Koldov Posted July 13, 2023 Posted July 13, 2023 (edited) New thread from: http://www.edugeek.net/forums/cloud-services/233648-email-security-challenge.html Due to to new information/new questions, but the saga continues... We have found someone who knows about these accounts! However they are an ex-council IT dept. employee, that was part of the move from the LEA in-house IT support for schools, to them all being made redundant when the council dissolved that support dept. and then they all went off and set up a support company, became consultants and were contracted by the council to provide IT support... to schools... Unfortunately, they are 'very busy'... but we have received a response! It turns out that despite my belief that these were 'official' council run email accounts from a sanctioned and managed O365 tenant on an official council owned domain... they are none of these things!!! These were in fact setup by the aforementioned ex-council IT dept. employees (now acting as 3rd party consultants) using a '.sch.uk' domain name (which I will mention, contrary to what I believe is .sch.uk policy, is NOT affiliated to a particular school) for the whole of the LEA. Therefore every individual school using these email accounts for their Headteacher and Admin are just 'users' all in the same tenant on the same domain... So, 'myheadteacher' & '[email protected]' is on the same tenant as 'yourheadteacher' & '[email protected]' The killer line in the response....? 'The @council.town.sch.uk is not managed. So, all this time I have believed these were 'managed' by the council, they have basically been left at the defaults in terms of security, compliance, etc. since about 2014.... And the footer "IMPORTANT: The content of e-mail sent and received is routinely monitored to ensure compliance with policies and procedures. " is a joke at best... Now, it would appear that (forgive me if I get this wrong as I don't deal with it) this means (and bear in mind we haven't been able to access the MAIN admin email account for the school in nearly 2 weeks so need this sorted, like, NOW): 1) Microsoft (not the council) have enabled MFA on this domain (as obviously nobody at the council has done anything on the accounts for years). Q1) Can we turn this off? Because this is the only option we are being given: 2) We can't turn MFA off. Q2) Can we do something else that means our BM can access the account on his computer through Outlook 2016, without having to have the Microsoft authenticator app on his personal phone as it's a generic 'Admin' account (obviously thinking about if they are, on holiday/off sick/leave)...? Edited July 13, 2023 by Koldov
Sadiq_to222 Posted July 13, 2023 Posted July 13, 2023 New thread from: http://www.edugeek.net/forums/cloud-services/233648-email-security-challenge.html Due to to new information/new questions, but the saga continues... We have found someone who knows about these accounts! However they are an ex-council IT dept. employee, that was part of the move from the LEA in-house IT support for schools, to them all being made redundant when the council dissolved that support dept. and then they all went off and set up a support company, became consultants and were contracted by the council to provide IT support... to schools... Unfortunately, they are 'very busy'... but we have received a response! It turns out that despite my belief that these were 'official' council run email accounts from a sanctioned and managed O365 tenant on an official council owned domain... they are none of these things!!! These were in fact setup by the aforementioned ex-council IT dept. employees (now acting as 3rd party consultants) using a '.sch.uk' domain name (which I will mention, contrary to what I believe is .sch.uk policy, is NOT affiliated to a particular school) for the whole of the LEA. Therefore every individual school using these email accounts for their Headteacher and Admin are just 'users' all in the same tenant on the same domain... So, 'myheadteacher' & '[email protected]' is on the same tenant as 'yourheadteacher' & '[email protected]' The killer line in the response....? 