LuciferMorningstar Posted November 6, 2023 Posted November 6, 2023 Hi all, We are looking into the best options for remote access for staff, we are a bit behind the times in some ways. How do you (or don't you) provide remote access for teachers/staff from the comfort of their homes? and what can they access? Ideally the staff here want access to Sims, MS office, home directory and a few other applications. Thanks
DalekSec Posted November 6, 2023 Posted November 6, 2023 How's your setup? Desktop, laptops etc cloud or on-site? E.g our staff can access all of those without need for Remote access as all our files are on Sharepoint and OneDrive. They all have company issued Laptops also. Only thing they need to VPN on for is a DB that only a handful need access to 1
simpsonj Posted November 6, 2023 Posted November 6, 2023 What firewall do you use? The Palo Alto and Smoothwall firewalls I've used have VPN software that is relatively straight forward to deploy.
mavhc Posted November 6, 2023 Posted November 6, 2023 Hi all, We are looking into the best options for remote access for staff, we are a bit behind the times in some ways. How do you (or don't you) provide remote access for teachers/staff from the comfort of their homes? and what can they access? Ideally the staff here want access to Sims, MS office, home directory and a few other applications. Thanks Using their home computers, or school issued laptops?
LuciferMorningstar Posted November 6, 2023 Author Posted November 6, 2023 We are onsite physical servers, desktop computers. Staff do have a mix of Chromebooks and Windows laptops (school owned), these were mainly used for remote learning via GC. We use currently use Smoothwall.
mrbios Posted November 6, 2023 Posted November 6, 2023 A lot of variables depending on your setup as above. Personally we have the following options which all work really well: Always on VPN for school staff devices that go home Foldr - Web based access to on site and cloud storage in one UI, this is setup behind Cloudflare tunnel (previously had it behind application proxy, but it breaks some functionality that way) HTML5 RDP access - For any staff who don't have a school laptop on AoVPN, or as a fallback. Primarily used for accessing SIMS, and is behind Microsoft application proxy, requiring 2FA. 2
mavhc Posted November 6, 2023 Posted November 6, 2023 I suggest moving files to google drive, which I assume you're using as you have chromebooks, or onedrive Office is on the laptops already, and web office on Chromebooks Which leaves SIMS, either vpn or rdp depending on whether you want access on chromebooks 1
LeMarchand Posted November 6, 2023 Posted November 6, 2023 Which leaves SIMS, either vpn or rdp depending on whether you want access on chromebooks Even better: Ditch SIMS and get a decent cloud-based MIS. Probably cheaper, better, and less likely to try renewal shenanigans. 1
Sephiroth Posted November 6, 2023 Posted November 6, 2023 We have a similar setup to what you've described. What we went with was an RDS cluster with NPS to require MFA off-site. We couldn't use a VPN as all staff have Chromebooks and they needed access to SIMS and some "SIMS adjacent" applications. Data is all in Google Drive, and home directories are redirected. The benefits of RDS over VPN are that they don't need to set anything up on their own machines for them to remote in from home on personal devices, but it can be set to require MFA. When we looked at it, MS Always On VPN didn't seem as simple to set up or secure of an implementation. 1
dhicks Posted November 6, 2023 Posted November 6, 2023 Ideally the staff here want access to Sims, MS office, home directory and a few other applications. We're reviewing our setup at the moment. Our current remote access server has about a dozen regular users, most staff have moved accross to using Google Workspace for most things. For our own admin access, we use Guacamole behind Cloudflare's ZeroTrust platform, with user authentication via 2FA-protected Google accounts. That has been very reliable over the past 6 months or so, we're considering if we move our main remote access behind it, too. Interestingly, as Guacamole supports SSH and VNC as well as RDP connections, we should be able to give pupils access to individual Raspberry Pi desktops or SSH sessions via their Google accounts if we wanted. 1
LuciferMorningstar Posted November 7, 2023 Author Posted November 7, 2023 Even better: Ditch SIMS and get a decent cloud-based MIS. Probably cheaper, better, and less likely to try renewal shenanigans. Already tried going down that road! The data team are happy with Sims and not interested in a move away at the moment (its a long term plan to convince them otherwise).
