Jump to content

Recommended Posts

Posted

After years of having static, complex passwords we have had a security audit that has recommended that passwords are changed regularly. I do not want the IT department to be responsible for changing dozens of passwords a week so need to find a self-service password reset tool that works with on-premise AD (and potentially Azure AD if that is what we end up doing at some point). We are talking about both students and staff so although free would be good it is more important that it is simple to use so commercial is an option.

 

Currently looking at Manageengine but price may be a barrier - $2800 per annum for 3k users although I need to see if there is movement for education and delete a load of old accounts which may bring us into a lower price bracket etc.

 

Passwords are a contnetious issue at the best of times - there is plenty of advice that you should change them regularly but probably almost as much that you shouldn't and instead rely on 2fa or something similar.

 

Al always, thanks in advance :)

Posted
We use a custom mmc snapin displaying the students ou, with cut down ad tools installed and delegated permissions only to teachers for only resetting passwords on students, also the ad-tools are only installed on teaching pcs. Free, all microsoft tools, already got mmc on the machine. Only ourselves can change the staff passwords.
Posted
Thanks @Martin48, I've been thinking about this on the drive home. I did consider delegated permissions but our staff are not technical, some of them struggle to open documents (although some are very, very good) and they are already pushed to do more and more in less and less time so it's not an option to make them responsible to reset student passwords. The recommendation from the auditor was that staff passwords were changed every 42 days but we could leave students as they are. I think that if we are preparing them for the outside world then we should change their passwords as well - although I may well reconsider that and come to a different conclusion overnight! Our student passwords are stored an a password protected Excel spreadsheet (read only for anybody outside of the IT department) so currently any member of staff could tell a student what their password is. These passwords are not complex - 6 numbers - but some students have enough trouble remembering those so perhaps a rethink is required. Staff passwords on the other hand are complex and consist of 10/11 characters including uppercase, lowercase, numbers and non-alphanumeric and I would like to keep that level of complexity if I can. However, we do not have the resource to be changing 100+ staff passwords every 6 weeks because they cannot remember what they set it to which is why I want to look at a self-service option.
Posted (edited)

Fair enough, ours is more for students we allow staff to put a ticket and have us do it then usually send a generic guide saying they could also do it themselves which reduces calls. (to new staff and cover)

I wouldn't trust our staff to change each others passwords!! although considering to allow business manager to do it at a primary via the mmc method (since we are not onsite all the time)

I know your looking at azure ad, don't know if you are using office 365 with azure ad connect, because the newer tool allows password write back allowing self service via the microsoft 365 portal but that might require a personal/work phone number or email as secondary authentication which you would have to look at your policies about and a security risk.

 

edit: just thought the password write-back might not be too useful for people already onsite...

for reference we get around 50% of our staff forgetting their password at the end of summer, make for a busy inset day, then about 5 or so on other holidays and about 1 every other day. Typically even the less tech savvy get embarrassed with having to call up every time, and lets face it most people just change the last digit of their original password, or write it on a post-it note (we ask they don't do that but what we ask is not always what we get)

Edited by Martin48
Posted

We do use azure ADConnect at present but not every AD user has an O365 account and not every O365 account has a corresponding AD account although it is definitely worth looking at. With regard to staff forgetting passwords - we've always issues staff with a complex (but simple to remember) password made up of a couple of 3 letter words with a symbol between them and the month/year the password was created at the end, for example Fog-Bus417 or Day=Sun417 would be generated today but last month the numbers would have been 317, next month 517 etc. We synch those passwords between AD, O365 (although we are now starting to use ADConnect so that requirement will disappear), our MIS, our class registration software and potentially a couple of other bits of software as well.

 

Given that some our users are like everybody else's and need their password reset NOW! IMMEDIATELY!!1! I would prefer them to be able to change it themselves, a great option would be the ability to choose between an email, a text message or a phone call but if we go that route we will definitely restrict it to staff only as we would burn through thousands of texts to students.

Posted

We use Nervepoint which is free https://www.hypersocket.com/en/products/password-self-service (for basic features which includes self-service password reset). Comes as virtual appliance s too if you'd like.

 

Handy tip - do what I did when setting it up, which is I pre-filled in answers to the security questions with known data :)

 

We have it setup as some standalone machines on campus, and have make it available off-campus too

  • Thanks 1
Posted
Had a look at Nervepoint (or Access Manager as it is now called), is there a way for the user to change the password at login time as there is with the ManageEngine product? At 1st glance it seems to be a 'kiosk' style service that allows you to change the password using a dedicated machine but not one that allows you to change it using the PC you are sitting in front of at the point of logging in. I do like the price however!
Posted
We use Foldr https://foldr.io/ for remote file access, with their latest release users can remotely reset their own passwords as well as us being able to delegate out password reset control to staff (ie, only be able to reset specific year groups, tutor groups, etc).
  • Thanks 1
Posted
Had a look at Nervepoint (or Access Manager as it is now called), is there a way for the user to change the password at login time as there is with the ManageEngine product? At 1st glance it seems to be a 'kiosk' style service that allows you to change the password using a dedicated machine but not one that allows you to change it using the PC you are sitting in front of at the point of logging in. I do like the price however!

