Showing posts with label student. Show all posts
Showing posts with label student. Show all posts

Friday, May 4, 2012

Why you should ban USB drives at school

After spending hours restoring desktops recently, which a clever student had booted from a rogue USB flash drive loaded with Malware, it dawned on me that the convenience of these handy little gadgets might just be overrated. And when combined with the benefits of the cloud, specifically the free cloud available to students via the Office 365 (live@edu) service, the risks vs. benefit ratio has clearly tipped towards risk.

I know it seems like such a simple way to transport data like homework, projects, photos, etc, but it also just as easy to transport utilities that can destroy the hard drives on your computers, take direct control of the underlying computer hardware, or modify computer registry errors in a way that is nearly impossible to repair.

You may have the very best security practices in place, such as a perimeter Unified Threat Management (UTM) device, endpoint Anti-Virus protection, and separate VLans (network isolation), and yet be vulnerable to a meltdown caused by a free download from the Internet attached directly onto a PC in your school. It is nearly impossible to guarantee computer security if there is physical access to the device.

Banning USB devices is one of the simplest and most effective ways to reduce the cost of network administration in your school.

But aside from the security aspects, there are also some real practical benefits of tossing those USB drives. Let’s take a look at the advantages to see if they don’t, in your specific circumstance, outweigh the benefits.

Here are the top 10 reasons why you should ban USB drives at your school, in favor of the cloud:
  • 10) Eliminate the cost of purchasing the hardware. At $5.00 - $75.00 ea. (depending on capacity), you could save a bundle of money.
  • 9) Reduce the cost of managing the devices – tracking these identical (presumably) looking devices and accounting for them can be burdensome.
  • 8) Avoid the cost of replacing the devices – responsibility for replacing the drives when they are lost; placing identity (ownership) upon them is difficult.
  • 7) Reduce plagiarism - unauthorized sharing of work is nearly impossible to detect and prevent while using a flash drive.
  • 6) Improve collaboration – accountable sharing of work is possible in the cloud, impossible on a flash drive.
  • 5) Reduce support costs – time spent unnecessarily managing infected or otherwise misconfigured hardware is a real cost.
  • 4) Lower the cost of your infrastructure – spending money on student servers can in most cases be completely eliminated.
  • 3) Improving teacher to student interaction – with cloud based services, teachers can simultaneously push information to an entire class of students.
  • 2) Increase student access to teachers – individual work can be made available to teachers with no extra effort by the student other than saving the work to their private cloud space.
  • 1) Eliminating the excuse of “I forgot my homework, it's on my flash drive!” Homework is always a device away (computer, tablet, phone, etc). Presuming it is done, of course!

There you have it, ten solid reasons to ban flash drives from your school.

Now if you are more gently persuaded, have plenty of resources, and don’t want to offend anyone’s sensitivities, you could adopt a more persuasive approach to the matter by making cloud services available to your students and making flash drives subject to inspection if used on school computers.

Given the chance, smart students will quickly realize the tremendous advantages of using their own private cloud and soon leave their flash drives at home.

Friday, March 23, 2012

Driving Efficiencies in Desktop Administration

Let’s do a quick math test to give you an idea of the time typically spent doing routine maintenance on the computers in your school and then discuss ways you can dramatically cut those time requirements. We’ ll use round numbers to make it easy, starting with the assumption that you have 100 computers to manage.

At least once each month, you should be doing software updates, security patches, and system scans – the routine maintenance that keeps computers in optimal shape. Doing this maintenance will help keep your computing experience consistent, remove unwanted virus’ and spy ware programs, and apply the latest improvements in operating system and software program functionality.

In a perfect world this process would be entirely automatic, but there are a number of reasons why automation fails and part of desktop administration is monitoring and resolving those failures, proactively.

Back to the math quiz….

How much time does it take update 100 computers each month? If you do it the old fashion way and allow yourself 20 minutes per computer (that’s optimistic) you are looking at 2,000 minutes – plus travel time (between computers). That is roughly 35 hours; which approximates the amount of time we normally spend in an entire month managing infrastructure at a typical school. Not a sustainable model because there are more tasks required to manage technology resources than just updating computers.

The way to improve desktop administration is a three point approach consisting of automation, reporting, and remote control. These actions should be taken simultaneously and there are a wide variety of solutions to help you.

Whatever system you use, and there are several, you should focus on the following three areas:
  1. Automation – implementing automatic updates that work within your security model
  2. Reporting – providing a centralized inventory of computers and their current status
  3. Remote Control – installing remote control tools for efficient technician access
Automation

At the most basic level, you should set your computers to do automatic updates from Microsoft,  but depending upon security settings or user account privileges, this might not work. Finding the right balance between local user access and security of the environment is tricky, but as it relates to automatic updates it can cause the process to fail.