'The @council.town.sch.uk is not managed. So, all this time I have believed these were 'managed' by the council, they have basically been left at the defaults in terms of security, compliance, etc. since about 2014.... And the footer "IMPORTANT: The content of e-mail sent and received is routinely monitored to ensure compliance with policies and procedures. " is a joke at best... Now, it would appear that (forgive me if I get this wrong as I don't deal with it) this means (and bear in mind we haven't been able to access the MAIN admin email account for the school in nearly 2 weeks so need this sorted, like, NOW): [ATTACH=CONFIG]69475[/ATTACH] 1) Microsoft (not the council) have enabled MFA on this domain (as obviously nobody at the council has done anything on the accounts for years). Q1) Can we turn this off? Because this is the only option we are being given: [ATTACH=CONFIG]69476[/ATTACH] 2) We can't turn MFA off. Q2) Can we do something else that means our BM can access the account on his computer through Outlook 2016, without having to have the Microsoft authenticator app on his personal phone as it's a generic 'Admin' account (obviously thinking about if they are, on holiday/off sick/leave)...? So currently you don’t have admin privileges over the tenant showing MFA required? If you have admin privileges, In azure Active Directory, go to properties once in your chosen tenant, click manage security defaults and disable security defaults. If you aren’t admin, I think you have to contact MS support from what I’ve seen when I’ve been locked out of one of mine. Hope this helps. 1
psydii Posted July 13, 2023 Posted July 13, 2023 A detail in this makes me wonder whether @steve_forbes recently spotted that domain being used. 1
Koldov Posted July 13, 2023 Author Posted July 13, 2023 So currently you don’t have admin privileges over the tenant showing MFA required? If you have admin privileges, In azure Active Directory, go to properties once in your chosen tenant, click manage security defaults and disable security defaults. If you aren’t admin, I think you have to contact MS support from what I’ve seen when I’ve been locked out of one of mine. Hope this helps. Yes, that's right. So you think this will stop it? A detail in this makes me wonder whether @steve_forbes recently spotted that domain being used. Interesting, I know what you mean but I doubt it (this domain has been up since 2014) and I think it has more to do with the fact that (and forgive me if I'm wrong as I don't deal with email) Microsoft have just recently applied and enabled 'Security Defaults' (which enforces MFA) to the tenant (as iirc that is being rolled out this year)?
Sadiq_to222 Posted July 13, 2023 Posted July 13, 2023 (edited) Yes, that's right. So you think this will stop it? [ATTACH=CONFIG]69479[/ATTACH] Interesting, I know what you mean but I doubt it (this domain has been up since 2014) and I think it has more to do with the fact that (and forgive me if I'm wrong as I don't deal with email) Microsoft have just recently applied and enabled 'Security Defaults' (which enforces MFA) to the tenant (as iirc that is being rolled out this year)? Microsoft enforced security defaults by default back in 2018-2019-2020, can’t remember off the top of my head. Did the user only just notice MFA enforcement notifications? I have that exact option set to disabled on my tenant, and I don’t get MFA notifications. Another thing I would try is go to this link (https://account.activedirectory.windowsazure.com/UserManagement/MultifactorVerification.aspx?BrandContextID=O365) This should show you who has mfa enabled. Worth a shot. Edited July 13, 2023 by Sadiq_to222 1
psydii Posted July 13, 2023 Posted July 13, 2023 Microsoft enforced security defaults by default back in 2018-2019-2020, can’t remember off the top of my head. Did the user only just notice MFA enforcement notifications? Its only been rolling out on old tenants recently. 1
Sadiq_to222 Posted July 13, 2023 Posted July 13, 2023 Its only been rolling out on old tenants recently. Hmmm. This may be because Microsoft haven’t caught up to a certain age of tenants maybe? If the setting in azure is disabled and the option to disable security defaults is there, I see no reason why it would continue to show mfa prompts if that option has been set to disabled. 1
Koldov Posted July 14, 2023 Author Posted July 14, 2023 Its only been rolling out on old tenants recently. Hmmm. This may be because Microsoft haven’t caught up to a certain age of tenants maybe? If the setting in azure is disabled and the option to disable security defaults is there, I see no reason why it would continue to show mfa prompts if that option has been set to disabled. Yes, this tenant has been up since 2014. Unfortunately, although we have been informed that the Security Defaults have been disabled (I have no visibility of this, so can't confirm), we continue to see the MFA set-up prompt! So frustrating! My HT and BM are about to have an actual meltdown!!!
psydii Posted July 14, 2023 Posted July 14, 2023 Can you not request that they forward emails sent to those addresses to a domain/address you do control? and by request, I mean you write the technical bit, and the Head Teacher sends it, 'ccing the Director of Education at the LA?
