Jump to content

Recommended Posts

Posted

Hi All, We are one of many Birmingham schools who have just moved from Facility to SIMS. I have been told by Link2ICT that SIMS lacks the ability to force complex passwords. Also they say you cannot stop a user changing their own password.

 

Are either of these true. If so is there a way of stopping teacher changing their own password to "password".

 

What I have done so far is to reset the password and then manually impersonated them and then changed the password to the first 5 characters (to make life easier for them) and told them not to change their password (chocolate teapot territory I know).

Posted

Yep link to AD.

I don't know if it's fixed in the latest version but some people had issues when linking to AD, basically after you search the user out and select, it doesn't include the domain name in the username box. it just says for example \vik.paw , but if you manually type in the start 'my_domain' before the '\' it works fine. then you have the same complexity that you enforce on the domain.

 

not much auditing of who did what, if that's what you mean.

Posted

There's "User A logged on from Workstation B at Date:Time"

 

There's no "User A logged on from Workstation B at Date:Time and then proceeded to change Joe Blogg's address to the wrong thing and that's why Mrs Bloggs never got that letter". Or at least, there isn't in a way that's exposed to the customer.

 

So from a point of view of "who's been messing around with X", there's no audit trail unless it involves cash.

Posted (edited)

We have previously used the audit trail in Facility and IIS log files to track who was using e-Portal from home to add offensive comments against pupils and staff.

 

Does the Web facing SIMS product add more audit trails?

Edited by Alis_Klar
Posted
Yes it should, but i can imagine you won't get access to the logs unless you self-host. That would be using IIS and sharepoint, tied to Active Directory logins. However, that will allow you to say as @pete said above that User A logged in from home. I'm not sure if it goes as far as to say, User A was served the behaviour add page, and entered details on person X. I think at some point, the calls go straight through to the SIMS server, and SIMS has no auditing.
Posted
I can't say I've heard of anything like you describe happening. Teacher access is tightly controlled - they can't just go into the basic pupil records and edit. Assessments are all audited with date, time and who made the entry. Pupil access is even more tighly controlled.
Posted
The equivalent of the behaviour add screen in e-Portal is where we previously had the trouble. So assessments entries are audited but not behaviour add entries?
Posted

We use custom groups, so not sure if the basic ones have changed, but i'm sure teachers could edit some student details, though it appears not now.

On assessment, it records date but not time, and for a resultset linked grade, only the most recent saved entry is recorded. This is on the surface, the db may store other logs behind the scenes.

Not sure how this changes through SLG.

Posted
The equivalent of the behaviour add screen in e-Portal is where we previously had the trouble. So assessments entries are audited but not behaviour add entries?

Behaviour auditing is lacking in SIMS and has been something many have requested for a long time.

Posted
I spoke to Geoff Perry the prooduct manager today about the Behaviour improvements that are due in the autumn release. A lot of change requests have been implemented but not a full audit trail. However the person that created the incident is automatically recorded and there are new permissions to prevent ordinary users from changing content.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...