Some people would just bring their own mouse in to get past the defences.
They also used a surveillance system called LanSchool, which sent out all of its commands entirely unencrypted and unauthenticated, so people would spoof the remote takeover command and steal exams from teachers' accounts. It ended up being a whole thing my senior year.
The name of the class? "Digital literacy".
You overestimate "professional best practices" in many places...
One example was that my school refused to give out the Wi-Fi password as a form of security, so they'd demand to manually type it in themselves on your machine. A simple keylogger and now the whole school just ignored that rule for a few months.
Another is that while they tried to block things like SSH, VPNs, etc... to get around the school's internet filtering, turns out you could just run SSH over port 80 and have a tunnel out :)