Jump to content

Recommended Posts

Posted
Is using ADFS an option? O365 and Google work with this.

 

ADFS would be the answer, I'm not not aware of many schools \ LA implementing it however. Also there is a "admin" cost in terms of setting up the trust.

 

For the uneducated. ADFS is Microsoft authentication method for the cloud. It basically allows you to build a trust between cloud providers. Once it is setup when you hit your cloud provider, they will then pass you to your own AD for authentication, then you can use your issued token to access the cloud services. ADFS also allows you to define your own grain of security - ie on (your) prem, just user\pass, off (your) prem then user\pass + 2 factor - telephone, text, mobile, one-time token thing, or even a combination of them and\or a school owned device or fully patched device. The bottom line is, if you've set it up correctly, you, the end-user, have no idea if the application\service\whatever is on-prem or off-prem. From an admin point of view, person leaves, go into AD, hit disable. Bang, they are locked out. No messing around disabling 4-5 accounts. From a security point of view, users are more likely to change their password more frequency, its only 1 place that the password is stored and its managed by you, not 50 different cloud providers all with different password requirements.

 

The main problem for schools is you need to use that Azure credit to build a read only replica of your AD in Azure then build the ADFS stuff up their too so you don't get latency issues. This is the bit where I think ADFS would fall over for Capita @vikpaw.

  • Thanks 2
Posted
The idea behind using Google, Microsoft Live (and soon Office 365) authentication is that users don’t need SIMS IDs to be issued and maintained. Almost everyone has one of these IDs so it should reduce the overhead of managing teacher staff access.

Phil, could you please tell us when "soon" is - I'm getting pressured to implement the Teacher App, but having just created an Azure sync'd copy of our AD into Office365 for all our staff, I'm not now going to manually create each of them a Microsoft account (which has no password sync / which I can't control in any way etc.) purely so they can use an app whilst in our school, on our network, accessing a locally hosted, AD authenticated, network resource (SIMS).

  • Thanks 1
Posted

Hi, this might (or might or might not) be a bit of thread-jacking but I've fallen at the first hurdle with this because I can't login to get the app!

Now I've got office365 login with my work details and I can log into office 365, however when I try and authenticate using my Office 365 login from the SIMS page apparently I don't exist (yet my personal one works fine).

 

Any ideas why? I have it doing a DirSync with passwords into Office 365 but I haven't set up a full ADFS line with SSO. Is that a possible issue?

Posted
Hi, this might (or might or might not) be a bit of thread-jacking but I've fallen at the first hurdle with this because I can't login to get the app!

Now I've got office365 login with my work details and I can log into office 365, however when I try and authenticate using my Office 365 login from the SIMS page apparently I don't exist (yet my personal one works fine).

 

Any ideas why? I have it doing a DirSync with passwords into Office 365 but I haven't set up a full ADFS line with SSO. Is that a possible issue?

 

Although Capita say it is, Office365 authentication is currently not supported or available, for use with the Teacher App.

 

I've just had Capita confirm this is the case - they say Office365 support will be available "in the coming weeks"

Posted

We are currently using SLG and were told (by a rep not more than two weeks ago) that we would receive the Teacher App for free as an SLG customer. When we adopted SLG we didn't have to set up any google, micorsoft live or Office 365 accounts for staff to use that and surely SLG offers more functionality than the teacher App. Due to this I am perplexed why any of the schools that "evaluated" the APP and had SLG didn't raise this point.

As it stands, I now discover that I have to pay for the App and configure another bunch of accounts. In short, I have to carry out far more work and pay for the privilege. This can be spun anyway you like but it comes across to me as a spectacular own goal. I can understand a "stand alone version" for those that don't have SLG or AD but for those that do this appears to be an unnecessary level of complexity. After initially looking forward to the release of this Teacher App this has all led to a great sense of disappointment in terms of an opportunity missed. Based on the above posts I somehow feel I am not alone in this opinion.

