I'm skeptical of the suggestion that the school admins were able to do this with no input, but I'm absolutely willing to entertain the idea that:
a) AD login is a complete mess, and
b) the UI is utterly misleading and near-unusable.
I'm skeptical of the suggestion that the school admins were able to do this with no input, but I'm absolutely willing to entertain the idea that:
a) AD login is a complete mess, and
b) the UI is utterly misleading and near-unusable.
IMO, The main issue in here is BigTech obsession with a single login. One single credentials give you access to everything, from entertainment to professional services.
People do share their credentials with family, specially if involves subscription and payment. BigTech try so hard to push for not sharing, but they fail to understand (or don’t care) that most people, specially non American, don’t have the budget to subscribe multiple time. Family accounts are non existent, lacking management options, and also more expensive.
The UI of this is just as bad as the one that asks you to sign into MS account and upload all files to OneDrive when setting up Windows. It even comes back after some time if you deny it!
AD login is something that used to work well (10-20 years ago) but is now a complete clusterf*k. What was designed for logging into Windows NT workstations isn't what most users nowadays are expecting when logging onto web apps. Plus the UI full of antipatterns. Yet it's still the easiest for IT folks to manage.
This is pretty much just best practice. When's the last time you could change your password without entering the original, short of a re-verification via email? Same idea here.
which, if the persons password is saved in their browser, would pass through to the website, granting a re-auth.
I got you now. I've been using 3rd party password managers (with a timeout for a forced reauth) long enough that I forgot when you let the browser do it it's not nearly so locked down.