Jump to content

Recommended Posts

Posted

These are my own thoughts of Arbor as a new systen admin setting up the system.

 

We are moving from Bromcom to Arbor and my first thoughts of Arbor from a Sys Admin point of view haven't given me that wow factor.

 

1. Whilst testing our dummy site, setting user permissions is clunky. I thought Bromcom was clunky but in my opinion Arbor isn't any better. Not being able to export user permissions and import them into a live system is a bit.. ah really!?

 

2. Still on the user permissions, trying to create an Arbor Sys Admin role for those with full admin access is very slow and clunky having to click on every individual permission to turn it to "allow". There's over 250 of these permissions! I would have thought it would have thought that the role permissions would have been set out in at least modules / groups.

 

3. We have to use and edit one of the pre-defined permission roles to turn it into our own user permission role and unable to add to this list.

 

4. 2FA setup for end users does not contain a QR code so the end user has to manually type in the long security code when adding 2FA to their account.

 

5. Yet to get confirmation on this but if we use IP Allow lists so users don't need to us 2FA, we cannot have higher level accounts like HR, Sys Admin etc forced to use 2FA even when using the system from an IP Allowed list.

 

6. There's a lot of things that don't transfer over from SIMS or Bromcom.

 

I hope i'm not the only one expressing these concerns but I would have thought that a new MIS would have thought about the above points raised.

Posted

Staff and student photos, DMS / documents & reports attached to students, exam information. I've heard the medical information such as doctors is all mis-aligned too so students are all given the wrong doctors information.

Posted

regarding 2 and 5, just use 365 SSO instead, set all the Arbor accounts to randomised passwords (except maybe certain key accounts) then use that for access and 2FA rather than Arbors 2FA.

 

 

Posted (edited)
27 minutes ago, timbo343 said:

Staff and student photos, DMS / documents & reports attached to students, exam information. I've heard the medical information such as doctors is all mis-aligned too so students are all given the wrong doctors information.

seems odd, I did a Arbor migration in 2022, staff and student photos came across, as well as all the documents and DMS stuff, all were part of the SQL dump and the DMS copy that was uploaded to them. Don't remember having any issues with doctors etc, the only thing that didn't come across was assessment, that had to be extracted from SIMS and uploaded in to a format that Arbor uses for assessment as the way SIMS and Arbor treat assessment is too different for them to migrate through the SQL dump from SIMS.

 

IGNORE ME, saw you were coming from Bromcom not SIMS haha, SIMS its only really assessment 

Edited by stephen.loader
Posted
3 hours ago, timbo343 said:

These are my own thoughts of Arbor as a new systen admin setting up the system.

 

We are moving from Bromcom to Arbor and my first thoughts of Arbor from a Sys Admin point of view haven't given me that wow factor.

 

1. Whilst testing our dummy site, setting user permissions is clunky. I thought Bromcom was clunky but in my opinion Arbor isn't any better. Not being able to export user permissions and import them into a live system is a bit.. ah really!?

 

2. Still on the user permissions, trying to create an Arbor Sys Admin role for those with full admin access is very slow and clunky having to click on every individual permission to turn it to "allow". There's over 250 of these permissions! I would have thought it would have thought that the role permissions would have been set out in at least modules / groups.

 

3. We have to use and edit one of the pre-defined permission roles to turn it into our own user permission role and unable to add to this list.

 

4. 2FA setup for end users does not contain a QR code so the end user has to manually type in the long security code when adding 2FA to their account.

 

5. Yet to get confirmation on this but if we use IP Allow lists so users don't need to us 2FA, we cannot have higher level accounts like HR, Sys Admin etc forced to use 2FA even when using the system from an IP Allowed list.

 

6. There's a lot of things that don't transfer over from SIMS or Bromcom.

 

I hope i'm not the only one expressing these concerns but I would have thought that a new MIS would have thought about the above points raised.

I can't comment on moving from Bromcom to Arbor, but from moving from SIMS to Arbor most, if not all, of the above weren't an issue.

 

Specifically with relation to #2, there is an Arbor role called "School Administrator" which does essentially what you're asking for.

 

And regarding #3, yes it's mildly frustrating you can't add your own business roles, but there are - certainly in our case - numerous superfluous roles that can be re-purposed fairly easily. Probably easier than setting up a new one from scratch.

Posted (edited)
4 hours ago, timbo343 said:

5. Yet to get confirmation on this but if we use IP Allow lists so users don't need to us 2FA, we cannot have higher level accounts like HR, Sys Admin etc forced to use 2FA even when using the system from an IP Allowed list.

 

In relation to MFA, we enabled Arbor MFA (for staff) with no exceptions (e.g. no white list) combined with enabling Microsoft SSO and an associated MS Entra Conditional Access Rule.

 

The end result being;

  • Any attempt to access Arbor using a 'Arbor' username and password, the staff member would always be prompted to enter their Arbor MFA
  • Staff would log in using 'Log in with Microsoft' (e.g. Microsoft SSO) option and then based on the applicable Ms Entra Conditional Access Rule they would / not be prompted for Microsoft MFA.

