sippo Posted July 23, 2020 Posted July 23, 2020 Not sure where to put this, but our secondary school has registered to use CPOMS. They say that you can bulk import staff email addresses and need to input manually. Surely this cannot be correct?
DrBeaker Posted July 23, 2020 Posted July 23, 2020 Not sure where to put this, but our secondary school has registered to use CPOMS. They say that you can bulk import staff email addresses and need to input manually. Surely this cannot be correct?I know we installed a CPOMs connector on the SIMs server some point last year. 1
jthompson Posted July 23, 2020 Posted July 23, 2020 We're in the process of starting up with them, too. It has an MIS link, but I think the user management side of things is manual. If a staff member leaves, for instance, we need to remember to close off their CPOMS account. Happy to be corrected on this (we're not actually using it yet).
ass17 Posted July 23, 2020 Posted July 23, 2020 CPOMS links to SIMS via Groupcall Xporter (Meritec) 1
DrBeaker Posted July 23, 2020 Posted July 23, 2020 We're in the process of starting up with them, too. It has an MIS link, but I think the user management side of things is manual. If a staff member leaves, for instance, we need to remember to close off their CPOMS account. Happy to be corrected on this (we're not actually using it yet).Still amazing how in 2020 how many "leading" programmes still lack basic functionality like AD group membership and AD user integration systems.
DrBeaker Posted July 23, 2020 Posted July 23, 2020 Get ready for the usb fobs being lost I was toying with the idea of having a USB extension cable on the desk for these? What do you think?
ass17 Posted July 23, 2020 Posted July 23, 2020 Our CPOMS users all use username/password combo, thought about the Authenticator app but USB key no chance with our staff.
Michael Posted July 23, 2020 Posted July 23, 2020 We're in the process of starting up with them, too. It has an MIS link, but I think the user management side of things is manual. If a staff member leaves, for instance, we need to remember to close off their CPOMS account. Happy to be corrected on this (we're not actually using it yet). That's correct - I did suggest SSO years ago when I spoke to CPOMS. The other issue with it (same as with MyConcern), is personnel are sent an invitation email to enroll into the system, as well as create a password. The amount of users who forget or can't be bothered... then the invite has to be resent out. It demonstrates that if it was natively SSO based then this wouldn't be an issue and likewise disabling accounts too.
DrCheese Posted July 23, 2020 Posted July 23, 2020 That's correct - I did suggest SSO years ago when I spoke to CPOMS. The other issue with it (same as with MyConcern), is personnel are sent an invitation email to enroll into the system, as well as create a password. The amount of users who forget or can't be bothered... then the invite has to be resent out. It demonstrates that if it was natively SSO based then this wouldn't be an issue and likewise disabling accounts too. Gawd yes, 99% of what I do with CPOMS is sending password resets (never mind they can do that from the login screen!) - Other 1% is setting up users. I did email them once saying they need to sort out SSO and they weren't all that interested. It's dumb because it's a blocker to staff using it that shouldn't exist nowadays. 1
forkies Posted July 24, 2020 Posted July 24, 2020 When we got CPOMS I asked about all this and I was so happy when they said “we recommend IT not having admin access as it is a safeguarding system”. So the DSL is responsible for anything to do with CPOMS now and she does all the staff account management. Obviously I suggested sso but if they aren’t providing it, and this is the system my safeguarding/LT want to go with, then I am more than happy I am not responsible for it. Only thing that annoys me is the USB key which comes out of my budget, would be much easier and cheaper to use the authenticator app.
DrBeaker Posted July 24, 2020 Posted July 24, 2020 When we got CPOMS I asked about all this and I was so happy when they said “we recommend IT not having admin access as it is a safeguarding system”. So the DSL is responsible for anything to do with CPOMS now and she does all the staff account management. Obviously I suggested sso but if they aren’t providing it, and this is the system my safeguarding/LT want to go with, then I am more than happy I am not responsible for it. Only thing that annoys me is the USB key which comes out of my budget, would be much easier and cheaper to use the authenticator app.Ha! Got told same about Inventry BY Inventry! IT shouldn't have access. Guess who gets asked about it as the first port of call though? Why do the keys come out of your budget? Shouldn't that be a general lot of money for things like that? It's not IT specific stuff but communal/general services.
