The safety and security of data within Compass is of the utmost importance. There are security measures in place to ensure that your user community is safeguarded against potential threats.
To access security settings, staff will require the 'Configure' permissions.
For details on how to assigne permissions in Compass, please refer to the 'Permissions' article from the Knowledge Base.
To access the 'Security Settings' page, go to the cog icon and select 'Administration Tools' from the menu.
Click the 'Security Settings' option to load the page.
Here you will see a range of settings for the following:
- Two Factor Authentication
- Session Configuration
- Access Settings
If you make any changes to settings, ensure that you click 'Save' at the bottom of the page for the changes to take effect.
For details on enabling two factor authentication, please refer to the 'Two Factor Authentication' article from the Knowledge Base.
In this section you can set the time in which a session will expire if the user does not perform any actions in Compass. The settings allow you to set different times for web and mobile sessions.
If you are concerned an account has been compromised you can force a logout to ensure all current sessions for the user, or user group, are logged out.
To do so for an entire user group, select the applicable role type.
Click 'Force Logout'.
To force logout for a single user, enter their username and then click 'Force Logout'.
When doing a forced logout, you will be prompted to confirm the action.
You will get a confirmation when the process has been completed.
If you need to temporarily disable all access to Compass accounts for students and/or parents, you can do so by ticking the applicable option and clicking 'Save'.
Each time a user logs in to Compass, they will receive an email alert to notify of that login. If they have not logged in on the date and time in the email, they should immediately take steps to secure their account.
For details on resetting user passwords, please refer to the 'Reset Passwords or Account Lockouts' article from the Knowledge Base.
When requesting to download large files (e.g. Attendance exports, Chronicle exports, Report results), the file will be emailed to the user’s email address, rather than downloading directly onto the computer of the user. This feature prevents the amount of data a user can access if an account was compromised. They are unable to access the data unless they have access to the user’s email.
When any of these requests are run, all users with CompassSponsors, CompassPrincipals and CompassBusinessManagers will also be notified to ensure school leadership can be alerted to any suspicious behavior in the portal should they not be aware already.
To avoid a person using a compromised account from simply changing their email address in the user’s account in the portal in order to receive the file, you can specify which domain/s are eligible to receive these files to avoid this action from being successful.
On the Security Settings page in the 'Data Export' section, enter any email domains (e.g. @education.vic.gov.au) that are eligible to receive the download files. Files will not go to any emails outside of that domain that request it.
When signing into Compass from a web browser, always look to see that the domain is structured as follows:
https://yourschool.compass.education/pages.aspx
Automated emails from the Compass platform will come from the compass@compass.email address.
Any email sent from a Compass employee will be from NAME@compass.education.
If you have received an email that you deem to be suspicious, please forward this to support@compass.education immediately for investigation.