For example,

  • Within school, using a (compliant) school device and "Log in with Microsoft' method, would result in no (Microsoft) MFA prompt (e.g. compliant device is one factor) and access granted
  • 'Higher Level Accounts' could be prompted for (Microsoft) MFA (e.g. using a suitably configured Conditional Access Rule to apply to applicable users / security groups)
    Frequency, and conditions for (Microsoft) MFA requirements can be stipulated (to suit) within the Conditional Access Rule too.

Of course, this is assuming you are using M365 and have (at least) P1 licencing (for Conditional Access Rules) etc.

 

We didn't enable 'whitelisting' using Arbor MFA for other reasons too. One being that traffic originating from personal / guest devices connected to Wi-Fi would have same IP(s) as school devices. And it has also proved useful for such (Arbor) accounts that are used for supply / temp staff, whereby we need to ensure they don't have access outside of school (we additionally pre-configured the Arbor account's MFA combined with blocking emails sent from Arbor, so they can't reset the Arbor account / password either in addition to applying a Conditional Access Rule such that these accounts are only allowed access (to Arbor) from a school IP and compliant device, e.g. school managed device).

 

May be convoluted, but was necessity as Arbor is cloud-based and can effectively be accessed from anywhere, on any device. Which, for us, only by using MS Entra Conditional Access Rule(s) has allowed is to restrict accordingly.

 

TLDR, essentially what @stephen.loader said! 😉

  

2 hours ago, stephen.loader said:

regarding 2 and 5, just use 365 SSO instead, set all the Arbor accounts to randomised passwords (except maybe certain key accounts) then use that for access and 2FA rather than Arbors 2FA.

 

 

 

Edited by MYK-IT
  • Like 3
Posted

We have recently migrated to Bromcom.  If we use M365 SSO would we have all the same options as you have with Arbor?  I would also like to eradicate the supply login from offsite issue.

Posted

So I've spoken to Arbor today and mentioned that those users with higher level access to staff records should have 2FA on as forced regardless if they all within the IP Allow White list. They said they would take it back to the developers.

Posted
On 06/06/2025 at 06:36, timbo343 said:

2. Still on the user permissions, trying to create an Arbor Sys Admin role for those with full admin access is very slow and clunky having to click on every individual permission to turn it to "allow". There's over 250 of these permissions!

oh my god

 

this is the type of thing I can't deal with,.what the hell is wrong with the people making these systems? there's just no excuse for it. Unless the "School Administrator" Alistair mentions is sufficient (or maybe some other roles as someone else mentions). Surely making one customised role that you can save and then use for <whoever> is an obvious want (unless I'm misunderstanding, and that can be done)

 

I don't understand the MS Entra Conditional Access Rule(s) discussed above but can google SSO be used for google schools? From the discussion, is the problem that you can't prevent eg temp staff accessing arbor from outside school?

Posted (edited)
7 minutes ago, coolhands said:

Surely making one customised role that you can save and then use for <whoever> is an obvious want (unless I'm misunderstanding, and that can be done)

There isn't the ability to make a new customised role, however there are numerous roles that will, most likely, be superfluous for most schools which can easily be re-named and re-worked.

 

For example, we have a 'Teacher #2' business role which includes a number of permissions we wanted to grant to all teaching staff, so we simply re-purposed the existing Business Role of "Traveller Support" to achieve it. We currently have 28 business roles that aren't in use, so plenty of scope to amend as necessary.

Edited by AlistairB1983
  • Like 1
Posted

We grabbed one that would never be used and used that.

 

I must admit though, the pages refreshes EVERYTIME a policy item is changed.

 

It's soooo clunky it's unbelievable!!!

Posted (edited)

Out of interested which one is best? Bromcom or Arbor? Since you have now tested both.

 

I don't understand the Bromcom clunky statement. Setting permissions is 1 click to apply to all for things like admin permissions.

 

I find the bromcom interface very nice to work with to be fair. But I've never used Arbor.

Edited by supportman
Posted
17 hours ago, supportman said:

Out of interested which one is best? Bromcom or Arbor? Since you have now tested both.

 

I don't understand the Bromcom clunky statement. Setting permissions is 1 click to apply to all for things like admin permissions.

 

I find the bromcom interface very nice to work with to be fair. But I've never used Arbor.

For me, as my personal opinion as a Sys Admin who will be having a lite-touch on it, i'd say Bromcom but i'm not sure if have the issue is down to familiarity.

 

Just like when we moved from SIMS to Bromcom, yes there was a learning curve but really it felt more natural and slicker.

 

With Arbor, things don't feel as slick especially in the user permissions or security side.

 

I've looked at setting permissions and it's really clunky especially when you search for a specific group of permissions like "HR" or "Appraisal" and want to disable a load of permissions in one go. There is no option to select multiple and you have to individually set each permission with the page and search refreshing each time a permission is changed. Think of it as changing a group policy setting and the entire policy resetting the view back to the beginning.

