Warwick_Tech Posted March 18, 2021 Posted March 18, 2021 So several MIs systems use a SSO option, SIMS, Bromcom Etc. Do you use this feature? Or is the argument although it's more complicated for users is it better to use seperate passwords for cloud services and MIS? Whilst I agree with the above, the likleyhood a user uses the same password anyway is quite high, so if they forget one, they're likely to forget the other....
Guest Guest Posted March 18, 2021 Posted March 18, 2021 We were going to enable Windows authentication in SIMS, however, our DPO wasn't happy with it as credentials weren't required to access SIMS
mavhc Posted March 18, 2021 Posted March 18, 2021 The correct number of passwords is 0, the further you get from that the worse it is. 0 passwords, smart authentication is best (certificate authorised from application) Internet accessible accounts have an attack surface of 510 million km^2, so need better security than unlocking your local computer, which is why Microsoft added the Pin, and biometric scanners were added to computers.
noelmm Posted March 18, 2021 Posted March 18, 2021 We don't use SSO for our MIS (Bromcom), while staff may like the idea as a department we weren't keen on it. Having the extra password just allows for a little bit more security (we have our browser set to not remember passwords) should someone walk away from their computer and leave it logged in (everyone knows they shouldn't but some staff still do).
TechMonkey Posted March 18, 2021 Posted March 18, 2021 We currently don't due to security concerns, as others have mentioned. But with M365 SSO and MFA I may relook at that. 1
mavhc Posted March 18, 2021 Posted March 18, 2021 Any password you can remember is a bad password. If they're leaving their computer unlocked set the lock screen timeout to 1 min
3s-gtech Posted March 18, 2021 Posted March 18, 2021 Yes - I'm not hugely happy with that, but M365 is also accessed with SSO so it's all under that account. I'd like to see MFA reach the Windows domain login screen, without being Azure only, somehow!
Theblacksheep Posted March 18, 2021 Posted March 18, 2021 Yes. An extra password (9/10 the same) for the MIS offers no extra protection if you can send a password reset to the email address anyway.
TechMonkey Posted March 18, 2021 Posted March 18, 2021 Any password you can remember is a bad password. If they're leaving their computer unlocked set the lock screen timeout to 1 min A watch pot never boils. Even a stopped clock is right twice a day. Trite soundbites may sound good but aren't actually much use. It is a balance between security and usability. 1
Primus Posted March 18, 2021 Posted March 18, 2021 We don't use SSO for our MIS (Bromcom), while staff may like the idea as a department we weren't keen on it. Having the extra password just allows for a little bit more security (we have our browser set to not remember passwords) should someone walk away from their computer and leave it logged in (everyone knows they shouldn't but some staff still do). Do you not worry that by doing this you encourage staff to use weak and reused passwords? We've encouraged staff to use the password suggestions and have Chrome remember them for them - their Google account is protected by MFA. Obviously everything is a balance. If someone walks away from a PC without locking it then that itself is an issue that needs addressing, but making it harder to use strong and unique passwords doesn't mitigate this - if they walk away without locking it they're likely logged into key sites already in any case.
jthompson Posted March 18, 2021 Posted March 18, 2021 We use the trusted auth for SIMS, but I'd much prefer it to still prompt the user when launching it, just to give a little bit of friction. We also use EduLink, with auth against AD for staff. I haven't tried the M365 or Google SSO options yet. EduLink has configurable inactivity timeouts for different categories of user.
caffrey Posted March 18, 2021 Posted March 18, 2021 Seperate logins for SIMS, but edulink uses the windows one anyway so not sure if it's worthwhile
jthompson Posted March 18, 2021 Posted March 18, 2021 Seperate logins for SIMS, but edulink uses the windows one anyway so not sure if it's worthwhile EduLink does at least prompt for credentials, though, unlike SIMS when set to trusted auth.
