Jump to content

Recommended Posts

Posted

I'm not a big user of 365 but I'm aware that it allows you to enforce 2FA for users when they are offsite (i.e off school network)

 

Does anyone know of a way (third party tool perhaps) that allows this with GSuite? We currently have it enabled but it applies regardless of the login location

Posted
I think Google's black box determines what a 'suspicious' login attempt looks like, and probably can't or doesn't want to accomodate any user-managed rules geared towards skipping MFA for convenience. The opacity of what 'suspicious' means is presumably to not give attackers any clues on how to not appear suspicious.
Posted
I tried to look at this before summer and i drew a blank on it as I struggled to get something to work but it would be great if we could have something configured in google that would allow for location based 2FA access.
Posted

I have to admit I'm still in two minds about it, part of me thinks that 2FA should apply all the time, in school or otherwise, part of me thinks I'll get less complaints about 2FA if its only used outside school

 

Although if staff learned to lock their PCs it would be a start!

Posted

We've taken the view here that MFA should be used everywhere, there are lots of reasons why simply trusting an IP or location are a bad idea. If nothing else it trains staff in a conistent manner - ie. "If I do this I always get an MFA prompt and it looks like x" then when something out of the ordinary happens they're in theory more able to spot in and avoid phishing etc.

 

Across various schools we've had very little pushback with MFA - nowhere near what you might expect.

 

You may need to be firm with locking of PCs, enforce it after a certain period of inactivity and tell staff if they're not actively locking when they leave a PC then the inactivity locking period will keep getting reduced - it's for a very good reason, data protection - they have access to so much confidential data that the school needs to take reasonable steps to protect it.

Posted
We've taken the view here that MFA should be used everywhere, there are lots of reasons why simply trusting an IP or location are a bad idea. If nothing else it trains staff in a conistent manner - ie. "If I do this I always get an MFA prompt and it looks like x" then when something out of the ordinary happens they're in theory more able to spot in and avoid phishing etc.

 

Across various schools we've had very little pushback with MFA - nowhere near what you might expect.

 

You may need to be firm with locking of PCs, enforce it after a certain period of inactivity and tell staff if they're not actively locking when they leave a PC then the inactivity locking period will keep getting reduced - it's for a very good reason, data protection - they have access to so much confidential data that the school needs to take reasonable steps to protect it.

 

 

Whilst I completely agree with you, we had to do it location based for office 365 to avoid the potential safeguarding issues of having staff getting phones out all over the place.

Posted
I doubt conditional access will ever come to Workspace. All you are doing is making your users access less secure based on location. That pupil who finds that teachers password on a post it note. Maynot be able to access outside of school becasue 2FA but while at school......
  • Thanks 2
Posted
Whilst I completely agree with you, we had to do it location based for office 365 to avoid the potential safeguarding issues of having staff getting phones out all over the place.

 

Buy them the USB tokens, they're not that expensive. The added security is well worth it.

  • Thanks 1
Posted (edited)
I have to admit I'm still in two minds about it, part of me thinks that 2FA should apply all the time, in school or otherwise, part of me thinks I'll get less complaints about 2FA if its only used outside school

 

Although if staff learned to lock their PCs it would be a start!

 

My thoughts exactly! It's a shame Google haven't thought about this.

 

Our staff move around, we don't have laptops (or chromebooks) that staff have with them at all times, we have desktop machines in classrooms, we use mandatory profiles rather than local as this way for us doesn't cause the issues we would have with local profiles and staff would naturally complain that they have to use 2FA everytime they used their Google Account.

 

I would love to approve a feature that when outside of our external IP range that users need to input a 2FA code.

 

It seems miniorange is possibly the best 3rd party add-on which i have seen however it comes at a cost (but doesn't everything that Google won't setup!)

 

Then we have some staff who don't actually have a Smart phone so dongles would need to be purchased.

Edited by timbo343
Posted
This isn't a thing in Google Workspace and I think it is an ideological thing - security should apply all the time, and they also believe everyone should have a personal device. So, end result is no conditional access.
  • Thanks 2
Posted
I doubt conditional access will ever come to Workspace. All you are doing is making your users access less secure based on location. That pupil who finds that teachers password on a post it note. Maynot be able to access outside of school becasue 2FA but while at school......

This is my sticking point - careless use in school! Of course they always set it remember their device anyway but 2FA at least mitigates some of this

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...