Jump to content

Recommended Posts

Posted

I've been asked to set up a school email address and give the password to a consultant from an external company. I'm really not comfortable with this and am going to create a M365 group and invite the external user so that emails sent to the school address will also be sent to them. However, this means that if they reply, the email will come from their own company address.

 

From a Data Protection/Security point of view, I think I'm going about it the right way. I just wanted to canvass opinion in case I have SLT coming back to me insisting that I just set up a normal username and password.

 

So, am I right?

 

TIA

Posted

I did the same as you in the same circumstances for the same reasons.

 

However, I was later overruled and made to issue school E-Mail addresses to individuals not employed by the school, and not on the school roll.

 

:(

  • Thanks 1
Posted

Minimum requirements to getting and email account: Signed Contract, Signed AUP, DBS, Completed mandatory training (Safeguarding, Data Protection, H+S).

 

We can and do secure with MFA.

  • Thanks 4
Posted (edited)

Its not uncommon. People who work with NHS / Hospitals / Microsoft often have email addresses owned by these organizations, even though they might actually work for consultancies / universities / 3rd party companies contracted to provide specific services.

 

Here our Head of Catering has a school address despite being employed by our 3rd party provider. The same has been variously true for Facilities, HR, IT, the cleaners over the years.

 

Why? Often for the duration of the engagement the leadership want them to appear as part of the school to internal and/or external stakeholders. Also sometime they may be processing/handling sensitive information, and by requiring all communication to occour on school controlled platforms, it is easier to provide the necessary protections as part of the standard IT offer.

Edited by psydii
Posted
...Here our Head of Catering has a school address despite being employed by our 3rd party provider. The same has been variously true for Facilities, HR, IT, the cleaners over the years.

 

It sounds like these parties have a long term relationship/arrangement with the school in your examples. Our head of catering (when I left) was a former school employee who had been TUPE'd over.

Posted
Astute of you. However, some of these people got their addresses when they started with the 3rd party before they TUPEd to us. Some never worked for us starting with the third party and leaving before we brought the service back in house. We have in the past had our facilities hire people with school email addresses since they worked very closely with our internal teams on resource availability and booking, so the whole system was school branded. In later contracts they were less integrated and operated under their own branding.
Posted
Astute of you. However, some of these people got their addresses when they started with the 3rd party before they TUPEd to us. Some never worked for us starting with the third party and leaving before we brought the service back in house. We have in the past had our facilities hire people with school email addresses since they worked very closely with our internal teams on resource availability and booking, so the whole system was school branded. In later contracts they were less integrated and operated under their own branding.

Bit hostile! As you say, they were working closely with your internal teams. I was overruled on visitors who would be in working with the school, or in contact with it for a matter of months at the very outside.

Posted
So far, these comments have been about the risk of giving someone a school email address, so let's flip that and discuss the risks of them not having one. Will they be handling sensitive or confidential information? If so, one could argue it would be better to secure this behind a school email account, where you can be certain of access controls, etc. If the emails go to their external company address, who else has access now and after they leave the consultancy? Will they be saving files on an unencrypted hard drive or another company's OneDrive? If so, have you done a DPIA on that company having such information.
  • Thanks 2
Posted

Bottom line is that SLT have requested it and you are expected to deliver it. If anything goes wrong then you have it in writing (I assume), that all you did was deliver on what was requested.

Sometimes, regardless of how you feel about it, its better to just not question for your own sanity.

  • Thanks 3
Posted
Bottom line is that SLT have requested it and you are expected to deliver it. If anything goes wrong then you have it in writing (I assume), that all you did was deliver on what was requested.

Sometimes, regardless of how you feel about it, its better to just not question for your own sanity.

 

I disagree. Part of my role is to understand the technology, surrounding laws and implications of decisions, and advise SLT accordingly. What if SLT went "Internet filters are impacting learning, please turn them off" or "I'd like teachers to have choice of software they use, and easy access to all student documents, so please give everyone domain admin rights"? If SLT decide to do it anyway, get it in writing that you objected and move on, but in my role at least, I am expected to advise on policy and strategy.

  • Thanks 3
Posted
I disagree. Part of my role is to understand the technology, surrounding laws and implications of decisions, and advise SLT accordingly. What if SLT went "Internet filters are impacting learning, please turn them off" or "I'd like teachers to have choice of software they use, and easy access to all student documents, so please give everyone domain admin rights"? If SLT decides to do it anyway, get it in writing that you objected and move on, but in my role at least, I am expected to advise on policy and strategy.

 

I think this is very much down to what sort of "head" they are. I have worked with 3 different heads, 2 of them were very much let's discuss and would take in my concerns and would often take my side or compromise. the other head did not listen to any advice and always forced his way of thinking and what he wanted (even to the point of rewriting policies to get his own way).

 

On the actual issue, we have many of what we call "non-contract" accounts (external contractors). They are all locked down so they have no access to the student address book, they are limited to files shares to only what they require by default they get the school policy folder, then are shared anything else by the department or people they are working with. As others have said, to me it seems far more sensible to be able to track and report on what the external has been doing!

Posted

I give these out all the time - we have externals from the LA, the NHS, an external SALT agency, Peri music teachers - they all get a school address.

 

That address only gives them what I choose to give them access to, for most externals thats nothing - they don't even get to see the student address book let alone any details?

 

SALT gets access to an SEN folder in Sharepoint but she's signed AUP and has done all apropriate training as determined by the BM.

 

We give them 2FA OATH tokens which are issued with a £10 deposit returnable on end of contract along with keys/fob lanyard and badge.

Posted
How are you guys restricting address book access? That could be useful for some of our accounts.

 

Custom address lists and address book policies.

 

I've set up address lists here so that each school in the Trust can only see members of their own site. Students are restricted to only seeing other students and staff at their school. Staff can see student distribution lists, staff distribution lists and students at their own school. This stops staff using the "suggested recipients" and accidentally e-mailing a student or member of staff somewhere else. All staff at all sites also have an "All Trust Staff" list so if they want to communicate with staff at other sites, they can.

 

Students are denied permission to e-mail all distribution lists (groups).

 

You can apply the same idea to external users, so set them up with a policy that basically shows them an empty address book so they see nothing.

Posted
By all means question it and give solid reasons why it should not be done - but if the headteacher instructs you to do it anyway, follow their orders!

 

Not if it breaks the laws

Posted

Thanks, all, for your comments. I was in a bit of a hurry, when I posted, and forgot to include some important details.

 

Firstly, the email address would be accessed by multiple people, both inside and outside the organisation, and I had been asked to provide the password to all of them.

Secondly, the address was required to go live almost immediately, so I wouldn't have had time to set up address book policies (although that is something I would like to configure at some point).

Thirdly... I can't remember the third thing!

 

Either way, everyone is happy with the solution I have implemented. I added the external user as a guest in AAD, created an M365 group and included them as a member along with SLT. This way, emails are still sent to a school address and each member of the group receives a copy. I've also set up a mail flow rule that adds a prefix to any message sent to the group address to make them easily identifiable.

  • Thanks 3
Posted
This sounds like you should be using a shared mailbox and then delegating rights for individuals to be able to send and read emails. They shouldn't need to share a password.
Posted
This sounds like you should be using a shared mailbox and then delegating rights for individuals to be able to send and read emails. They shouldn't need to share a password.

External users can't be added to shared mailboxes.

Posted

Ah, it was a case of "I know 5 things about computers, so you must do it my way", sigh.

 

Dear clients: Please state your requirements, I will provide solutions. Do not state solutions

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...