matt40k Posted February 11, 2015 Posted February 11, 2015 Is using ADFS an option? O365 and Google work with this. ADFS would be the answer, I'm not not aware of many schools \ LA implementing it however. Also there is a "admin" cost in terms of setting up the trust. For the uneducated. ADFS is Microsoft authentication method for the cloud. It basically allows you to build a trust between cloud providers. Once it is setup when you hit your cloud provider, they will then pass you to your own AD for authentication, then you can use your issued token to access the cloud services. ADFS also allows you to define your own grain of security - ie on (your) prem, just user\pass, off (your) prem then user\pass + 2 factor - telephone, text, mobile, one-time token thing, or even a combination of them and\or a school owned device or fully patched device. The bottom line is, if you've set it up correctly, you, the end-user, have no idea if the application\service\whatever is on-prem or off-prem. From an admin point of view, person leaves, go into AD, hit disable. Bang, they are locked out. No messing around disabling 4-5 accounts. From a security point of view, users are more likely to change their password more frequency, its only 1 place that the password is stored and its managed by you, not 50 different cloud providers all with different password requirements. The main problem for schools is you need to use that Azure credit to build a read only replica of your AD in Azure then build the ADFS stuff up their too so you don't get latency issues. This is the bit where I think ADFS would fall over for Capita @vikpaw. 2
Stuclark Posted February 12, 2015 Posted February 12, 2015 The idea behind using Google, Microsoft Live (and soon Office 365) authentication is that users don’t need SIMS IDs to be issued and maintained. Almost everyone has one of these IDs so it should reduce the overhead of managing teacher staff access. Phil, could you please tell us when "soon" is - I'm getting pressured to implement the Teacher App, but having just created an Azure sync'd copy of our AD into Office365 for all our staff, I'm not now going to manually create each of them a Microsoft account (which has no password sync / which I can't control in any way etc.) purely so they can use an app whilst in our school, on our network, accessing a locally hosted, AD authenticated, network resource (SIMS). 1
vikpaw Posted February 12, 2015 Posted February 12, 2015 @Stuclark - be interested to hear how you did this and any issues you had, i think we might go ahead with this ADFS business, although some have said to avoid it lik the plague.
Stuart_C Posted February 12, 2015 Posted February 12, 2015 Hi, this might (or might or might not) be a bit of thread-jacking but I've fallen at the first hurdle with this because I can't login to get the app! Now I've got office365 login with my work details and I can log into office 365, however when I try and authenticate using my Office 365 login from the SIMS page apparently I don't exist (yet my personal one works fine). Any ideas why? I have it doing a DirSync with passwords into Office 365 but I haven't set up a full ADFS line with SSO. Is that a possible issue?
Stuclark Posted February 12, 2015 Posted February 12, 2015 Hi, this might (or might or might not) be a bit of thread-jacking but I've fallen at the first hurdle with this because I can't login to get the app! Now I've got office365 login with my work details and I can log into office 365, however when I try and authenticate using my Office 365 login from the SIMS page apparently I don't exist (yet my personal one works fine). Any ideas why? I have it doing a DirSync with passwords into Office 365 but I haven't set up a full ADFS line with SSO. Is that a possible issue? Although Capita say it is, Office365 authentication is currently not supported or available, for use with the Teacher App. I've just had Capita confirm this is the case - they say Office365 support will be available "in the coming weeks"
jamesfed Posted February 12, 2015 Posted February 12, 2015 For the uninitiated - What's it do? Read/Write data or just read?
BrotherSidious Posted February 12, 2015 Posted February 12, 2015 We are currently using SLG and were told (by a rep not more than two weeks ago) that we would receive the Teacher App for free as an SLG customer. When we adopted SLG we didn't have to set up any google, micorsoft live or Office 365 accounts for staff to use that and surely SLG offers more functionality than the teacher App. Due to this I am perplexed why any of the schools that "evaluated" the APP and had SLG didn't raise this point. As it stands, I now discover that I have to pay for the App and configure another bunch of accounts. In short, I have to carry out far more work and pay for the privilege. This can be spun anyway you like but it comes across to me as a spectacular own goal. I can understand a "stand alone version" for those that don't have SLG or AD but for those that do this appears to be an unnecessary level of complexity. After initially looking forward to the release of this Teacher App this has all led to a great sense of disappointment in terms of an opportunity missed. Based on the above posts I somehow feel I am not alone in this opinion.
