Jump to content

Recommended Posts

Posted

Hi all,

 

I'm doing some more research for the National Cyber Security Centre on secure cloud configurations with a focus on Google Workspace for Education and Office 365.

I'm hoping the collective mind within Edugeek can help validate my statements below:

 

  1. The majority of schools now have one or both of these services but they may have been configured some time ago and not necessarily by an expert, therefore they may be insecure
  2. There are still cases where brand new cloud tenancies are created for migrations etc
  3. Even if setting up a new tenant today, the default configurations are not sufficient to ensure the school's data is secure

 

Does anyone have any thoughts on the above statements, any additional information would be very useful. If there is a proven need then I am hoping to get some NCSC and Microsoft/Google approved configuration guidelines that include options for additional security if licences have been purchased.

If there are areas that could be improved by changing default settings then we can also lobby the cloud provider to do so.

 

Thanks

Steve

Posted (edited)

Edit: Office 365

I'm not sure if this matches Security but the defaults for being set for a School instead Business would be nice, the default setup from what I remember encourages them to create groups and share outside the organisation with "Anyone"

Edited by ittech2342323
Posted
I'm not sure if this matches Security but the defaults being set for a School instead Business would be nice, the default setup from what I remember encourages them to create groups and share outside the organisation with "Anyone"

 

Thank you - that's useful as I think that constitutes a pretty big security risk!

Posted (edited)

Google Workspace certainly has a feel of being too liberal by default. It feels like Google have designed it with the assumption that users are responsible, professional, adult employees, so things are allowed by default unless more restrictive configuration is opted for. As schools, we prefer to work on a "restrict by default" basis where users can not be considered to be particularly responsible agents.

 

The biggest issue for me is that all of the various kinds of third-party add-ons, extensions and apps that can use Google Workspace data are allowed by default, when schools really ought to have all of that restricted with an allowlist. That's mainly a data protection thing, but it's also a security thing as well. It would be easy for Google to block all of that and then allow admins to opt in to third-party integrations. I can imagine Google having a strong business case for not doing that, however.

Edit: I take that back. It appears that third-party apps are blocked by default for Education tenancies. https://apps.google.com/supportwidget/articlehome?hl=en-GB&article_url=https%3A%2F%2Fsupport.google.com%2Fa%2Fanswer%2F6089179%3Fhl%3Den-GB&assistant_id=generic-unu&product_context=6089179&product_name=UnuFlow&trigger_context=a

 

Another example off the top of my head is Admin > Gmail > End-user access > Automatic forwarding, which is on by default. Perhaps more of a data protection thing again, but an example of a default configuration being too liberal for schools.

 

I can't remember what the default configuration is for Drive/Docs sharing outside of the domain, but if that were to allow sharing outside of the domain (or collaboration on external content), then that would be too liberal as well.

 

Gmail security can be tightened up in various ways. The various anti-spam settings are not especially strict by default. Some of the Gmail security is not really able to be done by Google alone, though. DKIM, DMARC and MTA-STS are all things that schools can definitely benefit from, and tbf Google does a good job of promoting those features and guiding admins through getting them configured.

Edited by jthompson
  • Thanks 1
Posted

Just for info - API access on Google Workspace has recently been changed to Whitelist by default for Edu customer.

 

I've worked with O365 and Google Workspace - both need careful setup. However, both also give detailed guidance on how to setup on how to set things up to be secure by default. But this does require whoever is setting it up to either know what they are doing or read the instructions.

  • Thanks 1
Posted

Yep, I would agree about carefuly setup. If I were setting up a new GW tenancy today, I'd be going through every single option in turn and working out what it needs to be set at for each OU.

 

But then I say that without being able to actually point to anything much in particular, as it turns out, since I haven't built a new Google domain for years. So I don't know how helpful that is for this research!

  • Thanks 1
Posted

Definitely agree with the "assumes all people are adults" defaults, including the "why haven't you turned on MFA for ~1800 children" nag screens.

 

However, the "these are children" options (Teams, for example) are too restrictive for older students doing video interviews with prospective Uni/apprenticeship/employers. It seems like a token effort at best.

 

Other issues include:

 

  • 365 - Inconsistent labelling of what security options / remediation options cost extra on top of current licensing. Sometimes it's up-front (can turn on a "already have license?" filter), sometimes it's four clicks deep before you hit "you need X license".
  • Configuration drift due to the rate of change for 365 and Azure. Secure settings can become insecure because "we migrated your settings to the new portal and settings X,Y & Z are no longer available / cost money now".
  • Compliance search tools (the ability to search Teams, for example) becoming "paid-for" options with associated impact on safeguarding and budget.
  • Third party suppliers of licensing request excessive permissions (ability to create accounts and reset passwords, for example) within 365 because MS documentation** on the access required to add / sell licenses is awful. Risk of supply chain attack increases.

 

*not that I'm expecting you to solve that - Microsoft have had decades and still can't.

