<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Staff Accounts and Password Syncs and Prompts to Change - Seeking Feedback in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65873#M2830</link>
    <description>&lt;P&gt;We have a very similar setup and over the years have migrated to this process for new staff;-&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Accounts are set up in AD &amp;amp; Synced to Google.&lt;/LI&gt;&lt;LI&gt;We assign a password that is secure and, due to complexity, they will want to change as soon as possible. We do have a web portal (to the AD) that allows users to change their password online. However, we found this caused issues when they arrived in school, they had forgotten their changed password which complicated then logging onto the Windows PCs. By issuing a password, we have a record of this and can get them to change easily. All new staff do this in a dedicated IT session when they arrive.&lt;/LI&gt;&lt;LI&gt;After sending them their emails and passwords, we get them to read some IT related info and confirm that they have read this using a Google Form. We then know that they have access to our Google Workspace.&lt;/LI&gt;&lt;LI&gt;As above, one of the first meetings they have in the school is where we issue devices and get them to change their passwords.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jun 2024 23:29:43 GMT</pubDate>
    <dc:creator>James_Seymour</dc:creator>
    <dc:date>2024-06-03T23:29:43Z</dc:date>
    <item>
      <title>New Staff Accounts and Password Syncs and Prompts to Change - Seeking Feedback</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65613#M2824</link>
      <description>&lt;P&gt;Hello. For many years our process has been to create new staff accounts in AD, sync them via GADS/GCDS to Google and then have the staff sign in for their first time on a Windows network PC on-premise, where they would be prompted to change their password on first login, and that password would be synced to Google via GAPS. This process works well without issue.&lt;/P&gt;&lt;P&gt;However, leadership now wants new staff to get access to their email and other Google resources once they are hired but before they will be onsite (as early as a month before they will first visit onsite). As is now, I don't think GADS/GCDS sets the new Google account to prompt for password change on first login, since we are handling that with the AD account. So, if new staff login remotely for the first time they will not be prompted to change their default password. If I change that setting, I would still want to keep that setting enabled on the AD account as well because not all staff will sign in remotely the first time, and I want them to be prompted when signing in on the domain the first time so the passwords are synced with GAPS. In this situation, they would be prompted when signing in remotely via Google the first time and then they would be prompted again when signing in to AD on-premise the first time. This doesn't seem ideal but it's the best situation I can come up with since we want to offer what they are requesting and since we want to keep passwords synced via GAPS.&lt;/P&gt;&lt;P&gt;I'm looking for feedback from anyone who is in a similar situation (I feel this must be a fairly common situation). Any other suggestions? Any better way to handle a similar process?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 16:01:59 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65613#M2824</guid>
      <dc:creator>mcbride</dc:creator>
      <dc:date>2024-06-03T16:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: New Staff Accounts and Password Syncs and Prompts to Change - Seeking Feedback</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65873#M2830</link>
      <description>&lt;P&gt;We have a very similar setup and over the years have migrated to this process for new staff;-&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Accounts are set up in AD &amp;amp; Synced to Google.&lt;/LI&gt;&lt;LI&gt;We assign a password that is secure and, due to complexity, they will want to change as soon as possible. We do have a web portal (to the AD) that allows users to change their password online. However, we found this caused issues when they arrived in school, they had forgotten their changed password which complicated then logging onto the Windows PCs. By issuing a password, we have a record of this and can get them to change easily. All new staff do this in a dedicated IT session when they arrive.&lt;/LI&gt;&lt;LI&gt;After sending them their emails and passwords, we get them to read some IT related info and confirm that they have read this using a Google Form. We then know that they have access to our Google Workspace.&lt;/LI&gt;&lt;LI&gt;As above, one of the first meetings they have in the school is where we issue devices and get them to change their passwords.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 23:29:43 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65873#M2830</guid>
      <dc:creator>James_Seymour</dc:creator>
      <dc:date>2024-06-03T23:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: New Staff Accounts and Password Syncs and Prompts to Change - Seeking Feedback</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65968#M2836</link>
      <description>&lt;P&gt;Just taking a step back to state the obvious.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Nobody should have access to any accounts before their first day of work&lt;/EM&gt;&lt;/STRONG&gt;&lt;STRONG&gt;.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First day of employment is first day with access. Never before, nor after.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Now, if your leadership hires &lt;EM&gt;and starts paying salary for&amp;nbsp;&lt;/EM&gt;staff to work earlier than&amp;nbsp;the first day they spend at location, ie let them work remotely for some time before first visit, then that's fine.&lt;/P&gt;&lt;P&gt;Then a solution like the one presented by&amp;nbsp;&lt;a href="https://www.googleforeducommunity.com/t5/user/viewprofilepage/user-id/195"&gt;@James_Seymour&lt;/a&gt;&amp;nbsp;can be used, an online portal for password management of the AD password. There are plenty to choose from, some free, others not, some easy to use and simple to set up, and some not. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Alternatively&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Some organisations can also just ignore that the AD and Google passwords are temporarily different, if they allow Google passwords to be changed in &lt;A title="Change your password in My Account" href="https://myaccount.google.com/signinoptions/password" target="_blank" rel="noopener"&gt;My Account&lt;/A&gt; (most who sync passwords from AD actually allow it!).&lt;/P&gt;&lt;P&gt;Then the user will/can just fix it when they come to location for the first time. Either with the help from IT or by using the same password portal as last time. Some even offer third-party user authentication, like e-id, so they don't even have to remember their old initial password.&lt;/P&gt;&lt;P&gt;This, of course, depends on whether their AD account is used as credentials to log into day-to-day systems, which they need to access before first visit. Then they need to keep using their AD account.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 15:01:23 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65968#M2836</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2024-06-04T15:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: New Staff Accounts and Password Syncs and Prompts to Change - Seeking Feedback</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65969#M2837</link>
      <description>&lt;P&gt;The first thing I did was have our legal counsel confirm. The proposed change is to provide them their credentials once they contract has been ratified, instead of on their first day of work as it previously was. In the summer this can be 1-2 months earlier than previously before.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The biggest questions I have stem around the setting in GADS to force password change for new accounts. I currently have that disabled because we have the setting enabled in AD and our process was for staff to sign into AD first and we didn't want the passwords between AD and Google getting out of sync, which causes confusing because of all of our SSO applications.&lt;/P&gt;&lt;P&gt;I want to know more about these web-based AD password change options for the end user, can someone please recommend some that are highly recommended and have support to get setup? This may be our best option. Otherwise, I was considering putting all new staff in a separate OU in both AD and Google, setting that OU in Google to force a password change, so they can sign in remotely and get forced to change. Then the week before school starts moving their AD accounts to the correct school OUs, running a GADS sync to move them to Google, etc. Not the cleanest, but could work.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 15:09:35 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/65969#M2837</guid>
      <dc:creator>mcbride</dc:creator>
      <dc:date>2024-06-04T15:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: New Staff Accounts and Password Syncs and Prompts to Change - Seeking Feedback</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/66014#M2841</link>
      <description>&lt;P&gt;We are using Microsoft's RDWeb service (part of the remote desktop), which I am sure is free and relatively easy to set up. We were forced during Covid when physical access to school computers was impossible&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 00:07:28 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/New-Staff-Accounts-and-Password-Syncs-and-Prompts-to-Change/m-p/66014#M2841</guid>
      <dc:creator>James_Seymour</dc:creator>
      <dc:date>2024-06-05T00:07:28Z</dc:date>
    </item>
  </channel>
</rss>

