Jump to content

Recommended Posts

Posted

Hi All,

 

I was wondering if anyone has fully migrated their schools to Google....? I work in a large primary school with a very "hybrid" set up. The students use Chromebooks, and some of the staff/teachers do to. However, there is still an on-prem DC (that is tired) managing a few windows laptops hosting services such, Active Directory, DNS, DHCP, Printing, and file shares too.

 

My thoughts are to do the following...

 

- Deploy the google drive client on remaining windows devices to sync users files to the workspace

 

- Use papercut mobility print for printing services

 

- Host DNS, and DHCP on firewall.

 

- Use something like Synology Active Backup for workspace, pointing to a NAS off/on site.

 

- They already use Arbor for their MIS so no issues there.

- Invest in a redundant FTTC/5G connection in the event of a main line issue.

 

- Senso.Cloud for safeguarding monitoring, and possibly Securly for extra filtering.

- Licensing is perpetual, so would be looking at roughly £30 per device

 

- Training provided to staff/students on how to use the Google Workspace apps

 

Please let me know if I have missed anything, as I am sure I have!

 

I am more interested to see if any schools have actually succeeded in migrating fully to Google? How have staff found it? Has there been any software issues? is it even possible? haha!

  • Thanks 2
Posted

A Server will still be needed for Papercut?

 

Could you mix firewall and filtering to cover on site protection?

 

How do you create your users? If you are using anything like Salamander or Locker you will need a server for that.

 

Those are the first things that pop to mind.

Posted

Hi, thanks for your reply!

 

- Yes, a server will still be needed for Papercut forgot to mention that! I suppose it could be hosted on a desktop or I could look into a different printing method such as IPP or similar.

 

- Users could either be created by myself, or by using something like salamander to link to Arbor (as you mentioned)

 

- Yes, I could mix firewall with filtering. They use RMSafetynet at the moment. So I could set up an IP range for staff and student devices and apply the policies accordingly to each range (staff/student). Or I could assign a policy to the whole IP range and enable the staff proxy for staff to access certain sites etc.

Posted (edited)
Hi All,

 

I was wondering if anyone has fully migrated their schools to Google....? I work in a large primary school with a very "hybrid" set up. The students use Chromebooks, and some of the staff/teachers do to. However, there is still an on-prem DC (that is tired) managing a few windows laptops hosting services such, Active Directory, DNS, DHCP, Printing, and file shares too.

 

My thoughts are to do the following...

 

- Deploy the google drive client on remaining windows devices to sync users files to the workspace

 

- Use papercut mobility print for printing services

 

- Host DNS, and DHCP on firewall.

 

- Use something like Synology Active Backup for workspace, pointing to a NAS off/on site.

 

- They already use Arbor for their MIS so no issues there.

- Invest in a redundant FTTC/5G connection in the event of a main line issue.

 

- Senso.Cloud for safeguarding monitoring, and possibly Securly for extra filtering.

- Licensing is perpetual, so would be looking at roughly £30 per device

 

- Training provided to staff/students on how to use the Google Workspace apps

 

Please let me know if I have missed anything, as I am sure I have!

 

I am more interested to see if any schools have actually succeeded in migrating fully to Google? How have staff found it? Has there been any software issues? is it even possible? haha!

In our trust we have a school in a similar situation. 55 kids and about 7 staff and their server is 9 years old.

 

Obviously they dont need a high end server these days but they are still running a couple of Server VMs.

 

Until we completely find a way to go cloud or until Google implement the Google Drive for Desktop as a seemless experience i'd say there is always going to be a need for a "server" of some description.

 

Do you allow users to store files on the local devices? If not where would they save them to and how would you manage the Windows Policies Centrally? Intune aka endpoint manager, isn't quite up to speed yet, well certainly not in my eyes.

 

You'd need to consider resilience on your internet lines too and firewall(s) and draw up a risk matrix and a "what happens if" and "how long can we live without x of y was to fail".

 

Now a days it's cheaper to get a FTTP installed and 5G is only going to be good enough for DR. We had a primary school use 4G and the connection was appauling! The throughput wasn't high enough for their teachers devicea let alone their student devices and this wasn't a particually a big school.

Edited by timbo343
  • Thanks 1
Posted (edited)

Hi thanks for your reply!

