Scorpio
Members-
Posts
261 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Scorpio
-
Its because they have to comply now with GDPR, all their servers are in the US I assume.
-
Also @imran_r i looked at that package but looks like its just a portal, no QR badges ?
-
Hi, not really got anywhere, we looked at Wonde but it has to use their sync tool at additional cost to be able to actually unlock the computer, otherwise it will only sign on apps, which is a bit weird as most of the trouble is getting logged on in the first place. Clever have been in touch, just awaiting them confirming. I think they are missing a trick, they could market this in the UK and EU for sure. Just need to have a server in a EU data centre.
-
No we didnt pay anything the SSO is free so I suppose its nothing lost for them. But we had finally set it up and it was live, spent considerable time getting AD synced with GSuite and Azure etc to be able to implement it. They signed us up first before we went ahead with all the work, which was with a .co.uk email address and also the address of the school so they knew we was in the UK.
-
Looked at Wonde, it doesnt come close just yet in relation to Clever, they have to install it, and you have to use their sync program at additional cost to enable Single sign on to the actual Chromebook and not just the portal, anyone here in europe using Clever, as they may delete you at any point
-
Hi Guys Is there a way of forcing this or manually syncing without waiting what is around 40 minutes according to the documentation ? Obviously we can force AD to Azure but want to force Azure to Gsuite as we have provisioning now setup. Any pointers would be great, seems silly if there isn't, had a search and cant find anything... Thanks S
-
Just awaiting their response, but just deleting the account was really poor of them. Yeah Wonde may have to be the one, no info on it at all though online in comparison to Clever, no tech docs. Also Windows integration isn't done yet too even though the website says so, i spoke to them a few weeks ago... but its all we have atm.
-
Weve just had our Clever account shut down, literally deleted it, causing the school to not be able to login on any device, saying they cannot deal with European schools due to GDPR ? Anyone from the UK using this ? Also anyone using the Wonde QR Badge logins ? Thanks S
-
Next.... does anyone know how to wallpapers the Clever login ? Or change the school name thats displayed ie edit the text maybe ? Also how do you guys deals will password changes, or user must change password on next logon, as it doesnt seem to work or be able to handle it.?
-
Well, i think i may have sorted it, the section that says Network Mask in the SSO section of Google Admin, the clever instructions say to enter this: 1.1.1.1/32 removed and now it works as expected More info here: https://support.google.com/a/answer/6369487?hl=en&ref_topic=6348126 Put on here to help anyone out....
-
You are bang on with your following of this, as we are in the UK we are only using the Clever system to log into the Chromebooks and will be doing so on windows too once we get everything working. Yes we did have the Azure as the identity provider and this worked on Chromebooks and on a simple gmail login either on phone or pc, we would be redirected to the Azure page to authenticate, as you say the google password shouldnt matter. However to sign in with Clever badges because Google can only have one identity provider weve had to change the google one to point to clever then clever points back to azure, thats way the qr or email can be used to login, works fine on the Chromebooks, but now when we use a phone to access email or a random pc and go to gmail.com and enter the email address, instead of being redirected to the Azure page we would assume it should redirect to the Clever login but its just the standard google login using the google password which defeats the object of the SSO. Not sure why its not redirecting to the Clever login, im playing the the User Attributes / claim rules but as above its set and works on the Chromebooks so unsure why anything outside of the Chromebooks is using Google to auth. Any ideas ? Thanks S
-
Weve got the Chromebook to now display the Clever logon box with the option to select Active Directory or Clever badges, either the QR or the Azure email and password work on the Chromebook, BUT when we go to a gmail login it does then pop up with the azure login anymore, it just does the standard google login and the Azure password doesnt work, just the g suite password works.... ???? Am I correct in thinking, the Google and Azure password will be different and not synced? Because the google password becomes dormant ? as the user is being or SHOULD be redirected to the Azure logon page or now the Clever page with option of QR or Azure login? Any ideas on this, i was expecting the same Clever pop up with the QR or AD login as this is now what is in the SSO path in the "Setup SSO with third party identity provider" under Security in Google Admin Thanks S
-
Hi Guys FIRST: I've been setting this up and at the point where we have Lo0cal AD syncing to Azure, we have Google using Azure as its Security provider via SAML, this now seems to work and on Chromebooks we get the Microsoft Logins, also in Windows the passwords for Gmail are the same and the Windows passwords, so all good there, there s a few tweak we need to do but so far seems to be working. But first i have a quick question on the mapping of User Attributes, the Microsoft document HERE says use user.mail instead of user.userprinciplename, which was the default, which did you use ? SECOND: Now we want implement Clever badges, weve signed up and got into the portal and enabled the SSO with Azure as per this document HERE Again, the User Attributes / claim rules seem to differ a lot, again what did you use, i started off with clever.any.email mapped to value user.userprinciplename and the other 2 then set as per the instructions but unsure if this is correct, what did you use? THIRD: I assume to use the Clever QR badges, data somehow need to get into the clever app. How did you sync the data into Clever, I only see manual and SIS sync, I cannot see anyway to sync from AZURE, also I've read something about having to play around with security providers HERE, but unsure if this applies, anyone who uses the clever badges enlighten me to how this is done or how you have this all working. It looks like you have to create CSVs, and SFTP? How do you build the CSVs, is it all manual or is there a semi / automated way ? Thanks S
