Jump to content

Recommended Posts

Posted

Staff have been using Teams for a while now and we are ready to roll it out to our primary students. As I work 3 days the HT wants admin access to 365 to manage Teams and add new pupils when I am not in. I don't have a problem with that as he is very competent IT wise.

 

I'm a 365 global admin and when I logon to the admin portal I use a separate account that has 2FA enabled. My everyday 365 account is a standard user but still has 2FA.

 

Last year I started a trial of 2FA with the HT and office staff but not having any P1 licenses it didn't go down too well and was told to disable it so now I'm the only one with 2FA on their account which brings me back to the question of the HT having admin status. As I don't like the sound of the HT having admin access on a non 2FA protected account can I now insist on enabling 2FA on his account or perhaps making a new 2FA enabled admin account just for the HT to use when I'm not in?

Posted (edited)
Personally I'd create a seperate account for him and enable 2FA on that. Personally I don't think any admin accounts should be same as normal log in accounts anyway. Edited by Davit2005
  • Thanks 2
Posted

Really all your staff accounts should be using MFA, they'll get used to it but the security it provides outweighs the inconvenience 100 fold. P1 isn't necessary since excluding an IP address or range is compromising its effectiveness anyway.

 

Also yes give him a separate admin account.

  • Thanks 2
Posted

We enabled 2FA for O365 accounts here around without the P1 license and being unable to exclude school IP ranges. Staff moaned a lot in the beginning and still do occasionally, but we give the same response of 'we're keeping you and your data safe'.

I would definitely try and persevere and enable on all staff accounts if you can.

  • Thanks 2
Posted
^ Plus there's the "remember this computer for X days" (after a successful sign-in) option, so it's not particularly troublesome unless they switch device a lot.
Posted
exactly, if you don't check it every 30 days you might find it's broken when you do need it anyway. But also have a different account, that way you get to pick a stupidly complex password too
Posted
WTF! So I'm in 365 admin portal and see the company who setup the teams remote learning has already given the HT global admin status without enabling 2FA and without telling me. I'm lost for words.
Posted (edited)
WTF! So I'm in 365 admin portal and see the company who setup the teams remote learning has already given the HT global admin status without enabling 2FA and without telling me. I'm lost for words.

 

I think you need to raise this to cover yourself.

Edited by Davit2005
Posted

Remember you can also set Hybrid joined devices as a factor even on the free Office 365 licences. This gets around the Trusted IP issue. You get SSO on the hybrid devices.

 

You need to do some ADConnect work and allow some domains through your proxy.

  • Thanks 1
Posted
Remember you can also set Hybrid joined devices as a factor even on the free Office 365 licences. This gets around the Trusted IP issue. You get SSO on the hybrid devices.

 

You need to do some ADConnect work and allow some domains through your proxy.

 

But defeats the point of MFA.

Posted (edited)

I would be tempted to approach this a different way (one that don't need you to give out global admin in your tenant) ton of options here PowerApp that can be used to do the user admin get it to read membership from a sharepoint list (could also be pure PowerShell) you can all so use this methodology to crate your teams as well. This way you can give access to the SP site and the required privileges to service accounts that your PowerApp/ scripts use. The guys you are paying to develop your teams service should be able to build you your service wrapper for this mind!

 

That's just one way if you have a ticketing system you could hook that up as part of your service wrapper for your teams service.

 

(if not I am tempted to start offing my own skills to get this stuff built for you...)

Edited by HPlum78
Posted
WTF! So I'm in 365 admin portal and see the company who setup the teams remote learning has already given the HT global admin status without enabling 2FA and without telling me. I'm lost for words.

 

Remove their admin rights. And the HTs. And then do it properly. Also report them for GDPR violations or something

  • Thanks 1
Posted
But defeats the point of MFA.

 

Not really, their logon to the school domain is their second factor? that then passes through AAD Connect to 365, not all MFA methods need to be explicit

  • Thanks 1
Posted
Not really, their logon to the school domain is their second factor? that then passes through AAD Connect to 365, not all MFA methods need to be explicit

 

Ok so situation for you - I'm a kid, I watch the teacher type their password in. Later I go to a domain joined device and log in as them - proper MFA would have prevented this, using the device as a factor doesn't.

Posted
Ok so situation for you - I'm a kid, I watch the teacher type their password in. Later I go to a domain joined device and log in as them - proper MFA would have prevented this, using the device as a factor doesn't.

 

Not disagreeing with your example at all and completely agree (and I enforce MFA for staff anywhere and students out of school), just that MFA, using SSO on trusted IP ranges is MFA, just not explicit MFA it doesnt have to be a generated code etc, could even be a security question or text code etc

Posted (edited)

But they can only use that password on school computers, which you're monitoring.

 

As the password will be reused they can log into all the non school accounts the teacher has though.

 

Two flaws, teacher let someone watch them, and they had a password so simple someone could watch them

 

Actually 3 flaws, they were typing their password, why? No auto login? No biometrics?

Edited by mavhc
Posted
Not disagreeing with your example at all and completely agree (and I enforce MFA for staff anywhere and students out of school), just that MFA, using SSO on trusted IP ranges is MFA, just not explicit MFA it doesnt have to be a generated code etc, could even be a security question or text code etc

 

Excluding a device because of it's domain status or IP address is not effective MFA.

Posted
Yep, you also need a password, now it's effective. You've just eliminated 7 billion people logging in.

 

Respectfully, you are being ridiculous. For MFA to work you need to use multiple effective challenges - a password, an app on your phone, a security USB key etc etc.

 

Relying solely on a password and the domain status of a device is not effective MFA.

Posted
Think I've gone a bit of topic off MFA on Office 365 admin accounts which should have MFA enabled as default as per the consensus.

 

Best practice is that ALL staff acounts have effective MFA enabled on them not just admin accounts.

  • Thanks 3
Posted
Best practice is that ALL staff accounts have effective MFA enabled on them not just admin accounts.

 

Well as we seem to be splitting hairs, I'd suggest that best practice is that all accounts have MFA activated (as I stated earlier) but the OP was asking specifically about 2FA on 365 admin accounts hence the above statement........

Posted

The best practise is something people will actually do, and defense in depth.

 

Internet passwords have 7 billion people possibly trying to hack them, first stop those people. Have different passwords, too complex to remember, and write them down (use a password manager really, but writing them down is better than having them all be your cat's name), or use your phone as a second factor.

 

Now there's just the 30 people left in the world that can watch you type/read your post it note.

 

 

Passwords for a local computer are different, it's those 30-1000 people in the building that are the issue.

 

Oh crap, now we just synced the two. Which is why MS added the PIN.

Posted (edited)

The 2 Factor issue for me should be a none starter for anything that has elevated privs, its on. Having to hand out Global Admin to manage Teams for someone outside of IT seems a little like a bazooka to swat a fly! there are so many just better ways to do this, global GLOBAL ADMIN to manage teams! Surly the most amount of priv that is required for this is Teams Service Admin even then I would not be handing that out like smarties...

 

As for the using a Hybird joined device as a factor, well this just depends on what you want your user journey to look, what's the point in PTA if you are going to stick a popup in the way when a user wants to access something. Getting the balance of usability and security is a fine art and we should at least agree on that. We should also accept that a lot of this stuff is decided outside of IT and to be honest is not down to the IT department as its a business risk not an IT risk to accept we should be articulating these and be directed by external key stake holders not just mandating something that hinders the access/ usefulness of our services.

Edited by HPlum78

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...