Services · MDM and web filtering

MDM for schools and colleges: device management and content filtering

PenwinEdu rolls out and maintains a school's mobile device management (MDM) and content filtering: Chromebooks, iPads, Windows laptops and the mobile phones that come in every morning, with different policies by phase of education, group and role, and filtering that goes with the device inside and outside the classroom. Mixed fleets of iOS, Android, Windows and Chrome OS devices integrated with the school's directory, with the data protection framework agreed in writing before anything is switched on.

Request a proposal at info@penwin.org, telling us how many devices you have and for which phases of education. The initial assessment and proposal are free and come with no obligation.

What the service includes

Every device in the school is configured and controlled remotely from a single console: a device is enrolled once and from then on receives its Wi-Fi settings and certificates, accounts, apps, restrictions and updates over the internet. The console integrates with the school's directory (LDAP/Active Directory) and with Google Workspace or Microsoft 365.

  • Live inventory: which devices there are, who has them, operating system version and status.
  • Apps: silent installation and a managed app store with the approved apps.
  • Configurable restrictions: camera, app store, software installation, USB, private browsing.
  • Remote updates and patching, scheduled outside school hours.
  • Network profiles: the school's Wi-Fi arrives on the device already configured, without going classroom by classroom.
  • Remote actions: lock, locate, wipe and reset to baseline.
  • All three types of fleet: shared devices, 1:1 devices that leave the building and students' BYOD, governed from the school network.

Policies by phase, group and role

We design policies by phase of education – from early years (Infantil) to university – as well as by group and by role, with a dedicated policy for teachers and classroom management features. Because the policies are built on the directory groups, maintenance is no longer manual: a newly enrolled student inherits the policy for their year group, and that policy changes by itself when they move up to the next phase. We cover on our blog how each one is calibrated.

Content filtering: on the network and on the device

Filtering works in two layers. On the school network, the firewall and the DNS resolver filter everything that passes through the building, including devices the school does not manage. On the device, the profile installed by the MDM applies filtering wherever the device is: at home, in a library or on a mobile hotspot.

Filtering and logging students' browsing means processing children's personal data, and the roll-out arrives with that framework settled from day one: PenwinEdu signs the data processing agreement and the school adds it to its record of processing activities. We cover on our blog how responsibilities are divided.

  • Categories – adult content, gambling, violence, social media, streaming, proxies and anonymisers – plus the school's own allowlists and blocklists.
  • Remote device lock when browsing has to be cut off instantly.
  • PenwinEdu also develops PenwinSafe, its own safe browsing platform, with always-on DNS filtering on any network.

Roll-out and the school calendar

The service follows the school year: summer for major updates, policy changes and getting devices ready for September; during the year, new devices, removals, replacements and remote locking of lost devices; in June, collection, wiping, freeing up licences and the inventory for the refresh plan.

  • Inventory and labelling beforehand: serial number, location and person responsible.
  • Policy design by phase, group and role, based on the directory.
  • Documentation and training for the school's IT team.

Why PenwinEdu

We specialise in education – publicly funded private schools (concertados), private schools, universities, business schools and vocational training centres – and have spent more than twelve years managing their technology infrastructure in Spain. Today we manage more than 300,000 daily connections, 600 TB of traffic and more than 1,200 switches and firewalls, with 24/7 monitoring and a support response within 4 working hours.

  • Free, no-obligation assessment and proposal. Contact: info@penwin.org
  • Offices: Benet Cortada 14, 08174 Sant Cugat del Vallès · Av. de los Poblados 151, 28025 Madrid · Almagro 14, 23002 Jaén, Spain.

Frequently asked questions

What is the difference between MDM and web filtering?

MDM manages the device and web filtering manages the content: MDM decides which apps are installed, which settings are locked and when the device is updated; filtering decides which pages can be reached. They are rolled out together, because the MDM installs the filtering profile and locks it onto the device.

Can students' own devices (BYOD) be managed?

Yes, with the family's consent and through partial management: a work profile on Android and User Enrolment on iOS. The school controls its apps and data within that space, and the student's personal space is left untouched. Anything not covered by enrolment is controlled through the school network.

What happens to devices outside school?

School-owned devices remain managed when they are off site: the MDM communicates over the internet, so policies, apps and updates are applied in the same way at home. Filtering is applied by the profile installed on the device itself, with rules that can differ between school hours and the afternoon.

Can mobile phones be locked during lessons?

If the phone belongs to the school, yes: the MDM puts it in kiosk mode with a single app, turns off the camera or limits the handset to whatever the school authorises, with rules that switch on by time slot. With students' own phones, the school acts on its network: the Wi-Fi requires their own credentials and traffic is filtered.

How long does it take to enrol a whole device fleet?

The pace depends on where the devices come from. With zero-touch enrolment, a device registers itself when it is switched on and hundreds can be done at a time. For a fleet already in use, PenwinEdu plans assisted enrolment classroom by classroom, in scheduled sessions, with its own team on site and during non-teaching periods.

Does device management integrate with Google Workspace or Microsoft 365?

Yes. The console integrates with Google Workspace, with Microsoft 365 and with the school's directory (LDAP/Active Directory): users and groups are kept in one place, a newly registered student inherits their year group's policy and removing a user withdraws their access everywhere.

Who is accountable for students' data in MDM and filtering?

The school is the controller and the technology provider acts as processor, under a data processing agreement that sets out what data is processed, for what purpose, how long logs are kept and who can consult them. With children's data, the school relies on a valid lawful basis and informs families.

Let's talk about your school

Email us at info@penwin.org with details of your school, or fill in the contact form, and we'll reply with a specific proposal.