  • Thanks 1
Posted

The Office 365 NEW default security configuration now includes using 2FA for all users... The issue is schools don't want to use 2FA with pupils. This means that unless a school purchases upgrades all users use it without 2FA.

 

(yes you can use personal 2FA but that is being deprecated and will not be supported much longer)

 

Office 365 does have the "Microsoft Secure Score" for admins to tighten security, that although is somewhat useful is really an upsell machine for higher tier subscriptions.

  • Thanks 1
Posted

I have not found it easy to manage an inherited Google Workspace for Edu (that was setup by a teacher), and am still spending a disproportionate amount of time poking about. I've probably missed loads.

 

.

  • Thanks 1
Posted
I have not found it easy to manage an inherited Google Workspace for Edu (that was setup by a teacher), and am still spending a disproportionate amount of time poking about. I've probably missed loads.

 

It does help if you manage another Google Workspace system that you can check against.

  • Thanks 1
Posted
It does help if you manage another Google Workspace system that you can check against.
Google adding some Inline tips in Admin along the lines of "NCSC recommends this setting" would be nice. Never gonna happen, but nice.
Posted (edited)

1) Yes 10 years ago. We have tightened many things up. We have E5 and try to improve one or two things every few months. We have hooked 365 and Google Apps, AD, AAD and endpoints into cloud app security/ defender so threats are tracked and alerted upon. Defender seems to mostly handle itself. That said our Microsoft Security Score seems to be holding at a steady level despite gradually implementing recommendations.

 

Obviously there is a balance between a system that is fully secure and one that is usable and fit for purpose. I don't feel that we particularly have a problem walking that line. I'm sure a red team would rip right through us if they tried.

 

Screenshot 2023-05-26 114625.png

Edited by psydii
Posted

I don't have a specific issue with the default configurations, a few thoughts though:

 

As others mentioned there is difficulty analysing a domain and comparing to default config. The API's for Office 365 and Google workspace are available to all, so a method to check for configuration drift and provide a base config as code would be helpful. (A well maintained terraform provider would be most welcome).

 

The extra (paid) option to save data in UK regions should be unacceptable from a GDPR perspective if we want data location to be secure (Google Workspace)

 

Lack of options on O365 when adding third party applications (this may be fixed, I've not managed an O365 domain for nearly two years) IIRC there was a significant issue with allowing users to install third party apps which then allowed access to onedrive/ all users emails/ personal info etc - Google did a much better job because you could deny access based upon what access the application needed, but it does need some configuration and I forget the defaults. Most schools will just block this or allow a whitelist, it's an issue when staff tell students to install X,Y,Z that then gives a company access to all the users details.

 

I also recall there was an issue whereby 0365 users could use the SMTP server in their domain to spoof emails from another domain that they don't own. You had to use some telnet trickery but I certainly recall sending an email from #random-school when using the O365 relay. I was working in Unix support at the time and the Windows team didn't even seem to comprehend the issue, so it's entirely likely it was an internal misconfiguration - still it was a bit worrying that could even happen.

  • Thanks 3
Posted (edited)

It does seem like some PowerShell to configure your environments would be useful for Office 365 for buildings suggested secure configurations.

 

It would be good if there was some input from the Cyber security lead at Harris Federation.

Edited by nicholab
Posted

One point I've not seen raised; this is not a 'set once and forget' arrangement. Office365 configs are tending towards more secure (e.g. blocking basic auth) but at the same time new functionality is being offered and sometimes it's mind-numbingly daft (e.g. allowing end users to buy their own services!)

 

There needs to be a on going process which gathers together updates (both from official microsoft sources and chatter on twitter etc) to determine changes. Then

 

1) how can our organisation benefit from this

2) Is this a threat to our organisation and how should we tackle it

 

Point 1 is individual to each organisation, but point 2 could be looked at in a broader scope.

  • Thanks 2
Posted

I'm going to jump in quickly now to share a few things I (and many others) have covered before. What we are really talking about is understanding Security by Design and by Default and Privacy by Design and by Default.

As any cloud ecosystem grows and changes there will be things that need to be adapted. The problem is having a baseline to start with, and then having an understanding of why it is this way. As an EdTech vendor, I'll hold my hands up and say that this is not always easy, and since a number of cloud services that get used within education have come from a consumer base originally, it can be even harder. I know I bang the drop about how important helping schools with this is (indeed, my day job involves me writing this up and trying to find ways to make it better), but for this to change we *really* need to see widespread engagement with this.

 

If I was to ask everyone here what the key principles they wanted to see with any new cloud system, what would be the top 3?

 

Zero Trust? Granularity in controls/permissions? Clear information labelling? Encryption? Integration controls? Readable agreements? AI to identify gaps? I know there could be a lot more (hmmmm ... poll time?) but I am interested to hear what all of you are finding as the requirements, and the subsequent approaches we all take as a result of what we are given when cloud services finally get handed over.

Posted
If I was to ask everyone here what the key principles they wanted to see with any new cloud system, what would be the top 3?

