Jump to content

Recommended Posts

Posted

We have a tiered approach to staff.

1. You have management responsibilities or might handle sensitive data as your job role you get 2fa. Support staff who work on a pc all day and aren’t moving around between workstations.

 

2. You are a teacher, Ta or sta with no sensitive responsibilities you get a free pass on site and conditional gets applied to you(this allows for staff moving around a lot or not having their own base).

 

3. Cleaners and students no 2fa unless they get alerted as a high risk account. Credentials found on a database or a large number of risky sign in attempts.

 

I also suggest any roll out should be done as part of cyber resilience training lead by both IT and someone from senior management who knows what they are talking about this gets more people on board scare the shit out of them by showing the risks, how much an attack costs organisations etc etc. I used the NCSC training video presentation as a base and put our own spin reducing it to 10 slides.

Posted
configure a group of those who refuse and actively block their access externally

 

That seems reasonable. "Here is what you need to do to secure your account for external access; if you're not willing to do that, you will have external access revoked."

Posted
We have a tiered approach to staff.

2. You are a teacher, Ta or sta with no sensitive responsibilities you get a free pass on site and conditional gets applied to you(this allows for staff moving around a lot or not having their own base).

 

What teacher doesn't have access to sensitive data? Every teacher is required to know who their PP students are, as well as any adjustments needed for disability, medical or religious reasons.

Posted
2. You are a teacher, Ta or sta with no sensitive responsibilities you get a free pass on site and conditional gets applied to you(this allows for staff moving around a lot or not having their own base).

I mean, technically they're still on 2FA, because the fact that they're physically on-site is your second authentication factor. So your SLT are using 3 factor? (Location, password and phone/token)

 

The way it was explained to me is that MFA should interrogate the user based on things from 2 or more of the following categories: what they know (password/pin/ect), what they are (biometrics), what they have (key fob/phone/physical access to site/ect).

Posted
One thing I think a lot (and I mean a LOT) of people miss is there understanding of how conditional access works.

 

Many times I have read that by implementing conditional access to ignore internal addresses staff who are resistant to register for MFA simply don't have to do it as long as they don't want external access. This is not protecting your network. In this scenario the first person to get the registration prompt is the cyber criminal who can just register with their details. All staff members (particularly those with access to sensitive info) should have to enable MFA on their account. We run reports periodically to make sure this is the case and it is part of our IT induction process.

 

I am not saying that there isn't the argument for or against personal devices / hardware keys etc. but conditional access is not a replacement unless you configure a group of those who refuse and actively block their access externally (also possible using conditional access but not what I think most are referring to)

 

That is why you set it to only allow MFA setup to be allowed on site, the same site that you set it to be ignored from. Some thought has gone into this.

  • Thanks 1
Posted
That is why you set it to only allow MFA setup to be allowed on site, the same site that you set it to be ignored from. Some thought has gone into this.

 

Where's that setting? I'd like to check I've got it enabled.

Posted
The Feitian K9:

 

https://www.ftsafe.com/products/FIDO/NFC

 

For using them as 2FA USB keys, a couple of small gotcha's: our nice, compact all-in-ones have side-mounted USB ports hidden away behind the screen, and mounted the wrong way around for someone to be able to press the touch pad with their finger when using the key. A short (30cm) USB extension cable solves that. Also, the USB interface is of the thin style, so it can be put in a port upside down, which can confuse some users.

How easy were they to setup and how much did you pay? We're looking at entry systems too so this might fit the brief.

Posted
Where's that setting? I'd like to check I've got it enabled.

 

I have it as an actual policy in itself.

 

Settings are:

- Assignments > All users

- Cloud apps or actions > User actions > Register security information

- Conditions > Locations > Include Any, Exclude trusted locations (or populate the list yourself with your on-premises public IP address)

- Conditions > Client apps > Browser and Mobile apps and desktop clients

- Access controls > Block access

Source: Our very own Katy (https://katystech.blog/azure/azure-conditional-access-and-mfa). I can't remember where I got the setup from originally but Katy's is the same as mine so a good example.

  • Thanks 4
Posted
Does anyone use Google Authenticator over Microsoft Authenticator? Had some issues with iphones and the MS app but Google works first time. Any reason not to use it instead?
Posted
Does anyone use Google Authenticator over Microsoft Authenticator? Had some issues with iphones and the MS app but Google works first time. Any reason not to use it instead?

 

I think the MS authentication needs the MS app...

Posted
I think the MS authentication needs the MS app...
The browser based MFA that (caused controversy when) I mentioned in another thread works fine with MS. Not a recommendation for the browser based approach, but does suggest that other authenticator apps are compatible. I think they all use the time based approach rather than the notification and number confirmation that MS use.
Posted
Does anyone use Google Authenticator over Microsoft Authenticator? Had some issues with iphones and the MS app but Google works first time. Any reason not to use it instead?
Yep, lots of staff at my schools use Google authenticator without issue, but then they are mostly using Google workspace and not ms anyway.
  • Thanks 1
Posted
Does anyone use Google Authenticator over Microsoft Authenticator? Had some issues with iphones and the MS app but Google works first time. Any reason not to use it instead?

