Jump to content

Do you allow SSO for MIS and other cloud services?  

29 members have voted

  1. 1. Do you allow SSO for MIS and other cloud services?

    • Yes
      16
    • No
      13


Recommended Posts

Posted

So several MIs systems use a SSO option, SIMS, Bromcom Etc.

 

Do you use this feature? Or is the argument although it's more complicated for users is it better to use seperate passwords for cloud services and MIS?

 

Whilst I agree with the above, the likleyhood a user uses the same password anyway is quite high, so if they forget one, they're likely to forget the other....

Guest Guest
Posted
We were going to enable Windows authentication in SIMS, however, our DPO wasn't happy with it as credentials weren't required to access SIMS
Posted

The correct number of passwords is 0, the further you get from that the worse it is.

 

0 passwords, smart authentication is best (certificate authorised from application)

 

Internet accessible accounts have an attack surface of 510 million km^2, so need better security than unlocking your local computer, which is why Microsoft added the Pin, and biometric scanners were added to computers.

Posted
We don't use SSO for our MIS (Bromcom), while staff may like the idea as a department we weren't keen on it. Having the extra password just allows for a little bit more security (we have our browser set to not remember passwords) should someone walk away from their computer and leave it logged in (everyone knows they shouldn't but some staff still do).
Posted
Any password you can remember is a bad password. If they're leaving their computer unlocked set the lock screen timeout to 1 min
Posted
Yes - I'm not hugely happy with that, but M365 is also accessed with SSO so it's all under that account. I'd like to see MFA reach the Windows domain login screen, without being Azure only, somehow!
Posted
Any password you can remember is a bad password. If they're leaving their computer unlocked set the lock screen timeout to 1 min

 

A watch pot never boils. Even a stopped clock is right twice a day.

Trite soundbites may sound good but aren't actually much use.

 

It is a balance between security and usability.

  • Thanks 1
Posted
We don't use SSO for our MIS (Bromcom), while staff may like the idea as a department we weren't keen on it. Having the extra password just allows for a little bit more security (we have our browser set to not remember passwords) should someone walk away from their computer and leave it logged in (everyone knows they shouldn't but some staff still do).

 

Do you not worry that by doing this you encourage staff to use weak and reused passwords?

 

We've encouraged staff to use the password suggestions and have Chrome remember them for them - their Google account is protected by MFA.

 

Obviously everything is a balance.

 

If someone walks away from a PC without locking it then that itself is an issue that needs addressing, but making it harder to use strong and unique passwords doesn't mitigate this - if they walk away without locking it they're likely logged into key sites already in any case.

Posted
We use the trusted auth for SIMS, but I'd much prefer it to still prompt the user when launching it, just to give a little bit of friction. We also use EduLink, with auth against AD for staff. I haven't tried the M365 or Google SSO options yet. EduLink has configurable inactivity timeouts for different categories of user.
Posted
Seperate logins for SIMS, but edulink uses the windows one anyway so not sure if it's worthwhile

 

EduLink does at least prompt for credentials, though, unlike SIMS when set to trusted auth.

Posted
An extra password (9/10 the same) for the MIS offers no extra protection if you can send a password reset to the email address anyway.

That's why I wouldn't want self service password resets either.

 

We have different SIMS logins for the all the security reasons talked about above. They might use the same password (even though they've been told not to), but we have different username formats as well.

Posted
A watch pot never boils. Even a stopped clock is right twice a day.

Trite soundbites may sound good but aren't actually much use.

 

It is a balance between security and usability.

 

A clock that goes backwards is right 4 times a day.

 

The usability is high because you don't have to remember passwords, and the security is high because you don't have to have passwords that are rememberable

  • Thanks 1
Posted

iSAMS and no we don't have SSO. Reason for this is I feel it does reduce the risk a little, a computer left unlocked should then need another password to access the MIS. I know there are times when it might still be signed in.

 

2FA needed when accessing MIS off site.

Posted
iSAMS and no we don't have SSO. Reason for this is I feel it does reduce the risk a little, a computer left unlocked should then need another password to access the MIS. I know there are times when it might still be signed in.

 

2FA needed when accessing MIS off site.

Automatic screen lock when unattended?

Posted

The question asked for MIS and cloud services, are you hosting/ having your MIS hosted in the cloud? If so then SSO (and I use the term knowing we swap SSO and FID) then you should be using "SSO" as I don't think/ hope that for cloud hosted services anyone is creating an application identity for their users? And if you are I hope that you are not arguing that it "seems" more secure than using actual "SSO"!

Loads to unpick here, but Taskmaster is on... :-)

  • Thanks 1
Posted
We were going to enable Windows authentication in SIMS, however, our DPO wasn't happy with it as credentials weren't required to access SIMS

 

We tried this once, worked fine..... but it plained text the username & passwords in task manager!

Posted
SIMS is as secure as the bat files I found lying around to update it with the SA password in plain text, from when the council supported it.
Posted
SIMS is as secure as the bat files I found lying around to update it with the SA password in plain text, from when the council supported it.

 

niiiiiiiice

Posted (edited)

I also note we have dragged in SSPR here an all, next year will be the 10 year anniversary of our SSPR implementation and in all that time we have seen exactly 0 account compromises from its use, the biggest issue was getting the balance of questions/ challenges right (How to challenge a password reset still is but more on that later) as people generally forgot the answers to the challenges! But overall it has stopped 90% of users who registered for SSPR contacting IT Services for a pwd reset. Setting the password reset email to the account that you need to reset the password for is a chicken and egg scenario and is really not a thing in the world of SSPR!

 

Need to understand what the risks are and what you are trying to mitigate against, if you think that the biggest risk is a user leaving themselves logged in and little Johnny gaining access that's one risk and actually in the scheme of things is not a massive risk at that (and you will have policies in place to deal with this). If the risk is about external actors compromising an identity, then managing multiple identities in multiple places is a much bigger risk and using FID to control access to your applications is a much better option as MS/ Google know far more about nefarious activity than your IT departments will ever do. Also the ability to leverage conditional access/ MFA and all the other goodness that comes from one identity is massive (for those using cloud identities that is). Even for your internal MIS implementations (and not limited to) you should consider using app proxy to leverage Azure AD for signing in (I guess Google has something similar) as again you gain all the goodness of FID access.

 

Right it's Six nations coming up and I have things to fix and kids to feed! But happy to talk more about this as I love identity management....

Edited by HPlum78

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...