msm1000 Posted February 27, 2019 Posted February 27, 2019 Hi all, Looking for some advice regarding Office 365 MFA, we as a school are looking to implement MFA to all staff (currently only Office 365 administrator accounts have MFA). The question of enabling students to use MFA has also been raised as has the concerns in doing this. We are a primary and secondary school, students from Y5 to Y11 have email accounts. Do you have MFA enabled for all staff? Do you have Conditional Access polices for logging in within you school? Do you have MFA enabled for students? if so what years? Also added a poll if you do not want to reply in a post. Many thanks!
synaesthesia Posted February 27, 2019 Posted February 27, 2019 MFA turned on for all staff but only outside of school. Can't see a real need to do the same for student accounts *yet* but times change, however how that'd be an expensive addition.
gshaw Posted February 27, 2019 Posted February 27, 2019 MFA turned on for all staff but only outside of school. Can't see a real need to do the same for student accounts *yet* but times change, however how that'd be an expensive addition.Assuming that's O365 MFA and Azure AD Premium you should get 15 student licenses free for every licensed FTE member of staff.
synaesthesia Posted February 27, 2019 Posted February 27, 2019 No, not the licensing side of it; that'd actually cost nothing on top of our existing subscription. I meant to say having to buy them tokens/tags or relying on mobile phones, although they're banned in school but we wouldn't use MFA in school anyway. So really it's just down to not seeing a real need for it.
free780 Posted February 27, 2019 Posted February 27, 2019 I think it's coming for students. The issue is them using their own phones. Fine at FE/HE level but secondary and primary could be more of an issue. Or you just say no external access unless you have MFA enabled.
DrCheese Posted February 27, 2019 Posted February 27, 2019 I rolled out MFA here last year. I went for the SMS option primarily, as I figured that getting everyone on that level at least is a good level of protection for a school, without the hassle of getting everyone to install applications on their phones, which they may find challenging or simply go "I'm not using my personal phone for this" - Tho I let them do that if they wanted. It also meant that even those without smart phones would be fine & as smart token for Azure MFA didn't exist at the time, worst case I'd buy them a cheap £10 pay and go phone via the school and give them that I disabled the push notification option because I thought it was utterly stupid in it's current setup, as it simply comes up saying "Are you authenticating yes/no" with no other real info - I figured most staff would just press "Yes" on their phones either from thinking it was their mobile apps trying to authenticate or because they just wanted the error box to go away. When MS improve this I may reconsider. In terms of rolling it out, I set it so that they'd never get MFA challenged inside of school (I have Azure AD Premium 1 & use conditional access) & I also sent staff instructions on how to pre-register their numbers in advance of switchon. We kept an eye on this via powershell & basically jumped staff every time we could to get them to register. I honestly was expecting massive push back from it but 99% of staff just went "oh like my bank" and did it. Not a single one protested or complained about it. I've now put everything through Azure AD as our primary auth method and chucked out ADFS. I haven't done students because I figured there's miminal risks from a GDPR standpoint if someone compromises their accounts (They have no access to confidental stuff) & because we do auth all through Azure AD it flags up suspicious signins anyway (new locations etc) - So we just force password changes on them and get on with our day - There's also the fallout that might result from us asking for student mobile numbers that right now I didn't want to get into.
seustice Posted February 27, 2019 Posted February 27, 2019 We are in the process of rolling out for all, staff were already onboarded, but have extended to include on-site. We're an iPad 1:1, so MS Authenticator for us. The risk is, if you have a compromised workstation, weaker student accounts can be used to glean information about who to target for phishing attempts, and an innocent looking email to a member of staff from a student containing a phishing link is enough to gain access to your MIS.
Katy Posted February 27, 2019 Posted February 27, 2019 Only enabled for admins at the moment. I want to roll it out to staff but we don't have the correct licence to allow for the Trusted IPs option, as I don't want people being asked for MFA while on site. If I can make a big enough case for it (or if we needed it for something else as well) I'd spend the money on the licences and enable for all staff.
