Jump to content

Recommended Posts

Posted

Hello, I have been asked to investigate staff MFA onsite (so staff logging into their classroom/office PC were forced to MFA) and we were wondering if other schools do this, and how they approach it. We already have Duo MFA setup for staff when remote 365 and RDP login.

 

I think the obvious problems will be:

1. Staff refusing to use their personal mobiles for school use

2. Personal mobiles being not charged/forgotten etc

3. 4G coverage is very poor where we are

4. Inconvenience for already busy staff

5. Supply staff who move to different computers being asked every lesson for MFA (other staff will probably be Ok to be remembered for 24 hours and will not move computers)

 

Possible ideas:

1. Only forcing MFA on senior staff

2. Providing some/all staff with hardware tokens.

 

 

How's it working for others?

Posted

Asking for trouble..

 

I use Duo for Admins to log into Servers and thats about it. Also Duo isn't infallible... you either have 'offline access' enabled making it really complex for users to set offline codes, have it never prompt but then no one can login if your internet goes down / anything remotely interrupts connectivity from site to Cisco's online services... or have bypass enabled which means all someone has to do is pull out the network cable to log in without Duo prompting for MFA... (Just saying...)

 

I am interested in your experiences with it for RDP though.. are you successfully using it on the old web site, new web client and Mac/IOS apps? I heard there were limitations to it but haven't tested myself.

Posted

I struggle to see what this is achieving.

 

MFA prompts should only be triggered from new locations or devices (if you allow BYOD). If a bad actor has gained a foothold on your network then you really need defence in depth.

 

Review your Anti-Malware solution and E-Mail filtering solution, given that E-Mail is the main way an attacker gains a foothold.

 

If a bad actor has a foothold and a service account creds MFA isn't going to prevent Ransomware across multiple endpoints.

 

Prehaps see if you can disable SMB and RDP Inbound to clients and any servers that don't require it.

  • Thanks 1
Posted
I am interested in your experiences with it for RDP though.. are you successfully using it on the old web site, new web client and Mac/IOS apps? I heard there were limitations to it but haven't tested myself.

 

So we don't use RDWeb, if that's what you're asking? We have the Duo client on the RDP session hosts. We distribute an RDP file that connects users to a full session, we don't bother with remote apps anymore.

 

We haven't had any issues with any of the various RDP clients connecting in, even the old RDP app for MacOS works fine.

Posted
Explain more please I’m happy to be wrong.

 

Just because the device and the location is the same, who’s to say it’s the actual person sat at the computer?

 

It could have been stolen, it could be another person. Maybe someone else in the office with bad intentions or maybe using someone else’s logins and device to poke into areas they shouldn’t. Maybe a family member at home on a work laptop.

  • Thanks 2
Posted
Just because the device and the location is the same, who’s to say it’s the actual person sat at the computer?

 

It could have been stolen, it could be another person. Maybe someone else in the office with bad intentions or maybe using someone else’s logins and device to poke into areas they shouldn’t. Maybe a family member at home on a work laptop.

 

That's my view too. That's why we've enabled MFA internally for staff.

  • Thanks 1
Posted

we enforce 2FA onsite for anyone with an admin role within the school (I dont mean domain admin - all those roles are help with service accounts - I mean users that have special jobs). We also give those staff a FIDO2 key so they can use that plus set up additional options (I have a fallback to the office phone in case I forget my FIDO2 and ms auth app phone). Otherwise 2FA is enforced outside of trusted location for everyone else. Regular teachers and staff are not forced to 2FA in trusted location.

 

dont forget that VPN + VPN gateway will technically be a trusted location as the traffic will egress from the school. We are hybrid domain so have VPN as a logon option still.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...