Jump to content

Recommended Posts

Posted

DfE standards say that we should have SSO for all "cloud solutions" (which is great!). Meeting digital and technology standards in schools and colleges - Cloud solutions - Guidance - GOV.UK

 

So, I've been contacting a few of our cloud solution providers to find out when they plan to implement SSO... The response has been mixed...

 

  • MyMaths have said they have no plans for students, but are considering staff...
  • MyConcern are apparently releasing this in April (but we've been asking for 5 years, so not holding our breath here)

 

The standards also require that these systems do not allow users to log in by any other method... Well, I'm not sure I could confidently name a single cloud system that reliably does that... Some companies say "we'll set all your users passwords to nonsense" - that's all well and good except users can just press the "forgotten my password" button on the login page and reset it... Some systems even send welcome emails that ask users to set their password...

 

It's tricky, as obviously you generally need to be able to sign into a system to set up SSO, which requires you to use a password - and what if you ever have an issue with said SSO - how do you get back in without being able to login with a password? The system has to allow you to specify on groups of people which can/cannot use passwords? This all adds some considerable development time for companies. I can see why it often feels like SSO is just thrown in as a "convenience" for users, rather than a "security" measure for securing logins that happens to also be convenient.

 

Has anyone else had similar conversations with suppliers? We basically have a rule of "no SSO, no go" on new purchases now - are others doing the same? Has anyone parted ways with companies that haven't met this requirement?

Posted

Yes. How did it go? Well let's just say that I am glad the current guidance from the DfE is that SSO should be used.

 

However I fear the "SSO" platform TES have built is their answer to that: "well its SSO. It's the school's IT Team who are being non compliant by refusing to migrate to us and instead continuing to use their legacy not-bespoke-for-education Entra/Google Identity platforms."

Posted

This is an interesting topic given that Bromcom's Google SSO fell over the other week. Bromcom SSO is pretty decent, in that end users don't have to perform a regular sign-in first: it just works even on the first login with all the setup being done for people by admins. Importantly, regular credentials are positively disabled when SSO is turned on for an account, so the end user is unburdened.

 

SIMS Connected is a good example of how not to do it. The SSO is their own SIMS ID account, which you can SSO into in turn via Google, but the end user has to opt in to that. Their single sign-on documentation was largely about using SIMS ID to sign into other things, rather than about Google or Microsoft account SSO. Regular credentials remain active, too, and the Google account links seemed fragile IME.

 

If I were starting up a web app, I'd be looking to support Google or Microsoft SSO only, with no local credentials. I'm not especially knowledgable about it, but my gut feeling is that leaving the bulk of authentication code to the big providers would seem sensible.

  • Like 2
Posted
1 minute ago, jthompson said:

 

 

SIMS Connected is a good example of how not to do it.

There is actually a flow you can follow that sets up the user without setting up a separate account first. I've written a six page document describing the process precisely.

 

...and precisely no-one (apart from me) has been able to complete the flow without clicking the wrong thing and messing it up. I now step through it with each teacher individually.

 

I'm very happy that it can be done. But wow does it needs a UX re-work.

Posted
19 minutes ago, psydii said:

There is actually a flow you can follow that sets up the user without setting up a separate account first. I've written a six page document describing the process precisely.

 

...and precisely no-one (apart from me) has been able to complete the flow without clicking the wrong thing and messing it up. I now step through it with each teacher individually.

 

I'm very happy that it can be done. But wow does it needs a UX re-work.

We recently set up all our staff with SIMS Connected. Booked groups of 10 teachers to come to and IT suite and got them to follow what we told them to click on, EXPLICITLY telling them to race ahead or guess what to click next. About 20% of them ignored our instructions and had to be reset. 

Posted

Yup that tracks. It can be done,  but not by normal people. You need an odd sort of brain to correctly follow instructions that say "don't do anything until you've read the next three pages, then do exactly what these pages say, not what the instructions on the screen say, even though you think they are the same, they are not, everything that you think your should click on you should not, apart from in these three specific places, no not that one"

Posted

We've been setting up SSO for everything we can recently, I'm going live with a bunch of systems over Easter hols, using our AD / Entra accounts as our source of truth. I haven't been leaning hard on anyone though, just setting it up where it's available.

 

We've done / doing:

  • Google
  • Adobe
  • Arbor
  • School Cloud
  • Canva (already live - we did SSO from day 1)

 

It'll be interesting to see if MyConcern go that way, last I heard from them was they didn't want to expose safeguarding data to SSO as it was "less secure". 

 

I will laugh heartily if MyMaths manage SSO in any meaningful way. They still haven't linked their student management up to an MIS sync tool, and their manual / csv based student management is awful, which I would argue is a far bigger problem.

Posted

I can understand why a safeguarding platform might shy away from offering SSO. Yes, technically, a school staff member's Google or Microsoft account could be about as secure as anything (enforced MFA, strong password, allowllisting of third-parties, automated provisioning/deprovisioning via MIS link), but it's not in the platform's power to ensure that that is being done.

Posted

Yeah its the upsell to "enterprise" customer.  That said, its bonkers how many 3rd party services offer an end-user-initiated SSO flow. Most weeks there's a dozen random services in the enable sso request queue!

Posted
On 18/03/2026 at 14:01, jthompson said:

Bromcom SSO is pretty decent, in that end users don't have to perform a regular sign-in first: it just works even on the first login with all the setup being done for people by admins. Importantly, regular credentials are positively disabled when SSO is turned on for an account, so the end user is unburdened.

Guess again... try the teacher app (for example)... old credentials still work.

 

An enterprising student told me that credentials still work for the student app too - and they can request a password reset email in the portal. They told me the web version shows an error, but does actually provide the login token. I haven't had time to personally verify this, but it seems highly plausible as they had created their own version of the Bromcom student portal because, and I paraphrase: "the original was so terrible". Sadly as there was a significant potential for harvesting credentials, we did have to ask them to limit it to be only for themselves. I would recommend blocking the password reset email in your inbound email rules.

 

We had to have some... protracted conversations... with The Access Group after they emailed all users at 6:30pm instructing them to create a password for their new "Access Workspace" accounts, despite them already being 365 SSO enabled at the time. Sigh.

 

If any other MyMaths customers should choose to email in and ask about SSO - it would be much appreciated. Alternatively... has anyone moved away from MyMaths to another product? Any good alternatives?

  • Like 1
  • Thanks 1
Posted

Anyone using Wonde MyLogin solution?  We're primary.  This will work with Google and EntraID for authentication, will also provision those from your MIS using their other product EduSync.

 

Is useful for Primary Schools where you can log into the Entra Enrolled Windows or Google Chrome OS device using a QR code or Emoji password.

 

Coverage by apps is patchy tho.

 

Mathletics and Pearson ActivLearn refuse to interoperate with any MIS sync tool.  They have made their in-built tool a bit less confusing recently.

 

TTRS and PurpleMash and Just2Easy are very good at interoperability.

Posted
27 minutes ago, Alis_Klar said:

Mathletics and Pearson ActivLearn refuse to interoperate with any MIS sync tool.  They have made their in-built tool a bit less confusing recently.

Full Pearson ActivLearn MIS integration is coming in April apparently. I believe that if your used modules have migrated to ActiveHub already you can use Wonde now...

 

Light at the end of the tunnel...!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...