Jump to content

Recommended Posts

Posted

Hi all,

 

I lead a small IT team comprising of myself and 4 techncians managing just under 50 schools. I am making it a requirement that all our schools we have global administrator access to have app based MFA setup for access. Currently we have an office mobile receiving SMS codes which we request from our admin staff who are in office during the weekdays which we need to request over teams. I don't find SMS authentication secure and this also limits our access to our portals when attempting to do out of hours work.

 

My ideal setup would be app based authentication that can be shared with all my technicians using a single login. I'm aware MS authenticator can be signed in on multiple devices, however I'm seeing conflicting reports on whether the passcodes actually sync across devices, or whether restoring the accounts saved on another device will de-activate the device the accounts were backed up from.

 

Any one else in a similar position or have suggestions on best practice to work around this?

Posted
Don’t share credentials. Particularly for global admin! Can you not get FIDO2 key for each tech which can be used for multiple accounts? More secure than voice,sms and app.
  • Thanks 1
Posted

USB security keys for each person and/or store T-OTP secrets in a password manager.

 

If more than one person needs to be able to use a particular account (!) then you can register more than one of those sescurity keys to the account as required.

 

Similarly, you can also use T-OTP with the secrets stored in a password manager. That secret can be plumbed into as many different T-OTP authenticator apps as you like/need, so that staff members aren't needing to share physical devices for MFA.

Posted (edited)
Another vote for Hardware Keys/authentication. Sharing Codes and logins is defo not a good idea. Ideally too would be to have a dedicated account for each admin that is separate from their day to day user account. Edited by Davit2005
  • Thanks 2
Posted
Me and my team require a "user" account with no elevated rights and an admin account that is very restricted in what it has access to but enough to administer systems. Results in a lot of individual accounts for all of us but we use keeper for account management with MFA functionality within it. Been a very good investment so advocate considering something like this and introduce individual accounts.
Posted
I cannot tell what is happening here, is this someone just poking a bear or have I hit my head and woke up in the 00's? Sharing accounts let alone ones with any kind of Admin role(s) is a no (and there is no exceptions here!). Stop that and do anything else!
Posted
It's much more common for certain web companies to charge per user per month, so for this sort of thing we'd use a shared account: hence the bitwarden recommendation for MFA codes shared per team
Posted

And that being said the OP is talking about GA Role and MS are not one of those companies that have that licensing structure so in this case it is not a thing (and for those that still do that for Admin staff then I would be having a conversation and still would not be convinced! as traceability is more important than cost)

 

I have made a statement there not fully knowing how this is architected so I don't know if the OP is saying that each of the 50 schools has it's own tenant with a GA in each rather than each admin having a priv account in each tenant (if this is the case and they are all under the same umbrella trust then this should be looked at) or they are all in the same tenant but even with all that said sharing a GA account with multiple should not be a thing in my mind.

Posted
Named admin accounts for each admin staff member makes sense, with suitable privileges as required. But is there not still a place for generically named (i.e. not tied to an individual) super admin accounts? My understanding is that you have them, and that organisation management has break-glass access to them, but you look to use them as little as possible.
Posted
Named admin accounts for each admin staff member makes sense, with suitable privileges as required. But is there not still a place for generically named (i.e. not tied to an individual) super admin accounts? My understanding is that you have them, and that organisation management has break-glass access to them, but you look to use them as little as possible.

When we set up MFA, part of Microsoft's documented procedure was to set up a "break-glass" admin account for use if MFA failed and the regular, named administration accounts couldn't log in.

Posted (edited)
When we set up MFA, part of Microsoft's documented procedure was to set up a "break-glass" admin account for use if MFA failed and the regular, named administration accounts couldn't log in.

 

Absolutely. But the break glass accounts are meant to be just that. Kept under metephorical glass, which is only broken in the case of emergency. To ensure Confidentiality (because admin privs can be scoped to the need of the specific admin and Integrity (because actions can always be assigned to the person who took them), which is two-thirds of the cybersecurity CIA Triad, one should always use named admin accounts whenver possible.

 

Microsoft Authenticator will support this. It is possible for one authenticator app to support MFA for many tenants, though this does preclude things like passwordless/passkeys, as this requires that the device is registered with one tenant.

Edited by Roberto

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...