Jump to content

Recommended Posts

Posted (edited)

I'm having an email discussion (read 'low-key argument') with a member of SLT at the moment regarding a new user's account and passwords... or rather how this information should be communicated.

 

I'm not entirely sure what they expect me to do, I don't know if they want me to email the passwords to them or find this user in the school somehow and communicate it to the new user personally, but previously the user would come to me and I'd create the account (not sure why it's different with this user - something about "it isn't correct to expect the user to find the information from someone they don't know, in a room they don't know and it should be 'given/provided' to them").

 

We'd discuss various things not to do, like put it on a label stuck to the laptop, or if they must write it down don't store it with the laptop etc. Being a small friendly school, this still happens a lot and unfortunately nobody takes it very seriously, passwords are often shared and nothing is ever done about it when I raise the issue..

 

Obviously they have no account as yet, so no email to send it to, or any other way of communicating it to the new user apart from me telling someone else (email or written down) or finding the new user myself. I'm going to be a little bit naughty here and pretend I don't know who this new user is or where they are, so I think I should be introduced as the 'IT guy' so they know who I am and where my office is in case they ever have any issues.

 

But the upshot is, I don't think emailing a password or passing it on via a 3rd-party is appropriate...

 

Thoughts?

 

Also how do you do this?

Edited by Koldov
Posted

It's not really appropriate, it's a great opportunity to let it be known who you are, what you can do to help and just put a name to a face for them. It's good practice if not anything else.

If they really insist on being a bit muppety like that, provide a random generated password (a fully secure one, nice and long) - not to be spiteful, but to help ensure it gets changed, obviously with that flag set in AD. It could be useful to provide a crib sheet, and I would also make a point of putting details on it such as how to get help, helpdesk email/URL and a couple of little pointers maybe. But nothing is as good or useful for new staff IMO than meeting someone face to face and just saying "We're here to help."

  • Thanks 2
Posted (edited)

Personally accounts for us are created by Locker (based off their Bromcom details, eg rights and permissions)

 

It generates and email/login/password for us via an email, I will then print this and give to their line manager/whoever is doing their induction before they start. I then book in an IT induction as part of this usually on their first day, where they first login and get shown any systems / services as part of their role. This way if for any reason on the first day we cannot do their IT induction, their line manager will be able to at least get them started.

 

A bit more importantly for me, getting accounts generated before they start gives time for Office 365 services such as Outlook and OneDrive to provision and be ready on first use.

Edited by TheRobins
  • Thanks 1
Posted

Perhaps as part of their day one induction they could be brought to the IT office where they could receive their credentials and meet the "IT Guy". Failing that, put it in a sealed envelope along with an introduction as to who you are, where you're based and helpdesk details etc. Give this to the headteacher to be passed on to teh new person on their first day.

 

Off the back of this it's worth taking the opportunity to get a process in place for future appointments.

  • Thanks 2
Posted
as part of their day one induction they could be brought to the IT office

it's a great opportunity to let it be known who you are, what you can do to help and just put a name to a face for them. It's good practice if not anything else.

+1

 

We do offer remote induction too, using self-service password reset for their first log on, which seems to work well, but in person is always preferable.

  • Thanks 1
Posted

Staff and student user accounts get provisioned here with the person's date of birth as their initial password (dd MMMM yyyy), with a new password required at first sign in. We can then just distribute a new staff username to HR or line management, along with a reminder that the initial password will be the person's date of birth. Not all staff need to come and meet the IT team upon starting.

 

Gmail has a confidential mode which is handy for those odd occasions where a password does need to be emailed to someone. It allows you to make the content of the message available for only a set period of time, and you can revoke it at any point, so it helps contain it more so than a regular email.

Posted (edited)

Thanks so far...

 

Maybe I should have clarified, there is no process, no formal induction that I'm aware of, no tour of the school or meet and greet (well if there is IT isn't on the list if you know what I mean).

 

The Headteacher isn't really involved (and wouldn't want to be),

 

In fact there was a sarcastic comment in one the emails from the SLT (as I bemoaned the fact there was no process, due to getting an email on the day a user started a couple of weeks ago requesting account creation and a laptop) that I was the one who wanted a procedure... and I think they were saying that me giving passwords out 'somehow' without seeing the new user was going to be it!

 

In fact the whole conversation went:

 

SLT: New user needs email account and username/password for school network so they can use desktop until you provide laptop.

ME: Yes, these were both done last week.

SLT: Does the new user know?

ME: No, I don't know who they are...

SLT: Ok. So what would you like the protocol to be in these cases as I think we need to give it to them rather than them have to come and ask/find it.

ME: No, that’s incorrect. The user’s password is given only to the user and only by me and therefore not passed around on pieces of paper or via a third party who should not know it.

SLT: Ok, I understand that but as an induction we should be 'giving' this information to them, not sending them around to various people to get different information. As you said the other day it needs to be organised and done as 'properly' as possible so we just need to work out the best way of doing this for new arrivals.

ME: Yes, we did. This is the ‘proper’ way for passwords.

SLT: The proper way is not to send a new person to a room they don't know of, to a person they have never met. If I have a password for a new person, I take it to them, they don't come and find me.

 

I had a long answer ready to send, but thought I'd ask on here if I am being unreasonable first...

 

Just as an extra piece on 'info' the user started over a week ago, so it's not really anything to do with an 'induction' because there isn't one, they're already in class.

Edited by Koldov
  • Thanks 1
Posted
... there is no process, no formal induction that I'm aware of, no tour of the school or meet and greet (well if there is IT isn't on the list if you know what I mean).

 

& this is the issue. & a very academic response by the SLT, effectively there is no process and that is the process. Deal with it.

