Jump to content

Recommended Posts

Posted

Good morning,

 

Hoping somebody can advise me as to what their LA advises, or indeed what you just happen to do when it comes to:

 

1.) Staff configuring their mobiles for access to work e-mail

2.) Staff using personal laptops or PCs to access cloud-based resources such as OneDrive, Exchange Online, Teams, etc.

 

Seems to me that our LA has a hard "do not use a personal device for anything work-related" stance but my issue with this is that with more and more going cloud it surely makes sense to allow this and stop spending so much money on literally everyone having a laptop provided by us (in addition to desktop in the classroom). Not all staff can\will take a laptop to and from.

 

I get not storing documents on personal devices but to look at and work on documents directly from cloud I don't understand.

 

All thoughts welcome, thanks in advance.

Posted

@APMerry

 

Agreed that is a separate question, I personally prefer the desktop in classroom approach and they've historically always given laptops to staff it has just continued in my short time here.

 

Thanks

Posted (edited)

Just in my own honest personal opinion... I have no idea what the LA advises, I've never had any contact with them in over a decade working here (since they decided to withdraw IT support and I got employed).

 

Anyway, I'll be the first to admit we're not there yet (we do have staff accessing email on their personal devices - mostly phones), but ideally I'd want any school data to only be accessed from a device that:

 

Has policies in place to stop malicious code being run

Can be wiped/disabled remotely

Has the latest OS updates

Has Anti-Malware/Anti-Virus

Uses only approved software (and cannot have any other software installed)

The user is only a 'user' not an Admin

Etc...

 

We do give our teachers laptops for the reasons above (and because we don't have desktops) and it's surprising how many of them say they don't have a personal laptop at home anyway... editing a Word document/PowerPoint/Excel spreadsheet on a phone (whilst not impossible) is going to make planning tomorrow's lesson difficult...

 

I get your point of just creating/editing content on a purely cloud basis (and although we 'have' Google, uptake is slow and most prefer the installed copy of Microsoft Office on their laptops), but they can also download these documents (or upload content to the platform). I know you can probably stop this (or possibly stop this happening from $device), so I guess they could then email themselves content and then open that on any device... but in the main, most people will take the easy way out and if they have a device provided, will use it.

Edited by Koldov
Posted
Good morning,

1.) Staff configuring their mobiles for access to work e-mail

2.) Staff using personal laptops or PCs to access cloud-based resources such as OneDrive, Exchange Online, Teams, etc.

All thoughts welcome, thanks in advance.

1.) We do allow staff to use their personal phones for setting up Outlook with their school mailbox. The device has to register with inTune & meet policies to allow setup.

 

2.) We have no block in place to stop this, however it is advised to staff to not use non work devices for work purposes. All staff have their own laptop, so never really had an issue with this. The one thing we do limit however, is Bromcom access. This is limited via public IP - so can only be access either on the school LAN, or when connected to the VPN.

Posted

The Microsoft way for BYOD accessing cloud services is "Conditional Access" which is fairly straightforward to implement.

 

As an overview, the BYOD is registered on Intune on your tenancy - it's not a full member, just a lightweight registration - to allow basic checks like supported and updated OS. Once the user connects their organisational account on that machine, it creates an encrypted "container" on their device storage and any data belonging to the organisation is only stored within that container. The M365 admin can remotely delete the data from the BYOD machine. You can also set rules to prevent users downloading files.

 

There are other data loss protection facilities in M365 that's fine more on the data side than the device side that might be worth looking at.

Posted

Both 365 & Google have systems that allow personal devices to be used in a walled off way. We are a Google school and you can have Work profiles deployed onto a personal phone if they log into a school account, this keeps their work apps and settings separate from the personal stuff.

 

Might be too much for the LA to manage, so they just say NOOOO

Posted

We are a M365 organisation and have strict personal device policies enforced using Conditional Access and Mobile Application Management (MAM).

 

Conditional access defines that you must be using a Microsoft App to access information (Outlook, Word, Teams etc) and that a MAM policy must be applied.

 

MAM then allows you to ensure that the apps data is encrypted, a PIN on the app set and the app and device OS is not vulnerable to compromise.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...