Jump to content

Recommended Posts

Posted

Hi all,

 

We have just migrated to O365 from Exchange 2016 (Way overdue) bit of background, I took over a destitute IT system just over a year ago. Almost nothing configured, redirected folders barely working (most, including SLT!!!!, were saving to local desktop/documents etc.

 

A lot has changed over the past year and staff have on occasion been reluctant to change, this was expected as I basically fort knoxed the system after 12 years of them having essentially complete freedom and no restrictions.

 

We are trying to adhere to Microsoft's Cyber Essentials and thus with the heads go ahead, have told staff Microsoft Authenticator will be required as of next week.

 

As you can imagine, staff are not happy with the idea of using their phones to authenticate their work emails.

 

My question is, has anybody else experienced this push back from staff and how have you managed it?

 

How have you found Authenticator to work in this kind of environment?

 

Thanks!

Posted

What will help, is having Conditional Multi-Factor Authentication. So, if they are on the work network they won't get Authenticator requests, but outside the network they will. Best of both worlds. The only thing is, for this your need the P1 license with Microsoft365 to use this.

 

I had very little push back when I introduced it for all staff and most people accepted the situation.... security or convenience, pick one.

 

Pete

  • Thanks 2
Posted

We rolled Conditional Access MFA out to all our staff across the MAT before Summer.

There have been one or two staff over the 5 schools that did not want to use it, however as it only limits them accessing their Office 365 account off site, I don't think they complained too long.

 

We've recommended that staff use the MS Authenticator where possible instead of the default SMS option, as if using a personal device in school they always have access to the school wifi for the app to get the request, where as for some providers our schools can be signal black holes.

 

By going down the Conditional Access route (We purchased the A3 EM&S addon pack for our tenancies so also got InTune), and that all our school devices are classed as Hybrid AD Joined device, we could set the policy so that the school workstations count as the 2nd authenticator so they do not have to authorise on the app in school (which was causing a headache for one fo the schools who switched on MFA before the licences were allocated)

  • Thanks 1
Posted

Just remember, to enable Conditional Access, you need to have a P1 licence on your tenancy as a minimum.

 

Each of the A3 EM&S add on licences were under £8 per member of staff for the year, but we also got 40 student licences with it.

Depending what your current MS licencing provision is, you might want to talk to your provider to make sure you have suitable licencing in place... as while you can unlock Conditional Access with just 1 licence on your tenancy, it's not always the correct method.

Posted

"I don't want to use my own phone"

 

That's fine, we'll just buy you a hardware authenticator and deduct the cost from your department's budget.

  • Thanks 1
Posted
"I don't want to use my own phone"

 

That's fine, we'll just buy you a hardware authenticator and deduct the cost from your department's budget.

Expressed in @mavhc's inimitable style, but he's right. The school should care enough about security to spend the money if necessary. I personally have absolutely no issue with using my own phone for things like that, but staff definitely have a right to object. You can't insist that staff buy equipment that's essential to do their job.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...