Jump to content

Recommended Posts

Posted

Hello Guys!

 

 

Trust you are doing well.

 

We are trying to implement 2FA in our school, and the management won't allow the use of phone or USB devices.

 

Please can you reccommend any solution for this? Your input is higly appreciated.

 

 

 

Thank you.

Posted
I posed the question here that, if you don't enforce MFA on the PC itself, an authenticator app such as bitwarden (that you can buy as SaaS, or host yourself for free) will give you MFA codes without the use of external devices.
Posted
Apologies! The 2FA is needed for Google accounts, and the management won't allow the use of the Google Titan Key.

 

It's probably a good idea to make a distinction between SLT not wanting to require the use of USB security keys (such as the Titan key), versus not wanting to allow them where users may have a preference for it.

 

Without either a hardware [uSB] security key or a phone-based method (authenticator apps, passkeys, notification prompts, etc.) then I think you're either looking at hardware code generators or a password manager application on the computer. The password manager on the computer would need to not be reliant on the Google account at all. Various options on that front, but all of them arguably quite thorny to guide 100s of end users through, compared to handing out USB security keys.

Posted
Various options on that front, but all of them arguably quite thorny to guide 100s of end users through, compared to handing out USB security keys.

 

Bitwarden seems to be as hard as 'copy' 'paste' the MFA code.

Still unclear why that's not an option.

Posted
Bitwarden seems to be as hard as 'copy' 'paste' the MFA code.

Still unclear why that's not an option.

 

Well, it's another account for the end user to know about and remember.

Posted
Well, it's another account for the end user to know about and remember.

 

That's true. I don't see it any more challenging than plugging in USB key, or loading the phone app TBH.

I guess if SLT think the other options are too difficult for the teachers then this isn't going to be any easier.

  • Thanks 1
Posted
That's true. I don't see it any more challenging than plugging in USB key, or loading the phone app TBH.

I guess if SLT think the other options are too difficult for the teachers then this isn't going to be any easier.

 

Authenticator on phone/tablet seems to be the quickest and easiest.

 

Most of us, inclyding teachers have all been using multifactor in one way or another for like 10 years so theres no excuse not to use it now.

Posted
Authenticator on phone/tablet seems to be the quickest and easiest.

 

i don't really agree with that. For me, I have to reach into my pocket, unlock the phone, open the auth app, read out, and manually type in the code. With the browser app (assuming I'm logged in, which I am) I just copy, paste. Find it much eaiser myself as it's all on the device I'm using. Then again; I'm not a teacher so I probably don't know what I'm talking about.

Posted
i don't really agree with that. For me, I have to reach into my pocket, unlock the phone, open the auth app, read out, and manually type in the code. With the browser app (assuming I'm logged in, which I am) I just copy, paste. Find it much eaiser myself as it's all on the device I'm using. Then again; I'm not a teacher so I probably don't know what I'm talking about.

 

IME, it's the onboarding process of T-OTP authenticator apps which really seems to throw people. It's not helped when some services direct users to install and use their proprietary authenticator app (Pearson!!), or when a well-known generic one isn't quite as generic as it should be and manages to completely mangle the UX and instill confusion (*cough* Microsoft *cough*).

Posted

The trust also want to do 2FA here (computers, email, and MIS), I think the school will have to supply a large number of mobile phones, with a contact, that are still getting O/S updates. My belif is that the cost will be a budet line item next year (2FA for staff, or hire another teacher, pick one!)

 

We are using local profiles, so nothing is rembered, thus it is not possible to use an authenticator app in a browser on the computer.

Also desktops do not have camera's, or fingerprint readers.

 

One suggestion, for everyone using 2FA (some staff here), get them to get a set of one time backup codes, so that they can get into there account, if they forget/lose/destroy there phone.

Posted
We are trying to implement 2FA in our school, and the management won't allow the use of phone or USB devices.

 

For Google Workspace, GAM will let you script adding backup 2FA codes for each user - I think you get 10 per user. You could then export those codes to a template that prints onto an A4 pre-perforated cards sheet, so each user gets a credit-card sized card with their codes on. They are one-time-use, so they'll have to cross each one out as they use it, then come to you for a refill when all 10 are used. If people mostly use the same computer they'll probably only have to complete the 2FA step once.

 

The above might not be the best / most secure option, but it is an option.

Posted
If you can't use USB devices then OTP hardware tokens are a possible solution. For Microsoft you can use pre-programmed TOTP tokens if you have p1/p2 licenses, if not then use programmable tokens (they will act like authentication apps and therefore don't need a p1/p2).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...