paulkerton Posted February 23 Posted February 23 We can't be the only ones scratching our heads over this one! Supply staff. Schools can't run without them but from an IT and safeguarding perspective, they sit in this really awkward middle ground. They need enough access to actually do their job on the day, but they're in and out so fast that proper account management often goes out the window. So what are you all actually doing? I know a lot of schools are still handing out a shared "supply" login at the front desk. I get why as it's quick and easy when someone rocks up at 8:15am, and need to be teaching within 30 minutes. But then MFA comes along and suddenly nobody can agree whether it should be on a phone, whether it should be a hardware key, what kinda device they get to access, do you just generate one-time passcodes... and then the password gets written on a Post-it, and before you know it you've got no idea who's actually been logging in and whether the account has been reset nightly. Most of this has just grown organically because schools are busy and people are just trying to get through the day. But I think it's worth trying to figure out what a sensible approach actually looks like, especially as Cyber Essentials and general expectations around account security keep moving the goalposts. Are you using named accounts for supply? If so, how are you turning those around quickly enough when someone's booked last minute? Have you found a way to make MFA work that isn't a complete nightmare in practice? Or are you still in the "we know it's not ideal but here we are" camp? Not here to judge anyone, cause I know this is a constantly moving target. I'm genuinely curious what's working (or not) for people, and how we can work this out as a sector.
altecsole Posted February 23 Posted February 23 We have generic Cover accounts. We use conditional access, so no MFA required for accessing M365 from the school site. We also have a rule which blocks the accounts from signing in from anywhere other than the school site.
ShellfishClive Posted February 23 Posted February 23 The main setup we use for supply is exactly how you have mentioned above. We have a generic account "SchoolSupply", when the account isn't in use we disable and the school will ask us to enable it the day of. We find the school can wait that extra 2/3 minutes for us to enable the account and reset the password. The account itself has restricted access to the shared areas, although we do have central locations for just supply teachers to access where the teacher they are covering can drop work if needed and we have MFA turned off on these accounts as well. We can't find a way to have MFA setup where it isn't just a massive hinderance, so we have it disabled and manually just enable/disable the account as and when it's used.
Rob_D Posted February 23 Posted February 23 We have named accounts for cover teachers, but most external supply are for long-term cover and the school handles most day-to-day stuff internally. (Back when we used more external cover, we found we had the same supplies in over and over, which really helps, but that was about 10 years back) If they're short term then they can only access the "cover work site" and have conditional access for onsite logins only, and the accoutns are auto-disabled every night anway. If they're longer term and have more access then they'd have an ICT induction and be told to set up MFA the same as any other new starter.
TwistedHelixis Posted February 23 Posted February 23 Shared accounts have nearly all cloud apps disabled. We just have a supply shared drive and the staff drop stuff there if needed. We also have supply only laptops, so the 2 step has already been used on that device, so its not needed when the actual supply logs in.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now