Jump to content

Recommended Posts

Posted
Silly question..

 

If you were rolling out the Google Authenticator app, would you advise them to use their own gmail account to sign into the app or a school one?

 

If it's an Android phone it will probably sign their personal account in automatically, but they can add another account.

  • Thanks 1
Posted

I'd have thought either:

  • a personal account, so that any other personal accounts that they might have secured against the app are not then going to encounter any issues when they leave the organisation.
  • or the work account if an Android work profile is being used. A separate instance Google Authenticator installed in the work profile to be used just for work accounts. If they also have an instance of the app in their personal profile, then they use that for their non-work accounts.

Posted
I'd have thought either:

  • a personal account, so that any other personal accounts that they might have secured against the app are not then going to encounter any issues when they leave the organisation.
  • or the work account if an Android work profile is being used. A separate instance Google Authenticator installed in the work profile to be used just for work accounts. If they also have an instance of the app in their personal profile, then they use that for their non-work accounts.

Presumably will all be set up in such a way that you don't need to log into your work account to access the authenticator to be able to log into your work account.

Posted
Silly question..

 

If you were rolling out the Google Authenticator app, would you advise them to use their own gmail account to sign into the app or a school one?

 

The initial account ultimately doesn't matter. In a perfect world, you'd do it all on work accounts and work devices though. However...

Posted
Presumably will all be set up in such a way that you don't need to log into your work account to access the authenticator to be able to log into your work account.

 

I was thinking of staff using Google Authenticator to secure whatever range of accounts they use for work, not just their Google Workspace account. MIS, exam boards, etc. Having their authenticator codes for those synced by their Workspace account seems sensible enough. 2FA for their main Google Workspace account does need to not rely entirely on being signed into the account though, you're right there, so having it installed in the work profile would be problematic without them having an alternative method set up.

  • Thanks 1
  • 1 month later...
Posted

I'm trying to enforce 2FA on some newly created Google accounts in a given OU but it doesn't seem to be working as I would expect.

 

My plan was to give these users a hardware key at the same time as issuing their credentials and leave them to it.

 

I have set Enforcement under 2-step verification to 'On' and set the 'New user enrolment period' to 'none' (i.e. zero days) in the Google Admin Console. I was expecting users to be forced to set up their hardware key during their first sign in to their Chromebook, in a similar way to how they are forced to change their password. However, doing this causes them instead to see a message saying "Your sign-in settings don't meet your organisation's 2-Step Verification policy. Contact your admin for more info" without them having a chance to actually set up 2FA.

 

If I set 'New user enrolment period' to '1 day', they can sign in on day 1 but I expect they will see the same message on day 2.

 

It seems that although 2FA is enforced, they are never forced to actually set it up.

 

How do other schools have Google configured for users to use 2FA without (too much) IT involvement?

Posted

Google 2FA is a git, as you say it goes from wanted but not needed to required with out ever forcing the user to set up. We just had to live with this when we moved the school to 2FA.

 

We already had a touch point with new users and now we just make them set up the MFA before they leave the office.

Posted

Although the grace period for Google 2FA enforcement doesn't actually force the user's hand into setting up 2FA, it does invite them to during sign-in. They can opt to skip the setup wizard for now. I tend to give people a grace period of a week.

 

If I were handing out hardware keys to new starters, I'd probably add the relevant key to their Google account for them ahead of time (Admin > Directory > Users > [user] > Security > Security keys). That way you're not relying on them taking note of the setup wizard, and you can avoid having to have any grace period in play.

Posted
Although the grace period for Google 2FA enforcement doesn't actually force the user's hand into setting up 2FA, it does invite them to during sign-in. They can opt to skip the setup wizard for now. I tend to give people a grace period of a week.

 

The issue I found with this is that some users will not set up 2FA and then be locked out, and I have even had users who had done this twice, Microsoft 2FA asks users until the end of the grace period and then forces them to set it up rather than just not letting them log on which I feel is better.

  • Thanks 1
Posted
Although the grace period for Google 2FA enforcement doesn't actually force the user's hand into setting up 2FA, it does invite them to during sign-in. They can opt to skip the setup wizard for now. I tend to give people a grace period of a week.

 

In my, somewhat limited, testing I am not seeing this when signing in to a Chromebook for the first time. The user can of course go to their Google account settings and set up 2FA but I can't see that they are prompted or encouraged to do so.

If I were handing out hardware keys to new starters, I'd probably add the relevant key to their Google account for them ahead of time (Admin > Directory > Users > [user] > Security > Security keys). That way you're not relying on them taking note of the setup wizard, and you can avoid having to have any grace period in play.

 

This is probably the right answer for hardware keys but we probably won't issue hardware keys to all users so we will still have the issue for those users using Google Authenticator or similar and not setting up 2FA before the end of the grace period. It's also annoying that the grace period starts from when the account is created rather than when the account is enabled or first signed in to. Maybe I will have to only create the Google account on the day that the user starts to avoid the grace period expiring before they have even signed in.

Posted
I have a NewUser OU with all Google apps disabled, except Gmail. 2FA is also disabled on this OU. Any new users I create in this OU. I email any new users with the steps needed to setup 2FA. In the email I explain they will not be able to access any Work files etc, until they have setup 2FA and emailed me to let me know.

 

When I get the email, I check their account does actually have 2FA enabled, then I move them into an OU with all Workspace apps enabled.

 

If needed, I can check the NewUser OU every once in a while to see who hasn't emailed me back.

 

97d.gif

 

Sys admin of the year! :D

Posted
I have a NewUser OU with all Google apps disabled, except Gmail. 2FA is also disabled on this OU. Any new users I create in this OU. I email any new users with the steps needed to setup 2FA. In the email I explain they will not be able to access any Work files etc, until they have setup 2FA and emailed me to let me know.

 

When I get the email, I check their account does actually have 2FA enabled, then I move them into an OU with all Workspace apps enabled.

 

If needed, I can check the NewUser OU every once in a while to see who hasn't emailed me back.

 

Stealing this!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...