Jump to content

Recommended Posts

Posted

We've recently migrated to Arbor, and I am wondering how you give access to the data to external/agency/supply staff. With SIMS, the data is only accessible via a school computer so access is effectively revoked when the supply staff leaves, however with Arbor being cloud-based, they can continue to access it remotely (presenting a GDPR and potential safeguarding concern). How do you all handle this? We don't currently have SSO enabled on Arbor, although I know that is a possibility.

Posted
28 minutes ago, enjay said:

We've recently migrated to Arbor, and I am wondering how you give access to the data to external/agency/supply staff. With SIMS, the data is only accessible via a school computer so access is effectively revoked when the supply staff leaves, however with Arbor being cloud-based, they can continue to access it remotely (presenting a GDPR and potential safeguarding concern). How do you all handle this? We don't currently have SSO enabled on Arbor, although I know that is a possibility.

We use SSO with Google and limit supply accounts using context-aware access so they can only log on on site.

Posted
3 minutes ago, Primus said:

We use SSO with Google and limit supply accounts using context-aware access so they can only log on on site.

 

Is the context-aware access something you're setting in Google, limiting where those accounts can log in?

Posted
14 minutes ago, enjay said:

Thanks. I'd prefer to use MS rather than Google, but I'm pretty sure it can do the same thing.

Yeah, we use Google because we're a Google Workspace trust, it makes sense to use SSO with the service you use or use the most etc.

Posted
3 minutes ago, Primus said:

Yeah, we use Google because we're a Google Workspace trust, it makes sense to use SSO with the service you use or use the most etc.

 

Agreed. We use both, and where possible have SSO set up on both too so people don't have to remember which to use! MS is generally cleaner though, as Google SSO can get problematic when accessing from personal mobile phones.

 

I was considering enabling SSO for Arbor anyway, so maybe this is just the reason I need.

Posted
1 minute ago, bobsmith said:

on a side note - isn't access revoked when you disable their arbor account when they leave?

 

Yes, but you misunderstand my question. I'm meaning access for emergency cover staff who only come in for one day, not long-term supply.

Posted

ok - for short term access I had placeholder staff accounts that were used for the cover - their logins were restricted to in-school only and passwords were generated daily.

worked well enough

Posted

when we did it on sims it was on-prem servers with no remote access - so it handled itself

 

when we had bromcom (works 99% the same as arbor) - we used ip-restrictions within bromcom - but conditional access for their microsoft/google accounts would work equally well.

 

but since the passwords were only good for 24 hrs it wasn't a major security concern.

Posted (edited)

In relation to supply/agency, for a Microsoft/Arbor scenario we have setup as follows:

 

Microsoft Entra ID etc

  • Dedicated Supply/Agency (Microsoft) Account(s) to sign into computer
  • Conditional Access Rule to stop signing into M365 Account outside school etc. - Stops access outside of school / devices
  • Conditional Access Rule to stop "Log in using Microsoft" option for Arbor outside school etc (Trusted Location only) - Stops access to Arbor outside of school / devices

Arbor

  • Arbor MFA Enabled (No Whitelist) - E.g. Arbor MFA applied at all times
  • Arbor (Supply/Agency) Account pre-set up
    Password set, but not given to supply / agency (Retained by IT Support)
    Arbor Account MFA pre-setup (by, and retained by IT Support)
    Arbor Password Reset Emails Blocked (e.g. Mail Flow Rule) - Stops Supply/Agency receiving link to reset Arbor Account Password.

 

Result, Supply/Agency staff member sign in using assigned M365 account / credentials then uses school-specific Arbor Sign-in URL to sign into Arbor using "Log in using Microsoft" option.

 

With changes this week by Arbor in relation to SSO we had to reset the SSO of our Supply/Agency Arbor Accounts.

 

We had to use Microsoft Conditional Access, as MFA Whitelist by School IP within Arbor wasn't sufficient enough by itself.

 

 

Edited by MYK-IT
Posted

Unfortunately Arbor doesn't offer IP restriction, nor does it do daily password resets (we have the AD logins doing that, which means the supply staff can't continue to access Office but Arbor has its own logins).

Posted (edited)
5 minutes ago, enjay said:

Unfortunately Arbor doesn't offer IP restriction, nor does it do daily password resets (we have the AD logins doing that, which means the supply staff can't continue to access Office but Arbor has its own logins).

Arbor does provide IP Whitelist for Arbor MFA, but as previously mentioned Microsoft Conditional Access combined with Microsoft SSO will give you more (granular) control - plus don't give them their Arbor Account (credentials)..if you are able to enable Microsoft SSO option.

Edited by MYK-IT
Posted
1 minute ago, MYK-IT said:

Arbor does provide IP Whitelist for Arbor MFA, but as previously mentioned Microsoft Conditional Access combined with Microsoft SSO will give you more (granular) control - plus don't give them thier Arbor Account (credentials)..if you are able to enable Microsoft SSO option.

 

Indeed, I should have been more specific. Arbor does provide IP whitelisting, but it applies to all users. I'm happy for most users to have remote access, I just want to stop the temporary staff from continuing to access it once they've left. It looks like I'll need to enable SSO for Arbor, then restrict the login locations for the supply accounts.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...