lickydog Posted August 11, 2020 Posted August 11, 2020 As per title... (kicks hornets nest) I've been asked to allow teachers to set a shared password for all class users, that they will then use to log on to a specific cloud service for digital resource access - in scenarios where SSO integration is not used. Note that this is not (I hope) in relation to their school AD accounts, but notwithstanding this, expecting students to respect each others accounts on an external system where they know each other's email address to log in, and have the common password at their disposal rubs up so many hackles I can't count (traceability, privacy principles under law, account abuse, account lockout, falsification of assessments taken etc.). The key arguments being laid out are: 1. Too much class time is lost with students not knowing their password (hence password in common), students failing to check their email for a reset message (hence no reset or TFA required), or not having set up their account in the first place (hence bulk provisioning - which I should note I have no issue with in and of itself). 2. "All the competitive publishers" offer this (?!) I *cannot* find any examples where this is a supported service by any educational publisher, has anyone actually come across this before - and can you name *any* providers that offer this as a service to schools?
Steve21 Posted August 11, 2020 Posted August 11, 2020 Not really sure what you mean. You want them to reset passwords for an online service? (If so which one?) Or for their whole account via AD? You say about where SSO isn't used for a website, but if it's not there it's not going to sync their AD password so resetting that wouldn't help. If it's for a certain website, every one is going to have different options to reset it etc Steve
lickydog Posted August 11, 2020 Author Posted August 11, 2020 Cheers Steve - apologies - I should have been clear - this is for external accounts registered on specific educational websites, where the accounts are now under SAP-CDC (as was Gigya) - a CIAM solution that is being integrated across the publisher's portfolio of sites and services (one account to rule them all as it were). I don't mean to be cagey about which site/publisher, but I'm conscious of the potentially career threatening fallout that may come my way if I do (or more worryingly - can't) stamp this issue out. The accounts are typically on-site registered accounts that only exist for those sites (SSO is not really in play for the majority - and would be far preferred imho) . Like registering on Amazon for shopping, carry through the same identity to Amazon Prime, Kindle etc. insert educational publisher {here} - register on any site, use same details for purchasing, browsing products, teaching and learning sites. As standard, we would request an email address to register, and on receipt of a confirmation (click the link/add the text) would create the account. Alternately, a bulk load of users can be processed, to get through back-to-school, ensuring that accounts are created, and passwords pre-set for distribution by the teacher (that's pretty standard). Thereafter, I would expect students to have to set their password on first login, relieving the teacher of that information going forward, and maintaining privacy. Someone in our authority chain is insisting that the passwords do not need to be unique to the user, and that they should not require reset on first login. Putting these requirements together lays the accounts open to teenagers wreaking havoc with no consequence for them, but plenty for us - picking up the pieces etc.
CHiLL Posted August 11, 2020 Posted August 11, 2020 I'd be opposed to the idea if I was asked to do this. Even if it's not an AD/AAD account, there has to be some kind of accountability. Some of these educational websites have messaging or posting systems (like a VLE), where a student could log on as someone else and send/post a hateful message. If that message has safeguarding implications, it could be difficult to prove who posted it, given anyone can log on as anyone else. I can't think of any more examples of misuse at the moment that would help prevent this. If you are required to do this, then the safest way to do this that I can think of, would be to reset the passwords on a class-by-class basis, whilst they're in the room. Also ensure that there is a force change password option on the website(s). If you cannot force the change of password after a reset, chances are a lot of students won't change it from the default one you set. That way you're not resetting everyone's at the same time. 1
dhicks Posted August 11, 2020 Posted August 11, 2020 that they will then use to log on to a specific cloud service for digital resource access - in scenarios where SSO integration is not used. How is the site's login process implemented - can you submit a username / password from your own login page? If so, you could set everyone's password to the same but (to them) secret password and have users login through your own login page where you could provide integration with GSuite / O365 / etc.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now