3
What do you do when you have a pool of laptops that are given to staff when they travel? I work for a travel agency where we will send a staff member or two away on a tour with a group of people, and they need to continue to connect back to the office, clear emails etc.
What I want to know is this: Is it normal to connect these laptops to the AD domain as well, or would you leave them off the domain as standalone workstations?
FWIW, this is a SBS2011 Standard network, with around 25 staff and 8-10 laptops. It's not feasible to give each user one laptop.
As I see it, these are the pros/cons.
Connect the laptops to the domain (the pros/cons are more or less opposite for 'not connecting the laptops to the domain'):
- Pro: Better security (GPOs applied, problem areas locked down, Firewall rules setup appropriately etc.)
- Pro: Staff login with one account, and don't need a separate 'Laptop User' account that they need to remember the password for
- Con: WSUS won't work (see above reason)
- Con: Integrated AV doesn't work (AV updates require a connection back to the AV server which isn't accessible to the world) so it will scan, but not with the most up-to-date definitions. Given some people are away for a month or two at a time, that's not a great look
- Con: Staff have to remember to logon to the domain at least once before they leave while in the office, as the laptop needs to cache their logon. If they don't do this, the laptop is a brick, unless I give them the local admin account
Anything else I'm not thinking of?
We haven't used the VPN software built into SBS 2011 as yet, as it's an extra thing to investigate, watch for security advisories on etc. however if it proves to be useful then it's worthwhile setting up.
We are using ESET for AV, I'm sure there is an ability to update over the internet, I will just have to look for it. A non-issue.
I'm fairly sure a cached login expires after a while, no? The laptops are for teams, so anyone might grab any laptop (as mentioned). Finally, not sure how you can create a VPN connection without logging in, which you can't do until you have a VPN connection? – Matt – 2012-08-20T00:39:01.297
windows allows you to log in with the VPN connection. – Keltari – 2012-08-20T00:46:00.990
Thanks - I'll have to look into that. Sounds like you've answered everything, thanks! – Matt – 2012-08-20T00:46:41.440