Hi all,
When our Smoothwall was first installed in the school (Feb 2014), we set up the following group structure within our AD:
AD Security Group "Pupils" - contained an explicit list of all student accounts in the school
AD Security Group "students2013" - contained an explicit list of all student accounts for intake for that specific year
AD Security group "Year 7" - contained just the AD Security Group "students2013" (i.e. "nested")
AD Security Group "Key Stage 3" - contained the AD Security Groups "Year 7", "Year 8" and "Year 9" (i.e. "double-nested")
(and same for all Year Groups and the 3 Key Stages)
So, to clarify, the Key Stage groups contained no explicit student accounts - just nested groups. Easy to manage - each year we just needed to update the membership of the "Year x" group to align with the relevant "studentsxxxx" group, and all other groups would update accordingly. And excellent granularity for use in Firewall rules....
In Smoothwall, we mapped, within our AD integration:
AD Security Group "Year 7" to Smoothwall Local Group "Year 7"
AD Security Group "Key Stage 3" to Smoothwall Local Group "Key Stage 3"
AD Security Group "Pupils" to Smoothwall Local Group "All Students"
We then created Firewall/Guardian Rules based on the above hierarchy - so that, for example, we could add an explicit permit to the rule for "Key Stage 5", which would give access to a specific Website to 6th Form Students, but not the rest of the school student population. Or we could grant temporary access to a Website (perhaps a gaming site for one lesson) for just Year 8, etc.
But the above is no longer working. All Students are only being categorised by Smoothwall only as a member of the group "Pupils" (which is, of course, the only group that has a full, explicit list of student accounts - no nested groups).
So, can I throw this out there - is there anyone else using nested groups within AD, and mapping said groups to Smoothwall Local Groups...?
I would really welcome any positive confirmation that someone else has, or more importantly is, using nested groups successfully in this manner....
I realise that a lot of school implementations may more simply have a couple of groups, such as "All Staff" and "All Students" (or indeed have granular groups, but perhaps with explicit lists of student accounts in them - with a potentially higher management overhead?) - but the simplicity of group management, and the granularity that this approach provides to us is really useful in demonstrating, for example, the use of technology in safeguarding - it's not always appropriate to permit Year 7's to have access to Websites that Year 13's need to get to.
Of course - if anyone *not* using nested groups would like to consider the above hierarchy and do any tests between their Smoothwall and their AD, that would be great...
Thanks,