 

Well, I would be issuing a chromebook to every staff member. So there would be no need for Intune, or Azure etc (at the moment). I would just manage the devices and users from the G-suite console. Of course the only issue I see with me doing this, is.... Legacy software! such as the office suite. I suppose in the future I could always buy some staff licensing so they can access the apps in a browser such as word, excel etc.

 

And yes, resilience is definitely a key factor. It would need be planned correctly, and They would need to invest in a redundant line for sure.

Edited by HyperTech
Posted
Deploy the google drive client on remaining windows devices to sync users files to the workspace

 

Also the Google Credential Provider for Windows (GCPW):

 

https://support.google.com/a/answer/9250996?hl=en

 

Lets users log in to a Windows machine using their Google logins. You can do similar with the Mac, too, although that uses Google's LDAP service.

 

For a server to run Salamander or similar tasks, that can be off site if you want to avoid having hardware on site. You'd still need something local to run Papercut, though, and I'd want a local NAS of some kind to hold a just-in-case backup of Google Drive files - I understand Synology do a nice all-in-one solution that can back up a Google Workspace's worth of files.

  • Thanks 1
Posted

Hi, thanks for your reply!

 

Thanks for the link, that looks very interesting. Do you use this at the moment?

 

Yes, if they have available funds, I will definitely be looking at an on-site (NAS) and possibly a cloud back up. For papercut I could use the current server (but just for that) or invest in a cheap desktop to run it.

Posted

You could also consider Chrome OS Flex to make use of your existing desktop hardware.

 

There was also a mention of needing a local server for Locker or Salamander, but it looks as though Locker does offer a cloud-based option.

Posted (edited)

Hi @southhamster thanks for your reply.

 

Yes this seems to be the only thing holding them back at the moment. With everything moving to a web based service, I am sure they would manage, but I would want to confirm this with them first of course. As @dhicks mentioned earlier in the thread, I could use GCPW so the admin staff could sign into their windows devices with their google accounts, and I believe the device can then be managed through the console, but please correct me if I am wrong!

Edited by HyperTech
  • Thanks 1
Posted
Thanks for the link, that looks very interesting. Do you use this at the moment?

 

We got it working on a test (Windows 10) machine, yes - somewhere in my to-do list is an item to add the installation to our standard Windows 11 setup and see how it works with the current version of the Google Drive Client. On our test machine, we found we could redirect user folders to Google Drive folders, but only after the drive client had loaded, which loaded after Windows Explorer (the main user interface for Windows). Ideally, we want the Drive client to load first, then handle folder redirects before presenting folders to the user, so as far as the user is concerned their dekstop folder just appears and automatically appears on Google Drive as well.

 

Costs: for an off-site hosted Windows server capable of running Salamander or other software: somewhere under £20 a month, probably a bit cheaper. If you want a local machine, we've found these to be good value for money (around £250):

 

https://www.amazon.co.uk/gp/product/B09PRH1R4J/ref=ppx_yo_dt_b_search_asin_title

 

Synology box to handle on-site backups of Google Drive: I think around £1,000, possibly with a cost for disks on top of that.

 

Offsite backup: we use Backblaze, £5 per TB per month.

Posted

Hi @dhick,

 

wow, it seems that you have the exact set up that I should be running haha! I have had a look over GCPW and looks really good. I think I am going to need to test this out. So do you not have an on-premise AD?

 

In a sense, this basically seems like Google's version of Intune/Azure. Do find that the included restrictions for endpoints are more than enough? and also, what plan do you have? I currently have education fundamentals...

Posted
Hi All,

 

I was wondering if anyone has fully migrated their schools to Google....? I work in a large primary school with a very "hybrid" set up. The students use Chromebooks, and some of the staff/teachers do to. However, there is still an on-prem DC (that is tired) managing a few windows laptops hosting services such, Active Directory, DNS, DHCP, Printing, and file shares too.

 

My thoughts are to do the following...

 

- Deploy the google drive client on remaining windows devices to sync users files to the workspace

 

- Use papercut mobility print for printing services

 

- Host DNS, and DHCP on firewall.

 

- Use something like Synology Active Backup for workspace, pointing to a NAS off/on site.

 

- They already use Arbor for their MIS so no issues there.

- Invest in a redundant FTTC/5G connection in the event of a main line issue.

 

- Senso.Cloud for safeguarding monitoring, and possibly Securly for extra filtering.

