Jump to content

Recommended Posts

Posted (edited)

I have had IMAP & POP disabled for many years at my schools as it is not very secure, and if someone is using a third part mail program at home, the schools data is then not on our systems. Also IMAP & POP do not not work with 2FA.

 

Recently I taken over a new school. After disabling IMAP & POP one governor is not very happy as he can no longer use his Mac email client at home to read the emails and wants me to re enable it.

 

I have sent him an email explaining that IMAP & POP are not very secure and that schools should keep any data on the schools supplied systems.

 

The reply I got back was, he does not understand any of that but needs me to help him get the school email in his Mac email client like it always has.

 

I know that IMAP & POP are a security concern, but am I correct in saying the schools data should stay on the schools systems? Basically should he be using the schools supplied email software?

 

If not, how do we make sure he deletes any emails after he has left?

 

BTW we are using G suite.

Edited by TwistedHelixis
Posted

I would never enable POP3 for anyone. IMAP is debatable.

 

What do you do for your staff? We use Exchange which can be used in the built-in mail client or via the Outlook app. There must be similar for GMail.

  • Thanks 1
Posted (edited)

Three Two options...

 

  1. Use the Gmail web interface.
     
     
  2. Don't access school e-mail on personal devices.

Edited by Arthur
  • Thanks 1
Posted

Question about step 2. Setup the Mac mail client to connect via the Google account provider.

 

Does the Mac client download the emails to its software or are the emails still held on Google servers? If we removed his account would any emails still be available on his email client?

Posted

Also found this

The concept of creating a Gmail account in Apple Mail is simple enough. Gmail makes use of standard mail protocols, and Apple Mail supports the methods of communicating with the Gmail servers. You can add a Gmail account the same way you'd add any POP or IMAP account you currently use. Most versions of OS X and the newer macOS have an automated system that creates Gmail accounts for you.You can create a Gmail account either directly in Mail or from System Preferences. The System Preferences option is a handy way to keep all your social media and your email accounts together so you can easily make changes that are automatically reflected in any OS X app that makes use of them. The two methods, using Mail and System Preferences, are nearly identical and end up creating the same data in both Mail and System Preferences. The Gmail account makes use of IMAP because Google recommends IMAP over POP.

Posted
Absolutely not, whether he's a governor, head teacher or the leader of OFSTED, you shouldn't compromise your network security for the sake of his convenience. Advice the use of the web client if the above options don't appear available.
  • Thanks 1
Posted (edited)
Does the Mac client download the emails to its software or are the emails still held on Google servers?

I think the e-mails would still be cached on his Mac, but they should be deleted when you remove his G Suite account. You may want to try this with a test user account to see if this is the case however.

 

By the way, the Google account provider does support 2FA (not security keys), although I'm not sure if it would connect via IMAP.

 

z6b0TL4.png

 

zW9l4vh.png

 

SqtnHHY.png

Edited by Arthur
Posted

Very much appreciate all the help so far.

 

That is good to know it does now support 2FA.

 

So would I still need to enable IMAP on my G Suite domain, as these sites seem suggest?

https://www.lifewire.com/gmail-os-x-access-1172876

 

https://www.lifewire.com/set-up-gmail-account-with-macs-mail-application-2260069

 

If so, that is still a reason for me to ask this Governor not to use his Mac email client, as I do not want to enable IMAP.

Posted (edited)
So would I still need to enable IMAP on my G Suite domain, as these sites seem suggest?

I did some more testing (with POP/IMAP still disabled on my G Suite domain) and while it appears that you can send e-mails after logging in with your 2FA protected G Suite account, it doesn't let you do much else (see account error in top right of screenshot).

 

I therefore wouldn't recommend using the Apple Mail client. :)

 

i02q25m.png

 

zMf183q.png

 

If so, that is still a reason for me to ask this Governor not to use his Mac email client, as I do not want to enable IMAP.

Yeah. I would tell him he has to use the Gmail web interface. Anything else would compromise security.

Edited by Arthur
  • Thanks 1
Posted

The problem is that sometimes, as a Governor, having access to information quickly is key.

I can fully understand his requirements on this ...

 

However, there are things that need to be done to protect you systems.

 

1 - any data that is sent via email or is linked to within an email can still be downloaded. Don’t confuse protecting one method of access with protecting information.

 

2 - POP is a big no no, and IMAP is susceptible, but you are going to have to face that if he uses the web app he will need to get notifications ... how about explaining how he can do that.

 

3 - also face the fact that guidance needs to be given to Governors about securing data on home devices. Whilst Governors rarely have to deal with personal data, when they do it is important to keep it safe ... organisational measures should be there to support that (policies).

 

4 - Please remember that Governors are volunteers ... generally a dedicated bunch who are not there to be difficult, but to help the school. There are many governors on EG (including yours truly) so please be mindful of not casually dismissing their needs.

  • Thanks 2
Posted (edited)

4 - Please remember that Governors are volunteers ... generally a dedicated bunch who are not there to be difficult, but to help the school. There are many governors on EG (including yours truly) so please be mindful of not casually dismissing their needs.

THIS! #MeToo!

 

Governors are a vital part of the team working hard for the students in your school in their own unpaid time. They come with all levels of skill, expertise and experience in everything and anything. Your school’s governors cannot all have the same levels of GDPR, Safeguarding, IT and governance expertise as Grumbledook or me.

 

Be an enabler. If the thing requested can be done in a better way then present it as that... most governors will be eternally grateful for a solution presented with a smile.

 

Have a chat with your DPO and DSL about what training or guidance could be offered to governors. The offer of a short presentation at the start of a full governors meeting is likely to be eagerly accepted.

 

I will also mention the Clerk to the governors. This person is paid, but likely part time and for very few hours. (Some, but by no means all, will be school employees) Their role is not just taking minutes; they are also the people who have the knowledge of procedure and statute to ensure the GB covers its obligations. Clerks are people to befriend. They are the primary access point to any Governing Board. Get them onside and you will have easy access to getting the message over to the GB!

Edited by elsiegee40
Posted
so please be mindful of not casually dismissing their needs.

 

Have I missed something? I though asking these questions were actually taking the governors needs in to account. This is a fact finding process and all avenues should be discussed.

 

If there was a secure way for me to help him I would, but I do not want to start enabling protocols on our system when they are know to be insecure and the school has a very simple alternative method of working.

 

I am sure he will be fine to use whichever system we suggest but the point of these posts was to check alternatives.

 

BTW, I have only been at this school for a couple of weeks, and prior to my arrival it was another governor that was looking after all the schools G Suite systems.

Posted
Screengabs will be taken, and even people taking photos of the screen.

 

If folk want the data, they will get the data.

 

I am not sure that is a good reason to lower the security of s system.

Posted
I am not sure that is a good reason to lower the security of s system.

 

It is mainly there as a comment for those looking to say "do x as it will prevent y", when doing x only makes y difficult, doesn't prevent it. If your justification for x is solely to prevent y then it is faulty.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...