The scale of investment under the National Recovery and Resilience Plan (KPO) is unprecedented – over 735,000 modern multimedia devices and equipment for 16,000 artificial intelligence (AI) labs and 4,000 STEM laboratories have been delivered to more than 17,000 Polish schools. The challenge currently faced by local governments and school principals is to transform this massive, multi-platform fleet into an educational ecosystem that is secure, easy to maintain, and fully compliant with GDPR regulations and the NIS2 Directive.
Below, we present a comprehensive analysis and implementation strategy for governing bodies.
The KPO challenge: A hybrid, multi-platform environment
The value of the equipment delivered under the KPO exceeded PLN 1.7 billion gross. This initiative aimed to equalise educational opportunities for students across the country. At the same time, ownership of the equipment was transferred to the governing bodies (Local Government Units – JST), meaning that local governments and school management bear full legal and technical responsibility for its efficient operation, inventory management, and digital security.
Due to the outcomes of multi-part tenders, devices from multiple manufacturers (including HP, Dell, Lenovo, Acer, Asus) running on various operating systems were delivered to educational institutions. This phenomenon is commonly referred to as a diverse multi-platform fleet or a hybrid hardware environment.
Structure of the delivered hardware volume
- Classic Laptops: 404,250 units were delivered, with a total estimated maximum value of approximately PLN 1.168 billion gross. These devices mainly run Microsoft Windows 11 and are based on x86 architecture (Intel Core i5 processors, 16 GB RAM, SSD drives), providing significant computing power.
- Chromebooks: 110,250 browser-based laptops valued at approximately PLN 181.5 million gross reached schools. These devices run Google ChromeOS (x86/ARM architecture) and are highly optimized for cloud-based work.
- Multimedia Tablets: The fleet is complemented by 220,500 tablets with an estimated maximum value of approximately PLN 384.5 million gross. The vast majority are based on Android (with a marginal share of Apple iOS) and ARM architecture, offering mobility and touchscreens.
Threats associated with an unmanaged model
An unmanaged deployment – consisting simply of unboxing hardware and booting it up on local user accounts – carries significant organizational and technical risks:
- Performance Degradation: Uncontrolled software installation, saving files to desktops, and changing settings cause Windows and Android systems to slow down in just a few weeks.
- Student Privacy Violations: In an environment where dozens of students use a single computer each week, the lack of session isolation means the next student gains access to files, search history, and even saved passwords of their predecessor.
- Lack of Asset Tracking Capability: Without a cloud management console, a governing body cannot generate an automated report on the technical status and location of a specific device.
Manual configuration, updates, and wiping of hundreds of devices defeats the purpose – it exceeds the capabilities of school IT administrators and local IT support. The solution lies in a central cloud management model, which allows remote and automated deployment of security policies, permissions, and app limits across the entire hardware fleet.
Legal requirements: GDPR regime and the amendment to the national cybersecurity system act (NIS2 Directive)
Managing endpoints from KPO is not merely a matter of convenience for IT administrators – it constitutes a strict statutory obligation.
Personal data protection under GDPR
Article 32 of the GDPR imposes an obligation on schools and governing bodies to apply technical measures ensuring a level of security appropriate to the risk:
- Drive Encryption: Theft or loss of an unencrypted laptop containing personal data constitutes a personal data breach (GDPR incident) requiring notification to the President of the Personal Data Protection Office (UODO) within 72 hours. Managed encryption must be used (e.g., BitLocker for Windows or native ChromeOS encryption).
- Accountability and Confidentiality: The school must be able to prove who used a given device and when. The absence of audit logs during a UODO inspection is treated as gross negligence.
National Cybersecurity System (NIS2)
The implementation of the NIS2 Directive as part of the amendment to the National Cybersecurity System (KSC) Act imposes strict digital protection requirements on local government units and subordinate educational institutions. Schools are currently listed among the entities most vulnerable to ransomware attacks; therefore, maintaining hundreds of unmanaged devices presents a direct threat to the operation of the entire local administration.
The regulations impose specific obligations on governing bodies:
- Asset Inventory and Access Control: The necessity of continuous supervision over IT assets and strict user permission management.
- Cyber Hygiene Standards: Implementation of mandatory requirements regarding password complexity and the widespread use of Multi-Factor Authentication (MFA).
- Mandatory Audits and Reporting: Conducting periodic security assessments under the threat of severe financial penalties.
