Sheridan Posted November 10, 2021 Posted November 10, 2021 I'm not a big user of 365 but I'm aware that it allows you to enforce 2FA for users when they are offsite (i.e off school network) Does anyone know of a way (third party tool perhaps) that allows this with GSuite? We currently have it enabled but it applies regardless of the login location
Oaktech Posted November 10, 2021 Posted November 10, 2021 I'm pretty sure it's not a thing yet, 3rd party or not.
jthompson Posted November 10, 2021 Posted November 10, 2021 I think Google's black box determines what a 'suspicious' login attempt looks like, and probably can't or doesn't want to accomodate any user-managed rules geared towards skipping MFA for convenience. The opacity of what 'suspicious' means is presumably to not give attackers any clues on how to not appear suspicious.
Sheridan Posted November 10, 2021 Author Posted November 10, 2021 Yeah - MS seem to have managed with 365 but I can understand why there's reasons why it hasn't been implemented with Google.
newtechman Posted November 10, 2021 Posted November 10, 2021 Not sure, but have a look at GSuite IP restriction (SSO/2FA) where a 'whitelist' might work for you
timbo343 Posted November 10, 2021 Posted November 10, 2021 I tried to look at this before summer and i drew a blank on it as I struggled to get something to work but it would be great if we could have something configured in google that would allow for location based 2FA access.
Sheridan Posted November 10, 2021 Author Posted November 10, 2021 I have to admit I'm still in two minds about it, part of me thinks that 2FA should apply all the time, in school or otherwise, part of me thinks I'll get less complaints about 2FA if its only used outside school Although if staff learned to lock their PCs it would be a start!
Primus Posted November 10, 2021 Posted November 10, 2021 We've taken the view here that MFA should be used everywhere, there are lots of reasons why simply trusting an IP or location are a bad idea. If nothing else it trains staff in a conistent manner - ie. "If I do this I always get an MFA prompt and it looks like x" then when something out of the ordinary happens they're in theory more able to spot in and avoid phishing etc. Across various schools we've had very little pushback with MFA - nowhere near what you might expect. You may need to be firm with locking of PCs, enforce it after a certain period of inactivity and tell staff if they're not actively locking when they leave a PC then the inactivity locking period will keep getting reduced - it's for a very good reason, data protection - they have access to so much confidential data that the school needs to take reasonable steps to protect it.
Oaktech Posted November 10, 2021 Posted November 10, 2021 We've taken the view here that MFA should be used everywhere, there are lots of reasons why simply trusting an IP or location are a bad idea. If nothing else it trains staff in a conistent manner - ie. "If I do this I always get an MFA prompt and it looks like x" then when something out of the ordinary happens they're in theory more able to spot in and avoid phishing etc. Across various schools we've had very little pushback with MFA - nowhere near what you might expect. You may need to be firm with locking of PCs, enforce it after a certain period of inactivity and tell staff if they're not actively locking when they leave a PC then the inactivity locking period will keep getting reduced - it's for a very good reason, data protection - they have access to so much confidential data that the school needs to take reasonable steps to protect it. Whilst I completely agree with you, we had to do it location based for office 365 to avoid the potential safeguarding issues of having staff getting phones out all over the place.
PrimaryNetMan Posted November 10, 2021 Posted November 10, 2021 I doubt conditional access will ever come to Workspace. All you are doing is making your users access less secure based on location. That pupil who finds that teachers password on a post it note. Maynot be able to access outside of school becasue 2FA but while at school...... 2
Primus Posted November 10, 2021 Posted November 10, 2021 Whilst I completely agree with you, we had to do it location based for office 365 to avoid the potential safeguarding issues of having staff getting phones out all over the place. Buy them the USB tokens, they're not that expensive. The added security is well worth it. 1
timbo343 Posted November 10, 2021 Posted November 10, 2021 (edited) I have to admit I'm still in two minds about it, part of me thinks that 2FA should apply all the time, in school or otherwise, part of me thinks I'll get less complaints about 2FA if its only used outside school Although if staff learned to lock their PCs it would be a start! My thoughts exactly! It's a shame Google haven't thought about this. Our staff move around, we don't have laptops (or chromebooks) that staff have with them at all times, we have desktop machines in classrooms, we use mandatory profiles rather than local as this way for us doesn't cause the issues we would have with local profiles and staff would naturally complain that they have to use 2FA everytime they used their Google Account. I would love to approve a feature that when outside of our external IP range that users need to input a 2FA code. It seems miniorange is possibly the best 3rd party add-on which i have seen however it comes at a cost (but doesn't everything that Google won't setup!) Then we have some staff who don't actually have a Smart phone so dongles would need to be purchased. Edited November 10, 2021 by timbo343
localzuk Posted November 10, 2021 Posted November 10, 2021 This isn't a thing in Google Workspace and I think it is an ideological thing - security should apply all the time, and they also believe everyone should have a personal device. So, end result is no conditional access. 2
Sheridan Posted November 10, 2021 Author Posted November 10, 2021 I doubt conditional access will ever come to Workspace. All you are doing is making your users access less secure based on location. That pupil who finds that teachers password on a post it note. Maynot be able to access outside of school becasue 2FA but while at school...... This is my sticking point - careless use in school! Of course they always set it remember their device anyway but 2FA at least mitigates some of this
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now