Educause Security Discussion mailing list archives

Re: MFA requirement for faculty


From: "Telfer, Will" <Will_Telfer () BAYLOR EDU>
Date: Wed, 12 Sep 2018 17:55:49 +0000

  1.  Did you require it everywhere, or have exempt locations?  Like on your campus network, perhaps.
No exemptions allowed for students, faculty, & staff (there is one service account used for training that has a 
permanent bypass in place, but it was approved by the CIO/CISO who is my supervisor)


  1.  Did you allow devices to be "remembered?"
Yes, for 7 Days.


  1.  Was there any blowback from "helicopter parents" that were used to accessing their "child's" account?
I dealt with this at new student orientation at least 3 times per day, we allowed the parent to leave their device 
registered but set the student's device as the default. We recommend having a backup device enrolled & we cannot stop a 
student from sharing their username & password with their parent - I can explain FERPA is the reason that the student 
is the only one that can see their grades, but ultimately the parent is paying the bill & what happen between them & 
their child I can't really get in the way of...


  1.  If yes to #3, how did you deal with it?
I referred them to the Office of the Registrar where the student could fill out a FERPA release form & explained why we 
are using MFA to protect the accounts...but most of the time the parent just told the student to give them the password 
& accept the MFA request whenever it rolled in from them. I tried to educate, but ultimately I cannot stop them from 
allowing their parent into the SIS that contains their bill & grades (even though we have a system that they can enroll 
in at orientation that allows the parent access to the bill & the ability to contact Baylor to ask questions about the 
bill).

Please let me know if you have any more questions.


Thank You,
Will Telfer, M.S.
Information Security Analyst
Information Technology Services
[sig]
Twitter: @BearAware
Facebook: www.facebook.com/BearAware


From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of 
McClenon, Brady
Sent: Wednesday, September 12, 2018 12:37 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] MFA requirement for faculty

For those that rolled out MFA:


  1.  Did you require it everywhere, or have exempt locations?  Like on your campus network, perhaps.
  2.  Did you allow devices to be "remembered?"
  3.  Was there any blowback from "helicopter parents" that were used to accessing their "child's" account?
  4.  If yes to #3, how did you deal with it?



Brady McClenon
IT Security Administrator
ITS - IT Security
SUNY Oneonta

Information Security is Everyone's Responsibility!  Learn more at 
http://staysafeonline.org/ncsam/<https://na01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fstaysafeonline.org%2Fncsam%2F&data=01%7C01%7CWill_Telfer%40BAYLOR.EDU%7C7584ab8ee2cf4c0b2ed808d618d6649c%7C22d2fb35256a459bbcf4dc23d42dc0a4%7C1&sdata=%2F6Fg1mK6j9XE%2F9QQMX3eqgJEOLtvmSyPiaopyNqb5vs%3D&reserved=0>




From: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> On Behalf Of Manjak, Martin
Sent: Wednesday, September 12, 2018 1:28 PM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] MFA requirement for faculty

As far as Azure AD MFA, and the lack of token support, our experience was similar to Chris's. Out of nearly 16k student 
enrollments, we had less than a dozen who requested exemption based on not have a device to receive the second factor. 
We limited our rollout to students only.

Anyone whose account was compromised as a result of social engineering, regardless of their affiliation, is enrolled.

FAC/STAFF can request enrollment, but we haven't mandated it yet.

BTW, here's an article on 2-Step Login (our branding of MFA) that appeared in the last issue of our student press. [1]

Marty Manjak
CISO
University at Albany

[1] 
http://www.albanystudentpress.net/opinion-two-step-verification-long-overdue<https://na01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.albanystudentpress.net%2Fopinion-two-step-verification-long-overdue&data=01%7C01%7CWill_Telfer%40BAYLOR.EDU%7C7584ab8ee2cf4c0b2ed808d618d6649c%7C22d2fb35256a459bbcf4dc23d42dc0a4%7C1&sdata=W7jpEoQV%2B13ZQVPwN23Ghi5Bczww9EwlbIHl4xRAngw%3D&reserved=0>/

From: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> On Behalf Of Gregg, Christopher S.
Sent: Wednesday, September 12, 2018 10:47 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] MFA requirement for faculty

We require MFA for all users (faculty, staff, and students) for Office365, Banner and a couple of other applications.  
Adding MFA to other higher risk systems is in the works for this year.

