enjay Posted December 10, 2025 Posted December 10, 2025 We've recently migrated to Arbor, and I am wondering how you give access to the data to external/agency/supply staff. With SIMS, the data is only accessible via a school computer so access is effectively revoked when the supply staff leaves, however with Arbor being cloud-based, they can continue to access it remotely (presenting a GDPR and potential safeguarding concern). How do you all handle this? We don't currently have SSO enabled on Arbor, although I know that is a possibility.
Primus Posted December 10, 2025 Posted December 10, 2025 28 minutes ago, enjay said: We've recently migrated to Arbor, and I am wondering how you give access to the data to external/agency/supply staff. With SIMS, the data is only accessible via a school computer so access is effectively revoked when the supply staff leaves, however with Arbor being cloud-based, they can continue to access it remotely (presenting a GDPR and potential safeguarding concern). How do you all handle this? We don't currently have SSO enabled on Arbor, although I know that is a possibility. We use SSO with Google and limit supply accounts using context-aware access so they can only log on on site.
enjay Posted December 10, 2025 Author Posted December 10, 2025 3 minutes ago, Primus said: We use SSO with Google and limit supply accounts using context-aware access so they can only log on on site. Is the context-aware access something you're setting in Google, limiting where those accounts can log in?
Primus Posted December 10, 2025 Posted December 10, 2025 Just now, enjay said: Is the context-aware access something you're setting in Google, limiting where those accounts can log in? Yes
enjay Posted December 10, 2025 Author Posted December 10, 2025 Thanks. I'd prefer to use MS rather than Google, but I'm pretty sure it can do the same thing.
Primus Posted December 10, 2025 Posted December 10, 2025 14 minutes ago, enjay said: Thanks. I'd prefer to use MS rather than Google, but I'm pretty sure it can do the same thing. Yeah, we use Google because we're a Google Workspace trust, it makes sense to use SSO with the service you use or use the most etc.
enjay Posted December 10, 2025 Author Posted December 10, 2025 3 minutes ago, Primus said: Yeah, we use Google because we're a Google Workspace trust, it makes sense to use SSO with the service you use or use the most etc. Agreed. We use both, and where possible have SSO set up on both too so people don't have to remember which to use! MS is generally cleaner though, as Google SSO can get problematic when accessing from personal mobile phones. I was considering enabling SSO for Arbor anyway, so maybe this is just the reason I need.
bobsmith Posted December 11, 2025 Posted December 11, 2025 on a side note - isn't access revoked when you disable their arbor account when they leave?
enjay Posted December 11, 2025 Author Posted December 11, 2025 1 minute ago, bobsmith said: on a side note - isn't access revoked when you disable their arbor account when they leave? Yes, but you misunderstand my question. I'm meaning access for emergency cover staff who only come in for one day, not long-term supply.
bobsmith Posted December 11, 2025 Posted December 11, 2025 ok - for short term access I had placeholder staff accounts that were used for the cover - their logins were restricted to in-school only and passwords were generated daily. worked well enough
enjay Posted December 11, 2025 Author Posted December 11, 2025 How did you restrict the login to in-school only? Is that conditional access policies, as per the other suggestion?
bobsmith Posted December 11, 2025 Posted December 11, 2025 when we did it on sims it was on-prem servers with no remote access - so it handled itself when we had bromcom (works 99% the same as arbor) - we used ip-restrictions within bromcom - but conditional access for their microsoft/google accounts would work equally well. but since the passwords were only good for 24 hrs it wasn't a major security concern.
MYK-IT Posted December 11, 2025 Posted December 11, 2025 (edited) In relation to supply/agency, for a Microsoft/Arbor scenario we have setup as follows: Microsoft Entra ID etc Dedicated Supply/Agency (Microsoft) Account(s) to sign into computer Conditional Access Rule to stop signing into M365 Account outside school etc. - Stops access outside of school / devices Conditional Access Rule to stop "Log in using Microsoft" option for Arbor outside school etc (Trusted Location only) - Stops access to Arbor outside of school / devices Arbor Arbor MFA Enabled (No Whitelist) - E.g. Arbor MFA applied at all times Arbor (Supply/Agency) Account pre-set up Password set, but not given to supply / agency (Retained by IT Support) Arbor Account MFA pre-setup (by, and retained by IT Support) Arbor Password Reset Emails Blocked (e.g. Mail Flow Rule) - Stops Supply/Agency receiving link to reset Arbor Account Password. Result, Supply/Agency staff member sign in using assigned M365 account / credentials then uses school-specific Arbor Sign-in URL to sign into Arbor using "Log in using Microsoft" option. With changes this week by Arbor in relation to SSO we had to reset the SSO of our Supply/Agency Arbor Accounts. We had to use Microsoft Conditional Access, as MFA Whitelist by School IP within Arbor wasn't sufficient enough by itself. Edited December 11, 2025 by MYK-IT
enjay Posted December 11, 2025 Author Posted December 11, 2025 Unfortunately Arbor doesn't offer IP restriction, nor does it do daily password resets (we have the AD logins doing that, which means the supply staff can't continue to access Office but Arbor has its own logins).
MYK-IT Posted December 11, 2025 Posted December 11, 2025 (edited) 5 minutes ago, enjay said: Unfortunately Arbor doesn't offer IP restriction, nor does it do daily password resets (we have the AD logins doing that, which means the supply staff can't continue to access Office but Arbor has its own logins). Arbor does provide IP Whitelist for Arbor MFA, but as previously mentioned Microsoft Conditional Access combined with Microsoft SSO will give you more (granular) control - plus don't give them their Arbor Account (credentials)..if you are able to enable Microsoft SSO option. Edited December 11, 2025 by MYK-IT
enjay Posted December 11, 2025 Author Posted December 11, 2025 1 minute ago, MYK-IT said: Arbor does provide IP Whitelist for Arbor MFA, but as previously mentioned Microsoft Conditional Access combined with Microsoft SSO will give you more (granular) control - plus don't give them thier Arbor Account (credentials)..if you are able to enable Microsoft SSO option. Indeed, I should have been more specific. Arbor does provide IP whitelisting, but it applies to all users. I'm happy for most users to have remote access, I just want to stop the temporary staff from continuing to access it once they've left. It looks like I'll need to enable SSO for Arbor, then restrict the login locations for the supply accounts.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now