Jump to content

Recommended Posts

Posted

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID | Microsoft Security Blog

Quote

 

February 1, 2027     Microsoft-provided SMS and voice authentication ends.  

If SMS or voice remains necessary for specific users, configure a supported telecom provider before this date. 

 

 

Not sure how this will work without a company provided device for every user that can do some kind of biometrics or TOTP. The ones we do have on SMS or phone call is because they couldn't do TOTP and either didn't want to install an app on their personal phone (which is a perfectly acceptable reason) or couldn't due to free space for example. (Our MIS enforces TOTP as the lowest level accepted but lots of staff don't have or need access to it )

Posted

That's been coming a while, been lots of information about SMS not being a particularly good method. I expect Google to follow suit soon. However yes, that's pretty much the shape of it and something for your SLT to decide on. Personally I'd be playing the "you know, you could install this app on your phone which controls nothing, does nothing, links to no account if you don't want it to and just gives you a number, or we could buy you hardware which if you lose it, you pay for it, and we lose a TA to pay for them up front" card. Because that's reality for some schools and frankly some adults need to grow up. I understand not wanting to install something on your phone if it gives any control like MDM, but this day and age *everyone* should have a 2FA app on their phone for personal use anyway.

 

Posted
3 hours ago, synaesthesia said:

I understand not wanting to install something on your phone if it gives any control like MDM, but this day and age *everyone* should have a 2FA app on their phone for personal use anyway.

 

I agree but i guess should they be reading work emails on a personal device? and if they have a work device why are they using their phone for 2FA. We can do device compliance for their personal phone which does have some privacy issues but then we should also do passkeys to protect against common phishing although not short term token hijacking which would require device compliance

In the same way they should have 2FA on their phone for personal use I'm starting to shift towards employers have lagged behind and should jump ahead to provide a cheap android phone maybe for all work use, no access at all on personal devices, but I can see it being argued against and exceptions made.

 

 

Posted

Absolutely, no need for emails to be on personal devices without control. Authenticator can be used without any account attached easily.

And if course would anyone really want to heave around 2 phones? Again, another thing to lose/damage. Could argue it stays in school of course but it rather defeats the point and a Fido key will just be easier/cheaper. 

There is still a delicate balance between privacy, data protection and safeguarding control and the DfE/government have yet to figure out how to get that balance with contradicting or unfeasible options given. 

Could happily argue for all work related stuff to be on staff laptops only, realistically though that's a pain for for the more mobile and those options start to get expensive.

As it stands, and not needing to comply with Cyber Essentials outside of FE, I'm of the mind to convince people to take the path of least resistance for authenticator at least. Emails etc, for now it's fine but should we go down that road then it's either MAM or not on personal devices whatsoever, and suspect the majority would prefer the latter. For the others, they have a laptop and in one case only a cheap phone.

  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...