Planehazza
Members-
Posts
323 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Planehazza
-
Wish us luck, send flower to my funeral... We've turned a blind eye to iPad student internet tracking for too long. Yes, they've been filtered and tied to 1:1 pseudo accounts, but after I reminded them we were averaging 1.5 alerts per day across the trust and we had no way of tracking who was using any of the 600 iPads, our hand was forced and I've implemented Shared iPad mode, federated against Google. Some staff are very unhappy that it's too hard, but we just have to use Safeguarding to quieten them again. Anyone else been in this position? Teachers spouting safeguarding left, right, and centre, but heaven forbid they have to teach kids IT skills in an IT lesson, using a very simple user guide I created for them...
-
I guess another way to think of it is you're more likely to get backing from money people to ditch them now.
-
Clever - QR code Sign In for Chromebooks
Planehazza replied to Planehazza's topic in ChromeOS & Cloud Based OS
Oh I don't know real pain. I thought I did, but we're rolling out shared iPad mode across the whole trust, including KS1. Wish me luck. Drinking at work in schools is generally frowned upon, right? Just checking... 😂 -
Clever - QR code Sign In for Chromebooks
Planehazza replied to Planehazza's topic in ChromeOS & Cloud Based OS
Another bump to this but cloudwise are no more I believe, or were bought out or something. I'm in the process of implement Clever at our trust, employing the SSO feature for QR badge logins for KS1 and KS2, which is all free now. It's the MFA you now pay for and it's actually not too pricey. -
Honestly it depends on who installs it. We've got it in 8 schools and every install is different. Good luck getting them all consistent, especially if you have more than one domain. Their product was all the rage 5 years ago, but now it's overly complicated and their support is abysmal.
-
We're going through procurement process in Q4 so I can ask, but I suspect you'll have an answer by then.
-
Thanks Ben, and for just validating how I feel with this. It's nuts. I'm already a but miffed with these iPads, as we're rolling out Shared iPad for ALL devices, including KS1. It was my idea as we've no other way of keeping them compliant with KCSIE without relying on teachers to keep track etc. They're going to hate them and me, but we've reminded them how dangerous these are when I've showed them we've averaged an alert a day on the current system, and we don't know who uses which device currently... I'm anxious, but content in my choice. OK, so if you'd be so kind, please hear me out... I can have a single default policy that applies to all the names them say iPad-{{serialnumber}} then add the devices to the Site1-iPad All/Site 2 - iPad Students etc groups to which another policy is set with a different template? Them having Site1 etc in the name isn't crucial; what's crucial is easy, quick software to hardware identification for group assignment. Being shared mode, I can't simply enter a pin to go to Settings > General > about and the serial on the back is tiny. Of course this begs the question of asset management - why don't they have tags on them etc. That's another resource/time question...
-
Yep, ipads. I wonder if I've just misunderstood these enrolment policies then. I thought they applied at enrolment and only then? Surely I don't need to have multiple policies for each batch? It's going to be a lot overhead. I have got 600 devices linked in Intune to ASM. Really don't fancy manually assigning a policy one by one. Ans if these policies override names every time ASM and Intune sync, what is the point in a device rename feature MDM side? Or is there a way to remove enrolled devices from the scope of the enrollment profile once they're on boarded? Sorry I'm either just not understanding something here or this is pure madness?
-
Yep, we're not currently enrolling any devices and yet the number is now 25 devices. Why is the naming template on the enrolment profile renaming previously enrolled devices? This is madness, and is going to make it mental to manage the devices. I wonder if I need to set up separate sites per school in ASM then have a token for each so I can have different enrolment polices per site. What a nightmare this is, total garbage
-
Feel like I'm going crazy, but i'm 99% sure the enrolment polict that sets the device name at enrolment is renaming previously enroled devices. I thought I saw it happen at the last school and figured I'd bulk renamed the wrong group. Now at the second site, different site prefix and I'm seeing 20 devices checked in with the new prefix. We've only enrolled 14! Why's it doing this?
-
Intune - iOS App Deployment - A better way?
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
I thought about those but the issue I'm having (compounded by the fact we're reluctantly enforcing shared iPad mode KS1 through KS4 and staff) is I'm struggling to find a way to name them in bulk quickly and easily. I'm hacving to go through 600 iPads to wipe and enrol to Intune and am doing it as methodically as I can to leverage enrolment policy naming templates, but it's hit and miss and something has gone and renamed previously enrolled devices too 🤦 -
Deploying apps is tedious. We have 8 schools using ~600 ipads, and each school requests different apps, blah blah. I have the iPads in nest groups, ie Trust All iPads > School All iPads > School Student iPads > School KS1 iPads Trust All iPads > School All iPads > School Student iPads > School KS2 iPads etc## This way I can block Safari etc. and trust level, or ban settings at staff/student levels once. I've got quite nice targeting options. Deploying an app to KS1 iPads at school 1, then KS2 iPads and schools 2 and 3 etc, is going to take a lot of time especially if we have nearly 100 apps etc. Do you guys take a similar approach to SCCM? Have a group for each app then just add device groups into app groups? I'm just thinking out loud that this will be fast for subsequent deployments?
-
Lightspeed - Bulk wipe with return to service?
