Jump to content

Recommended Posts

Posted

I'd like to know if there are any schools out there who are using Google MFA and Mandatory Profiles (or local profiles even) on their domain and to understand what your Google MFA policy along with what you do with the Cookies and Profiles on your domain computers.

 

If feel there are so many variables to what I'm wanting to achieve that I cannot seem to find a perfect solution.

 

We mainly run Mandatory profiles around the domain for Staff members. Some staff members (a handful such as office staff use roaming profiles, to be honest these staff users could actually run local profiles these days).

 

Staff mandatory profiles are removed when the user logs off that particular computer which in turn removes the Cookie which is saved on the local machine.

 

Let's start with the MFA policies in Google.

 

Under Security > Authentication > 2-Step Verification:

Does anyone else disable / untick the Frequency - Allow the user to trust the device so that the browser (not the device) cannot be set as a trusted device / browser?

 

Under Security > Access and data control > Google Session control:

How long do people set the Google Session Control to? We have it set to 12 hours - is this too frequent - i say i'd rather be secure on devices that store the Google Cookie than have it open.

 

Now for the devices such as laptops and domain machines.

 

Let's start with the windows laptops. Our teaching staff are allocated windows devices which are enrolled into Azure Intune so staff can use their work email address and password which is the same as the network to login to the devices - happy days! The profile remains on the laptop so the Google Cookie remains on the local profile. If a member of staff logs off the laptop, the local profile is not removed. This is one of the reasons why i'd like to keep the Google Session Control to 12 hours.

 

On the domain computers / user accounts that have Local or roaming profiles where the profile remains on the machine when a user logs off a machine, the Google Session Control which is controlled via the cookie controls how often a user is to login to a computer which is why I'd like to keep the Google Session Control to 12 hours so that means staff who have this type of setup are required to login to their account at least once a day.

 

The user accounts that use Mandatory profiles are the issue and we feel we will get a lot of backlash from staff. When a user either logs on to a computer for the first time or re-logs on after being logged on, the local profile of the mandatory account is obviously overwritten so the cookies of Google are deleted. This means that staff who move around school and use the same computer on a daily basis may end up having to keep using their MFA token all the time - has anyone else had this problem and had any issues with staff? For me, i cannot see that as being an issue however I know some staff will object against it.

 

I've been trying to get this off my chest for a while and as i say, i'm struggling to find a happy balance but this is one of the situations where i cannot please everyone.

Posted

do you have any mapped drives that are available offline?

 

Could map the chrome userdata to that then or another persistent location so it would persist between sessions?

Posted
do you have any mapped drives that are available offline?

 

Could map the chrome userdata to that then or another persistent location so it would persist between sessions?

 

I tried this a while ago and found that mapping the user data for Google to their home directory and found near on 500mb, sometimes over a 1gb in Google settings.

Posted
I tried this a while ago and found that mapping the user data for Google to their home directory and found near on 500mb, sometimes over a 1gb in Google settings.

 

As much as i remember, theres 2 settings ones the cache and ones the login session, the later used to work fine for me

Posted

Do you still have access to the policies as ive looked through the admx files for Google and struggling to find the right one.

 

This doesnt just apply to Google though, im thinking that Edge will have the same issue too.

Posted
[ATTACH=CONFIG]65434[/ATTACH]h nE5iLcBsCuQAAAABJRU5ErkJggg==

 

https://support.google.com/chrome/a/answer/9866158?hl=en

 

heres the list of wildcards %whatever% from windows wont work

 

I've tested the Set Disk Cache Directory and this doesn't do what i want it to do and in the past i've used the Set User Data Directory which fills up the user's home drive with everything Google Chrome.

 

The cookies aren't stored in the Cache file, they are stored in AppData\Local\Google\Chrome\User Data\DEFAULT\Network

 

What i have found is, ${local_app_data}\ needs to be replaced with *userhomedrive*\ so it would H:\Google_Cache.

 

I'm thinking staff are going to have to put up with logging in with 2fa each time they log off and back on the same computer or we move our profiles to local profiles and set them to delete from the local machine after x days.

Posted
disk cache is all the browsing cache

 

userdata is the profile data iirc

 

Yeah you are right yet the browsing Cache doesn't hold the Cookies.

 

The User data is the one which is huge and pointing that to H:\Google_UserData saves the Cookie information.

 

By setting the User data to a network drive a message box appears in the top right of Google stating the UserData is stored on a network drive and there may be slow downs.

Posted
[ATTACH=CONFIG]65434[/ATTACH]h nE5iLcBsCuQAAAABJRU5ErkJggg==

 

https://support.google.com/chrome/a/answer/9866158?hl=en

 

heres the list of wildcards %whatever% from windows wont work

 

Hang on a minute i see what you have configured here, you have the Google Data going to C:\Users\*Username*\ rather than a network share.

 

Do you run mandatory profiles by any chance because what is happening now is the mandatory profile is removing the C:\Users\*Username*\GoogleUserData folder when an account with a mandatory profile logs in.

  • 8 months later...
Posted
Your facing similar dilemmas to most edu it teams now, where really you should be on 1:1 devices for staff rather than desktops and hotdesking... All this software is designed to work better if you use the same device, rather than roam across multiple desktops... Your fighting a losing battle here sadly. Will only get worse with Win11 and dreaded store apps....
Posted
Local profiles here. Where staff work across a number of different computers, they'll be trusting those for MFA just in the first instance, and thereafter will be prompted just for their Google password to resume Chrome sync if not used recently enough. They won't be being prompted for MFA again unless the device is removed from their list of trusted devices in Google Admin, or gets reimaged.
Posted

We got round it by everyone having a USB Fob and staff are aware they need to use it when they sign into their Google account.

 

There were no real issues, some staff questioned it but the majority just got on with it and accepted the change - which was music to my ears.

 

They understand that they need their fob to get into their account and it's now becoming second nature.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...