browolf Posted November 18, 2008 Posted November 18, 2008 Just attended a non-technical meeting with a capita rep over sims learning gateway. There was some brief mention of taking over active directory. I don't like the sound of that. Can anyone elaborate on what this really means?
Michael Posted November 18, 2008 Posted November 18, 2008 I highly doubt it, although it would be nice if Sims just worked with AD automatically. Would make a lot of sense.
matt40k Posted November 18, 2008 Posted November 18, 2008 It has an Active Directory provising, basically it creates all your windows logon accounts from the SIMS db. Great really, you can get it separately too. Students\Staff\Parents.
browolf Posted November 18, 2008 Author Posted November 18, 2008 that doesnt sound so bad. so does that mean having stuff installed into sims that will auto-create accounts in ad?
penfold_99 Posted November 18, 2008 Posted November 18, 2008 Just attended a non-technical meeting with a capita rep over sims learning gateway. There was some brief mention of taking over active directory. I don't like the sound of that. Can anyone elaborate on what this really means? What will happen is your LA will installed as AD server there end and you will need to hook up your ad server to it. This will allow LA wide provisioning of usernames for SIMS learning Gateway, ie a parent has a username but can access all their children's detail even if they are at more than on school. I would be worried also as there is a possibility of loss of control of active directory. For people looking really darkly this is one of the key things before bsf can happen.
matt40k Posted November 18, 2008 Posted November 18, 2008 Yes, it does really look like a BSF product. However it can be installed at a school level, just looks a bit.... interesting. If the internet goes down you can't view student details (etc), you should still be able to log in. However you won't be able to login locally (ie at the school), one would hope if the plan was to have central AD, you would have backup lines. Maybe even a AD at large schools. At least it's not my problem!!
matt40k Posted November 18, 2008 Posted November 18, 2008 Yes which is part of SLG2. The main idea is that Active Directory is hosted at the LEA level, which means the school won't be able to log on if the school's internet is down.
powdarrmonkey Posted November 18, 2008 Posted November 18, 2008 Yes which is part of SLG2. The main idea is that Active Directory is hosted at the LEA level, which means the school won't be able to log on if the school's internet is down. That's what local domain controllers are for.
matt40k Posted November 18, 2008 Posted November 18, 2008 Sort to beats the idea of your LEA having them
jamesb Posted November 18, 2008 Posted November 18, 2008 Active Directory Provisioning by SLG2 doesn't actually have any effect on existing network accounts. The accounts it provisions are used purely to log into the SLG site and gain access to appropriate data. These accounts can then be consolidated with existing network accounts so that users can use these to log in to the SLG site. It isn't necessary to migrate all school ADs over to the LA at all, if the LA is hosting SLG then they can hold a seperate AD structure for SLG with no impact on school's existing sites. There is the potential, with customised provisioning, to use SLG to create an entire network structure for logins, but this is a seperate, chargeable service. There is no takeover of AD, all that needs to happen is an OU to be created for the use of SLG in the existing AD structure.
browolf Posted November 18, 2008 Author Posted November 18, 2008 This isnt an LA thing. atm our lea is nowhere, our senior management want to get ahead of the game and are dealing straight with capita.
penfold_99 Posted November 18, 2008 Posted November 18, 2008 Active Directory Provisioning by SLG2 doesn't actually have any effect on existing network accounts. The accounts it provisions are used purely to log into the SLG site and gain access to appropriate data. These accounts can then be consolidated with existing network accounts so that users can use these to log in to the SLG site. It isn't necessary to migrate all school ADs over to the LA at all, if the LA is hosting SLG then they can hold a seperate AD structure for SLG with no impact on school's existing sites. There is the potential, with customised provisioning, to use SLG to create an entire network structure for logins, but this is a seperate, chargeable service. There is no takeover of AD, all that needs to happen is an OU to be created for the use of SLG in the existing AD structure. It does impact netowrk accounts as if teachers want to use SLG2 they will need to have a sperate username and password from there network one. This is very impractical, the the LA would recommend teachers use the sims generated and get the school to integrated into there internal setup.
jamesb Posted November 18, 2008 Posted November 18, 2008 Its no more impractical than having a separate login for SIMS .net, or for webmail, or for a forum. From what I gather it is possible to consolidate accounts to different domains as well, not easy, but possible.