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
Formal answer from Lightspeed is no. -
I think we're giving them notice they're getting binned. Dire product and support now. I'm praying I can convince the powers to choose SignIn App
-
Lightspeed - Bulk wipe with return to service?
Planehazza replied to Planehazza's topic in Mobile Devices & Tablets
I should add that my current work around is an open wifi hotspot with the correct WiFi profile deployed, so I can get them online by selecting the SSID and not entering a password. Still quite slow though -
Lightspeed - Bulk wipe with return to service?
Planehazza posted a topic in Mobile Devices & Tablets
Lightspeed leverages a return to service tickbox which keeps a wifi profile on the device so you can hands off enrol it to the MDM assigned in ASM. VERY handy when dealing with one device. However, I need to remove erase 597 devices and push them across to Intune. Anyone know of a way, using Lightspeed or ASM to remotely wipe devices in bulk, whilst keeping them on WiFi for quick enrolment? -
iPad Lightspeed Configure Screen Layout
Planehazza replied to gpjt's topic in Mobile Devices & Tablets
Yep, works pretty well. As you say, at root level you create the layout, then at the OU/School/Group level you assign it. Works pretty quickly for me, but I find when dealing with many apps and many devices, instructions get lost and never arrive. Use the clear activities then trigger a resync. See if that helps? -
Intune app config - Smoothwall browser iPad
Planehazza replied to steveg's topic in Mobile Devices & Tablets
It really is. What age range was this with? We're trying to find a solutions for KS1 and it's a nightmare -
Intune app config - Smoothwall browser iPad
Planehazza replied to steveg's topic in Mobile Devices & Tablets
Having this same issue too. We've moved to (well I was planning to) Shared iPad mode in order to make students log into iPads to monitoring, but I can't seem to find a way of getting 'logged in' user or current manage apple ID to forward through to Smoothwall Browser. AppleId, userId, userprincipalname etc all fail. I can get SSO against Google to work, but then that defeats the purpose of shared ipad mode especially given that Smoothwall can only filter and monitor their browser - I might as well abandon shared iPad mode and have them sign into the browser. iPads for KS1 are an utter nightmare but we cannot get the schools to give them up... -
Hi all, thread bump. This topic is one that's been a concern of mine for a long time. Lack of funding and interest elsewhere has made progressing this impossible, but I've been given a potential go ahead to source solutions. It seems a lot of places are in the same boat, and I empathise with their concerns. KS1 kids are too young to log into devices with their individual accounts, yet I believe this is now mandated or at least set from DfE? Either way, teachers logging in Chromebooks with their accounts for kids is NOT a solution and we witness this daily with no consequence 😅🤷 Tomorrow I am tech demonstrating Shared iPad mode for student iPads and I expect this to go down like a lead balloon. I'm trying to sell it down the safeguarding path. especially given just how many lightspeed alerts we get daily. I've got a meeting today with Wonde to discuss MyLogin, and I want to speak again with Clever. Just wondering what you guys are doing with iPads and simple logins for KS1? I feel for the teachers, but we've got to keep students safe so I'm going to be pushing Shared iPad mode hard. We use Google so would be looking to federate either solution against that, but we are also looking to Federate Google against M365 down the line too for Intune etc. It's getting complicated quickly!
-
Tried both. Can't tackle it retrospectively; every student and their dog will try once the knowledge spreads. We must get Edge blocked or extensions blocked at the very least. Thankfully our Meraki is stopping access to most dangerous things, but VPNs are a major risk if they can be installed as an extension
-
Thread necro, but getting same issues. Kids installing VPNs. W11 is awful to manage. Can't get AppLocker to block Edge, and GPResult and edge://policy show the GPOs blocking extensions being applied, and yet extensions are installing.
-
Thanks, will look into this! Much appreciated.
-
Ooh interesting. would you be able to share any more on this please? We too are Google primarily, but have an M365 footprint for PowerBI and Intune. Right now, we have no SSO, but passwords sync from AD to Google to make lives a little easier, but full on SSO between Google and AD/Entra would be great. I was originally looking to have Google as the IdP but this might make more sense?
-
Hi all, We're moving to Intune after I've pushed for it for years. We currently 'manage' (Ha!) roaming laptops by domain joining them and relying on users signing in on site then using cached profiles externally. Yep, I know, let's skip past this... We have a few hundred devices in SCCM, v2309 (will be updating to latest in coming weeks) so I'm thinking co management is probably the best solution. We have Entra ID Sync (on prem agent) in place, and we're a Google site so I'll need some M365 tweaks and Intune configs to prevent access to M365 resources. We literally need to use M365/Entra for sign in and device enrolment, and may look to juts federate against Google in time also (I'd ditch Google in a second if I had the option/power). So, I'm thinking remove laptops from domain join and have Intune handle restritions and app deployment, but I'm a little fuzzy on the best way to tackle this. Should I look to build to handle existing devices in SCCM, or just purge and redeploy them all? We'll not be looking to use autopilot any time soon, so will be relying on (likely a cut down, tweaked) task sequence to image devices and enrol to Intune. Would love any advice and tips please, and apologies for the vagueness... going into this not blind, but perhaps naive. I'm teaching myself as I go. Thanks!
