Jump to content

Recommended Posts

Posted
We're considering enabling MFA using an authenticator app on our mobiles for all of our Office 365 admin accounts. However we use services such as Salamander AD, which has it's own admin account to automate account provisioning. How are services like this affected by MFA? I'm assuming they won't work, is that correct?
Posted

Salamander can make this work and there are things like app password that you use with Outlook. We have MFA for admins and Salamander setup both working together happily - I'm certain Salamander support had to change the configuration but I don't recall why or what was changed.

 

Might be worth throwing them a support request before enabling MFA?

Posted
Salamander can make this work and there are things like app password that you use with Outlook. We have MFA for admins and Salamander setup both working together happily - I'm certain Salamander support had to change the configuration but I don't recall why or what was changed.

 

Might be worth throwing them a support request before enabling MFA?

Strange. We have just received a reply from Salamander who outright said no, Salamander does not support using MFA for any accounts.

Posted (edited)

I remember there being no support for MFA with Salamander but they can tweak the software to make it run while you have MFA on the admin accounts - we have MFA for admins and Salamander working together in production :confused: it works one way or another, maybe you're using Salamander features we don't which is stopping the setup?

 

:\ Salamander is setting up our Office 365 groups, licensing users etc. and when I'm off site I have to use MFA to access the tenancy... Maybe its's as simple as the account used by Salamander doesn't use MFA in our setup? Could you geofence the account so it can only login from your subnet, adding some security to the Salamander admin account?

Edited by ThomL
Posted
I remember there being no support for MFA with Salamander but they can tweak the software to make it run while you have MFA on the admin accounts - we have MFA for admins and Salamander working together in production :confused: it works one way or another, maybe you're using Salamander features we don't which is stopping the setup?

:\ Salamander is setting up our Office 365 groups, licensing users etc. and when I'm off site I have to use MFA to access the tenancy... Maybe its's as simple as the account used by Salamander doesn't use MFA in our setup? Could you geofence the account so it can only login from your subnet, adding some security to the Salamander admin account?

We have enabled MFA only on the AD/O365 accounts we use ourselves to log in. Salamander is using it's own AD domain admin service account.

 

We're using Salamander to automatically provision AD accounts when staff/students are entered in SIMS with start dates (as well as disabling the account when an end date is entered, and account modification if a change to the name has been made, etc). It will also provision the user's Office 365 account with licenses and setup OneDrive. It also manage AD security/distribution groups based on forms/lessons from SIMS.

Posted
Sounds like what we are doing with it - I think without MFA support for salamander currently you're left with other means of securing the account. Having MFA on the accounts you actively use has to be a big plus towards security.
Posted

Yea, Salamander doesn't support MFA at the mo (Prob because it has no way of storing the TOTP keys) - I've sorta protected it by putting MFA on it, but applying conditional access on it's account outside of school so if it's coming via our main IP it doesn't need MFA, but if anyone tried to logon to it externally, they'd get slapped with MFA.

 

I have Azure AD P1 for this

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...