Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hello,

 

Our school is moving away from parent owned BYOD iPads to School owned an managed iPads.

At present we have Smoothwall for filtering web traffic and monitoring when students are onsite.

 

Our IT team are saying that it is a new government requirement that managed devices are also filtered at home and that we can only do this with a system such as Ativion StudentKeeper which monitors all traffic and app data via screen recording. Anything short of this is not meeting Government requirements.

 

From Gov.uk

https://www.gov.uk/guidance/meeting-digital-and-technology-standards-in-schools-and-colleges/filtering-and-monitoring-core-standard

Your filtering system should be active, up to date and applied to all: 

  • school or college-managed devices, including those taken off-site 

 

I interpret the above to mean that yes we should have filtering systems for managed devices which children take off-site - but that the filter doesn't necessary have to be active when these devices are connected to other networks (ie at home)

 

My question is this:

  • Is our IT department correct? 
  • What are other schools doing about managed iPads when off-site?
  • Is there any further documentation/guidance to support the case either way?

 

Thanks

 

Lawrence 

Posted

In short, yes they are correct, certainly as far as all the advice we have received see's it.

 

The short version, is that as we (The Trust/School) is providing the device, we would hold the safeguarding responsibility, in school or at home.

 

I think that most parents would think it reasonable that if we issue a device, we are ensuring a pupil could not access content they shouldn't in school , and I certainly wouldn't want to be the one answering a complaint if they could with ease.

 

In our case, we use smoothwall cloud filter enable this activity.

 

Hope this helps

 

 

Posted

In addition to what others have said, no matter what technology you put in place, you should still have a home school agreement where there is responsibility put upon the parent to provide appropriate supervision of device use. Given enough devices and enough idle students, some of them are going to get around your efforts, and having an explicit shared responsibilty will afford some protection. 

  • Like 1
Posted

Yes - We have all school owned devices fully filtered & monitored when on or offsite.

 

Logic is, we provided them. Doesn't matter how you word any home use contract, the moment a student accesses inapproriate material on a school owned device you will be held responbile. If the worse happened and a student was groomed, you would have provided that device to allow that. If you are happy to defend that then fair enough, but it wasn't something we was prepared to accept.

 

We do this even on laptops that in theory are owned by the student, eg ones provided by the virtual school or LAC funding. When they leave, we do a reset on them and they then take them from there.

 

 

  • Like 1
Posted

Just had a parent describe our proposed 1:1 device rollout as "Orwellian" due to Securly's 24/7 monitoring. 😕

Posted

I remember on the COVID laptop scheme, if you picked a vanilla Windows image rather than the DfE's Intune setup (with Cisco Umbrella for filtering), you had to acknowledge that you were legally required to have a filter on the device.

 

At the time due to limited resources I scrambled and used the Web Control on Sophos, but have since moved to LGfL HomeProtect (branded Netsweeper) as it's included with our broadband.

Posted
24 minutes ago, midweek said:

Just had a parent describe our proposed 1:1 device rollout as "Orwellian" due to Securly's 24/7 monitoring. 😕

Same parent would be banging on your door when Little Johnny/Jenny picks up nasty browsing habits, because of course it wouldn't be their fault ;)

 

Can only otherwise echo the above comments - if it's managed/school owned then yes, it must be filtered accordingly.  

Posted
2 minutes ago, synaesthesia said:

Same parent would be banging on your door when Little Johnny/Jenny picks up nasty browsing habits, because of course it wouldn't be their fault ;)

 

Can only otherwise echo the above comments - if it's managed/school owned then yes, it must be filtered accordingly.  

 

Aye exactly.

 

Also, said parent is perfectly free to buy their child a seperate non school device if they don't wish for the monitoring.

I say the same to staff. No one really minds if staff use their work device for odd browsing at home, but they need to be aware that whatever they do may be filtered/monitored. If they are unhappy with this, then they should buy a personal device.

 

 

I am massively pro Internet freedom when it comes to personal devices, but work/school devices are fair game.

 

  • Like 3
Posted
15 minutes ago, itskdog said:

I remember on the COVID laptop scheme, if you picked a vanilla Windows image rather than the DfE's Intune setup (with Cisco Umbrella for filtering), you had to acknowledge that you were legally required to have a filter on the device.

 

At the time due to limited resources I scrambled and used the Web Control on Sophos, but have since moved to LGfL HomeProtect (branded Netsweeper) as it's included with our broadband.

 

We use their have HomeProtect for offsite use as well. 

Posted (edited)

Anyone just rely on a school AUP for staff using standalone laptops at home, covering acceptable/inappropriate use, best practice, dos and don’ts etc.?

Every staff member with a standalone device signs the AUP and, when onsite, the device defaults to the staff internet policy, the same as other non-domain/non-AD devices.

Historically, we’ve managed staff standalone devices this way and have never had any incidents. However, I’m now considering whether we should start introducing filtering for off-site/home use as well.

