Jump to content

Recommended Posts

Posted
We oversee multiple schools that have transitioned to a cloud-based infrastructure without maintaining any on-site servers. To accommodate this shift, we've set up Microsoft 365 accounts for all individuals, including students. As you might be aware, starting in March, Microsoft will mandate the use of Two-Factor Authentication (2FA), a move that presents significant challenges, especially for our student users. To address this, we're considering implementing a conditional access policy that would waive the 2FA requirement when users are connected to the school's network. We're in discussions with the LCC to facilitate this through the use of their external IP addresses as designated trusted locations. The hurdle we're facing is the initial mandate for users to configure 2FA, which serves as a "baseline" security measure. This requirement could potentially disrupt the user experience significantly, especially since our schools with hybrid server setups, currently rely on Single Sign-On (SSO) policies. Does anyone know of any solutions or workarounds?
Posted

Following, first I've heard on this..

 

How does this affect tenants with just the A1 licences? I can't set up conditional access policies unless I purchase P1 or at least Microsoft A3

Posted
Tenants equipped with A1 licenses will face impacts as well. We have experimented with the P1 plan as a potential substitute for A3 licenses but haven't yet fully evaluated its effectiveness. It's unclear whether a P1 plan is required for each individual user or just for the GA.
Posted
Tenants equipped with A1 licenses will face impacts as well. We have experimented with the P1 plan as a potential substitute for A3 licenses but haven't yet fully evaluated its effectiveness. It's unclear whether a P1 plan is required for each individual user or just for the GA.

 

Not 100% sure, but I think you would be breaking licencing terms by just having P1 on the GA..

Posted
Not 100% sure, but I think you would be breaking licencing terms by just having P1 on the GA..

 

You would, yes. Although some features get enabled tenant wide with single licenses, MS expect you to make an effort to ensure you're only using features on accounts you are licensed for. Only having 1 account licensed & applying CA rules to everyone would definitely go against this...

Posted
Tenants equipped with A1 licenses will face impacts as well. We have experimented with the P1 plan as a potential substitute for A3 licenses but haven't yet fully evaluated its effectiveness. It's unclear whether a P1 plan is required for each individual user or just for the GA.

 

 

Think it's 1:15 faculty:students but it will work for everyone after purchasing one licence which makes it confusing.

 

Microsoft Entra ID P1 Microsoft Entra ID P1 OVS-ES, School, EES, CSP 15

https://www.microsoft.com/licensing/terms/product/StudentUseBenefitsandAcademicPrograms/all?

Posted (edited)
We oversee multiple schools that have transitioned to a cloud-based infrastructure without maintaining any on-site servers. To accommodate this shift, we've set up Microsoft 365 accounts for all individuals, including students. As you might be aware, starting in March, Microsoft will mandate the use of Two-Factor Authentication (2FA), a move that presents significant challenges, especially for our student users. To address this, we're considering implementing a conditional access policy that would waive the 2FA requirement when users are connected to the school's network. We're in discussions with the LCC to facilitate this through the use of their external IP addresses as designated trusted locations. The hurdle we're facing is the initial mandate for users to configure 2FA, which serves as a "baseline" security measure. This requirement could potentially disrupt the user experience significantly, especially since our schools with hybrid server setups, currently rely on Single Sign-On (SSO) policies. Does anyone know of any solutions or workarounds?

 

You can exclude your students from the policy requiring users to enrol in MFA. Entra Admin Center > Identity > Protection > Identity Protection > Multifactor authentication registration policy

 

However, I feel this is just kicking the can down the road. It's 2024 and we need to get all users protected with MFA... but the challenges of doing this in a school environment are significant - not all kids have phones, kids would lose physical tokens etc etc.

Edited by gybe78
Posted
It seems that a P2 plan is required to set up the Multifactor Authentication registration policy. It's surprising and disappointing that there aren't more accessible options for educational bodies. Given the push towards cloud-based products and away from on-premise solutions, it's frustrating to see essential features restricted by various subscription levels and enforced by default.
Posted (edited)
It seems that a P2 plan is required to set up the Multifactor Authentication registration policy. It's surprising and disappointing that there aren't more accessible options for educational bodies. Given the push towards cloud-based products and away from on-premise solutions, it's frustrating to see essential features restricted by various subscription levels and enforced by default.

 

MS knew what they were doing when they got schools onboarded to 365 with free A1 Plus licences. I think we all knew free wouldn't last forever and we now quickly find ourselves needing ever increasing licence subscriptions to get the functionality we require.

