Jump to content

Recommended Posts

Posted (edited)

Hi Guys

 

FIRST: I've been setting this up and at the point where we have Lo0cal AD syncing to Azure, we have Google using Azure as its Security provider via SAML, this now seems to work and on Chromebooks we get the Microsoft Logins, also in Windows the passwords for Gmail are the same and the Windows passwords, so all good there, there s a few tweak we need to do but so far seems to be working. But first i have a quick question on the mapping of User Attributes, the Microsoft document HERE says use user.mail instead of user.userprinciplename, which was the default, which did you use ?

 

SECOND: Now we want implement Clever badges, weve signed up and got into the portal and enabled the SSO with Azure as per this document HERE

 

Again, the User Attributes / claim rules seem to differ a lot, again what did you use, i started off with clever.any.email mapped to value user.userprinciplename and the other 2 then set as per the instructions but unsure if this is correct, what did you use?

 

THIRD: I assume to use the Clever QR badges, data somehow need to get into the clever app. How did you sync the data into Clever, I only see manual and SIS sync, I cannot see anyway to sync from AZURE, also I've read something about having to play around with security providers HERE, but unsure if this applies, anyone who uses the clever badges enlighten me to how this is done or how you have this all working.

 

It looks like you have to create CSVs, and SFTP? How do you build the CSVs, is it all manual or is there a semi / automated way ?

 

Thanks

 

S

Edited by Scorpio
Posted
The attribute you choose doesn't really matter as long as there is a match. For our orginization user.mail and user.userprinciplename are the users email address so it does not matter what attribute we pick to make the match. For us with google we use user.userprincipalname and for clever we are using user.mail but again it really doesn't matter if both attributes are the same. What we do to get users into clever is a oneroster sync from our sis.
Posted

Weve got the Chromebook to now display the Clever logon box with the option to select Active Directory or Clever badges, either the QR or the Azure email and password work on the Chromebook, BUT when we go to a gmail login it does then pop up with the azure login anymore, it just does the standard google login and the Azure password doesnt work, just the g suite password works.... ????

 

Am I correct in thinking, the Google and Azure password will be different and not synced? Because the google password becomes dormant ? as the user is being or SHOULD be redirected to the Azure logon page or now the Clever page with option of QR or Azure login?

 

Any ideas on this, i was expecting the same Clever pop up with the QR or AD login as this is now what is in the SSO path in the "Setup SSO with third party identity provider" under Security in Google Admin

 

Thanks

 

S

Posted
Im not sure if I totally follow you on this one and we don't use clever badges but do use clever and have SAML from azure with clever and GSuite setup so I'll try my best to help. The password stored in google should be irrevelant becuase with SAML setup it will use the SAML provider to authenticate the user and the password stored in google is pointless. It sounds like you changed the identity provider in GSuite from using azure to using clever so when logging into the chromebook you should not expect the azure login page but the clever badge page or clever login page. If you go to clever.com can you log into the site with the clever badge or what options does that give you when you select your school?
Posted

You are bang on with your following of this, as we are in the UK we are only using the Clever system to log into the Chromebooks and will be doing so on windows too once we get everything working. Yes we did have the Azure as the identity provider and this worked on Chromebooks and on a simple gmail login either on phone or pc, we would be redirected to the Azure page to authenticate, as you say the google password shouldnt matter.

 

However to sign in with Clever badges because Google can only have one identity provider weve had to change the google one to point to clever then clever points back to azure, thats way the qr or email can be used to login, works fine on the Chromebooks, but now when we use a phone to access email or a random pc and go to gmail.com and enter the email address, instead of being redirected to the Azure page we would assume it should redirect to the Clever login but its just the standard google login using the google password which defeats the object of the SSO. Not sure why its not redirecting to the Clever login, im playing the the User Attributes / claim rules but as above its set and works on the Chromebooks so unsure why anything outside of the Chromebooks is using Google to auth.

 

Any ideas ? Thanks

 

S

Posted (edited)

Next.... does anyone know how to wallpapers the Clever login ? Or change the school name thats displayed ie edit the text maybe ?

 

Also how do you guys deals will password changes, or user must change password on next logon, as it doesnt seem to work or be able to handle it.?

Edited by Scorpio
Posted (edited)

Weve just had our Clever account shut down, literally deleted it, causing the school to not be able to login on any device, saying they cannot deal with European schools due to GDPR ?

 

Anyone from the UK using this ?

 

Also anyone using the Wonde QR Badge logins ?

 

Thanks

 

S

Edited by Scorpio
Posted (edited)

That sounds unpleasant. I looked at this a while ago but never got around to implementing. I'm hearing a lot recently about GDPR and data storage outside of UK, but I thought that had been declared a non-issue quite a while ago in relation to Brexit an GDPR. Can they point to what part of the legislation is the issue?