 

It has a web portal, so the way we have this set-up is a few machines on campus in public areas, that can be used by people who have completely forgotten their passwords. If you're at home etc then you can just use the web portal. I don't think the free version lets you reset password at login time, its possible its one of the paid options - I'll try and have a look in ours

Posted
Delegate the permission to your top level staff security group to reset passwords and lockouts to the root student OU in Active Directory. Then use a small VB .Net app that only searches for users from that OU with a couple of buttons for resetting passwords/lockouts. Share it somewhere accessible by staff and drop an icon on all staff computers using GPP. That is what we do here. The app that I wrote is a little more involved than that (displays student photos and gives access to home folders), but it can be pretty simple.
Posted

Thanks for all of the suggestions. Nervepoint / Access manager looks ideal, there are options for the user to reset their password at the PC at the point of login with authentication including questions and answers, 1 time passwords, text message and so on. I think that it is the one we are most likely to go with, I just need to get the funding approved :(

 

Many of our staff are not IT particularly literate and if has to be said that some of them feel that "IT work" is not within their remit...and may even consider it below their pay grade!

  • 2 weeks later...
Posted

We allow staff and students to change their passwords whenever they want; staff are forced to change every 100 days or so (5 days of reminders at login, then forced change). I am looking at a giving teachers the ability to reset students' passwords using a Wise Soft tool - some won't bother, but others prefer it so they can get the student working quickly (often "I've forgotten my password" is code for "I would like a 5 minute skive while I slowly walk to the IT office")

 

To be honest, we have very little issue with people forgetting passwords, and I don't think I've ever had to do a network password reset for a staff member because they had forgotten theirs (excluding people returning from maternity leave, of course). Our hosted SIMS has a fairly aggressive password policy, so staff sometimes forget those after the holidays, but others have come up with coded ways of writing their passwords down.

 

The problem we have is when passwords expire over the holidays which prevents access to Google Apps (we use SSO).

Posted
...using an encryption/substitution method called "plaintext"...?

 

For some people, I'm sure that is the case (and we're probably deluding ourselves if we think otherwise) but they receive better advice from me (see below). Generally they are using a known base word with the inclusion of frequently-changing numbers and symbols, and they record just the number/symbol. Some teachers go a step further and shift that value by a secret increment, e.g. writing down 7 when the number is actually 6, or % when it is actually $. This allows the user to be reminded without anyone else being able to use their note to log in. Any passwords which staff do write down are typically written in their staff planners, which are closely guarded anyway due to the myriad other sensitive information contained in them.

 

Our staff and student handbooks include the following advice on password security:

You should choose passwords which you can remember and type quickly, but which other people would not be able to guess very easily. The longer and more complicated you can make your password, the better (although long simple passwords are actually more secure than short complicated ones), but... it must be something which you can remember and type quickly. If your password is so difficult to remember you have to write it down, it is a bad password. If you can only type it very slowly, it is also a bad password because other people might be able to see what you type.

 

  • avoid using your first or last name
  • avoid using the first names of your immediate family members because other people might know their names; consider using their middle names instead
  • if you are well-known for being a sports fan, don't use the name of your favourite team; the same obviously applies to music, films, etc.
  • pets' names might be easy to remember, but if possible, use the name of a pet you no longer have rather than any current pets
  • include capital letters, numbers and symbols - this makes it harder for people to work out your password even if they know the base word you're working from, for example, everTon is harder to guess than everton
  • Put the capital letter in the middle of the password, not at the start
  • if there is a number which is significant to you, you could use the special character on that key instead, e.g. use $ instead of 4
  • consider using a passphrase rather than a password. This is where you take the initial letters of a phrase which is well-known to you, e.g. the title of the book you are currently reading, the last film you saw, a line from a song or a poem. For example, you could use tbontbtitq taken from "to be or not to be, that is the question"
  • Do not use a space as the first character in your password; if you do, you might not be able to log in again after changing it.

 

Ideally, you should never write down a password, however with an ever-increasing number of different passwords which we have to use, sometimes remembering them all can be difficult. If you must write them down, follow the advice below:

 

  • do not write them anywhere other people might see them
  • never write the username and password together
  • do not write the full password, but something which can remind you what it is, e.g.
  • write "first cat" rather than "tibbles"
  • write "anniversary" rather than "15"

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...