Active directory secure mode – Faronics Insight User Manual

Page 30

Advertising
background image

Faronics Insight User Guide

30

|

Installing Faronics Insight

Active Directory Secure Mode

Faronics Insight has the ability to leverage Windows Active Directory to ensure that only
authorized teachers can control students. This mode adds an extra level of security to prevent
unauthorized consoles from being used. This mode will only function in an Active Directory
Domain environment and on Windows XP or newer systems.

To fully configure this mode, you must have Domain Rights to create and populate a domain User
Group.

Installation Steps:

1. After double clicking on either the teacher.msi or student.msi file, continue through the install

as previously described. To install the password protected version, Check the box to Enable a
security mode
.

2. Select Active Directory Secure Mode.

3. Repeat these steps for both Teacher or Student computers (the iOS device must be on the

same subnet as the Teacher console).

To install the Active Directory Secure mode on the Teacher or Student using a script or Active
Directory, refer to the section,

Scripting or Mass Deploying Faronics Insight via MSI

.

When in this mode, a teacher must be a member of the Domain User Group “Insight Teachers”. If
the teacher is not a member of that group, then Active Directory Secure students will not interact
with that teacher.

Creation of the “Insight Teachers” Domain User Group is done using the appropriate Windows
Server 2003 or 2008 Active Directory tools. Once the group has been created, those same tools
can be used to populate the group with the appropriate teachers.

While Password Secure Mode requires that both Students and Teachers are installed with this
option, Active Directory Mode is a bit different. If the Student has Active Directory Secure Mode
enabled, then it will be Security Locked Out to any Teacher who was not installed with the Active
Directory Secure Mode enabled (or is not a member of the “Insight Teachers” group). The
restriction does not go the other way. An Active Directory Secured Teacher (who is also a a
member of the “Insight Teachers” group) will be able to control Students who do not have AD
Secure Mode Enabled, without any restrictions.

Note: Active Directory Secure Mode is not available yet for Mac Teachers or Linux or Mac
Students.

Advertising