3rd Party Access to My Online file (without breaching security protocols)

This thread is now closed to new comments.
Some of the links and information provided in this thread may no longer be available or relevant.
If you have a question please start a new post.
The_Doc
Ultimate Partner
1,537 Posts
Ultimate Partner
Australia
Ultimate Partner

1,537Posts

165Kudos

162Solutions

3rd Party Access to My Online file (without breaching security protocols)

Hi Folks

 

Need some guidance in this aspect of allowing a 3rd party access to our business online file.

We have decided to go with a 3rd party wage roster/timesheet app that needs access to our online file.

We are expediting the start up to 7 Jul 22 so things need to get going.

 

A integrator manager was appointed and he rang me and we were discussing 'access to our online file'and this guy said

Oh you just give us access to your Administrator Account and password - we logon and select your file from the list and that is it!!!!!!!!!!

 

My words were not very kind but similar to "Not B!@$@#%#$^%$&^%& likely mate" !!!! - I think a bit kinder.

 

I have access to 20 -30 of my client files as an administrator and they come up in my portal - but there is no way anyone gets near that account.

 

If I send an invite to them as a user - setup a new user - and create a new payroll role in the "User Access" and locked down all but whatever they need - will that enable them to gain access they required.

 

I can give them the file URI and the user name and password I have created (as an invite uses an email and is a direct link created within MYOB to the file uri).

 

I am not sure whether these people can use a uri, username and password as the credentials or they need to be let in as an administrator - which lists my file in their myob portal for them to select and to logon to - that is simply a no no for me!

 

Some direction would be most helpful thanks.

 

The Doc 

 

3 REPLIES 3
ChrisMYOB
1,545 Posts
Former Staff
Former Staff

1,545Posts

0Kudos

173Solutions

Re: 3rd Party Access to My Online file (without breaching security protocols)

Hello @The_Doc 

 

From a software point of view, setting them up as a user with a role and the permissions that they need should work just as well as adding them as an administrator.

 

However, I can't confirm how this 3rd party software operates, so while I can agree with you that setting up their own role restricting them to what they need to operate should work, I can't specifically confirm if this will work.

Kind regards,
Chris

MYOB Community Support

Online Help| Forum Search| my.MYOB| Download Page

The_Doc
Ultimate Partner
1,537 Posts
Ultimate Partner
Australia
Ultimate Partner

1,537Posts

165Kudos

162Solutions

Re: 3rd Party Access to My Online file (without breaching security protocols)

Hi @ChrisMYOB 

 

Thanks Chris - it worked the way I thought it would/should and as you have alluded to.

 

However I will write this post for others as there is an inherent security breach problem here if this process is not fully understood by allowing generic 3rd party connection through the API to your file.

 

We are implementing a 3rd party Wage system and though I have no criticism of their process of implementation - it has been very good - but the person tasked to do the "integration" of their internet based software to our MYOB file, very polite and very professional - but they had 'ABSOLUTELY NO IDEA WHAT THEY WERE TALKING ABOUT WITH REGARD TO SECURITY, CONNECTION' and actually understanding what they were asking me to let them do!!!!!!!!!!

 

That is the problem - the person (neutral gender - very 'woke am I') said 

         "To connect to your file we 'JUST NEED YOUR ADMINISTRATION LOGON' !!!!!  (I didn't say this but I thought it (wow - nope you don't mate))

 

My reply - "hmm - let me review your request - I am loathe to give you the keys to the crown jewels as I think this is unnecessary just to look at them!"

 

I was right and 'the person' in retrospect admitted he went and talked with his software guys and they agreed the 'admin'  logon is unnecessary.

 

And when we did the connection process he 'screenconnected' to my server and I showed him the permissions area of MYOB and how to tighten down Roles and limit access.

 

Get this - HE HAD NEVER SEEN THIS BEFORE AND DIDN'T KNOW IT EXISTED - oops !!!!

 

Be careful about just handing out the keys to your crown jewels.

 

How did I tighten down their access so they can only get the information I want them to have.

 

1.  Setup a new email account just for this permission - lets just say your email account is @bigtractors.com.au  and you are using this 3rd party wage system called 'WagesOnTheNet'   create a new email account called

wagesonthenet@bigtractors.com.au  and have this email account directed to your main email account.

 

2. Setup a new user in MYOB called 'wagesonthenet@bigtractors.com.au' but do not make them administrator - this is for payroll - so just tick payroll 'ROLE'for the moment and tick the box this user will sign on with my.myob account

3. The invite will come to you as the new email is a redirect to your main account.

4. Accept the invite - setup and create a password for the account and select 2FA to your email - and register the account 2FA to your 2FA on your phone - this account now belongs to you and cannot be hijacked.

5. In MYOB go into ROLES - right click the ROLE 'PAYROLL' - and select 'Create a copy of the role' - and a new role is created called 'copy of payroll' - rename it to 'Payroll - WagesOnTheNET' and assign this to the new user deselect the generic payroll role.

6. Go into the new ROLE and severely lock it down to allow 'only the information you want them to have' - which this permissions tick box now gives you control over without changing the generic payroll ROLE

7. Connection day - you actually don't need the 2FA as the permission token is got via the http API call - but when they connect - YOU DO THE LOGON DETAILS - type in as the user 'wagesonthenet@bigtractors.com.au

password - [DO NOT HAND THIS OUT] - type it in yourself as it cannot be seen unless someone can see your keyboard.

The 3rd party is now connected to your online file fully under your control and with only the permissions of access you want them to have.  You cannot terminate this at anytime by deactivating this user.

 

That is it - secure but controlled 3rd party connection to view (only) your crown jewels.

 

The software wage company integrator person had absolutely no idea of this degree of control was possible!!!

 

Know your security.

 

The Doc

 

 

 

 

 

 

 

 

The_Doc
Ultimate Partner
1,537 Posts
Ultimate Partner
Australia
Ultimate Partner

1,537Posts

165Kudos

162Solutions

Re: 3rd Party Access to My Online file (without breaching security protocols)

Hi @ChrisMYOB 

 

Correction my statement - fully under your control and with only the permissions of access you want them to have.  You cannot terminate this at anytime by deactivating this user.

 

Should read 

 

"You 'can' terminate this connection to 'your' file at anytime by deactivating this user in MYOB."

 

The Doc

Didn't find your answer here?

Try using advanced search to find a post more easily Advanced Search
or
Get the conversation started and make a new post Start a Post