Rob_D Posted November 7, 2023 Posted November 7, 2023 We've got RD (with HTML5 and app proxy and all that good stuff) at the moment, but are looking to depreciate it in favor of everything they need being in the cloud, before we moved away from SIMS we were looking at just having SIMS as a published app (rather than just having the full desktop experience for everyone) to better fit in with the 365 model we were pushing. Recently, I was out with some friends (we're all techies/gamers so messing around on a computer is something we do as a hobby). We're talking about WFH and they said that being able to close the remote desktop/vpn connection at the end of the day, really helps with the delineation between being "at work" on the computer and not. I bring this up, because it made me slightly re-evaluate the choice to push everyone into "cloud all the things" and perhaps there's a valid reason why people use RD to access SharePoint and webmail.
jthompson Posted November 7, 2023 Posted November 7, 2023 We've got RD (with HTML5 and app proxy and all that good stuff) at the moment, but are looking to depreciate it in favor of everything they need being in the cloud, before we moved away from SIMS we were looking at just having SIMS as a published app (rather than just having the full desktop experience for everyone) to better fit in with the 365 model we were pushing. Recently, I was out with some friends (we're all techies/gamers so messing around on a computer is something we do as a hobby). We're talking about WFH and they said that being able to close the remote desktop/vpn connection at the end of the day, really helps with the delineation between being "at work" on the computer and not. I bring this up, because it made me slightly re-evaluate the choice to push everyone into "cloud all the things" and perhaps there's a valid reason why people use RD to access SharePoint and webmail. A browser profile for my work account serves that function for me, as well as having an Android Work profile turning on/off on a schedule. When I close my work account Chrome profile, I'm done. 1
LeMarchand Posted November 7, 2023 Posted November 7, 2023 A browser profile for my work account serves that function for me, as well as having an Android Work profile turning on/off on a schedule. When I close my work account Chrome profile, I'm done. Not that I got to wfh for more than a few days, but I have similar. Work stuff is opened in a separate virtual desktop so that I had take a break and switch to my personal desktop. Still on W10 at home, so I have a start menu "work" group.
ITGuyNW Posted January 24, 2024 Posted January 24, 2024 I'm also looking at our remote access options. Currently have RDS setup. Only reasons to log in are for SIMS and files held on network, everything else is cloud based. Staff have laptops that they use in school and at home. Is there a better way so I can bin off RDS?
DrCheese Posted January 24, 2024 Posted January 24, 2024 (edited) If you provide staff laptops, AOVPN will fit the bill for you. Seemlessly connects back to school when offsite. If you want to improve your RDS security you can either setup NPS with Azure MFA on it (So staff get a push notification) or you can set up the web client & hide it behind an Azure app proxy, so staff have to preauth to access it. Edited January 24, 2024 by DrCheese
colly72 Posted January 24, 2024 Posted January 24, 2024 We use Sophos Firewall VPN here, with MFA. Works pretty flawlessly for those who want to use it.
Rob_D Posted January 24, 2024 Posted January 24, 2024 I'm also looking at our remote access options. Currently have RDS setup. Only reasons to log in are for SIMS and files held on network, everything else is cloud based. Staff have laptops that they use in school and at home. Is there a better way so I can bin off RDS? Can you move the files up onto SharePoint/Google? Unfortunately there's not a lot you can do about SIMS, unless you can replicate the functionality people want remotely with apps like Mint (sorry I can't think of any better examples right now). Or whoever owns SIMS now gets on and actually do the cloud migration thing. (or I guess move to a cloud based MIS) If you can move the files to the cloud, then you could publish SIMS as a remote app and take away the full desktop option. It doesn't help with security, but it starts to change the staff mindset away from "Remoting into the school desktop to work". (I've known enough teachers that would go on Remote Desktop to access cloud resources that it's always a consideration)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now