Rob_D Posted September 25, 2024 Posted September 25, 2024 I'd be surprised if this hasn't been done before, but who here enables MFA for students?
3s-gtech Posted September 25, 2024 Posted September 25, 2024 Yup, year 9 and above. Phone ownership is very broad by that point. Opt-out rather than opt-in.
mavhc Posted September 25, 2024 Posted September 25, 2024 I don't, but if I did it would be via passkeys that can be stored in Chrome, or Vaultwarden
msi_school Posted September 25, 2024 Posted September 25, 2024 We don't because Google don't do an exception for the school site
jthompson Posted September 25, 2024 Posted September 25, 2024 We don't because Google don't do an exception for the school site Ditto. We allow students to turn it on, but isn't enforced. For M365, which we pretty much don't use with students anyway, I've got security defaults turned on (so MFA enforced for all).
mrbios Posted September 25, 2024 Posted September 25, 2024 (edited) Enforced for everyone, without exception. Y7-Y13 and Staff. (365, no MFA needed on-prem, only external. Everything I can possibly setup to use MS SSO is utilising that such as satchel one, sparx maths etc) I've currently issued out 4 x DeepNet Security MFA tokens to Y7s this year who don't own a phone, and told them if and when they get a phone to just bring it back and we'll set them up like everyone else. Edited September 25, 2024 by mrbios
dhicks Posted September 25, 2024 Posted September 25, 2024 I'd be surprised if this hasn't been done before, but who here enables MFA for students? We (Google Workspace school) enable (allow), but don't enforce. Children (and staff, really) aren't allowed phones in lessons, so we would have to issue 2FA keys. We might consider doing so for Year 10 upwards. Actually, pupils hand their phones in at the front desk on arrival, and generally only need to complete 2FA steps once when first logging in to their Chromebook, so it might be do-able to let them come down to the front desk and request their phone as a once-off when first signing in.
Squelch Posted September 25, 2024 Posted September 25, 2024 365 MFA enabled for everyone, the school network is listed as a trusted location so it doesn't ask for MFA in school but will do away from school.
FragglePete Posted September 25, 2024 Posted September 25, 2024 Forced for our Sixth Formers, and I would like to roll out to a few more lower years. Did some trial groups of Year 10 & 11 last academic year and they just couldn't seem to cope with it. Found in these year groups the student phones were poor quality hand me downs and seemed to change their numbers often also. But, of course there was few very shiny new phones also Pete
ITGURU Posted September 25, 2024 Posted September 25, 2024 MFA for all users, school IP as trusted location so not required on-site, only off-site. User guide sent out to all new year 7 parents. Pointless just enabling for staff considering we used to get student accounts compromised before we enabled MFA. All or nothing or not worth the time.
smithson83 Posted September 25, 2024 Posted September 25, 2024 A side question if I may. How do you have the pupils enrol MFA? Do you leave them to it, or use IT classes to walk them through it? We limit Staff enrolment to a trusted device on a trusted network with CA. So having pupils enrol at home with parents etc would open up a big security risk in the process.
ITGURU Posted September 25, 2024 Posted September 25, 2024 A side question if I may. How do you have the pupils enrol MFA? Do you leave them to it, or use IT classes to walk them through it? We limit Staff enrolment to a trusted device on a trusted network with CA. So having pupils enrol at home with parents etc would open up a big security risk in the process. Guide sent home to parents. Lunchtime sessions, students come to office. many ways
DrCheese Posted September 25, 2024 Posted September 25, 2024 Yes we do the same as ITGuru They can register outside of school (UK only) - Aware it's a risk but it's a balancing act. The alternative is no MFA at all. 1
free780 Posted September 25, 2024 Posted September 25, 2024 A side question if I may. How do you have the pupils enrol MFA? Do you leave them to it, or use IT classes to walk them through it? We limit Staff enrolment to a trusted device on a trusted network with CA. So having pupils enrol at home with parents etc would open up a big security risk in the process. If you pay for P2 you can set the CAP to only allow MFA registration from a low/no risk sign in. Many orgs need remote workers to register for MFA anywhere. It is a risk. Better than no MFA. If an account starts sending a lot of email or triggers Anti Malware then you can take action. MFA isn’t a silver bullet but it does make things a lot harder for threat actors.
