I'm going through this exact dilemma here. BYOD became compulsory for older students.
We require certificates for students and of course many of them either get a new laptop, borrow one from a sibling/parent/friend, or a particular device or antivirus may not like the certificate or some sort parental control feature makes it difficult to install or a parent is the device’s admin and child does not know the password.
I would say this sort of issue accounts for 90% of students not being able to navigate to the internet.
On top of that, sometimes we have genuine slowness due to all the filtering rules and ssl inspection.
User perception (students) is of course that the school internet is slow and the WiFi does not work. And this is the perfect excuse for students to claim that they “need to use their hotspot to do their classwork”.
I am therefore seriously considering removing the need for certificates, at least for the older ones, 16+.
Students authenticate using their AD credentials. If there is no certificate, they can’ go out to the internet, only navigate the Intranet page.
The SSID they use is separate from the one used with school-owned devices so they cannot access file server for instance.
Our Fortigate will continue to have all the category filtering which blocks social media, games and the no-go sites.
Given we will still have web filtering, how risky would it be to remove the need for certificates?