petben Posted November 9, 2022 Posted November 9, 2022 Hello, I have been asked to investigate staff MFA onsite (so staff logging into their classroom/office PC were forced to MFA) and we were wondering if other schools do this, and how they approach it. We already have Duo MFA setup for staff when remote 365 and RDP login. I think the obvious problems will be: 1. Staff refusing to use their personal mobiles for school use 2. Personal mobiles being not charged/forgotten etc 3. 4G coverage is very poor where we are 4. Inconvenience for already busy staff 5. Supply staff who move to different computers being asked every lesson for MFA (other staff will probably be Ok to be remembered for 24 hours and will not move computers) Possible ideas: 1. Only forcing MFA on senior staff 2. Providing some/all staff with hardware tokens. How's it working for others?
bezzoh Posted November 9, 2022 Posted November 9, 2022 Asking for trouble.. I use Duo for Admins to log into Servers and thats about it. Also Duo isn't infallible... you either have 'offline access' enabled making it really complex for users to set offline codes, have it never prompt but then no one can login if your internet goes down / anything remotely interrupts connectivity from site to Cisco's online services... or have bypass enabled which means all someone has to do is pull out the network cable to log in without Duo prompting for MFA... (Just saying...) I am interested in your experiences with it for RDP though.. are you successfully using it on the old web site, new web client and Mac/IOS apps? I heard there were limitations to it but haven't tested myself.
free780 Posted November 9, 2022 Posted November 9, 2022 I struggle to see what this is achieving. MFA prompts should only be triggered from new locations or devices (if you allow BYOD). If a bad actor has gained a foothold on your network then you really need defence in depth. Review your Anti-Malware solution and E-Mail filtering solution, given that E-Mail is the main way an attacker gains a foothold. If a bad actor has a foothold and a service account creds MFA isn't going to prevent Ransomware across multiple endpoints. Prehaps see if you can disable SMB and RDP Inbound to clients and any servers that don't require it. 1
free780 Posted November 9, 2022 Posted November 9, 2022 (edited) This also works on Windows 10 and Windows Server 2022 even on prem. RDP can be subject to conditional access. https://techcommunity.microsoft.com/t5/azure-virtual-desktop-blog/announcing-public-preview-of-sso-and-passwordless-authentication/ba-p/3638244 Edited November 9, 2022 by free780 1
FN-GM Posted November 10, 2022 Posted November 10, 2022 MFA prompts should only be triggered from new locations or devices (if you allow BYOD). Personally I disagree with this. 2
psynegy Posted November 10, 2022 Posted November 10, 2022 I am interested in your experiences with it for RDP though.. are you successfully using it on the old web site, new web client and Mac/IOS apps? I heard there were limitations to it but haven't tested myself. So we don't use RDWeb, if that's what you're asking? We have the Duo client on the RDP session hosts. We distribute an RDP file that connects users to a full session, we don't bother with remote apps anymore. We haven't had any issues with any of the various RDP clients connecting in, even the old RDP app for MacOS works fine.
free780 Posted November 10, 2022 Posted November 10, 2022 Personally I disagree with this. Explain more please I’m happy to be wrong.
FN-GM Posted November 10, 2022 Posted November 10, 2022 Explain more please I’m happy to be wrong. Just because the device and the location is the same, who’s to say it’s the actual person sat at the computer? It could have been stolen, it could be another person. Maybe someone else in the office with bad intentions or maybe using someone else’s logins and device to poke into areas they shouldn’t. Maybe a family member at home on a work laptop. 2
colly72 Posted November 10, 2022 Posted November 10, 2022 Just because the device and the location is the same, who’s to say it’s the actual person sat at the computer? It could have been stolen, it could be another person. Maybe someone else in the office with bad intentions or maybe using someone else’s logins and device to poke into areas they shouldn’t. Maybe a family member at home on a work laptop. That's my view too. That's why we've enabled MFA internally for staff. 1
Primus Posted November 10, 2022 Posted November 10, 2022 That's my view too. That's why we've enabled MFA internally for staff. Same view here.
KK20 Posted November 16, 2022 Posted November 16, 2022 we enforce 2FA onsite for anyone with an admin role within the school (I dont mean domain admin - all those roles are help with service accounts - I mean users that have special jobs). We also give those staff a FIDO2 key so they can use that plus set up additional options (I have a fallback to the office phone in case I forget my FIDO2 and ms auth app phone). Otherwise 2FA is enforced outside of trusted location for everyone else. Regular teachers and staff are not forced to 2FA in trusted location. dont forget that VPN + VPN gateway will technically be a trusted location as the traffic will egress from the school. We are hybrid domain so have VPN as a logon option still.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now