ConceroEdu_Brad Posted September 5, 2023 Posted September 5, 2023 Whats the thoughts on all students having MFA in place or is that overkill?
RLR Posted September 5, 2023 Posted September 5, 2023 We've had MFA on for all students from Year 7 upwards for a few years now. It's only really possible because our students are 1:1 with iPads. I feel it will be difficult to force implement it without some sort of 1:1 device setup. 1
DrCheese Posted September 5, 2023 Posted September 5, 2023 We've done all students, from Year 7 up since mid 2021. We aren't a 1:1 School, but it's been fairly painless. Will always have edge cases, but we made the call that we can deal with those on a 1:1 basis rather than risk a students account being compromised & an attacker sitting on our system for months. 2
colly72 Posted September 5, 2023 Posted September 5, 2023 Year 7 upwards here too. We use conditional access to prevent MFA when in school - effectively the IP address becomes the 2nd factor. Very little pushback or problems with the students understanding how it works. 1
Davit2005 Posted September 5, 2023 Posted September 5, 2023 Uni and all students are MFA with a few exceptions some exclusions on site. 1
pete Posted September 5, 2023 Posted September 5, 2023 Considering it with pre-seeded tokens at the secondaries. The attrition rate (based on how frequently locker keys are lost) might be a bit high, but it avoids the phone debacle. 2
mavhc Posted September 6, 2023 Posted September 6, 2023 What are you using as your second factor?, we've rebanned all students having phones. 1
DrCheese Posted September 6, 2023 Posted September 6, 2023 We don't allow mobile phones in school, so internally of course they don't have to do it. Externally they can use mobiles either via the app or SMS. We also let them use a landline if needed. If students don't have access to any, then they probably have an IT at home need anyway so it's flagged up. We have bought a few 2fa tokens that import into Azure AD if needed as well that we issue if needed (Ultra rare) 1
simpsonj Posted September 6, 2023 Posted September 6, 2023 I quite like ClassLink that can use a picture or 6 digit code as the 2nd Form Factor (Students login with their password, then choose a picture from a set of 16 or so), is anyone using this? 1
pete Posted September 6, 2023 Posted September 6, 2023 I quite like ClassLink that can use a picture or 6 digit code as the 2nd Form Factor (Students login with their password, then choose a picture from a set of 16 or so), is anyone using this? Looked at it but the CE auditors made very dubious noises as it's just two lots of unchanging information that can be intercepted/shoulder-surfed without the user realising. The second factor should be something ephemeral (regenerated every 30 seconds) or hard to get hold of in a way the user wouldn't notice. 2
DrCheese Posted September 6, 2023 Posted September 6, 2023 I quite like ClassLink that can use a picture or 6 digit code as the 2nd Form Factor (Students login with their password, then choose a picture from a set of 16 or so), is anyone using this? That's just for it tho - Not the students main IT accounts (Office 365/GSuite) 2
CTIDTech Posted September 19, 2023 Posted September 19, 2023 We use the pin and images for students and authenticators for staff and Yubikeys for Admins - You can have different levels for each user. I agree that this can be shoulder surfed, but so can entering details - We give users a QR code (something they have) and then they MFA using one of the methods above (something they know) - Here is some more info from their website https://www.classlink.com/solutions/multi-factor-authentication - In practice this works very well and is certainly better than none.
mavhc Posted September 19, 2023 Posted September 19, 2023 We use the pin and images for students and authenticators for staff and Yubikeys for Admins - You can have different levels for each user. I agree that this can be shoulder surfed, but so can entering details - We give users a QR code (something they have) and then they MFA using one of the methods above (something they know) - Here is some more info from their website https://www.classlink.com/solutions/multi-factor-authentication - In practice this works very well and is certainly better than none. What's the QR code for? Isn't a pin/static image just a second password?
CTIDTech Posted September 22, 2023 Posted September 22, 2023 What's the QR code for? Isn't a pin/static image just a second password? The QR code is their user name and password to either authenticate into ClassLink which is then backed up by MFA for students staff etc - This is important because they can lose them, get bags stolen or whatever else happens to them too! If using a Windows or Chromebook device they can also use this to authenticate into he device itself - this can be set up and takes them straight to their launchpad! So it cuts out loads of log on issues and means that our smallest users flash the qr code at log in to the device, and then everything we want them to access is SSO from the dashboard they have. So in effect no user name or password to enter at all from the user end - the QR code does that for them.
mavhc Posted September 22, 2023 Posted September 22, 2023 So the QR code is their username, and the picture/pin is their password?
CTIDTech Posted September 22, 2023 Posted September 22, 2023 So the QR code is their username, and the picture/pin is their password? Not quite - THE QR code is the username and password - they don't need anything else! (We use this for younger children) For older we use Log in with MS. They are then asked to present some form of MFA - Image (Y1-4), PIN (Y4-13) or Authenticator (staff/admins) - You do not need to have to MFA enabled for students but we do for the reasons above. So they can operate independently. The MFA is just that, and the QR code gets them into the devices (Win and CB)and loads ClassLink straight away if configured or gets them into ClassLink where they can access all their resources from any device.
mavhc Posted September 22, 2023 Posted September 22, 2023 OK, so the QR code is someone writing down their username and password on a piece of paper, and the picture/pin is a second password they didn't write down, which is a very easy to brute force password
CTIDTech Posted September 29, 2023 Posted September 29, 2023 To a point, there is an argument to say that with brute force attacks you can almost get you into any system depending on the sophistication of the attack and tool used. The QR code is encryped and no mention of the website to go to, it is simply to help the youngest learners easily access their resources which used to be kept in a teachers notepad at the front of the class and save time in the classroom which our staff wanted us to solve. We don't use it for older children...they can enter their details or use the Log in with MS button in our case. Staff also log in this way (not QR code) and use their MS authenticator (it's not a one size fits all approach) The images change in both location and also what they show every time too so is more than enough for us and better than none! Also, we now do account claiming through this too (started with staff) and now with students so we never have to email or share user details again on paper/using traditional methods so a win win for us.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now