rogerdnixon
Members-
Posts
667 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by rogerdnixon
-
We whitelist apps and API access for all users. On the staff/students sites, there is a link to a form to request access to an app/extension. We check them out and approve as appropriate. Same goes for Android apps on Chromebooks. Users can browse the entire store but only add/authorise what we allow. Most ket addons (Formmule, Autocrat, Copydown etc) are deployed centrall anyways via the Admin marketplace - so are just there for users. We addons, for the most part they are scripts (which in theory the user could make themselves themselves) and jst run on the local G Suite user and don't give any data to third parties. You can do lots of cool stuff and build loads of systems with addons - we sort of run on lots of them - never been a problems - but we do manage quite carefully.
-
Comodo do them - can buy in bulk - or free individual one. Did a blog post about it: https://wpsit.blogspot.com/2018/06/smime-email-signature-and-encryption.html
-
Just for info S/MIME and DLP rules are now available (at least on our domain). Set a few users up with S/MIME which seems to work as expected.
-
Just one Classroom per class - not per period. You can have multiple teachers per class.
-
We use Classroom with all teaching groups. So every timetabled class gets a Google Classroom associated with it. Teachers use it to communicate with their classes, share resources, set assignments/homework and to give feedback. Parents also get the daily/weekly updates on set work. I sync Classroom to SIMS using a few scheduled reports and GAM. However, there are lots of ways of doing this. Classroom is also used for staff training courses and some out of school clubs.
-
Linus Tech Tips?
-
Online Application Forms
rogerdnixon replied to davipton's topic in Data Protection & Information Handling
We use Google Forms. Data goes directly into a spreadsheet. Autocrat add-on merges some the data and send out a pdf summary to the applicant after they submit the form. Head of Sixth form has a notification rule on the sheet and gets the daily digest emailed to him. -
Its coming as a standard feature to G Suite for Education very soon along with DLP rules.
-
Have you considered using Chromecast for Education? Works well for us and requires no extra hardware - just pushing the extension to teachers.
-
Viable Alternatives to K9 Webprotection
rogerdnixon replied to browolf's topic in Internet Related/Filtering/Firewall
It's not been an issue for us. We are very clear to all users that activity on school accounts is monitored. -
Viable Alternatives to K9 Webprotection
rogerdnixon replied to browolf's topic in Internet Related/Filtering/Firewall
At home, it will only work on devices where the Securly extension is present. So the user would need to sign into Chrome with their school account. So if they were on a private PC and used a different browser or none school account, then there would be nothing. Offsite its aimed at Chromebooks which are managed and restricted to your domain only - so they get the extension etc. Private devices are not affected. -
In the filter, top left - select just disabled devices rather than all devices. Then you will have the option. Or you can click on the device and open up all the info about it and the option is there as well. The options in that menu as not active when you have all devices selected. You can do it via commandline with GAM as well.
-
Yes - same here - about two/three days for a custom directory to sort itself out.
-
I'd suggest taking a look in Vault and seeing what it says + looking in the email audit logs. Also give Google support a call and they can work out from the full message details why a message has been marked as SPAM.
-
I'd check that email authentication is setup correctly. So pick a message and select "show Original Message". You pass SPF and DKIM (and ideally DMARC). Without DKIM it will go into SPAM by default. If thats OK - you might find that the specific user has marked it as SPAM. I'd avoid whitelisting your domain as that leaves you open to attack if you have one compromised account. If authentication is correctly configured, it should not be needed.
-
Viable Alternatives to K9 Webprotection
rogerdnixon replied to browolf's topic in Internet Related/Filtering/Firewall
We use Securly on Chromebooks for this. Their basic product is free. The paid for product which we use allows guardians to control the offsite filtering if you allow it. We also use it for all our onsite filtering as well. Easy to use, setup and manage. You do need either G Suite or Azure AD. -
Email filtering in G Suite is excellent. If you put the SPAM filter on aggressive - only the best-behaved emails get through. We use admin quarantine to quarantine all SPAM (so users never se anything in their SPAM folder). We have also recently enabled the latest features which give users very explicit warning about anything remotely dodgy.
-
If you are going G Suite, then you might want to take a look at Securly. We use it here (1150 1:1 Chromebooks, PCs, Macs) and it just works - no slowdowns. Been very impressed. Authentication is done against users G Suite account.
-
We use Google Classroom + Sites. You can auto provision Classroom and manage parents using a few scheduled SIMS reports + GAM. Very easy for staff and students to use and largely looks after itself once setup. This coupled with a few Sheets scripts to pull all the assignment data into one place for central tracking and monitoring.
-
There are various approached to using Chromebooks. Currently we have an examuser G Suite account. The policies set on this user mean every url is blocked except for our Ericom AccessNow url which is set to open automatically. They then sign in as an assigned exam user (an AD account). This AD use has no internet access and has access to a network share with a folder that they and the exams office has access. So they just go to the share and open up the template in Word (spellcheck disabled) and edit it. Seems to work fine. If you had dedicated machines, you could set them up in kiosk mode and launch the Android version of Docs (or any other editor) and save the file to a usb key at the end.
-
I've not used the free offering so I don't know what the reporting looks like on that. For the alerts (Filtering + Auditor) I set up a group which is where all the alerts go and have members of the safeguarding team as members - so they get a digest every 25 alerts. I've also setup members of the safeguarding team as a group of staff users (not sure if this is a thing on the free one). This means they can login and run searches for activity and pull up browsing/search history for student users. I've never had a need for a "whole use" export - but you can always submit a feature request if you want some other form of report. With a Sheets script you could probably pull all the alert emails into a Sheet and do stuff with it if you wanted to. What we have found nice is that you can deligate most stuff away from IT Support (so we just block/allow the occasional thing) and the interface is simple enough for the safeguarding people to do their stuff without having any real training.
-
We use the full product - so its filtering for everything - byod/PCs and ChromeOS - I've done two blogs on the product: https://wpsit.blogspot.co.uk/2016/08/securly-web-filtering-some-deployment.html https://wpsit.blogspot.co.uk/2017/10/automate-securly-guardians-upload-from.html Link to the best practice guides: https://support.securly.com/hc/en-us/articles/217632758-Best-Practices-Guides A lot of the stuff in the blogs relates to the full product and some of my initial issues (like the google.ie thing) have been fixed. The ChromeOS deployment is really just pushing the extension and making sure you lock down your devices as in the best practice guide. Pretty quick and simple to deploy. If you are a full G Suite setup - I'd recommend the full product - the parental portal is very good and is a hit with our parents. We use it alongside a Virgin Media leased line and ClearOS (free community edition) based firewall/router VMs - removes the need for costly onsite filtering appliances while having very granualar filtering and reporting.
