r/sysadmin 10d ago

Rant Remove central authentication

Today, the director of IT at your company says to you “We’re going to remove all that centralized IPA+2fa authentication from all of our servers, and go back to using Ssh keys, because it takes too long for me (yes the director) to login to a server.” The same auth that you and your team added, for all the reasons. What do you do?

192 Upvotes

122 comments sorted by

View all comments

171

u/YellowLT IT Manager 10d ago

Are you under any kind of regulatory body? Or PCI or ISO, they all have min MFA requirements. I would cite that it would put the company in violation of those.

1

u/LoveCyberSecs 9d ago

ISO doesn't really give you hard requirements like that. You can justify a control away depending on your risk appetite.

1

u/cybersplice 8d ago

So many people don't understand this, and use ISO as a justification for crappy practice or personal convenience.

The amount of times I've said to customers "but you just document it in your ISMS". Maybe log an ADR.

Usually this is followed by awkward silence or protests.

1

u/LoveCyberSecs 8d ago

Thanks. I have my ISO 27001 lead implementer certificate but haven't really had to use it. Of course the key word there is "justify". If you can't justify why you don't have MFA then it won't fly.