Failure to comply in this area may result in fines reaching up to 2% of the entity's annual turnover or amounts running into tens of millions of zlotys. Under current law, implementing central cloud fleet management for KPO hardware using professional licenses is no longer an option for admin convenience – it has become an absolute legal requirement and a critical element in protecting the local government budget.
Foundation of the architecture: Federated identity (SAML 2.0 and SSO)
A common mistake is creating separate logins and passwords for students and teachers across e-registers, Google Workspace, Microsoft 365, and other educational platforms. This leads to the use of overly simple passwords or writing them down on paper, violating security principles.
The solution is building a federated identity environment based on the SAML 2.0 standard and Single Sign-On (SSO) mechanism:
- Identity Provider (IdP): The governing body designates a single environment (e.g., Google Cloud Identity) as the primary single source of truth for users.
- Service Providers: The secondary cloud environment (e.g., Microsoft 365), e-registers, and educational applications (e.g., Canva) rely on authorization from the primary source.
Authentication flow scheme in federated architecture
When a user attempts to access a selected service (e.g., Microsoft 365 ecosystem or an e-learning platform), they are redirected to an encrypted, master Google login portal with Multi-Factor Authentication (MFA) enabled. Upon successful identity verification, the system issues a digital ticket via SAML 2.0 protocol and passes it to the target service. This provides secure access without transmitting the user's physical password to external systems.
Benefits for the governing body and regulatory compliance
- Single Source of Identity: The user remembers only one secure set of credentials. This supports the principles of minimizing attack vectors under GDPR.
- One-Time MFA Configuration: Multi-Factor Authentication configured in the primary cloud identity source protects all integrated applications and computer access. This meets the requirements of KSC and the NIS2 Directive.
- Instant Revocation of Access: Deactivating a single account after a teacher leaves or a student graduates automatically and globally blocks access to all hardware and applications. This fulfills the GDPR principles of access limitation and accountability.
Google Workspace and ChromeOS: Mobile computer labs and revitalizing old PCs
The distribution of KPO equipment resulted in some schools receiving only a few Chromebooks each, making it impossible to set up a traditional computer lab. However, using Google technology, it is straightforward to construct a fully functional, secure mobile lab.
ChromeOS Flex and Chrome Education Upgrade (CEU) license
Legacy PCs and Macs gathering dust in school storerooms can be revitalized using the free ChromeOS Flex operating system. Installing it on 10 older laptops and pairing them with 5 new KPO Chromebooks creates a cohesive, 15-station laboratory.
- New KPO Chromebooks include the Chrome Education Upgrade (CEU) license in the price of the device.
- For legacy computers running ChromeOS Flex, purchasing a CEU license is necessary to enroll them into the management console. This is a one-time perpetual fee of approximately PLN 150–210 net per computer.
CEU features in everyday school operations
- Ephemeral Sessions (Ephemeral Mode): Upon user sign-out, all local cache, files, and digital footprints are removed from the drive. The next student logging in via SSO gets a pristine device. This guarantees full data security (GDPR) and prevents storage drive clutter.
- Mobile Lab Architecture: Chromebooks boot up in 8 seconds, and updates occur in the background. Placing them in a mobile charging cart allows quick relocation of the lab to any classroom.
- Intuitive Management: The Google Admin Console enables administrators with just a few clicks to block USB ports, disable webcams during exams, or remotely deploy educational applications.
Android and Windows systems: Precise control with Microsoft 365 A1 for Devices
The large volume of Android tablets (over 220,000 units) and Windows 11 laptops (over 400,000 units) requires appropriate oversight to ensure the hardware serves educational purposes rather than entertainment. The optimal solution is the Microsoft 365 A1 for devices license. It functions similarly to the Google CEU license.
This license costs approximately PLN 150 net (~USD 38) and is a one-time fee tied to the physical lifecycle of the device (calculated up to a maximum of 6 years).
Microsoft 365 A1 for Devices application in school practice
- Android Tablet Management (Kiosk Mode / App Lock): The administrator can remotely lock the tablet interface, exposing only designated applications to the student. Access to system settings, the browser, and the app store is blocked. Software licenses are assigned en masse from the cloud.
- Securing Windows Stations (Shared PC): Windows 11 laptops are configured using a Shared PC profile. Login is performed via SSO with Google Cloud Identity, data automatically syncs with cloud storage, and local files are overwritten after a set period. Forced BitLocker encryption runs in the background.
