M365 global admin secondary mfa
In the process of trying to document the environment for a small non-profit that I have been supporting for a long time. My time is winding down but I thought I had most things covered, password manager with mulitple MFA options including a hardware yubikey…
In the process of trying to document the environment for a small non-profit that I have been supporting for a long time. My time is winding down but I thought I had most things covered, password manager with mulitple MFA options including a hardware yubikey to allow access to vault. But I never thought about doing the same for other sites like M365 or Duo Security etc. I have enabled MFA with the microsoft authenticator but if I was to be hit by a beer truck etc before being able to move accounts over etc, I do not think they would be able to logon etc. I assume m365 allows for hardware tokens in ADDITION to soft tokens and if so I can register the yubikey hardware token and do the same hopefully for Duo. But it had me thinking for small shops how are folks handling secondary MFA authentication methods so a new admin is able to carry on etc...I prefer not to use email as secondary but thought I would ask to see what other options are out there, thanks.
已收录讨论
Hardware key locked in the office. Preferably 2.
Yeah that is what I am thinking, 2 hardware keys in two different locations. One thing I just read though at least for Duo administrators are only allowed 1 hardware token, MS allows 10. So for Duo I will have to create another admin account to have the additional token in order to have 2 methods in case the other one is lost etc...
Should create a recovery account that is tied to this that is never used except in a break glass scenario and have monitoring around its use. Here is a pretty good document on what you should do, https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access
Is there really any wrong beer truck?
haha true
Yup I am headed in a similar direction, currently have one admin with yubikey and bitwarden passkeys and I need to purchase another yubikey for the other admin account which will also be added to Bitwarden under the other account. I think we are covered halfway now but would like to have an additional yubikey as a backup.
What kind of beer truck?
Two Yubikeys in different locations is good practice. I can't speak to Duo as I've never used it but within my MS tenant, my standard baseline is any privileged account gets 1 Yubikey minimum but any GA account gets 2 Yubikeys (e.g. an Intune admin gets 1, GA gets 2, etc). This is mostly because I have some purpose-specific GA accounts, so I keep the first Yubikey in a locked cabinet in my office and the second in a safe at another building a few miles away which contains a "if intense_username gets hit by a bus" stack of documentation, info, these secondary keys, etc. One of the few GA's I have is also a break glass account where same rules (two Yubikeys) applies. A few months ago I sat at my desk for maybe an hour and laid everything out -- all the Yubikeys with who they were going to, keychain tags, label maker, etc., and one by one met with my team and knocked it all out. Once they were handed out I set my CA policies to require phishing resistant MFA from report only to "on" and off to the races we went. Worked out well. Another thing semi related/unrelated - regarding the password manager, do you have an offline recovery method? I don't know how others feel about this but I always wanted a more basic means to recover the passwords in the event I got hit by a bus + our password manager service went up in flames simultaneously (or something as equally unlikely/outrageous). As a result, once a quarter I export my password manager to a spreadsheet and put it on two flash drives, where both flash drives are Bitlocker encrypted, and then I have the Bitlocker key within a sealed envelope kept in a locked drawer in my superintendent's office (I'm in K12 edu). That way the flash drives aren't of much use without the key, but the content is accessible to the right person in an emergency with a more basic/common app, e.g. Excel. Just a thought.
God I imagine dealing with DUO support would be far less painfull than MS.
we have 2 break glass accounts with permanent global admin assigned with 20 characters long password and a Yubikey assigned to each. One is with IT (to be used if all of our phone becomes unusable) in server room and another one in a labeled envelope given to management with a whole mail why this key and PIN should be kept with utmost confidence. oh also both accounts are monitored for login alerts via defender incidents.
You can print the QR code and use it unlimited times . Keep in safe or at the ceo house