TheScarfedOne Posted November 19, 2008 Posted November 19, 2008 Multiple logons for SIMS.net no longer applies - you can link the accounts using passthough in System Manager.
jamesb Posted November 19, 2008 Posted November 19, 2008 I'm aware of that, but my point was more that people regularly use multiple logins for different systems.
forcryingoutloud Posted November 25, 2008 Posted November 25, 2008 My worry with this like the rest is that it smacks of BSF. Luckily our AD doesn't attach to SIMS (the SIMS manager wanted it her own way so I din't feel like arguing), but what happens if the LEA's server gets compromised? We all know how good the public bodies are at looking atfer info.
localzuk Posted November 25, 2008 Posted November 25, 2008 This is how Somerset County Council have done it: The LEA has AD servers, which are provisioned from your SIMS data. Our staff already have an LEA AD account. The 2 accounts created can be consolidated (ie. the existing LEA AD account takes over the role of the SIMS provisioned account), leaving only one username. The school maintains its AD system separately. Now, this means that staff only need to have one AD account (which for us is used for various SCC and SouthWest One provided services), pupils will have one account and parents will have one account for the service. Your in school AD stuff stays separate. It does, of course, mean that pupils will need to remember their 2 different usernames. I have enquired into ADFS with our SLG bods, which could solve this issue, but it is just an idea.
Quackers Posted November 25, 2008 Posted November 25, 2008 We have it installed here onsite self hosted, it works with AD very well. Just do not expect a speedy response if you need support, as its really bad. It does adjust the schema. With the student accounts you can consolidate their sims login with there network login, so it all links in. It all works well, just a shame its so over priced.
Sylv3r Posted November 25, 2008 Posted November 25, 2008 We have it locally installed here as well. Student and Staff accounts are consolidated so it silently logs them in when they are logged onto the domain. Parents are to be provided with their own username / password for the launch in September, which have been created on our AD. This links the username provided with their sons / daughters.
FragglePete Posted November 26, 2008 Posted November 26, 2008 This is also falls in line with a project called Merlin on the SWGfl. I idea of Merlin being one login does all. Using Shiboleth (sp?) to authenticate against all the different systems a user will need access to. The example given that if a parent has a three children at two different Schools they should be able login once through the Merlin portal which will then authenticate them against the MIS system at two different locations. The same for students who may have access to the School VLE and a College VLE and resources. Again, Merlin authenticates them and they get automatic access whereever they go. We're involved in the Pilot at the moment, but at the moment it's only the Portal that's active. When asking the technical questions about how it all ties in with network accounts, etc it was mentioned that the MIS would be the system that generate the network accounts, etc. So I guess this all ties in with that. Pete
mleighton Posted November 26, 2008 Posted November 26, 2008 Consolidation means that all your users can access SIMS online using their 'normal' network username and password. We have been running it since it was made available - some teething issues but it does work. At least it makes transfer from your learning platform to the SIMS data and vice versa seamless.
YorkshireTechie Posted November 26, 2008 Posted November 26, 2008 we have had integrated AD happen at some of our local schools here, a high school and its family of feeder schools had there AD integrated by the LEA service provider. they said that from a support aspect nothing would change and that third party support would still get the required access to maintain and configure the individual networks. but it did...... it took weeks to get a logon account (administrator status gone) and then when that happened you still couldnt do anything on the networks. there were lots of promises and nearly all of them were broken, it seems like they just wanted total control, they even offered free technical support to try and Persuade the primary schools to offload the third party support.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now