Jump to content

Recommended Posts

Posted

Hello Everyone -

 

Just wanting to get a feel for what everyone's doing in terms of managing admin accounts and Office 365, with two factor.

One of the schools I work with has a couple of techs that share an admin acccount for Office 365 management but this leaves them currently without two factor auth - What's everyone else doing in this case, multiple separate accounts with two factor enabled or something else?

 

Thank you!

Posted

a) you can add a TOTP to more than 1 phone, just scan the QR code twice

b) you can add more than one 2FA to an account

c) you can just have multiple accounts, that's probably best

Posted
a) you can add a TOTP to more than 1 phone, just scan the QR code twice

b) you can add more than one 2FA to an account

c) you can just have multiple accounts, that's probably best

d) use a password manager that supports TOTP codes, and have a shared vault which both techs can use for shared account details plus individual vaults for their non-shared account details.

Posted

An account being shared shouldn't be a barrier to adding 2FA to it.

 

For instance, T-OTP (aka Authenticator) will be available to add and can be shared easily: when setting it up, either scan the QR on all devices that will need it, or display and note down (in a password manager) the secret/QR so that it can be added to further devices later on. Devices with the same secret will generate the same codes (the codes being a function of the secret and the current time).

 

We have a number of admin and/or shared accounts on Google and M365 that all have 2FA enabled in this way.

 

If you have USB security keys, you can also just add those to the account(s). Accounts can have multiple security keys associated with them, and an individual security key can be associated with multiple accounts.

Posted
My question would be, why are they sharing an admin account? If more than one person has access to an account you lose all hope of auditing and accountability. Set them both up with an appropriate admin account and your 2FA issue goes away.
  • Thanks 2
Posted

MFA is enabled across the board here, anyway.

 

A few of us have separate admin accounts that have directly assigned roles (such as Global Admin). We have recently moved to using Privileged Identity Management for 365 so that techs can use their everyday accounts for 365 activities on a basis of just-in-time escalation which always requires a 2FA authorisation. I weighed up the pro's and con's of giving the techs a separate 'admin' account for this but concluded that it's safe enough, given that they always need to MFA whenever elevating and Microsoft designed it this way, by default they don't have any active roles, only eligible roles.

 

Eligible roles are assigned to techs. Some roles require admin approval, some are self-approving. One example is the ability to reset a user's MFA, I've made it so they don't need admin approval for that, just a ticket number so we can check. PIM allows you to customise the maximum time that a role is available before requiring another elevation, and I've modified them to a reasonable time-frame to complete a task (I think the default is 8, I lowered it to 2 or less for some roles).

 

We get a notification when a tech elevates to a role.

 

I would not personally advise to be sharing an account, unless a system/service makes it unavoidable, and it should most certainly have MFA.

  • Thanks 1
Posted (edited)

Everyone should have their own admin account.

 

Our orginal GA admin has 2fa on it still tho, as we have 1password & that supports TOTP.

 

We have MFA on for every account (Even students)

Edited by DrCheese
Posted

I would suggest that sharing an admin account is not particularly GDPR compliant as it wouldn't really tick the requirement that personal data is processed securely by means of "appropriate technical and organisational measures" per the security principle. Having 2 admin accounts costs nothing extra, and ensures traceability of actions.

 

So, I would suggest the first thing to do is get them each to use an individual admin account for admin stuff, and then have 2FA protecting each.

  • Thanks 1
Posted

Even with well defined admin accounts/roles, there's presumably going to be a superadmin account that isn't associated with a named individual. That account will need suitable 'shared' MFA, with documented credentials.

 

Documenting/sharing MFA for any non-admin, departmental mailbox accounts, for instance, seems like a good idea.

Posted
Even with well defined admin accounts/roles, there's presumably going to be a superadmin account that isn't associated with a named individual. That account will need suitable 'shared' MFA, with documented credentials.

Documenting/sharing MFA for any non-admin, departmental mailbox accounts, for instance, seems like a good idea.

I would suggest such a super admin account should be locked away in a safe, along with a physical token for 2FA.

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...