Jump to content

Recommended Posts

Posted

We're an LGfL school and, at the moment we don't host our own Exchange, but we're looking to migrate to G Suite anyway.

 

This gives us the option of a fresh slate, and the opportunity to get rid of a buttload of old emails with, no doubt, a ton of sensitive data on. However, SLT want to retain their archives. That's fine.

 

But most of them have got email accessible on their own devices (phones and home laptops). LGfL fairly widely publish the method for doing so. I presume it's the member of staff's responsibility to keep their passcodes/passwords secure, but I'd like to at least offer them a more secure "recommended" method so as not to annoy the hell out of them.

 

How have other schools handled this?

 

Does anyone know a simple method of making email on mobiles have two-factor authenticacation?

Posted

On gmail/gsuite I think you can only enforce 2fa on OUs, rather than if they access emails by xyz method.

 

The other thing with having 2fa Auth on mobiles with work email is unless you're going to buy separate tags the 2fa device is probably going to be that mobile.

 

I'm looking to come up with a guide that shows how to add email app to a protected folder that needs a fingerprint or secondary pattern to access.

 

You can set a basic MDM for your domain accounts. So when a user signs in to the drive, docs etc app it requires them to download the device policy app (at least this is what happens on Android). In the Google admin you can enforce them having a basic, standard or strong screenlock

Posted
G Suite now allow you to choose basic which means no device policy download is needed onto their device but it still forces them to have a passcode or pin on their mobile device.
Posted
We're Office 365 but all the "getting ready for GDPR" stuff we've been given by our trust implies that they just have to have the phone passworded/coded (but the finger swipe thing doesn't count as you can just follow the greasy pattern on the screen of the nicked phone). Not sure if this can be forced in 365, no idea about Google but ours is just in the policy that staff have to sign, appears to be okay as a bare minimum effort.
Posted
G Suite now allow you to choose basic which means no device policy download is needed onto their device but it still forces them to have a passcode or pin on their mobile device.

I forgot the basic didn't need the device policy app. I'm just the guinea pig that gives himself the advanced MDM.

 

And forgot to say it's down to setting a policy staff should follow too. That should cover the school.

Posted

You don’t have to take technical measures ... you can have organisational measures instead.

Ensure you policies stare the need for complex passcodes (alphanumeric) rather than 4 or 6 digit / pattern swipes. You can make a decision on fingerprint or facial recognition for access (I had agreed to it previously when implementing ISO27001) ...

but it is really just down to your school and what level of risk the school is willing to accept.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...