Jump to content

Recommended Posts

Posted

Hi all,

 

As you may know Microsoft have enforced users to setup a MFA on their accounts.

 

I am attempting to disable this feature for my students as many of them do not own additional devices to set this up.

 

I attempted to see if I could remove this from Office 365 admin center. Users > Active users. >Multi-factor authentication. I have ensured they are all disabled.

 

However they are they are still receiving 2-factor authentication request upon signing in.

 

Any ideas?

 

Many thanks

Posted (edited)
Have you risk assessed this. A compromised student email account could as much as a concern as a compromised staff account these days. Conditional access can be used if you O365 plan includes it but defo worth a look. Edited by Davit2005
  • Thanks 1
Posted
Easy risk assessment to do really. It is fairly impossible to have MFA with children. Its either unaffordable to issue physical fobs to them all, or impractical to have them all use personal phones - not to mention the security risk of having all those phones in school as well (especially in light of the various govt ministers being pro-banning phones in schools entirely). Then add in the fact that not all children are old enough to have a phone etc, and the idea of MFA for children is a non-starter.

 

True , we don't know the age range of students in this case so might be a bearing. Also possibility of enabling MFA but conditional access to override whilst at school a possibility.

Posted (edited)
As you may know Microsoft have enforced users to setup a MFA on their accounts.

 

As far as I could find out, Microsoft are only doing this on recently created Tenants. Whether this is 1, 2 or 3+ years old, I'm not sure. Ours is 9 years old and Microsoft have left ours alone.

 

Once you've risk-assessed this (as mentioned above), you'll need to go to your Azure Active Directory, go to Overview, click the Properties tab and down the bottom of the page is a section called "Security defaults". It'll most likely be enabled for your Tenant and this enforces MFA for all users in the Tenant. If you're truly okay with turning this off, change it to Disabled and click on Save at the bottom of the window. That should hopefully take away the enforcement and allow you time to set MFA up at a later date.

Edited by MrEprise
  • Thanks 1
Posted

yes, as above, security defaults... MFA for all users or NONE. Personal MFA is ending support, if you want to MFA your staff, you'll have to stump up the money.

 

I agree MFA for pupils is an unbelievable burden, even if you manage the "no MFA" from the school network, they need support at home x 1000+ pupils... no thanks.

Posted (edited)

I know this has been discussed a lot, especially with the newer set of requirements for Cyber Essentials this year with the inclusion of MFA for all accounts etc.

 

Multi-Factor Authentication (MFA)

As well as providing extra protection for passwords that are not protected by other technical controls (above), multi-factor authentication should always be used to provide additional protection to administrative accounts, and accounts that are accessible from the internet.

 

The password element of the multi-factor authentication approach must have a password length of at least 8 characters, with no maximum length restrictions.

 

There are four types of additional factor that may be considered:

 

• A managed/enterprise device

• An app on a trusted device

• A physically separate token

• A known or trusted account

 

Additional factors should be chosen so that they are usable and accessible. This may require user testing to verify if a factor is suitable for the users. For more information see NCSC’s guidance on MFA.

 

As mentioned, unless you have Azure P1/P2, you are ultimately left with MFA on for all users, or not. Whereas conditional access will allow some 'sliding scale' of implementation. One way, could be to exclude Trusted Locations (e.g. your school's ISP IP). However you could expand on that to also require access via a managed (e.g. school) device.

 

Device Scoping Table.jpg

Edited by MYK-IT
Posted
The other approach which will require a P1 licence to all staff is to deny access for students off site. Maybe restrict access only from the UK. Not perfect but reduces the risk. A compromised student account can be used for recon to try and phish staff. Restricting the Azure Management enterprise application to site and maybe allow users access with MFA setup would reduce the attack surface.
  • Thanks 1
Posted
Can't you setup a federation from O365 with Google, use google MFA for staff and either leave the student MFA auth off or use a browser plugin once the students have logged in based on IP restriction ?
Posted

where possible we enable on both student and staff accounts. only 2 so far we've disabled so not disadvantaging off site.

It only takes one account without 2FA to be compromised and it's almost always we find it's student accounts being compromised when issues arise.

  • Thanks 1
Posted

Could anyone share a link to an announcement from Microsoft about this please? I can’t find where Microsoft have said they are forcing all users to have MFA enabled.

 

Thanks

Posted
where possible we enable on both student and staff accounts. only 2 so far we've disabled so not disadvantaging off site.

It only takes one account without 2FA to be compromised and it's almost always we find it's student accounts being compromised when issues arise.

 

A trick we used pretty early on (thanks to an Azure AD P1 I think) was to require MFA for accounts logins that have a risk level of "medium" or above, for users who aren't MFA enabled this just blocks the logon.

Posted

I think I have shared this before, however we do have MFA for all accounts including students using a PIN or Image with no additional devices or key fobs required. We layer this so primary school children (up to year 4) use an image and all others use a PIN - Staff and admins use their authenticators.

 

We did this through ClassLink as agree with the comments above, a compromised account is still a compromised account and possibly worth a look for some. ClassLink | MFA & Authentication Methods I believe they are also bringing in QR code sign in in to windows machines too (they already do this for chromebooks) with MFA so saving more time and effort from September.

Posted
I think I have shared this before, however we do have MFA for all accounts including students using a PIN or Image with no additional devices or key fobs required. We layer this so primary school children (up to year 4) use an image and all others use a PIN - Staff and admins use their authenticators.

 

If it is not something you have (a fob, a phone etc...), and is just a second "something you know" it is not MFA. It just a 2 part password, and doesn't really add any appreciable extra security to the system - someone can get both the password and pin/image choice without the user knowing and breach the account.

Posted

What does this mean for orgs who only have the basic 0365 edu/ Azure AD Basic Edu? Ours is still set to disabled (not recommended) - we do not have conditional access as we do not have P1 etc.. I have MFA enabled per user for our IT Staff.

 

I am looking to move to Microsoft 365 A3 in the future, to give us P1 bundled in + o365 desktop apps.

Posted

Officially: buy E3 for all staff.

 

In practice, a Microsoft Licensing partner will probably find you a solution, and its up to you if you take it.

  • 10 months later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...