Free tools Windows power users keep installed
One-click scans. No signup required.
Ask vendors to demonstrate how they authenticate users, enforce multifactor authentication (MFA), limit access to student records, handle account recovery, and control their own staff’s access. Put the questions below into demonstrations, security questionnaires, and contract reviews; ask for evidence rather than relying on assurances. This U.S.-oriented guide draws on federal guidance and does not replace state-specific privacy or contract review.
Questions to ask about authentication and MFA
Which authentication methods do you support, and can our school require MFA for every account?
Ask the vendor to explain how MFA applies to students, staff, parents and guardians, support personnel, and vendor administrators. Can the school enforce its policy through its identity provider, through the product’s own controls, or both? Ask the vendor to show where those settings are configured and how the school can confirm which accounts are covered.
Do you support phishing-resistant MFA, and which users can use it?
Ask the vendor to identify supported phishing-resistant methods and demonstrate setup for the account types the school uses. Request a clear list of limitations by role or deployment. CISA says phishing-resistant MFA is the standard K–12 leaders should strive for, while noting that any MFA is better than none. See CISA’s 2023 K–12 cybersecurity report.
How are privileged and support accounts protected?
Ask which accounts have elevated permissions, whether MFA is mandatory for school and vendor administrators, and how those accounts are reviewed. Ask how the school can identify accounts that lack MFA and how exceptions are remediated. CISA specifically recommends MFA for administrators and other users with elevated privileges, as well as regular identification and remediation of accounts without MFA. A vendor should be able to explain its process and show the relevant controls, not simply say that administrators are protected.
#1 Best Overall
Questions about school identity systems and access boundaries
Can the product integrate with our single sign-on and identity-management environment?
Ask how the product works with the school’s single sign-on (SSO) and identity and access management (IAM) systems. What happens to access when the school disables or removes a user’s account? Can local product accounts, emergency accounts, or other sign-in routes bypass school authentication policies? Ask the vendor to demonstrate the full account lifecycle, including deprovisioning. CISA notes that applications may each have their own MFA and that a comprehensive SSO solution may centralize IAM controls; schools should assess whether that approach fits their environment, rather than treat it as a universal requirement. See the CISA K–12 cybersecurity report.
How do roles and permissions restrict access to records?
Ask the vendor to demonstrate what a teacher, counselor, school administrator, and support account can see and change. Find out how roles are assigned, reviewed, changed, and removed, and whether the school can inspect those assignments. Under FERPA, schools must use reasonable methods to ensure school officials see only records in which they have legitimate educational interests. The Department of Education says physical or technological access controls can meet this purpose; if those controls are not used, an effective administrative policy must control access. See the Department’s FERPA guidance on limiting school officials’ access.
Rank #2
Questions about identity verification and account recovery
How do you verify the identity of people accessing education records?
Ask how the vendor verifies students, parents and guardians, staff, and other recipients before allowing access to personally identifiable information from education records. Ask the vendor to walk through account recovery when someone loses an authentication device or changes contact details. What checks prevent another person from taking over the account, and what happens if those checks fail? FERPA regulations require reasonable methods to identify and authenticate people before protected information is disclosed or made accessible. See the Department of Education’s FERPA regulations and guidance.
Questions about vendor staff, subcontractors, and student data
What access do your employees and subcontractors have?
Ask which vendor and subcontractor roles can access school data, what conditions authorize access, and how access is limited, logged, and reviewed. Ask how the school can learn about and govern that access under its agreement with the provider. If a provider is treated as an outsourced school official under FERPA’s school-official exception, the party must be under the school’s direct control concerning the use and maintenance of education records, along with meeting the exception’s other conditions. See the Department’s explanation of who qualifies as a school official under FERPA.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsHow do you protect children’s information from unauthorized access or use?
Ask the provider to explain its practices for maintaining confidentiality and security and preventing unauthorized access or use. Request a demonstration or other evidence relevant to the school’s assessment before sharing information. FTC COPPA guidance tells schools to determine a service provider’s data practices for these purposes before sharing children’s information. See the FTC’s COPPA frequently asked questions.
Questions about default protections and security evidence
Which protections are on by default, and what must the school enable or buy?
Ask the vendor to demonstrate the standard configuration and identify any security controls that require a separate switch, configuration, or purchase. Clarify who is responsible for enabling and maintaining each control, and how the vendor communicates configuration changes. CISA’s K–12 technology-acquisition guidance calls for software with standard security features out of the box and frames secure-by-design around customer security outcomes, transparency and accountability, and organizational leadership. See CISA’s Cybersecurity Guidance for K–12 Technology Acquisitions.
Rank #4
What evidence can you provide for the controls you describe?
Ask for evidence that fits the school’s risk and procurement process, such as a live demonstration, configuration documentation, or answers to the school’s security questionnaire. Ask the vendor to explain how it takes responsibility for customer security outcomes and how it will notify the school of relevant changes. The cited federal guidance does not make any particular certification, penetration-test report, or questionnaire a universal legal requirement; schools should decide what evidence is appropriate to their circumstances.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to compare vendors consistently
Use the same questions and request comparable demonstrations from each vendor. A practical comparison can track:
- MFA coverage and enforcement across students, staff, families, support personnel, and administrators.
- Support for phishing-resistant MFA and any role or deployment limits.
- SSO/IAM integration, local-account exceptions, and account deprovisioning.
- Protections and review practices for privileged and vendor-support accounts.
- Role granularity, record-access boundaries, and access reviews.
- Identity verification and recovery procedures.
- Security controls enabled by default, controls requiring school action, and how vendor access and use of records are governed.
These are practical comparison criteria drawn from the federal guidance cited above, not a prescribed CISA scoring model. Apply them in light of the school’s jurisdiction, data-sharing arrangement, risk level, and procurement process.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

