Jump to content

Recommended Posts

Posted

Hello, we are going to hand out laptops (with docking stations) for staff to use at home and in their classrooms . The reason we are handing out laptops is to provide managed secuity for users on the school systems, but quite a few members of staff don't 'justify' a personal laptop e.g. They are PT, Teaching assistants or just not expected to ever work from home, BUT we do need to allow them access school systems remotely (e.g. occasionally checking email, 365 logging in to a system or accessing the staff Sharepoint Sites) how do we cater for this, yet also adhere to the security aspect of the project? They will presumably be using iOS, Windows, Android etc..

Posted

thanks, so if we can put this security in place on home devices why are schools leaning back towards providing laptops for staff to use at home? we could just keep workstations in classrooms, but that very much does not seem to be the trend.

 

I know Intune may drive the trend a bit as it's inherently terrible on non 1-1 devices, but eventually (if not already) schools will be using Intune for multi user devices in IT rooms, so we are going to have to cater for Intune managed non 1-1 devices anyway.

Posted
23 minutes ago, petben said:

thanks, so if we can put this security in place on home devices why are schools leaning back towards providing laptops for staff to use at home? we could just keep workstations in classrooms, but that very much does not seem to be the trend.

 

I know Intune may drive the trend a bit as it's inherently terrible on non 1-1 devices, but eventually (if not already) schools will be using Intune for multi user devices in IT rooms, so we are going to have to cater for Intune managed non 1-1 devices anyway.

 

 

You will have some staff who wouldn't be happy with any level of control over their personal devices. We have staff that don't want to have the Microsoft Authenticator on their phones for MFA. 

  • Like 1
Posted
49 minutes ago, petben said:

thanks, so if we can put this security in place on home devices why are schools leaning back towards providing laptops for staff to use at home? we could just keep workstations in classrooms, but that very much does not seem to be the trend.

 

I know Intune may drive the trend a bit as it's inherently terrible on non 1-1 devices, but eventually (if not already) schools will be using Intune for multi user devices in IT rooms, so we are going to have to cater for Intune managed non 1-1 devices anyway.

 

We provide laptops to staff which is their "official" way of accessing school data as we can put all the provisions in place. If for some reason they also want to use a personal device, we lock them down with app policies and conditional access.

Posted

it's a tricky one, so we have a list of staff who probably work externally - they get a laptop, and a list of staff who don't really do that - they don't get a laptop. so for this second list of staff if they need to access school systems they either have to put up with the App Protection Policy, or use a school device when onsite, which tbh is open a huge period of time 6am-9pm ish. this same rule could apply to the first group of staff?

  • Like 1
Posted
12 minutes ago, NegativeKillDeath said:

 

 

You will have some staff who wouldn't be happy with any level of control over their personal devices. We have staff that don't want to have the Microsoft Authenticator on their phones for MFA. 

 

Just now, ITGuyNW said:

In that case they don't get to access school data... it's not a valid argument in 2025.

 

For myself, stuff the school having ANY "control" whatsoever over any of my personal devices. 

 

Authenticator apps are different. They are under my control.  If you want somebody to work either off-site or out of hours surely they would need to tools for they job, and payement for the time?

  • Like 1
Posted
7 hours ago, ITGuyNW said:

In that case they don't get to access school data... it's not a valid argument in 2025.

 

 

7 hours ago, sigma said:

 

 

For myself, stuff the school having ANY "control" whatsoever over any of my personal devices. 

 

Authenticator apps are different. They are under my control.  If you want somebody to work either off-site or out of hours surely they would need to tools for they job, and payement for the time?

 

 

If the school doesn't pay a single penny towards anyone's mobile phone cost, the phone bill or their internet bill or electric bill, WHY WOULD they work at home?

 

The schools can't have it all their way and not expect a bit of flexibility from staff e.g lunchtime browsing etc. on staff devices.

 

 

Posted

I think we’re going a little off topic. my personal thoughts, right or wrong, is that for schools who are nearly all struggling with finances to now be purchasing devices for staff which are more expensive to initially purchase, have a shorter life span and are more difficult to upgrade/repair seems to be counter intuitive. Especially as there is an alternative - to use your personal device with App control, or work on-site if that is not an option.

Posted

Can you accept the risk of unpatched, unprotected devices, potentially compromised personal devices accessing personal data?  
 

We use ‘last gasp’ devices before they are disposed of for these users. 
 

 

  • Like 2
Posted

hence the original question and answer - use App Protection Policies (rather than force staff to use, and IT to manage, outdated/out of warranty/slow hardware).

 

Posted (edited)
22 hours ago, petben said:

I think we’re going a little off topic. my personal thoughts, right or wrong, is that for schools who are nearly all struggling with finances to now be purchasing devices for staff which are more expensive to initially purchase, have a shorter life span and are more difficult to upgrade/repair seems to be counter intuitive. Especially as there is an alternative - to use your personal device with App control, or work on-site if that is not an option.

 

I do appreciate this can be a very divisive and charged topic.  

For my 2-cents as that access given as a privilege has been blatantly abused in the past - I have learnt otherwise on this approach. e.g. one time reading a nasty email from a staff member on a Friday on a personal device after work hours, whilst trying to help them, was on my mind all weekend - totally unfair on me. 

 

On topic - Any issues accessing it aren't actually an IT / Technical problem, it's a MANAGEMENT problem.  

 

 

Edited by DrBeaker
Posted

Interesting thread...

 

What do you all do about staff accessing their school email on their personal devices?  Most of our staff have the Outlook app as not all staff have a school laptop/device.  

I have suggested to a number of Android users that they put their email app into a "Secure Folder" as an additional layer of security - not sure if that is something that Apple have too?

Posted

 

1 hour ago, BlueSkies said:

Interesting thread...

 

What do you all do about staff accessing their school email on their personal devices?  Most of our staff have the Outlook app as not all staff have a school laptop/device.  

I have suggested to a number of Android users that they put their email app into a "Secure Folder" as an additional layer of security - not sure if that is something that Apple have too?

You still need to be using conditional access policies to force use of the Outlook app, otherwise they can use the browser or any other email client and you have no control over the state of the phone. 

 

Personally, I'm happy to have conditional access controls on my phone - it suits me to be able to look at an email or receive a Teams message when I'm not at work and I'd rather not carry two phones. Conditional access doesn't give the organisation any control over my device and I have a separate profile with work apps/accounts so I don't get disturbed, but I can proactively look if I want to. If I was expected to work remotely it be available by phone, I'd expect to at least be given the option of a work provided device. 

 

I know what the finance issues are in schools having spent years managing a school IT budget. Where I am now, individual line managers have control on what they spend on IT for their staff, so we get the same issue in some places. It's a false economy; we issue Dell Pro laptops (previously Latitude) which cost around £800 with a five year next day onsite warranty including accidental damage cover. That's £1.50 per week, a tiny proportion of the cost of employing someone.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...