- Licensing is perpetual, so would be looking at roughly £30 per device

 

- Training provided to staff/students on how to use the Google Workspace apps

 

Please let me know if I have missed anything, as I am sure I have!

 

I am more interested to see if any schools have actually succeeded in migrating fully to Google? How have staff found it? Has there been any software issues? is it even possible? haha!

 

You could look into Printix for your print solution?

Posted
So do you not have an on-premise AD?

 

We do at the moment, the process has been slow. Hopefully, we should have staff moved over to Google Drive by summer half-term, then we can turn the local file server off, then we have to roll out the GCPW for Windows workstations - we might do that alongside a roll out of new hardware as some of our classroom machine are a bit old now.

 

Do find that the included restrictions for endpoints are more than enough? and also, what plan do you have?

 

I think we have Google Workspace for Education Plus. We haven't got many Windows devices managed via Google yet. We're using Action1, a separate package, to handle management of Windows updates and software installations - we're finding that to work very well, and for under 100 endpoints it's free.

Posted
We do at the moment, the process has been slow. Hopefully, we should have staff moved over to Google Drive by summer half-term, then we can turn the local file server off, then we have to roll out the GCPW for Windows workstations - we might do that alongside a roll out of new hardware as some of our classroom machine are a bit old now.

 

 

 

I think we have Google Workspace for Education Plus. We haven't got many Windows devices managed via Google yet. We're using Action1, a separate package, to handle management of Windows updates and software installations - we're finding that to work very well, and for under 100 endpoints it's free.

 

Do you still setup the machines initallly? For example, do you use MDT or just hand it to the user fresh out of the box?

 

How are you handling Software installation and software updates? We currently have PDQ deploy/inventry which I don't think works if devices are not connected to the domain?

Posted
Do you still setup the machines initallly? For example, do you use MDT or just hand it to the user fresh out of the box?

 

We have one test machine using GCPW, most office / classroom workstations are still Windows domain machines. We currently deploy new machines by installing Windows from USB storage, adding to the domain, installing software, etc. My plan (that I'll hopefully get to work on over Easter) is to automate this process for our newly-deployed machines, probably via the unattend.xml mechanism on USB storage. I've used this previously, with Windows images delivered over the network and automatically being renamed and joining the domain, I just need to move that setup to local USB storage. Myplan is to possibly have a setup configuration picked up from Google Drive, but I'll see how I get on with that.

 

How are you handling Software installation and software updates?

 

We've just moved to Action1 - free for up to 100 endpoints. Handles Windows updates and software installs, with a nice web-based dashboard. Seems to work very well so far, I'm not sure of costs past 100 endpoints but I think it would be worth paying for if we needed to.

Posted

Hi @dhicks

 

I have tested out GCPW today and I have to say it's seems really promising. I signed in with my Google account and obviously still have access to the software already on my laptop (which is a bonus). I also had a play around with the policy settings and most of these worked, however, I couldn't seem to get custom settings (gpos) to work. I would set them up (block camera for example) and assign it to an OU but it wouldn't show in the console as applied, or even show at all! I'm not sure if this is due to a licensing issue perhaps?

 

But overall really good, I think if staff moved all of their data from the file server into Google drive and used this from now on, I could definitely remove the on-prem AD/file server in the future.

 

Then it's just handling printing, DNS, DHCP etc but definitely doable. Thanks for your help!

  • 1 month later...
Posted
Hi All,

 

I was wondering if anyone has fully migrated their schools to Google....? I work in a large primary school with a very "hybrid" set up. The students use Chromebooks, and some of the staff/teachers do to. However, there is still an on-prem DC (that is tired) managing a few windows laptops hosting services such, Active Directory, DNS, DHCP, Printing, and file shares too.

 

My thoughts are to do the following...

 

- Deploy the google drive client on remaining windows devices to sync users files to the workspace

 

- Use papercut mobility print for printing services

 

- Host DNS, and DHCP on firewall.

 

- Use something like Synology Active Backup for workspace, pointing to a NAS off/on site.

 

- They already use Arbor for their MIS so no issues there.

- Invest in a redundant FTTC/5G connection in the event of a main line issue.

 

- Senso.Cloud for safeguarding monitoring, and possibly Securly for extra filtering.

- Licensing is perpetual, so would be looking at roughly £30 per device

 

- Training provided to staff/students on how to use the Google Workspace apps

 

Please let me know if I have missed anything, as I am sure I have!