Posted
@Stuclark Cheers for the response. That's helpful, and I understand your earlier comment a bit more now. Surely that would have been the thing to do first? Which school has MS ID's for all their staff so they don't use personal one's that isn't linked through Office365?
Posted
Staff are not allowed to use personal email accounts in school for safety reasons.

 

I try and authenticate using my Office 365 login from the SIMS page apparently I don't exist (yet my personal one works fine).

 

I guess the "not allowed" doesn't mean not physically possible.

Posted
I guess the "not allowed" doesn't mean not physically possible.

 

I guess it means all staff have to have yet another account to use and remember...

Posted

@matt40k I'll just say for clarity that I didn't actually use my personal account. 1: I don't want it and 2: It's stupid for many reasons.

However the fact that I could authenticate makes me wonder how the organization is protected when badgering the staff fails?

 

Personally i think this won't be looked at until Capita get it sorted and I can use Office 365, AD Sync'd logins.

Posted

No, I think the paints still wet.

 

Fair play for them wanting something for BETT and its great it appears to be in demand, but they are letting the sales guys lead the product out the door whilst the devs are still finishing it. Its the sort of thing a certain ex product manager would have put his foot down and stopped from happening...

Posted
@Stuart_C Sorry, I didn't mean to indicate you have, I know you wouldn't, more a question that you can - which means someone else could. We both know the damages of being able to use personally accounts, for starts, one typo and you've just given a total stranger access to your SIMS data!
Posted

'S OK :) I know you didn't. But yes it does raise the question of how "we" as the organization admin can check the system to make sure staff are not using personal ID's (I know they should be told not to and adhere to it but....)

 

The other thing I'm curious about is how it works with trusted authentication (like we have). Teachers are going to love putting DomainName\username into that login box. :rolleyes:

Posted
The other thing I'm curious about is how it works with trusted authentication (like we have). Teachers are going to love putting DomainName\username into that login box. :rolleyes:

The way I understand it is that they won't have to actually log in to SIMS.

 

To authorise an (AD / SIMS) account to use the Teacher App, that account must be linked to a Microsoft or Google (or at some point in the future Office365) account; which will in turn be linked to a particular iPad. The user will then unlock their iPad using their Apple code; log into the SIMS Teacher App using their Microsoft or Google account; then, if configured how Capita recommend, sign in to the Teacher App one more time using another numeric PIN. This numeric PIN will expire every 12 or 24 hours, meaning they have to think of and remember a new one every day. (I'm not sure if you can re-use the same one, but it would seem to be a security hole if you can)

 

The apparent advantage of this is that the SIMS user details don't get passed around anywhere...

Posted

@Stuclark I'm not able to say how soon we'll have O365. We had hoped it would be ready for the Feb release but MS couldn't figure why it wouldn't work! Since we are working at MS COO level I don't think it will be long.

 

The whole on-boarding process has been designed to be simple, avoiding complex installs but safe. We're a FTSE100 company and do not take risks with children's data. We currently have around 80,000 registered users making use of Google/Live IDs to access SIMS modules.

Posted

How many of those 80,000 are Live ID - these are personal accounts?? How many are "free" addresses - @Hotmail.co.uk etc?

 

MS couldn't figure why it wouldn't work! Since we are working at MS COO level

 

Mmm...

Posted
Sorry I don't know how many are personal accounts.

 

I think someone at your place is telling porkies because they don't want to be the bearer of bad new, surely the person who told you that you have 80,000 users would know. Otherwise, how do they know they don't actually have 70,000 @Capita.co.uk users? Or 10,000 users with the same email address? Surely its a question of exporting the list of users - then go, hey - @gmail.com, @Hotmail.co.uk - that ain't right...

Posted

I fail to understand why you would want the App (which incidentally is iOS, Android and Windows Modern) to auth to AD. The point is that this is for use outside as well as inside the classroom. Now, before people start - I do not work for Capita, I am an independent journalist when it comes to my interactions there.

