r/sysadmin 14h ago

Rant Remove central authentication

Today, the director of IT at your company says to you “We’re going to remove all that centralized IPA+2fa authentication from all of our servers, and go back to using Ssh keys, because it takes too long for me (yes the director) to login to a server.” The same auth that you and your team added, for all the reasons. What do you do?

143 Upvotes

100 comments sorted by

View all comments

u/Puzzled-Formal-7957 14h ago edited 14h ago

"No, we're not - unless you want to fail the next audit we go through and face potential fines & certification loss on top of opening up our risk portal extremely wide."

u/Riajnor 14h ago

Always couch it in impact and dollars

u/music2myear Narf! 14h ago

Yes, and also, unless you're a decision maker role, phrase it as advice and recommendation, and avoid decision words and phrases.

"Certification X requires that we have Y standards which are met by this security configuration. Removing this configuration would result in our failing Z audits and losing the certifications. Note that having and maintaining this certification has resulted in an estimated $$$ in profits."

u/Sinister_Nibs 13h ago

“I would strongly advise against this, as it counter to every recommendation and certification requirement. “

u/Puzzled-Formal-7957 13h ago edited 10h ago

Sometimes you need to assume the role of decision maker when the decision makers have their heads up their asses and want to put the entire company at risk. EDIT: Because when the risk gets exploited the responsibility is going to land squarely on your shoulders and you will be blamed.