Skip to main content

Curious… do any of you allow Parent to login to iiQ?

Are you aware of this security concern?  A Parent can see you entire Asset inventory. 😳

 

@jo.cpa While this has been submitted to our developers for review, it would be a workaround to direct parents to the quick ticket menu instead of the “My Assets” tab. 

You can set up a Quick Ticket for a generic student device (either model or model category), then set up your issue categories and issues. Additionally, you would need to add a custom field requiring them to enter their child’s asset tag. 

AD_4nXe6G-PdP2PTxIEXyZnrxxf4nFAKvwmeTi63gU3uPNNzgqFPAQZ776cns79NEdeKYUnP7YAo5zdrkSfKajm9rpXRvlTz4e-Q2iqiROvqdyDYOk0VXRXk34hvpVJm9gWBGtftxIa-KWtxyEVYqyYT1Psafq5q?key=1hliOgPswvGq-EhcJhigFg

The parents can then easily submit a ticket with the asset tag. The agent working on the ticket will copy and paste the asset tag to update the ticket with the proper asset. 😄


Isn’t this supposed to be a basic feature of a school - Parent/Student help desk? 😕

Does it concern Incident IQ that the entire list of Assets can be viewed by a Parent that has logged in? 😬

It concerns us and our Cyber Insurance provider, with which we are in the middle of a security audit.  It has been noted.

The suggestion of the workaround is appreciated, but Incident IQ seems to be full of workarounds.
KB articles (can’t control access) - Parents entering/viewing tickets for their own students - external emails cannot be added - no variables in emails (that are useful)

Sorry to be such a downer, but I’m unhappy with the level of response on issues, feature requests, and product deficiencies.


Hello?  Any other users notice this issue?  If you allow Parents to login?  Are they able to see all of the other Assets (when searching)?


Good morning!

Over the weekend, we released a patch to ensure that only users with the appropriate permissions can favorite assets. This update should allow parents to use the IIQ platform without favoriting assets and therefore without accessing asset metadata.

Please let us know if you continue to experience any issues with this solution.


Reply