 

Having attended a number of high level Microsoft events lately, and Im sure @EduTech will back me up with this, Azure AD (aka the auth behind Office 365) is the way things will be going. Windows 10 supports Azure AD auth from the initial logon - and all those schools using Office 365, guess what - that will bring SSO. So, the real story here is that by leveraging the Google and Microsoft Cloud logins - you are allowing users to keep using familiar credentials. At the moment, that will be gmail and Microsoft Accounts. I see no reason why the Google login (correct me if Im wrong @PhilNeal) couldn't be a GADS account. The same Im sure will be true of Office 365 once Microsoft sort out the issue that Capita have.

 

Also...think outside the current "Teacher" version... there would in theory be future scope for a pupil, parent, governor etc versions. How would you get those "linked" to a device - which definitely wont be a School owned device? The freedom is that the device for the teacher doesn't need to be a School owned device either. Parents etc also wouldn't have local credentials. Let them use the same cloud logins - as already is the case with Agora. Why reinvent the wheel?

  • Thanks 1
Posted
I fail to understand why you would want the App (which incidentally is iOS, Android and Windows Modern) to auth to AD. The point is that this is for use outside as well as inside the classroom. Now, before people start - I do not work for Capita, I am an independent journalist when it comes to my interactions there.

 

Having attended a number of high level Microsoft events lately, and Im sure @EduTech will back me up with this, Azure AD (aka the auth behind Office 365) is the way things will be going. Windows 10 supports Azure AD auth from the initial logon - and all those schools using Office 365, guess what - that will bring SSO. So, the real story here is that by leveraging the Google and Microsoft Cloud logins - you are allowing users to keep using familiar credentials. At the moment, that will be gmail and Microsoft Accounts. I see no reason why the Google login (correct me if Im wrong @PhilNeal) couldn't be a GADS account. The same Im sure will be true of Office 365 once Microsoft sort out the issue that Capita have.

 

Also...think outside the current "Teacher" version... there would in theory be future scope for a pupil, parent, governor etc versions. How would you get those "linked" to a device - which definitely wont be a School owned device? The freedom is that the device for the teacher doesn't need to be a School owned device either. Parents etc also wouldn't have local credentials. Let them use the same cloud logins - as already is the case with Agora. Why reinvent the wheel?

 

Personally i wouldn't want staff to have a separate username and password than they already have. I don't really care how it is done but if there was a way to have it so it uses the on premise credentials. Maybe ADFS or via Office 365 or something else. Why would end users want to have different sets of credentials?

Posted

@TheScarfedOne I agree, ADFS/Azure AD (whatever Microsoft brands it) is the way forward. You sync your on-prem with one cloud provider (Microsoft) and your done.

 

I don't agree with your statement about the personal accounts, if you were correct, why would Microsoft offer a "enterprise" solution? From the point of view of administration, enterprise makes sense, you disable a local AD account, then all the cloud services are automatically disabled.

 

As for parents, I agree, they will be wanting to use personal non-O365, no-one would want to fund the license costs, but their is a key difference between a parent and a teacher is a parent is going to have access to what, a 3 students and a limit subset of data - teachers are going to see what, at least 28 students and the full data set.

 

My main bug bear is the fact they've released it into the wild with Office 365 auth not work - not being funny, they are using Microsoft technology, that seems like a massive problem to me, if the out-the-box stuff isn't working it doesn't inspire confidence. Because of this I would imagine a large number of those 80,000 accounts are personal accounts and I'm surprised this passed PEN testing. Add the fact they claim they don't know how many are personal accounts, which I find unbelievable. So any School\LA who have setup remote access and forced 2 factor authentication in the name of security now have the away of bypassing it, without any way of verifying that any of those accounts have 2 factor enabled, or even any proper password policy or even auditing enabled all because the school\LA has no idea what levels of security the individual has on their personal account. So it's because putting techies in a position of either say to the boss "hey, great that you've purchase that new Capita service, but you can't use it till AT LEAST mid-March", or setting up butt loads of personal accounts (which would contradict the whole idea of Azure AD).

 

Anyway, just seems irresponsible for FTSE100 company to release a product in a such a unpolished state, especially when there are alternative products on the market, or perhaps that's why its be rushed out the door...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...