In an enterprise the size of a charter school, the single biggest problem we see (in terms of wasted resources) is having an open desktop security policy, with local install permissions. Managing this is the first order of business when struggling to gain control of computer administration costs.

With no security (access control) in place you will quickly find every single computer in a different state. There will be different backgrounds or wallpaper, butterfly or alligator pointers, and a wide variety of default program settings, browser toolbars, and freeware (accompanied by malware) installed.

The conflict between automatic updates and access control is best managed by a programs such as  System Center Essentials, Windows InTune, or other third party desktop administration tools that provide sufficient security access to accomplish the automatic updates required, with no intervention on your part. The sooner you get control of your desktops – the sooner your support costs will plummet.

In order to measure the success of your update automation, you’ll need some kind of centralized reporting tool.

Reporting

Quickly evaluating the state of your desktop computers is the essential job of a reporting tool. Rather than waiting for a user to call the help desk to address a computer issue, a good reporting tool will notify your help desk well in advance of a pending computer problem.

Applying support resources in advance is almost always more efficient than resolving a problem after the issue has caught the attention of an end user.  And sophisticated reporting tools are both inexpensive and quite robust.

Not only will a reporting tool disclose the state of your computers, with respect to software updates; it will also report impending hardware failures, disk space limitations, device driver conflicts, and other developing problems. And often these are represented in very clear color coded graphs and charts to not only give you a realistic overview of system health, but allow you to drill down to details of a given issue.

Remote Control

Simply stated, Remote Control is the ability for your technical support team to reach across the limitations of physical space and control your computer.  This allows technical support to happen as though the support engineer were sitting physically at your desktop, when in fact they are on the other side of the building, city, or country for that matter.

But there is much more to the advantage of remote control than remote access. Most remote control solutions are Internet browser based and as such, a support engineer can open multiple support sessions at once – as many as a dozen or more, depending upon bandwidth, browser limitations, and the ability to keep track of a large number of simultaneous support sessions. This is the model of efficiency.

In a recent upgrade scenario involving a major Windows Service Pack, we measured the time to do it manually vs. remotely. The time required on site was more than four times greater than doing so remotely.  One significant benefit that is often overlooked with remote support is the ability to provide support services while the class is in session, which is not practical on site.

One of my favorites remote tools is LogMeIn.com, a free browser based program that works well, is easy to install, and can be configured by having end users click on a link within an email message and follow a short installation routine. There are many others that work equally well.

Summary

An efficient desktop management model looks at your infrastructure once each day to view the state of computers. It proactively manages required updates, mostly through automation, but manually if required;  then resolves any computer errors using remote tools that do not interrupt your class.

Our experience suggests that by investing 20 – 30 minutes each day, you can proactively manage 100 computers. That of course does not include repairing intentional damage caused by students, catastrophic hardware failures, or major operating system upgrades, which require physical access.

Want to improve the score on your math quiz stated above? With automation, reporting, and remote administration your total will be a little more reasonable than what you are doing now.  Contact us if you would like a free recommendation on the automation, reporting, and remote support tools that will best suit your situation.

Friday, March 16, 2012

Managing Computers in a hostile computer lab

OK, so the notion of a hostile environment may be a stretch, but hear me out on this one. Jr High and high school students are not always the sweet and innocent models of decorum we would like. But having been there once,  I  understand. Managing computers in a lab can be frustrating, but with a little forethought you can keep your sanity.

Whether it’s showing off, flirting with a classmate, or just plain horsing around; stuff happens in the computer lab. Keys get popped off of keyboards, mice get ripped free of their chords, and the best one I’ve seen yet is a perfectly sized slice of baloney in the DVD drive. Being able to laugh about it is probably a good place to start.

However, if the problems are getting a little overwhelming with your resource constrained staff, here are some suggestions that might help.

Start with the right equipment

To the extent possible, use desktop computers in student labs, rather than laptops. They cost less to buy, are less expensive to repair, and tend to grow legs less often.  For real savings and administrative advantages, see the article about Multipoint Server in a computer lab, it will reduce the cost of the lab by 75%.

Desktops can often be mounted in cages that prevent physical access, which is an important step in your attempts to secure a computer.

Keep the network simple

Whenever possible, use a wired network connection for student labs. The bottleneck of twenty simultaneous You Tube videos will always impact a wireless network more adversely than a wired network. And wired adapters are much more reliable, given the security protocols passwords, keys, etc. that accompany WiFi.

