Jump to content

Do you use MFA in your school  

36 members have voted

  1. 1. Do you use MFA in your school

    • No
      6
    • Yes - Office 365 Admins
      17
    • Yes - Senior Leadership Teams
      3
    • Yes - All Staff
      9
    • Yes - Staff and Pupils
      1


Recommended Posts

Posted

Hi all,

 

Looking for some advice regarding Office 365 MFA, we as a school are looking to implement MFA to all staff (currently only Office 365 administrator accounts have MFA).

The question of enabling students to use MFA has also been raised as has the concerns in doing this.

We are a primary and secondary school, students from Y5 to Y11 have email accounts.

 

Do you have MFA enabled for all staff? Do you have Conditional Access polices for logging in within you school?

Do you have MFA enabled for students? if so what years?

 

Also added a poll if you do not want to reply in a post.

 

Many thanks!

Posted
MFA turned on for all staff but only outside of school. Can't see a real need to do the same for student accounts *yet* but times change, however how that'd be an expensive addition.
Assuming that's O365 MFA and Azure AD Premium you should get 15 student licenses free for every licensed FTE member of staff.
Posted
No, not the licensing side of it; that'd actually cost nothing on top of our existing subscription. I meant to say having to buy them tokens/tags or relying on mobile phones, although they're banned in school but we wouldn't use MFA in school anyway. So really it's just down to not seeing a real need for it.
Posted
I think it's coming for students. The issue is them using their own phones. Fine at FE/HE level but secondary and primary could be more of an issue. Or you just say no external access unless you have MFA enabled.
Posted

I rolled out MFA here last year.

 

I went for the SMS option primarily, as I figured that getting everyone on that level at least is a good level of protection for a school, without the hassle of getting everyone to install applications on their phones, which they may find challenging or simply go "I'm not using my personal phone for this" - Tho I let them do that if they wanted. It also meant that even those without smart phones would be fine & as smart token for Azure MFA didn't exist at the time, worst case I'd buy them a cheap £10 pay and go phone via the school and give them that

 

I disabled the push notification option because I thought it was utterly stupid in it's current setup, as it simply comes up saying "Are you authenticating yes/no" with no other real info - I figured most staff would just press "Yes" on their phones either from thinking it was their mobile apps trying to authenticate or because they just wanted the error box to go away. When MS improve this I may reconsider.

 

In terms of rolling it out, I set it so that they'd never get MFA challenged inside of school (I have Azure AD Premium 1 & use conditional access) & I also sent staff instructions on how to pre-register their numbers in advance of switchon. We kept an eye on this via powershell & basically jumped staff every time we could to get them to register.

 

I honestly was expecting massive push back from it but 99% of staff just went "oh like my bank" and did it. Not a single one protested or complained about it.

 

I've now put everything through Azure AD as our primary auth method and chucked out ADFS.

 

 

I haven't done students because I figured there's miminal risks from a GDPR standpoint if someone compromises their accounts (They have no access to confidental stuff) & because we do auth all through Azure AD it flags up suspicious signins anyway (new locations etc) - So we just force password changes on them and get on with our day - There's also the fallout that might result from us asking for student mobile numbers that right now I didn't want to get into.

Posted
We are in the process of rolling out for all, staff were already onboarded, but have extended to include on-site. We're an iPad 1:1, so MS Authenticator for us. The risk is, if you have a compromised workstation, weaker student accounts can be used to glean information about who to target for phishing attempts, and an innocent looking email to a member of staff from a student containing a phishing link is enough to gain access to your MIS.
Posted

Only enabled for admins at the moment. I want to roll it out to staff but we don't have the correct licence to allow for the Trusted IPs option, as I don't want people being asked for MFA while on site.

 

If I can make a big enough case for it (or if we needed it for something else as well) I'd spend the money on the licences and enable for all staff.

Posted
At least Azure AD Premium 1 - It cost me around £700ish to license all our staff (109 or so) - I've heard since that there's a license you can apply for that means students get it for free when you license your FTE - I've not done much digging into that yet tho
Posted
Standard Office 365 MFA is free but you can't set up Trusted IPs (where you define an IP range and MFA is disabled for requests coming from that range) so without paying extra your choices are MFA all the time even when sat in school, or not at all.
Posted

You can exclude MFA on Azure AD joined devices. Do you trust every device behind your public IP? It's worth the investment as it gives you insight into where logins are coming from. Has anyone started to implement this for students yet?

 

Is it worth moving this to the security forum?

Posted

Thanks for all the info so far and for everyone who has voted in the poll.

Currently we have the free Office 365 (A1) but I do think the MFA experience would be better if we could add Trusted IP addresses.

Posted

I honestly was expecting massive push back from it but 99% of staff just went "oh like my bank" and did it. Not a single one protested or complained about it.

 

How did you pull that one off? I didn't get through the first department before they kicked off and gave us the 'I'm not using my personal device or giving my number' excuse. These are the same numpties that would later go on to give their login details to a phishing scam >_<

Posted
As we don’t use O365 much yet, I decided to enable it for all accounts now. G Suite is linked to it, so I wanted the extra protection. I can cope without the IP exceptions, but only because our email is still on-site.
Posted

Thanks again for all the replies.

Going to roll MFA out to a select group to make sure all is working fine before looking at all staff.

  • 2 months later...
Posted

We've rolled out MFA to be required when not onsite. Some people prefer the app, some text.

 

However, we are down to our last member of staff to be authenticated. It is becoming quite difficult as he has an old windows 7 laptop at home, but has never owned a mobile phone/tablet and does not plan on doing so.

 

What would people recommend?

 

Thanks.

Posted
Can you upgrade the member of staff? He sounds quite obsolete and he's probably not in warranty any more. In seriousness, I think you need to be a bit reactive with it - if he has no easy way of using MFA, you'll have to leave it off but perhaps encourage him to look into a phone (or even provide a basic one - not ideal I know!)
Posted

My plan in that case was to buy a cheap mobile phone (like £15) and force them to use that, else thankfully I had management backing up just tell them they've lost the ability to work remotely.

I think you can opt in hardware token support now on 365 too so you can buy those keys.

Posted

They can also use a landline phone or an alternative email address.

If they don't have a mobile phone, computer or land line phone then they can't work remotely anyway - as well as being an incredible Luddite.

Posted

As the staff member goes away, he wont have access to a landline.

 

I did not think that you could use an alternative email address for office 365's MFA.

 

I'll have to look into it.

 

Thank you.

Posted
I have tested some OATH tokens and yes they work, but the setup is more involved (activating each token) so I would not want to roll this out for every user.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...