Jump to content

Recommended Posts

Posted
We've had MFA on for all students from Year 7 upwards for a few years now. It's only really possible because our students are 1:1 with iPads. I feel it will be difficult to force implement it without some sort of 1:1 device setup.
  • Thanks 1
Posted

We've done all students, from Year 7 up since mid 2021. We aren't a 1:1 School, but it's been fairly painless.

 

Will always have edge cases, but we made the call that we can deal with those on a 1:1 basis rather than risk a students account being compromised & an attacker sitting on our system for months.

  • Thanks 2
Posted
Year 7 upwards here too. We use conditional access to prevent MFA when in school - effectively the IP address becomes the 2nd factor. Very little pushback or problems with the students understanding how it works.
  • Thanks 1
Posted

Considering it with pre-seeded tokens at the secondaries.

 

The attrition rate (based on how frequently locker keys are lost) might be a bit high, but it avoids the phone debacle.

  • Thanks 2
Posted

We don't allow mobile phones in school, so internally of course they don't have to do it.

Externally they can use mobiles either via the app or SMS. We also let them use a landline if needed.

 

If students don't have access to any, then they probably have an IT at home need anyway so it's flagged up.

 

We have bought a few 2fa tokens that import into Azure AD if needed as well that we issue if needed (Ultra rare)

  • Thanks 1
Posted
I quite like ClassLink that can use a picture or 6 digit code as the 2nd Form Factor (Students login with their password, then choose a picture from a set of 16 or so), is anyone using this?

 

Looked at it but the CE auditors made very dubious noises as it's just two lots of unchanging information that can be intercepted/shoulder-surfed without the user realising.

 

The second factor should be something ephemeral (regenerated every 30 seconds) or hard to get hold of in a way the user wouldn't notice.

  • Thanks 2
Posted
I quite like ClassLink that can use a picture or 6 digit code as the 2nd Form Factor (Students login with their password, then choose a picture from a set of 16 or so), is anyone using this?

 

That's just for it tho - Not the students main IT accounts (Office 365/GSuite)

  • Thanks 2
  • 2 weeks later...
Posted
We use the pin and images for students and authenticators for staff and Yubikeys for Admins - You can have different levels for each user. I agree that this can be shoulder surfed, but so can entering details - We give users a QR code (something they have) and then they MFA using one of the methods above (something they know) - Here is some more info from their website https://www.classlink.com/solutions/multi-factor-authentication - In practice this works very well and is certainly better than none.
Posted
We use the pin and images for students and authenticators for staff and Yubikeys for Admins - You can have different levels for each user. I agree that this can be shoulder surfed, but so can entering details - We give users a QR code (something they have) and then they MFA using one of the methods above (something they know) - Here is some more info from their website https://www.classlink.com/solutions/multi-factor-authentication - In practice this works very well and is certainly better than none.

 

What's the QR code for?

 

Isn't a pin/static image just a second password?

Posted
What's the QR code for?

 

Isn't a pin/static image just a second password?

 

The QR code is their user name and password to either authenticate into ClassLink which is then backed up by MFA for students staff etc - This is important because they can lose them, get bags stolen or whatever else happens to them too! If using a Windows or Chromebook device they can also use this to authenticate into he device itself - this can be set up and takes them straight to their launchpad! So it cuts out loads of log on issues and means that our smallest users flash the qr code at log in to the device, and then everything we want them to access is SSO from the dashboard they have. So in effect no user name or password to enter at all from the user end - the QR code does that for them.

Posted
So the QR code is their username, and the picture/pin is their password?

Not quite - THE QR code is the username and password - they don't need anything else! (We use this for younger children) For older we use Log in with MS. They are then asked to present some form of MFA - Image (Y1-4), PIN (Y4-13) or Authenticator (staff/admins) - You do not need to have to MFA enabled for students but we do for the reasons above.

 

So they can operate independently. The MFA is just that, and the QR code gets them into the devices (Win and CB)and loads ClassLink straight away if configured or gets them into ClassLink where they can access all their resources from any device.

Posted
OK, so the QR code is someone writing down their username and password on a piece of paper, and the picture/pin is a second password they didn't write down, which is a very easy to brute force password
Posted
To a point, there is an argument to say that with brute force attacks you can almost get you into any system depending on the sophistication of the attack and tool used. The QR code is encryped and no mention of the website to go to, it is simply to help the youngest learners easily access their resources which used to be kept in a teachers notepad at the front of the class and save time in the classroom which our staff wanted us to solve. We don't use it for older children...they can enter their details or use the Log in with MS button in our case. Staff also log in this way (not QR code) and use their MS authenticator (it's not a one size fits all approach) The images change in both location and also what they show every time too so is more than enough for us and better than none! Also, we now do account claiming through this too (started with staff) and now with students so we never have to email or share user details again on paper/using traditional methods so a win win for us.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...