I’m trying to strike a balance between:

  • allowing staff to use the laptops without unnecessary barriers when researching or planning, and
  • maintaining appropriate safeguarding/security measures.

The head also likes the laptops to provide some personal benefit to staff, as quite a few don’t have their own devices at home, so I’m conscious of not making them overly restrictive/intrusive

Edited by JazzFlute
Posted
Quote

The head also likes the laptops to provide some personal benefit to staff

I'd warn him about using those terms as a benefit could be taxable.

 

My question would be, if the barriers are unnecessary, why are they there during the day?  Or to put it another way, what could they do at home that they can't do in School that would be acceptable in school?

Posted
15 minutes ago, JazzFlute said:

Anyone just rely on a school AUP for staff using standalone laptops at home, covering acceptable/inappropriate use, best practice, dos and don’ts etc.?

Every staff member with a standalone device signs the AUP and, when onsite, the device defaults to the staff internet policy, the same as other non-domain/non-AD devices.

Historically, we’ve managed staff standalone devices this way and have never had any incidents. However, I’m now considering whether we should start introducing filtering for off-site/home use as well.

I’m trying to strike a balance between:

  • allowing staff to use the laptops without unnecessary barriers when researching or planning, and
  • maintaining appropriate safeguarding/security measures.

The head also likes the laptops to provide some personal benefit to staff, as quite a few don’t have their own devices at home, so I’m conscious of not making them overly restrictive/intrusive

 

I believe KCSiE only says you need to filter & monitor students. Staff comes down to school policy.

 

We keep the network filter in school for all devices, and rely on Sophos to catch malware at home and block downloading executables (especially now it decrypts HTTPS). When off-site, we only filter students, and the only 1:1 devices we have are the ones we got from the DfE/LA/Daily Mail during COVID that we give to PPG students.

  • Like 1
Posted
12 minutes ago, TechMonkey said:

I'd warn him about using those terms as a benefit could be taxable.

 

My question would be, if the barriers are unnecessary, why are they there during the day?  Or to put it another way, what could they do at home that they can't do in School that would be acceptable in school?

 

A few benefits off the top of my head are things like being able to search for resources that might otherwise be blocked, which avoids staff needing to submit filtering requests once they’re back in school and allows them to complete these tasks more easily.

 

As staff aren’t required to work in the evenings, I also don’t want to put unnecessary barriers in the way and risk losing goodwill over small frustrations, as that can sometimes result in staff simply not bothering to do the additional work.

 

There’s also normal day-to-day personal use such as booking holidays, managing finances, and the usual odd personal tasks while using the laptop, although the vast majority of usage is still school-related work.

Posted

In fact, we viewed the opposite on that JazzFlute.

 

By filtering at home, it enabled us to identify resources they wanted to use in school, and to enable them.

 

Rather than them find it working and home, coming on site and then finding them blocked.

 

It swings both ways, but we do see less requests to unblock things, since we went down this road.

 

Both ways have their pluses mind you

  • Like 4
Posted
1 minute ago, JazzFlute said:

A few benefits off the top of my head are things like being able to search for resources that might otherwise be blocked, which avoids staff needing to submit filtering requests once they’re back in school and allows them to complete these tasks more easily.

 

As staff aren’t required to work in the evenings, I also don’t want to put unnecessary barriers in the way and risk losing goodwill over small frustrations, as that can sometimes result in staff simply not bothering to do the additional work.

 

There’s also normal day-to-day personal use such as booking holidays, managing finances, and the usual odd personal tasks while using the laptop, although the vast majority of usage is still school-related work.

 

But what could they be researching that would be blocked in school, as staff, that it wouldn't be legitimate to unfilter, or that they could use in school? Not trying to be awkward, but what it boils down to is why differentiate?  If it is OK for them to look at home on a work device, then what is the issue them looking at it in school? Either your filters for staff in school are too harsh, meaning staff are more willing to research at home, or you want to allow them to look at questionable things out of work on a work device. I'd be more annoyed as a teacher if I did research at home, set up a lessons worth of tabs or links and then come in the next day to find I can't use them as they are filtered now on the same device.

 

What if they do their 'special' research at home and bring their device in the next day and the tab left open tries to launch.  Filtered or not it is potentially going to be splashed up for the pupils to see.

 

Again, I would be careful creating policy or codifying use based on a personal use case outside of hours.

  • Like 2
Posted

Wow, thank you for such fast responses.

So Ativion StudentKeeper monitors everything as it is recording the screen when devices are online - it goes beyond the web browser to read content on iMessages other apps etc... but I have concerns about whether this is either over the top, or will affect battery life and performance.

What other solutions are schools using that are not as invasive but still complying to the government regulation?... or will we all have to switch to these new solutions?

Posted (edited)

I don’t understand the logic for not filtering staff & locking down the device as normal at home.