- Bulk App Deployment: The administrator assigns software from the cloud to a group of devices. Applications install automatically once the device connects to the school Wi-Fi, saving hundreds of IT staff labor hours.
Staff and administrative protection: Google Endpoint Education Upgrade (EEU)
The greatest risk of personal data leaks occurs on devices used by management, teachers, and administrative staff who process sensitive data (e.g., national ID numbers, psychological-pedagogical center evaluations, medical records).
To secure this segment, the Google Endpoint Education Upgrade (EEU) license is used, available under an annual subscription model priced at approximately PLN 20 net per user per year. A single license assigned to an employee allows management of up to 15 of their devices.
Advanced protection mechanisms in EEU
- Work Profile on Personal Devices (BYOD): Logging in with a work account on a teacher's personal phone creates an isolated workspace (Work Profile on Android or Apple User Enrollment on iOS). School data is separated from personal apps and photos. Upon employment termination, the administrator wipes only the work container from the phone.
- Conditional Access (Zero Trust): The system analyzes the login context. It can block access to school databases if a login attempt comes from an unknown IP address or a device with an outdated operating system.
- Remote Wipe: In case a work device is lost, the administrator can remotely wipe the device memory, minimizing the risk of data exposure and protecting the school from UODO fines.
Economic analysis and model cost calculation
Implementing a centralized management system does not require ongoing, high annual financial outlays. Most expenditures are one-time costs.
Sample Cost Estimate for a Model Educational Institution
- Creating a 30-Station Chromebook Lab: The school utilizes 5 new KPO Chromebooks and 25 old laptops running ChromeOS Flex. Purchasing 25 Google Chrome Education Upgrade licenses at PLN 150 net each is required. Total one-time cost: PLN 3,750 net.
- Securing 30 Android Tablets and 60 Windows Laptops from KPO: The school purchases 90 Microsoft 365 A1 for devices licenses at PLN 150 net each. Total one-time cost: PLN 13,500 net.
- Protecting Devices of 30 Staff Members (EEU): The school purchases 30 annual Google Endpoint Education Upgrade licenses at PLN 20 net per year per person. Renewable cost: PLN 600 net per year.
In summary, fully securing the fleet and adapting it to legal regulations in a model school requires a one-time investment of PLN 17,250 net and a minor annual subscription fee of PLN 600 net.
IT infrastructure for AI and STEM Labs
KPO equipment also supports the operations of 16,000 Artificial Intelligence labs and 4,000 STEM laboratories. Working in these environments requires secure code execution, connecting sensors, and using open-source software.
A central management system provides the user access to a secure profile. Project files and data sync with cloud storage, and after the student logs out, the system automatically restores the clean initial configuration. Furthermore, specialized programming software can be deployed en masse to all devices directly from the cloud, relieving teachers from the need to manually configure workstations.
Implementation recommendations for governing bodies
To effectively secure KPO assets and fulfill legal obligations, following four steps is recommended:
- Implement Single Sign-On (SAML SSO): Integrate user identities across Google and Microsoft into a single authentication system protected by MFA.
- Utilize the ChromeOS Ecosystem: Activate Chrome Education Upgrade licenses and revitalize old computers using ChromeOS Flex to build secure mobile labs.
- Manage Windows and Android Fleets: Deploy Microsoft 365 A1 for devices licenses and configure tablets in kiosk mode and laptops in a Shared PC profile.
- Protect Data on Staff Devices: Apply Endpoint Education Upgrade licenses to create work profiles on staff members' personal and corporate devices.
Creating a modern and secure digital environment in schools does not demand massive financial outlays. Compared to the value of hardware acquired from the KPO and the potential financial consequences of personal data leaks, license costs represent a mere fraction of the budget.
However, it is worth remembering that possessing licenses is only the beginning – proper integration of identity systems, GDPR rules, and security policies requires professional engineering support.
As an authorized and certified technology partner of Google and Microsoft, the MScloud team assists governing bodies and school principals in transforming hardware challenges into an organized, secure, and fully compliant digital ecosystem.
We will guide you through the entire process: from audits and optimal license selection, through SSO identity federation, to the deployment of management policies for student and staff devices.
Contact the MScloud team and schedule a free technology consultation.
A detailed legal and technical analysis can be found in our full report: "IT Infrastructure Management and Licensing Strategy in the Polish Education System in Light of KPO Deliveries and New Legal Requirements".