 

I've got about 6 members of staff using the Google auth app just fine with our school MS services. They were all using it to auth things like FB, Amazon etc. and just added the school service to it without a problem.

  • Thanks 1
Posted
How easy were they to setup and how much did you pay?

 

For the Feitian NFC K9 key themselves, I think they were a little cheaper than the Ubikeys - we bought in bulk, a quick Google suggest around £21 each, which sounds about right, maybe a bit cheaper if you're buying 50-odd at a time.

 

They were easy enough to set up for use with our printers - the printers have USB-connected NFC sensors and are managed by PaperCut, we have one of the same NFC sensors on an admin PC we use to set the keys up. You'll probably need to buy the sensors via whoever manages your printers, which is going to depend on your provider. Same with door entry - our new door entry system project has been a bit delayed, so we're not using them for door entry yet, but it should simply be a case of making sure we get compatible readers that work with our system (Paxton, so common enough).

  • Thanks 1
Posted

I have been looking into options for our schools recently too. Most teachers have iPads, but they always seem to misplace them - or complain about the prompt taking to long to come through. I considered using yubikeys, but they aren't supported with GCPW which is the login method we use.

 

Might be one to discuss with SLT, as having to wait an extra 30 seconds for a prompt certainly beats a data breach!

Posted (edited)

If your staff misplace an iPad, I don't fancy their chances with a Yubikey!

 

EDIT - one way to make sure they remember their key is to remove passwords altogether and do logon via key (is that even possible?!)

Edited by enjay
Posted
If your staff misplace an iPad, I don't fancy their chances with a Yubikey!

 

EDIT - one way to make sure they remember their key is to remove passwords altogether and do logon via key (is that even possible?!)

 

Very good point, although a yubikey could be attached to a lanyard and they don't seem to forget those... haha!

Posted
If your staff misplace an iPad, I don't fancy their chances with a Yubikey!

 

This was a while ago, but at a school I used to support it was less "misplaced" than "left it with my kids to play games on". These were SMT machines.

Posted
Bought one of these as a test

 

I bought the slightly snazzier version for my own use:

 

https://www.amazon.co.uk/dp/B0BJP64YTT

 

Has both USB A and USB C interfaces and NFC. I find the press-able button easier to use than the capacitive touch ones used on the Feitian keys, which can take a few seconds / bit of finger-wiggling to get to register a touch.

  • Thanks 1
Posted (edited)

We ended up providing school ipads to staff with Authenticator on, as we didn't expect them to use their own phones (and 4g is VERY patchy on site so it wouldn't work well).

 

Extra brucie bonuses are:

1 They have a device they can use at home to do work

2 They have a great camera and mic for taking classroom photos/videos has been particularly useful for orals or PE performance feedback, social media etc.

3 We can push free apps from the app store, useful for classcharts and things like that.

4 We can push specific paid for apps that are darn good like iDoceo, Goodnotes, Lumafusion etc very handy for specific departments

 

Don't really have any regrets to be honest other than not sure where were gonna find the money for replacements in 5 years time but hey ho that's ever been the same problem in my 23 years of doing this so I don't worry about it any more!

Edited by PotNoodleTech
Posted
We ended up providing school ipads to staff with Authenticator on, as we didn't expect them to use their own phones (and 4g is VERY patchy on site so it wouldn't work well).

The whole thing with Authenticator is that it doesn't need a data connection to work, just for the initial setup. It uses the phone's time and the seed you used when setting up to generate the right code.

 

Anyway, Authenticator/phone where possible. Where it isn't possible or staff object, they get their first Yubikey free. Surprisingly a few of them have gone missing, but those people are perfectly happy to use their phone once they may be out of pocket :D

Posted
Extra brucie bonuses are:

 

5. Reduced printing costs, as staff take iPads to meetings and Insets rather than printing off agendas and resources they might need during the discussion. That's one of the big changes we saw at my previous school when we gave iPads to all teachers.

6. School work done on managed device not personal one, ticking GDPR boxes (until the iPad is given to a child, of course!).

 

If you're expecting teachers to plan and prep lessons on an iPad, I'd be tempted to offer Bluetooth keyboards to go with them, maybe the ones built-in to a case (which also ensures they are kept in protective cases!)

Posted
6. School work done on managed device not personal one, ticking GDPR boxes (until the iPad is given to a child, of course!).

Oh the hell I've had when suggesting you shouldn't be giving work provided devices to students, or your own family to use!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...