Jump to content

Recommended Posts

Posted

The powers that be are currently having a bit of a panic over an issue that has been raised

 

We recently started migrating over to Office 365 (for email primarily at the moment), but it isn't strictly ours it is owned by NHS.NET

 

Several computers currently use generic Windows / AD logins, e.g. a ward just logs in as WARDABC rather than an individual user as otherwise they start moaning it would take to long to switch user etc. whilst playing a game of real life 'Operation' :)

 

The problem is then the individual member of staff wants to check their email, so they open a web browser, visit NHS.NET, sign in, check their email then close the browser window (annoyingly I believe 'remember me' is ticked by default which is hopefully going to change in the near future, I believe we could change this if we owned the 365 instance but...we don't!)

 

Then another member of staff comes along, and is signed straight into the first member of staff email! A massive data protection headache of course... (it also seems to affect services such as Microsoft Teams even if you 'sign out' you can sign straight back in as the initial user without knowing their credentials for some reason!)

 

Has anyone come across this issue and if so what are some of the methods used to resolve it? As a temporary solution we have fired out a Internet Explorer Inprivate shortcut that loads up the site and advised anyone using a generic login to go through that, but it only takes one person not to use that advice and we are back at square one!

 

Perhaps enforcing Inprivate browsing for EVERYTHING under a shared login but we would need extensive testing for this idea to check it doesn't affect the 958,444 other web based systems they use on a frequent basis...

Posted

Doesn't the same problem occur for all the other sites? Or if people had their own login and didn't log off properly?

 

What does the rest of the hospital do?

  • Thanks 1
Posted
Are you stuck with Internet Explorer as your web browser on these machines? Would chrome/edgium with the various clear cache on browser close/ephemeral mode policies work for this perhaps? Certainly seems like a problem that could be solved by group policy.......or better yet a change of working practices so that everyone has their own accounts, but i know healthcare is particular crap sometimes when it comes to the way they work with IT.
  • Thanks 1
Posted

Datix!!!!!!!!!!!!

 

A number of options, create a desktop shortcut to NHS Mail and set it to use Chrome incognito mode, other option block the use of NHSMail on these PC's and can only be used if they login as them, some kind of proxy GPO restriction. Another which won't happen is ensure staff sign out, failure to do so breaks trust IT policy?

 

I know the generic login's are big use on the ward, I will speak to a colleague and see how they address it there. I think your best option is to disable access on shared logins, can you filter the generic accounts to block the use of NHS Mail?

  • Thanks 1
Posted

Are you using pass thru authentication?

 

are you 100% sure it’s remember me situation

 

Have a look at these

 

Disable IE caching of passwords

https://docs.microsoft.com/en-us/troubleshoot/browsers/disable-password-caching

 

 

https://support.dashlane.com/hc/en-us/articles/360012461279-Disabling-Chrome-Edge-Firefox-IE-password-managers-via-GPO

 

Also I believe you can disable the advance settings in IE to disable the use of automatic login via network credentials or something or another via gpo

  • Thanks 1
Posted (edited)

Scheduled task triggered by an event like lock that close ie and clears cache?

 

You could use something like idle mon to do the disconnect or set up a key combination when they are finished they press it and it runs the task then disconnects.

 

I take it you work in a hospital? I work in a acute Trust and have been having similar issues, users who aren’t on the ward are logged in just because the computers are slow.

 

We have just launched VDI and it makes a massive difference. Fast log on, follow you desktop, also accessible from home. When the user finishes for the day the desktop is destroyed and a new one is created so they are always fast.

 

Other option is have you looked into imprivata? Single sign on but offers a kiosk mode for fast login / log off. Really good piece of software.

Edited by MartinRouterKing
  • Thanks 1
Posted

Look at Shared PC mode for Windows 10. It is supposed to speed up logins on shared PCs.

Generic Logins are just a world of pain now with per user licensing and if you deploy MFA you have to protect generic accounts as well some how.

  • Thanks 1
Posted

Thanks for the suggestions, for now we have just gone with a site wide desktop shortcut that opens an Internet Explorer InPrivate instance and goes straight to the NHSMail site with some communications to point this out to users, not ideal but it'll have to do for now...

 

-The saved network credentials GPO setting seemed to have no effect

-Removing caching / clear history of all passwords is a longer term fix, as we need to check it doesn't bugger up several other sites / systems first

-I would love to remove generic accounts full stop but again sadly not a quick job to do so!

-We got a nice shiny new VDI / Imprivata infrastructure in at the end of last year, but at the moment that project is on hold due to Covid

-Give me back Exchange 2010 and Outlook!

Posted

Wouldn't everyone be logged into the same Outlook account then? Or did you have profiles?

 

Didn't think IE was supported for Office 365, not got Edge/Chrome? Plus then you have user profiles

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...