Cracking Student MFA Without Student Phones

Cracking Student MFA Without Student Phones

By Derek Devine, Director of International Markets, Clever

Australian schools are under growing pressure to meet cybersecurity standards across their organisations, and multi-factor authentication (MFA) is one of the trickiest boxes to tick, especially for student accounts.

The reason is simple: most students don't carry a phone. Phones are banned during the school day in many schools, and plenty of younger students don't own one at all. Traditional MFA assumes a smartphone is sitting in someone's pocket, ready to receive a code. Take that assumption away, and IT teams are left with a compliance requirement they can't easily satisfy.

That gap is exactly what's pushing more schools to rethink what MFA looks like for students, and to look for an approach that drops into their existing environment and doesn’t cause friction in classrooms.

The problem with borrowing enterprise MFA for the classroom

Enterprise-grade MFA tools were built for adults with company laptops and personal phones. Drop that model into a primary school classroom and it falls apart fast. Six-year-olds can't manage an authenticator app. Shared devices break the one-to-one assumption most MFA systems are built on. And IT teams already stretched thin can't take on a flood of login-related help desk tickets on top of everything else.

Schools need an approach built for how classrooms actually work: age-appropriate, device-independent, and simple enough that a Year 3 student can use it without adult help. Just as important, it needs to sit on top of the identity systems schools already run.

How school-friendly authentication plays out in practice, in Microsoft and Google environments

Newcastle Grammar School, an independent school in New South Wales, ran into this exact hurdle. The school's students, especially in younger year groups, aren't permitted phones during the school day, and many Year 7 parents choose not to provide one at all. That made a standard second factor a non-starter, even as the school moved to a managed one-to-one device program built on Microsoft Intune and Entra ID.

IT Manager Michael Browning had spent years looking for a fix. Clever's visual authentication, where students select a simple combination of images instead of entering a code from a device, integrated directly with Entra ID through conditional access policies. Students log in with their Entra ID password, then Entra ID routes them to Clever for the second factor, no phone required. The Year 7 rollout of 120 devices went smoothly, and it's now unlocked modern authentication features like Windows Hello, cut down on SOC alerts tied to unexpected sign-in locations, and given the school a clear, confident answer when its board or cyber insurer asks about MFA coverage.

St Thomas More School in Hadfield, Melbourne, took a related path on the other major platform schools run on: Google Workspace. Before Clever, teachers were logging students into Chromebooks manually or relying on shared passwords written on sticky notes, sometimes losing up to half a lesson to login friction. STEAM Specialist Kate Mackintosh introduced Clever Badges, a secure physical passcode students flash at the webcam to unlock their device instantly. The school recovered 20 minutes of a 40-minute lesson, cut login-related IT tickets to zero, and built the unified identity foundation it now needs to move toward deviceless MFA and full Essential 8 alignment.

Two different schools, two different tools, two different ecosystems, but the same underlying shift: identity and MFA built around how young students actually use technology, and around the systems schools already have, not around adult assumptions or a single vendor.

Built to work with what schools already have

For most schools, the honest starting question isn't 'which MFA vendor should we adopt,' it's 'will this work with what we already run.' Clever's approach is built to answer yes either way. On Microsoft environments, Clever integrates directly with Entra ID through conditional access policies, so IT teams keep their existing sign-in flow and add a student-appropriate second factor on top of it. On Google environments, Deviceless second factors, like Clever Badges, slot into Google Workspace and Chromebook fleets the same way. Schools running a mix of both, which is common once you get past the primary years, don't have to choose.

What this means for schools working toward Essential 8

“From an Essential Eight perspective, MFA is one of the strongest controls we have against credential theft, phishing, and account takeover — threats that are increasingly targeting students, not just staff. A compromised student account is no longer low-risk; it can expose learning platforms, cloud storage, email, and identity systems.”

— Shaq Herath, Director of ICT, Trinity College

For schools working toward adopting tighter cybersecurity standards, the instinct is often to look for an enterprise MFA vendor and adapt it. What Newcastle Grammar and St Thomas More show is that adaptation is the wrong starting point, and that the fix doesn't have to come at the cost of the Microsoft or Google environment a school has already built. The fix isn't stretching adult tools to fit classrooms or ripping out existing identity infrastructure, it's starting from how classrooms actually work and layering student MFA on top of the systems already in place.

Talk to an MFA expert

Not sure what deviceless MFA looks like for your school? Our team can walk you through how Clever fits your existing systems, from Entra ID to Google Workspace, and how to get from where you are to Essential 8 compliance without disrupting a single lesson.

Talk to a Clever specialist →