Jump to content

Recommended Posts

Posted

Hi everyone,

 

I am currently looking after a school that has bought an entire apple provision and is not currently set up for Apple School Manager or MDM. I am in the process of resolving this with apple configurator etc.

 

The issue I have is that they have an on-prem smoothwall appliance and the school would like to monitor web activity by username, rather than device. The current set up is not compliant with current KSIE or Safeguarding requirements.

 

In the past I have achieved this with an AD environment using iDex and joining the iMacs to the domain but I don't have that option here.

 

Could any please point me in the right direction on how to achieve this on an all apple provision? I have been told I might need to use a smoothwall browser etc.

 

Thanks again!

Posted

1. Ditch Apple configurator, sign up to Apple school manager – the authorization email has to come from the heads account they won’t accept an application from the network managers email address.

 

2. You need to buy all of your APPs again; contact your Apple supplier and ask for a voucher for Apple Volume licence credit (VPP?) – raise an official order for the voucher this is the easiest way to add credit to your Apple volume licence account once you’ve got Apple school manager setup (they will send you a redemption code).

 

3. Contact the supplier you got the Apple devices from and tell them they need to be assigned to your Apple School account (I hope they used an official Apple supplier to buy them).

 

4. Pick an MDM (I used Meraki because it used to be free)

 

5. Link your MDM to Apple school and assign the devices

 

6. Buy the Apps via Apple school manager volume licencing and assign them to your MDM

 

7. Use the MDM to create profiles, configure device restrictions and assign the APPS to devices

 

 

 

RE Smoothwall monitor, I used it when it was still called Policy Central before Smoothwall got their grubby hands on it and ripped out the built in filtering. It was great on PC (most of the time) but the iPad browser was garbage you couldn’t even save favourites.

 

It might have improved in the last couple of years but I wasn’t convinced it always worked as it should. Since the Policy Central days they kept promising to support other clients but never did, again this might have changed in the last couple of years.

 

If you want to go down the Smoothwall monitor route ask for a demo / visit another school that is using it on iPads.

 

 

At a Primary I assigned iPads to Teachers and changed the device name to the Teachers name, they were locked down with the MDM and the policy central / future digital (smoothwall) browser replaced Safari.

 

A handful of ipads were setup for the children with a limited selection of kids APPS. I used the browser “allowed” list in the MDM to restrict internet access to a handful of pre approved websites that had been checked and didn’t have chat rooms etc… so no need for the Policy Central browser on those.

 

 

Now in your case you could try using Apple school Manager to create Apple id’s for the users but I don’t know if Smoothwall monitor or your smoothwall appliance will pick up the Apple ids. Note I believe there is an issue with how many Apple id profiles you can have an iPad before they run out of space if they are shared devices.

 

 

iPads are consumer devices they were never intended to be used as shared devices in an educational environment, things like Apple school manager came years later and were an after thought. There are still issues with Apple such as users being given the option to turn off tracking and I believe newer IOS releases can change the MAK address (for consumer privacy) which can cause other issues if it’s not disabled.

 

(There are other products similar to Smoothwall monitor which you might want to investigate)

 

 

- Good look!

Posted

Thanks for the insightful reply, its incredibly helpful and appreciated!

 

The school have recently been registered with Apple School Manager and Mosyle MDM (as its Free for basics). The school have 15 iMacs and about 10 iPads, they are a small independent school.

 

They have a Smoothwall S8 which was installed prior to me supporting them but the school outright purchased the devices from Currys and not an Apple authorized reseller, so as I understood it, I'd need to use Apple configurator to enroll the devices into Apple School Manager.

 

Your suggestion around the iPads being named against who they are assigned to with the Smoothwall browser replacing safari is something I thought about as a backup plan, thanks for confirming that would work as I wasn't entirely sure!

 

I am beginning to think that Smoothwall for an all Apple provision is not suitable if I am unable to track users on iOS and MacOS which is a real shame as I have used Smoothwall in other schools, albeit in an AD environment, and its been great.

Posted

I've used Smoothwall with Apple devices in the past and still do.

 

You've got a bunch of options for authenticating users here. Ipads should redirect to a login page

 

https://kb.smoothwall.com/hc/en-us/articles/360003986299-Smoothwall-Filter-Firewall-Authentication-Methods

 

You're going to need a directory service to map your users against - take your pic

 

https://kb.smoothwall.com/hc/en-us/articles/11657935583132-Smoothwall-Filter-Firewall-Directory-Services

 

I'd look at Jamf Connect (or mosyles equivalent) for the macs to handle logging in and use that against your directory service of choice (Azure AD works well).

 

https://www.jamf.com/products/jamf-connect/#macosedu_0

Posted

Yes if they got them from Currys, unless it’s changed in the last couple of years you will need to use Apple configurator to add them to Apple school manager.

 

I can’t comment on Smoothwall S8 I’ve never used it, we used the LEA’s internet connection and didn’t have access to logs etc on the filter.

 

Then we switched broadband provider to RM and had RM Safety Net but as we were using Policy Central (Smoothwall monitor) on all devices we didn’t need to use the reporting on the web filter.

 

If the web filter requires a tech to log in and generate reports then its not a suitable solution; the DSL’s need to receive the reports automatically, then come to you if they need any advice or want something blocked.

