Jump to content

MFA - Is it actually protecting your accounts?


Recommended Posts

Posted

Hi all,

 

We have MFA applied to all student and staff accounts via conditional access policy in Entra.

Like a number of schools students are not to use phones during the school day so we whitelist internal IP's to negate the need for MFA internally.

When (if) students attempt to access their M365 account externally, they are prompted to set up MFA.

 

However, there are a number of students who have not done this.

We are thinking that this is an issue as these accounts are then only protected by login and password.

Should these details be phished, just copied by someone seeing someone logging in internally, or any other method, the details could be used by someone to setup MFA to their own device.

We have told governors in good faith that we have MFA in place, but technically, only students who have tried to access resources and have had to setup MFA are actually protected.

 

Has anyone else come accross this and what method did you use to mitigate?

Ideally there would be some way to give a grace period for when the users join the school to set up MFA or else their account be automatically blocked from being able to register for MFA, we can then pick genuine cases up as they occur.

Any insight would be welcome.

Posted

I asked a similar question previously, which there are a couple of solutions

 

A. Stop anyone signing up for MFA unless they are on trusted ip. Pupils would have to do it in school before they access at home.

 

B. Enforce MFA enrollment for all users regardless of where they are and then allow them access without on trusted ips

 

Both are discussed here https://www.edugeek.net/forums/security/240476-enforce-2fa-enrollment-trusted-ip.html

  • Thanks 2
Posted

Hi Steve,

 

Thanks for the reply.

Do you have MFA applied to students? Do they have 1 to 1 devices?

How do you handle the students setting up MFA?

 

The concern is not the staff, its the students. We would not be able to force them to sort MFA internally, as they are not permitted to use their phones during the day.

Posted
The concern is not the staff, its the students. We would not be able to force them to sort MFA internally, as they are not permitted to use their phones during the day.

 

Could a one-time exception not be made to allow MFA setup in, for example the first IT lesson of the school year? (with some similar dispensation sometime in their first week for in-year starters) You'd need SLT on-side, but if everything is clearly communicated with parents and students, it's not unworkable.

 

The flip side might be, that there's a (say) 2 week period after they first start where they can set up MFA at home, and then it's locked down. It's still a risk, but it's better than nothing.

  • Thanks 1
Posted

We're a primary school so different set of problems, but I don't think there is a perfect solution for any school. As Rob_D says above an exception so they can use their phone in first lesson is potentially workable solution.

 

Another option could be to enabled enforced enrollment on a Friday evening and tell all pupils they must login and enroll a device over the weekend or they will not be able to login for their IT lesson on Monday morning. potentially disruptive, but hopefully enough of an incentive to get it done.

  • Thanks 1
  • 3 months later...
Posted

So, I've run this past one of my secondary colleagues... Here's what they do.

 

At the start of term MFA is enforced, no grace period. After 10 working days run a report to show accounts that have not been logged into/set up. Block them. Email to form tutors instructing those who haven't signed up to get on and do it or to visit IT office at break or lunch. If it's staff - email to line manager with the same instructions. Ignoring 2 reminders means the IT team hunt them down with a laptop and make them do it there and then.

 

Run the same report at the end of every half term - block and repeat the process on the first day back to mop up new starters.

 

Apparently the worst offenders are 1:1 TAs, Cache health/childcare students and the ALP kids. 

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...