EduDataPro Posted November 1, 2023 Posted November 1, 2023 I'm working on a DPIA for some schools looking to migrate to SIMS Connected but have yet to see it first hand. With it being cloud hosted I'm concerned about the additional risk of accounts being accessed due to weak or found out passwords. Is there an option for 2FA/MFA? I know it is available with SIMS ID but I'm not clear if SIMS ID is used to access SIMS Connected or if it is an separate product/optional extra. As well as security and the connection and speed issues I've read about here, any other additional risks/issues specific to 'Connected' that first hand users have come across we should include in the DPIA?
gaz350b Posted November 1, 2023 Posted November 1, 2023 You use SIMS ID to authenticate which has 2fa. You also have options like sign in with Microsoft which should reduce the burden on staff. Only annoying part is they have to link the Microsoft account t 1st…. 1
jthompson Posted November 2, 2023 Posted November 2, 2023 You can allow users to opt in to SSO against Microsoft or Google accounts, which makes things simple, but their manual SIMS ID login remains available, so they'll still need to have 2fa enabled for them in SIMS ID, I would say. That would mean that when signing in using SIMS ID creds, they would be prompted for 2FA, but if they choose the MS/Google sign-in option, they just go straight in. In SIMS ID, you can set 2fa as mandatory for everyone or just for select groups and/or users, so it's nice and granular on that front. The 2FA options are T-OTP or memorable passphrase (e.g. charaters 2, 4 and 7 from a passphrase). https://id.sims.co.uk/support/wiki/46 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now