Our school is a mixed environment and the nice part of apple products is that when a machine is rebuilt it will automatically report to the MDM and configure the machine for our school.
However, with our Windows side we don't currently have that luxury. Does anyone know of a way to control the devices in a way that the IT staff would have the ability to identify quickly if a machine is being rebuilt with a different base build then what the school wants.
For example a student/teacher taking the machine home and putting a new version of the operating system and still using the device as needed but doesn't contain our group policies. Most of what our teachers and students need is web based so they could go months without connecting to our network.
We can monitor the last time they reported to our domain but that is too late sometimes for us to identify the rogue machine.
Thanks for any ideas.