Skip to content

Article IT SECURITY

Reading time
5 min
Published

IT training on company computers: how do you balance security and hands-on practice?

A company laptop's security policy does not have to block the exercises. The computer can remain a device for connecting, while the operating system, tools, permissions and training data run on an isolated VM.

A managed laptop is there to protect the company, not to stand in for a lab

No administrator rights, controlled installation, a security agent and network rules are normal features of a company device. Trying to switch these protections off temporarily for a workshop increases risk and puts a burden on the IT department. A better solution is to leave the laptop in its proper role.

The participant uses a browser or an SSH client, and the tools run on a separate virtual machine. They do not install compilers, databases, a container daemon or libraries on the local system. When the training is over, the company computer is left with its configuration unchanged.

The security team needs a precise description of the connection

Before the event, you should provide the addresses, ports, authentication method, account lifetime and the type of data being transferred. A desktop in the browser can use HTTPS on port 443, and a terminal can use SSH on port 22. Whether a connection is ultimately possible depends on the organisation's proxy, firewall and policy.

If a domain has to be added to an allow list, the request should go through the standard process. Participants should not be asked to use a personal hotspot as a way round company controls. That shortcut removes visibility of the traffic and shifts the risk onto the user.

A test from the target device is part of acceptance

One person from the company should sign in from a managed laptop on the network that will be used during the sessions. The test covers keeping the session alive, the keyboard layout, the clipboard, opening the material and running a basic command. With SSH, you should also check the host key and how the key or password is handed over.

The result of the test should be unambiguous. If the connection only works after switching browser or turning off TLS inspection, that decision has to be approved and documented. Do not assume that every participant will find a workaround on their own on the day of the training.

Training data should be kept separate from company resources

The lab receives synthetic data, sample repositories and credentials that are valid only in the exercise environment. A participant should not copy customer files or production tokens just because the remote VM is isolated from the laptop.

If the programme requires internal materials, the organisation must define how they will be delivered, the scope of access and when they will be deleted. Clipboard and file transfer settings should be consistent with that decision. Being technically able to download a file does not automatically mean being permitted to.

Each participant needs their own account and workstation

A shared password makes it harder to revoke access and to establish who made a change. Separate accounts can expire after the event and lead to private VMs. This is especially important when the exercises involve root privileges, network services or data that changes during the work.

Identical workstations let the instructor use a single set of instructions. Differences in local system policy no longer affect tool versions or file paths. The laptop is responsible for the connection, and the whole technical context of the task sits on the lab side.

Support should work without asking for local permissions

When reporting a problem, the participant gives the workstation identifier, the exercise stage and the symptom. The instructor checks the state of the VM, the service and the logs, and if necessary helps within the session with the user's consent. There is no need to install a support tool or take over the company computer.

If the problem concerns the connection, the person responsible for the lab and the IT department work together. If it concerns the base image, the affected machine can be restored. A mistake in the participant's own code remains part of the training and should be analysed, not automatically reset.

After the workshop, no local installations or open accounts are left behind

Participants export the agreed results, and temporary tokens and accounts are revoked. The VMs run until the agreed date, after which they are shut down and deleted. The company does not have to clean up a dozen or more different installations on employees' laptops afterwards.

Access through a desktop in the browser or SSH lets you match the way of working to the programme and the device policy. An advance test and concrete arrangements with the security team matter more than trying to find a universal exception for every training tool.