Jump to content

Recommended Posts

Posted

Hi

We have been heavily relying on teams to deliver lessons to pupils during the pandemic. Somehow though someone has manage to create accounts that have the same name as some of our staff members so the teacher in charge of a team would give them access to the lesson but they would then start shouting down the mic. So they seem to also be able to over ride the group mute settings.

They haven't hacked a teachers account as when we look in the teams admin portal the actual teachers account doesn't show any activity.

Does anybody know how a pupil may have been able to change their account name?

 

Thanks

Posted

They are taking the meeting url and opening a chrome incognito window and pasting it into that. Because that window isn't authenticated you get the guest prompt where you can enter any name.

 

You can't stop this, all you can do is educate the teacher not to admit guest accounts in the lobby and the students soon tire of doing it....

  • Thanks 1
Posted
They are taking the meeting url and opening a chrome incognito window and pasting it into that. Because that window isn't authenticated you get the guest prompt where you can enter any name.

 

You can't stop this, all you can do is educate the teacher not to admit guest accounts in the lobby and the students soon tire of doing it....

 

Little darlings [emoji849]

Posted

Open tickets with MS Support via admin.microsoft.com and aka.ms/edusupport

 

There are a couple of ways they are able to do this. Support will eventually close this down as it is the behaviour of Teams as it ships. However it is not the *INTENDED* behaviour, and we need to get the product team's attention and for them to understand the serious nature of this flaw in part of their implementation.

 

The real problem is that the only way to keep kids out of meetings when there isn't a teacher present is to require the lobby for a meeting. If we weren't fording people through the lobby, the only people in the lobby would be these uninvited guests, which would be more manageable.

 

Currently the only way to stop it reliably is to disable anonymous access to your tenant.

 

There are some medium term improvements in the pipeline that may obviate these hoops we are trying to jump through, but for now we need to be able to identify anonymous users in the lobby easily.

Posted
Hi

We have been heavily relying on teams to deliver lessons to pupils during the pandemic. Somehow though someone has manage to create accounts that have the same name as some of our staff members so the teacher in charge of a team would give them access to the lesson but they would then start shouting down the mic. So they seem to also be able to over ride the group mute settings.

They haven't hacked a teachers account as when we look in the teams admin portal the actual teachers account doesn't show any activity.

Does anybody know how a pupil may have been able to change their account name?

 

Thanks

 

Have spent the week with our schools talking to various 3rd parties and MS and getting to grips with the how & why.

 

It will be a mix of your meeting settings and staff being sure they can identify who is in the lobby.

 

This doc will help you a lot

https://support.microsoft.com/en-us/office/keeping-students-safe-while-using-teams-for-distance-learning-f00fa399-0473-4d31-ab72-644c137e11c8

 

Especially the "for educators" section.

 

Happy to have a chat about what we have found and can post further if useful when things calm down. PM if you want to talk through.

Posted
You can stop unauthenticated users from joining teams meetings though, so just do that

 

Won't that stop external users you invite from being able to join?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...