Jump to content

Recommended Posts

Posted

I am supporting a school (not in the UK) with an incredibly tight budget. There are 40 teachers each of whom have a Windows laptop, which is unmanaged. All teachers have a local admin account. Most are running Windows 11 Home. There is no Windows server, and no budget for one or a cloud alternative. I have spoken to a dozen teachers and looked at their laptops with them to discuss how they are getting on. Many were handed the laptops out of boxes and have used their personal Microsoft accounts to sign in. Others were passed the laptop by a teacher who has left and the laptops are signed into their personal MS accounts. Others have local accounts and have risky apps or Chrome extensions installed. Many users were distratcted by many of the features in Win 11, such as the facts on the lock screen, the 'about this background' icon on the desktop, and the useless pinned apps. 

 

I have resigned myself to the fact that it needs to be a case of best endeavours with unmanaged devices. I am currently compiling a list of devices, so that I can figure out which are obselete, and groups of laptops which have identical hardware. The school has a Google Workspace which I am managing, but not a Microsoft 365 in place.

 

My plan is to find a group of identical laptops, and choose one to copy necessary data from, and then follow this process:

 

- factory reset (wiping all data)

- sign in using a generic school admin account and use this to ensure laptop encrypts using bitlocker

- create a local, standard user account

- install necessary software (as much as possible from MS Store as these will auto-update with standard account no problem), and the rest Chrome, Drive etc. that should auto-update themselves

- there is no Office licence in the school - most staff use Libre Office - so install that also - I know that is a MS Store version, but I believe the regular version can be ammended to ensure that the default file extension is .docx - I have heard of many issues in the past with it defaulting to .ods and it causing problems

- log onto the local user account and remove bloating e.g. useless apps and just generally clean it up

 

Does this process sound reasonable?

 

I am also looking at scaling it? If I had a checklist to work from, it's not an impossibility to run through it all individually. Especially if I had 5 identical devices on the bench at one time. Ideally I want to streamline it though. Either through a script (I had a terrible experience with chatGPT writing a script!) or by cloning the devices. The issue I had with cloning though was that after they are generalised the user accounts are removed, and the bulk of the time going into this is with the user accounts. 

 

Does anyone have any suggestions?

 

Some devices have free virus checkers, others nothing. I'm aware we can get Bitdefender for all devices cheaply with a central console. Is this worthwhile or is Windows Defender sufficient? The lack of central console scares me to be truthful.

 

I am fully aware that this situation is bordering on farsical, and the school are well aware that what I will be doing is best endevaours, and I am happy that I am sufficiently covering myself. There is almost no budget for this. My experience is with physical Windows servers, domains and group policy. And those aren't tools available to me here.

Posted (edited)

Action1 is your friend here.

 

Free for 200 endpoints, and will allow you to begin the management process of the devices e.g. manage updates, asset management, remote desktop, scripting, deploying apps. If you have a Google Workspace tenant already, I would look into GCPW, or if you would rather use Microsoft then Intune (but this route will be more costly than Google's). You will need one or the other to lock them down correctly, as Action1 is just an RMM tool.

 

As @synaesthesia mentioned, you could look at Chrome OS flexing the laptops, I believe a license for this is currently ~£27 but it is a one off, and stays with the device until it is no longer in use. Staff could use the Google suite (docs, sheets, slides) which is free - even on the fundamentals tier.

 

But first and foremost, I would be getting Action1 on them - just to see what I was dealing with.

Edited by HyperTech
Posted

As you already have Workspace, Flex would be great if you can afford the licences. Then you'd have something similar to what you're already used to unless there is software that is needed but there isn't a Google equivalent.

 

If it has to be Windows, I've never used it but @HyperTech's GCPW idea sounds great. Also a massive +1 for Action1. As long as you have <201 endpoints this should be able to take care of your patching and software needs. You could then just install Windows + Action1 and only give staff limited accounts. Action1 can take care of the software installs. I'm looking at doing that with the deprecation/death of MDT and WSUS. Still not as "controllable" as if you went down the Flex route but no/low cost if you need to stick to Windows.

 

Also, why bother with even LibreOffice if staff can just use Google Docs etc and have it autosaved in the cloud?

Posted

I would sign up for an Edu 365 tenent with A1 licences, and purchase A3 licencing for FTE staff. Use Intune to manage the devices once A3 is in place. Action1 is a great supplement to Intune to be able to deploy apps/update/patch instantly rather than wait for a sedatary Intune application.

A1 licence for staff would cover 365 apps online.

A3 licence for staff comes with 1:40 student use benefit and would alllow the full 365 desktop/mobile apps to be used.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...