Jump to content

Do you enable MFA/2FA for student accounts.  

32 members have voted

  1. 1. Do you enable MFA/2FA for student accounts.

    • Yes
      8
    • No
      24


Recommended Posts

Posted
We don't because Google don't do an exception for the school site

 

Ditto. We allow students to turn it on, but isn't enforced.

 

For M365, which we pretty much don't use with students anyway, I've got security defaults turned on (so MFA enforced for all).

Posted (edited)

Enforced for everyone, without exception. Y7-Y13 and Staff. (365, no MFA needed on-prem, only external. Everything I can possibly setup to use MS SSO is utilising that such as satchel one, sparx maths etc)

 

I've currently issued out 4 x DeepNet Security MFA tokens to Y7s this year who don't own a phone, and told them if and when they get a phone to just bring it back and we'll set them up like everyone else.

Edited by mrbios
Posted
I'd be surprised if this hasn't been done before, but who here enables MFA for students?

 

We (Google Workspace school) enable (allow), but don't enforce. Children (and staff, really) aren't allowed phones in lessons, so we would have to issue 2FA keys. We might consider doing so for Year 10 upwards. Actually, pupils hand their phones in at the front desk on arrival, and generally only need to complete 2FA steps once when first logging in to their Chromebook, so it might be do-able to let them come down to the front desk and request their phone as a once-off when first signing in.

Posted

Forced for our Sixth Formers, and I would like to roll out to a few more lower years. Did some trial groups of Year 10 & 11 last academic year and they just couldn't seem to cope with it. Found in these year groups the student phones were poor quality hand me downs and seemed to change their numbers often also. But, of course there was few very shiny new phones also

 

Pete

Posted
MFA for all users, school IP as trusted location so not required on-site, only off-site. User guide sent out to all new year 7 parents. Pointless just enabling for staff considering we used to get student accounts compromised before we enabled MFA. All or nothing or not worth the time.
Posted

A side question if I may.

 

How do you have the pupils enrol MFA? Do you leave them to it, or use IT classes to walk them through it?

 

We limit Staff enrolment to a trusted device on a trusted network with CA. So having pupils enrol at home with parents etc would open up a big security risk in the process.

Posted
A side question if I may.

 

How do you have the pupils enrol MFA? Do you leave them to it, or use IT classes to walk them through it?

 

We limit Staff enrolment to a trusted device on a trusted network with CA. So having pupils enrol at home with parents etc would open up a big security risk in the process.

Guide sent home to parents. Lunchtime sessions, students come to office. many ways

Posted
A side question if I may.

 

How do you have the pupils enrol MFA? Do you leave them to it, or use IT classes to walk them through it?

 

We limit Staff enrolment to a trusted device on a trusted network with CA. So having pupils enrol at home with parents etc would open up a big security risk in the process.

 

If you pay for P2 you can set the CAP to only allow MFA registration from a low/no risk sign in. Many orgs need remote workers to register for MFA anywhere. It is a risk. Better than no MFA. If an account starts sending a lot of email or triggers Anti Malware then you can take action.

 

MFA isn’t a silver bullet but it does make things a lot harder for threat actors.

Posted (edited)

Enforced on all staff, nothing for students.

 

I want to do it for students however have the following hurdles:

 

- Off-site proxies so machines don't come out of our dedicated IP's they come out of the shared proxy addresses for all customers.

 

- I could go down the hybrid joined device route which would work for our 3 IT suites but now all our students have 1:1 iPads through JamF so they are seen as external devices to Azure.

 

- Trying to setup and maintain iPads on a 1:1 level with 12+ year olds is bad enough, add on MFA which would need to be setup beforehand via a computer and then required for the 4/5 user authentications when setting up an iPad and apps let alone when they forget their password and we reset then needing to sign into all the apps again, not a chance!

 

My security OCD shudders at all of this but I can't see an easy way around it. Throw into the mix a no phone policy in the school which is bad enough when teachers keep bringing up the "we shouldn't be using our phones in classrooms, it's against the DofE regulations and advisories" let alone trying to convince it for security with students when we all know the students will just abuse it.

Edited by Tefters
Posted
MFA for all users, school IP as trusted location so not required on-site, only off-site. User guide sent out to all new year 7 parents. Pointless just enabling for staff considering we used to get student accounts compromised before we enabled MFA. All or nothing or not worth the time.

 

Staff have access to way more important documents that students

 

MFA != you need a phone, we're living in 2024!

Posted
Staff have access to way more important documents that students

 

Yes, this is chiefly what's behind SLT being so onboard with enforcing MFA for all staff whilst being more meh when it comes to the students. Also, if accounts don't provide access to an email mailbox, then that alters the risk imho. WRT students, the main factor in decision-making seems to be not wanting to undermine a no-phones policy (which I get). Whilst MFA != phones, realistically, buying security keys for all the students and dealing with the layer of logistical complication that that would entail makes it a non-starter right now.

 

If we were a 1:1 Chromebook school (I live in hope), then the calculus would be very different, and I think we'd be able to enforce Google 2SV for all, and have everyone get behind that as an opportunity to instill some good digitial hygiene life skills.

Posted
How would that work in an environment where students aren't using 1:1 devices?

 

Store the private keys on a server. Google syncs to your chrome account for passkeys, or run a vaultwarden server and use bitwarden.

Posted
Signing into a shared Chromebook without being able to use a phone for 2SV would require a hardware token. On a shared Windows device, I guess you'd have the option of using an installed password manager to sign into Google/Chrome using a passkey or T-OTP from the password manager. Onboarding that in such a way that students can also sign into their accounts away from school seems like a massive headache, though.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...