I think the infosec pros, particularly those who manage security for large institutions, will get a good eye roll out of this one.
I work for a large school district, which uses GSuite Education and also a separate SSO portal for all the other apps we use.
First teacher in service day it was mentioned that the district would be finally implementing 2FA for all accounts. Great.
Today, we all receive an email from our head of tech. By the end of the month, we must set up 2FA.
1/x
Unless of course we sign into our district WiFi. On our personal phones. Yeah, not happening.
It's pretty clear to me that they are trying to bring their security in line with the 21st century, but doing so at zero cost to them. What they should be doing is buying hardware FIDO keys for every employee, instead trying to force us to all use our personal devices for this.
Needless to say, this will be a topic of discussion at next week's union meeting.
3/3
@0x56
It would have to be separate computer. We each have a Windows laptop and a Chromebook. Our Google accounts are tied to our Windows logon, and the SSO portal is how we sign into our Chromebooks.
@voltronic - I get that
@voltronic - can you use Authy desktop?