 

As an alternative you might want to look at Wonde Magic Badges - possibly just referred to as Single Sign on nowadays?

Edited by Ditto
Posted

Just awaiting their response, but just deleting the account was really poor of them.

 

Yeah Wonde may have to be the one, no info on it at all though online in comparison to Clever, no tech docs. Also Windows integration isn't done yet too even though the website says so, i spoke to them a few weeks ago... but its all we have atm.

Posted
Looked at Wonde, it doesnt come close just yet in relation to Clever, they have to install it, and you have to use their sync program at additional cost to enable Single sign on to the actual Chromebook and not just the portal, anyone here in europe using Clever, as they may delete you at any point :(
Posted
That's disappointing to say the least. When I looked at Clever Badges, it looked to be free, but you had to do your own setup. Were you paying anything? I think they are missing a big opportunity, as there clearly is demand here.
Posted
No we didnt pay anything the SSO is free so I suppose its nothing lost for them. But we had finally set it up and it was live, spent considerable time getting AD synced with GSuite and Azure etc to be able to implement it. They signed us up first before we went ahead with all the work, which was with a .co.uk email address and also the address of the school so they knew we was in the UK. :(
  • 2 weeks later...
Posted
Hi @Scorpio, did you get Wonde working like you wanted? I'm looking at a setup for SSO and was considering Clever till i read your thread. Another company that I've looked into is Cool by Cloudwise. More pricey than Wonde but offers some extras which were interesting.
Posted
@Scorpio - did Clever ever get back to you. I've pinged them on Twitter and got no reply so have tried a direct communication - I'd just like to understanding there reasoning. I have approached Bark (US Web filtering solution) about UK support and they quickly replied "not yet, but we are working on it".
Posted
Hi, not really got anywhere, we looked at Wonde but it has to use their sync tool at additional cost to be able to actually unlock the computer, otherwise it will only sign on apps, which is a bit weird as most of the trouble is getting logged on in the first place. Clever have been in touch, just awaiting them confirming. I think they are missing a trick, they could market this in the UK and EU for sure. Just need to have a server in a EU data centre.
Posted
Just had a reply back from Clever and they simply state "We do not support districts outside the US". I have asked for an explanation why as previously they were happy for me to use unsupported and as of yet no reply, but it's my last attempt - sometimes you just have to stop :deadhorse:
Posted
Hi, not really got anywhere, we looked at Wonde but it has to use their sync tool at additional cost to be able to actually unlock the computer, otherwise it will only sign on apps, which is a bit weird as most of the trouble is getting logged on in the first place. Clever have been in touch, just awaiting them confirming. I think they are missing a trick, they could market this in the UK and EU for sure. Just need to have a server in a EU data centre.

 

Absolutely agree and no doubt would work in Europe with a bit of software localisation. We have the advantage of having the same language - well mostly :).

 

I do wonder if it is GDPR related, but I thought the Data Privacy Shield arrangement which came after Safe Harbor dealt with that. I think we need the input of the great comedian (see other threads!), @GrumbleDook to set the record straight.

Posted
Also @imran_r i looked at that package but looks like its just a portal, no QR badges ?

That's correct, which is why i'm reluctant to go with them. Their focus is the emoji login method which I don't really want to implement for KS2. I'm probably going to go ahead with Wonde, if I can find a way to reduce their emoji logins to 3 pictures. At the moment its 6 or 7 pictures which is too much for the younger kids.

Posted
You have no control over the install you have to let Wonde do it (At cost) and have to use their sync tool (At cost) on top of the SSO costs (At cost), and it has to sync to Google not Azure. So you may hit issues with passwords problems which i relayed to them if you have AD > Azure and Gsuite Synced.
Posted

Further to my earlier post #18, Clever have come back with the following statement:

"At this point, we're still evaluating our compliance strategy with GDPR so we're pausing on allowing European districts to use our platform. We'll let you know if anything changes. "

 

Whilst it doesn't help the immediate situation, I do appreciate the answer. Now, I'd thought the 'Privacy Shield' (which I thought you could self-certify) that replaced 'Safe Harbor' dealt with this, but was starting to feel there was a problem. It appears perhaps this is behind the change in US companies approach? Going to start a separate thread on this.

  • 2 weeks later...
Posted
We've not had a concrete response and to be honest they have left us in a bad position, we had made substantial changes to the network and all services after they signed us up to accommodate the badges which we had all up and running, we have lost lots of man hours and also teachers have had severe downtime when they pulled the plug without even a warning.
Posted
I'd be tempted to try to let them know. It's not good, but there's something afoot in the US. I recently followed a link on a technical forum that went to a 'standard' US website. The website was blocked and it quoted concerns about GDPR in Europe for and therefore not being willing to show the article - it's all very baffling.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...