Jump to content

Recommended Posts

Posted (edited)

On the other thread we were talking about SSO - Single Sign On. So you login for x also works for y. Y being your MIS system and x begin email (and Windows\Chromebook). See here: http://www.edugeek.net/forums/mis-systems/205639-moving-arbor-sims-2.html

 

@GrumbleDook quoted the NCSC (you know the UK National Cyber Security Centre):

“However, if an attacker compromises a user's account or password, that attacker could have easy access to far more content than they might have in a traditional system. For this reason, we recommend that SSO be implemented to require MFA.”

 

https://www.ncsc.gov.uk/collection/p...-your-approach

 

And they are correct, however I question why you wouldn't enable MFA for MIS access regardless of SSO. MFA standing for Multi Factor Authentication. Now traditionally (ie SIMS 5 years ago), I'd say Windows Auth and physically onsite ticks the boxes. The 2 factor element would be something you know - you're password and something you have - a physical computer onsite. Nowadays your MIS would be in the "cloud", so you'd need to use something like the Google\Microsoft Authenticator app or something. If you have to pay for MFA, surely that should be factored into the costs of going "cloud" - ie its removed from that savings.

It terms of SSO, like I said, basically people get password fatigue having to remember numting passwords with different password requirements and policies and ultimately people are lazy and reuse passwords which makes their password less secure (you've now got 12 places storing the same information that could be hack rather then 1). I accept password managers resolve this issue but really it's a work around to the fact lot of places don't support SSO - you are after all basically using 1 password to get into other systems. This is all off course forgetting the fact that you now have 2 or more places to manage - I dread to think how many accounts for random things I still have active from previous jobs that got missed and this is with company spending £££ on automation of account management (creation \ disable \ delete) based on HR data.

 

So really, if you're using a hosted MIS system, which most schools should be doing these days, you should be using Google Apps or Office365 for authentication with MFA enabled. Both Google and Microsoft have massive security teams that will be better than anything of the MIS providers could develop, monitor and support. So our Outlook \ Skype \ Teams will "randomly" require you hit approve on the Authenticator app because some security tripwires got set off.

 

You may not have MFA on your SSO ...

 

I'd avoid them, if someone is offering SSO but they can't support MFA these days, they aren't using a standard security toolset, or if they are, it's out-of-date, regardless these aren't the sort of people you want dealing with the keys to the kingdom. SSO - Google Apps \ Office365 (Windows Auth for onprem stuff)

 

Staff not wanting an app on their personal phone is one that comes up.

 

I kinda get that, so we have to have the authenticator app, even cleaners etc. You can have email, but then you have to have InTune or whatever its called and then you've got yourself a corporate device and yer, ain't gonna happen. I used to work at a place and they got those really dumb phones that the battery last for years and cost a few pounds to buy and setup telephone MFA - so they had to answer it and press # and weirdly the staff who got them strangely found a personal smartphone that had the app on pretty quick as it was such a pain (I suspect they wanted a new fancy phone)

Edited by matt40k
  • Thanks 4
  • 5 months later...
Posted

It is correct that Arbor have looked VERY carefully at SSO functionality, you CAN use SSO when Arbor is the identifier (I think I may have the wrong term there)

In laymans terms we often say "do you use your google account to log into online banking" and (most) people are vaguely horrified by the thought as they see banking as requiring more security. Well, in your MIS it isn't just your personal data - it could be 1000's of pieces of identifiable information!

Posted
As a school looking at changing MIS. We would want a MIS that used our existing Office 365 MFA. I just don't think we could launch a new MIS with another MFA provider. If you have a login to Office 365, you also have access to all the information saved outside the MIS. That's just as important as the MIS information so protect both with the same system and make sure that system is a full proof as it can be.
Posted

I'd avoid them, if someone is offering SSO but they can't support MFA these days, they aren't using a standard security toolset, or if they are, it's out-of-date, regardless these aren't the sort of people you want dealing with the keys to the kingdom. SSO - Google Apps \ Office365 (Windows Auth for onprem stuff)

 

Absolutely agree, especially with staff (unfortunately) needing to work off-site more and more. Cloud systems can address that nicely, but the risk of compromising security increases alongside it unless proper data protection precautions are taken. At that point, MFA with SSO becomes more and more essential.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...