Jump to content

Recommended Posts

Posted

Hello, I'm after some pointers about how we can make our iPad experience better in schools. 

 

We have a well-established Mosyle platform, but feel we're falling short on some critical parts of the eco-system as we're locking down quite a lot and not using it to its full potential. 

 

What we want to do is have students pick an iPad up, log in with their own account, and be able to track their browsing history within our Securly platform. 

 

We're using their smartpac certificate in order to force the iPads to use their proxy, so we are getting some metrics, but due to the nature of the beast, it never shows who is actually using those iPads. 

 

Wondering how others have their MDMs set, or if they've had better success with the likes of InTune which we're willing to give a try!

  • Like 1
Posted
13 minutes ago, MrIlly said:

What we want to do is have students pick an iPad up, log in with their own account, and be able to track their browsing history

 

...

 

We're using their smartpac certificate in order to force the iPads to use their proxy, so we are getting some metrics, but due to the nature of the beast, it never shows who is actually using those iPads. 

 

Keen to know the same also. I'm fairly sure (or at least until recently) the "logging into the ipad" part just plain isn't there. Hopefully I'm wrong or something new has come along!

Posted

We use InTune (Clunky) but they have to set the ipad up with the remote management policy by signing in with their school details.

 

They join the wifi using school credentials too.

 

But this means the student has their "own" ipad by default (we're 1:1)

  • Like 1
Posted
1 hour ago, JRA said:

 

Keen to know the same also. I'm fairly sure (or at least until recently) the "logging into the ipad" part just plain isn't there. Hopefully I'm wrong or something new has come along!

I've stumbled across the "Multi-user (Apple Shared iPad)" policy in ADE Profiles. But it seems to be doing something a bit funky at the moment, where it's not giving the end user the ability to enable location services. Which in this case, is required for it to get the correct time and date, but instead, enforces a time zone of LA, which is -08 hours.

 

I assume I've probably got a duff config somewhere so going to tear it apart and see what I've done wrong!

  • Like 1
Posted
1 hour ago, Andycat said:

We use InTune (Clunky) but they have to set the ipad up with the remote management policy by signing in with their school details.

 

They join the wifi using school credentials too.

 

But this means the student has their "own" ipad by default (we're 1:1)

Thanks for this Andycat. I've had a play about with InTune in the last hour or so, and I'm already stuck at getting the company portal app to play ball... It's asking me to enrol the already enrolled (in InTune) iPad. So, great start!! 🤣

Posted

Shared iPad still isn't great - never has been. The best iPad experience is still as a 1:1 device IMO.

 

However - in terms of identifying students - depending on how you're pushing the SmartPAC, and how you're logging into Securly, you should be able to have user information pull through no?

Posted
1 minute ago, StephenPink said:

Shared iPad still isn't great - never has been. The best iPad experience is still as a 1:1 device IMO.

 

However - in terms of identifying students - depending on how you're pushing the SmartPAC, and how you're logging into Securly, you should be able to have user information pull through no?

I agree 1:1 probably will be the best choice; the only caveat is that not all of our schools in the trust have enough iPads to give each student their own. Nor do they then have the budget to do this so we're stuck with shared devices for the most part. 

 

The problem we found surrounding Securly is to do with the way we have our Windows systems authenticated. It works near flawlessly for staff and students on PCs, where it's easy enough to inject the user's email string from the account to the proxy file variables. The problem then started with the iPads, shared user mode wasn't a thing when we first started doing this, so the setup really consisted of a single username being set for the proxy on the iPads WiFi profile, to which the staff at the schools made a manual record of which student was using what iPad. 

 

We were also getting bombarded by teaching staff about how most students, especially the younger ones, were unable to log in because they couldn't remember their usernames or their passwords, reducing the amount of actual teaching time they're getting with the iPads while they ring us to get their passwords changed, or login themselves.

 

So a struggle all round! 

 

Since discovering multi user device on the ADE profile, I'm currently exploring how this works, but still a little bit unsure about how to get the Securly proxy to pick up the variables from the logged in Apple ID. 

Posted
2 hours ago, MrIlly said:

Hello, I'm after some pointers about how we can make our iPad experience better in schools. 

 

We have a well-established Mosyle platform, but feel we're falling short on some critical parts of the eco-system as we're locking down quite a lot and not using it to its full potential. 

 

What we want to do is have students pick an iPad up, log in with their own account, and be able to track their browsing history within our Securly platform. 

