Jump to content

Recommended Posts

Posted

Hi all,

 

I am in the process of getting MFA enforced for a school but a sticking point is the lack of access to a device for some staff / not wanting to install apps on a personal one. My suggestion for this was to provide these users with hardware tokens.

 

Is there a particular type you would recommend? Cost isnt a huge issue I am mainly looking for something easy and reliable.

 

Thanks,

Posted (edited)
Yubikey, there are cheaper options but check compatibility with other services you might want to use with first. They also provide the Yubikey manager which might prove handy. Edited by Davit2005
Posted
If it's for a few users only, YubiKeys are a safe bet. FIDO2 keys for passwordless M365 auth, but with the added ability to generate OTP codes as well as a backup option, or for any other systems they might be required to use OTP for.
  • Thanks 2
Posted
You can get the Yubikey Authenticator app then you can have best of both Hardware and TOTP. Other hardware keys might have similar solution. I've setup online services to use a mixture of both in some cases if they only allow one hardware key per account. The Yubikeys have a desktop app too so can use the key to get the TOTP codes which could be handy if no access to a phone..
Posted
Worth mentioning that the cheaper blue-coloured YubiKeys just do FIDO2 stuff, so comparable function to all the other £20ish security keys, whereas the more expensive black ones are the snazzy multi-protocol ones that will allow you to also do OTP.
  • Thanks 1
Posted

We use ClassLink as SSO for all users and that allows you to have different levels of MFA for each user group or individual - For this issue, we avoid devices completely as some staff won't use their own - You can choose from image, PIN etc as well as all the MS/Google authenticators too although they require devices. Problem solved and cheap compared to other options. We have evaluated others, however this does the job. I feel; your pain with the devices issue though. We cannot provide everyone with a mobile (even though some asked!!)

Posted
If staff are unable to MFA because they don't want to install an authenticator app then limit their access to trusted locations, or by all means offer another form of token but at a cost. This whole not on my personal device is a nonsense, I won't use online banking as I don't want to use my personal device to auth... the list goes on! Or indeed not as the case may be, as most would not even give it a second thought when being asked to setup MFA (or use a second factor) for the other accounts in their life. Why when we are protecting our networks is this treated any differently?
  • Thanks 3
Posted
I think it's important to provide options for anyone not wanting to use a personal mobile as a 2nd factor device, without also making them feel as though they need to explain their position. Their device, their choice. Note that "limit their access to trusted locations" is not really a thing that you can do with Google accounts, for instance.
  • Thanks 1
Posted
Yeah I appreciate all those things, and was merely playing devil's advocate. Also was answering in the vain of the posted question so was not including google in scope of my response.
Posted
But now we have pulled google into the fold context-aware access is googles implementation of conditional access, I am not as clued up on these as MS's offering but from my previous experience you are able to set policies based on ip address and second factor auth requirements and such likes. But without dusting off my Google knowledge I will defer any further comments to someone who is knee deep in that cloudy based environment...
Posted
Google's context-aware access doesn't allow you to create a rule equivalent to "Require MFA, except on these IPs/devices". It'll let you stipulate that access is granted if the user has MFA enabled in their account settings, but you can't kind of opt out to MFA under certain conditions. Which is annoying as it means we can't enforce MFA for students (as not 1:1 yet).
  • Thanks 1
Posted
If staff are unable to MFA because they don't want to install an authenticator app then limit their access to trusted locations, or by all means offer another form of token but at a cost. This whole not on my personal device is a nonsense, I won't use online banking as I don't want to use my personal device to auth... the list goes on! Or indeed not as the case may be, as most would not even give it a second thought when being asked to setup MFA (or use a second factor) for the other accounts in their life. Why when we are protecting our networks is this treated any differently?

 

Lots of people have it in their heads that their employer putting MFA tokens on their device allows the employer to spy on them somehow. Or, they resent the idea that an employer is trying to dictate how they use their personal device. I actually have some sympathy for the latter perspective - I see why people might feel that way even if it's a view I personally disagree with.

 

As such, I think that it isn't that unusual for staff to balk at a request to put MFA apps on their personal device - I don't think you can dictate to people that they have to put your software on their device. As such, the school has to have an alternative plan in place - either issuing tokens such as YubiKeys, or simply making it clear to people that access to organisation resources and data without MFA is not going to happen and both the organisation and the employee recognising this may present issues with, e.g., being able to WFH.

  • Thanks 3
Posted
Yeah absolutely and it comes down to how the individual organisations what's to approach this. Let's be certain we should be protecting identities with a separate factor. It's then a policy decision on how that is implemented (if you are going to supply tokens and all that) and like I have said in the past policy should not be the IT departments arena.
Posted
We evaluated these, however as with anything - we thought they may be misplaced, lost etc hence why we went for a PIN for staff. The misplaced bit comes from the amount of times devices have not come into schools when they should have and we had to scramble up a new temp device.
Posted (edited)

we use yubikeys. They are fantastic for using as windows hello logon devices for youngsters. We have them for our infants in the junior school - secure 365 logon and no worry about 5 year olds having resilient passwords...

 

There is some admin time at the start of the year as you might need to delegate access for someone to help with the initial setup but it is worth it in our book. Teachers use them for 2FA if they dont want to use a phone, ironically not many use them as windows hello logons.

Edited by KK20
Posted

YEs same problem here was hoping to run authenticator on the staff chromebooks but then realised they'd have to use authenticator to log into their own chromebook outside of school so that one's not gonna work so well.

 

Will investigate yubikeys now - thanks for the heads up.

Posted
We evaluated these, however as with anything - we thought they may be misplaced, lost etc hence why we went for a PIN for staff. The misplaced bit comes from the amount of times devices have not come into schools when they should have and we had to scramble up a new temp device.

A PIN doesn't really fit with the concept of 2FA. The idea is supposed to be you have something you know, and something you have. Password + Fob. Or Password + Phone etc... Password + PIN would be 2 things you know, and therefore can both be breached without needing to get hold of a physical object.

Posted
I think it's important to provide options for anyone not wanting to use a personal mobile as a 2nd factor device, without also making them feel as though they need to explain their position. Their device, their choice. Note that "limit their access to trusted locations" is not really a thing that you can do with Google accounts, for instance.

 

im sure the paid editions have contextual access now

Posted
They do, but it doesn't allow you to contruct rules for skipping MFA challenges, sadly.

 

Well that seems a bit crap, though being a school id guess id never turn MFA off anyway as the biggest risk will be postit notes getting found by pupils....

Posted
Google contextual access rules are more about "this app or set of files can only be accessed if...", with a condition being something like "user has 2FA enabled".

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...