Jump to content

Do you allow password writeback to AD/Internal services  

11 members have voted

  1. 1. Do you allow password writeback to AD/Internal services

    • Yes
      4
    • No
      7


Recommended Posts

Posted

An age old question, which might be good to get some anonymous data for:

 

Do you allow password writeback so staff/students can change their passwords off-site? Or do you lock password changes to on-site only?

 

I'm tempted by the former, however the idea of self serve passwords when users forget their own heads most days frightens me - I wonder if we can set it so only Administrators can writeback (?)

Posted (edited)

We do allow SSPR for both our staff and students via MIM and also have a subset that are able to do this via azure and we are looking to roll this out to all and decommission the MIM SSPR setup we have.

 

And the answer is yes you can limit who can use SSPR via a group, but we do not allow any privileged accounts (admin) to do this as that could end badly!

Edited by HPlum78
  • Thanks 1
Posted
Yes we started allowing SSPR via group membership during the lockdowns. It was enabled on a case by case basis using a verified phone number from the MIS.
Posted
I'm tempted by the former, however the idea of self serve passwords when users forget their own heads most days frightens me - I wonder if we can set it so only Administrators can writeback (?)

 

Allowing SSPR for admin passwords is the last thing you want - potential for compromise etc.

 

For 'normal' accounts, you can require MFA to allow a password reset and that should be fine imo.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...