-
What did you use for your SSO user indetifier on the Google App in Azure ? The Walkthrough you posted says use user.userprincipalname but the microsoft one says use user.mail ? Thanks S
-
Chromebooks - Play Store & Apps Installing on each login
Scorpio replied to Scorpio's topic in Cloud Services
Ok, so ive turned off Delete the Data and it seems to work as described, but like you say this is no good really for Trolley Chromebooks... I would have thought android/play store apps were device based. Seems a little weird that, but it is what it is. Ive approved Excel and Word so would have expected them to show, searching for them brings them up, i will see if they appear by tomorrow.. Thanks. S -
How did you get on with this ? S
-
Hi Guys Getting a roll out of Onsite AD sync to Azure and then using SAML SSO which are testing atm. We've enabled to the play store on the Chromebooks as we want the full version of Office installing, however the playstore and any apps are installing at each login, and reoocours each time, this is obviously not right. The Chromebook is on this compatible list but has an * next to it: https://www.chromium.org/chromium-os/chrome-os-systems-supporting-android-apps However the Chromebook is not set to keep user data, its set to delete at logoff, which we thought was the issue at first. But on this link its says the following: On Chrome OS version 64 and earlier, Google Play apps can't be installed if the User Data device setting is configured to erase all local user info, settings, and state each time the user signs out The version of ChromeOS is 73 so this shouldn't apply based on this. Another thought was because the Chromebook is listed with an * on the comparability list it explains it may need the data migrating, however this should only apply to profiles that were created before the update to 60 or above as explained here in this link User-created profiles on devices after Chrome version 60 or 61 already use a compatible file system and won't need any migration. ----- Secondly I've made a couple of apps available for users to install but they dont show, it just says "there are no apps to install, since your administrator hasn't made any available yet" however upon searching for the names it finds them, but surely they should be listed ? Has anyone ran into any of these issue? Is it to do with one of these settings? Many Thanks S
-
Sync Accounts and Passwords between AD, Microsoft & Google - SSO
Scorpio replied to Scorpio's topic in Cloud Services
Hi Guys Started this. I've got local AD synced to Office 365, ive added the G suite Azure addon and added SSO on there, also added SSO in G suite, so this is initially just setting up SSO, which seems to work however i have a few queries: 1. When logging onto Gmail it asked to login Twice? 2. On Chromebooks i had to enable the SAML SSO for Chrome Devices in G suite, this then redirected to the Login.microsoftonline.com pages but it seems to ask twice for the email address? Is there a way of passing the email to the next screen automatically ? So i just need to enter once then when the screen pops up from Microsoft, just enter the password ? 3. It looks like the user can change the password in Google, how does this work as it seems to change the password in google but not to AD, so the passwords are different in AD and Google, its not a problem on devices that redirect to MS to login, but what about Phones that may use email apps, that will use the changed password in Google ? Do i need to use GSPS or do i have to do something else.? 4. What path do you guys use in the password reset in the Azure G suite plugin ? Its blank atm but should this be filled out ? Next after this I will do the auto provisioning, so many need some more help Many Thanks S -
Sync Accounts and Passwords between AD, Microsoft & Google - SSO
Scorpio replied to Scorpio's topic in Cloud Services
Going to give this a go soon, might do some tests with dummy accounts in G suite to see what happens when account exists. If anyone has done this recently it would be good to hear from you. We are then looking to use the QR badges to log into windows and Chromebooks -
Looks like the Clever option could work to authenticate to a device and not just apps....they support windows now apparently: https://support.clever.com/hc/en-us/articles/360000384086-How-do-I-enable-Clever-Badges-into-Windows-devices-
-
I just spoke to Wonde, they cant login all platforms via QR currently although a tech is contacting me back with more info. Seems its for logging into a predefined list of apps mainly. Possibility of logging into Chromebooks, but wasnt confirmed based on who i spoke to, hence the call back from a tech due. We need to log on any device / platform (Not apps only) as easy as possible for the younger years and have that account associated with that one user. Have you guys done this? We need the web filter reporting to show the user that is using the device / internet. Thanks S
-
Hi We looked at Sophos, and it was too much for this school the software / cloud based filters are way less for lower numbers of devices. Iboss dint want to know with the small numbers and worked out expensive. Looking to use Lightspeed Relay, seems to tick all the boxes and the prices is much better than hardware and some of the other software. Anyone using Lightspeed Relay ? Thanks S
