KK20 Posted May 20, 2022 Posted May 20, 2022 We currently use conditional access for staff and pupils. Staff have conditional access for MFA in non trusted locations. Pupils do not (yet). Trusted locations are our school IPs only and this works fine for us. Pupils dont have enforced MFA, however we do have location conditional access limited to UK connections only. Its a crutch and not ideal but is better than nothing at the moment. However from what I can tell, conditional access kicks in AFTER a successful login. My idea is that some of our pupils are being absolutely hammered with external attempts from all over the world, this can cause a problem with account locking as these external attempts can happen at any point in the day. Ideally I would have liked the process to be: 1) attempt to login was made 2) conditional access checks location 3) conditional access fails location check 4) dont bother trying to check credentials, just send the usual username/password might not be correct - i.e. the phisher doesnt know if it was a correct u/n or p/w or conditional access What appears to be happening is: 1) attempt to login was made 2) credential check is made - this will increment the "x number of checks in y minutes" 3) conditional access checks location 4) response given to client. Obviously point (2) is the issue with this approach. MFA solves this because point (1) requires MFA to continue so you never get an account lock issue. But we cannot enforce MFA with pupils as not all will have capable phones and we cant afford to give everyone FIDO2 keys. How does everyone else deal with random login attempts and account locking?
chaplic Posted May 20, 2022 Posted May 20, 2022 CA is post-authentication. Do you have a lockout session too low. Do you even need it? Password spray is an issue where lockouts won't help, but no-one is brute-force guessing passwords.
KK20 Posted May 20, 2022 Author Posted May 20, 2022 (edited) Lockout is default of 10 with 60 seconds lockout. Attempts on one particular user is approximately 10 per minute in bursts, all from vietnam/far east area. Obviously with azure AD the first unsuccessful attempt after a lock is also a relock. Luckily this user is a fairly savvy 6th former so what I have done is given them a FIDO2 key and manually added MFA to them. That pretty much squashed the issue but there will be others. the irony of all this is our firewall used to geoblock so when we were fully onsite this was not such much of an issue... Edited May 20, 2022 by KK20
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now