[Advisory] RE: Two factor authentication

Glyn Pascoe gpascoe@cprlearningspace.co.uk
Thu, 18 Feb 2010 09:17:22 +0000


--_000_F484D1560524AE4B907E6B5E21BF097321E38A6E8FtiggerCPRLSAD_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi David,

We are also looking at this for some of our supported school, currently we =
use the Sonicwall VPN 200 series installed in the majority of our sites. Th=
is allows staff to access their virtual desktop and applications using RDP =
by utilising a personal desktop at home.  Or if they take their encrypted l=
aptops home they can use the built in system called netextender which is ba=
sically a VPN so it allows them to access everything like they were sitting=
 with their laptops at school.

With regard to the two factor authentication, we are currently looking at a=
 company called SecurEnvoy. http://www.securenvoy.com/ They provide a servi=
ce that will work alongside our existing Sonicwall systems and instead of p=
roviding each member of staff with a hardware token, it simple texts the nu=
mber to the user's mobile phone. Therefore keeping the cost to a minimum as=
 we all know the expense if someone looses a hardware token.

This is just something I have been looking into but I would be grateful to =
hear other ideas that other people have tried / implemented.

Many thanks

Glyn

******************************************************************
* View the new CPR SWGFL Merlin website, log help requests and find the    =
 *
* latest ICT news within the CPR http://intranet.cprlearningspace.co.uk<htt=
p://intranet.cprlearningspace.co.uk/>         *
******************************************************************

Glyn Pascoe
ICT Networks' Manager
ICT Systems' Support Team
Children, Schools and Families
Cornwall Council

Tel: 01209 610146
Mob: 07891 840695
Fax: 01209 719506
gpascoe@cprlearningspace.co.uk<mailto:gpascoe@cprlearningspace.co.uk>

CPR Learning Space, Cranberry Road, Camborne, TR14 7PJ
Intranet.cprlearningspace.co.uk<http://intranet.cprlearningspace.co.uk/>
www.cornwall.gov.uk<http://www.cornwall.gov.uk/>

Please let us know if you need any particular assistance from us, such as f=
acilities to help with mobility, vision or hearing, or information in a dif=
ferent format

Please consider the environment. Do you really need to print this email?

From: advisory-admin@talk.naace.org [mailto:advisory-admin@talk.naace.org] =
On Behalf Of Tidman , David
Sent: 16 February 2010 5:12 PM
To: advisory@talk.naace.org
Subject: [Advisory] Two factor authentication

Colleagues, does anyone know of anywhere where they have rolled out two fac=
tor authentication to schools to meet the requirements' of data security fo=
r teachers? We are trying to find any LA's or schools who has done this at =
a cost effective level, particularly for accessing confidential information=
 such as email and IMS data.
Regards
Dave

David Tidman
E-learning Consultant
Berneslai Close
Barnsley
S70 2HS

Phone:01226 773551
Mobile: 07792813025


*** Barnsley MBC Disclaimer:
This e-mail and any files attached are confidential for the use of the inte=
nded recipient. If you have received this e-mail in error please notify the=
 sender as soon as possible and delete the communication from your system w=
ithout copying, disseminating or distributing the same in any way by any me=
ans.

Any views or opinions expressed belong solely to the author and do not nece=
ssarily represent those of the Council. In particular, the Council will not=
 accept liability for any defamatory statements made by email communication=
s.
Recipients are responsible for ensuring that all e-mails and files sent are=
 checked for viruses. The Council will not accept liability for damage caus=
ed by any virus transmitted by this e-mail. No guarantees are offered on th=
e security, content and accuracy of any e-mails and files received. Be awar=
e that this e-mail communication may be intercepted for regulatory, quality=
 control, or crime detection purposes unless otherwise prohibited.
The content of this email and any attachment may be stored for future refer=
ence.