forkies Posted July 24, 2020 Posted July 24, 2020 Ha! Got told same about Inventry BY Inventry! IT shouldn't have access. Guess who gets asked about it as the first port of call though? Why do the keys come out of your budget? Shouldn't that be a general lot of money for things like that? It's not IT specific stuff but communal/general services. Anyone contacts us about CPOMS I just close the ticket/reply to the email with “we do not manage this, contact the safeguarding team”. (Even when it comes from the safeguarding team!) Because it is basically a usb stick, which means it is IT, which means we pay for it. It’s ok, I just don’t replace their computers as often to save the cost and some. 1
DrBeaker Posted July 24, 2020 Posted July 24, 2020 Anyone contacts us about CPOMS I just close the ticket/reply to the email with “we do not manage this, contact the safeguarding team”. (Even when it comes from the safeguarding team!)... That has made me chuckle after a very long week and VERY long school year.
stottio Posted July 24, 2020 Posted July 24, 2020 We use it, the 2FA is handled by the CPOMS app staff have on their devices, we never looked at the USB keys as all staff have smart phones. Users are created by groupcall, the safeguarding lead assigns permissions for all users. We have limited access to reset users 2FA devices and nothing else, makes sense as it takes only a couple of clicks to do and can be logged on our helpdesk. The biggest issue is the changing of passwords which happens every 60 days or so. If the password is incorrect the warning writing is tiny and not obvious so it looks like the password was changed successfully, almost all issues are due to this.
DrBeaker Posted July 25, 2020 Posted July 25, 2020 Surely like any systems that's down to the user's professional responsibilities to change their password/manage their logins etc. Being IT and the nuclear launch code length-type of passwords we have to remember for things, doesn't really fly with me users claiming it's too hard to remember password's or changing them.
DrBeaker Posted July 25, 2020 Posted July 25, 2020 We use it, the 2FA is handled by the CPOMS app staff have on their devices, we never looked at the USB keys as all staff have smart phones. Users are created by groupcall, the safeguarding lead assigns permissions for all users. We have limited access to reset users 2FA devices and nothing else, makes sense as it takes only a couple of clicks to do and can be logged on our helpdesk. The biggest issue is the changing of passwords which happens every 60 days or so. If the password is incorrect the warning writing is tiny and not obvious so it looks like the password was changed successfully, almost all issues are due to this.Surely like any systems that's down to the user's professional responsibilities to change their password/manage their logins etc. Being IT and the nuclear launch code length-type of passwords we have to remember for things, doesn't really fly with me users claiming it's too hard to remember password's or changing them.
Primus Posted July 25, 2020 Posted July 25, 2020 Surely like any systems that's down to the user's professional responsibilities to change their password/manage their logins etc. Being IT and the nuclear launch code length-type of passwords we have to remember for things, doesn't really fly with me users claiming it's too hard to remember password's or changing them. Forcing a change of password every 60 days not only makes it hard for the user to remember it but it leads to them using weaker passwords and potentially writing them down on sticky notes attached to the monitor etc. Forcing password expiry after a certain number of days is no longer best security practice and hasn't been for some time. There is simply no justification for CPOMS forcing this especially given the MFA required usage. 2
Ditto Posted July 25, 2020 Posted July 25, 2020 Forcing a change of password every 60 days not only makes it hard for the user to remember it but it leads to them using weaker passwords and potentially writing them down on sticky notes attached to the monitor etc. Forcing password expiry after a certain number of days is no longer best security practice and hasn't been for some time. There is simply no justification for CPOMS forcing this especially given the MFA required usage. 100% agree and this is well documented National Cyber Security Centre. 1
DrBeaker Posted July 26, 2020 Posted July 26, 2020 Forcing a change of password every 60 days not only makes it hard for the user to remember it but it leads to them using weaker passwords and potentially writing them down on sticky notes attached to the monitor etc. Forcing password expiry after a certain number of days is no longer best security practice and hasn't been for some time. There is simply no justification for CPOMS forcing this especially given the MFA required usage.100% agree and this is well documented National Cyber Security Centre.I agree. But we've all still got legacy-type systems or even brand new ones from suppliers that don't support 2FA of any kind. Why this couldn't be linked into a mixture of Azure AD and synced-on prem, group memberships and then 2FA somehow I can't see why? I'm surprised Windows hasn't really gotten much more support/development with the 2FA. The ubikey stuff has so much promise and potential. Don't Google use this themselves or their own version now?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now