Jump to content

Recommended Posts

Posted

Hello,

 

We're a small MAT consisting of both Secondary and Primary Schools. We have SIMS at the moment and are looking at moving to something a bit more FFP! We have them scheduled Arbor for a demonstration in a couple of weeks. If people can give me any feedback on their transition and any issues they faced it would be much appreciated. Positive experiences are welcomed as well.

 

We'd like to be able to give them examples of potential road humps we may come across and get them to explain how we'll get over them!

 

Thanks in advance.

Posted

One of my schools shifted just over a year ago, and I've not had to deal with any MIS type problems since!

 

IIRC some of the initial documentation for transferring the database wasn't in enough detail and wasn't written for the more literal mindset (most/many of us?). I assume this might have been updated since, certainly wasn't difficult to get it sorted with a phone call or two.

 

There has been some sort of problem recently to do with pupils moving schools. Arbor say they are following the established guidelines but SIMS isn't. Haven't heard any more about it, so suspect that's also resolved.

  • Thanks 2
Posted

10 School primary MAT here. Just completed our SIMS to Arbor migration last month. Migration was a breeze, all 10 in one weekend! Admin and Teaching staff are loving it.

 

One thing to watch out for is 3rd party system integrations, we have found a few of these to be more difficult than first described. It's early days but that's the only issue that's come up so far.

  • Thanks 1
Posted
One thing to watch out for is 3rd party system integrations, we have found a few of these to be more difficult than first described. It's early days but that's the only issue that's come up so far.

 

Arbor say they are happy to work with 3rd Parties to get the integration sorted but the school that uses them doesn't have much need. OTH there are possibly slanderous rumours that other MIS providers favour those that don't work too hard to mesh with rival systems.

  • 3 weeks later...
Posted

Just thought I would add my experience to this. We are a new single academy, and had been running Arbour from when the school started. That seemed to work fine for the small school (and without any IT Staff). I started as ICT Manager last January, and oversaw the migration to Bromcom over the summer.

For the migration from Arbour, we had to write a load of reports to get the data out in csv format, and then work it around into the format Bromcom needs for the import, which did take a while. That was made more complicated by the slightly haphazard way we had been using Arbour, but we got there. We then uploaded all those exports to Bromcom and over the course of a week or so they worked through importing them into our system, and coming back to me with questions! The only real quirk I remember from the migration was around teaching groups - the import brought them all in with the same name and description (eg 1MaA), but as soon as you when in to edit them, the "Proper" description (eg First Form Maths Group A) started to appear. Other than that, it was all extremely smooth.

We are now nearly a year into it, and it has been for the most part very successful, we are still struggling with the behaviour module a little (more to do with us really thinking through how sanctions work - if you give out more sanction than there are slots in a week, they will start to book up way in advance for some of our kids!).

If you have more questions, please do ask!

Tom

Posted
Sorry, OP was asking about a move to Bromcom in another thread, but wanted to keep the Arbor discussion elsewhere. I mistook it as a move from Arbor to Bromcom - sorry.
Posted
Actually, the move away from Arbour is also relevent. When moving to any technology you *have* to consider the exit strategy. Failing to do this could mean serious problems further down the line, so I would consider the mention of Bromcom within the boundaries of relevance for others reading this thread over time.
  • Thanks 2
  • 2 weeks later...
Posted
We had the Arbor demo and was pretty impressed with the overview we were given. Something disappointing was that there doesn't seem a way to offer SSO to staff and integrate with Federation Services. Has anyone else had this discussion or come across this when migrating or looking at migrating? I'm waiting on their programming team getting back to me with more information.
Posted
We had the Arbor demo and was pretty impressed with the overview we were given. Something disappointing was that there doesn't seem a way to offer SSO to staff and integrate with Federation Services. Has anyone else had this discussion or come across this when migrating or looking at migrating? I'm waiting on their programming team getting back to me with more information.

 

I asked about this when we moved over. If i remember correctly they currently (or are close to) supporting SSO through google accounts. O365 however is not supported.

Posted

SSO / federated Access is not always a good thing. If the main account username / password is compromised then access to the MIS is then open too.

 

There have been incidents of this in schools previously, including one school having to sign an Undertaking with ICO as a result.

  • Thanks 1
Posted
SSO / federated Access is not always a good thing. If the main account username / password is compromised then access to the MIS is then open too.

 

There have been incidents of this in schools previously, including one school having to sign an Undertaking with ICO as a result.

 

Agreed - SSO to sensitive systems with good MFA (i.e. no SMS codes) is fine, but otherwise I'd steer clear.

  • Thanks 1
Posted
SSO / federated Access is not always a good thing. If the main account username / password is compromised then access to the MIS is then open too.

There have been incidents of this in schools previously, including one school having to sign an Undertaking with ICO as a result.

 

This kinda goes against NCSC advice - basically people get password fatigue having to remember numting passwords with different password requirements and policies and ultimately people are lazy and reuse passwords which makes their password less secure (you've now got 12 places storing the same information that could be hack rather then 1). I accept password managers resolve this issue but really it's a work around to the fact lot of places don't support SSO - you are after all basically using 1 password to get into other systems. This is all off course forgetting the fact that you now have 2 or more places to manage - I dread to think how many accounts for random things I still have active from previous jobs that got missed and this is with company spending £££ on automation of account management (creation \ disable \ delete) based on HR data.

Posted (edited)

“However, if an attacker compromises a user's account or password, that attacker could have easy access to far more content than they might have in a traditional system. For this reason, we recommend that SSO be implemented to require MFA.”

 

https://www.ncsc.gov.uk/collection/passwords/updating-your-approach

 

It is a risk assessment and introducing SSO to connect to your MIS significantly increases the risk to Personal Data and Special Category Personal Data ... and considering that there is evidence of this resulting in data breaches (including sanctions against a school) then you *have* to treat it with caution.

The use of MFA is a good countermeasure but you have to also look at how good it is at treating the risk. Good if app-based on a phone that also has access control on it but not as good if a code generating token that is in the same bag as the notebook where a user has written down their passwords!

Edited by GrumbleDook
Posted
SSO / federated Access is not always a good thing. If the main account username / password is compromised then access to the MIS is then open too.

 

There have been incidents of this in schools previously, including one school having to sign an Undertaking with ICO as a result.

 

Thats not the fault of SSO or federated services. There should be 2 factor authentication for the first login.

  • Thanks 1
Posted
It is worth saying that some schools can not afford MFA and not all SSO/federation can be set up to allow it.

So corners get cut ...

We know corners get cut.

 

Sorry, could you expand on MFA costs? Also I don't understand why you wouldn't have MFA on MIS system?

Posted (edited)

All my primary schools use MFA already so having SSO just makes sense. It's probably a main reason are are not getting Arbor

 

UPDATE: We recently had a demo and were told it was not supported, but reading the previous posts it looks like it might be. I'll contact them and check

Edited by TwistedHelixis
Posted
Sorry, could you expand on MFA costs? Also I don't understand why you wouldn't have MFA on MIS system?

 

You may not have MFA on your SSO ...

 

Actually, some of the organisational barriers to MFA on MIS also apply to SSO to, to be honest ... however, I think this is going off-topic for this thread ... @matt40k if you fancy starting a thread on it, it could be worth folk talking about the technical and organisational issues they have had to deal with in implementing MFA.

 

Staff not wanting an app on their personal phone is one that comes up.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...