This article was originally published in District Administration on 8/18/26 by Charlie Sander.
Now, this debate has expanded to include issues like AI, a ban on cellphones and/or tablets, and the broader role of digital learning. While the concerns are legitimate, for schools’ technology leaders, these questions are incomplete.
The most urgent concern is not determining how many devices belong in classrooms; it is understanding how schools intend to govern the digital ecosystems students are using, across school-issued and personal devices. Those advocating for stricter limits on classroom technology have learned to recognize this distinction.
As the American Federation of Teachers recently outlined new recommendations on student technology use, President Randi Weingarten pointed out that she was “not calling for a ban on AI or a bonfire of Chromebooks.”
Cybercriminals do not need access to a district-issued device to compromise a student account. Because Microsoft 365 and Google Workspace can be accessed from virtually anywhere, weak or stolen credentials can give attackers easy access to accounts that lack adequate monitoring.
Charlie Sander, CEO, ManagedMethods
The issue is no longer whether technology belongs in classrooms. It’s whether schools have the operational maturity to manage it responsibly, and that is a responsibility that extends far beyond the device itself.
School-issued laptops or tablets are only one part of a student’s digital learning environment. Student identities, cloud storage, collaboration platforms, browser sessions, and third-party applications are the new learning infrastructure. And this is also where most cybersecurity risks emerge.
Cybercriminals do not need access to a district-issued device to compromise a student account. Because Microsoft 365 and Google Workspace can be accessed from virtually anywhere, weak or stolen credentials can give attackers easy access to accounts that lack adequate monitoring.
Attackers can then send phishing emails from trusted school addresses, making recipients more likely to click malicious links or disclose sensitive information. These attacks can compromise additional accounts and expose student, staff, and financial data.
Without appropriate monitoring, governance and security controls, restricting managed devices does little to reduce a district’s exposure.
In other words, removing “managed” devices doesn’t remove digital risk. It transfers that risk into environments where school technology teams have less visibility and fewer opportunities to intervene.
This shift has fundamentally changed what K-12 cybersecurity looks like. Protecting endpoints is still important, but it is no longer sufficient.
Schools cannot secure what they cannot see. Visibility must now extend beyond networks and devices into the cloud services students use.
Shared documents, email accounts, collaborative workspaces, and third-party applications are all potential attack surfaces that traditional network controls are not designed to monitor…
