Jump to content

What MFA hardware tokens are you using with O365 / G Suite?


Recommended Posts

Posted
We’re mid rollout of MFA and are using that exact same Token2 device for the odd users that cannot use the Microsoft Authenticator App. Works really well and is easy to setup.
  • Thanks 1
Posted
What (if anything) are you using?

 

We've rolled out Yubikeys to senior management and admin staff as a start, we're considering what we do with other staff - those Token2 devices look like a good option, thanks.

 

Something we want to test out if we can:

 

https://breakdev.org/evilginx-2-next-generation-of-phishing-2fa-tokens/

 

Evilginx is a server that proxies a site, to which you can point a nearly-the-same domain name (g00gle.com, etc) in the hopes of phishing someone to visit your site thinking it's the original and capturing their login details. The above article points out that using a one-time-code 2FA mechanism doesn't protect against that kind of attack. However, I suspect if your site is using login-with-Google (or Microsoft, or other provider) that should offer suitible protection as Google (for instance) requires a valid host URL to be entered on their OAuth login setup to use login-with-Google on your site.

  • Thanks 1
  • 1 year later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...