Bankesy Posted January 16, 2024 Posted January 16, 2024 Good morning, Hoping somebody can advise me as to what their LA advises, or indeed what you just happen to do when it comes to: 1.) Staff configuring their mobiles for access to work e-mail 2.) Staff using personal laptops or PCs to access cloud-based resources such as OneDrive, Exchange Online, Teams, etc. Seems to me that our LA has a hard "do not use a personal device for anything work-related" stance but my issue with this is that with more and more going cloud it surely makes sense to allow this and stop spending so much money on literally everyone having a laptop provided by us (in addition to desktop in the classroom). Not all staff can\will take a laptop to and from. I get not storing documents on personal devices but to look at and work on documents directly from cloud I don't understand. All thoughts welcome, thanks in advance.
APMerry Posted January 16, 2024 Posted January 16, 2024 If everyone has a laptop, why do they need desktops in the classroom?
Bankesy Posted January 16, 2024 Author Posted January 16, 2024 @APMerry Agreed that is a separate question, I personally prefer the desktop in classroom approach and they've historically always given laptops to staff it has just continued in my short time here. Thanks
Koldov Posted January 16, 2024 Posted January 16, 2024 (edited) Just in my own honest personal opinion... I have no idea what the LA advises, I've never had any contact with them in over a decade working here (since they decided to withdraw IT support and I got employed). Anyway, I'll be the first to admit we're not there yet (we do have staff accessing email on their personal devices - mostly phones), but ideally I'd want any school data to only be accessed from a device that: Has policies in place to stop malicious code being run Can be wiped/disabled remotely Has the latest OS updates Has Anti-Malware/Anti-Virus Uses only approved software (and cannot have any other software installed) The user is only a 'user' not an Admin Etc... We do give our teachers laptops for the reasons above (and because we don't have desktops) and it's surprising how many of them say they don't have a personal laptop at home anyway... editing a Word document/PowerPoint/Excel spreadsheet on a phone (whilst not impossible) is going to make planning tomorrow's lesson difficult... I get your point of just creating/editing content on a purely cloud basis (and although we 'have' Google, uptake is slow and most prefer the installed copy of Microsoft Office on their laptops), but they can also download these documents (or upload content to the platform). I know you can probably stop this (or possibly stop this happening from $device), so I guess they could then email themselves content and then open that on any device... but in the main, most people will take the easy way out and if they have a device provided, will use it. Edited January 16, 2024 by Koldov
Olliedawg Posted January 16, 2024 Posted January 16, 2024 Good morning, 1.) Staff configuring their mobiles for access to work e-mail 2.) Staff using personal laptops or PCs to access cloud-based resources such as OneDrive, Exchange Online, Teams, etc. All thoughts welcome, thanks in advance. 1.) We do allow staff to use their personal phones for setting up Outlook with their school mailbox. The device has to register with inTune & meet policies to allow setup. 2.) We have no block in place to stop this, however it is advised to staff to not use non work devices for work purposes. All staff have their own laptop, so never really had an issue with this. The one thing we do limit however, is Bromcom access. This is limited via public IP - so can only be access either on the school LAN, or when connected to the VPN.
jmak Posted January 17, 2024 Posted January 17, 2024 The Microsoft way for BYOD accessing cloud services is "Conditional Access" which is fairly straightforward to implement. As an overview, the BYOD is registered on Intune on your tenancy - it's not a full member, just a lightweight registration - to allow basic checks like supported and updated OS. Once the user connects their organisational account on that machine, it creates an encrypted "container" on their device storage and any data belonging to the organisation is only stored within that container. The M365 admin can remotely delete the data from the BYOD machine. You can also set rules to prevent users downloading files. There are other data loss protection facilities in M365 that's fine more on the data side than the device side that might be worth looking at.
TwistedHelixis Posted January 17, 2024 Posted January 17, 2024 Both 365 & Google have systems that allow personal devices to be used in a walled off way. We are a Google school and you can have Work profiles deployed onto a personal phone if they log into a school account, this keeps their work apps and settings separate from the personal stuff. Might be too much for the LA to manage, so they just say NOOOO
Mr.Ben Posted January 17, 2024 Posted January 17, 2024 We are a M365 organisation and have strict personal device policies enforced using Conditional Access and Mobile Application Management (MAM). Conditional access defines that you must be using a Microsoft App to access information (Outlook, Word, Teams etc) and that a MAM policy must be applied. MAM then allows you to ensure that the apps data is encrypted, a PIN on the app set and the app and device OS is not vulnerable to compromise.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now