4 ms·
I work for a school district (not CPS) with about 2000 deployed Chromebooks and you're likely running into one of two things. 1) You somehow 'enrolled' the dev
by mfreydavis 5y ago
I work for a school district (not CPS) with about 2000 deployed Chromebooks and you're likely running into one of two things.
1) You somehow 'enrolled' the device into the Chromebook management. This is hard to do by mistake but if you do, essentially puts the device under the control of the school district. It also uses up a license on their end. We only allow particular IT only accounts to enroll devices.
2) You're logging in with their CPS account. Once a person logs in with their managed account it can deploy user level policies that include everything you described: extensions, filtering, and blocking signing into another account in the browser. You'll also find some random pages are blocked to keep students from bypassing the restrictions.
That you can wipe the machine makes me think you didn't enroll it - if you wipe an enrolled device it will prompt/force you to re-enroll.
You should be able to reboot the device so you land at the login screen and hit "Add Person" down at the bottom. From there sign in with a different Google account and it should be completely unaffected by any policy the school is deploying. Unless you enroll it, the policies are deployed to the Google account, not the device.
Its likely the CPS Help Desk Staffer you reached doesn't have the power to fix things for you if you've enrolled things - that usually requires permissions that are restricted to a few admins.
Feel free to shoot me a message via the email in my profile - I'm happy to give you some of the inside perspective and help you figure it out.
- londons_explore 5y agoSo, it sounds like the best advice to OP is to create another 'home' account for their son, on the same device, which won't be monitored or affected by anything the school does. The son can decide which account to log into based on what they plan to do that day.
- alar44 5y agoNo, at this point they probably can't. It's locked down the way it is to specifically prevent that sort of thing. It should be removed from enrollment, the IT dept doesn't want that on there any more than OP does.
- toast0 5y agoProbably better to login (or not) to the chrome OS device as a personal account, and then login in the browser (private mode perhaps?) to the school account to do the classroom stuff. I don't think logging in to the school account in Chrome the browser will trigger the same behavior as logging in to the school account in Chrome the OS. You may need/want to powerwash the device again.
- staticassertion 5y ago> The son can decide which account to log into based on what they plan to do that day. You can log into multiple accounts at once on a Chromebook. ctrl + alt + `.` lets you switch between workspaces across accounts, and you can right click windows to move them across workspaces. I'm doing this right now so I can post on HN from my personal account while I code for work.
- magicalist 5y agoThis response should be higher instead of the useless armchair lawyering :) With GoGuardian, though, I think device level management is common? It's BYOD but it essentially becomes the district's device (and all the other accounts disabled) until you remove the managed account. It can't happen by accident, though, it tells you very clearly you're making it a managed device. It sucks that schools are using enterprise management to monitor every thing a student does on their machine, but it's not a rootkit or something. If it's not the district's device just remove the account.
- evilDagmar 5y agoNo, it should only be the district's device while the district student's login is being used. There's still very much a legally-enforceable expectation of privacy for the other possible users of the machine. That the user is the actual owner of the equipment makes it pretty important that someone at the school system defined the MDM policies properly so as not to violate other user's privacy rights. ...but considering the way most of them are staffed, they probably screwed up and need to be shown the right way to do it before they land themselves in court.
- cameldrv 5y agoWhy is it ever the "district's device?" It's owned by the parent, it's being used at home. What justification does the district have to monitor anything that's happening not at school using equipment that they do not own that does not involve any of their servers?
- staticassertion 5y agoIt isn't the district's device. OP just enrolled it in the School's GSuite organization so, obviously, policies got pushed. They can just... not do that. If they want to log into apps or whatever on the Chromebook, they do need to do that. At that point the device has to follow policies for accessing the school's services or whatever. They still don't own the device, but they can push policy to it. At any time the device can be removed from the organization, but that has to be done by the organization, I believe. Of course, you can have multiple accounts on the Chromebook, so they could just have the device enrolled for one user, but have a personal account not enrolled. It's all pretty straightforward.
- jcz_nz 5y agoHave written Chromebook extensions for large school systems. The OP is absolutely correct. It boggles the mind what some of the posters above this are thinking. Seriously, no one wants to spy on your home browsing habits - if nothing else because it creates a new workload and a potential liability for the teachers and the institution. Create a new profile, and you're good to go.
- IWillForgetThis 5y agoI experienced scenario #2 on my son's Chromebook during pandemic school closings. One day he logged in with his school account and about half the apps were disabled, including core stuff he needed to do school work. I got the "we can't control your computer, that's not how computers work" speech from the school. It was one of the most frustrating things I've ever experienced. The policies finally got fixed a few days later, but I'm pretty sure the people I talked to thought I was crazy.
- rejectfinite 5y agoThis. Then again this site is mostly developers. They have no idea about SCCM, Intune, JAMF and other MDMs and how they work.
- meetingthrower 5y agoAgree. We have filtering on our kid's Chromebook, but only when they login as user to their school account. They have their separate account which gives them their own space. Certainly you WANT the school district to do some filtering for the school accounts, right? I mean, I think ours locks it down so tight that students can't get outside emails until they are whitelisted somehow...
- nybble41 5y ago> Certainly you WANT the school district to do some filtering for the school accounts, right? a) No. Filtering (if there is any) should be limited to their own network or a school-issued device, not some device the school system doesn't own. b) Filtering only the school accounts is pointless if the student can just switch to a non-school account (or guest account) and access whatever they want there.
- FateOfNations 5y ago> Filtering only the school accounts is pointless if the student can just switch to a non-school account (or guest account) and access whatever they want there. From the district's perspective this does have a point: it removes perceived or actual liability for things that the student could be exposed to or experience using their managed services. Being able to tell an offended parent "not our account, not our device, not our problem" versus having to answer for "but he was logged into his district managed Google account, shouldn't you have protected him?"
- meetingthrower 5y agoYour A) is exactly what is happening. Filtering on school account only. On B) I agree that kids can and will do anything they want on other accounts including just opening their phone! But what happens on school sponsored email, virtual drives, and applications should be controlled I would think. It opens the school to liability if nothing else.
- nybble41 4y ago