________________________________
Please note that the CPR Learning Partnership may need to disclose this e-m=
ail under the Freedom of Information Act 2000 or the Environmental Informat=
ion Regulations 2004.
Important: This e-mail and its attachments are intended for the above-named=
 only and may be confidential. If they have come to you in error you must t=
ake no action based on them, nor must you copy or show them to anyone; plea=
se e-mail us immediately at admin@cprlearningspace.co.uk
Security Warning: Although this e-mail and its attachments have been screen=
ed and are believed to be free from any virus, it is the responsibility of =
the recipient to ensure that they are virus free. The CPR Learning Partners=
hip will not accept liability for any damage caused by a virus

--_000_F484D1560524AE4B907E6B5E21BF097321E38A6E8FtiggerCPRLSAD_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:x=3D"urn:schemas-microsoft-com:office:excel" xmlns:p=3D"urn:schemas-m=
icrosoft-com:office:powerpoint" xmlns:a=3D"urn:schemas-microsoft-com:office=
:access" xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:s=3D"=
uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" xmlns:rs=3D"urn:schemas-microsof=
t-com:rowset" xmlns:z=3D"#RowsetSchema" xmlns:b=3D"urn:schemas-microsoft-co=
m:office:publisher" xmlns:ss=3D"urn:schemas-microsoft-com:office:spreadshee=
t" xmlns:c=3D"urn:schemas-microsoft-com:office:component:spreadsheet" xmlns=
:odc=3D"urn:schemas-microsoft-com:office:odc" xmlns:oa=3D"urn:schemas-micro=
soft-com:office:activation" xmlns:html=3D"http://www.w3.org/TR/REC-html40" =
xmlns:q=3D"http://schemas.xmlsoap.org/soap/envelope/" xmlns:rtc=3D"http://m=
icrosoft.com/officenet/conferencing" xmlns:D=3D"DAV:" xmlns:Repl=3D"http://=
schemas.microsoft.com/repl/" xmlns:mt=3D"http://schemas.microsoft.com/share=
point/soap/meetings/" xmlns:x2=3D"http://schemas.microsoft.com/office/excel=
/2003/xml" xmlns:ppda=3D"http://www.passport.com/NameSpace.xsd" xmlns:ois=
=3D"http://schemas.microsoft.com/sharepoint/soap/ois/" xmlns:dir=3D"http://=
schemas.microsoft.com/sharepoint/soap/directory/" xmlns:ds=3D"http://www.w3=
.org/2000/09/xmldsig#" xmlns:dsp=3D"http://schemas.microsoft.com/sharepoint=
/dsp" xmlns:udc=3D"http://schemas.microsoft.com/data/udc" xmlns:xsd=3D"http=
://www.w3.org/2001/XMLSchema" xmlns:sub=3D"http://schemas.microsoft.com/sha=
repoint/soap/2002/1/alerts/" xmlns:ec=3D"http://www.w3.org/2001/04/xmlenc#"=
 xmlns:sp=3D"http://schemas.microsoft.com/sharepoint/" xmlns:sps=3D"http://=
schemas.microsoft.com/sharepoint/soap/" xmlns:xsi=3D"http://www.w3.org/2001=
/XMLSchema-instance" xmlns:udcs=3D"http://schemas.microsoft.com/data/udc/so=
ap" xmlns:udcxf=3D"http://schemas.microsoft.com/data/udc/xmlfile" xmlns:udc=
p2p=3D"http://schemas.microsoft.com/data/udc/parttopart" xmlns:m=3D"http://=
schemas.microsoft.com/office/2004/12/omml" xmlns:st=3D"&#1;" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Arial","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Arial","sans-serif";
	color:windowtext;}
span.EmailStyle19
	{mso-style-type:personal-reply;
	font-family:"Verdana","sans-serif";
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page Section1
	{size:595.3pt 841.9pt;
	margin:35.95pt 42.55pt 72.0pt 14.2pt;}
div.Section1
	{page:Section1;}
-->
</style><!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-GB" link=3D"blue" vlink=3D"purple">
<div class=3D"Section1">
<p class=3D"MsoNormal"><a name=3D"_MailEndCompose"><span style=3D"font-size=
:10.0pt;
font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;">Hi David,<o:p></o:p=
></span></a></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;">We are also looking at this for some of=
 our supported school, currently we use the Sonicwall VPN 200 series instal=
led in the majority of our sites. This allows staff to access
 their virtual desktop and applications using RDP by utilising a personal d=
esktop at home.&nbsp; Or if they take their encrypted laptops home they can=
 use the built in system called netextender which is basically a VPN so it =
