Jump to content

Recommended Posts

Posted (edited)

Hi all,

Just after some advice, we have a wireless network configured at user level for BYOD devices what I would like to do is block this wireless network for a certain OU

 

Using the global network config i have added the SSID to the blocked SSID list and can see this being applied at device level to the chromebook, unfortunatley (I believe due to policy overrides) the user policy for the network is applied and the SSID can be connected to on a device in the OU where the blocked SSID is being applied.

 

https://support.google.com/chrome/a/answer/9037717?hl=en details the order of policy settings being applied.

 

I can see on the chromebook the policy for the blocked ssid is set as "Source = Cloud, Applies to = Device, Level = Mandatory"

 

When the settings are exported as a JSON and viewed I can also see the user level network being applied as well.

Source = Cloud, Applies to = User, Level = Mandatory.

 

My order of policy application is set as default (which is Machine > machine cloud > OS user > Chrome profile)

 

How can I make my device level SSID blocking over ride the user setting?

From my understanding anything set at device level shouldn't be overwritten by the user policies?

 

Just for testing purposes I added my mobile hotspot SSID to the blocked list and that worked but this was not a managed network set at user level.

 

Any help would be appreciated.

 

Thanks

 

 

Edit: Ive now tested my SSID connecting from the login screen where no user policies are being applied so only device level setting should be set at this level, it still lets me connect to the blacklisted SSID even though its no longer a "Managed" network, the blocking of SSID is done via string to Hex and ive reversed the hex i can see in the JSON and it converts back to the correct SSID.

Oddly even though blocked SSID setting is device only it only applies once a user is logged in, my hotspot only gets blocked when a user logs in, my needed blocked SSID still does not get blocked.

Edited by pfl
Posted

When I navigate to Admin > Devices > Networks > [some OU] > General settings, the set of options there includes the "Blocked WiFi networks" option which I think you're trying to make use of. However, at the head of that page it reads Showing settings for users in [OU name], so I suspect that those options aren't actually applicable to devices, only to users.

 

That doesn't quite tally with what you're seeing in chrome://policy on your devices, though.

Posted (edited)
When I navigate to Admin > Devices > Networks > [some OU] > General settings, the set of options there includes the "Blocked WiFi networks" option which I think you're trying to make use of. However, at the head of that page it reads Showing settings for users in [OU name], so I suspect that those options aren't actually applicable to devices, only to users.

 

That doesn't quite tally with what you're seeing in chrome://policy on your devices, though.

 

 

Thats what i thought BUT the blocked ssid setting has a header "General settings (Chromebook only)"

which to me indicates device settings?

Edit: Maybe i jumped the gun in thinking this was device only , especially with chromebook only being specified, it might just mean Chromebook "User" setting only.

Edited by pfl
Posted (edited)

@jthompson

 

Even stranger

This bug post (The last post)

https://bugs.chromium.org/p/chromium/issues/detail?id=837205

 

"2) user vs device -> all network settings you can modify on the Networks page under "General settings (Chromebook only)" are per-device, including the new block list for wifis. They are part of the GlobalNetworkConfiguration type (https://chromium.googlesource.com/chromium/src/+/main/components/onc/docs/onc_spec.md#globalnetworkconfiguration-type if you want to read the details), which is present for the device policy only. You can not specify that list as per-user restriction. You should set these values on OUs that contain devices."

Indicates that yet again this is a device setting

 

EDIT: updated bug url

https://issuetracker.google.com/issues/256513725

 

Also displays the block SSID setting is device level although the posts above do show it as being applied at user level only

 

 

Wish i didn't even start looking at this now! ;)

 

https://chromium.googlesource.com/chromium/src/+/main/components/onc/docs/onc_spec.md#globalnetworkconfiguration-type

 

GlobalNetworkConfiguration type

 

The GlobalNetworkConfiguration contains settings which apply to all of the networks that the device may connect to. The client supports this only in device-level policy; the client-side ONC validator fails if it appears in user policy. To avoid bricking devices, these policies will only be enforced in user sessions. The login screen ignores these policies and may still be used for fetching new policy or logging in. A Help Center article warns admins of the implications of mis-using this policy for Chrome OS.

 

 

 

So if the above is correct my understanding is , Yes its device level settings BUT only enforced in a user based session (surely this is classed as "User Policy"?)

 

My question is... why does my black listed SSID still allow connection due to it being allowed at user policy level.

 

 

What i thought was a simple solution to a problem we had is now causing me a headache!

 

All i want to do is block an SSID for an OU :D!

 

(im actually considering collating a list of mac addresses and creating a deny ACL on our SSID - might cause me less stress then these gsuite policies!)

Edited by pfl
Posted

If the Chromebooks don't go offsite, then just set them to connect to managed networks only - so use the WiFi network policy setting "Restrict users to connecting only to the Wi-Fi networks configured for this organisational unit" - then set to "restrict". Apply your SSID you want the devices to connect to Devices - not users. Then the devices will just connect to the SSID you want them to connect to and nothing else. If they go home - so staff,1:1 device change the policy to "Restrict users to connecting only to the Wi-Fi networks configured for this organisational unit". This stops people using WiFi hotspots onsite - but allows them to use the device offsite.

 

I basically never deploy WiFi to users as I've never really come across a use case for that really.

 

I've never needed to use the policy to block a network as we restrict them to the networks we deploy to them.

 

Thats as complicated I've ever had to do and we have 11000 devices - just works.

Posted (edited)
If the Chromebooks don't go offsite, then just set them to connect to managed networks only - so use the WiFi network policy setting "Restrict users to connecting only to the Wi-Fi networks configured for this organisational unit" - then set to "restrict". Apply your SSID you want the devices to connect to Devices - not users. Then the devices will just connect to the SSID you want them to connect to and nothing else. If they go home - so staff,1:1 device change the policy to "Restrict users to connecting only to the Wi-Fi networks configured for this organisational unit". This stops people using WiFi hotspots onsite - but allows them to use the device offsite.

 

I basically never deploy WiFi to users as I've never really come across a use case for that really.

 

I've never needed to use the policy to block a network as we restrict them to the networks we deploy to them.

 

Thats as complicated I've ever had to do and we have 11000 devices - just works.

 

 

Unfortunatley the above doesn't work for us, Students here are assigned a chromebook and utilise on-site and off-site filtering which is provided by an extension.

For this extension to work our web filter / proxy has a separate network to allow this extension to work and to also segregate the traffic from our internal traffic.

 

Chromebooks are usually given a managed network at device level but the student with assigned chromebooks also need this other ssid so their assigned chromebooks filter correctly, trouble is these students have the tendancy to not bring their devices in so end up using classroom devices which means the user assigned managed network profile follows them on to these class devices, no matter what form of ssid blocking I use at device level the user based cloud policy always overrides this.

If there was a setting for changing conenction priority or if the setting for ssid bloacking was set at device level and enforced at device level (instead of user session based) this would solve the above issue.

Thanks

Edited by pfl

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...