Jump to content

Allowing school laptops to be used outside the network?


Recommended Posts

Posted

I have seen topics with mention of this on here and very mixed views but with a new batch of CLT laptops coming very soon and the increasing requests for them to be able to use them both in school and on their networks at home I was wondering what the best method is. We currently operate a policy of a device used in school on the network remains on the network, if a staff member wants to use it on their home network then it shall be removed from ours permantly or until we have checked it over before allowing it back on.

 

We also currently use Sophos and although im yet to read much into it would Sophos NAC be able to assist this task? I'm also yet to look into offline documents but its something which would be really useful to staff, if anyone has any advice or genral things to look out for then please let me know as this would be great!

 

Thanks,

Posted
Regards Sophos, you can configure it so that if the device is not attached to the network it will seek out a secondary - in this case on-line - location from which to obtain its updates.
Posted

The majority of mine are off the network. When i have tried to set them up like that ive not had much luck (my fault probably!). Sophos seems to do its job, but then i think a lot of our staff use them more at home then in school anyway as they have PCs in there rooms.

 

Do your staff move around a lot?

Posted

We have always kept ours off the network as most teachers want to do their own thing with them, they can always get to their work via remote access either in the school or out of the school.

 

I do find that laptops are a good way of pushing the latest applications out to the teachers first before introducing them on the network as this gives the staff time to adjust to the differences from the older apps.

 

It has worked for us for the past 8 years and continues to work very well, not much to do with them except image beforehand and then when they come back after the installation of everything off the net we just rebuild from image, update and then re-image ready for the next time. Build is Windows 7, Office 2010 with Microsoft Essentials as the AV and malware manager. Any other packages which they use in the line of their duty is installed and that's it.

 

It works just fine for them and they appreciate the fast turnaround.

 

Unfortunately as from last year the school policy is "No more laptops for Teachers or other Staff" in future they have to purchase their own. :)

  • Thanks 1
Posted
Ours are on the domain and staff are free to take them home. We have McAfee which will happily sit working away with a virus installed anyway 8(. We have recently re-imaged every laptop with windows 7 enterprise with the intention of making use of encryption school wide.
Posted

For our domain laptops that leave school we use Sophos with a secondary online server (no proxy) so it can update at home. We also have them set up with offline files so staff can work at home on their work which then syncs with the servers when coming back to school, and we have TrueCrypt installed for encyrption of any machine that leaves school.

 

So far we've not had many problems virus wise, and offline files works well (as long as you don't sync your network shares).

Posted
They arn't moved around alot no but staff have shown they would like to have more freedom and asked us if possible. They currently have access to their documents via the LG and sharepoint anyway so its not too bad
Posted
We have always kept ours off the network as most teachers want to do their own thing with them, they can always get to their work via remote access either in the school or out of the school.

 

I do find that laptops are a good way of pushing the latest applications out to the teachers first before introducing them on the network as this gives the staff time to adjust to the differences from the older apps.

 

It has worked for us for the past 8 years and continues to work very well, not much to do with them except image beforehand and then when they come back after the installation of everything off the net we just rebuild from image, update and then re-image ready for the next time. Build is Windows 7, Office 2010 with Microsoft Essentials as the AV and malware manager. Any other packages which they use in the line of their duty is installed and that's it.

 

It works just fine for them and they appreciate the fast turnaround.

 

Unfortunately as from last year the school policy is "No more laptops for Teachers or other Staff" in future they have to purchase their own. :)

 

The big problem for us is getting them in - SLT won't 'insist' and on a voluntary basis the most we've had for a summer rebuild is about 30%!!

Posted
Unfortunately as from last year the school policy is "No more laptops for Teachers or other Staff" in future they have to purchase their own. :)

 

What! Eugh, i could only wish for such a thing! Ive been told by a member of staff today that she is putting in a letter of complaint because she doesnt have a laptop. She does have one, sat with me, but its a complete brick! Unfortunately my wand ran out of fairy dust so cant make it work better. PLUS this is the woman who complained her laptop wouldnt work and it was because the battery was completely flat and she hadnt plugged it in...

 

Sorry, rant over! lol Back to the thread....

Posted

Ours are also on the domain and they are free to take them home.

 

We give them a separate local admin user to do whatever they want with it.

Posted
We're about to start looking at client hypervisors, so that they have a fully supported school network build for in-school with full connectivity (offline files etc, but if taken out of the school will not connect to a network), and a seperate "home" installation which they can do whatever they want with (except connect to the schools network).. if they break that, the work one will still be fine. Lots of settings etc to check through, but would certainly solve some of the problems we see. The carrot of the home version should work.
Posted

Our staff log in to their laptop, we then set their user account to be a local admin so they can add home printers. They have a proxy .pac file to they can access the internet at home. Offline files is set up so they can work on files at home.

 

Our staff wouldn't be able to cope with two accounts. Nor would they understand the difference!

Posted

Our staff have a seperate local user account that they use at home. We don't have offline files set up but I think if you have offline files and add their account to be a local admin on the laptop for when they are at home that would be the best option.

 

McAfee AV seems to keep the viruses etc out for us :)

Posted

In Birmingham schools, there should be a Primary Sophos instance for updates within the school network and a Secondary instance hosted at the LA for laptops used at home.

 

Once all policies are setup properly, everything just works. I join laptops to the school domain so it means staff receive Sophos, Microsoft Updates and newly deployed MSIs.

 

Staff use two separate accounts - jbloggs for domain logon and .\jbloggs for local logon to their own laptop only.

 

Optionally staff use VPN to access their files remotely.

Posted

We give them a separate local admin user to do whatever they want with it.

 

We used to do that, have since switched to an offline files method of doing things so they logon with the same username + pw on and offline, with their home folders synced.

 

Most staff are then setup as standard users so they can't break it, with the odd few who really can't do without admin rights being given local admin to the same account to install stuff.

Posted

Why pay for laptops if they are only going to be used on the network on site? Surely a desktop or netbook with Terminal Services would be much cheaper.

 

I've never understood this reluctance to let staff use their laptops as they need and want to. Yes it may be the schools, but at the end of the day we're always complaining about teaching staff IT literacy and some folks then go and lock staff machines down so they can barely use them.

 

Ours are on the domain, staff have local admin rights. Sophos AV updates from a secondary source provided by the LEA, and they are all encrypted with Sophos Safeguard. I also use LANSweeper to report on software installed, and give them all the copyright and virus reminder each term. No one has abused this. Their home page is set to Sharepoint which is in the proxy exceptions list. So on site they log straight in, and when at home they get the Forefront web login page.

 

Staff actually comment on how much better it is compared to other schools where they were severely restricted.

 

My father in laws old school (retired physics teacher) locked down staff laptops so staff could only use white listed applications. Anything else had to be trialed by the IT Support department, approved by them and then installed by them. Talk about restricting innovation!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...