 

SLT: The proper way is not to send a new person to a room they don't know of, to a person they have never met. If I have a password for a new person, I take it to them, they don't come and find me. [/i][/b]

 

They are new. Every room they don't know of, every person they have never met. Kind of the definition of being new. It would be good of the school to show them round, introduce them to key staff or departments so they get to know people and the layout of the school. How else are they going to learn? Sounds like they were just dropped in a classroom and told to get on with it.

 

To counter this though, we try and offer inductions where new staff are put in a class and various departments go and present and get them sorted. Just makes sense, but that is normally a full day. I'd have no problem going to a new user as long as it was organised, not just expected to sort it out randomly. Otherwise, your situation happens where a user ends up working for a week without being seen.

  • Thanks 2
Posted

Prior to having DOB-based initial passwords, we would occasionally send out a randomised initial password for new staff account (to HR or line manager) if that person wasn't due into the office to collect an assigned laptop. That would only ever have been on request, though.

 

Not ideal, but resonably well controlled since the password is effectively a one-time use, and misuse of it by somebody else is likely to become apparent pretty quickly when the new staff member can't get signed in as expected.

  • Thanks 1
Posted
Thanks so far...

 

Maybe I should have clarified, there is no process, no formal induction that I'm aware of, no tour of the school or meet and greet (well if there is IT isn't on the list if you know what I mean).

 

The Headteacher isn't really involved (and wouldn't want to be),

 

In fact there was a sarcastic comment in one the emails from the SLT (as I bemoaned the fact there was no process, due to getting an email on the day a user started a couple of weeks ago requesting account creation and a laptop) that I was the one who wanted a procedure... and I think they were saying that me giving passwords out 'somehow' without seeing the new user was going to be it!

 

In fact the whole conversation went:

 

SLT: New user needs email account and username/password for school network so they can use desktop until you provide laptop.

ME: Yes, these were both done last week.

SLT: Does the new user know?

ME: No, I don't know who they are...

SLT: Ok. So what would you like the protocol to be in these cases as I think we need to give it to them rather than them have to come and ask/find it.

ME: No, that’s incorrect. The user’s password is given only to the user and only by me and therefore not passed around on pieces of paper or via a third party who should not know it.

SLT: Ok, I understand that but as an induction we should be 'giving' this information to them, not sending them around to various people to get different information. As you said the other day it needs to be organised and done as 'properly' as possible so we just need to work out the best way of doing this for new arrivals.

ME: Yes, we did. This is the ‘proper’ way for passwords.

SLT: The proper way is not to send a new person to a room they don't know of, to a person they have never met. If I have a password for a new person, I take it to them, they don't come and find me.

 

I had a long answer ready to send, but thought I'd ask on here if I am being unreasonable first...

 

Just as an extra piece on 'info' the user started over a week ago, so it's not really anything to do with an 'induction' because there isn't one, they're already in class.

:doh:... and they're SLT? You're not being unreasonable at all. There should be a process to induct them! We work closely with HR for new staff and once someone is confirmed they give us as much notice as possible and we sort out a sheet with their login info (which includes a temporary password which asks them to change upon login) which is given to HR and they deal with it as part of onboarding. New staff normally pass our way for devices or for a photo for their ID so they'll see us either way and should do really, they need to know who the IT team is!
  • Thanks 1
Posted
SLT: The proper way is not to send a new person to a room they don't know of, to a person they have never met. If I have a password for a new person, I take it to them, they don't come and find me. [/i][/b]

Then maybe they should be brought to you, rather than sent on their own. Or alternatively, arrange a time for you to come to them.

 

We have an induction schedule for staff, which involves key meetings or information they will need, ranging from having their photo taken for the ID card, IT induction, safeguarding meeting, subject/department meeting, etc. They are taken from reception, by a member of the office to their first meeting and handed over, then when they're done there, the person from that meeting takes them to the next. The benefit we have in this school is that we are an extremely small school in terms of footprint area, which helps with the coordination of meetings.

  • Thanks 1
Posted
Password in a sealed envelope seems like a decent compromise. I have a introduction letter: this is your username, this is your email, this is your password, which is synced to these things, but not these, this is the stupid site that needs a different username and wouldn't know oauth if it raised from the seabed and started attacking the city
  • Thanks 2
Posted
Personally accounts for us are created by Locker (based off their Bromcom details, eg rights and permissions)

 

It generates and email/login/password for us via an email, I will then print this and give to their line manager/whoever is doing their induction before they start. I then book in an IT induction as part of this usually on their first day, where they first login and get shown any systems / services as part of their role. This way if for any reason on the first day we cannot do their IT induction, their line manager will be able to at least get them started.

 

A bit more importantly for me, getting accounts generated before they start gives time for Office 365 services such as Outlook and OneDrive to provision and be ready on first use.

Our process is very similar to this, works well

Posted

It's been a while, but I'm pretty sure from when I was a school governor that an induction policy is a mandatory document and you're supposed to keep an audit trail when people complete it.

 

Login details in a sealed envelope with the information that it was sent in a sealed envelope and should be reported immediately if there's any sign it has been opened could be a reasonable compromise.

 

You can set a really long but simple password:

 

everyoneknowsthispasswordbecauseigivethesameonetoeveryonesoanyonecanreadyouremailsuntilyouchangeit

  • Thanks 2
  • 4 months later...
Posted
So staff we set random passwords give it to Line Manager and HR before they arrive - but as part of the induction day 1 they come and see us in IT and that is when we change it, give them iPad and Laptop - (we are a Secondary school) other things include seeing DSL and doing Training safeguarding and IT Security. There should be an induction day and you should be part of it
  • 7 months later...
Posted
A long random number password might be a good way of encouraging them to change it to something more memorable. Perhaps some training could help on how to create good secure yet memorable passwords might help.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...