 

We're using their smartpac certificate in order to force the iPads to use their proxy, so we are getting some metrics, but due to the nature of the beast, it never shows who is actually using those iPads. 

 

Wondering how others have their MDMs set, or if they've had better success with the likes of InTune which we're willing to give a try!

For more info, we're maninly a Google based school with an Entra ID authentication system, so we're quite flexible with which route we can do down for auth.

Posted

I’ve also found this challenging when working with shared profiles. I couldn’t get Smoothwall to communicate properly with Meraki and then with the iPad—something always seemed to go wrong. The biggest issue was not being able to view their browsing history.

In the end, we opted for single app mode with the highest level of filtering. It’s not the most efficient use of the iPad, but it does prevent any inappropriate or unintended usage.

 

Ross

Posted
17 minutes ago, MrIlly said:

We were also getting bombarded by teaching staff about how most students, especially the younger ones, were unable to log in because they couldn't remember their usernames or their passwords, reducing the amount of actual teaching time they're getting with the iPads while they ring us to get their passwords changed, or login themselves.

 

Could you configure the iPads to use Securly Guest, and not bother with authentication?

Posted (edited)
56 minutes ago, rossibIT said:

I’ve also found this challenging when working with shared profiles. I couldn’t get Smoothwall to communicate properly with Meraki and then with the iPad—something always seemed to go wrong. The biggest issue was not being able to view their browsing history.

In the end, we opted for single app mode with the highest level of filtering. It’s not the most efficient use of the iPad, but it does prevent any inappropriate or unintended usage.

 

Ross

 

Seems I've been mentioning it a lot lately but...Classroom Cloud (I promise I'm not affiliated) solved this sort of issue for us.

 

Usernames, and email auth wasn't an option for our younger users so we opted to use the CC browser which supports QR code login.  Each child has a unique QR code that they scan to authenticate themselves in the browser. It then reports any keyword matches back to the Safeguarding team and allows them to be monitored live during lesson time. Browser can be set to timeout after a short while, meaning the next pupil that picks it up can't browse the web without their QR code. We disable safari, so the only way to access the internet is via our manage browser.

Edited by Cat_Jam148
  • Like 2
Posted
1 minute ago, Cat_Jam148 said:

 

Seems I've been mentioning it a lot lately but...Classroom Cloud (I promise I'm not affiliated) solved this sort of issue for us.

We're a Senso trust. Looked at Classroom Cloud many times over the years and it just doesn't fit the bill for our use case. Great for teaching force, but that application massively falls short for technicians work (which we really want so get the final say HAHA!).

 

I appreciate the suggestion, and someone else may take you up on that if they're up for renewal with another classroom solution! 👍

Posted
49 minutes ago, altecsole said:

Could you configure the iPads to use Securly Guest, and not bother with authentication?

How do you mean Securly guest? I think we're already doing this at the moment by using a generic account for web traffic reporting, but we really need it to report back to Securly for safeguarding.

Posted
4 minutes ago, MrIlly said:

How do you mean Securly guest? I think we're already doing this at the moment by using a generic account for web traffic reporting, but we really need it to report back to Securly for safeguarding.

It's probably not what you want, as Secury Guest has no SSL inspection or authentication. Great for 'guest' access, but not if you want detailed reports. We use it for guests, and staff who say they need access on their own device, for work purposes. It's set to be more restrictive than policies that do SSL inspection, and require authentication.

Posted
1 hour ago, Cat_Jam148 said:

 

Seems I've been mentioning it a lot lately but...Classroom Cloud (I promise I'm not affiliated) solved this sort of issue for us.

 

Usernames, and email auth wasn't an option for our younger users so we opted to use the CC browser which supports QR code login.  Each child has a unique QR code that they scan to authenticate themselves in the browser. It then reports any keyword matches back to the Safeguarding team and allows them to be monitored live during lesson time. Browser can be set to timeout after a short while, meaning the next pupil that picks it up can't browse the web without their QR code. We disable safari, so the only way to access the internet is via our manage browser.

 

 

How much is it/device? Their site is a bit coy.

Posted (edited)

3 1/2 year iPad manager here :Cry:, your best option is 1:1 devices unfortunately. You have the user permanently signed in with the iCloud account from the start and then you can use a profile to read the $email from the iPad and match it through the proxy. When trying to do this through shared devices and logging in / out all the time with their Apple ID simply does not work 90% of the time unless you go for a simple standard base filtering profile but then you are already in that position and know the pain of not being able to identify.

