast user switching.
We allow students to lock their screens, but we don't allow fast user switching for all the various reasons already stated here.
"But someone locked their computer and walked away" was my favourite. They were horrified when I said "Well, log them out then" as they feared the student losing their work. I pointed out that everything we do should autosave, and if it doesn't the child gets to learn an important life lesson. 🤣

  • Like 2
Posted (edited)
51 minutes ago, paulkerton said:

I've had some wild arguments about fast user switching.
We allow students to lock their screens, but we don't allow fast user switching for all the various reasons already stated here.
"But someone locked their computer and walked away" was my favourite. They were horrified when I said "Well, log them out then" as they feared the student losing their work. I pointed out that everything we do should autosave, and if it doesn't the child gets to learn an important life lesson. 🤣

Saving regularly should be ingrained to students. I once went to a student who had been working on an Adobe project and had not saved at all for 3 hours then it refused. I did manage to create a new project and copy over the stuff for her then save, teacher jus sat there next to student. I had this argument with another teacher once who kept telling students to save often because IT could not be trusted till I pointed out a power failure and the work is lost would of been a better statement.

Edited by Davit2005
Posted (edited)

Not allowing locked computers is (imo) *crazy* - But then I have locking my computer ingrained in me from the IT tech back when I was at school, who would troll students who left their machines unlocked.

 

Fast user switching is fine, just force shutdowns at the end of the day.

Edited by DrCheese
  • Like 3
Posted
21 hours ago, paulkerton said:

I've had some wild arguments about fast user switching.
We allow students to lock their screens, but we don't allow fast user switching for all the various reasons already stated here.
"But someone locked their computer and walked away" was my favourite. They were horrified when I said "Well, log them out then" as they feared the student losing their work. I pointed out that everything we do should autosave, and if it doesn't the child gets to learn an important life lesson. 🤣

How do they log them out? When I looked into this briefly yesterday, they had no option to log out on the lock screen.

Posted

We don't allow user switching on our student machines as it messes with Senso a bit. Students can lock their machine.

 

Staff we do allow user switching

Posted
1 hour ago, ITGuyNW said:

How do they log them out? When I looked into this briefly yesterday, they had no option to log out on the lock screen.


There is a restart the device option I believe? Then it says that the user is still logged in etc, and they use that.
It's been a while since it was configured tbh, and I don't use Windows day-to-day.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...