Koldov Posted July 14, 2023 Author Posted July 14, 2023 Yeah, this was discussed as soon as we realised we had email accounts for the main Admin and Headteacher were in an 'unmanaged' tenant on a domain we don't own (and shouldn't even exist)!! But in all honesty I didn't realise it was going to such a PITA to get sorted and I thought we would be in by today (but then I have thought that every day for the last two weeks - lessons learned I guess), so the 'new' accounts haven't finished being provisioned yet... Anyway, BM has installed the Authenticator app on their phone, so at least it's sorted for now. I mean don't get me wrong, I'm all for MFA and 'securing all the things' and in fact now they have to use it I may get less resistance from SLT, it's just that we hadn't been informed it was being switched on (as nobody was ever going to get the notification), so it took us a while to figure out what was even happening, then find out who the admin was, then get a response, then get them to action anything... And although we probably should have had a strategy for this already, a furious HT and BM who haven't had emails for 2 weeks aren't the best people to have an MFA discussion with!
ZakFarnworth Posted July 14, 2023 Posted July 14, 2023 Yeah, this was discussed as soon as we realised we had email accounts for the main Admin and Headteacher were in an 'unmanaged' tenant on a domain we don't own (and shouldn't even exist)!! But in all honesty I didn't realise it was going to such a PITA to get sorted and I thought we would be in by today (but then I have thought that every day for the last two weeks - lessons learned I guess), so the 'new' accounts haven't finished being provisioned yet... Anyway, BM has installed the Authenticator app on their phone, so at least it's sorted for now. I mean don't get me wrong, I'm all for MFA and 'securing all the things' and in fact now they have to use it I may get less resistance from SLT, it's just that we hadn't been informed it was being switched on (as nobody was ever going to get the notification), so it took us a while to figure out what was even happening, then find out who the admin was, then get a response, then get them to action anything... And although we probably should have had a strategy for this already, a furious HT and BM who haven't had emails for 2 weeks aren't the best people to have an MFA discussion with! Did you disable security defaults? I’d be interested to know why mfa would still be asking them to set it up. This whole office 365 setup you seem to have inherited or discovered is a total mess though 1
Koldov Posted July 14, 2023 Author Posted July 14, 2023 Honestly? I have no idea... I can only really go on what I've been told unfortunately and the message I got was that it had been disabled. Here's a strange thing though... my BM went through the MFA process, downloaded the Authenticator app on their phone and gained access to the account... however, I can now log into the account without MFA! So, I believe yes, it HAS been turned off, however it just got stuck on the fact that it needed MFA to be set up before it allowed non MFA access... if that is even possible? The other thing is that if I try to do any thing else other than view emails, it actually DOES ask for MFA... For example: https://aka.ms/mysecurityinfo ...does require MFA, so I don't know if there are various levels? The thing that really irks me, is that in the last message where it was stated that the Security Defaults had been turned off, we got some push back... with the person stating that it wasn't 'best practise' etc. But they've obviously been happy with us using these email accounts that have never been ‘managed’ in regards to, non-MFA access, security settings/compliance/anti-spam or anti-malware policies (there was nobody checking the ‘postmaster@’ or ‘admin@’ account or dealing with any of the Azure back-end or reading any admin centre messages either), since 2014! Yes, it's a mess and we are going to remove ourselves from it ASAP now we know. However from my research I've found at least 10 other local schools that appear to have Admin/Headteacher accounts on this tenant, so I wonder if I should reach out to their IT support and ask if they're aware...?
ZakFarnworth Posted July 14, 2023 Posted July 14, 2023 (edited) Honestly? I have no idea... I can only really go on what I've been told unfortunately and the message I got was that it had been disabled. Here's a strange thing though... my BM went through the MFA process, downloaded the Authenticator app on their phone and gained access to the account... however, I can now log into the account without MFA! So, I believe yes, it HAS been turned off, however it just got stuck on the fact that it needed MFA to be set up before it allowed non MFA access... if that is even possible? The other thing is that if I try to do any thing else other than view emails, it actually DOES ask for MFA... For example: https://aka.ms/mysecurityinfo ...does require MFA, so I don't know if there are various levels? The thing that really irks me, is that in the last message where it was stated that the Security Defaults had been turned off, we got some push back... with the person stating that it wasn't 'best practise' etc. But they've obviously been happy with us using these email accounts that have never been ‘managed’ in regards to, non-MFA access, security settings/compliance/anti-spam or anti-malware policies (there was nobody checking the ‘postmaster@’ or ‘admin@’ account or dealing with any of the Azure back-end or reading any admin centre messages either), since 2014! Yes, it's a mess and we are going to remove ourselves from it ASAP now we know. However from my research I've found at least 10 other local schools that appear to have Admin/Headteacher accounts on this tenant, so I wonder if I should reach out to their IT support and ask if they're aware...? Weird, it could be that after it’s been disabled it may just need some time to adjust. Personally, if this tenant isn’t being synced to local AD or anything else and Is purely cloud based only. I’d contact the other head teachers and bm’s asking if they use this tenant and if so go from there. Do teachers even have their own email too? If it was me, I’d start again. Each school have your own tenant, even if you only want 2 email accounts. Start again, make note of admin emails, passwords etc for future reference. It may not be in your power to do this, if so leave it to the other folks to sort. Edited July 14, 2023 by ZakFarnworth
Koldov Posted July 17, 2023 Author Posted July 17, 2023 Teachers are on a completely different tenant and domain, it's just these two legacy accounts that are on a tenant/domain that was created by the new '3rd party' I.T. support team (ex LA/LEA) back in the day when the council dropped in-house I.T. support for schools (including the council run email system). Yes, I might contact a few of the other schools and ruffle some feathers (after we have extricated ourselves from the mess, as we still need to remain on good terms with the person who holds the admin for it for now), as I had another thought over the weekend... During my investigation I found that the random (council.town.sch.uk - which shouldn't even exist) domain was created and registered by one of the ex LEA I.T. support team, who now no longer works for the council, the new '3rd party' I.T. support team and does not consult for them either. What powers does the registrant have? That was actually part of @steve_forbes original enquiry in his post wasn't it?
TechMonkey Posted July 17, 2023 Posted July 17, 2023 Liaise with the IT support person to get the domain transferred. If they are unwilling go to the registrar and point out that a commercial entity has taken control of domains that should not be in the hands of commercial entities. Once you have the domain transferred to your tenant you can do what you want with it. I would keep hold of the sch.uk domain, even if it isn't used, as it can be used as identification in certain circumstances and prevents situations like you are in happening.
Koldov Posted July 17, 2023 Author Posted July 17, 2023 I doubt that we would be able to in all good faith, although the registrars were very sympathetic and offered to do just that for us! At least 10 other schools have Headteacher or Admin (or both) email accounts within this O365 tenant on this domain publicised. How many are 'live' and actually being used, I don't know (but I guess I'll find out when I email them all and let them know the situation). Plus although it is registered and that gives it a certain amount of legitimacy, the domain isn't really a 'school' domain and is very generic in terms of its descriptiveness (council.town.sch.uk) so no real use to us once we have transferred those two mail boxes out and into our own.
TechMonkey Posted July 17, 2023 Posted July 17, 2023 Ahh, so these aren't the old @schoolNAME.COUNTY.sch.uk addresses? I'm not sure why they have head or admin addresses. I'd ask for them to be closed down or redirected, update anywhere that may have that address and move on. Not sure I've ever heard of the council.town.sch.uk format and would never have twigged it was a legit school email.
Koldov Posted July 17, 2023 Author Posted July 17, 2023 Ahh, so these aren't the old @schoolNAME.COUNTY.sch.uk addresses? I'm not sure why they have head or admin addresses. I'd ask for them to be closed down or redirected, update anywhere that may have that address and move on. Yeah, that's pretty much the plan! Not sure I've ever heard of the council.town.sch.uk format and would never have twigged it was a legit school email. No, it's totally random and made up, but I think they were based around the school name/county/sch/uk type address (our town is our county if you see what I mean) and close enough to get through any NOMINET checks though. Plus created and registered by ex-council I.T. dept. employee (then I.T. support for schools consultant) which must have given it some legitimacy (?).
steve_forbes Posted August 4, 2023 Posted August 4, 2023 Apologies I've just seen the updates on this post - if I can be of any help (as a Nominet employee) then please do let me know and I'll be happy to try and sort it - although sounds more like a Microsoft issue from the mail perspective?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now