 

They are *work* devices; not personal playabout ones. Tell them to buy their own device. It’s not the 90s anymore, laptops aren’t a luxury.
 

I have seen it before in other schools where they weren’t filtered/treat like a normal device and they were riddled with pirated downloaded movies, family photos and games for their kids. You can’t meet the DFE or cyber security  guidelines this way. Then you have the inevitable guilt if the laptop breaks and you have to reimage/wipe out photos. It causes a ton more work for what reason?


 

If a staff member downloads adult content on the work device and it then comes up at work, IT will be asked why it occurred in the first place.

 

Honestly, save yourself and the organisation the hassle of having to deal with the mess. Keep it simple, work devices are work. Home devices are home. 

 

Edited by DrCheese
  • Like 1
Posted

We've ensured all our laptops that go offsite, be it by staff or students, have same level of filtering at home as they do in school.

During covid we did this by making sure all the laptops had Forced User Tunnel configured for our AoVPN we setup so all web traffic came back to school before hitting the school ISP and filter.

These days we just configure them for Device level AoVPN as our web filter now has a browser based extension instead of relying on proxy addresses.

 

We also have Impero on all the devices so it's monitoring content that way and ether reporting back in real time (joys of the VPN) or uploading the data when the device comes back in school.

 

  • Like 1
Posted
18 hours ago, itskdog said:

I remember on the COVID laptop scheme, if you picked a vanilla Windows image rather than the DfE's Intune setup (with Cisco Umbrella for filtering), you had to acknowledge that you were legally required to have a filter on the device.

 

At the time due to limited resources I scrambled and used the Web Control on Sophos, but have since moved to LGfL HomeProtect (branded Netsweeper) as it's included with our broadband.

 

Sorry to Hijack - We use NetSweeper too; but found out you can turn it off via control panel; LGFL weren't much help so are you aware of this loophole, and if so can you share what setting you use to disable this ability?

 

(You can turn it off on the taskbar too, but this requires UAC)

Posted
Just now, Warwick_Tech said:

 

Sorry to Hijack - We use NetSweeper too; but found out you can turn it off via control panel; LGFL weren't much help so are you aware of this loophole, and if so can you share what setting you use to disable this ability?

 

(You can turn it off on the taskbar too, but this requires UAC)

 

Thanks for flagging, was not aware.

 

Fix is probably easy to just disable access to the control panel on 1:1 devices, though. Then they'd have to hunt the .CPL file to execute it. (At least until such time as Microsoft retires the Control Panel completely, though I don't see that happening until at least Windows 15 at this point)

  • Like 1
Posted


I’m trying to gather more information from schools that apply web filtering to staff devices when they are used offsite.

  • What happens to the logs, violations, and blocked pages that appear in your filtering reports?
  • Are any violations or instances of inappropriate use escalated further, and if so, to whom?
  • Who determines what constitutes inappropriate use — is this decided by the IT department, or by another role responsible for reviewing reports and logs?

I’m also interested in understanding monitoring practices:

  • Do any schools actively monitor staff devices offsite using software (for example, tools like Securus that can capture screenshots of violations)?
  • Who has access to potentially sensitive information gathered, such as browsing logs or monitored activity? For example, if a user accesses online banking, NHS services, personal health information, or general shopping, who is able to view or handle that data?

In addition, I’d like to understand how this is communicated to staff:

  • What kind of wording or policies are staff asked to agree to regarding offsite filtering and monitoring?
  • How clearly do these policies explain what data may be captured and how it is used?

My assumption is that where offsite filtering and monitoring applies, personal use of school devices may be discouraged or not permitted at all, given that any activity could be logged by the school or IT department — even if that use is infrequent.

Also, for staff who are issued mobile devices, are these subject to the same filtering and monitoring controls when used offsite?

 

Has anyone created a policy/agreement that they can share that they ask their staff to sign

Posted (edited)
On 08/06/2026 at 15:52, harmless_saucer said:

What other solutions are schools using that are not as invasive but still complying to the government regulation?... or will we all have to switch to these new solutions?

My experience was a decade ago, so this might be out of date. 

We put a policy on the devices (chromebooks) that simply routed all connections through our existing on-premises filter via VPN, so there was no difference between being in-school or anywhere else. This obviously put load on the filter device out of hours (a fortinet thing IIRC), so we had to load balance it to allow for downtime. 

We did allow parents to 'opt-out' of the school filtering. Most didn't. Not sure if that would be acceptable these days. 

Edited by dmj
Posted

All of our staff devices whether in school or at home are filtered and monitored as per our Staff AUP.

They are treated exactly the same - as are any student devices loaned out.

  • Like 1
Posted
9 hours ago, Sylv3r said:

All of our staff devices whether in school or at home are filtered and monitored as per our Staff AUP.

They are treated exactly the same - as are any student devices loaned out.

What happens though when you see violations, misuse  etc. as my last post above?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...