My client (a financial advice charity) has a number of laptops used by volunteers working from home. As these laptops contain client personal and financial data, they need to be encrypted. I have installed the SGE 6 Policy Editor on a computer in the office (actually a server) and created the configuration file. My question is about the client laptops.
These laptops will never logon to the domain directly (from within the client’’’’s office). The users logon locally (from their own homes) and then access the client database via RDS (RemoteApps).
When I installed the first laptop, I didn’’’’t realise that the first logon is captured and is always there. This is not what I need as the provided laptops may be assigned to different volunteers and some actually belong to volunteers.
Is the best way to do this to have a two stage logon, i.e. to logon via the SGE POA and then logon to their computer locally? In that case, is it best that I create a username / password for the device rather than the person? Should these be POA users or Service Account list users? How do I get over the issue of the first logon being captured by POA and being ever present?
Or am I looking at this the wrong way?
Thanks
This thread was automatically locked due to age.