 

 

I believe the new guidelines have an emphasis on monitoring which is where Policy Central was good (on PC at least) because it saved screen shots when a violation (keyword) was detected. The DSL’s can then log into the system and see all of the captures. They now provide a managed service so they will check all the captures (think thousands of false positives) and contact the DSL directly if it’s a high priority capture. The iPad version will never be as good as the PC version because of Apples closed ecosystem and the restrictions they have in place.

 

 

 

It looks like Smoothwall monitor has a shared iPads option with google and 365 authentication now which might cover what you need, just bare in mind what I said earlier re running out of space on shared iPads if there are a lot of users.

 

 

https://monitorhelp.smoothwall.com/hc/en-gb/articles/7949853296156-How-to-Install-Monitor-on-iOS-Devices#h_01HWYW7RYV3CWW7RBDFXR5MME6

 

https://kb.smoothwall.com/hc/en-us/articles/4410521366162-Additional-Configuration-Options-for-Shared-iPads

 

 

 

I believe there’s a Smoothwall rep somewhere on here if someone could tag him / point him at the thread he might be able to give you more answers?

Posted

With iPads we played with different ways to go through a smoothwall and yes one was ad with domain joined apples which worked but very complicated and found the apples regularly had problems in this config. How ever that may have been down to lack of knowledge we all collective had with apple and ad

 

The other more simplistic method was a https redirect on all managed devices. The only caveat is the users had to login manually

The iPads had the smoothwall certificate sent out to them to allow inspections. They were joined to dedicated vlan which formed a location in smoothwall that forced authentication thru. You still need an ad present which wasn’t a problem as it was a hybrid school mainly windows so we needed ad anyway.

 

Not sure whether this fits your scope.

Posted
There's a couple of ways you can filter your ipads with Smoothwall - most have been mentioned here. We retain a custom browser (as it gives maximum safeguarding insight) but you will be pleased to hear it is now a fork of firefox so it is not hot garbage (like the one we acquired years ago!), it's a real browser :)
Posted
Thank you all so much for the help, this is massively useful and I think I can now see a way forward - it all looks pretty straight forward which is a bonus.
Posted

We actually re-did our Ipads today. These iPads will not be taken off site.

 

Accounts

 

AD > Azure > Apple school

 

Enrolled ipads into intune, shared mode profile setup etc.

 

Pushed proxy settings through the proxy.pac file

 

Published a link to the SSL login URL as a webclip app

  • Thanks 1
  • 3 months later...
Posted

Evening all, many thanks for the help with this Apple project - it was put on hiatus but is now up and running again.

 

I am hoping for a final bit of guidance if possible.

 

1. Smoothwall is now configured to use Azure for the directory service, synchronization is working - green ticks across the board. I have linked the Students Group on Smoothwall with the Students Group on Azure.

2. School is now registered with Apple School Manager and I have enrolled an iMac M1 using Apple Configurator

3. Jamf School has been registered and is linked with Apple School Manager - Synchronization is working fine.

4. Jamf Connect has been installed and configured on the iMac M1 and I can now log in with Microsoft 365 accounts

 

I feel that I am most of the way there, but there are a couple of outstanding issues that I am wondering if I need Jamf Pro for.

 

1. Although I can sign in with an Office 365 account, its not SSO and doesn't automatically sign-in to the users corresponding Apple ID or Microsoft services.

2. Whilst I see the device in Smoothwall the username in real-time web filter shows the IP of the device and not the username of the account that is signed in.

 

I have read that I need to set up Jamf Pro to use SSO via Enterprise apps registrations and have the Microsoft company portal app installed on the iMac, but I am using Jamf School and it isn't as feature complete.

 

If I could trouble anyone for some further guidance, I'd really appreciate it!

Posted
@Gobstopper - The login happens on the device and is not sent to the Smoothwall on-prem so it isn't aware of the user. Look into using our cloud filter extension - that will get the login from the OS and map the users correctly. It is part of the license so have a chat with the account manager - they will pass you on to a tech contact that can assist if you are interested in trying this out.
  • Thanks 1
Posted
@Gobstopper - The login happens on the device and is not sent to the Smoothwall on-prem so it isn't aware of the user. Look into using our cloud filter extension - that will get the login from the OS and map the users correctly. It is part of the license so have a chat with the account manager - they will pass you on to a tech contact that can assist if you are interested in trying this out.

Thank you so much for the heads up ibpalle I really appreciate it, I have raised it on the Smoothwall support portal, to get this implemented. I must admit, I thought there was a missing link in all of this and this makes total sense!

Posted
Hey! That sounds like a challenging situation. I've dealt with some similar setups before. If you're using a Smoothwall appliance, definitely look into its user authentication features. They can help track web activity by username, which is crucial for compliance. In my experience, using a Smoothwall browser can simplify things, but I’d recommend testing it to see if it works well with your Apple devices. Also, check if there’s a way to integrate Apple’s user accounts for smoother monitoring.
Posted
Hey! That sounds like a challenging situation. I've dealt with some similar setups before. If you're using a Smoothwall appliance, definitely look into its user authentication features. They can help track web activity by username, which is crucial for compliance. In my experience, using a Smoothwall browser can simplify things, but I’d recommend testing it to see if it works well with your Apple devices. Also, check if there’s a way to integrate Apple’s user accounts for smoother monitoring.

 

A combination of cloud filter extension for cloud directories, iDex and RADIUS for AD accounts on both BYOD and domain devices should hopefully cover most bases for transparent authentication of all devices/

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...