allows them to access everything like
 they were sitting with their laptops at school.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;">With regard to the two factor authentic=
ation, we are currently looking at a company called SecurEnvoy.
</span><a href=3D"http://www.securenvoy.com/"><span style=3D"font-size:10.0=
pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;">http://www.secur=
envoy.com/</span></a><span style=3D"font-size:10.0pt;font-family:&quot;Verd=
ana&quot;,&quot;sans-serif&quot;"> They provide a service that will work al=
ongside
 our existing Sonicwall systems and instead of providing each member of sta=
ff with a hardware token, it simple texts the number to the user&#8217;s mo=
bile phone. Therefore keeping the cost to a minimum as we all know the expe=
nse if someone looses a hardware token.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;">This is just something I have been look=
ing into but I would be grateful to hear other ideas that other people have=
 tried / implemented.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;">Many thanks<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;">Glyn<o:p></o:p></span></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;;
color:red"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;;
color:red">****************************************************************=
**<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;;
color:red">*
</span><span style=3D"font-size:10.0pt;font-family:&quot;Verdana&quot;,&quo=
t;sans-serif&quot;">View the new CPR SWGFL Merlin website, log help request=
s and find the&nbsp;&nbsp;&nbsp;&nbsp;
<span style=3D"color:red">*</span><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;;
color:red">*</span><span style=3D"font-size:10.0pt;font-family:&quot;Verdan=
a&quot;,&quot;sans-serif&quot;"> latest ICT news within the CPR
</span><a href=3D"http://intranet.cprlearningspace.co.uk/"><span style=3D"f=
ont-size:10.0pt;
font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;">http://intranet.cpr=
learningspace.co.uk</span></a><span style=3D"font-size:10.0pt;font-family:&=
quot;Verdana&quot;,&quot;sans-serif&quot;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;
<span style=3D"color:red">*</span><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;;
color:red">****************************************************************=
**<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;">Glyn Pascoe<br>
ICT Networks' Manager<br>
ICT Systems' Support Team<br>
Children, Schools and Families<br>
Cornwall Council<br>
&nbsp;<br>
Tel: 01209 610146<br>
Mob: 07891 840695<br>
Fax: 01209 719506<br>
</span><a href=3D"mailto:gpascoe@cprlearningspace.co.uk"><span style=3D"fon=
t-size:
10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;">gpascoe@cprl=
earningspace.co.uk</span></a><span style=3D"font-family:&quot;Verdana&quot;=
,&quot;sans-serif&quot;"><br>
</span><span style=3D"font-size:10.0pt;font-family:&quot;Verdana&quot;,&quo=
t;sans-serif&quot;">&nbsp;<br>
CPR Learning Space, Cranberry Road, Camborne, TR14 7PJ<br>
</span><a href=3D"http://intranet.cprlearningspace.co.uk/"><span style=3D"f=
ont-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;">Int=
ranet.cprlearningspace.co.uk</span></a><span style=3D"font-size:10.0pt;font=
-family:&quot;Verdana&quot;,&quot;sans-serif&quot;"><o:p></o:p></span></p>
<p class=3D"MsoNormal"><a href=3D"http://www.cornwall.gov.uk/"><span style=
=3D"font-size:10.0pt;font-family:&quot;Verdana&quot;,&quot;sans-serif&quot;=
">www.cornwall.gov.uk</span></a><span style=3D"font-family:&quot;Verdana&qu=
ot;,&quot;sans-serif&quot;"><br>
</span><span style=3D"font-size:10.0pt;font-family:&quot;Verdana&quot;,&quo=
t;sans-serif&quot;">&nbsp;<br>
Please let us know if you need any particular assistance from us, such as f=
acilities to help with mobility, vision or hearing, or information in a dif=
ferent format<br>
<span style=3D"color:green">&nbsp;<br>
Please consider the environment. Do you really need to print this email?</s=