 

I am more interested to see if any schools have actually succeeded in migrating fully to Google? How have staff found it? Has there been any software issues? is it even possible? haha!

 

One of my schools has retired its old server. To get printing to work afterwards I had to install the printer driver on each of the teacher Windows laptops. The printer is a multifunction device so I also went into the settings and enabled AirPrint for Apple devices and Cloud Print for the Chromebooks. DNS and DHCP are provided by the router. SWGfL/RM provide SafetyNet filtering.

 

Andy

Posted
I have tested out GCPW today and I have to say it's seems really promising.

 

So: GCPW (I think) hands login tokens over to the user's instance of Chrome - great, you log in to Windows with your Google account, then when you start up Chrome you're already logged in. I'm trying ot set up the Windows Google Drive client so it's a nice and seemless experience for the user. What I think I've now got working is that the user logs in and, if Drive isn't confugred yet, it hands the user over to Chrome (which should already be logged in as the user) to allow Drive access.

 

Currently, the sticking point is that, on startup, Google Drive starts after Windows Explorer, so if you try and redirect a user's home / Desktop folders the user gets an error message pop up on screen. Therefore, I'm trying to write (what I originally thought was) a simple, small application that loads Google Drive, then starts up Windows Explorer.

 

The way Windows handles how explorer.exe starts up is proving to be a bit fiddly, so this has got a bit more compelx that I was hoping it would be, but I hope to have a solution sorted soon.

Posted

Hi @dhicks thanks for your response.

 

Yes, that was the only issue I found with it too. In my case the windows devices I will be moving to GCPW are basically 1:1 (Teacher laptops). So I believe they would only need to sign into the drive client once and it will then stay signed in for the user if they log out (please correct me if I'm wrong though)

 

I guess if I provided training to staff as well, they would understand the need to save to Google drive rather than locally... Hopefully haha!

 

Action1 also seems very good. I almost can't believe it is free... In my experience and recent testing though, I honestly believe windows devices could be managed via GCPW and Action1. Quick question, as I only have education fundamentals, if I enable GCPW for my domain, does it make every user that signs in that way a standard user or an administrator? I think the answer is standard user, but wanted to confirm.

Posted

The majority of Windows devices are managed using Google Advanced Desktop Security now - both primary and secondary - so 1000's of devices. Works well and keeps the management of devices in one place - along with ChromeOS. As others have said, this requires either Plus or Standard licences.

 

GCPW is the application that facilitates this and can be used without the device management and can be used alongside an AD setup as well.

 

If you are using GCPW without the backend management, make sure you set the registry key not to enrol the device otherwise it will bug you about the lack of a licence. Users would be signed in as a standard user. If you use the management you can set admin permissions by OU.

 

My Slides from my talk at Google about this - has links to many useful resources.

 

To answer one of the other points - we do make it quite explicit that files must be opened/saved from Google Drive and this along with other stuff comes as a little instruction insert with all devices. We also backup Google Workspace using AFI backup and show users how to do self service restores of mail/drive.

 

Any questions - let me know.

Posted

Hi @rogerdnixon thanks for your reply.

 

I think enhanced desktop security via Google will be the way to go...

 

Quick question, do you apply the windows device management settings (such as update settings, access level, bitlocker etc) to user OUs

groups, rather than device OUs?

 

So if you apply these settings to a user OU they will apply to any device the user from the targeted OU signs into?

 

Thanks... I hope the above makes sense.

Posted

The concept of users/device OUs does not exist like it does for ChromeOS. A device will pick up policies of the account you use to enrol the computer and then policies based on any additional policies that you apply to specific OUs. For primaries we just have an "enrol" account we use for setting up devices in the root of the schools OUs. For secondary typically a few in different OUs - mainly because different software is pushed to different devices. You can then set polices that apply to uses (e.g. default apps and start menu) on an OU basis.

 

We set the majority of policies at the root of the trust - so applocker etc so you only need to do it once.

 

Update settings/bitlocker we set at the root level as it generally the same across the Trust.

Posted

Hi @rogerdnixon

 

Brilliant, thanks for the explanation. So in simple terms you would set the main user settings such as updates, bitlocker, account type at the top level so the child OUs inherit them. Then you can be more granular with settings for other OUs such as the administrator user group who will need their user account permissions changing.

 

It's good to know that the settings are applied to the OU -> User -> Device that they sign into.

 

Thank you.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...