Vendor-neutral guide · 8 min read
DfE digital and technology standards: remote access in schools and trusts
Written by the 247connect Marketing Team
Shape of the topic
In short
The Department for Education publishes digital and technology standards for schools and colleges, covering areas such as broadband, cyber security, filtering and monitoring, and network switching. Alongside these sit statutory safeguarding expectations under Keeping Children Safe in Education, which require appropriate filtering and monitoring systems. Remote access and remote IT support sit at the meeting point of both: a support technician connecting into a school's network, or a multi-academy trust IT team managing devices across several sites, has to operate within the same cyber security and safeguarding expectations as everything else on that network. This guide sets out what those standards imply for remote access in a school or trust setting.
Key takeaways
- DfE digital and technology standards cover cyber security, filtering and monitoring, broadband and network infrastructure for schools and colleges.
- Keeping Children Safe in Education requires appropriate filtering and monitoring, which remote access tooling must not bypass or weaken.
- Remote support access to school networks should follow the same named-account and logging principles expected elsewhere in DfE cyber security guidance.
- Multi-academy trusts managing several sites remotely need consistent access control across every school in the trust, not just the central office.
- Safeguarding leads and IT leads both have a stake in how remote access is governed, since either an outage or a bypassed filter can create a safeguarding gap.
- Schools should confirm specific obligations with the DfE, their local authority or their trust's data protection officer, since arrangements vary by school type.
The DfE's digital and technology standards
The Department for Education sets out standards that schools and colleges are expected to meet across areas including broadband connectivity, cyber security, network switching, wireless networks, and filtering and monitoring. The cyber security standards in particular expect schools to have measures such as up-to-date protection against malware, effective access control, and a plan for responding to incidents, closely mirroring the kind of baseline set out in Cyber Essentials.
These standards are aimed at the whole of a school's digital estate, not just classroom devices, which means remote access tools used by IT support providers, whether an in-house team, a local authority service, or an external managed service provider, fall within scope wherever they touch the school's network or devices.
Safeguarding and filtering and monitoring
Keeping Children Safe in Education requires schools and colleges to have appropriate filtering and monitoring systems in place, appropriate to the age of pupils and the risks they may face online. This is a safeguarding requirement as much as a technical one, and it has a direct bearing on remote access: any remote support session or remote administration tool that could disable, bypass, or interfere with filtering and monitoring needs to be governed carefully, since doing so even temporarily could open a safeguarding gap.
In practice, this means remote access accounts used for IT support should have their level of privilege matched to what they actually need to do, rather than being granted blanket administrative rights that happen to include the ability to alter filtering settings. Where filtering does need to be adjusted remotely, for example to fix a fault, the change should be logged and reviewed, and reverted once the underlying issue is resolved.
- Match remote access privilege levels to the task, rather than granting blanket admin rights by default
- Log any remote change to filtering or monitoring configuration
- Review filtering settings after remote support work to confirm nothing was left disabled
Access control for remote IT support
The same principles that apply to general access control, named accounts, multi-factor authentication, and timely removal of access, apply just as much to remote IT support providers working with schools. A school or trust should be able to say who, specifically, can remotely access its network, whether that is an internal technician, a local authority support team, or a contracted managed service provider, and should not be relying on shared logins that make it impossible to attribute a change to a specific person.
For trusts running several schools from a central IT function, consistency matters as much as the individual controls. A remote access policy that is followed rigorously at the trust's flagship school but loosely at a smaller site creates an uneven risk picture across the trust, which is exactly the kind of inconsistency that DfE standards and audits tend to surface.
- Maintain a current list of every individual or organisation with remote access to the school's network
- Apply the same access control standard across every school in a multi-academy trust
- Remove remote access promptly when a support contract or staff role ends
Session logging and evidence for governors and trustees
Governors and trustees have oversight responsibility for how a school manages its digital and safeguarding risk, and being able to show evidence of well-governed remote access, rather than simply asserting it, supports that oversight. Session logs showing which named operator connected to which system and for how long give a governing body something concrete to review periodically, rather than taking assurances about remote support arrangements on trust alone.