Once configured, wired network devices rarely need management and access to the hardware is less apparent. In fact normal access is preventable through group policy settings. Speed is much faster on a wired network where even the very fastest wireless internet connection is about half the speed.

Provide Adequate Supervision

Adequate supervision is paramount in a computer lab. And this is the most common challenge we observe. If your staff is unwilling to provide accountable supervision and you as an administrator are unwilling to require it, then you might want to consider a teachers aid or parent volunteer. Even a non-technical individual can readily discern when a student is dismantling a computer.

It makes little sense to assign the task of student-sitting to your desktop or network support engineer. In a well managed environment,  they  are better utilized spending time resolving more complex issues.

Install video surveillance

This may seem  an overreach, but there may in fact be a very good case for this – especially in those schools with high risk populations  or special education requirements. Not only will this reduce vandalism, but in extreme cases may provide a solid defense against litigation. And there may be other very good reasons for videos surveillance.

Just knowing the possibility of videos recording exists can change behavior.

If you elect to use video surveillance, be sure to use digital cameras that are correctly specified as to focal length, field of view, and pixels per foot.  In most cases you can use your existing network infrastructure and Power Over Ethernet to eliminate much of your installation costs.

Summary

Remember that the only way to completely secure a computer is to prevent physical access to the computer.  Even the most hardened computer can be compromised if a student is given access to the physical device. By rebooting a computer with a bootable USB device, a very secure computer can be easily compromised by a clever student hacker.

So start with the right equipment, improve your supervision – either in person or by camera – and be suspicious if you see a student in the lunch room with a baloney sandwich, without the baloney.

Friday, February 3, 2012

What’s the big deal about Live@edu? It’s more than a free email account

Offering your students free email will get you about as much mileage as offering them free brussel sprouts for lunch. It's just not a big deal anymore to have an email account, with Gmail, Hotmail, Yahoo mail, and Facebook mail all competing for young minds as an advertising audience.

However, there may be very good reason for your school to offer Live@edu services for students. Here are a few advantages of doing so:
  • Increased collaboration and communication among students and teachers
  • Security and control of your email environment
  • Brand and community building with customized logos, color schemes, and campaigns
  • Real world training for your students to communicate in a 21st Century work environment
  • Reduced infrastructure costs
So, it’s not really just free, it actually pays you significant dividends! Let’s dig a little deeper.
 
Increased collaboration and communication
 
By giving students the ability to email, instant message, video chat, share documents, and store homework assignments in the Live@edu system, you give them a powerful set of creative tools. They can collaborate on project documents using Microsoft Office Web apps, free online companions to Word, Excel, Powerpoint, and One Note.
 
Security and Control
 
Because the Live@edu is centrally managed by your internal staff, you have complete control over access to the system. And with Microsoft’s advanced email security you significantly reduce the risk of phishing, virus, and malware attacks on your internal systems. And in the event of a disciplinary matter, you have access to email communication and message archives.
 
Brand and community building
 
Think about every email sent outside of your organization as a small advertising snippet. As your students communicate around the world and across the community, your institution becomes more visible, relevant, and cutting edge. Your Live@edu email and workspaces are branded with your logo and school name.
 
Real world training
 
Live@edu services are built upon the same technology as Microsoft Office 365, a powerful and widely used business communication and collaboration system. Your students will gain valuable experience in real world communication by using Live@edu. And they can plug into the Live@edu from anywhere and on any device.
 
Reduced costs
 
How much are you spending for student servers? Maintaining shared drives, keeping track of student documents, managing student access, securing other student’s work, and keeping ahead of student hacks is a significant IT management cost. With 25GB of storage per student and access control by Live@edu account, you can eliminate a great deal of administrative expense.
 
Summary
 
Building a communication platform for students to email, instant message, video chat, share documents, and store homework assignments seems like a lot of infrastructure – and it is. An equivalent cost to build and manage such a system internally would be thousands of dollars, not to mention the administrative time diverted from more strategic initiatives.
 
Showcasing your school as a leader in technology and forward thinking will generate interest and improve your recruiting efforts.
K-12 institutions have a very specific set of requirements for cloud-based messaging and collaboration solutions. No one brings a richer set of free hosted solutions to the K-12 space than Microsoft Live@edu. Not only are our enterprise-grade services cost effective and flexible, but they also prepare students for the next step with professional tools used in higher education institutions and businesses the world over.
 
Let us help you implement a Live@edu solution on your campus.