Stuart_C Posted February 12, 2015 Posted February 12, 2015 @Stuclark Cheers for the response. That's helpful, and I understand your earlier comment a bit more now. Surely that would have been the thing to do first? Which school has MS ID's for all their staff so they don't use personal one's that isn't linked through Office365?
matt40k Posted February 12, 2015 Posted February 12, 2015 Staff are not allowed to use personal email accounts in school for safety reasons. I try and authenticate using my Office 365 login from the SIMS page apparently I don't exist (yet my personal one works fine). I guess the "not allowed" doesn't mean not physically possible.
GREED Posted February 12, 2015 Posted February 12, 2015 I guess the "not allowed" doesn't mean not physically possible. I guess it means all staff have to have yet another account to use and remember...
Stuart_C Posted February 12, 2015 Posted February 12, 2015 @matt40k I'll just say for clarity that I didn't actually use my personal account. 1: I don't want it and 2: It's stupid for many reasons. However the fact that I could authenticate makes me wonder how the organization is protected when badgering the staff fails? Personally i think this won't be looked at until Capita get it sorted and I can use Office 365, AD Sync'd logins.
matt40k Posted February 12, 2015 Posted February 12, 2015 No, I think the paints still wet. Fair play for them wanting something for BETT and its great it appears to be in demand, but they are letting the sales guys lead the product out the door whilst the devs are still finishing it. Its the sort of thing a certain ex product manager would have put his foot down and stopped from happening...
matt40k Posted February 12, 2015 Posted February 12, 2015 @Stuart_C Sorry, I didn't mean to indicate you have, I know you wouldn't, more a question that you can - which means someone else could. We both know the damages of being able to use personally accounts, for starts, one typo and you've just given a total stranger access to your SIMS data!
Stuart_C Posted February 12, 2015 Posted February 12, 2015 'S OK I know you didn't. But yes it does raise the question of how "we" as the organization admin can check the system to make sure staff are not using personal ID's (I know they should be told not to and adhere to it but....) The other thing I'm curious about is how it works with trusted authentication (like we have). Teachers are going to love putting DomainName\username into that login box.
Stuclark Posted February 12, 2015 Posted February 12, 2015 The other thing I'm curious about is how it works with trusted authentication (like we have). Teachers are going to love putting DomainName\username into that login box. The way I understand it is that they won't have to actually log in to SIMS. To authorise an (AD / SIMS) account to use the Teacher App, that account must be linked to a Microsoft or Google (or at some point in the future Office365) account; which will in turn be linked to a particular iPad. The user will then unlock their iPad using their Apple code; log into the SIMS Teacher App using their Microsoft or Google account; then, if configured how Capita recommend, sign in to the Teacher App one more time using another numeric PIN. This numeric PIN will expire every 12 or 24 hours, meaning they have to think of and remember a new one every day. (I'm not sure if you can re-use the same one, but it would seem to be a security hole if you can) The apparent advantage of this is that the SIMS user details don't get passed around anywhere...
PhilNeal Posted February 13, 2015 Posted February 13, 2015 @Stuclark I'm not able to say how soon we'll have O365. We had hoped it would be ready for the Feb release but MS couldn't figure why it wouldn't work! Since we are working at MS COO level I don't think it will be long. The whole on-boarding process has been designed to be simple, avoiding complex installs but safe. We're a FTSE100 company and do not take risks with children's data. We currently have around 80,000 registered users making use of Google/Live IDs to access SIMS modules.
matt40k Posted February 13, 2015 Posted February 13, 2015 How many of those 80,000 are Live ID - these are personal accounts?? How many are "free" addresses - @Hotmail.co.uk etc? MS couldn't figure why it wouldn't work! Since we are working at MS COO level Mmm...
PhilNeal Posted February 15, 2015 Posted February 15, 2015 Sorry I don't know how many are personal accounts.
Jonah Posted February 15, 2015 Posted February 15, 2015 Not allowing auth against a widely used solution like AD is just a bad idea, no matter how it's spun. 1
matt40k Posted February 16, 2015 Posted February 16, 2015 Sorry I don't know how many are personal accounts. I think someone at your place is telling porkies because they don't want to be the bearer of bad new, surely the person who told you that you have 80,000 users would know. Otherwise, how do they know they don't actually have 70,000 @Capita.co.uk users? Or 10,000 users with the same email address? Surely its a question of exporting the list of users - then go, hey - @gmail.com, @Hotmail.co.uk - that ain't right...
PhilNeal Posted February 16, 2015 Posted February 16, 2015 An update on O365 authentication. We have the answer and expect to implement by mid-March.
