Microsoft‘s licensing policies and legal restrictions that forbid schools from distributing software patches to many students are leaving IT executives at universities with potentially thousands of unmanaged desktops that pose a serious security risk.
The issue is that higher-education institutions, and other organizations outside Microsoft and its resellers, don’t have the legal right to distribute Windows software to computers they do not own. For most schools, that is a majority of their student desktops.
The result is that universities can’t distribute patches for many Windows-based machines; instead they must rely on students to patch their own systems.
As a result, schools end up with lopsided networks with secure network infrastructure servicing clients not adequately patched and protected.
“We have one set of licensing agreements in place to handle site licensing for faculty, staff and employees, and then we have the infamous black hole for student-owned computers because they are not owned, managed or have site-licensed software installed,” says Rodney Petersen, coordinator for the Security Task Force at Educause, a nonprofit association of 1,900 schools that promotes IT in higher education.
Microsoft offers licensing options for student machines but the cost is prohibitive, with requirements to cover entire departments or entire campuses. Few schools subscribe, according to Educause.
The problem joins a list of growing Windows-patching challenges in specific industries. In July, Network World uncovered potentially life-threatening patch problems that plague the healthcare industry.
Educause’s Security Task Force is encouraging Microsoft to adapt to the unique relationship schools have with students through licensing revisions or modifications to Microsoft’s software distribution technology.
The higher-education community has solutions in mind but is skeptical of Microsoft, which has promised a long-term remedy but has yet to provide details.
Some say the solution should combine flexibility in both delivering patches to machines not owned by the university and how it can be done.
“Educational institutions are looking for more flexibility to secure the entire network,” Petersen says. “They don’t want to rely on students getting a CD or going to an update server.”
Many users are trying workarounds using methods that don’t scale, including Active X controls for rudimentary patch assessments, or don’t work well. Products that perform security checks before allowing access typically require client-side code, which is impossible to load on student machines new to campus. Remote security scans also are difficult because many students use personal firewalls.
What complicates the matter further is that Microsoft is legally required to track software it distributes in case of a recall. If schools re-distributed patches they would have to log and track each user, including those that leave the university system.
Microsoft also closely guards distribution to secure the integrity of the software.
Company officials said in a statement that they are “working closely with their higher-education customers on this and exploring options to meet the unique needs of the campus computing environment.”
The situation has been building over the past 12 months of worm and virus outbreaks and came to a head in August when Microsoft released Windows XP Service Pack 2 (SP2).
In response, Microsoft bent its own rules to foster installation of XP SP2 by creating the Higher Education Voluntary Distribution Program, which provided the SP2 code via an allotment of free CDs for universities to distribute to students. The program ends Nov. 30.
However, schools want a long-term plan to easily and affordably distribute patches to students.
“The current license model is aggressive for campuses,” says Jack Suess, CIO at the University of Maryland, Baltimore County, and co-chair of the Educause Security Task Force. “We have to track who gets each CD, and we need a method of recall. That is tough for institutions to do.”
That’s especially true given Microsoft’s monthly patch release and random critical updates.
Licensing restrictions also prohibits computers not owned by the school from connecting to a school’s Software Update Services (SUS) server, which is Microsoft software that the schools deploy internally to distribute patches. The same is true for Microsoft’s Systems Management Server.
Microsoft does not provide tools to authenticate access to SUS servers, which would permit auditing of downloads, Suess says. Schools also would have to validate that only users with licensed software download patches and would be liable for any breaches.
“We need simple things like getting standard license agreements that are readily adoptable by universities,” says Suess, who adds that the task force has not yet developed concrete proposals to present to Microsoft. “Other users, governments and corporations expect us to manage these students who are using our IP addresses. There is a level of accountability.”
The Security Task Force has been working with Microsoft, which hosted a Webinar in August to answer questions and appointed a technical staff member to field questions on Educause’s security discussion list.
Microsoft currently has a few licensing programs for schools, including the Campus Agreement with a Student Option, which provides licensed software for students. A license to provide 500 students with a desktop operating system, Office and a client access license for Windows Server and SQL Server Standard Edition costs $13,500. However, universities must license a minimum of 300 students and license by entire departments or the entire campus; they cannot license random students.
Microsoft has the MSDN Academic Alliance membership program for departments that teach and use computers. The $800 per department fee includes access to software for instruction only and an electronic software distribution system run by e-academy, Inc.




