Jump to content

Recommended Posts

Posted

Hello,

 

I have been searching through old threads about username conventions and see that lots of people use Entry Year + Surname + First Initial (or a version of this format) which sounds great.

 

Our pupils currently have class logins (yes, I know!). We are a Primary school, just getting started with GSuite and I wanted to take advantage of the opportunity to now move across to individual logins for AD (as they will need to have them for GSuite). I will be creating accounts for Reception year upwards and want to make the usernames as child-friendly for the younger ones as possible (I realise that they will carry these usernames all way through until they leave).

 

Do you stick to the same naming convention for AD and GSuite for login names? What works best for younger children? Can I use Entry Year + First name + Surname Intial? Or should I stay away from names altogether?

 

Do you have any computers based in shared areas that are always logged in for pupils to use? I am thinking of computers in library/bay areas which are logged on each morning and used thoughout the day. Do you have shared/classroom logins for these machines?

 

Thanks

Posted

Depends on the school size and how you're automate the MIS to AD sync.

 

With a small school, little chance of overlap, FirstnameS, eg johns is fine, when that'll end up with johns1 and johns2, better to do something like entry year.

 

For primary I'd use whole first name too, kids are changing surnames at a rapid pace these days.

 

Make them log in to all machines, so they keep remembering their username/password

  • Thanks 1
Posted
Initials then a number so RLP12 could be one of my daughters usernames. Never understand the year of entry in a username, no need for it if you have your identity strategies in place.
Posted
Initials then a number so RLP12 could be one of my daughters usernames. Never understand the year of entry in a username, no need for it if you have your identity strategies in place.

 

I'd strongly disagree to that, it may work well for us as IT people because we can check groups/AD etc

 

But how does any old staff/student know that RLP12 is "Rebecca L Plum In Y7" or "Ralph L Paster in Y11" or in that example one of the other 10 RLPs? etc etc. Just complicates things especially with some more common initials/initial surname where you could have lots of people with it. Or to counter what is the downside of having a Year Group at the start?

 

Steve

Posted (edited)
I am talking about the bit that has to be unique here samAccountName not the givenName or sn. The staff generally know who they have in their class and and we leverage groups to help with identifying class groups and the likes. The GAL displays the users names in the address book and we leverage some of the other attributes that are pulled into the GAL to help users find/ identify the people they are looking for. ~40k users in the directory staff and students are able to identify the user they are looking for with no issue. Edited by HPlum78
Posted (edited)

For op:

 

"Do you stick to the same naming convention for AD and GSuite for login names? "

 

You definitely need SSO set up - absolutely no benefit in having two sets of user accounts with twice as many passwords to forget/reset.

 

Therefore they must be the same.

 

Edit: set this up *before* you create user accounts for real people, as I had all kinds of trouble when I tried to link existing accounts.

Edited by jmak
  • Thanks 1
Posted

It's not too bad syncing, just matches on email address really.

 

I go sims2ad.vbs, and then gcds and gcps to google, and azure ad with seamless sso and password hash syncing to MS. Google requires all passwords to be reset on AD though once the users are synced

Posted

I found it matched them fine and they could login, but GSuite reported server error, didn't allow access to any of the GSuite apps or the pre-existing user data.

 

I spent hours on the phone to Google and Microsoft, neither could explain why and both blamed the other. New accounts created in AD automatically created Azure AD accounts and then GSuite accounts with all the correct permissions.

 

It should work and YMMV, but I'd avoid it.

 

(I was using Azure AD Connect).

Posted

I get them to use firstnamelastname no spaces if it's a double barrel name it would be firstnlastname they get on with it and the staff accept it, used to use cohorts but the younger staff prefer to have their names in full helps with spelling their name right as well and i haven't been asked to change one in the many years i have been using this method.

Granted some names are ridiculously long but hey i didn't name them did I. :smile:

Posted
For op:

 

"Do you stick to the same naming convention for AD and GSuite for login names? "

 

You definitely need SSO set up - absolutely no benefit in having two sets of user accounts with twice as many passwords to forget/reset.

 

Therefore they must be the same.

 

Edit: set this up *before* you create user accounts for real people, as I had all kinds of trouble when I tried to link existing accounts.

 

 

Hi, so would I need to set my AD users up first and then pull them into GSuite? How would that work if using say Wonde or something to pull users in GSuite from the MIS system?

Posted
Hi, so would I need to set my AD users up first and then pull them into GSuite? How would that work if using say Wonde or something to pull users in GSuite from the MIS system?
Hi,

I've never used Wonde. From what I've seen it looks very good, but doesn't have the facility to create AD accounts.

 

You definitely only want one source of accounts for GSuite. As you're creating AD accounts for all the pupils, I'd personally use Azure AD Connect to create the GSuite accounts and provide SSO. (Workflow is create user in on premises AD > auto creates Azure AD > auto provision GSuite account)

 

However, you need to consider how to get the benefits from Wonde, which might outweigh the benefits from auto provisioning via AD. My understanding is that there are a lot of benefits from using Wonde in the classroom. I'd probably start by talking to them and asking how they recommend integrating Wonde with AD - it can't be an unusually request.

  • Thanks 1
Posted
Hi,

I've never used Wonde. From what I've seen it looks very good, but doesn't have the facility to create AD accounts.

 

You definitely only want one source of accounts for GSuite. As you're creating AD accounts for all the pupils, I'd personally use Azure AD Connect to create the GSuite accounts and provide SSO. (Workflow is create user in on premises AD > auto creates Azure AD > auto provision GSuite account)

 

However, you need to consider how to get the benefits from Wonde, which might outweigh the benefits from auto provisioning via AD. My understanding is that there are a lot of benefits from using Wonde in the classroom. I'd probably start by talking to them and asking how they recommend integrating Wonde with AD - it can't be an unusually request.

OK thanks for the info .. I haven't had any experience with anything Azure so far and tbh I wouldn't even know where to start! I think I need to do some serious binge-learning!

Posted

Remember, convenience is not quite as important as the security and safety of your children. The 2 issues need to be looked at and balanced.

 

Here, we follow firstname + surname initial + 3 digits - and that is the same for AD and for G Suite.

 

Staff we follow initial + surname + 3 digits.

 

There is no need that I can see to be able to identify a child's age from their username.

Posted
Not having the whole year 10 and 13 not being able to remember their user name, my 3 year old is able to remember her own initials and a number! As for having to look it up if that really is an issue well teachers take a register electronically and the samAccountName is reflected back in to the MIS system for every user, they are also in the GAL.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...