DrCheese Posted February 27, 2019 Posted February 27, 2019 At least Azure AD Premium 1 - It cost me around £700ish to license all our staff (109 or so) - I've heard since that there's a license you can apply for that means students get it for free when you license your FTE - I've not done much digging into that yet tho
Katy Posted February 27, 2019 Posted February 27, 2019 Standard Office 365 MFA is free but you can't set up Trusted IPs (where you define an IP range and MFA is disabled for requests coming from that range) so without paying extra your choices are MFA all the time even when sat in school, or not at all.
free780 Posted February 27, 2019 Posted February 27, 2019 You can exclude MFA on Azure AD joined devices. Do you trust every device behind your public IP? It's worth the investment as it gives you insight into where logins are coming from. Has anyone started to implement this for students yet? Is it worth moving this to the security forum?
msm1000 Posted February 28, 2019 Author Posted February 28, 2019 Thanks for all the info so far and for everyone who has voted in the poll. Currently we have the free Office 365 (A1) but I do think the MFA experience would be better if we could add Trusted IP addresses.
Cthulhu Posted March 2, 2019 Posted March 2, 2019 I honestly was expecting massive push back from it but 99% of staff just went "oh like my bank" and did it. Not a single one protested or complained about it. How did you pull that one off? I didn't get through the first department before they kicked off and gave us the 'I'm not using my personal device or giving my number' excuse. These are the same numpties that would later go on to give their login details to a phishing scam >_<
free780 Posted March 2, 2019 Posted March 2, 2019 In that scenario I would not allow remote access. The security and data protection risks are too great.
3s-gtech Posted March 2, 2019 Posted March 2, 2019 As we don’t use O365 much yet, I decided to enable it for all accounts now. G Suite is linked to it, so I wanted the extra protection. I can cope without the IP exceptions, but only because our email is still on-site.
msm1000 Posted March 9, 2019 Author Posted March 9, 2019 Thanks again for all the replies. Going to roll MFA out to a select group to make sure all is working fine before looking at all staff.
Silky Posted May 16, 2019 Posted May 16, 2019 We've rolled out MFA to be required when not onsite. Some people prefer the app, some text. However, we are down to our last member of staff to be authenticated. It is becoming quite difficult as he has an old windows 7 laptop at home, but has never owned a mobile phone/tablet and does not plan on doing so. What would people recommend? Thanks.
3s-gtech Posted May 16, 2019 Posted May 16, 2019 Can you upgrade the member of staff? He sounds quite obsolete and he's probably not in warranty any more. In seriousness, I think you need to be a bit reactive with it - if he has no easy way of using MFA, you'll have to leave it off but perhaps encourage him to look into a phone (or even provide a basic one - not ideal I know!)
DrCheese Posted May 16, 2019 Posted May 16, 2019 My plan in that case was to buy a cheap mobile phone (like £15) and force them to use that, else thankfully I had management backing up just tell them they've lost the ability to work remotely. I think you can opt in hardware token support now on 365 too so you can buy those keys.
PlantHead Posted May 16, 2019 Posted May 16, 2019 They can also use a landline phone or an alternative email address. If they don't have a mobile phone, computer or land line phone then they can't work remotely anyway - as well as being an incredible Luddite.
Silky Posted May 16, 2019 Posted May 16, 2019 As the staff member goes away, he wont have access to a landline. I did not think that you could use an alternative email address for office 365's MFA. I'll have to look into it. Thank you.
seustice Posted May 16, 2019 Posted May 16, 2019 I bought a few of these for such luddites. https://www.token2.com/shop/product/token2-c200-hardware-token Only given one out so far.
msm1000 Posted May 17, 2019 Author Posted May 17, 2019 I have tested some OATH tokens and yes they work, but the setup is more involved (activating each token) so I would not want to roll this out for every user.
jmak Posted May 17, 2019 Posted May 17, 2019 Would this work: https://docs.microsoft.com/en-us/azure/active-directory/b2b/one-time-passcode
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now