TheScarfedOne Posted February 16, 2015 Posted February 16, 2015 I fail to understand why you would want the App (which incidentally is iOS, Android and Windows Modern) to auth to AD. The point is that this is for use outside as well as inside the classroom. Now, before people start - I do not work for Capita, I am an independent journalist when it comes to my interactions there. Having attended a number of high level Microsoft events lately, and Im sure @EduTech will back me up with this, Azure AD (aka the auth behind Office 365) is the way things will be going. Windows 10 supports Azure AD auth from the initial logon - and all those schools using Office 365, guess what - that will bring SSO. So, the real story here is that by leveraging the Google and Microsoft Cloud logins - you are allowing users to keep using familiar credentials. At the moment, that will be gmail and Microsoft Accounts. I see no reason why the Google login (correct me if Im wrong @PhilNeal) couldn't be a GADS account. The same Im sure will be true of Office 365 once Microsoft sort out the issue that Capita have. Also...think outside the current "Teacher" version... there would in theory be future scope for a pupil, parent, governor etc versions. How would you get those "linked" to a device - which definitely wont be a School owned device? The freedom is that the device for the teacher doesn't need to be a School owned device either. Parents etc also wouldn't have local credentials. Let them use the same cloud logins - as already is the case with Agora. Why reinvent the wheel? 1
FN-GM Posted February 16, 2015 Posted February 16, 2015 I fail to understand why you would want the App (which incidentally is iOS, Android and Windows Modern) to auth to AD. The point is that this is for use outside as well as inside the classroom. Now, before people start - I do not work for Capita, I am an independent journalist when it comes to my interactions there. Having attended a number of high level Microsoft events lately, and Im sure @EduTech will back me up with this, Azure AD (aka the auth behind Office 365) is the way things will be going. Windows 10 supports Azure AD auth from the initial logon - and all those schools using Office 365, guess what - that will bring SSO. So, the real story here is that by leveraging the Google and Microsoft Cloud logins - you are allowing users to keep using familiar credentials. At the moment, that will be gmail and Microsoft Accounts. I see no reason why the Google login (correct me if Im wrong @PhilNeal) couldn't be a GADS account. The same Im sure will be true of Office 365 once Microsoft sort out the issue that Capita have. Also...think outside the current "Teacher" version... there would in theory be future scope for a pupil, parent, governor etc versions. How would you get those "linked" to a device - which definitely wont be a School owned device? The freedom is that the device for the teacher doesn't need to be a School owned device either. Parents etc also wouldn't have local credentials. Let them use the same cloud logins - as already is the case with Agora. Why reinvent the wheel? Personally i wouldn't want staff to have a separate username and password than they already have. I don't really care how it is done but if there was a way to have it so it uses the on premise credentials. Maybe ADFS or via Office 365 or something else. Why would end users want to have different sets of credentials?
matt40k Posted February 16, 2015 Posted February 16, 2015 @TheScarfedOne I agree, ADFS/Azure AD (whatever Microsoft brands it) is the way forward. You sync your on-prem with one cloud provider (Microsoft) and your done. I don't agree with your statement about the personal accounts, if you were correct, why would Microsoft offer a "enterprise" solution? From the point of view of administration, enterprise makes sense, you disable a local AD account, then all the cloud services are automatically disabled. As for parents, I agree, they will be wanting to use personal non-O365, no-one would want to fund the license costs, but their is a key difference between a parent and a teacher is a parent is going to have access to what, a 3 students and a limit subset of data - teachers are going to see what, at least 28 students and the full data set. My main bug bear is the fact they've released it into the wild with Office 365 auth not work - not being funny, they are using Microsoft technology, that seems like a massive problem to me, if the out-the-box stuff isn't working it doesn't inspire confidence. Because of this I would imagine a large number of those 80,000 accounts are personal accounts and I'm surprised this passed PEN testing. Add the fact they claim they don't know how many are personal accounts, which I find unbelievable. So any School\LA who have setup remote access and forced 2 factor authentication in the name of security now have the away of bypassing it, without any way of verifying that any of those accounts have 2 factor enabled, or even any proper password policy or even auditing enabled all because the school\LA has no idea what levels of security the individual has on their personal account. So it's because putting techies in a position of either say to the boss "hey, great that you've purchase that new Capita service, but you can't use it till AT LEAST mid-March", or setting up butt loads of personal accounts (which would contradict the whole idea of Azure AD). Anyway, just seems irresponsible for FTSE100 company to release a product in a such a unpolished state, especially when there are alternative products on the market, or perhaps that's why its be rushed out the door...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now