Allie
Members-
Posts
24 -
Joined
-
Last visited
Reputation
308 ExcellentAbout Allie

Personal Information
-
Location
London
-
Correct, thus it went to resellers instead, because Apple didn't bid, it went to them by default. Since Apple no longer has to provide the 3-year to unis on the framework, they probably didn't see the reason to continue to offer it to students when they don't anywhere else in the world.
-
Doesn't fly in a functioning newsroom either, actually... we actually produced news that went on air, those were mission critical systems. I didn't love even a second of downtime, but it had to be done. That was not my favourite situation at all :/
-
Oh, I agree! I'm not sure how you'd deal with things like the situation I had in a secondary school. But for staff, I'm surprised how different it is. I would have expected the staff relationship to be very similar.
-
In our case, the product that required it was a rather old version of Avid ISIS Client Manager (that was the latest that could be used with our ISIS). In theory it didn't require it, but it was the only way to get it running consistently, and Avid support recommended this.
-
Thank you very much. We don't have that setup yet, but that's on a "later this year" goal list - once we start managing with Casper Suite. Again, I'm very sorry for passing along incorrect info I was told elsewhere. I guess that's why you're here though, and I appreciate it very much!
-
Thank you Charli, that's very good to know! My apologies for the misunderstanding! It was a fellow IT manager at another university, not an official source at Stone. I'll tell him that you do offer it. One question though, and I'm not familiar with it yet, is it easy for us to mix and match resellers we used when we start using DEP? I know I can go back and enroll about seven years of purchases (according to the JAMF training people), but is it going to be easy for me to enroll my old Apple orders, my Academia orders, and any orders for, for example Stone (or XMA or Insight if they come in cheaper).
-
This whole situation makes me even more sceptical of leasing than I already was (I think it's rarely good value for money as kit often has useful life to the school long after its defined life cycle - it can get given to projects and labs with worse funding for example). But for them to make the OP re-image machines adds so much time that the value of the lease vanishes even further.
-
Others have pointed out that this is way beyond your job, but excessively controlling users so they bend to your will and tastes seems to be a theme around here among some people, but I'd like to point out the technical and educational problems as well. One, it's part of the MS core fonts. It's reasonable for a software developer to assume it will exist on every Windows machine, deleting it might break some things. Two, it's reasonable to have the entire MS core set for education - including teaching students about good design and why NOT to use it. You wouldn't want to prevent that, would you?
-
Who wants to bet this is related to the National HE Apple Agreement framework going to resellers instead of Apple directly?
-
Get yourself a Mac to manage it. Explain that it's a cost that's necessary. It can be very low end, but you'll need something. You can easily join it to AD. Password changes are a pain, but they'll get used to it (when it asks for the keychain password, that's the old password). See: https://support.apple.com/en-au/HT201609 . Some third party tools can help. GPOs are Windows only and don't apply. Use Profile Manager. Mourn for the loss of Workgroup Manager. When you inevitably get more Macs, look for a solution like Casper Suite. Any decent print server will work just fine, same with file sharing. I've never used or heard of SIMS/DISCOVER so I'll leave that one to someone else. Hope this helps. I have years of experience managing Macs in education, so please do let me know if you need anything specific.
-
Exactly, and I understand not giving local admin on PCs more. For me, the reality is a lot of specialised software needs local admin rights. At the last uni I was at, we had one lab where ALL students who had login permission on the machine got local admin rights. Why? Avid newsroom software won't run properly without it! Insanity, right? Did I LIKE giving students local admin rights? Of course not. But I also didn't lose sleep over it. I had backups, I had version control, I had an imaging server and could re-image a PC on a second's notice if anything seemed at all wrong on it, and in 15 minutes or less it'd be all fixed and ready to go no matter what a student broke (and that was very rare - only twice, and students who did break anything were very apologetic - they both realised what they did wrong the moment it happened, reported it to us, and we re-imaged devices... no big deal). Local admin sometimes means more headaches, but not giving local admin doesn't prevent the worst issues. Cryptolocker can still destroy anything someone can write to, necessitating solid endpoint protection and version control anyway to protect data. Licensing compliance is better handled by asset management software than by simply blocking installs. Policy can still restrict items you want to restrict, even if users have local admin - having local admin need not be all-powerful (though there's very little I restrict, in reality). Staff and students are my partners in this, and ultimately IT is about serving them and making things work better to advance their studies. They're dedicated researchers who are either highly respected (staff) or are paying a lot of money to study and commit years of their life in pursuit of what they're doing. They're not going around deliberately trying to break machines, and they're generally very responsible people. We trust them with everything else on the campus, including things like highly toxic chemicals, incredibly personal research data, and sensitive experiments - why would we lose that trust with IT? I understand that most of you do NOT have that trusted partner relationship with your students, but you certainly do with your staff, I would think? It's fascinating to me how different of a world it is.
-
Thanks! Sorry for not understanding this, I've only been interested in device assignments so I didn't know! It's an option.
-
How I view it, but how can you revoke an app given to an Apple ID? I haven't tried, but I thought they could only be revoked if assigned to a device. I am absolutely not arguing against MDM, just against the level of restriction on staff. Maybe it's different in a university, but I can't imagine the revolt my staff would create if I gave them iPads with any restrictions on what they could install.
-
Fair point, as I noted at the end of my post. I still find it strange to apply the level of restriction one would apply to students, to staff.
-
Exactly. I just registered for this forum and frankly, the level of restriction it seems most people on here use on their staff is baffling. If I tried to tell a professor doing research programming they couldn't have admin rights on a computer, they'd never accept it. Much less telling someone they can't have YouTube/anything on an iPad. Also, I think it's very important that you be careful with talking about reporting someone. Our only job in IT is to monitor performance and operation of equipment. It isn't IT's job to report what is not "appropriate" much less what is not "relevant". The uni I work for actually makes this very clear in our policies, and clear that if we are investigating operational issues and stumble across a legal or HR issue, we're to immediately stop, report it up the chain, and get out of the situation. We're not law enforcement, or HR enforcement. We're IT. I've stumbled across a lot of interesting things, including porn, at my last university. None of it reported, as no laws were being broken, no one was endanger, and I'm certainly not HR policy enforcement. Why would you want to take on that job? To that end, I manage iPads the same way I manage computers - the goal is to restrict as little as possible to meet the goals of secure, supportable operation. If a staff member wants local admin rights, they get it after acknowledging the risks in writing. If they want firewall restrictions changed (some want SSH, etc), they get it, after filling out an information security form required by policy. And if they want YouTube or any other 17+ app they feel is relevant to their job, they certainly get it, with their own AppleID. My interest is in preventing viruses, protecting data (enforcing encryption, secure passwords, etc), and supporting the academic mission of the university by providing repair and technical support. I'm not interested in what is "relevant" to someone's job or what is "appropriate". What do those words even mean? Even, at the extreme, the study of hardcore porn could have a relevant place in an anthropology course or similar. P.S. This view is obviously shaped by the fact I'm the IT manager for a very research-heavy and technically-minded department at a university, and I provide technology for staff and mostly post-graduate students (with a small number of undergraduates with specific computing needs). Obviously, if I was supporting primary/secondary it'd be much different in terms of my argument that appropriateness doesn't matter. However, I'd still argue it's not an IT job - and I certainly would never want to work in IT if my boss was asking me to also play appropriateness cop. If I run across something, that's one thing. But I would never feel comfortable proactively looking for violations. I make computers work, I'm not a cop or a private investigator.
