ITGuyNW Posted May 18 Posted May 18 Hi all Just reviewing login security and two factor for admins. I feel like I have too many eggs in one basket. I also found out my Microsoft authenticator is no longer allowing me to do a cloud backup! For example, if you have a Microsoft admin, do you also use Microsoft authenticator or do you go with someone else like 2FAS so its held with someone else? How do other people diversify their security? Do you just have the one ecosystem and are happy or do you use a couple different ones etc?
itskdog Posted May 18 Posted May 18 I use Microsoft Authenticator personally. I like the additional fingerprint confirmation before accessing any TOTP codes, and also we're an M365 school so it integrates well there. I do also set up a passkey where I can with Google Password Manager on my phone, and Windows Hello for Business on my work PC, for the added convenience of not having to get a separate device or app out just to sign in (in addition to the security benefits of using phishing-resistant authentication)
Olliedawg Posted May 18 Posted May 18 (edited) You can also use a software TOTP in a password manager as a backup (KeePass for example) Edited May 18 by Olliedawg
Rob_D Posted May 18 Posted May 18 The way I see it, if the 2FS is locked local to the device, then it makes no odds which brand of authenticator we use. We also have office landlines as a backup 2FA.
pete Posted May 18 Posted May 18 If the platform allows me to have N+1 second factors per account, one goes on the phone and another goes in the password manager.
itskdog Posted May 18 Posted May 18 Is storing a TOTP secret alongside the password in the password manager sensible? I've always avoided that as then at least if the password vault is compromised (e.g. LastPass the other year) then at least they still won't be able to get through the 2FA screen as it's stored separately.
altecsole Posted May 18 Posted May 18 We have two break glass accounts - both Global Admins, both with Yubikey, and backup key, for MFA. One is in the school safe, the other off site. For my admin access I have PIM and JIT setup - I have a Yubikey for MFA, with MS Authenticator as a backup.
DalekSec Posted May 18 Posted May 18 PIM, MS Auth and Yubikeys for our admins Also a breakglass account with a Yubikey and alerts if its ever signed in
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now