Hey folks,
Apologies if a similar thread has been made before, I couldn't seem to find anything on the subject
We're reviewing how supply accounts/supply laptops are being handled within our schools. These accounts are currently setup on Bromcom, where the corresponding AD account is then made and maintained by Salamander with a rotating password daily. Each account is restricted to logging into an assigned supply laptop (i.e. Supply1 -> SupplyLaptop1, etc). This has worked for a while, but recently a real-world incident has caused us to make changes. The account details can be used to logon to Microsoft 365, i.e. on a student's phone, where they are then able to log onto Bromcom via SSO and make changes (i.e. add/remove behaivour events, etc).
We've thrown around the idea of using Windows Hello PINs per device and rotating them periodically (i.e. every half term, every week, etc). This would solve the above, however another concern that was raised is that we're still not Cyber Essentials compliant.
So, how does your school do "it?" - any thoughts would be greatly appreciated