Looking for recommendations regarding Duo MFA setup/should users be required to use MFA at login to PC and for VPN or one or the other.
What factors might affect this decision?
OS SecurityNetwork SecuritySecurity
Last Comment
madunix
8/22/2022 - Mon
David Johnson, CD
both or at a minimum login
David
ASKER
That was my thought as well.... I was questioning the decision because a cyber security company we work with said VPN instead of login.
btan
My environment is both. Gone are days we rely in one factor as threat vector becomes sophisticated. I guess "they" are thinking of physical security, managed device and there is bitlocker in place hence one factor is risk mitigated. Each security layer would assumed to fail and authentication is one critical layer which should target higher security level at machine and apps level. Ultimately dependent on risk appetite.
Here is Authentication method strength and security:(source: link) If you don't want to use Windows hello for business, you could try with hardware token or phone.