Tefters Posted September 26, 2024 Posted September 26, 2024 (edited) Enforced on all staff, nothing for students. I want to do it for students however have the following hurdles: - Off-site proxies so machines don't come out of our dedicated IP's they come out of the shared proxy addresses for all customers. - I could go down the hybrid joined device route which would work for our 3 IT suites but now all our students have 1:1 iPads through JamF so they are seen as external devices to Azure. - Trying to setup and maintain iPads on a 1:1 level with 12+ year olds is bad enough, add on MFA which would need to be setup beforehand via a computer and then required for the 4/5 user authentications when setting up an iPad and apps let alone when they forget their password and we reset then needing to sign into all the apps again, not a chance! My security OCD shudders at all of this but I can't see an easy way around it. Throw into the mix a no phone policy in the school which is bad enough when teachers keep bringing up the "we shouldn't be using our phones in classrooms, it's against the DofE regulations and advisories" let alone trying to convince it for security with students when we all know the students will just abuse it. Edited September 26, 2024 by Tefters
mavhc Posted September 26, 2024 Posted September 26, 2024 MFA for all users, school IP as trusted location so not required on-site, only off-site. User guide sent out to all new year 7 parents. Pointless just enabling for staff considering we used to get student accounts compromised before we enabled MFA. All or nothing or not worth the time. Staff have access to way more important documents that students MFA != you need a phone, we're living in 2024!
jthompson Posted September 26, 2024 Posted September 26, 2024 Staff have access to way more important documents that students Yes, this is chiefly what's behind SLT being so onboard with enforcing MFA for all staff whilst being more meh when it comes to the students. Also, if accounts don't provide access to an email mailbox, then that alters the risk imho. WRT students, the main factor in decision-making seems to be not wanting to undermine a no-phones policy (which I get). Whilst MFA != phones, realistically, buying security keys for all the students and dealing with the layer of logistical complication that that would entail makes it a non-starter right now. If we were a 1:1 Chromebook school (I live in hope), then the calculus would be very different, and I think we'd be able to enforce Google 2SV for all, and have everyone get behind that as an opportunity to instill some good digitial hygiene life skills.
mavhc Posted September 26, 2024 Posted September 26, 2024 Passkeys exist, Password managers that manage TOTP exist
jthompson Posted September 26, 2024 Posted September 26, 2024 Passkeys exist, Password managers that manage TOTP exist How would that work in an environment where students aren't using 1:1 devices? e.g. a shared Chromebook.
mavhc Posted September 26, 2024 Posted September 26, 2024 How would that work in an environment where students aren't using 1:1 devices? Store the private keys on a server. Google syncs to your chrome account for passkeys, or run a vaultwarden server and use bitwarden.
jthompson Posted September 26, 2024 Posted September 26, 2024 Signing into a shared Chromebook without being able to use a phone for 2SV would require a hardware token. On a shared Windows device, I guess you'd have the option of using an installed password manager to sign into Google/Chrome using a passkey or T-OTP from the password manager. Onboarding that in such a way that students can also sign into their accounts away from school seems like a massive headache, though.
mavhc Posted September 26, 2024 Posted September 26, 2024 True, does preclude shared Chromebooks, that is annoying. You can preconfigure the self hosted server for the extension https://bitwarden.com/help/configure-clients-selfhost/#tab-windows-55MXwgIamulyigoLoAbLMo
tapb Posted September 26, 2024 Posted September 26, 2024 This might be interesting to consider: Passwordless for Students - M365 Education | Microsoft Learn 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now