Jump to content

Recommended Posts

Posted

Hey folks,

 

Apologies if a similar thread has been made before, I couldn't seem to find anything on the subject :(

 

We're reviewing how supply accounts/supply laptops are being handled within our schools. These accounts are currently setup on Bromcom, where the corresponding AD account is then made and maintained by Salamander with a rotating password daily. Each account is restricted to logging into an assigned supply laptop (i.e. Supply1 -> SupplyLaptop1, etc). This has worked for a while, but recently a real-world incident has caused us to make changes. The account details can be used to logon to Microsoft 365, i.e. on a student's phone, where they are then able to log onto Bromcom via SSO and make changes (i.e. add/remove behaivour events, etc).

 

We've thrown around the idea of using Windows Hello PINs per device and rotating them periodically (i.e. every half term, every week, etc). This would solve the above, however another concern that was raised is that we're still not Cyber Essentials compliant.

 

So, how does your school do "it?" - any thoughts would be greatly appreciated :)

  • 2 months later...
Posted
1 minute ago, SuperChris said:

All schools will need to have Cyber Essentials by 2030 is my understanding

Incorrect. All colleges.

Until the government departments can decide how an actual school can do this whilst banning the equipment most likely to help and chopping schools budgets, this is not going to happen.

  • Like 4
Posted

I haven't faced that specific requirement, but conditional access policies should allow you to restrict login to domain/Intune joined Windows devices for a specific M365 user group.

Posted

We have 3 users in Bromcom and 3 dedicated AD accounts and 3 Dedicated laptops with PIN and Windows Hello for Business... that way negating the need to let anyone know the windows passwords for those cover users..  it also has Passkey setup in Chrome from their google account so that works as the 2nd Factor stopping google randomly throwing a 2FA prompt that cant be dealt with just asks for the windows PIN...

Not saying it is CA compliant.. as much as i wanted to try and achieve this...  as others have said until DfE work out what they are doing with phones its going to be hard... and we have 1:1 iPads in yrs 7-9 (maybe 11 if they look after them) 

Posted
On 06/07/2026 at 09:36, k-strider said:

We have 3 users in Bromcom and 3 dedicated AD accounts and 3 Dedicated laptops with PIN and Windows Hello for Business... that way negating the need to let anyone know the windows passwords for those cover users..  it also has Passkey setup in Chrome from their google account so that works as the 2nd Factor stopping google randomly throwing a 2FA prompt that cant be dealt with just asks for the windows PIN...

Not saying it is CA compliant.. as much as i wanted to try and achieve this...  as others have said until DfE work out what they are doing with phones its going to be hard... and we have 1:1 iPads in yrs 7-9 (maybe 11 if they look after them) 

Thanks for this, and for all other replies. The solution we decided to implement was to instead rely on per-device PINs that are rotated on a semi-regular basis, with account passwords not being stored by IT.

Posted
On 02/07/2026 at 11:42, SuperChris said:

All schools will need to have Cyber Essentials by 2030 is my understanding

 

2030 is the DfE Technology Standards, not CE. CE is only for colleges.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...