 

Zero Trust? Granularity in controls/permissions? Clear information labelling? Encryption? Integration controls? Readable agreements? AI to identify gaps? I know there could be a lot more (hmmmm ... poll time?) but I am interested to hear what all of you are finding as the requirements, and the subsequent approaches we all take as a result of what we are given when cloud services finally get handed over.

 

  • Readily available accurate and properly maintained documentation organised coherently in one place.
  • Change modelling/reporting before making the change. If I change X, what's the impact on Y and Z? Does anything change that I wouldn't expect to?
  • Current config vs baseline config comparison. How much drift? Of that drift, how much is against best practices/deprecated/problematic? Is there a better way of achieving something now the product/feature has matured a bit?

Posted

Do you think Google are reading this and following the ideas, just had the following email.....

 

With these enhancements, we're requiring that you review and confirm access settings for third-party apps that are currently accessible to your users (configured apps) by Oct 23, 2023. **You’ll do this via a guided experience in Admin Console, where we’ll take you step by step to review and confirm settings. If needed, you’ll be able to make changes before confirming settings.** Keep in mind that you’re responsible for obtaining parental consent, as required, before allowing users designated as under 18 to access third-party apps. Learn more

Posted
Do you think Google are reading this and following the ideas, just had the following email.....

 

With these enhancements, we're requiring that you review and confirm access settings for third-party apps that are currently accessible to your users (configured apps) by Oct 23, 2023. **You’ll do this via a guided experience in Admin Console, where we’ll take you step by step to review and confirm settings. If needed, you’ll be able to make changes before confirming settings.** Keep in mind that you’re responsible for obtaining parental consent, as required, before allowing users designated as under 18 to access third-party apps. Learn more

 

That was planned a while ago. It has been a discussed item within one Google edu group for about 2 years now ... if not a bit longer. It has been included in their guidance for some time and discussed on here previously too, IIRC. The difficulty I have is the terms they use. Some of the apps are indeed third-parties ... nothing to do with the school and users are just using their school account as part of login/verification. These are the ones that should be blocked asap. If there are some you are happy for users to keep on using, then yes ... consent will be needed and there will be things from the Children's Code to consider too ... but that is a completely separate conversation and speak to your DPO on that one!

 

Others will be services you buy into which you use the Google accounts as SSO (NetSupport's classroom.cloud integration with Google Workspace and M365 is an example). Unfortunately, because of the common language used in Regions, they get lumped in with 'third-parties'. These are the service providers who should be able to give you instructions about how to ensure that any integration remains working during the above change. This is why you need to review what is in the list of apps using you for sign-on and making sure you only allow the ones you want ... but please make sure you discuss this with DPO, DSL and relevant senior leaders ... have a comms plan in place to let people know of the change and give others a chance to come forward with things they still want to access. They may not be granted permission to have that integration ... but better to have them come forward. I've got a guide on this somewhere that I have previously shared on some google groups. I'll see what I can dig out.

  • Thanks 1
Posted
That was planned a while ago. It has been a discussed item within one Google edu group for about 2 years now ... if not a bit longer. It has been included in their guidance for some time and discussed on here previously too, IIRC. The difficulty I have is the terms they use. Some of the apps are indeed third-parties ... nothing to do with the school and users are just using their school account as part of login/verification. These are the ones that should be blocked asap. If there are some you are happy for users to keep on using, then yes ... consent will be needed and there will be things from the Children's Code to consider too ... but that is a completely separate conversation and speak to your DPO on that one!Others will be services you buy into which you use the Google accounts as SSO (NetSupport's classroom.cloud integration with Google Workspace and M365 is an example). Unfortunately, because of the common language used in Regions, they get lumped in with 'third-parties'. These are the service providers who should be able to give you instructions about how to ensure that any integration remains working during the above change. This is why you need to review what is in the list of apps using you for sign-on and making sure you only allow the ones you want ... but please make sure you discuss this with DPO, DSL and relevant senior leaders ... have a comms plan in place to let people know of the change and give others a chance to come forward with things they still want to access. They may not be granted permission to have that integration ... but better to have them come forward. I've got a guide on this somewhere that I have previously shared on some google groups. I'll see what I can dig out.

 

Thanks for all the advice @GrumbleDook, very helpful.

  • Thanks 1
Posted
2FA can be targeted to groups of users, so you can exclude students and also enable conditional access so 2FA won't apply with devices when they are used in school.
Posted
2FA can be targeted to groups of users, so you can exclude students and also enable conditional access so 2FA won't apply with devices when they are used in school.

 

I thought that targeted 2fa on 365 was not part of the free version, and conditional access was not part of the free Google Workspace version.

 

I always thought that these security systems should be free for schools, after all, being able to say your system is more secure for schools than the competitors is a win win.

Posted

Not necessarily a 'security risk' but I would love it if the likes of Microsoft end up taking some of this feedback on board that a school isn't a business.

 

Even using something like Teams for Education you still end up with the Teachers first names all over the channels when they comment or upload a document !

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...