Jump to content

Recommended Posts

Posted

I am looking at implementing 2FA for us IT Techs when logging into servers either remotely or at the console. There seems to be a free version of Duo but I cannot tell if it integrates with Windows to provide 2FA or whether it's one of the paid versions.

 

What are folks using for 2FA for Server logins please?

 

Thanks

Posted
We use the free version of Duo. It's free up to a maxiumum of 10 users. We use it for servers and our main workstations.
  • Thanks 1
Posted

We use the paid for version of Duo - we've got 20 staff but I think the only limitation of the free version is the number of staff.

 

We've had no issues at all with the product and can 100% recommend it.

  • Thanks 1
Posted

Just trying to set up and wondered what you guys have chosen as the options during install? Any ticks shown in the screenshots are there by default.

 

step 1.pngstep 2.pngstep 3.png

Posted

I think it’s potentially a game changer and it’s all for the better, I’d be interested in the decision that go behind this for people

 

For example what are you gain buy installing this e

 

For example

 

On our servers the only people that can rdp to them is the support department,

 

second to this only the IP address registered against the ports on the windows firewall will accept the rdp connection, our IP address are reserved,

 

Also what happens if your schools lose connection, do you then compromise on security to by pass 2fa ? So you can login

 

It’s a tricky one as I know all setups will be different, and different requirements etc

 

But it’s good that we are thinking about the next level of security for our servers,

 

I’ve registered with duo this evening and will definitely be having a play tomorrow, will I put it on my servers I don’t know is my honest answer

 

What are other peoples thoughts pros vs cons etc

Posted
I think it’s potentially a game changer and it’s all for the better, I’d be interested in the decision that go behind this for people

 

For example what are you gain buy installing this

 

 

RDP is shortform for "Ransomware Delivery Protocol" in certain areas of IT security. By 2FA'ing it, it adds an extra layer of protection for your internal servers. Even if an attacker gets on your network, it's then difficult for them to jump straight onto a server & escalate upwards from there.

 

The real issue is why MS haven't done this themselves yet

Posted (edited)
RDP is shortform for "Ransomware Delivery Protocol" in certain areas of IT security. By 2FA'ing it, it adds an extra layer of protection for your internal servers. Even if an attacker gets on your network, it's then difficult for them to jump straight onto a server & escalate upwards from there.

 

The real issue is why MS haven't done this themselves yet

 

Yea I understand that and I agree adding 2FA to the servers is only a good thing, my unease is around lost of

 

Loss of internet connectivity

 

Trusting a company that helps unlock your severs

 

Having to decide on what the best settings to use, as god forbid loosing access to a server is never good especially if a domain controller, (as per prev post about recommendations on settings)

 

These are just 3 thing from top of my head

 

But again it’s a good idea and it’s something we all should do and start to think about doing, I’ve currently created an account to start having a play myself

 

But if you do decide not to put the software directly on the servers it should definitely be on IT support admin pcs which have access to servers.

 

 

The real issue is why MS haven't done this themselves yet

 

I agree it is strange

 

Thoughts?

Edited by kevin_lane
Posted

I'm sure when I've used duo before, there's been an option to generate recovery/bypass codes that can be used in place of a prompt/OTP in case of issues with connectivity etc.

 

Obviously the issue then becomes recording/storing that securely as to not compromise the security the MFA provides in the first place.

 

Chris

Posted
I'm sure when I've used duo before, there's been an option to generate recovery/bypass codes that can be used in place of a prompt/OTP in case of issues with connectivity etc.

 

Obviously the issue then becomes recording/storing that securely as to not compromise the security the MFA provides in the first place.

 

Chris

 

You can setup a USB key for offline access. This works on your every day machine but not really on virtual servers.

  • 2 weeks later...
Posted
Just trying to set up and wondered what you guys have chosen as the options during install? Any ticks shown in the screenshots are there by default.

 

[ATTACH=CONFIG]69809[/ATTACH][ATTACH=CONFIG]69810[/ATTACH][ATTACH=CONFIG]69811[/ATTACH]

These are the options we use. You can also deploy it group policy and configure Duo with Group policy so you dont have to do it on each server. (Again thats how we do it).

 

Make sure to leave the bypass feature enabled as when you have no internet it won't promoted for it. Unless you want to setup offline codes for every server you have.

  • Thanks 1
Posted
What are folks using for 2FA for Server logins please?

 

We have our remote gateway behind Cloudflare's Zero-Trust product - handles Google (for us, several other providers supported) logins, which for our staff are all 2FA protected. You can have 50 users on their free tier, which is pretty generous - we might move our general staff remote gateway to that, too. There's also NGrok, which offers something similar - less users for free (3, I think), but more affordable per-monthly-user.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...