Jump to content

Recommended Posts

Posted

Hi all

 

Finally getting SLT onboard that we need to be doing two factor. We're an O365 school. How have you been doing it? Does everyone *need* the app or can it just be a text? or do you use a physical device?

Posted
We’re also an O365 school. All staff MFA setup using the Microsoft Authenticator App on their mobile phones. Provide USB keys for those staff whose phones cannot have the App (usually due to age of their phone). Those who don’t setup MFA don’t have offsite access to their school account.
  • Thanks 3
Posted
We discourage SMS as its not necessarily secure but will use that as an option as USB tokens I believe MS are no longer going to support.

 

Is there any prospect of MS dropping hardware tokens soon? Is it documented anywhere?

Posted
Picked up from a thread on here, so no credit claimed, but I've tested this browser extension on Edge and Chrome:

 

https://authenticator.cc/

 

It also has a Firefox version and is available through Windows Store as well as from the website.

 

Yeah I saw this on other threads but I didn't know it was a proper viable option. If it is, then great!

Posted

Best: Using a passkey, cross platform, biometric checks, a standard

2nd: Using Google/Android or MS/Authenticator notifications (because there's more options for using biometric checks

3rd: Using TOTP, works offline, requires no wireless signal on phone

4th: Same device TOTP

5th: SMS

  • Thanks 1
Posted
Is there any prospect of MS dropping hardware tokens soon? Is it documented anywhere?

 

My apologies, without setup its been discontinuted due to the national system we use but for normal O365 they will remain, sorry for the confusion.

  • Thanks 1
Posted (edited)
My apologies, without setup its been discontinuted due to the national system we use but for normal O365 they will remain, sorry for the confusion.

 

Thanks for update. I could not see anything either but I would not put it past them. SMS is my least favorite and Push notifications is close.

Edited by Davit2005
Posted
For us it's either Authenticator app or SMS. I use SMS as I don't always have a second device with me, but always have my cellular watch that I can pick up the code from. Might be less secure but is a lot more convenient (for me anyway!)
Posted
Another thing that has come up quite regularly for us is the benefit of having a second MFA method. Everyone thinks they won't lose, break or forget their phone.... Some of you might have the capacity to reset immediately - in our organisation it's usually a two hour turnaround time.
  • Thanks 1
Posted

We deployed 2FA to a Trust - 600 staff rather rapidly.

We sent out a 2-page PDF explaining what 2FA is, why we are doing it, and how to set it up.

 

Preference is Microsoft Authenticator - no other options available.

When we have staff who have an older phone that cannot get the app, we add their phone number ourselves - reluctantly.

 

Gone really well, few issues here and there - but overall fairly smooth.

We also blocked sign-in attempts from abroad for students completely - our logs actually exceed the 250k limit without using Microsoft Graph API. Great success on reducing compromised accounts sending spam emails.

Posted
Preference is Microsoft Authenticator - no other options available.

When we have staff who have an older phone that cannot get the app, we add their phone number ourselves - reluctantly.

What about the member of staff who refuses to use their phone for work stuff? And/or doesn't want to give MS their number?

Posted
What about the member of staff who refuses to use their phone for work stuff? And/or doesn't want to give MS their number?

 

Great point, we raised this to the Exec team and their response was "well, they wont be able to access emails from home then"

So far we have not had any staff with objections to this.

Some disliked it at first, then after explaining that we cannot spy on them, and it is Microsoft and not us - all was well.

  • Thanks 2
Posted

We bought TOTP devices for all staff in our trust 2000+

 

We haven't setup conditional access so they are prompted within school too - our mobile phone policy in schools was that these shouldn't be used and we didn't want staff to be taken personal devices out of their pocket to authenticate at the start of a lesson.

 

Students currently don't have MFA enabled on their accounts, but it may be something we look at doing certainly for external access.

 

The purchase of the TOTP has been a massive financial outlay but the rollout has gone relatively smoothly and other than about 10 staff per week forgetting them it's been relatively painless.

Posted
We use the Microsoft Authenticator app for most of our staff. Some are using SMS. We aren't using TOTP devices because of the cost, especially with replacements.
  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...