HPlum78 Posted March 20, 2021 Posted March 20, 2021 (edited) On a side note are those who are using Azure (hybrid AD sync) set up this yet: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-password-ban-bad-on-premises-deploy Take a look. Edited March 20, 2021 by HPlum78 1
dhicks Posted March 20, 2021 Posted March 20, 2021 Do you use this feature? Yes - iSAMS have reduced functionality for any non-2FA-enabled accounts, limiting access to facilities to contact parents. For admin staff and senior management we've linked iSAMS accounts to GSuite accounts and turned on GSuite 2FA, handing out Ubikey USB dongles to staff, so GSuite (which handles email and shared file access) is covered, too. It seems to have worked well so far, with little fuss or problem. We're just trying to figure out the best way to roll out further - Ubikeys are £25 each, so there's a bit of a cost if we roll out to all staff, we're probably going to go with authenticator app on phones. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now