When connecting a third party, we lock down the integration by IP address and sometime client cert authentication as well as a username and password. I think the real security issue is users keeping their password secure. There was a recent case when one MIS supplier left a default username and password set up on their system, it was the same credentials for every school that wasn't a cloud based system. Also recently I was in a school and the secretary had her password written on a postit note attached to the screen, when I asked her about it, she complained that she was forced to make up a really long username with numbers, letters, different cases and funny characters and couldn't remember it.