jimbopembo Posted January 29, 2025 Posted January 29, 2025 How are you accommodating staff that refuse to use their phones for 2FA. Out of about 100 staff we have just one person that refuses to have Authenticator and doesn't want to receive text.
altecsole Posted January 29, 2025 Posted January 29, 2025 We've had similar. I just tell them that it's fine. There is no expectation on them to do work outside of school hours. Eventually they give in, as it's too inconvenient for them. 1
DWilson1997 Posted January 29, 2025 Posted January 29, 2025 They are not permitted to access our systems or use their device outside of the school network. Also, if they become a medium or high risk users in entra then they will be blocked must come to us to manually resolve. 1
machy Posted January 29, 2025 Posted January 29, 2025 You can get "Dongles" from people like deepnet for about £20 Or yubikeys for a bit more 1
BucksITguy Posted January 29, 2025 Posted January 29, 2025 We've added it to our staff agreement that they must have it on their account and it is set up when they login for the first time. Obviously if you have support from senior management it makes life 10x easier! 2
Cat_Jam148 Posted January 29, 2025 Posted January 29, 2025 There is no expectation here for staff to work outside school hours, so we don't push the issue. If they decline the app, it was agreed with SLT that they get no access from home. We use a conditional access policy to prevent login from non school IP address. They quickly change their minds once they see everyone doing 'training' from home on the odd training day, and they have to be in-school. 1
Rob_D Posted January 29, 2025 Posted January 29, 2025 When we first enabled conditional access we bought a couple of yubikeys for our "there's always one" who kicked up a fuss but still "needs to work from home". We also have a handful of others who haven't set up their MFA (for one reason or another) but don't work from home so it doesn't matter. 1
PotNoodleTech Posted January 29, 2025 Posted January 29, 2025 (edited) It's their choice not to use their personal phone for work use. I respect that. Instead of being annoyed, you should cater for that by either providing a cheap android device (non sim) for multifactor use of even better/cheaper - we use thestis fido USB hardware keys - they work great and are only 30 bucks off amazon. We've done both - the android devices or ipads come in double handy for them to use for teaching/learning or to do things like take photos to post on twitter etc. The USB keys actually function as an awesome backup 2fa method incase phone dies/lost/forgot etc. It's a win win. Edited January 29, 2025 by PotNoodleTech 2
phil0569 Posted January 29, 2025 Posted January 29, 2025 we just brought all staff a SafeID key, then there is no agro about phones. If they want to use their phone that's fine, but they have a key if they don't. 1
ITGuyNW Posted January 29, 2025 Posted January 29, 2025 We have it where if you want to access work stuff at home, you need MFA. Soon sorts them out. 1
NegativeKillDeath Posted January 29, 2025 Posted January 29, 2025 I've had a problem staff member be more understanding when it was explained to them that the authenticator app was only for generating the code and that it wouldn't be ping for work emails etc. A deaf teacher who historically never had a phone we provided a Yubikey. And for a blind teacher we registered their home laptop in Entra and set it as trusted device to not require MFA. 1
PotNoodleTech Posted January 29, 2025 Posted January 29, 2025 And for a blind teacher we registered their home laptop in Entra and set it as trusted device to not require MFA. I would strongly reccomend providing them with a work laptop rather than allowing them to use their personal device unrestricted? 2
LeMarchand Posted January 29, 2025 Posted January 29, 2025 Our refusenik wouldn't use their phone for 2FA at work, e.g. for Arbor, and was given an old tablet that used to get passed around the class. This had a problem so I replaced it with an even older one locked down as an Authenticator kiosk. Didn't go down well, but it does the job it was supplied for without any extra expense or the ability for it to be used as a "reward toy".
jimbopembo Posted January 29, 2025 Author Posted January 29, 2025 So, I guess the easy way would be to get some hardware keys for everyone. I'm only just getting to grips with Entra and starting to understand how I can leverage it to help us to be more secure moving forwards. Looks like we'll need to upgrade our subscription. Could anyone recommend online training for Entra that they have undertaken? Apart from the Microsoft Learn resources that I'm ploughing through? TIA
Rob_D Posted January 29, 2025 Posted January 29, 2025 It's their choice not to use their personal phone for work use. I respect that. Instead of being annoyed, you should cater for that by either providing a cheap android device (non sim) for multifactor use of even better/cheaper - we use thestis fido USB hardware keys - they work great and are only 30 bucks off amazon. I don't get the whole "I don't want to use my personal phone for work but need to be able to work from my home computer/laptop" people. Not wanting work stuff on personal devices I get. But why would you be okay with work stuff on your laptop but not your phone?
LeMarchand Posted January 29, 2025 Posted January 29, 2025 I don't get the whole "I don't want to use my personal phone for work but need to be able to work from my home computer/laptop" people. Not wanting work stuff on personal devices I get. But why would you be okay with work stuff on your laptop but not your phone? Our refusenik just tries to get as much free kit as possible.
dhicks Posted January 29, 2025 Posted January 29, 2025 How are you accommodating staff that refuse to use their phones for 2FA. We have a no-phones-visible-around-school policy for staff, and therefore can't expect them to use their own phone as a 2FA device. We have instead issued USB keys to all staff, which (so far), has worked well - there's a couple of recent related threads: https://www.edugeek.net/forums/hardware/239969-what-people-using-mfa-tokens-hardware.html#post2052735 I think it's helped that we have staff use the same key for door entry and printer logins, now they just have one token that covers all three, and as it's also effectivly their door key they don't tend to forget to bring them in.
Sylv3r Posted January 30, 2025 Posted January 30, 2025 SafeID dongles for all staff ~2,000. We would rather staff didn't use their personal devices - phones etc. Even inside of school, we've not setup conditional access so they are prompted for the code - would much rather a member of staff get their trust provided MFA device out then their personal mobile phone. It's been an expensive journey, but I think worth it. However, we will no doubt come to a point in time when all the batteries run-out at the same time - then we may have to have a rethink.
Oaktech Posted January 30, 2025 Posted January 30, 2025 One site is entirely 2fa for every login, no exceptions and we're issuing OTP C200 dongles to all of them, staff and Y6. My other 2 sites are both conditional access onsite to not require the 2fa onsite and we give dongles to staff who don't want to use personal devices offsite - therre's literally been 6 staff out of 150 who won't or can't. https://www.microcosm.co.uk/order/product.php?ProductID=396
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now