ContributionsMost RecentMost LikesSolutionsRe: Payroll security - not quite secure HiCelia_B As perFreman( thanks for yourr candid reply) reply - you have not answered my question. I am quite aware of roles, new or existing - you perhaps are not - perhaps you could read my question then provide an answer - and in providing an answer appropriate to the question you will perhaps realise that there is a hole in your roles security. The Doc ( he) Payroll security - not quite secure Hi Folks Locking MYOB components to various users - especially payroll. Staff seem to find a way to find out what other peers are paid with the potential to start spark disharmony. Typically, MYOB users in a company, are of mixed seniority with the pay officer generally an administrator and users on their staff with MYOB access being locked out of MYOB payroll. This happens in my company - staff cannot see payroll or any component. However, a hole in the payroll armour came to light from a client asking me about allowing a new member higher access but NOT payroll. The **bleep** - was if you lock a user out of payroll, totally - but allow them ability to prepare electronic payments in purchase access - then by default - that component in payroll gets ticked. This, then allows a user with this access to see queued electronic payments - single or multiple and to see the total paid to each staff member ( however, they cannot open the payslip - just see the total paid. If the have access to the bank account - which is inherent in the electronic payment permission they can see electronic payments (pays) to find out a staff members net pay. I have just checked whether they can see emails with payslip - no they can't. Am I missing something or is this a **bleep** in the permissions for payroll - if so a big one. The Doc Re: MYOB logon no longer requires 2FA Hi All I answer, now, my own post after MYOB have finally replied to my concerns in private replies. My concerns were that the changes MYOB have made to the security of logging on to online files has changed - and these changes has actually DECREASED THE SECURITY of this process. This forum echoed with the cries of users screams - "WHAT HAVE YOU DONE MYOB - the security is decreased" - and no real answers came forth from MYOB explaining the changes. In essence - the changes that we all noticed 1. 2FA authentication requirement disappeared - and we were only required to enter our user name and password 2. that the username (typically the user's email) was no longer stored and remembered and had to be entered everytime ( this in itself I have no problem with and is actually an increase in security protocol - and does add a small level of secuirty) However, the biggee was that 2FA disappeared. MYOB never actually explained the changes ( to my knowledge) and let us comment - the users. As it turns out - in my private email from MYOB - which was polite, respectful and answered my queries quickly - finally) That the 2FA authentication does appear - however, only when you goto the 'SERVICES' tab and select 'Sign out from AccountRight Live' !!!! - and this appears to be correct! - end of STORY NO!!!!!! My reply - which MYOB acknowledged was correct - was that MYOB's improved security actually was a deprecation of secuity and LEFT our online files open to access with only a user name and password - i.e. the 2FA requirement had by default been cancelled/removed - or negated! Why....... Typically, and for years if your MYOB online file was left open, or you closed it by just clicking the cross top right or you selected in the tab FILE - EXIT ( which I do, as do all my staff) - then accessing the same MYOB file within 12 hours ( if you ticked the 12 hr click box to not ask for credentials - BUT NOT THE 30D - we just don't use that - and forbid staff to do) - then within the day you could click back onto the file and open without 2FA/username/password. If these parameters expired - which they did within 24 hours - next time you logged on you entered your password ( because your email was pre-entered) and you were asked for your 2FA - this secuirty was good, adequate and appropriate. Suddenly it all changed - carryout these procedures AFTER MYOB updated their security - and BY DEFAULT - using EXIT/ click the X or time out - and by DEFAULT MYOB on line allows you back into any file, any client's file - with just the username and password In my realm - a deprecation of secuirty procedures - a decrease of secuirty and yet we do not get told of this. EXCEPT when everyone screams we just get told "YOU NEED TO NOW!!!!!! - SELECT LOG OUT OF ONLINE SERVICES" - !!!!! OK then MYOB - if weese dumb users continue to select "EXIT"; or "X" or just leave it open to time out - PUT A DEFAULT reset in there that automatically logs us out of ONLINE SERVICES!!!!! MYOB this really is a stuff up and a deprecation of security which needs notification to the appropriate agency. Please FIX this and create a default that logs us out of on line services either in 24 hours - 7 days or 30D - if that user is using the same IP and the same computer. THE DOC MYOB logon no longer requires 2FA Hi Folks Whilst this subject has, it seems, been done to death and MYOB refuses to address it - BUT!!!! "why has 2FA logon into ANY of my online MYOB files" been deprecated/turned off Since the introduction of MYOB's new security to users it has been an unmitigated shambles. We run an online cloud service for medical practices ( 100s of them - 1000s of doctors) and had we introduced such shoddy logon procedures we would have been laughed at - and the screaming would have been heard this side of Timbuktu. Not only have we upped our logon but we have gone 3FA YET - since MYOB introduced their updated SECURITY - I and all my staff have never again been asked for a 2FA code. Myself - I have logged on from 3 different places in the country - odd and different IPs - a bnb in Brisbane - and I was only required to enter my password - no 2FA. Please MYOB - this needs to be reported as a deprecation of security - why do you fail to explain things. Where is the old 2FA procedure - minimum 2FA to secure your clients files!!!!!! Please, please provide answers to the basic of security questions. The Doc MYOB emailing payslips. Hi MYOB MYOB - this is a constant problem - not just for me but for many people on this list If I send payslips from MYOB via the MYOB emailing system it is hit and miss who gets them. We have a policy in the business that all payslips must go to