 

iPads, they are the future of IT in schools so I keep getting told 🙄

Edited by Tefters
Posted
34 minutes ago, LeMarchand said:

 

 

How much is it/device? Their site is a bit coy.

 

We pay £5.50 a device for the IT & Classroom management package.  As far as I'm aware, it's the only provider out of the big ones which allows us the QR code login. (although it's been awhile since checking)

 

Can't really fault it apart from the confusing layout at times.  Staff and DSLs seem happy enough with it.


 

  • Like 1
  • Thanks 1
Posted
3 hours ago, MrIlly said:

I agree 1:1 probably will be the best choice; the only caveat is that not all of our schools in the trust have enough iPads to give each student their own. Nor do they then have the budget to do this so we're stuck with shared devices for the most part. 

 

The problem we found surrounding Securly is to do with the way we have our Windows systems authenticated. It works near flawlessly for staff and students on PCs, where it's easy enough to inject the user's email string from the account to the proxy file variables. The problem then started with the iPads, shared user mode wasn't a thing when we first started doing this, so the setup really consisted of a single username being set for the proxy on the iPads WiFi profile, to which the staff at the schools made a manual record of which student was using what iPad. 

 

We were also getting bombarded by teaching staff about how most students, especially the younger ones, were unable to log in because they couldn't remember their usernames or their passwords, reducing the amount of actual teaching time they're getting with the iPads while they ring us to get their passwords changed, or login themselves.

 

So a struggle all round! 

 

Since discovering multi user device on the ADE profile, I'm currently exploring how this works, but still a little bit unsure about how to get the Securly proxy to pick up the variables from the logged in Apple ID. 

 

Yeah fair enough, we have one site that is 1:1 and one that isn't - Securly at both. 

So the way we do the non 1:1 site is;

- iPads setup as a set user (e.g. StudentiPad01@DOMAIN etc etc)

- This is mapped as a 1:1 in the MDM (Jamf School)

- This is also mapped to Securly, with correct policy applied

- SmartPAC then happy as you say with the user injection

 

However, at the 1:1 site, we have loan iPads (because students forget...) so for those;

- Shared iPad mode

- SmartPAC profile WITHOUT user injection

- Securly set to force login > currently local AD but moving to Azure AD imminently 

 

 

We do have Apple School Manager federated to Azure, so once the Securly auth moves to Azure too, I'm hoping the SSO will kick in for that on the Shared iPads (haven't tested yet though)

  • Like 1
Posted
21 hours ago, StephenPink said:

 

However, at the 1:1 site, we have loan iPads (because students forget...) so for those;

- Shared iPad mode

- SmartPAC profile WITHOUT user injection

- Securly set to force login > currently local AD but moving to Azure AD imminently 

 

I have a meeting with Securly on Monday about creating a system cert that will read the current email address from the iCloud logged in user, and in theory, will use that to user inject into the smartpac file, saving the faff with login. This is what I'm hoping to do while also keeping the iPads in multi user mode.

 

I'll let you know my findings once I've spoken to them!

Posted
On 01/10/2025 at 19:12, Tefters said:

@StephenPink You using securly for filtering and safeguard alerting or just filtering?

 

If both, how are you finding the safeguard alerting?

 

Yes we use Filter and Aware. The DSLs at relevant sites are happy - I would say it's personal preference in terms of instant alerts vs reviewing activity dashboards. You can choose whether to have instant email alerts on or off for the relevant blocked categories. Aware is pretty powerful - in terms of email content that's definitely been useful. 

Obviously there is no perfect product, but in terms of consistency across all devices, Securly seem to be pretty good.

 

On 02/10/2025 at 14:32, MrIlly said:

I have a meeting with Securly on Monday about creating a system cert that will read the current email address from the iCloud logged in user, and in theory, will use that to user inject into the smartpac file, saving the faff with login. This is what I'm hoping to do while also keeping the iPads in multi user mode.

 

I'll let you know my findings once I've spoken to them!


Ooh interesting! Not that we've had problems with the way we've been doing it for Shared iPads but I'm still curious to hear more about that!