pan></span><span style=3D"font-family:&quot;Verdana&quot;,&quot;sans-serif&=
quot;"><o:p></o:p></span></p>
</div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,&quot;sans-serif&quot;"><o:p>&nbsp;</o:p></span></p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:10.0pt;fo=
nt-family:
&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span lang=3D"EN=
-US" style=3D"font-size:10.0pt;
font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> advisory-admin@talk=
.naace.org [mailto:advisory-admin@talk.naace.org]
<b>On Behalf Of </b>Tidman , David<br>
<b>Sent:</b> 16 February 2010 5:12 PM<br>
<b>To:</b> advisory@talk.naace.org<br>
<b>Subject:</b> [Advisory] Two factor authentication<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Colleagues, does anyone know of anywhere where they =
have rolled out two factor authentication to schools to meet the requiremen=
ts' of data security for teachers? We are trying to find any LA&#8217;s or =
schools who has done this at a cost effective
 level, particularly for accessing confidential information such as email a=
nd IMS data.<o:p></o:p></p>
<p class=3D"MsoNormal">Regards<o:p></o:p></p>
<p class=3D"MsoNormal">Dave<span style=3D"font-size:10.0pt"><o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt">David Tidman</span>=
<o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt">E-learning Consulta=
nt</span><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt">Berneslai Close</sp=
an><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt">Barnsley</span><o:p=
></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt">S70 2HS</span><o:p>=
</o:p></p>
<p class=3D"MsoNormal">&nbsp;<o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt">Phone:01226 773551<=
/span><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt">Mobile: 07792813025=
</span><o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p><span style=3D"font-size:8.0pt;font-family:&quot;Arial&quot;,&quot;sans-=
serif&quot;">*** Barnsley MBC Disclaimer:<br>
This e-mail and any files attached are confidential for the use of the inte=
nded recipient. If you have received this e-mail in error please notify the=
 sender as soon as possible and delete the communication from your system w=
ithout copying, disseminating or
 distributing the same in any way by any means.<br>
<br>
Any views or opinions expressed belong solely to the author and do not nece=
ssarily represent those of the Council. In particular, the Council will not=
 accept liability for any defamatory statements made by email communication=
s.<br>
Recipients are responsible for ensuring that all e-mails and files sent are=
 checked for viruses. The Council will not accept liability for damage caus=
ed by any virus transmitted by this e-mail. No guarantees are offered on th=
e security, content and accuracy
 of any e-mails and files received. Be aware that this e-mail communication=
 may be intercepted for regulatory, quality control, or crime detection pur=
poses unless otherwise prohibited.<br>
The content of this email and any attachment may be stored for future refer=
ence.</span><o:p></o:p></p>
</div>
<br>
<hr>
<font face=3D"Verdana" color=3D"Gray" size=3D"1">Please note that the CPR L=
earning Partnership may need to disclose this e-mail under the Freedom of I=
nformation Act 2000 or the Environmental Information Regulations 2004.<br>
Important: This e-mail and its attachments are intended for the above-named=
 only and may be confidential. If they have come to you in error you must t=
ake no action based on them, nor must you copy or show them to anyone; plea=
se e-mail us immediately at admin@cprlearningspace.co.uk<br>
Security Warning: Although this e-mail and its attachments have been screen=
ed and are believed to be free from any virus, it is the responsibility of =
the recipient to ensure that they are virus free. The CPR Learning Partners=
hip will not accept liability for
 any damage caused by a virus<br>
</font>
</body>
</html>

--_000_F484D1560524AE4B907E6B5E21BF097321E38A6E8FtiggerCPRLSAD_--