private emails - never to staff business emails. We have 30 employees. It is consistently a problem that a proportion of those staff do not get their payslip and they simply see it as ( they didn't get their payslip). So MYOB why - Occassionally, rarely - they all go out - I wait a day and check the email bin to see who received them - then re-send those missed - sometimes I send payslips 3 to 4 times to members that have received them successfully, 1st time, before. THIS IS A MAJOR PROBLEM MYOB - your system is dropping the ball consistently - look at the list and see how often this comes up. Last pay - 1/2 the staff didn't get their payslip - I resnt them 2 to 3 times and still they haven't received them. Please MYOB - this is your problem - your server is not doing its job. Surely you can tell us if a 'send' is unsuccessful - vs 'sucessful' If I sendf these payslips manually via outlook 'THEY ALWAYS ARE RECIVED BY THE STAFF MEMBER' - sort of points to your problem MYOB. The Doc Re: Payslips do not go to ALL employees HiEarl_HD Thank you for that detailed reply. Interestingly - I had just done the pay run today and sent payslips. Waited 30 mins and looked at sent emails in MYOB. And today - for the 1st time - all pay slips have actually gone out. Notwithstanding the above advice - usually if I resend they get it - and they all come back to me telling me no it isn't in spam or other places. Regards Howard Re: Bad internet connections HiEarl_HD Whilst your post does cover some of the problems of an intermittent internet connection - the 2nd part of your POST doesn't cover what is pertains to cover - a sudden loss of internet. And that was whatParadiseTaveuniwas worried about - internet up/down ( unless they are scheduled and timetabled and I don't know any that this is known ahead of time) - internet can/will go down at anytime!!!!!!!! Anytime means if you are working on your online MYOB file and you lose internet - that is it - you are stuffed until the internet comes back up - MYOB doesn't cache ( to my knowledge) ( or does it? ) a copy of the MYOB locally - so that if you lose internet you can keep working - it use to it doesn't anymore. So if the internet is lost your current copy of your MYOB file is 'in the cloud' and you cannot do any work until the internet comes back on. The only way this would work successfully is to just run your file as a local file - if you don't want to do that because of extra features that the online file gives then you are always at the whim of the internet going down and up. There is no simple solution - work locally - it cannot be multi-user. To me the simplist solution if the internet is the problem is set up a remote computer on your Island and run MYOB as a local file in a Remote server - RDP into this - and if you have users on the mainland also using it - they remote into the server and use MYOB - if the internet goes down - they lose access - you don't - you can keep working. Internet comes back up - the remote user logs back in. The other way around means you - the master user lose access and work time - there is no solution that solves this problem. The Doc Re: Bad internet connections HiParadiseTaveuni Unfortunately you can't do what you want to do easily - no internet simply means - no file. MYOB had an earlier system where you could 'sort of do this' and when the internet came back on the system refreshed whichever was out of date - but I think Microsoft axed that ssytem. The problem is the controlling thing here is "no internet" not low speed. If you had low speed you could setup a RDP server on the main island and remote into it with a small bandwidth connection relying on the server to file connection doing the heavy lifting. There is only one way to handle this unless your clients are paying you through MYOB and MYOB needs to update your file with payments - which would defeat this solution? When the internet comes up - you download your file ( just use back it up and take it offline) - then you restore your file locally and run it locally - back it up and then when the internet comes back on line - restore to the cloud. This is messy - not really a solution but is the only way to enable you to continue to work with it whilst the internet is out. I am not sure why you went online because it, in itself, doesn't solve your problem - just complicates it. However, there may be other reasons why you needed to go online that aren't obvious but 'no internet for unknown periods' makes having your file online to be an incorrect solution. Are there alternative internet solutions - is the internet wireless broadband; cable; ADSL - are there low speed alternatives - or other solutions where you could set up the main island server and remote into it??? Is StarLink available there? I was running remote desktop ( terminal server) solutions on MYOB in the late 90s - long before MYOB admitted it could happen - RDP ( terminal Server) is the solution but you need the internet even if only modem dial up. The Doc The Doc Re: Can I Access MYOB Accountright while travelling overseas by login my Laptop using the Program? HiChuncun1 I would say to you - don't!!!!!!! - not the way you plan to do it. Undoubtedly, you will use the internet in China and that will not be without a great deal of risk just before you begin. Further, if I was your internet provider and your business IT provider I wouldn't allow you to do it - and further often many business lock their ability to logon from overseas. However, if you are still determined to do it organise a vpn as a minimum to tunnel through the internet to a local machine where you then can safely run MYOB to access your online file. Running payroll from China would be as risky as you could ever get. And to add a further level of security - use the vpn to tunnel to a RDP server on which you have a Server version of MYOB setup and hence no need to use your laptop do doing anything else but to logon to the server - which then safely runs MYOB. The Doc Re: Payslips do not go to ALL employees @ MYOB Sorry, I under exaggerated - just checked my emails out Off the 29 payslips emailed in 2 batches - ONLY 10 ( 10 out of 29) went out!!!!!!!!!!!!!! Yep that is a 66% fail rate - that MYOB is just not acceptable. Every pay fortnight this happens - No matter MYOB - we are moving to XERO anyway ( and after being a Partner for 25 years that is painful) We are a private cloud provider for medical practices - (we would be out of business with such a failure). The Doc