Rob_D Posted March 18, 2021 Posted March 18, 2021 An extra password (9/10 the same) for the MIS offers no extra protection if you can send a password reset to the email address anyway. That's why I wouldn't want self service password resets either. We have different SIMS logins for the all the security reasons talked about above. They might use the same password (even though they've been told not to), but we have different username formats as well.
mavhc Posted March 18, 2021 Posted March 18, 2021 A watch pot never boils. Even a stopped clock is right twice a day. Trite soundbites may sound good but aren't actually much use. It is a balance between security and usability. A clock that goes backwards is right 4 times a day. The usability is high because you don't have to remember passwords, and the security is high because you don't have to have passwords that are rememberable 1
Chaniel Posted March 18, 2021 Posted March 18, 2021 We don't at the moment (SIMS) but we will once we migrate to Bromcom and have 2FA enabled on emails.
Danp Posted March 18, 2021 Posted March 18, 2021 iSAMS and no we don't have SSO. Reason for this is I feel it does reduce the risk a little, a computer left unlocked should then need another password to access the MIS. I know there are times when it might still be signed in. 2FA needed when accessing MIS off site.
paulkerton Posted March 18, 2021 Posted March 18, 2021 iSAMS and no we don't have SSO. Reason for this is I feel it does reduce the risk a little, a computer left unlocked should then need another password to access the MIS. I know there are times when it might still be signed in. 2FA needed when accessing MIS off site. Automatic screen lock when unattended?
HPlum78 Posted March 18, 2021 Posted March 18, 2021 The question asked for MIS and cloud services, are you hosting/ having your MIS hosted in the cloud? If so then SSO (and I use the term knowing we swap SSO and FID) then you should be using "SSO" as I don't think/ hope that for cloud hosted services anyone is creating an application identity for their users? And if you are I hope that you are not arguing that it "seems" more secure than using actual "SSO"! Loads to unpick here, but Taskmaster is on... :-) 1
supportman Posted March 19, 2021 Posted March 19, 2021 Yes we use single sign on with Office 365 here with bromcom. Works perfectly.
Jaan Posted March 19, 2021 Posted March 19, 2021 We were going to enable Windows authentication in SIMS, however, our DPO wasn't happy with it as credentials weren't required to access SIMS We tried this once, worked fine..... but it plained text the username & passwords in task manager!
mavhc Posted March 19, 2021 Posted March 19, 2021 SIMS is as secure as the bat files I found lying around to update it with the SA password in plain text, from when the council supported it.
Jaan Posted March 19, 2021 Posted March 19, 2021 SIMS is as secure as the bat files I found lying around to update it with the SA password in plain text, from when the council supported it. niiiiiiiice
paulkerton Posted March 19, 2021 Posted March 19, 2021 We tried this once, worked fine..... but it plained text the username & passwords in task manager! Ahhh that silent R in Capita reappears once again.
HPlum78 Posted March 20, 2021 Posted March 20, 2021 (edited) I also note we have dragged in SSPR here an all, next year will be the 10 year anniversary of our SSPR implementation and in all that time we have seen exactly 0 account compromises from its use, the biggest issue was getting the balance of questions/ challenges right (How to challenge a password reset still is but more on that later) as people generally forgot the answers to the challenges! But overall it has stopped 90% of users who registered for SSPR contacting IT Services for a pwd reset. Setting the password reset email to the account that you need to reset the password for is a chicken and egg scenario and is really not a thing in the world of SSPR! Need to understand what the risks are and what you are trying to mitigate against, if you think that the biggest risk is a user leaving themselves logged in and little Johnny gaining access that's one risk and actually in the scheme of things is not a massive risk at that (and you will have policies in place to deal with this). If the risk is about external actors compromising an identity, then managing multiple identities in multiple places is a much bigger risk and using FID to control access to your applications is a much better option as MS/ Google know far more about nefarious activity than your IT departments will ever do. Also the ability to leverage conditional access/ MFA and all the other goodness that comes from one identity is massive (for those using cloud identities that is). Even for your internal MIS implementations (and not limited to) you should consider using app proxy to leverage Azure AD for signing in (I guess Google has something similar) as again you gain all the goodness of FID access. Right it's Six nations coming up and I have things to fix and kids to feed! But happy to talk more about this as I love identity management.... Edited March 20, 2021 by HPlum78
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now