-
Posts
700 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by TheHyperTechie
-
A couple of Google Credential Provider questions
TheHyperTechie replied to TwistedHelixis's topic in Cloud Services
I can't really comment on using each of the services separately, as we rolled both out together which is recommended from Google. Those devices that you see under Devices > Mobile and Endpoints > Devices, are devices that users from your console have signed into with their work account. The devices you see, will differ according to the level of mobile management you have enabled. If unmanaged, it will just list devices you own that your users have signed into. If set to basic, it will list these along with personal devices e.g if Joe Bloggs has used their iPhone to check their email. This is the same for advanced (I believe) As for the teacher logging in from home on their own PC - It wouldn't be affected, as the device wouldn't have GCPW installed and wouldn't be enrolled into the tenant (Windows Device Management). If you are not using GCPW you enroll the device manually using a link. The only situation I could see this happening in, is if the user downloaded GCPW onto their personal device, and you had the setting applied to the OU they were a member of, to automatically enroll the device into Windows Device Management. Does this help? -
A couple of Google Credential Provider questions
TheHyperTechie replied to TwistedHelixis's topic in Cloud Services
It's just the way that Google displays their documentation, it can be confusing. If you click on the link at the end of the sentence you quoted. It breaks down what GCPW can provide on its own, followed by Windows Device Management. GCPW (on its own): Additional Security SSO experience Password Sync Automatic enrollment into Windows Device Management Windows Device Management: Settings management (custom settings, updates, bitlocker, admin permissions) Device Management (Wipe device, sign users out, audit device activity, unenroll a device) Hope this helps. EDIT - Sure he won't mind, just going to tag @rogerdnixon who is a GCPW/Windows Device Management guru. Roger initially helped me setup my console. I am sure he can provide more info or correct me on any information I have provided. -
A couple of Google Credential Provider questions
TheHyperTechie replied to TwistedHelixis's topic in Cloud Services
1. I have this turned off, I believe (correct me if I am wrong) it requires the devices to be setup using advanced mobile management. We just use basic level - as this is how I inherited the console/setup. I may turn this on at some point though, as for laptops and desktops it only requires Endpoint Verification. 2. I have Windows Device Management enabled at the top (Trust) level OU. You could have it set at a particular OU though. However, the device would only enroll if the user is a member of the OU you have applied it to. -
A couple of Google Credential Provider questions
TheHyperTechie replied to TwistedHelixis's topic in Cloud Services
I don’t leave any local admins on the devices. I just rely on the administrators OU and the account settings option in GCPW. So when I need admin access to a machine, I just log in so the computer recognises my account then sign out/in again (this is standard GCPW behaviour) and my account is elevated to administrator. Honestly I am happy to answer any questions you have. GCPW does have its quirks and isn’t highly documented. I feel that unless you have used it, it’s a minefield to try and find something out. It definitely gave me the occasional headache! -
A couple of Google Credential Provider questions
TheHyperTechie replied to TwistedHelixis's topic in Cloud Services
This setup sounds exactly like mine, the only difference is that I allow the staff members to enroll the device using their Google account rather than a generic one. I have my teachers OU, with all of the relative custom policies added. I apply the main GCPW policies at the root (Trust level) though, as these are settings I would want enabled regardless of the user e.g. update settings, user permissions, and bit locker. For the user permission sections, I do have an override in place to allow the “Administrators” OU admin privileges. This OU contains myself and my assistants account. In regard to a teaching leaving - standard practice for me is/has always been to wipe the device anyway. So I just initiate a reset from the Google admin console, and then redeploy GCPW to it. Luckily I have Action1 to help me with this. -
A couple of Google Credential Provider questions
TheHyperTechie replied to TwistedHelixis's topic in Cloud Services
Just re-read my message. My logic of thinking is actually incorrect (long day!) it wouldn’t matter about the account you used to enroll it, as this would just be signed out of and then you would sign in with your Google account. This would then SSO into chrome and connect the correct profile. -
A couple of Google Credential Provider questions
TheHyperTechie replied to TwistedHelixis's topic in Cloud Services
Hopefully I can help answer these below, please correct me if I am wrong though! 1. The OMA-URI policies are set at the user level according to the OU you assign them to. The only policies that apply at the device level are the top-level ones, including updates, BitLocker, and GCPW settings. So, whichever user signs in first to a device, the device will use the settings applied to that user. It's fixed (if that makes sense). This is the official explanation from Google: "When many users sign in through GCPW on the same device, the first user is enrolled in Windows device management. Their device-level settings (such as Windows updates, admin privileges, and BitLocker encryption) apply to all users of the device." 2. I believe the logic behind this is correct; however, I think it would only work properly with fleets of student devices or IT suites. What about SSO for Chrome? It would prompt all of these devices to log into the same Chrome account. For that reason, I allow all of our teachers to use their own Google accounts. I then applied all of the custom OMA-URI policies to our "teachers" OU. I also made sure to adjust the top-level policies, such as account settings and updates, to ensure they receive the correct level of access on the device (Standard User). I can see the benefit of following this method for student devices though, but our students use chromebooks so we didn't need to implement it. -
Do you pay for their support package? We use iCT4 which is listed as one of their (external) support providers. They are great, I have used Arbor's own support before... and it was as you described. I know they have no obligation to help, but it might be worth a shot to send one of the companies on this list an email. I would highly recommend iCT4 though, and if you are looking for a support provider regardless - go external.
