Education West Yorkshire 280 staff, 4 schools 10 weeks phased rollout

Multi-academy trust hardens Microsoft 365 and blocks 1,400 malicious sign-ins a month

A four-school multi-academy trust with 280 staff hardened Microsoft 365 over 10 weeks, enforced MFA on 100% of staff accounts, blocked around 1,400 malicious sign-in attempts a month and recorded zero account compromises in the following 12 months.

Repeated staff account compromises were being used to send internal phishing to colleagues and parents. Multi-factor authentication was available but not enforced, and nobody was monitoring sign-in activity across the trust.

Client: Multi-academy trust, 280 staff and 2,600 pupil accounts. Name withheld under our confidentiality terms.

At a glance

Client
Multi-academy trust, 280 staff and 2,600 pupil accounts
Sector
Education
Location
West Yorkshire
Size
280 staff, 4 schools
Services
Microsoft 365 Security, Email Security, 24/7 SOC (MDR)
Timeline
10 weeks phased rollout
Headline result
~1,400 — Malicious sign-in attempts blocked per month

Measured results

Malicious sign-in attempts blocked per month
~1,400Malicious sign-in attempts blocked per month
Staff accounts enforced with MFA
100%Staff accounts enforced with MFA
Account compromises in the 12 months since
0Account compromises in the 12 months since
Phased rollout across 4 schools
10 weeksPhased rollout across 4 schools

The challenge

  • Three staff mailboxes compromised in one term, each used to phish colleagues and parents.
  • MFA was licensed but enabled for fewer than a third of staff accounts.
  • Legacy authentication protocols remained enabled, bypassing MFA entirely.
  • No visibility of sign-in attempts across four schools and 2,600 pupil accounts.

What we did

  1. 1

    Audited Microsoft 365 tenant configuration against the NCSC and Microsoft security baselines.

  2. 2

    Disabled legacy authentication protocols in stages, after identifying and migrating the few systems still using them.

  3. 3

    Enforced MFA for all staff accounts through conditional access, with a phased rollout by school.

  4. 4

    Restricted sign-in to managed devices and approved locations for administrative accounts.

  5. 5

    Onboarded identity and email telemetry to the 24/7 SOC for continuous monitoring.

  6. 6

    Trained staff on the new sign-in process before enforcement, reducing support calls at cutover.

The outcome

  • Account compromise, previously a termly event, stopped entirely.
  • Legacy authentication removed, closing the route that bypassed MFA.
  • Sign-in anomalies now trigger SOC investigation rather than going unseen.
  • Parents no longer receive phishing from genuine school addresses.
The damaging part was not the compromise itself, it was parents getting scam emails from a real school address. That stopped immediately.
Director of IT, multi-academy trust, West Yorkshire

The concepts behind this engagement

Plain-English reference pages explaining the certifications, threats and controls involved in this piece of work.

FAQ

Questions about this engagement

The questions businesses in a similar position ask most often before starting.

Why does MFA sometimes fail to prevent account compromise?

+

Usually because it is enabled rather than enforced, or because a bypass route remains open. Legacy authentication protocols such as IMAP, POP and SMTP AUTH predate MFA and cannot present a second factor, so an attacker with a valid password simply authenticates through one of those instead. Per-user MFA settings also leave gaps whenever a new account is created outside the process. Conditional access solves both: it applies policy to every sign-in by default rather than per user, and it lets you block legacy protocols outright. Disabling legacy authentication is normally the single highest-impact change in a Microsoft 365 tenant.

How do you enforce MFA across a school without overwhelming IT support?

+

By training before enforcing and rolling out in phases. In this trust each school was given a two-week window with drop-in registration sessions, printed guidance, and a clear cutover date, so the majority of staff had already enrolled before policy enforcement began. Administrative and finance accounts went first because they carry the most risk, and teaching staff followed by school. Support call volume at cutover was a fraction of what a tenant-wide overnight switch would have produced. The phased approach took ten weeks rather than one, and that trade was worth making.

Should pupil accounts be secured the same way as staff accounts?

+

Not identically, because the risk profile differs. Staff accounts hold personal data on pupils and families, financial systems access and the credibility to phish parents, which is why they received enforced MFA and device restrictions here. Pupil accounts carry lower data risk but far higher volume and much weaker password practice, so the controls that work are different: blocking legacy authentication, restricting external sending, disabling risky sharing, and monitoring for bulk anomalies. Applying full staff-grade MFA to 2,600 pupils would generate substantial support load for a smaller reduction in real risk.

Related case studies

Two ways to get started

Not sure what you need? Speak to us. Want ongoing protection? Try it free.

Book a free 30-minute Cyber Security Review with our UK team, or start a 14-day free trial of Cyber Shield and see the difference for yourself.

Not sure what you need?

Book a Cyber Security Review Takes 30 minutes. No obligation.

Want ongoing protection?

Start Cyber Shield Free Trial14-day free trial. Cancel anytime.
Reply within 1 working hour UK-based specialists No obligation either way