 

Edit: We bit the bullet a couple of years ago and opted for A3 / P2 licensing.

Edited by gybe78
Posted

Can't you just use Office 356 as a service provider and use another identity provider or host your own. I'm sure the Google IDP is still free for schools.

Then you can setup the MFA how you see fit.

 

It doesn't seem very long ago we were all hosting our own IDP's and integrating third parties with them, has edugeek just lost that collective skillset now or are microsoft forcing schools to use their auth?

Posted

Do your students need to external access?

Limit access to Hybrid Joined Devices.

 

You can roll out certificate authentication as 2nd factor. Most likely only work practically on managed devices where you can set up user enrolment.

Posted (edited)
You can exclude your students from the policy requiring users to enrol in MFA. Entra Admin Center > Identity > Protection > Identity Protection > Multifactor authentication registration policy

However, I feel this is just kicking the can down the road. It's 2024 and we need to get all users protected with MFA... but the challenges of doing this in a school environment are significant - not all kids have phones, kids would lose physical tokens etc etc.

 

Going to have a look at this tomorrow morning. Hoping I can buy some more time to hopefully persuade SLT to purchase the A3 licences.

 

I've read a few blogs & there was one I found interesting : https://techcommunity.microsoft.com/t5/microsoft-entra-blog/auto-rollout-of-conditional-access-policies-in-microsoft-entra/ba-p/4044870

 

Microsoft-managed Conditional Access policies have been created in all eligible tenants in Report-only mode. These policies are suggestions from Microsoft that organizations can adapt and use for their own environment. Administrators can view and review these policies in the Conditional Access policies blade. To enhance the policies, administrators are encouraged to add customizations such as excluding emergency accounts and service accounts. Once ready, the policies can be moved to the ON state. For additional customization needs, administrators have the flexibility to clone the policies and make further adjustments.

Edited by Olliedawg
Posted (edited)

Trying to follow this myself. We have 80x A3 Faculty licenses so this should easily cover us.

 

Apologies in advance as I am trying to follow this with clear head........

 

However what does it enable us to do? Conditional Access but MFA will be applied outside of school for all? or as @gybe78 points out will we be able to exempt students from the MFA rule altogether (not ideal but allows time to phase in)

 

Still trying to find an categorical information that says they are about to implement this.

 

Thanks

 

 

EDIT: I dont have Entra ID P2 Screenshot 2024-02-21 092826.png but is greyed out unless I have P2

Edited by hyb80
Posted (edited)

There is the MS blog post which Olliedawg linked Which if I'm reading it correctly will only target specific scenarios where a tenant already has the P1 licences that allow conditional access.

 

Microsoft-managed Conditional Access policies have been created in all eligible tenants in Report-only mode. These policies are suggestions from Microsoft that organizations can adapt and use for their own environment. Administrators can view and review these policies in the Conditional Access policies blade. To enhance the policies, administrators are encouraged to add customizations such as excluding emergency accounts and service accounts. Once ready, the policies can be moved to the ON state. For additional customization needs, administrators have the flexibility to clone the policies and make further adjustments.

 

 

There is this blog post Microsoft will roll out MFA-enforcing policies for admin portal access (bleepingcomputer.com) which says it will be applied as a report only policy for 90 days and then get turned on if you haven't toggled it off. IT also suggests you are free to modify the policies.

Edited by NegativeKillDeath
  • Thanks 1
Posted
There is the MS blog post which Olliedawg linked Which if I'm reading it correctly will only target specific scenarios where a tenant already has the P1 licences that allow conditional access.

 

 

 

 

There is this blog post Microsoft will roll out MFA-enforcing policies for admin portal access (bleepingcomputer.com) which says it will be applied as a report only policy for 90 days and then get turned on if you haven't toggled it off. IT also suggests you are free to modify the policies.

 

I saw that blog post too.

 

From what I can make out, I think we're ok for now. All of the admin role accounts in my tenant already have MFA so that's no issue. I was more concerned over staff/students as we haven't rolled out MFA yet for users.. I'm planning on (hopefully) getting Microsoft A3 licences to manage MFA for staff.

Posted (edited)
We use an account for our printers to use scan to email and also Teams phone have their own accounts. How do I exclude that from MFA if I don't have A3/P1 etc? Edited by ITGuyNW
Posted
This concerned me at first but as previously suggested, the two "Microsoft-managed" MFA policies under Conditional Access can simply be toggled off to prevent them being automatically enabled. We're already implementing our own policies so only these will be used going forward unless we decide to toggle the Microsoft policies back on.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...