 

The issue of having higher level permissions / access without forced 2FA when IP Allow list enabled is worrying too, which i've asked our onboarding maanger to look into. A basic true or false statement for this is all it needs.

 

Arbor might be great for the basics or AI features but the ease of managibg user based permissions and security is concerning me.

Posted (edited)
1 hour ago, timbo343 said:

For me, as my personal opinion as a Sys Admin who will be having a lite-touch on it, i'd say Bromcom but i'm not sure if have the issue is down to familiarity.

 

Just like when we moved from SIMS to Bromcom, yes there was a learning curve but really it felt more natural and slicker.

 

With Arbor, things don't feel as slick especially in the user permissions or security side.

 

I've looked at setting permissions and it's really clunky especially when you search for a specific group of permissions like "HR" or "Appraisal" and want to disable a load of permissions in one go. There is no option to select multiple and you have to individually set each permission with the page and search refreshing each time a permission is changed. Think of it as changing a group policy setting and the entire policy resetting the view back to the beginning.

 

The issue of having higher level permissions / access without forced 2FA when IP Allow list enabled is worrying too, which i've asked our onboarding maanger to look into. A basic true or false statement for this is all it needs.

 

Arbor might be great for the basics or AI features but the ease of managibg user based permissions and security is concerning me.

@JamesWeatherill may be interested in that feedback. Sounds like an easy win for their development team to add a "Select All" check box when editing permissions.

Edited by supportman
Posted
On 10/06/2025 at 14:15, Alis_Klar said:

We have recently migrated to Bromcom.  If we use M365 SSO would we have all the same options as you have with Arbor?  I would also like to eradicate the supply login from offsite issue.

 

We have Bromcom and use both time based and location based access control for supply logins:

 

image.thumb.png.1b317c666f7181b83638414bc397b80d.png

 

Everyone else has more open access times/locations but is forced to use MFA through 365

Posted
4 hours ago, timbo343 said:

I'd be happy to talk to @JamesWeatherill about these issues / concerns as I can imagine it's not just me who could be thinking about these.

 

Sorry you've been experiencing issues with the migration. I've taken your list above and passed it back to the team, but if you DM me with any further feedback I'll ensure it's looked at

  • Like 2
  • Thanks 1
Posted
2 hours ago, JamesWeatherill said:

 

Sorry you've been experiencing issues with the migration. I've taken your list above and passed it back to the team, but if you DM me with any further feedback I'll ensure it's looked at

Thanks @JamesWeatherill, happy to have a chat offline if required.

  • 2 weeks later...
Posted

Another issue that has come out the woodwork by moving from Bromcom to Arbor is the Google Classroom integration. Bromcom provide native and free integration into Google Users and Google Classroom, however i've been told that this is a paid for in Arbor.

Posted

A lot use Salamander for all that onboarding of users etc which it can do Microsoft SDS on 365 and Google Classroom provisioning, if you use them or Locker for automated onboarding of users/groups etc then it would be able to do this for you.

Posted
4 minutes ago, stephen.loader said:

A lot use Salamander for all that onboarding of users etc which it can do Microsoft SDS on 365 and Google Classroom provisioning, if you use them or Locker for automated onboarding of users/groups etc then it would be able to do this for you.

 

Thanks. My gripe is that we were told Arbor could push to Google without any third party integration like what Bromcom could do. It's just yet another added cost because no one is transparent these days.

Posted

I didn't even know Arbor did it without a third party as i have been a long term salamander user for nearly 10 years, back when it was a man in a shed operation so would be keeping it regardless.

 

Arbor in my mind is the best choice above all, just got to look at the stats, within 12 months it will over take SIMS market share which is crazy given that years ago SIMS was nearly 95% back in the day.

 

You can do google classroom without a third party if youre already syncing user and class groups to your AD, there are ways and means.

 

Looks like Arbor are selling third party google integration, it isn't native to the product and there website does show that it is a paid for extra.

Posted

Quick Question about both platforms: Do either offer a hosted MCP server?

 

MCP has been the hottest thing in AI for the last six months and I've found them invaluable.

MCP is essentially an interface between the platforms API and your hosted AI agent. The way this works for me is that I authenticate (with my personal creds) to a remote MCP server and then I can use my local AI to ask questions of the API. e.g: "get me a list of the top 100 users with the following attributes, x,y,z. write the output to a google doc". 

This is a huge thing in (non-edu) tech right now and wondered if Arbor/BromCom are doing this or just reselling their own AI platforms with a large markup?

Alternatively, how open is the spec for the API's - writing MCP servers isn't difficult.

Posted
4 hours ago, timbo343 said:

 

Thanks. My gripe is that we were told Arbor could push to Google without any third party integration like what Bromcom could do. It's just yet another added cost because no one is transparent these days.

Make sure everything they say it can do is in your contract before you pay them, then they've breeched their contract

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...