BFCIT Posted April 25, 2016 Posted April 25, 2016 Hi All, Currently we provide our staff with their own SIMS SQL username/passwords to access SIMS in school. They receive a generated password and are then change it to one of their choice when they first login to SIMS. I have done a little bit of research on password management within SIMS and can only seem to find information about single sign on, linking SIMS with AD, which is the opposite of what I am trying to achieve. What I am interested to learn, is whether or not SIMS has an inbuilt password management section that we can use to make all staff users change their passwords (in line with password rotation in our password policy) and whether we can stipulate the complexity of the users password, like you can with Server 2012 and Fine grained password policies. Thank you,
Esteban_Child_of_the_Sun Posted April 25, 2016 Posted April 25, 2016 Currently SIMS can't do that. There are many change requests for such functionality. If you have a login for Capita's MyAccount then you can vote on some of them. e.g. Force SIMS password change and enforce more secure password 1212-1157750 Affected Products: System Manager 7 School has made a request to have a time limit on passwords in SIMS and for the system to enforce more secure passwords 1
BFCIT Posted April 25, 2016 Author Posted April 25, 2016 Thank you for your rapid response, I will be sure to take a look at the above link.
BFCIT Posted March 23, 2018 Author Posted March 23, 2018 Sorry to bump an old thread - I believe that you can configure SQL Server to utilise the OS/AD password policy. We use SQL 2014 to host SIMS, does anybody know the steps involved in applying the AD password policy for SQL users within the SIMS database? I can't seem to find a 'enforce password complexity' option within SQL itself. Thanks
matt40k Posted March 23, 2018 Posted March 23, 2018 Doesn't work with SIMS as SIMS mangles the password. Use Windows Auth
BFCIT Posted March 23, 2018 Author Posted March 23, 2018 Hi Matt40k, Thank you, can you elaborate on the windows auth? I know that you can configure single sign on with SIMS using AD details, but I still want teachers to be prompted to enter a user/pass when logging onto SIMS, would Windows auth enable this? Any dummy steps I need to take to get this working? Thanks
matt40k Posted March 23, 2018 Posted March 23, 2018 It's the same as Outlook - just passes the user token. It doesn't reauth. Again - it's a false wall. Pupils shouldn't be on a computer logged on as a member of staff - it just makes a mock of any auditing. If you really want to add a unnecessary barrier you could RemoteApps or something \ hosted.
bobsmith Posted March 23, 2018 Posted March 23, 2018 no, it's SSO. See the other thread which is currently on this topic.
BFCIT Posted March 23, 2018 Author Posted March 23, 2018 Hi Matt, I concur, more thinking about scenarios where mindless staff leave their computer unlocked but haven't opened SIMS. It would be nice to have the re-auth to stop opportunistic students getting on SIMS. - - - Updated - - - SSO just makes it even weaker in my opinion.
matt40k Posted March 23, 2018 Posted March 23, 2018 Hi Matt, I concur, more thinking about scenarios where mindless staff leave their computer unlocked but haven't opened SIMS. It would be nice to have the re-auth to stop opportunistic students getting on SIMS. SSO just makes it even weaker in my opinion. If you're staff are "mindless" enough to not be able to handle Windows+L how can they remember two secure passwords without writing it down on a post note or something?
BFCIT Posted March 23, 2018 Author Posted March 23, 2018 If you're staff are "mindless" enough to not be able to handle Windows+L how can they remember two secure passwords without writing it down on a post note or something? Common practice here no matter how many times staff are told to WINDOWS+L even with policy reinforcement, there is always a 'staff member' who is too busy or forgot. For me, they can write it down as long as wherever they write it is secured/locked away.
theeggmaster Posted March 23, 2018 Posted March 23, 2018 Common practice here no matter how many times staff are told to WINDOWS+L even with policy reinforcement, there is always a 'staff member' who is too busy or forgot. For me, they can write it down as long as wherever they write it is secured/locked away. Once SMT see how many data breaches are logged against this person under GDPR, they may take some action.
matt40k Posted March 23, 2018 Posted March 23, 2018 Common practice here no matter how many times staff are told to WINDOWS+L even with policy reinforcement, there is always a 'staff member' who is too busy or forgot. For me, they can write it down as long as wherever they write it is secured/locked away. Again, if they are too busy, why would they close SIMS? It takes an age to open \ Why would they remember to close SIMS vs pressing two buttons?
BFCIT Posted March 23, 2018 Author Posted March 23, 2018 I'm talking about scenarios where they haven't opened SIMS yet... - - - Updated - - - I do agree with you Matt, I can't answer for the folk that find WIN+L difficult.
matt40k Posted March 23, 2018 Posted March 23, 2018 I'm talking about scenarios where they haven't opened SIMS yet... Things have changed! They didn't use to take the laptop out the bag until it was time to do the register on SIMS!! God I feel old!
BFCIT Posted March 23, 2018 Author Posted March 23, 2018 The 'little darlings' just like to do their own thing.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now