  • 2 weeks later...
Posted (edited)

Been Managing iPads via VPP/ASM/MDMs (Meraki and Lighspeed) for 10 years now, and as others have yet, the best functional solution I have found is 1:1 mapping. The :1 doesn't have to be a real user. We (me in IT) have implement pseudo accounts, ie [email protected] and assigned iPads in lightspeed. Teachers are instructed to manage this in the classroom using register order or a paper check sheets, but it never actually happens.

 

The ideal solution would be have an actual login function with devices in shared device mode via MDM, but again as said by others, it's bizarrely still just not there. I've attended numerous Lightspeed webinars and I think even Lightspeed are aware this is a major issue of concern, but I think it depends on Apple functionality that just isn't there. It's really annoying and is quite a serious safeguarding concern, particular in primaries.

 

We just have Lightspeed Alert set up to alert DSLS and they attend the classroom as the alert comes in to find out which student has device X or Y etc.

 

So many potentials cracks or flaws for vulnerable students to fall through, but haven't found a better solution... It's a while since I've looked at this in great detail, so I guess like OP, if anyone knows a way to (without additional cost, that's another problem...) to allow students to sign in and out of iPads (and not be able to use them otherwise, like a Chromebook etc) it would be a game changer. I'm aware of federating accounts in ASM against Google, but it's useless without a true login feature. Manage iTunes accounts are pointless if they still force you to 1:1 assign devices.

 

For those that use Lightspeed for filtering and MDM, I do fancy trying this, just not sure how easy/suitable it is for students. Also, it would mean having to convert ~580 iPads and redeploying config/setup files to them, meaning they'd all need wiped and set up afresh.

 

 

https://help.lightspeedsystems.com/s/article/device-management-shared-ipad

Edited by Planehazza
Posted
On 01/10/2025 at 14:14, Cat_Jam148 said:

 

Seems I've been mentioning it a lot lately but...Classroom Cloud (I promise I'm not affiliated) solved this sort of issue for us.

 

Usernames, and email auth wasn't an option for our younger users so we opted to use the CC browser which supports QR code login.  Each child has a unique QR code that they scan to authenticate themselves in the browser. It then reports any keyword matches back to the Safeguarding team and allows them to be monitored live during lesson time. Browser can be set to timeout after a short while, meaning the next pupil that picks it up can't browse the web without their QR code. We disable safari, so the only way to access the internet is via our manage browser.

 

Similar situation here. Teachers all have custom admin roles to reset student passwords, but they're not prepared to manage these themselves. Getting curriculum and IT policies to align is half our battle too. IT say no generic accounts, but how do you get a KS1 student to remember and email address and password? It's just bonkers.

 

I wanted to implement a solution from Clever, but unfortunately it was shot down by the money team. 

  • 3 weeks later...
Posted (edited)
On 01/10/2025 at 10:27, MrIlly said:

Hello, I'm after some pointers about how we can make our iPad experience better in schools. 

 

We have a well-established Mosyle platform, but feel we're falling short on some critical parts of the eco-system as we're locking down quite a lot and not using it to its full potential. 

 

What we want to do is have students pick an iPad up, log in with their own account, and be able to track their browsing history within our Securly platform. 

 

We're using their smartpac certificate in order to force the iPads to use their proxy, so we are getting some metrics, but due to the nature of the beast, it never shows who is actually using those iPads. 

 

Wondering how others have their MDMs set, or if they've had better success with the likes of InTune which we're willing to give a try!

This can not be done this way, Securly uses a SmartPac file installed on each iPad with the users email address as part of the configuration file to identify them so Securly only operates correctly in a 1:1 iPad environment, unless you have iPad registers for each class.

Edited by Brimstone
  • 5 months later...
Posted

I'm back at this topic. We're moving away from Lightspeed and so have had to find a new MDM solution. We've elected to use Intune as we want to implement that for laptops anyway. With this opportunity, I'm testing shared ipads which still seems rather sucky and glitchy. Got it set up nicely yesterday, come to show my line manager proof of concept and it's all gone t**s up 😂

 

I seem to read a lot about using ASM to set passcode policies and device lock grace periods etc. but I cannot see any settings anywhere. I've got it federated against Google for now, but unsure whether this will be Entra or another third party (QR based etc) system in the future.

 

How are those using shared ipad finding it in schools, particularly primaries where there may not be enough devices for true 1:1? True 1:1 simply is impossible here; I've already had to get my boss to tell Finance and above that 150 of our 600 iPad fleet need to be removed from use being stuck at iOS12.5.7...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...