genesis Posted November 15, 2016 Posted November 15, 2016 Hi We use SIMS and the server is within our network. When we have new SIMS user, the data team creates users name and password. Also when users forget their password, they have to contact the SIMS team reset their passwords. Currently, For Example; The User name convention on SIMS for John BRYN: SIMSJBR The same user name on our AD is : JBR So to log into SIMS their user name is: SIMSJBR To Log into the our network PCS is :JBR I was wondering if it will be possible to integrate SIMS with AD, so that users can AD credentials to log into SIMS. This will make life easier for staff not to have a separate password to log into SIMS. We use Salamander, not sure if it will be possible to do through this\any other, method that can be achieved. Thanks and any help and suggestions, much appreciated.
clareq Posted November 15, 2016 Posted November 15, 2016 It is possible to configure SIMS to use pass through authentication, but think carefully whether you want to - how many times to you have staff walk away from a logged on machine. At least a separate username/password means that a student can't access SIMS. (unless of course the username is on a post-it somewhere!)
Arthur Posted November 15, 2016 Posted November 15, 2016 At least a separate username/password means that a student can't access SIMS It's still less secure... http://www.edugeek.net/showthread.php?t=165330 See posts by @matt40k, @PhilNeal and @pete.
robyholmes Posted November 15, 2016 Posted November 15, 2016 We've taken the view that there's just as much personal data outside of SIMS as there is inside. So staff should lock workstations hence we login to SIMS automatically.
genesis Posted November 15, 2016 Author Posted November 15, 2016 Ho do i configure SIMS to use pass through authentication, Do i need to do this on the SIMS server. Grateful if you post me tutorials. Thanks
Davit2005 Posted November 15, 2016 Posted November 15, 2016 It is possible to configure SIMS to use pass through authentication, but think carefully whether you want to - how many times to you have staff walk away from a logged on machine. At least a separate username/password means that a student can't access SIMS. (unless of course the username is on a post-it somewhere!) And even let students use their AD accounts .
JHLEHS Posted November 15, 2016 Posted November 15, 2016 To configure SIMS so it works with AD you just need to do the following: On a domain computer with SIMS installed logged into the domain 1. add the following to the connect.ini ConnectionType=Trusted 2. Log into SIMS System manager locate an existing user and then click on the magnifying glass next to the name, type in the domain and click search this is where you can map the SIMS account with an AD account. The Username field should now display the domain\username ie. School\j.smith The password should appear blank 2
Esteban_Child_of_the_Sun Posted November 15, 2016 Posted November 15, 2016 If you use ConnectionType=TrustedAuto then staff won't even see the login box to click OK, it will just go straight in to SIMS 1
matt40k Posted November 15, 2016 Posted November 15, 2016 Yer AD login for the win. SIMS passwords aren't case sensitive, aren't forced to change regularly and until a few years ago pretty weak min password complexity (which I think you can still get round). Combine with the fact the "encrypted" passwords are stored in a SQL table and folks have zero brute force protection on SQL logins, your pretty much asking for it. Teaching Windows Key + L is better then a separate password (at least within a single organisation\school). Surprisingly I seem to remember Capita documenting the setup process quite well too, it was either in the built in documentation or the techy training course guide they created - it included mapping SIMS users to AD accounts and updating the connect.ini file and deploying it via S3, still might be the nostalgia setting in!!
vikpaw Posted November 15, 2016 Posted November 15, 2016 (edited) I used to find the domain name didn't pull through and it had to be manually keyed in, in front of the username. Worked like a charm. We had the system set to do Trusted and then the user just has to press OK. This gave us the option for an admin to come and log into SIMS manually using a regular uname/pword combo for troubleshooting. Edit: people leaving their stations logged in is a weak argument when the same users are just as likely to leave SIMS logged in as well, regardless of the credentials required. Edited November 15, 2016 by vikpaw
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now