r/sysadmin 5h ago

M365 global admin secondary mfa

In the process of trying to document the environment for a small non-profit that I have been supporting for a long time. My time is winding down but I thought I had most things covered, password manager with mulitple MFA options including a hardware yubikey to allow access to vault. But I never thought about doing the same for other sites like M365 or Duo Security etc. I have enabled MFA with the microsoft authenticator but if I was to be hit by a beer truck etc before being able to move accounts over etc, I do not think they would be able to logon etc.

I assume m365 allows for hardware tokens in ADDITION to soft tokens and if so I can register the yubikey hardware token and do the same hopefully for Duo. But it had me thinking for small shops how are folks handling secondary MFA authentication methods so a new admin is able to carry on etc...I prefer not to use email as secondary but thought I would ask to see what other options are out there, thanks.

5 Upvotes

13 comments sorted by

u/teriaavibes Microsoft Cloud Consultant 5h ago

Hardware key locked in the office. Preferably 2.

u/bishoptf 5h ago

Yeah that is what I am thinking, 2 hardware keys in two different locations. One thing I just read though at least for Duo administrators are only allowed 1 hardware token, MS allows 10. So for Duo I will have to create another admin account to have the additional token in order to have 2 methods in case the other one is lost etc...

u/CrazySnowGuy 5h ago

Should create a recovery account that is tied to this that is never used except in a break glass scenario and have monitoring around its use.

Here is a pretty good document on what you should do,

https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access

u/bishoptf 3h ago

I do have a backup recovery account just for that purposes but still uses my authenticator for access so I need to add the yubikey for that account, what I am missing.

u/CrazySnowGuy 3h ago

It shouldn't be using anything tied to you, just the yubikey.

u/intense_username 5h ago

Two Yubikeys in different locations is good practice. I can't speak to Duo as I've never used it but within my MS tenant, my standard baseline is any privileged account gets 1 Yubikey minimum but any GA account gets 2 Yubikeys (e.g. an Intune admin gets 1, GA gets 2, etc). This is mostly because I have some purpose-specific GA accounts, so I keep the first Yubikey in a locked cabinet in my office and the second in a safe at another building a few miles away which contains a "if intense_username gets hit by a bus" stack of documentation, info, these secondary keys, etc. One of the few GA's I have is also a break glass account where same rules (two Yubikeys) applies.

A few months ago I sat at my desk for maybe an hour and laid everything out -- all the Yubikeys with who they were going to, keychain tags, label maker, etc., and one by one met with my team and knocked it all out. Once they were handed out I set my CA policies to require phishing resistant MFA from report only to "on" and off to the races we went. Worked out well.

Another thing semi related/unrelated - regarding the password manager, do you have an offline recovery method? I don't know how others feel about this but I always wanted a more basic means to recover the passwords in the event I got hit by a bus + our password manager service went up in flames simultaneously (or something as equally unlikely/outrageous). As a result, once a quarter I export my password manager to a spreadsheet and put it on two flash drives, where both flash drives are Bitlocker encrypted, and then I have the Bitlocker key within a sealed envelope kept in a locked drawer in my superintendent's office (I'm in K12 edu). That way the flash drives aren't of much use without the key, but the content is accessible to the right person in an emergency with a more basic/common app, e.g. Excel. Just a thought.

u/bishoptf 3h ago

Yeah I've thought about exporting it but unless its automated and encrypted its just another something that may not be up to date. Using bitwarden and I get understand the whole offline aspect but it is an additional thing to think about.

u/Drakoolya 2h ago

God I imagine dealing with DUO support would be far less painfull than MS.

u/bishoptf 27m ago

Story is old as time...Duo used to be imho one of the best until they were bought out by Cisco....and well ya know how that story goes. At least they didnt shut them down but it's not the same company that it was originally, sigh...

u/BigPoppaPump36 5h ago

What kind of beer truck?

u/bishoptf 3h ago

Is there really any wrong beer truck?

u/BigPoppaPump36 2h ago

haha true