THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Monday, November 07, 2022
Choosing a multi-factor token or tool based on the firm's demands and potential attackers helps prepare and reduce token and phone deployment and migration.
FREMONT, CA: The use of passwords to secure networks is insufficient for any organization or business. Security guidance will tell that multi-factor authentication (MFA) is essential for preventing attackers from accessing the system. A multi-factor token or tool should select based on the firm's needs and how attackers may target it. Planning allows for minimizing the deployment and migration of new tokens or phones. Choosing a solution that is easy to manage in advance, won't cause extra complications throughout upgrades, and fulfills the organization's needs.
Cloud authentication requirements: It is generally impossible to agree on a single authentication application for cloud services. Cloud services may synchronize with a single authentication application. Administrators often require a range of MFA technologies, such as authentication programs (Microsoft, Authy, and Google Authenticator) and hardware tokens. Planning to verify that the authentication mechanism satisfies the help desk can administer the regulatory needs and specifications. MFA should be a requirement in the organization, but how it's administered and managed can either aid or burden the support desk.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Understanding the MFA solution's limitations: Several decisions must be made when choosing an MFA tool. The first step is to review how the tool protects the network. MFA may only partially protect organizations from some attacks when added to on-premises applications. MFA is only sometimes effective in protecting servers. The attackers were able to attack servers around MFA because it did not protect that part of the site. The most important thing to consider is what chosen MFA solution protects, and then review what authentication processes remain vulnerable.
Using hardware tokens versus the phone for authentication: Companies may choose to deploy tokens or key fobs instead. Although some options may be more expensive, there is less need to migrate. Tokens incur additional costs because they are not always with the user, but smartphones are typically always within reach. Tokens and keyfobs may require additional training and must consider battery replacement and other deployment requirements.
Microsoft-exclusive choices: Companies have multiple options for Microsoft multi-factor authentication requirements, beginning with Microsoft Authenticator. If most of their employees use Android or Apple devices, Microsoft Authenticator is a cost-effective option that can deploy fast. They should be able to utilize the Authenticator app as a second factor for accounts even if they still need to upgrade. Options for authentication without a password include Windows Hello for Business, Microsoft Authenticator, and FIDO2 security keys. They can frequently utilize FIDO2 keys with other MFA-required programs to safeguard Microsoft applications and provide a second authentication factor for password management tools, remote access, and other purposes.
More in News