kennysarmy Posted September 17, 2020 Posted September 17, 2020 Hi, We've recently migrated from SIMS to BROMCOM. Is it correct that you can either have 2FA ON or OFF and you can't whitelist the school's IP addresses? Teachers and Admin staff can't be getting out their phones all the time....
mavhc Posted September 17, 2020 Posted September 17, 2020 Does it not offer: remember this computer for 30 days?
Bromcom_Support Posted September 17, 2020 Posted September 17, 2020 Hi @kennysarmy Yes you can whitelist the school's IP address as well as having 2FA set to on or off, however if 2FA is on, the school's IP being whitelisted won't make a difference as you will still be asked for authentication. If you could advise what you were hoping to achieve with the security settings we should be able to help you with the best course of action. Regards Bromcom
kennysarmy Posted September 17, 2020 Author Posted September 17, 2020 Hi @kennysarmy Yes you can whitelist the school's IP address as well as having 2FA set to on or off, however if 2FA is on, the school's IP being whitelisted won't make a difference as you will still be asked for authentication. If you could advise what you were hoping to achieve with the security settings we should be able to help you with the best course of action. Regards Bromcom Maybe I'm confused then. We'd like staff away from school to have to authenticate using a pin sent to their mobile phone as well as their usual username & password, BUT at school we'd just like them to logon with their username and password. We use Office 365 so some staff will have also linked their accounts.
Primus Posted September 17, 2020 Posted September 17, 2020 Maybe I'm confused then. We'd like staff away from school to have to authenticate using a pin sent to their mobile phone as well as their usual username & password, BUT at school we'd just like them to logon with their username and password. We use Office 365 so some staff will have also linked their accounts. If you need MFA for security (which you do) then whitelisting IPs seems nonsensical - a huge vector for attack is students watching staff type in usernames and passwords so excluding your PCs onsite from MFA limits its success. 1
mavhc Posted September 17, 2020 Posted September 17, 2020 "save this computer/browser for 30 days" works best
Bromcom_support2 Posted September 17, 2020 Posted September 17, 2020 Hi Kennsarmy, there is a way to achieve this, although it's a little complicated. You can assign security controls to a role, so you could manage this via assigning different roles to the same users, but some constraints would apply. I will drop you a DM with more detail to see if this will do what you want. You can always contact us in support too via the usual channels Kind regards, Bromcom support
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now