Link to home
Start Free TrialLog in
Avatar of David
DavidFlag for United States of America

asked on

MFA Procedure/Security Recommendations

Looking for recommendations regarding Duo MFA setup/should users be required to use MFA at login to PC and for VPN or one or the other.

What factors might affect this decision?
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

both or at a minimum login
Avatar of David

ASKER

That was my thought as well.... I was questioning the decision because a cyber security company we work with said VPN instead of login.
Avatar of btan
btan

My environment is both. Gone are days we rely in one factor as threat vector becomes sophisticated. I guess "they" are thinking of physical security, managed device and there is bitlocker in place hence one factor is risk mitigated.
Each security layer would assumed to fail and authentication is one critical layer which should target higher security level at machine and apps level. Ultimately dependent on risk appetite.

Here is Authentication method strength and security:(source: link)
User generated imageIf you don't want to use Windows hello for business, you could try with hardware token or phone.
Avatar of David

ASKER

Thank you both!
Absolutely for VPN, and maybe for device login.

I would never do no MFA on VPN unless you were using certificate based authentication for the VPN.

If you can also do strong authentication to a device, that is a bonus.
ASKER CERTIFIED SOLUTION
Avatar of madunix
madunix

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial