Jump to content

Recommended Posts

Posted (edited)

A couple of our schools have been told that junior age pupils now need individual logins, having previously had a generic year-wide login (for safeguarding reasons; so they can tell who is accessing what through Smoothwall).

 

We've been told they can't all have the same password, nor can they use anything that might be guessed by another pupil (so no sort of thing like initials followed by year of birth). Just wondering what other schools do?

 

Allowing children this age to select their own password seems like a minefield (or, at best, potentially leads to an on-site member of staff having to constantly change passwords at the start of ICT lessons?).

 

I had a search on here for fingerprint readers, the consensus on the thread I found was that they often don't work for young children. Anyone using this or another (fairly inexpensive) method for domain logins? Is there a way to perhaps use QR codes (I'm thinking we can maybe print them all out and stick them into a book), or something similar? I know you can use USB sticks (with software), but talking to the staff, they thought they'd just get stolen or lost.

 

Open to ideas (either password based, or using some kind of hardware login system), also happy to hear of experiences from those who've have implemented this kind of thing for this age group before.

 

Systems are all Windows 7 Enterprise.

Edited by Cazale
Posted
We have accounts for each student, but also generic for the lower grades. The lowers still tend to use the generic accounts because it's a lot easier to get a class of 30 screaming eight year olds logged on. I have a friend that works a couple districts over and they maintain a list of student accounts and passwords that is available to staff while disabling the option for pupils to change passwords. Their district has a student population of almost 9,000 kids. This may work for you.
Posted
Our KS1 students have their own logons, but a standard password for everybody. Our KS2 students, have all chosen their own password and they probably do better than our secondary age students in remembering their logon details !
Posted
A couple of our schools have been told that junior age pupils now need individual logins, having previously had a generic year-wide login (for safeguarding reasons; so they can tell who is accessing what through Smoothwall).

 

We've been told they can't all have the same password, nor can they use anything that might be guessed by another pupil (so no sort of thing like initials followed by year of birth). Just wondering what other schools do?

 

Allowing children this age to select their own password seems like a minefield (or, at best, potentially leads to an on-site member of staff having to constantly change passwords at the start of ICT lessons?).

 

I had a search on here for fingerprint readers, the consensus on the thread I found was that they often don't work for young children. Anyone using this or another (fairly inexpensive) method for domain logins? Is there a way to perhaps use QR codes (I'm thinking we can maybe print them all out and stick them into a book), or something similar? I know you can use USB sticks (with software), but talking to the staff, they thought they'd just get stolen or lost.

 

Open to ideas (either password based, or using some kind of hardware login system), also happy to hear of experiences from those who've have implemented this kind of thing for this age group before.

 

Systems are all Windows 7 Enterprise.

 

My first question would be who has told you this and what is their reasoning beyond safeguarding? Almost sounds like someone has been on a course, heard that pupils should have secure logins for safeguarding and rushed back to implement this best practice advice, not thinking through the specific implementations and challenges.

 

We have generic logins for nursery and reception, default passwords for Y1-Y3 and then they are allowed to set their own passwords beyond that. I am aware that is not secure but all those year groups use IT under supervision and if someone were to get on and delete everything there isn't any major issue, it's not coursework.

Posted (edited)
We've never really had much of a password policy for my infant and junior schools as we really haven't had any issues. Having said that perhaps in today's world getting the children to understand the importance of a password is really a great skill to have. The earlier we can help them with that the better. It's bad enough listening to the staff all sharing their passwords for this that and the other. Thinking I'm contributing to this situation in the future doesn't make me feel good! Edited by atcoates
Posted

We start lessons in the Computing room at year one where the whole class use a generic account which is class name for the username and a simple numeric password, this gives the idea of usernames, passwords Ctrl, Alt, Del and the log on process. It usually takes a couple of 30 minute lessons to get most of the pupils logged on by themselves.

 

In year two each child gets a unique username and password in the form of cohort surname initial ie 20bloggsf and a password from dinopass. We give them each a logon card with this written on in the first week and it usually takes a couple of 30 minute lessons to get most of the pupils logged on by themselves.

 

We sometimes get pupils who insist they are entering their credentials correctly but cant log on and yesterday I had a group who all seemed to have forgotten how to do a three fingered salute, but on the whole this is a fairly painless process. We have some pupils who require extra help with the process but this is the same ratio as the pupils who require extra help elsewhere.

 

Pupils with super long, complex, difficult to spell or double barrelled names get shortened all doubled barrelled names get hyphenated or have the spaces stripped out in school to avoid spaces in usernames as part of the username policy, email addresses use the same username ie 20bloggsf@ unless I have simplified the surname when they will have both the simplified email address and to the full surname ie 20bloggs-jones-smithf@ aliased to the same account.

 

When the pupils move up to year three and year six I reset their passwords on mass but otherwise we try not to change password unless they have been compromised.

 

Generally this works well some parents dont like the shortened names some pupils cant type their passwords consistently but some of our adult staff dont like their surnames being hyphenated or losing the spaces and I reset a staff password about once a month so the year ones and twos are no more of a technician load than any other age group.

Posted

Jumping on the bandwagon - but I think it's relevant and could conceivably be helpful to the OP...

 

We are an Infant and Nursery and have individual accounts for everyone from nursery intake at 3 years old to Year 2. Obviously the youngest can't manage it (some of them don't recognise letter or shapes!). Years 1 and 2 manage to differing degrees with simple user names and a four digit PIN. It made sense to have individual AD accounts across the board as they have individual accounts for Purple Mash and other online systems.

 

My query is whether I can set up a generic AD account that opens in kiosk mode. Our web based SSO platform (Groupcall IDaaS) offers QR code logins. Obviously that's no use for logging on to the computer as you have to have the IDaaS webpage open, but it would allow reception children to log themselves on to their web accounts like Purple Mash.

  • Thanks 2
Posted
My first question would be who has told you this and what is their reasoning beyond safeguarding?

 

The heads of two separate schools (so yes, heard the same thing on a safeguarding course). A lot of schools in our area, including these schools, have moved over to Smoothwall. From what I can gather, the rationale is that with individual logins we can match individuals with the safeguarding reports.

 

TBH, the system we have now (being able to match a year group, time and IP with an incident) is far better than anything we had previously.

 

I kind of understand the reasoning for them recommending this. I'm just wanting to implement it in the least painful way possible (for all involved, including the pupils and myself!).

Posted
The heads of two separate schools (so yes, heard the same thing on a safeguarding course). A lot of schools in our area, including these schools, have moved over to Smoothwall. From what I can gather, the rationale is that with individual logins we can match individuals with the safeguarding reports.

 

TBH, the system we have now (being able to match a year group, time and IP with an incident) is far better than anything we had previously.

 

I kind of understand the reasoning for them recommending this. I'm just wanting to implement it in the least painful way possible (for all involved, including the pupils and myself!).

 

There is no least painful way. Either pupils can remember usernames and passwords or they can't. If they can't either the teachers are logging them in, or they're shared.

 

Ask at what point young pupils are going on websites without the teacher watching.

 

Also why not just use a whitelist for young pupils?

 

In reality pupils are sharing their passwords out loud all the time, so it's not at all secure.

 

For some reason Windows Hello doesn't work on shared computers, it's a per computer thing, so that's useless.

 

Other option is to pay someone to write the login plugin code to use qr badges. Probably cost a few £k, maybe 10.

Posted
Jumping on the bandwagon - but I think it's relevant and could conceivably be helpful to the OP...

 

We are an Infant and Nursery and have individual accounts for everyone from nursery intake at 3 years old to Year 2. Obviously the youngest can't manage it (some of them don't recognise letter or shapes!). Years 1 and 2 manage to differing degrees with simple user names and a four digit PIN. It made sense to have individual AD accounts across the board as they have individual accounts for Purple Mash and other online systems.

 

My query is whether I can set up a generic AD account that opens in kiosk mode. Our web based SSO platform (Groupcall IDaaS) offers QR code logins. Obviously that's no use for logging on to the computer as you have to have the IDaaS webpage open, but it would allow reception children to log themselves on to their web accounts like Purple Mash.

 

Do you mean somone logins and it starts a program or the PC is ready to go, logged in automatically?

 

I'm sure both are feasible through GPO.

Posted
Do you mean somone logins and it starts a program or the PC is ready to go, logged in automatically?

 

I'm sure both are feasible through GPO.

 

Ideally I'd like the PC to be logged in ready to go with Chrome running set to our IDaaS login page. The pupils would then be able to hold up their QR code to the camera and it would log them in.

 

As the devices are laptops and used in different classes/age groups, we'd need the ability to logon as a standard domain user and have standard functionality. I've been reading about Assigned Access and that sounds like it might do it - pressing Ctrl Alt Del allows you to sign in as a different user - but it requires a local account on every machine and I'd need to use Shell Launcher, which I've never done before. Achieving something similar with Group Policy would be much more straightforward.

 

Just realised that this is in the Windows 7 forum (not obvious when viewing thread in App) and I'm using Windows 8.1 or 10. Probably need my own thread....

Posted

We do it by pushing out reg keys via GPO. I'd lock the account down as much as possible as the password is left on the machine and, of course, it is open access.

 

Works on Win10

Posted
Year 3-6 have their own logins here (Year 3 + 4 having a generic password) Nursery to Y2 have a yeargroup login.

 

Do you let them (5/6) chose their own passwords? If so, do you also have complexity requirements? Also, just wondering, do you get many passwords reset requersts?

Posted
They do have their own passwords, complexity is off, so some kids choose a 3 or 4 letter password, some (girls mainly??) chose to type a sentence to log in. Either way I probably get a few reset requests at the beginning of each term, but apart from that they are pretty good at remembering. I think it's down to the fact most of the kids have an online presence these days and get used to having to use/remember passwords.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...