-
A car vs money scenario... Please help me make up my mind!
TheHyperTechie replied to AB_IT's topic in General Chat
Currently going through a similar situation. We bought a (new to us) Peugeot 2008 2016 model less than a year ago. The heating system suddenly packed up about 2 months ago, garage thought they fixed it multiple times. A new resistor, relay, blower motor and £600 later, the issue is still not fixed. They are now telling me its something to do with the on-board computer. Honestly, people criticize PCP and new car schemes but the benefits. No MOT for 3 years, free services, that peace of mind... it may be a route we look down next. -
Stonebook Pro, or Stonebook Edge-R (If you don't mind AMD). Sturdy laptops, with a great warranty.
-
Our central team use this, and have said nothing but good things about it. - https://owllabs.co.uk/products/meeting-owl-3
-
Unifi Training Courses - Who has done them? Review?
TheHyperTechie replied to Noxid_w's topic in Wired Networks
Following, I have been looking at completing a UniFi course for a while. -
ChromeOS Flex? It would make them compliant, but again - there is the cost of £30 per license to manage them.
-
Google Endpoint Education Upgrade
TheHyperTechie replied to ThatBoringBloke's topic in Licensing Questions
Yes, you can use it to manage iPads within the Google console. But my advice would be... don't. There are many better options out there such as Jamf, or Mosyle which is free, albeit slightly limited. But I would look there first -
Haven't used it myself - but I quite often see these advertised - https://www.plaud.ai/ I believe it uses the GPT-4o model.
-
We used Parago for asset management, but recently moved to Every (MAT merge)... Parago worked well for us, was easy to use and navigate. Audit checks were quite simple, just run the app off an iPad. I would not recommend Every though!
-
Hi all, We are in a position now, where we would like our Trust to obtain CSE. I am just wondering what the best route is to start? Did you use an external company to help you through it? or did you just work through the questions yourself? What external company did you use? (if you used one) Thanks!
-
Google Endpoint Education Upgrade
TheHyperTechie replied to ThatBoringBloke's topic in Licensing Questions
No worries, one thing I will add - if you choose to go with one of education licensing tiers (standard or plus) you have to license all of the users in your tenant. You can't just license staff for example...! -
Google Endpoint Education Upgrade
TheHyperTechie replied to ThatBoringBloke's topic in Licensing Questions
Hi, yes, the licenses you have mentioned would allow you to manage Windows devices with their "enhanced desktop protection." However, you're better off just upgrading your licensing to Education Standard or Plus, as Windows device management is included in those licensing tiers anyway. We have Education Standard, which allowed me to set up GCPW and enroll our Windows devices into Googles Windows device management setup. It does have its quirks and annoyances, but Intune wasn't a good fit for us at the time, and to be honest, no platform tends to be perfect. Each staff laptop/desktop is assigned to their Google account, which in turn has settings applied to it. I manage the updates, user access level, BitLocker at the top level, and then apply custom settings (OMA-URIs, similar to Intune) to the individual OUs. This can include things like hiding settings, blocking unenrollment, disabling OneDrive, and setting a wallpaper. Hope this helps, and please let me know if you have any more questions! -
Classroom management - Chromebooks...
TheHyperTechie replied to TheHyperTechie's topic in Cloud Services
Hi Tom, thanks for your comment - do you mind sharing how much this costs per device/user? -
Classroom management - Chromebooks...
TheHyperTechie replied to TheHyperTechie's topic in Cloud Services
Thanks! do you mind sharing how much this costs? we only require it for our KS2 chromebooks which is about ~200 -
Hi all, We're exploring the implementation of a classroom management tool to help teachers manage student Chromebooks during class. The idea is to provide features such as, Remotely freezing student screens. Viewing student screens in real time. Other functionalities to support classroom productivity and focus. So far, I’ve come across Impero and Classroom.cloud, but I’d love to hear about any other tools or solutions you’ve used and would recommend. TIA.
-
Only one option in my opinion - Sign in App Easy to setup, support is helpful, lots of available add-ons, and it just... works!
- 31 replies
-
- 1
-
-
- paxton
- sims integration
-
(and 2 more)
Tagged with:
