5tu Posted October 31, 2023 Posted October 31, 2023 (edited) This statistic from Microsoft's Digital Defense Report 2023 gives me the shivers as many schools, ours included, allow students and staff to access data in 365 from unmanaged devices. I'd be really interested to learn from schools who have decided to only allow access to 365 data from managed school devices, or who have managed to implement device management controls on BYOD devices and how this has been received by users. Edited October 31, 2023 by gybe78
midweek Posted October 31, 2023 Posted October 31, 2023 You're not alone! There are so many things in that report that would be relatively easy to fix in a corporate setting that are so difficult to get senior management to agree to in a school - MFA for pupils? Providing corporate owned and managed devices for all staff and pupils? Or forcing staff/pupils to enroll their personal devices into a managed device solution?
jthompson Posted October 31, 2023 Posted October 31, 2023 If I was feeling ungenerous I'd quip that 80-90% of compromises involve a Microsoft email account at some point too, on the attack and/or target side. I can't cite any actual stats, but it feels about right. We're not big users of M365 here, and so our licensing doesn't include the sorts of security features that Microsoft will be promoting as essential in order to actually operate securely. Conditional access and endpoint verification stuff will help to allow 'safe enough' use of unmanaged devices, I should think. Like "refuse sign-ins from devices with an unsupported OS". I, too, would be interested to here from those who are actually doing this stuff.
midweek Posted October 31, 2023 Posted October 31, 2023 We have A3 licensing so can do some of this stuff, like conditional access forcing MFA for staff or blocking access by location, but it's only "safe enough" until it isn't I suppose. MS are shifting or creating a lot of their advanced security stuff into higher tier licensing models or add-ons which is annoying.
ITGuyNW Posted October 31, 2023 Posted October 31, 2023 We have A3 licensing so can do some of this stuff, like conditional access forcing MFA for staff or blocking access by location, but it's only "safe enough" until it isn't I suppose. MS are shifting or creating a lot of their advanced security stuff into higher tier licensing models or add-ons which is annoying. Yeah I'm in limbo at the moment because we were about to move to MFA then Microsoft moved the goalposts, so currently re-evaluating the options.
robintech Posted October 31, 2023 Posted October 31, 2023 Seems very hard to enforce unless you hand out devices to staff and students 1:1 , which would make life a lot easier, perfect world would be a phone and laptop for everyone. Wonder if all the Mcafee expired trials would cause an issue for our students and staff
supportman Posted November 2, 2023 Posted November 2, 2023 Just setup conditional access. We've done it to lock down to the UK and a couple of other types of devices. Works very well.
5tu Posted November 2, 2023 Author Posted November 2, 2023 (edited) Just setup conditional access. We've done it to lock down to the UK and a couple of other types of devices. Works very well. We have conditional access policies in place to protect user login. But currently a genuine user can login to 365 services on an unmanaged device which is unknown and untrusted. If the device is riddled with malware then data in 365 is at risk. I've just come across App Protection Policies in Intune which go a long way to mitigating risk on non-MDM enrolled iOS and Android devices, but it doesn't address unmanaged Windows devices (as far as I understand it). Edited November 2, 2023 by gybe78
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now