Jump to content

Recommended Posts

Posted

Now so much data is in the cloud how are you all controlling access to school data ?

 

E.g. access to teams / sharepoint / google drive / MIS offsite and on personal devices ?

 

 

Posted

Quite strict here. No access to any school data on personal devices, everything is chucked onto Microsoft SSO (if supported), access controlled by CA rules which require a compliant/hybrid device.

 

My dad is a caretaker at another local school & his is the complete opposite, he is allowed his work email on his personal device, with no management profile required.

  • Thanks 1
Posted (edited)

@Olliedawg can you elaborate a bit ? E.g. is this all done by intune policies? CA?  is that certificate authority, so you need a cert to sign on which you only put on school owned devices ? so no outlook on personal mobile phones for example ?

Edited by mrstrong
Posted
1 minute ago, mrstrong said:

@Olliedawg can you elaborate a bit ? E.g. is this all done by intune policies? CA?  is that certificate authority, so you need a cert to sign on which you only put on school owned devices ? so no outlook on personal mobile phones for example ?

Conditional Access in Entra - so to access for example Office 365, devices are required to be either Hybrid joined, or marked as a compliant device in Intune

  • Thanks 1
Posted
1 hour ago, mrstrong said:

Now so much data is in the cloud how are you all controlling access to school data ?

 

We use Google Workspace, and now all our file storage is on Google Drive. All staff have 2FA enforced on their accounts, we provide Feitian USB keys as the 2FA method, which (so far!) have proved quite robust and secure. I think we've mostly got people out of the habit of emailing documents around, instead editing and sharing them from Google Drive, which cuts down on the number of copies of data floating around in random "downloads" folders. We haven't yet stopped people connecting to GMail with phone / home desktop email clients, but we might consider it. Our MIS (iSAMS) is web-based and accepts our already-2FA-ed Google logins, which makes logging in to that nice and simple, and for the few users (only half a dozen or so now) that still need a Windows application for something we have a remote desktop server, also web-based and accessed via Google logins. We issue all teaching staff with managed Chromebooks, so they have a school-managed device they can use from home if wanted. We don't currently restrict people from logging in to GMail, Google Drive , etc from non-school-managed devices, but we might revisit that policy in the future.

  • Thanks 1
Posted

Not in education but we have at least equally strict data requirements.

 

We do this with Entra ID Conditional Access. This allows you to check the device being used is a corporate device, it allows you to ensure that only apps that can further have their settings managed (e.g. the Microsoft app stack and a few others) can be used to access data, that devices can be marked 'lost' and blocked, all the good stuff.

 

You can further make a general requirement that apps must support entra ID SSO which allows you to bring them under this tent quite nicely, and if you are obliged to have one or two exceptions (lets live in the real world and acknowledge exceptions will always be with us) then you can in theory spend more time managing risk from these exceptions because you've managed everything else in Entra ID.

 

I personally feel this - or the equivalent from other product stacks - is pretty much a basic requirement to be handling sensitive PII. 

  • Thanks 1
Posted

@Roberto Does this require A5 or is A3 good enough ? We are still old school with an on site server and a bit of cloud stuff mainly 365 (google for kids chromebooks).

Most of the 365 stuff is just planning / curriculum but I am a bit worried about staff signing into 365 with personal laptops at home. In theory they could also sign in to the

MIS and e.g. download reports with sensitive PII. There was a thread on here recently about "DfE standards for IT Support". I wonder if that will specify any specific requirements

in this area.

Posted
5 minutes ago, mrstrong said:

@Roberto Does this require A5 or is A3 good enough ? We are still old school with an on site server and a bit of cloud stuff mainly 365 (google for kids chromebooks).

Most of the 365 stuff is just planning / curriculum but I am a bit worried about staff signing into 365 with personal laptops at home. In theory they could also sign in to the

MIS and e.g. download reports with sensitive PII. There was a thread on here recently about "DfE standards for IT Support". I wonder if that will specify any specific requirements

in this area.

Conditional Access is Azure P1 which I believe is in A3.

  • Thanks 1
Posted
16 minutes ago, mrstrong said:

@Roberto Does this require A5 or is A3 good enough ? We are still old school with an on site server and a bit of cloud stuff mainly 365 (google for kids chromebooks).

Most of the 365 stuff is just planning / curriculum but I am a bit worried about staff signing into 365 with personal laptops at home. In theory they could also sign in to the

MIS and e.g. download reports with sensitive PII. There was a thread on here recently about "DfE standards for IT Support". I wonder if that will specify any specific requirements

in this area.

A3 would be good enough - All you would need is a Entra ID P1 (previously Azure P1..) licence to enable access to those features (you should have one licence per user, however just having one licence unlocks the features for the whole tenant... do with that information as you wish 👀)

  • Thanks 1
Posted (edited)

A3 as others have mentioned. In addition to unlocking all the functionality to review with just one A3 licence, you can of course purchase A3 then unlock the A5 functionality with just one licence, to decide if you want to pay for it (some interesting stuff around risky logins, etc). But A5 isn't required.

Edited by Roberto
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...