We had executive support to include all users, and the rollout went smoother than I anticipated.  We're using Microsoft 
Azure AD MFA which doesn't support hardware tokens (yet) so we did need to exempt a small population of about 40 users 
who didn't have a cell phone, and couldn't use a desk phone as their 2nd factor.  I expected we might get a run on 
people saying they didn't have a cell phone if they thought it would get them out of MFA, but that didn't really 
happen.  Most of those 40 people were faculty though so you may want to factor that in to your planning.

Thanks,

Chris


Chris Gregg
Associate Vice President of Information Security & Risk Management, CISO
Information Technology Services (ITS)
csgregg () stthomas edu<mailto:csgregg () stthomas edu>
p 1 (651) 962-6265
University of St. Thomas | 
stthomas.edu<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.stthomas.edu&data=01%7C01%7CWill_Telfer%40BAYLOR.EDU%7C7584ab8ee2cf4c0b2ed808d618d6649c%7C22d2fb35256a459bbcf4dc23d42dc0a4%7C1&sdata=oz4PYVpqoVQvV5Y0dajnR7ccdzGAwKxHBEBUWTnBVL4%3D&reserved=0>



From: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> On Behalf Of Pitt, Sharon
Sent: Wednesday, September 12, 2018 9:20 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: [SECURITY] Fw: MFA requirement for faculty


Sending to the security list for response.  Harvard, you may want to consider joining this constituent group list.  In 
the meantime, I ask that we copy Harvard on responses.



As a quick response to Harvard, the University of Delaware requires MFA for all users (including faculty) on multiple 
tools, to include anything associated with our ERP and email.



Thanks all!


Sharon P. Pitt
Vice President of Information Technologies
University of Delaware
030 Smith Hall
Newark, DE 19716
(302) 831-0221

Co-Chair, Higher Education Information Security Council (HEISC)


spitt () udel edu<mailto:spitt () udel edu>
twitter@sppitt


________________________________
From: The EDUCAUSE CIO Constituent Group Listserv <CIO () LISTSERV EDUCAUSE EDU<mailto:CIO () LISTSERV EDUCAUSE EDU>> 
on behalf of Harvard Townsend <harvard.townsend () WHEATON EDU<mailto:harvard.townsend () WHEATON EDU>>
Sent: Wednesday, September 12, 2018 10:01 AM
To: CIO () LISTSERV EDUCAUSE EDU<mailto:CIO () LISTSERV EDUCAUSE EDU>
Subject: [CIO] MFA requirement for faculty

Good morning,
We need some help selling multi-factor authentication to our faculty. Quick question - how many of you require MFA for 
faculty? We currently require it for staff and are now moving forward with faculty. Replies to the mailing list or 
directly to me are greatly appreciated.
Regards,
--
Harvard Townsend
Director of Infrastructure & Security
Academic & Institutional Technology
Wheaton College, IL
Office: (630)752-5528

**********
Participation and subscription information for this EDUCAUSE Constituent Group discussion list can be found at 
http://www.educause.edu/discuss<https://na01.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.educause.edu%2Fdiscuss&data=01%7C01%7CWill_Telfer%40BAYLOR.EDU%7C7584ab8ee2cf4c0b2ed808d618d6649c%7C22d2fb35256a459bbcf4dc23d42dc0a4%7C1&sdata=rKlfUb6IPFXg9%2F32DnjeUhUQUEl0UZob5vSC2pkLmFA%3D&reserved=0>.


Current thread: