Jump to content

Recommended Posts

Posted
I'm working on a DPIA for some schools looking to migrate to SIMS Connected but have yet to see it first hand. With it being cloud hosted I'm concerned about the additional risk of accounts being accessed due to weak or found out passwords. Is there an option for 2FA/MFA? I know it is available with SIMS ID but I'm not clear if SIMS ID is used to access SIMS Connected or if it is an separate product/optional extra. As well as security and the connection and speed issues I've read about here, any other additional risks/issues specific to 'Connected' that first hand users have come across we should include in the DPIA?
Posted

You use SIMS ID to authenticate which has 2fa. You also have options like sign in with Microsoft which should reduce the burden on staff.

 

Only annoying part is they have to link the Microsoft account t 1st….

  • Thanks 1
Posted

You can allow users to opt in to SSO against Microsoft or Google accounts, which makes things simple, but their manual SIMS ID login remains available, so they'll still need to have 2fa enabled for them in SIMS ID, I would say. That would mean that when signing in using SIMS ID creds, they would be prompted for 2FA, but if they choose the MS/Google sign-in option, they just go straight in.

 

In SIMS ID, you can set 2fa as mandatory for everyone or just for select groups and/or users, so it's nice and granular on that front.

 

The 2FA options are T-OTP or memorable passphrase (e.g. charaters 2, 4 and 7 from a passphrase).

 

https://id.sims.co.uk/support/wiki/46

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...