DrCheese Posted March 20, 2018 Posted March 20, 2018 Hi there, Has anyone looked at using Two factor authentication for Office365? I know we can turn it on for Global Admins for free, but ideally I'd want to have it on all staff users & then tie it into our remote access system. We had a staff member run through a phishing email last year and I'm really keen on doing what I can to tighten security, especially with the GDPR on it's way! 1
abaxter2 Posted March 20, 2018 Posted March 20, 2018 We do it here and needed azure ad premium 1, works a treat as can white list the school site so MFA is only required off site, you pay per user and we added to our OVS. https://docs.microsoft.com/en-us/azure/multi-factor-authentication/multi-factor-authentication-versions-plans
Geoff Posted March 21, 2018 Posted March 21, 2018 I'm commercial so the licensing works slightly differently (our E5 licenses get MFA included, our E3 licenses have to have the extra 'Enterprise Mobility + Security E3' bolt on) so I am no help for that. We have it setup like @abaxter2 says. Internally normal users don't get MFA. Admins always get MFA. Externally or on untrusted BYOD stuff normal users do get MFA. We use SMS and we also have RSA keyfobs deployed for some users. Note we're purely doing this for O365. MFA wont help stop your users doing the stupid. You need to train them.
MYK-IT Posted March 21, 2018 Posted March 21, 2018 We have Office365, and are currently testing / trailing MFA too. If you just want to protect Office365 applications, you can enable MFA for all users (not just Global Domain Admins) with the basic / free version. Although I've noted that you want to associate / work with on-site services too, so that will need Azure AD Premium as @abaxter2 mentioned.
DrCheese Posted March 27, 2018 Author Posted March 27, 2018 Thanks for the responses - I signed for a trial of the premium version & managed to get 2fa working for my test user. It's a bit long winded but it seems to do the job. I'm assuming that you guys are using the AD App Proxy if you want internal apps protected with 2fa?
Domino Posted March 27, 2018 Posted March 27, 2018 If your internal apps supports radius, this method is a lot easier: The Microsoft Platform: Securing RD Gateway with MFA using the new NPS Extension for Azure MFA!
AlexB Posted March 27, 2018 Posted March 27, 2018 Do you have the Azure/MS authenticator installed? I found it created massive wakelocks on my Android
gshaw Posted March 27, 2018 Posted March 27, 2018 Thanks for the responses - I signed for a trial of the premium version & managed to get 2fa working for my test user. It's a bit long winded but it seems to do the job. I'm assuming that you guys are using the AD App Proxy if you want internal apps protected with 2fa? For all you playing with Azure AD Premium... have you seen how much it is?! MS force you to pay per per user and not per FTE as you'd be used to on any other EES license. Blew it out the water for us, real shame as I wanted the password self-service reset functionality amongst others.
jmak Posted March 27, 2018 Posted March 27, 2018 For all you playing with Azure AD Premium... have you seen how much it is?! MS force you to pay per per user and not per FTE as you'd be used to on any other EES license. Blew it out the water for us, real shame as I wanted the password self-service reset functionality amongst others.I've had a quote for Azure AD P1 which seemed reasonable and have been told I can either add it to my OVS agreement and cover staff and pupils based on FTE , (in which case I'll lose 4 months and have to pay twice in one financial year) or subscribe separately now for 12 months but only cover staff. Price is the same in either case. Don't know about P2 though.
Bobby_Moore Posted March 28, 2018 Posted March 28, 2018 Has anyone experienced any issues upgrading their O365 tenant from oAuth 1 to oAuth 2 (required for 2FA)?
PyROm Posted April 12, 2018 Posted April 12, 2018 If it helps, ive just got a quote through for azure premium p1 and you just pay for fte, then you get student licenses free. The student licenses on our quote are listed as "GN9-00012 Microsoft®AzureActiveDirectoryPremP1Open ShrdSvr AllLng MonthlySubscriptions-VolumeLicense Academic OLV 1License NoLevel Student STUUseBenefit 1Month" 2
DrCheese Posted July 2, 2018 Author Posted July 2, 2018 (edited) ok, I've got approval to start pushing this out to staff - I'm thinking of generally pointing staff to the SMS option, as it's the easist option for them. People can generate codes in the app if they prefer (I've not enabled notification push as most people will just click "accept") I'm undecided tho Those of you that rolled it out, did you do the same/or did you push the app? Edited July 2, 2018 by DrCheese
peej2k Posted July 4, 2018 Posted July 4, 2018 ok, I've got approval to start pushing this out to staff - I'm thinking of generally pointing staff to the SMS option Are these personal phones they will be using. How are you getting around the safeguarding implications of having their mobile devices in the classroom?
DrCheese Posted July 4, 2018 Author Posted July 4, 2018 Are these personal phones they will be using. How are you getting around the safeguarding implications of having their mobile devices in the classroom? Outside of school only - You can exclude MFA from being required on internal devices.
Dave_G Posted July 4, 2018 Posted July 4, 2018 ok, I've got approval to start pushing this out to staff - I'm thinking of generally pointing staff to the SMS option, as it's the easist option for them. People can generate codes in the app if they prefer (I've not enabled notification push as most people will just click "accept") I'm undecided tho Those of you that rolled it out, did you do the same/or did you push the app? We're only testing MFA at the moment, but we're going for the Verification code from mobile app or hardware token option. The reason being is that you need to unlock your device to read the verification code in order to enter it. With the other two methods it's possbile to either 'Accept' the push notification, or preview the SMS message containing the verification code, without the need to unlock the device (depending on the devices notification settings).
JeffBirks Posted June 14, 2019 Posted June 14, 2019 If you are intending on using Oath Tokens to authenticate either Azure or Office 365 you might want to take a look at the following link that provides information on the SafeID hardware token from Deepnet Security; Deepnet Security Hardware MFA tokens for Office 365 and Azure Multi-Factor Authentication
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now