A remote access tool that supports named operator accounts, encrypted sessions and audit logging, such as 247connect, gives a school's IT lead the evidence needed to answer governor or auditor questions about remote support directly, though the wider policy and review process around it is what actually delivers the safeguarding and security outcome.
Best-practice checklist
1. List every remote access route into the school network
Include internal IT staff, local authority support, and any contracted managed service provider or software vendor.
2. Match remote access privilege to task
Avoid granting blanket administrative rights by default, particularly rights that could alter filtering or monitoring settings.
3. Confirm filtering and monitoring cannot be silently bypassed
Check whether any remote access tool or support process could disable filtering, and require logging and review if it can.
4. Require named accounts and MFA for all remote support
Apply this consistently whether the support is internal, local authority provided, or from an external supplier.
5. Apply one policy across every school in a trust
For multi-academy trusts, check that remote access controls are as rigorous at every site as at the central office.
6. Review remote access logs periodically
Give the IT lead or a governor with digital oversight responsibility a regular sight of remote access activity.
7. Remove access promptly when contracts or roles end
Build removal of remote access into the offboarding process for staff and the end-of-contract process for suppliers.
Common pitfalls
- Granting IT support providers blanket administrative access that includes the ability to alter filtering settings
- Applying strong remote access controls at a trust's main site but not consistently at smaller schools
- Leaving a departed IT support contractor's access active after the contract has ended
- Assuming filtering and monitoring cannot be affected by remote support activity
- Having no routine review of remote access logs by anyone with digital safeguarding oversight
What to measure
| Remote access accounts with MFA | Target 100% coverage |
|---|---|
| Filtering configuration changes logged | Target 100% of remote changes |
| Consistency of policy across trust sites | Should be uniform, not vary by school |
| Time to remove a contractor's access after contract end | Should be measured in days, not months |
Select any column heading to sort.
Frequently asked questions
- Do DfE digital and technology standards specifically cover remote access?
- Not as a standalone item, but the cyber security standards cover access control, malware protection and incident response, which apply to any remote route into a school's network, including remote IT support tooling.
- Can remote IT support ever disable a school's internet filtering?
- It should not be able to do so silently. Where a legitimate fault genuinely requires a temporary change to filtering, that change should be logged, time-limited and reviewed, since Keeping Children Safe in Education requires appropriate filtering and monitoring to remain in place.
- Does a multi-academy trust need the same remote access controls at every school?
- Consistency is expected in practice, since an uneven approach across a trust's schools creates an uneven risk picture and is the kind of gap that audits and inspections tend to identify. Trusts should confirm their specific policy expectations with their own IT governance framework.
- Who is responsible for reviewing remote access to a school's network?
- This typically sits with the school or trust's IT lead, supported by governors or trustees with digital oversight responsibility, though the exact arrangement depends on the school's governance structure and should be set out in its own policies.
- Should external IT support providers have their own named accounts?
- Yes, named accounts rather than shared logins allow any change or session to be attributed to a specific individual, which supports both the DfE's access control expectations and safeguarding accountability more broadly.
Sources
Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.
- Digital and technology standards for schools and colleges
Department for Education
Official DfE standards covering cyber security, filtering and monitoring, and network infrastructure.
- Keeping Children Safe in Education
Department for Education
Statutory safeguarding guidance including the requirement for appropriate filtering and monitoring.
- Cyber security standards for schools and colleges
Department for Education
Specific standard covering malware protection, access control and incident response for schools.
Putting it into practice
This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.
More best-practice guides
Vendor security questions
The security questions worth asking any remote access vendor before buying, and why each one matters to your organisation.
Remote access audit evidence
How to build an audit evidence pack for remote access, covering logs, approvals, access reviews and retention records.
Data residency & remote support
What data residency and international transfer rules mean for remote support, and where session traffic and metadata actually go.